Unforecast weather and flight below minimum altitude involving Fokker Aircraft F100, VH-NHV, Paraburdoo Airport, Western Australia, on 22 November 2021

Final report

Report release date: 24/03/2023

Executive summary

What happened

On the morning of 22 November 2021, a Network Aviation Fokker Aircraft F100, registered VH‑NHV, operating from Perth Airport to Paraburdoo Airport, Western Australia, encountered unforecast weather on arrival at Paraburdoo. Low cloud had developed below the landing minima, which resulted in 3 missed approaches. On the fourth approach, the aircraft fuel state was near the minimum fixed reserve, so the flight crew continued the approach below landing minima without visual reference and landed without further incident.

What the ATSB found

The ATSB found that, after having completed 2 missed approaches at Paraburdoo, the flight crew had lost confidence in their flight plan weather forecasts and were reluctant to attempt a diversion to an alternate airport without current weather information. After the third missed approach, the aircraft did not have sufficient fuel to reach a suitable alternate and the flight crew were committed to landing at Paraburdoo.

The flight crew’s flight plan for Paraburdoo indicated the lowest cloud would be above their landing minima, with deteriorations in the weather lasting for up to 60 minutes. However, the actual conditions encountered were below their landing minima and continued to deteriorate. This was difficult to forecast by the Bureau of Meteorology as detection of low cloud was obscured by higher level cloud. The development of low cloud at Paraburdoo contrasted with the expectation that surface heating would lift the existing cloud base.

After the second missed approach at Paraburdoo, the flight crew attempted to obtain an updated forecast for Newman Airport from air traffic control, but they did not express any urgency with this request. This, in combination with air traffic control workload at the time, resulted in a delay of 15 minutes before an update was offered. By that time, it was no longer required as they had insufficient fuel remaining to divert to Newman. Further, the aircraft was not fitted with an operational aircraft communications addressing and reporting system (ACARS), and they were beyond the range of the nearest automatic en route information service (AERIS). Therefore, the flight crew had no other means for obtaining updated weather forecasts for potential alternate aerodromes.

Paraburdoo Airport had an automatic weather station, which could measure the relative humidity at the surface. However, there were no means for measuring atmospheric data above the surface, which is one of the elements used to forecast cloud bases. In addition, the nearest weather balloon stations were more than 160 NM (300 km) from Paraburdoo, and therefore, the Bureau of Meteorology relied on cloud observations at nearby aerodromes to verify the expected conditions for Paraburdoo. Also, as the Newman automatic weather station was not recording the cloud or weather data groups, it was unknown if a SPECI report should have been issued for Newman for low cloud conditions, as it was for Paraburdoo.

Other than a procedure that limited the number of missed approaches to 2, Network Aviation did not provide flight crew with diversion decision-making procedural guidance when encountering unforecast weather at a destination.

In addition, Network Aviation had not included the threat of weather below the landing minima in their risk assessments for controlled flight into terrain. Consequently, these risk assessments did not include risk controls to address this threat. Without the identification of this threat and associated controls, their safety assurance team would not have had oversight of how effectively this was managed.

What has been done as a result

Following this incident, Network Aviation have implemented several proactive safety actions, which included:

  • An amendment to their flight plans to include diversion calculations for 2 alternate aerodromes. This was provided pre-incident for flights that required an alternate and amended post-incident to provide it for all flights.
  • Their arrival briefing procedure was amended to require flight crew to brief the minimum fuel required to divert to an alternate for all flights.
  • Introduced a Fokker Aircraft F100 company procedures manual with pre-populated diversion information for each of their F100 destinations.
  • Re-issued an updated internal safety advisory notice for their flight crew about the limitations of automatic weather information services.
  • Updated their Paraburdoo Airport risk assessment to capture this incident as a risk and their safety action as controls.
  • Updated their risk assessments for controlled flight into terrain to include adverse weather as an environmental threat.
  • Amended their company fuel policy to mandate additional alternate fuel requirements for nominated airports (operator approved variations). Airport classification is assessed based on alternate availability, instrument approach availability, aerodrome forecast reporting and historical accuracy, local mesoscale weather phenomena, and topography/terrain.
  • Established access for flight crew to obtain expanded briefings on ports (with operator fuel policy approved variations) from internal company meteorologists.
  • Updated the company’s Aerodrome and Route Data Manual to provide a new section on weather planning tools and resources, and a new section explaining the limitations of ceilometers and visibility meters installed in automatic weather information stations throughout the company network.
  • Enhanced the company’s training reference library for flight crew to support pilot knowledge and decision making. Additional content in the library is focused on company learnings from QF1616, which includes: 
    • fuel management
    • threat management and contingency planning
    • time management in areas of vulnerability
    • pilot in command responsibilities.
  • Updated their take-off and landing data cards to provide a dedicated section for recording the alternate aerodrome, estimated time interval, fuel burn and fuel on arrival.

Safety message

Adverse weather conditions may not be experienced in the Australian environment to the same extent as they are in other countries. However, these events have been identified as contributing factors to incidents and accidents throughout aviation history and have been a driver for numerous safety initiatives. Therefore, it is important for all operators to consider how unforecast weather will be managed and ensure it is reflected in their risk management so that safety assurance activities can review how effectively it is managed and provide feedback for management review.

 

The occurrence

Overview

On 22 November 2021, at about 0746 Western Standard Time,[1] a Network Aviation Fokker Aircraft F100, registered VH‑NHV, operating flight QF1616 from Perth Airport to Paraburdoo Airport (YPBO), Western Australia, encountered unforecast low cloud on arrival at Paraburdoo. Three missed approaches were conducted during which time the flight crew considered diversion options to Karratha Airport (YPKA), Newman Airport (YNWN), and Solomon Airport (YSOL) (Figure 1). On the fourth approach, the aircraft fuel state was near the minimum fixed reserve, so the flight crew continued the approach below the minimum descent altitude (MDA)[2] without visual reference to the runway. The aircraft landed without further incident.

Figure 1: Incident flight path from Perth to Paraburdoo

Figure 1: Incident flight path from Perth to Paraburdoo

Source: Google Earth, annotated by the ATSB

Pre-flight and departure

On the morning of 22 November 2021, the captain and first officer (FO) for flight QF1616 arrived at the airport and proceeded directly to their aircraft for a planned 0600 departure. Their flight was the first of 3 Network Aviation F100 flights from Perth to Paraburdoo, with the second and third flights scheduled to depart at 0630 (QF1618) and 0700 (QF1840). The flight time to Paraburdoo was scheduled to be 1 hour 29 minutes.

Once on board the aircraft, the flight crew downloaded and reviewed their flight plan on their electronic flight bags. The flight plan indicated a direct flight to Paraburdoo with the minimum required fuel, which included a 10% flight fuel variable reserve, 60 minutes of holding fuel for arrival at Paraburdoo, and 30 minutes of fixed fuel reserve. The additional 10-minute company fuel reserve was recorded on the flight plan as removed due to the forecast payload.

The mean weather conditions for arrival at Paraburdoo from the aerodrome forecast[3] included scattered[4] cloud at 1,000 ft and broken cloud at 3,000 ft with visibility greater than 10 km.[5] There was also a TEMPO[6] period for broken cloud at 1,000 ft and visibility reduced to 4,000 m, valid for their arrival time, which required 60 minutes holding fuel. The TEMPO conditions were forecast to be above their landing minima,[7] so while they departed with minimum fuel, the flight crew expected visual conditions at Paraburdoo before reaching the MDA. The captain recalled that the other inland airports in the Pilbara region had similar forecasts with TEMPO or INTER[8] periods, and that Karratha ‘was bad, but forecast to improve’.

At about 0553, the flight crew received a last-minute change on their flight plan, which reduced the planned take-off and landing weights by 847 kg. At this time, the fuel truck had departed, and the captain elected not to delay the flight by recalling the refueller to load additional fuel.

The flight data recorder indicated the aircraft departed at 0619:32 and reached its cruise altitude of flight level (FL)[9] 350 at 0646:05. The FO was designated as the pilot flying (PF) and the captain was the pilot monitoring (PM) at the start of the flight.[10] The PF had loaded Paraburdoo into the flight management computer (FMC) as route 1 and YPKA as route 2. Therefore, the FMC was calculating the fuel required for both destinations.

Arrival at Paraburdoo

The cockpit voice recorder indicated that at about 1 hour after take-off, at 0719 and FL 350, the flight crew listened to the Paraburdoo automated weather information service (AWIS).[11] The AWIS indicated the wind was from 050° at 6 kt, the cloud was scattered at 2,100 ft, broken at 4,800 ft, overcast at 6,700 ft, QNH[12] 1012, temperature and dewpoint[13] were 20 °C and 19 °C respectively, and relative humidity 94%. The flight crew discussed the weather and noted there was no rainfall reported and that the wind favoured runway 06. As the operator had a requirement for an instrument approach to be flown for arrivals at Paraburdoo, they commenced preparations for the area navigation (RNAV) approach to runway 06, which included their arrival briefing.

At about 0724, the PM contacted their ground station at Paraburdoo to advise them of their 0745 estimated time of arrival and their ground handling requirements. At 0725:41, the descent was commenced, and the PM advised Melbourne Centre air traffic control (ATC) of their estimated time of arrival at Paraburdoo. At about 0730, while on descent through FL 240, the flight crew listened to the Paraburdoo AWIS a second time.[14] The PM then verbalised ‘1013’[15] to the PF, who acknowledged the change in QNH, and they noted that the reported rainfall was less than moderate.

At interview, the captain (PM) recalled only noting the change in QNH and expected the visual conditions for landing to remain the same after listening to the AWIS.[16] The FO (PF) did not recall this second instance of listening to the AWIS.

First approach (runway 06)

At about 0731, the flight crew selected the Paraburdoo common traffic advisory frequency (CTAF) and turned on the pilot activated lighting (PAL),[17] which provided precision approach path indicators (PAPI)[18] for each runway and low intensity runway edge lighting. At about 0736, the flight crew completed their approach checklist for the runway 06 RNAV approach and noted their estimated time of arrival was 0744. As the aircraft descended through 5,500 ft, the flight crew observed extensive cloud. At 0741:43, just after passing the initial approach fix, the PF decided to configure the aircraft early due to a tailwind on the approach. At 0743:28, the flight crew changed the autopilot vertical mode from altitude hold to vertical speed and commenced their final descent to runway 06.[19]

At about 0744, the PF called for the before landing checklist, which the PM reported as completed as the aircraft descended through 3,000 ft towards the MDA of 1,960 ft. During the approach, the PM verbalised the aircraft’s vertical position relative to a 3° descent path and each subsequent distance-altitude step in the procedure as required. At 0746:01, the PM reported they were 100 ft above the minima, which was acknowledged by the PF. Shortly after, the PM announced ‘minima’, followed by ‘no contact’. The PF then announced that they were going around, and the PM commented that they were too high. The flight crew reported at interview that they sighted the runway with the PAPI indicating 4 white lights and were therefore too high to safely land from the first approach.

The aircraft was climbed to 5,200 ft in the missed approach, and while on climb, the flight crew briefly discussed the first missed approach. They concluded that they were too high on the approach due to a tailwind and decided to conduct an approach to runway 24. At 0747, the PM notified ATC of the missed approach and that they would make an approach to runway 24 and requested an operations normal[20] time of 0815.

Second approach (runway 24)

At 0752:46, while setting up for an approach to runway 24, the PM commented that the weather at all the surrounding airports was unsuitable, and then listened to the AWIS. The AWIS broadcast indicated the cloud was broken at 800 ft, overcast at 1,500 ft, and visibility had reduced to 5,000 m. Between 0753:20 and 0756, the flight crew had several conversations about the weather. This included that they could see ‘holes’ in the cloud where they were holding, that they were too steep when they became visual on the first approach, and that they expected to have a headwind on the approach to runway 24.

At about 0757, the flight crew activated the PAL, and the PM made a CTAF call to announce their intention to conduct an approach to runway 24. At about the same time, the flight crew of QF1618 contacted ATC for their clearance to leave controlled airspace on descent to Paraburdoo. At about 0758, the PM of QF1616 reported to QF1618 that they had commenced the runway 24 RNAV approach. This was followed 1 minute later by a broadcast from the flight crew of another aircraft (QF1802) to ATC that they had landed at Newman.

At 0802:43, the PM announced that they were 100 ft above the minima (of 2,040 ft) on the runway 24 RNAV approach, followed by ‘minima’. At 0802:53, the PF announced they were going around. At interview, the flight crew explained that they became visual with the ground on the approach to runway 24, but low cloud in front of them obscured the runway, which required a missed approach.

At 0805, while holding at 4,100 ft, the flight crew again discussed the weather and the PF commented that an aircraft had landed at Newman. They were uncertain of the actual weather conditions at that location and the PM noted they only had about 40 minutes of holding fuel remaining. At interview, the flight crew reported that, following the second missed approach, they noted that the FMC indicated they were at minimum fuel to divert direct to Karratha from their present position. However, the PM was cognisant of the fact that the FMC calculation did not account for the actual wind conditions they might experience en route or allow for an instrument approach on arrival. As Newman was closer than YPKA, they considered potentially diverting there with a fuel reserve on arrival for an approach.

At 0806, the PM contacted ATC to notify them of their second missed approach due to low cloud and requested the latest weather for Newman. Melbourne Centre acknowledged the request. However, there was no urgency conveyed by the PM nor was the aircraft’s fuel status relayed with this request. The flight crew and ATC then diverted their attention to their other tasks, which included traffic inbound to Paraburdoo.

Third approach (runway 06)

Between 0807 and 0809, the flight crew discussed their options, which included a preference to remain at Paraburdoo and that they had enough fuel for 2 more approaches. The PM then broadcast their intentions to QF1618. The flight crew of QF1618 reported that they had sufficient fuel for 35-40 minutes holding and then a diversion to Karratha.[21] At 0810:32, the PM contacted the Paraburdoo safety car officer and asked if the cloud overhead the airport was ‘sitting still or moving through’. The officer reported that it was coming from the north-west and was ‘moving through’. The flight crew briefly discussed this observation and then elected to make another approach to runway 06. The PF commented that the weather felt like it was persistent and that they did not have any options.

At about 0813, the PM provided ATC with a new operations normal time of 0830 and they commenced their third approach. At 0816:33, the PM announced ‘minima’ and 5 seconds later the PF announced that they were going around. During the missed approach, the PF reported that the runway 24 approach was better, and the PM noted that the wind was getting worse.

Fourth approach and landing (runway 24)

The aircraft climbed to 5,200 ft after the third missed approach and entered a holding pattern for the runway 24 RNAV approach. At about 0819, the flight crew noted they had 1.8 tonne of fuel on board and decided to hold while QF1618 conducted an approach to runway 24. The PM then advised QF1618 of their intention to hold until minimum fuel and offered them an approach while they were holding.

At about 0821, ATC contacted QF1616, and the PM notified them that they were manoeuvring to allow QF1618 to make an approach and provided a new operations normal time of 0840. This was acknowledged by ATC with the additional query as to whether the flight crew still required the weather forecast for Newman. The PM responded that it was no longer required (due to their fuel state).

At about 0822, the PF commented that Solomon was directly ahead (55 NM to the north), and the flight crew then discussed Solomon as a divert option and the need to obtain updated weather while they were holding. However, the PF then noted the lowest MDA at Solomon was about 800 ft above the aerodrome elevation (2,800 ft MDA), which was about 200 ft higher than at Paraburdoo. There were no further discussions of Solomon given the lower probability of establishing visual reference from an approach with a higher MDA.

At about 0825, the flight crew listened to the Paraburdoo AWIS, which reported the cloud was broken at 400 ft and 800 ft, visibility was 4,200 m, wind from 270° at 6 kt, QNH 1013 and relative humidity was 93%. At about 0826, QF1618 notified QF1616 they were going to start their approach and queried how long QF1616 would hold before diverting. The PM replied that they could not divert and would hold until they were ready to make a final approach. At about 0827, QF1840 broadcast that they were inbound to Paraburdoo and ATC notified them that QF1616 and QF1618 were traffic for them. At about 0828, the PM remarked that they had 12 minutes fuel remaining before landing with a 1.1 tonne fuel reserve.

At 0828:49, the captain and FO exchanged roles, the captain became the PF, and the FO became the PM for the final approach. The flight crew then discussed their options, which were to either comply with the missed approach criteria and declare a MAYDAY[22] fuel situation if not visual at the missed approach point or continue below MDA for a landing if they were not visual at the minima. They agreed to continue below the MDA for a landing.

At about 0834, ATC broadcast a SPECI alert for Paraburdoo, which was followed by a CTAF call from QF1618 to report their missed approach from runway 24, and then another ATC broadcast for a SPECI alert for Solomon. At 0834:48, the PM of QF1616 made a CTAF call that they were commencing the runway 24 RNAV approach. The PF then emphasised to the PM that they both needed to be prepared to call a go-around if either of them sensed the approach was becoming unsafe. At about 0837, ATC contacted QF1616 for an update and the PM reported that they had commenced the approach.

At 0841:51, the ground proximity warning system[23] announced ‘1,000 ft’, which was followed shortly after by the PM stating they were at 3 NM and ‘on profile’. Ten seconds later, at 844 ft above ground level and 273 ft above the MDA, the PM remarked the cloud was starting to break up. The PM called ‘minima’ at 0842:25. The ground proximity warning system then announced ‘500 ft’, ‘400 ft’, and ‘300 ft’. At 0842:50, the autopilot was disconnected, and the PM announced that they had sighted the runway and were on profile, at which stage they were 293 ft above ground level and 291 ft below the MDA. The flight crew reported they were slightly left of centreline, but on glideslope with the PAPI when they became visual with the runway. This was consistent with the flight data recorder information, which indicated a steady descent profile on the approach and a maximum of 5° heading change between the autopilot disconnect and landing.

At 0843:23, the aircraft landed without further incident. During the landing roll, the captain recalled noting that their fuel on board indicated 0.96 tonne.[24] Following the landing, the PM made a CTAF broadcast that there were some very low patches of cloud at 250-300 ft above ground level. Figure 2 depicts the weather during the landing roll.

Figure 2: Weather at Paraburdoo during the landing roll of flight QF1616

Figure 2: Weather at Paraburdoo during the landing roll of flight QF1616

Source: Aerodrome Management Services, annotated by the ATSB

Context

Personnel information

Captain

The captain held a valid Air Transport Pilot Licence (Aeroplane) with a multi‑engine aeroplane instrument rating, type ratings for the Fokker FK70/100 (F100) and De Havilland Canada DHC-8 aircraft, and a Class 1 Aviation Medical Certificate. They had accrued 6,698 hours total flying experience with 2,641 hours on the F100. The captain reported being awake for about 5 hours at the time of the incident, having slept 7 hours the previous night, and recorded a mental fatigue score of 3 (‘Okay, somewhat fresh’) for the time of the occurrence.

First officer

The first officer (FO) held a valid Air Transport Pilot Licence (Aeroplane) with a multi-engine aeroplane instrument rating, type ratings for the Airbus A320, Fokker FK70/100, Embraer EMB 120 and Dornier DO328-100 aircraft, and a Class 1 Aviation Medical Certificate. They had accrued 6,735 hours total flying experience with 1,556 hours on the F100. The FO reported being awake for 5 hours at the time of the incident, having slept 8 hours the previous night and recorded a mental fatigue score of 2 (‘Very lively. Responsive, but not at peak’) for the time of the occurrence.

Aircraft information

Fuel requirements and weight limits

In accordance with the forecast conditions, the QF1616 flight plan fuel for take-off from Perth comprised of 89 minutes flight fuel (3,614 kg), 11 minutes variable reserve (361 kg), 60 minutes holding fuel (1,733 kg) and 30 minutes fixed reserve (962 kg). This resulted in a minimum take-off fuel load of 6,670 kg. In addition, the aircraft was loaded with 36 kg of tanker fuel[25] and 100 kg of taxi fuel, resulting in a flight plan fuel load at engine start of 6,806 kg.

The operator’s fuel requirements included the option for an additional 10 minutes holding fuel (equating to about 290 kg), payload permitting. The flight plan indicated that this was removed due to the forecast payload. To allow for last minute, minor payload variations without exceeding maximum landing weight, flight dispatch was required to plan a tanker fuel limit that ensured a 300 kg buffer on maximum landing weight. Consistent with these requirements, the flight plan landing weight at Paraburdoo was 39,615 kg and the maximum landing weight was 39,915 kg.

At about 0553 (7 minutes prior to the scheduled departure), there was a last-minute change to the passenger and freight loads. This resulted in a reduced planned landing weight of 38,768 kg, which would have permitted the captain to take an additional 1,147 kg of tanker fuel. However, the aircraft had already been refuelled and the refueller had departed when the flight crew received their last-minute change.

Navigation system information

The aircraft was equipped with a flight management system (FMS), with an associated flight management computer (FMC). The FMS navigation source was the global navigation satellite system (GNSS). In GNSS mode, the FMS was certified for RNP[26] 2, RNP 1 and RNP 0.3 operations but the vertical navigation (VNAV) function was not certified. Therefore, Network Aviation could conduct RNAV approaches to the LNAV landing minima but did not have approval to conduct them to the LNAV/VNAV minima.  

Aircraft communications addressing and reporting system

The incident aircraft was fitted with a non-operational aircraft communications addressing and reporting system (ACARS). The ACARS is a digital datalink system used for transmitting messages between the aircraft and ground stations via very high frequency (VHF) radio or satellite. This system provides another mechanism for flight crews to obtain weather information.

The Network Aviation Group-A F100 aircraft, which included the incident aircraft, were not fitted with satellite communications. Without satellite communications, the ACARS was limited to VHF line of sight with the ground stations.

According to the operator, the F100 fleet had a mixture of ACARS hardware units, and they were originally acquired without ground station connectivity and had no service provider. In 2016, 2 aircraft were selected for a feasibility study to test the technical viability and likely cost for activating the ACARS, which was then projected out to the remainder of the fleet. A business case, which included the activation of ACARS across the F100 fleet, was submitted in 2016 and the decision was made not to proceed with implementation at that point in time. This decision was based on a consideration of the range of projects underway across Network Aviation and a benefits analysis of implementing the solution. They had not considered including satellite communications in their ACARS business case and believed that most of their operational requirements could be met with VHF ground station connectivity. Network Aviation continues to operate the F100 aircraft and are not currently planning to implement ACARs on the fleet, however, they have not ruled out implementation of ACARs in the future.

Airport information

Paraburdoo Airport was an uncontrolled aerodrome with an elevation of 1,406 ft. The town of Paraburdoo is located about 5 NM west of the airport and lower terrain is located to the west of the town along a north-west to south-east divide (Figure 3). The airport had one runway, runway 06/24 (2,132 m long and 45 m wide), which had low intensity runway lighting installed and precision approach path indicator lighting set at a 3.0° slope for a threshold height of 50 ft, which were serviceable. The instrument approaches available included RNAV using GNSS for runways 06 and 24.

Figure 3: Paraburdoo (YPBO) terrain map

Figure 3: Paraburdoo (YPBO) terrain map

Source: Topographic-map.com, annotated by the ATSB

The LNAV landing minima for the RNAV approach was the minimum descent altitude (MDA) of 2,010 ft for runway 06 (604 ft above aerodrome level (AAL)) and 2,090 ft (684 ft AAL) for runway 24. The MDA could be reduced by 100 ft if an accurate QNH was obtained within 15 minutes of arrival, which reduced it to 504 ft AAL for runway 06 and 584 ft for runway 24. For the flight crew of QF1616, when flying a constant descent profile, they were required to add 50 ft to the MDA for the missed approach commencement altitude. Therefore, the flight crew operated to a minima of 1,960 ft (554 ft AAL) for runway 06 and 2,040 ft (634 ft AAL) for runway 24.

The aerodrome was equipped with an automatic weather station (AWS), which provided an automatic weather information service (AWIS) to flight crew, and meteorological METAR and SPECI reports to the Bureau of Meteorology (BoM) and Airservices Australia (air traffic services provider). Local radio traffic was conducted on a common traffic advisory frequency and air traffic services were provided by a Melbourne Centre flight information area (FIA) frequency.

Automatic weather station

A basic AWS has sensors for the temperature, dewpoint,[27] wind, QNH and rainfall data groups. At aerodromes, these basic AWS sensors are supplemented with a ceilometer and visibility meter. The ceilometer estimates cloud height by sending a laser light pulse near vertically through the atmosphere and using the back scatter[28] to measure cloud height. The AWS algorithm processes the raw sensor data every minute. While the current ceilometer data is used by the AWIS, the METAR and SPECI reports use the 30-minute average of data, but with the last 10 minutes given a double weighting to improve the response time to changing conditions. The BoM provided the following explanation for the difference between a ceilometer and human observer:

The ceilometer is an estimate based on the continuous sampling of a single point over a period of time (30 minutes for the ceilometer); whereas a human observer produces an estimate based on a view of the whole airfield and the whole sky over a short time prior to the observation.

According to the BoM, the AWS will trigger a SPECI report if the 10-minute average for the cloud base is below the highest alternate minimum[29] (1,664 ft at Paraburdoo) or 1,500 ft. A SPECI is also triggered if the 10-minute average for the visibility is below the highest alternate minimum (7,000 m at Paraburdoo) or 5,000 m.

If a data group is not available when a METAR or SPECI report is produced by the AWS, then this is indicated by solidi; ‘////’ for visibility, ‘//’ for weather and ‘//////’ for cloud. This is broadcast by the AWIS as ‘[data group] not available’.

Meteorological information

The flight plan for QF1616 provided the flight crew with the aerodrome forecasts (TAFs) for their departure, destination, and company approved alternate aerodromes. The FO programmed Karratha Airport as route 2 in the FMS and the flight crew discussed Karratha, Newman Airport and Solomon Airport as divert options after the second and third missed approaches at Paraburdoo. Therefore, the investigation of meteorological information focussed on the forecast and actual conditions for these aerodromes.

Flight plan forecast conditions

Paraburdoo

At the scheduled departure time from Perth of 0600, the forecast mean conditions for Paraburdoo were light rain with scattered cloud at 1,000 ft AAL, broken cloud at 3,000 ft, and visibility greater than 10 km with a TEMPO period until 1100 for broken cloud at 1,000 ft and visibility reduced to 4,000 m with moderate rain showers. The Paraburdoo METAR conditions, issued at 0430, reported rain, scattered cloud at 4,500 ft, 5,700 ft and 6,700 ft, wind from 060° at 8 kt, and the temperature and dewpoint were 20 °C and 19 °C respectively.

Newman

The forecast cloud and visibility conditions for Newman were the same as Paraburdoo with the exception that the TEMPO period extended until 1400. The Newman METAR conditions, also issued at 0430, reported cloud overcast at 11,000 ft and the weather data group was not available.

Karratha

The forecast mean conditions for Karratha were light showers of rain with scattered cloud at 2,000 ft, broken cloud at 5,000 ft, and visibility greater than 10 km. The conditions were forecast to improve at 0900 to no significant weather with scattered cloud at 5,000 ft. There was an intermittent period of variation from the prevailing conditions on the forecast that ended at 0400 for broken cloud at 1,500 ft and visibility reduced to 3,000 m in showers of rain. The METAR conditions, also issued at 0430, reported scattered cloud at 7,900 ft, overcast cloud at 11,000 ft, greater than 10 km visibility and the weather data group was not available. The flight plan did not include a forecast for Solomon.

Aerodrome weather reports

Paraburdoo

The Paraburdoo AWS issued the following observation reports on the morning of the incident (Table 1). For each of the times provided below, the QNH was 1013 and there were light rain showers, except for 0930 when the weather data group was not available.

Table 1: Aerodrome weather reports for Paraburdoo

TimeTypeWindVisibilityCloud (above ground level)Temp. (°C)Dewpoint (°C)
0730METAR040° at 4 kt>10 km

scattered at 500 ft

broken at 1,500 ft and 2,400 ft

2120
0731SPECI040° at 4 kt>10 km

scattered at 600 ft

broken at 1,500 ft and 2,400 ft

2120
0751SPECI340° at 3 ktreduced to 6,000 m

broken at 800 ft

overcast at 1,500 ft

2119
0800SPECI330° at 4 kt, varying from 290° to 350°reduced to 3,000 m

broken at 800 ft

overcast at 1,000 ft

2120
0830SPECI260° at 7 kt7,000 mbroken at 400 ft, 1,000 ft, and 1,300 ft2120
0839SPECI250º at 7 kt7,000 mbroken at 500 ft and overcast at 1,600 ft2120
0845SPECI240º at 8 kt6,000 mbroken at 400 ft, 700 ft and overcast at 1,700 ft2120
0900SPECI240° at 7 kt>10 km

broken at 400 ft

overcast at 900 ft and 1,700 ft

2120
0930SPECI250° at 5 kt>10 kmscattered at 600 ft overcast at 1,100 ft and 1,500 ft2219
1056SPECI300° at 4 kt>10 km

scattered at 1,300 ft

broken at 1,800 ft

overcast at 3,200 ft

2420
1100The aerodrome exited SPECI conditions.     

The period in which the cloud base was broken below 1,000 ft extended from 0751 until 0930. Scattered cloud at 500–600 ft buffered this period. The actual conditions recorded by the AWS indicated a cloud base lower than the forecast conditions, which extended beyond the 30‑60‑minute duration for TEMPO conditions. According to the BoM’s analysis of the meteorological conditions at the time of the incident, the TAF for Paraburdoo was amended to alternate conditions in low cloud at 0834, which was 4 minutes after the TEMPO holding period of 60 minutes was no longer satisfying the observed conditions. Overall, the observed weather reports included a cloud base below the highest alternate minima of 1,664 ft for 3 hours 26 minutes, from 0730 to 1056.

Newman

The reports for Newman indicated the AWS weather and cloud data groups were not available for the period 0600-1000. In this period, 11 reports were issued, 9 METAR and 2 SPECI reports. The SPECI reports were for a reduction and subsequent improvement in the visibility at 0934 and 0944 respectively. As the cloud data group was not available, it could not be determined if Newman was suitable at the time the captain requested the latest weather from air traffic control for this location.

Karratha

The reports for Karratha indicated the cloud base was above 10,000 ft from 0730–1000, and the visibility was greater than 10 km for the period 0600-1000. Therefore, the weather reports for Karratha indicated it was a suitable diversion option during the period of the incident.

Solomon

From 0600-1000, 16 reports were issued for Solomon, which consisted of 12 SPECI and 4 METAR reports. At 0804, the lowest cloud was broken at 600 ft, which was below the lowest landing minima, and therefore it was unsuitable at the time the flight crew were considering it. At 0841, the cloud was scattered at 500 ft and 1,400 ft, and broken at 2,100 ft with 5,000 m visibility. The weather data group was not available for this period.

Development of low cloud base at Paraburdoo

The BoM noted that Paraburdoo was outside the optimal range[30] for the nearest weather radar stations, located at Learmonth (210 NM) and Dampier (162 NM). At these distances, any echoes appearing on the weather radar displays would be from clouds higher up in the atmosphere and thus not representative of conditions closer to the surface. So, while Paraburdoo appeared clear of rain on the weather radars at the time of the incident, light showers of rain reported on the METARs indicated that this was not the case. Nearby weather stations all recorded rainfall and it was likely that the light rain or drizzle was widespread due to a rainband over the area. The BoM further stated that the period of low visibility leading up to the incident further supported the presence of precipitation.[31] It was likely that the rainfall provided extra moisture through evaporative processes as it fell into unsaturated air, which is known as the wet bulb effect.

The BoM also reported that the wind direction was likely a contributing factor for the low cloud base, which backed from the north-east at 0730 to the north-west at 0751 and around to the west at 0830. When the wind blows from the west, the local terrain surrounding Paraburdoo forces the air to rise. Rising air cools, while the amount of moisture remains constant, thus reducing the dewpoint depression[32] and promoting the development of low cloud as the air becomes saturated. This process is known as orographic uplift and results in upslope stratus[33] cloud. Therefore, the BoM concluded that the mechanisms that produced the low cloud at Paraburdoo were a combination of the wet bulb effect due to moistening of the airmass from rainfall and the orographic uplift provided by the terrain.

On their first approach at Paraburdoo, the flight crew noted they had a tailwind component to runway 06, despite the AWIS indicating the surface wind was north-easterly. The BoM reported that the winds described by the flight crew indicated the layer of wind above the surface layer would have been ascending as it flowed over the terrain. If this layer was close to saturation, then this could have promoted the formation of low cloud. The BoM indicated that ‘meteorological theory supports this conclusion if all factors were to line up, but it can’t be stated for certain.’

Forecasting for Paraburdoo

The Paraburdoo TAF used by the flight crew during pre-flight planning was issued at 0208 with a validity period from 0200 to 2000. The BoM reported that, at 0200, there had been observations of scattered cloud at 1,000 ft at nearby airports, which supported the TEMPO forecast for broken cloud at 1,000 ft at Paraburdoo. Early in the morning, broken cloud at about 1,000 ft was observed at various locations, mostly for periods of less than 1 hour at a time. Meteorological model guidance was forecasting the low cloud would lift at around 0800. However, from the duty forecaster’s experience, low cloud would persist in the Paraburdoo area longer than what the modelling generally indicated. As a result, a conservative approach was taken regarding the timing of the TEMPO and the Paraburdoo TAF issued at 0208 retained the TEMPO for broken cloud at 1,000 ft until 1100.

The BoM’s model traces had indicated saturated levels through to near to the surface. However, modelling in northern Australia was subject to false alarms for widespread low cloud. Therefore, some form of surface verification and/or satellite observations were required for them to have confidence in the modelling. They noted that the lifting trend in the modelling did not occur, and cloud bases dropped further below the highest alternate minima after 0700 and persisted for longer than the 1-hour TEMPO periods. They reported that, this event was difficult to forecast accurately, given modelling false alarms and the lack of observed lower cloud and satellite imagery available prior to the onset of very low cloud at Paraburdoo. The cloud that lowered significantly after 0700 contrasted with what they would normally expect, where the surface heating would lift the cloud base rather than for it to lower further.

The 0208 TAF forecast the temperature to rise throughout the morning. However, the AWS recordings indicated a slower temperature rise than what was forecast and a small dewpoint depression. The following table presents the TAF forecast temperatures and the recorded AWS temperatures and dewpoints on the morning of the incident.

Table 2: Aerodrome forecast (TAF) and automatic weather station (AWS) temperatures and dewpoints

Time0200050008001100
TAF temperature (°C)20222325
AWS temperature (°C)20202124
AWS dewpoint (°C)19192021

Sources of atmospheric moisture

The BoM reported that the depth of moisture through the atmosphere is important in determining the potential for low cloud development. There are not many observation sources that indicate the depth of moisture in an airmass, except for balloon soundings and aircraft meteorological data relay (AMDAR). There were no weather balloons or AMDAR profiles available at Paraburdoo to provide atmospheric data, including the depth of moisture in an airmass and there is currently no plan to install a weather balloon station, or a weather radar, at Paraburdoo.

Weather balloons and radar

Balloon-based weather observations provide precise measurements of temperature, pressure, humidity, wind speed and direction. The BoM released about 56 balloons each day from 38 locations.The main items attached to the balloon are a foil-coated cardboard target used to slow the descent of the balloon and track it with radar, and a small white plastic box known as a radiosonde, which has the sensors used to measure meteorological variables.

During the radiosonde’s flight it is constantly transmitting the meteorological data to ground equipment, which processes and converts the data into weather messages and is displayed as an aerological diagram for use by forecasters. The aerological diagram allows forecasters to obtain a snapshot of the atmosphere above a specific location to determine the atmosphere’s stability and forecast the lower and upper levels of clouds and their types.

The nearest weather balloon stations were Port Hedland, Learmonth, and Meekatharra. These locations were 175-210 NM from Paraburdoo and not guaranteed to be representative of the conditions at Paraburdoo. Figure 4 depicts the nearest weather balloon stations to Paraburdoo (blue) and the nearby airports (West Angelas (YANG), Barimunya (YBRY), Eliwana (YEWA) and Christmas Creek (YCHK), in green) where the 0200 observation of scattered cloud at 1,000 ft was used to support the incident TAF conditions.

Figure 4: Weather balloon stations relative to Paraburdoo

Weather balloon stations relative to Paraburdoo

Source: Google Earth, annotated by the ATSB

According to the BoM, the spatial distribution of the upper air network is designed to meet the requirements of national and regional numerical weather prediction models. The spatial density was reviewed in 2022 and found to meet the requirements set by the World Meteorological Organization for numerical weather prediction. The weather radars are targeted to areas where significant or hazardous weather intersect with areas of highest community need. While this covers 98% of the population, much of inland Australia, such as Paraburdoo, are not covered. Consequently, no precipitation was detected at Paraburdoo by the nearest weather radar stations at Learmonth and Dampier at the time of the incident.

Aircraft meteorological data relay

The World Meteorological Organization, in cooperation with some international airlines, has established the aircraft meteorological data relay program (AMDAR). The AMDAR system predominantly utilises existing aircraft onboard sensors, computers, AMDAR software and communications systems to collect and transmit meteorological data to ground stations via satellite or radio links using ACARS. This data is then relayed to national meteorological and hydrological services. These observations supplement the data gathered by other meteorological instruments and help to improve the accuracy of forecasts.

Vertical profiles of the atmosphere are taken when the aircraft climbs or descends during the departure or arrival phase of flight. According to the World Meteorological Organization guide to aircraft-based observations (ABO):

Vertical profiles derived from ABO should be considered as being very similar in character and application to those derived from meteorological radiosondes. AMDAR and other ABO generally provide an improvement in forecasting ability through a reduction in NWP [numerical weather prediction] forecast error of 10%–20% over the first 24 hours of the forecast period.

The AMDAR profiles coverage for Western Australia throughout the month of November 2021 is shown in Table 3 (fractional profiles are the result of averaging over multiple weeks). Paraburdoo was not part of the AMDAR network.

Table 3: AMDAR profiles Western Australia in November 2021

Airport nameProfiles taken (per week)
Broome International1.69
Christmas Creek Station6.52
Fortescue Dave Forrest2.90
Ginbata9.41
Newman4.10
Karratha13.03
Kalgoorlie Boulder5.55
Port Hedland International14.48
Perth International125.52

Sources of in-flight weather updates

Air traffic control

According to the Airservices Australia Aeronautical Information Publication (AIP) section GEN 3.3.4, air traffic control provides pilots with pertinent information that will affect flight within one hour’s flight time. At the time the information is identified, it will be directed to pilots maintaining continuous communications and broadcast on appropriate air traffic services frequencies.

In November 2018, a new filtering system for SPECI reports was launched by Airservices Australia. The new system assessed SPECI reports for all locations and provided more specific filtering to identify significant SPECIs. Air traffic control then directed these SPECI reports to affected pilots within one hour’s flight time. However, SPECIs were only disseminated if they differed from the associated TAF.

For example, the Paraburdoo SPECI issued at 0731 was for the cloud base below the highest alternate minima, which was expected with the TEMPO forecast on the TAF. Therefore, there was no requirement to disseminate this SPECI. However, the 0830 SPECI with broken cloud at 400 ft differed significantly from the TAF conditions and was therefore broadcast by ATC at 0834.

Automatic en route information service

The automatic en route information service (AERIS) continuously broadcasts METAR, SPECI and TAF information from a network of VHF transmitters installed around Australia. However, there are many gaps in the coverage provided across Australia. The nearest AERIS station to Paraburdoo was Meekatharra. This station broadcasted information for several airports, which included Paraburdoo and Karratha. However, as Paraburdoo was located about 210 NM north of Meekatharra and, disregarding any local terrain shielding effects, an aircraft would have to be at an altitude of about 36,500 ft overhead Paraburdoo for AERIS reception. Therefore, while holding and conducting missed approaches at Paraburdoo, the aircraft was too low to receive Meekatharra AERIS broadcasts.

The flight from Perth to Paraburdoo passed through the Meekatharra AERIS coverage and could have been used to update the actual weather conditions for Karratha, which was route 2 in the FMC. However, the flight crew were operating with holding fuel for Paraburdoo and no expectation that they would need to consider Karratha.

Aircraft communication addressing and reporting system

The ATSB discussed the potential use of ACARS for weather updates in-flight with the flight crew. The captain reported no previous experience with ACARS, but provided the following comments about its potential benefit in this incident:

Had we been able to utilise the ACARS for weather information it may have further allowed us to also get weather for other aerodromes and perhaps with that information have gone somewhere else.

The FO, who had previous experience using ACARS, provided the following comments about its potential benefit:

The Fokker have ACARS in them, but they’re not connected, whereas with other aircraft we could just dial it into the computer and request the ATIS or the TAF on any airport and get an automatic update – we don’t have to rely on anyone. It was busy that day, you could tell the controllers were working hard, when I said we waited for the weather for 15 minutes, he was busy, it wasn’t like he was ignoring us.

According to the Société International de Télécommunications Aeronautiques, who are the ACARS ground station gateway service provider in the Australian region, the nearest VHF datalink ground station to Paraburdoo was located at Newman, which was about 115 NM to the east. Disregarding any local terrain shielding effects, without a satellite connection the aircraft would have required an altitude of about 11,000 ft overhead Paraburdoo to receive weather information via the ACARS.

Diversion options

The captain reported that their nearest preferred diversion airports were Karratha and Newman. The Karratha AWS was reporting a cloud base above 10,000 ft, whereas Newman had the same TEMPO forecast as Paraburdoo, and the cloud base was unknown. While they considered Solomon after their third missed approach, a SPECI was subsequently issued with cloud below the landing minima.

The ATSB used the fuel figures reported by the flight crew at interview and on the cockpit voice recorder to estimate the fuel on board (excluding fixed reserve) and potential diversion range of the aircraft after each missed approach, with reference to the airports of Karratha, Newman and Solomon.

The Network Aviation F100 aircraft performance manual indicated FL 160 was the optimum level for a diversion of 150 NM (Karratha was 157 NM) and FL 110 for 100 NM (Newman was 115 NM). The FL 150 performance table figures were the closest to FL 160 and indicated the range from the first missed approach was about 242 NM,[34] and about 155 NM from the second missed approach. The A100 (10,000 ft) table figures were the closest to FL 110 and indicated the range from the third missed approach was about 84 NM (Solomon was 55 NM).

The captain recalled that they did not consider diverting after the first missed approach and that the FMC indicated they were at the minimum fuel for a diversion to Karratha after the second missed approach. The FO had set route 2 in the FMC to Karratha, and it was calculating the fuel direct to Karratha from their present position. However, the captain recalled that the FMC calculation did not consider the actual winds that would be experienced en route, or the additional fuel for an instrument approach if it was required at the destination.

The captain and FO reported that they decided minimum fuel was insufficient to divert to Karratha after the second missed approach without current weather, noting they would be committed to a landing on arrival. The captain recalled that they had looked at the forecast but were not aware of the actual weather conditions at Karratha. Consequently, they considered Karratha to be a ‘worse choice than staying at Paraburdoo where we did have the fuel to hold’. The FO also recalled that they had a discussion after the second and third missed approaches but concluded that they did not have enough fuel to divert anywhere safely without an updated weather forecast.

The flight crew subsequently decided to request a weather update for Newman as they heard QF1802 reporting to ATC at 0759 that they had landed at Newman, which occurred between their first and second missed approach. However, the captain reported that a diversion to Newman would have only been considered if ATC had reported significantly better weather as it also had TEMPO holding on the forecast and they had insufficient fuel to comply with that requirement. The use of Solomon was considered after the third missed approach, but then dismissed as the landing minima there was higher than the minima at Paraburdoo. Figure 5 depicts the estimated nil wind diversion range from each missed approach (242 NM, 155 NM, and 84 NM) and the airports that were under consideration by the flight crew.

Figure 5: Approximate nil wind diversion range from each missed approach

Figure 5: Approximate nil wind diversion range from each missed approach

Source: Google Earth, annotated by the ATSB

Organisational and management information

Diversion decision-making guidance

According to the Network Aviation Aerodrome and Route Data Manual, the preferred alternates for Paraburdoo were Karratha or Port Hedland. The flight crew had Karratha loaded in the FMC as route 2, but they did not obtain a weather update for Karratha before arriving at Paraburdoo. Their flight plan weather forecast and AWIS at top of descent indicated they would be visual before reaching the MDA. The operator noted that the weather forecast for Karratha was well above landing minima with no expectation of deterioration, and that ATC would broadcast if a SPECI was issued. Consequently, there was no company expectation or requirement for the flight crew to obtain updated weather for Karratha while en route to Paraburdoo.

According to the International Civil Aviation Organization (ICAO) Doc 8168 (2018), Aircraft Operations (Vol 3) – Aircraft operating procedures, standard operating procedures ‘provide guidance to flight operations personnel to ensure safe, efficient, logical and predictable means of carrying out flight operations’. Therefore, the ATSB asked the operator if they had considered a diversion decision-making procedure.[35],[36] They did not consider a prescriptive procedure necessary but had published a standard operating procedure to limit the number of missed approaches. The Network Aviation Flight Administration Manual provided the following information:

8.59.2 Multiple Missed Approaches
 

Multiple Missed Approaches are not only distressing to passengers, but can also increase the risk of incident or accident. Therefore, during normal operations, Flight Crew should limit the number of weather-related Missed Approaches to two. A third approach in these circumstances should not be immediately attempted unless the Pilot In Command believes there is a high probability of a successful approach and landing, or greater emergency or operational requirement exists.

With respect to procedure 8.59.2, the captain reported that it was not weather-related or considerate of a fuel-critical state and the FO indicated there was insufficient fuel to divert after 2 missed approaches. The captain further stated that their interpretation of the procedure was that it was intended for the benefit of the passengers and to only continue if confident a landing would be made from the third approach. The chief pilot noted that, while it was worded from the perspective of passenger comfort, it did have a secondary intent of not continuing to conduct approaches in unsuitable conditions, and the 2 missed approaches were a limit unless there was an expectation that a landing would be made from the third approach.

The operator did not consider a prescriptive diversion decision-making procedure necessary. However, after the incident, they noted flight crew could benefit with better tools to assist their diversion decision-making process. For example, company flight plans included a summary on the possible diversion locations only when the flight legally required an alternate.

The operator also noted that they did not have a requirement for their flight crews to brief their minimum divert fuel at the top of descent. They had not provided a procedural expectation that this would be briefed, although it was a common practice for one of their management pilots in their previous employment. The operator considered that, if the flight crew had briefed their minimum divert fuel for Karratha as part of their arrival briefing for Paraburdoo, it might have influenced their decision-making.

The operator’s observations were consistent with ICAO Doc 8168 (2018), which stated that ‘Crew briefings communicate duties, standardize activities, ensure that a plan of action is shared by crew members and enhance crew situational awareness’. The objectives for flight crew briefings for safety-critical actions included:

 

a) refreshing prior knowledge to make it more readily accessible in real-time during flight;

b) constructing a shared mental picture of the situation to support situational awareness;

c) building a plan of action and transmitting it to crew members to promote effective error detection and management; and

d) preparing crew members for responses to foreseeable hazards to enable prompt and effective reaction.

The section for arrival briefings in ICAO Doc 8168 (2018) also provided the following information:

3.5.4 Flight crew arrival briefings should prioritize all relevant conditions that exist for the descent, approach and landing. They should include, but not be limited to:

h) alternate aerodromes and fuel considerations;

While this incident involved unforecast low cloud, and alternate aerodromes were not required for the flight plan, the operator noted, that even on a clear weather day, a preceding aircraft could have an accident at the destination airport, which could require a diversion.

Risk management

Bowtie risk assessments

Network Aviation, a subsidiary of Qantas, used the Qantas Group safety management system Risk assessment procedure and risk assessment guide for their risk management processes. Among their various tools was a bowtie risk assessment software. According to the software user manual (2019):

Risk in bowtie methodology is elaborated by the relationship between hazards, top events, threats and consequences. Barriers [also known as controls or defences] are used to display what measures an organization has in place to control the risk.

The top event represents the loss of control of the hazard (undesired aircraft state), and damage or injury is represented by the consequence(s). A threat is a factor that ‘itself should have the ability to cause the top event’ (Figure 6). While aviation traditionally distinguishes between threat and error, the software program used threat as the descriptor for both.

When the risk assessment is constructed with multiple threats on the left side and consequences on the right side of the top event, a bowtie like structure appears. Between the threats and the top event are the preventive controls, to reduce the likelihood of the top event occurring. Between the top event and the consequences are the recovery controls, to reduce the likelihood and/or severity of the consequences.

Figure 6: Example bowtie structure

Figure 6: Example bowtie structure

Source: ATSB

United Kingdom Civil Aviation Authority bowties

The United Kingdom (UK) Civil Aviation Authority (CAA) initiated a ‘Significant Seven’ task force in 2009. From this they then developed a series of bowtie risk assessments, known as the ‘Significant Seven’, with 3 bowties for each of the 7 risks. They were published on their website in their software file format so that they could be downloaded and customised by industry. According to the CAA website the scope of the Significant Seven project was focussed on the risks that contribute to UK commercial air transport fixed-wing operations. The operating environment and equipment were generic but UK oriented, therefore they recommended the following:

Aircraft operators can be expected to encounter operating environments outside the scope of the bowtie templates during international operations and these conditions are an example of issues that should be addressed when customising the bowties.

Their Significant Seven included controlled flight into terrain (CFIT) with the 3 bowties CFIT 3.1, CFIT 3.2 and CFIT 3.3, with revision dates 2013-2014. The CAA website provided the following information about their CFIT risk assessments:

The structure of the CFIT bowties is such that generic issues related to arrivals and departures are considered in bowtie 3.1 'Large CAT fixed-wing arrival or departure (general)/ Terrain separation deteriorating below normal requirements'.

 

Issues specific to non-precision or precision approaches have been addressed in their own bowties 3.2 and 3.3 respectively (e.g. both of these bowties should be considered in conjunction with the generic issues).

International Air Transport Association report

In 2018, the International Air Transport Association (IATA) published their CFIT research and analysis report for the period 2008-2017. They found that the highest frequency of accidents occurred in the approach phase of flight (24 from 47 accidents) and that ‘adverse weather’ was cited as a contributing factor in 51% of CFIT accident reports, ‘poor visibility / IMC’[37] in 46%, and ‘lack of visual reference including darkness and black hole effect’ in 33%. In addition, their report made the following observation about the role of situational awareness:

It is evident that most of the CFIT accidents result from a pilot’s breakdown in situational awareness (SA) instead of aircraft malfunction or a fire. In other words, these accidents are, for the most part, entirely preventable by the pilot. SA refers to the accurate perception by flight crew of the factors and conditions currently affecting the safe operation of the aircraft, and their vertical and/or horizontal position awareness in relation to the ground, water, or obstacles. The data shows that 49 percent of CFIT accidents had vertical, lateral or speed deviations as a contributing factor to CFIT accidents.

Network Aviation bowties

In 2019-2020, the Qantas Group Flight Operations Steering Committee (FOSC) downloaded, reviewed and amended the UK CAA bowties for CFIT 3.1, 3.2 and 3.3. After completing each review, the bowties were amended to ‘QF Group FOSC’ as the author and distributed to the operators within the group. The operators had the software and therefore could customise the bowties to their own operation if required. Network Aviation retained the FOSC copies of CFIT 3.1, 3.2 and 3.3 without amendment.

Following the incident, the ATSB asked the operator if they had a risk assessment relating to flight crews experiencing weather below the landing minima. They did not have a specific risk assessment for this scenario but provided a copy of their CFIT 3.1 with threat 8: Flt [flight] crew operate below the appropriate minimum altitude (exc. instrument approach) leading to the top event of terrain separation deteriorating below normal requirements during arrival or departure with the consequence of CFIT leading to hull loss. They considered this to be the closest risk assessment to the incident under investigation. On review of the CAA CFIT 3.1, it was noted that the original threat 8 was Flt crew continue approach below the MDA/DH without visual reference, with the note Commonly exposed. The remaining 7 threats were unchanged between the CAA bowtie and operator’s bowtie.

The operator’s bowtie preventive controls included Visual reference and Flt crew detect and recognise error via maintaining SA [situational awareness] … In addition, while their threat 8 captured their altimetry procedures as a control, it omitted some of their other existing procedural controls, such as their arrival briefing and approach checklist.

The CAA CFIT 3.1 threat 8 did not use Visual reference or Flt crew detect and recognise error via maintaining SA… as controls. However, situational awareness was used as a control by the CAA for other threats in CFIT 3.1 and in other bowties. This included CFIT 3.2, where Flt crew maintain SA via effective monitoring was included as one of the controls for the threat of Flt crew loss of Situational Awareness (SA) during a NPA [non-precision approach] and was reproduced in the operator’s CFIT 3.2 bowtie.

At interview, the operator acknowledged that they had treated Visual reference as a control, rather than as an aspect of the threat. On consideration of why threat 8 had been changed, they reported that CFIT 3.1 was considered from the arrival perspective – from the top of descent to the relevant lowest safe altitude, followed by a visual approach – and that CFIT 3.2 and 3.3 dealt with threats specific to an instrument approach. However, while the operator’s CFIT 3.2 and 3.3 were amended from the CAA versions, neither of them included the CAA CFIT 3.1 threat 8 of Flt crew continue approach below the MDA/DH without visual reference.

According to the Qantas Group Safety Management System Manual, the risk owner/risk assessment owner/risk register owner was responsible for:

  • ensuring that a comprehensive risk assessment is performed, and the progress and implementation of risk treatment plans is monitored
  • confirming that existing controls are fit for purpose and operating, designed, and periodically monitored.

Therefore, the ATSB queried the operator’s safety assurance, specifically whether the bowtie risk controls were subject to audit as part of their risk management review process. The operator reported that, in the design of their system-based audit of consequences, they utilised the bowtie as an audit tool, so the bowtie controls will be assessed as part of the audit. This was consistent with the ICAO Safety Management Manual, Doc 9859 (2013), which included the following:

The safety assurance process complements that of quality assurance, with each having requirements for analysis, documentation, auditing and management reviews to assure that certain performance criteria are met. While quality assurance typically focuses on the organization’s compliance with regulatory requirements, safety assurance specifically monitors the effectiveness of safety risk controls.

System safety design order of precedence

According to Stolzer et al. (2008), the field of system safety provided a categorisation scheme for evaluating hazard (risk) controls, and that it was important for the safety practitioner to understand this scheme so that appropriate decisions could be made. This scheme was the system safety design order of precedence (also known as the hierarchy of hazard control) and was described in the United States Department of Defence System Safety Standard Practice Manual (MIL-STD-882E)[38] in the following manner:

The goal should always be to eliminate the hazard if possible. When a hazard cannot be eliminated, the associated risk should be reduced to the lowest acceptable level within the constraints of cost, schedule, and performance by applying the system safety design order of precedence. The system safety design order of precedence identifies alternative mitigation approaches and lists them in order of decreasing effectiveness.

From MIL-STD-882E, the system safety design order of precedence was as follows:

  • eliminate hazards through design selection
  • reduce risk through design alteration
  • incorporate engineered features or devices
  • provide warning devices
  • incorporate signage, procedures, training, and personal protective equipment.

The use of humans to monitor, detect and correct problems, are not risk controls within the design order of precedence. Rather, it is the incorporation of controls in accordance with this scheme that shapes the required level of safety and human performance within the system. This is described in the ICAO Human Factors Training Manual, Doc 9683 (1998), as follows:

The control of human error requires two different approaches. First, it is necessary to minimize the occurrence of errors by: ensuring high levels of staff competence; designing controls so that they match human characteristics [reduce risk through design]; providing proper checklists, procedures, manuals, maps, charts, SOPs [procedural controls] … Training programmes aimed at increasing the co-operation and communication between crew members will reduce the number of errors [training controls] ... The second avenue to the control of human error is to reduce the consequences of the remaining errors by cross-monitoring and crew co-operation [procedural and training controls]. Equipment design which makes errors reversible and equipment which can monitor or complement and support human performance also contribute to the limitation of errors or their consequences [engineered features and warning devices].

The description for managing the risk of human error in ICAO Doc 9683 (1998) included design to reduce risk, procedural and training controls, and the incorporation of engineered features and warning devices. A similar approach was employed by IATA (2018) in their CFIT research and analysis report section on mitigation strategies, which targeted the 3 categories of human, procedural and technological. They included the following explanation for the meaning of human‑related mitigation strategies:

The available human mitigations involve improving and maintaining pilots’ knowledge, their awareness and their competence, and each of these can be achieved by a comprehensive training program embracing classroom, simulator and flight training.

Hence, the level of safety and human performance is managed by the design of the system, which is consistent with the approach suggested by Stolzer et al. (2008).

Similar occurrences

A search of the ATSB’s database for the period 2012-2021 for unforecast weather and low fuel events in the air transport high-capacity sector found 114 occurrences, of which 10 involved both events in the same occurrence. For unforecast weather events, this involved 67 occurrences (64 incidents, 2 serious incidents and 1 accident), and low fuel events found 57 occurrences (53 incidents and 4 serious incidents). There were no previous incidents reported for Paraburdoo Airport within this 10-year dataset.

The following is a summary of previous destination weather related occurrences, both in Australia and overseas.

Aircraft Accident Investigation Bureau of India

On 18 August 2015, a Boeing 737-800, departed Doha, Qatar, for Cochin, India. On arrival at Cochin, the weather had deteriorated, and 3 missed approaches were conducted. The fuel reserve fell below the minimum required alternate of Bangalore during the third missed approach and the flight crew redesignated Trivandrum as their alternate. However, the weather conditions deteriorated at Trivandrum when they arrived, and a missed approach was conducted. This was followed by a MAYDAY fuel declaration and a request to attempt a visual approach. Three visual approaches were attempted with a landing made from the third. The fuel on shut down, after 7 approaches, was 349 kg, which was insufficient for any further approaches.

United Kingdom Air Accidents Investigation Branch (1/2016)

On 23 August 2013, a Eurocopter AS332 L2 Super Puma helicopter, collided with water while the flight crew were attempting to gain visual reference after reaching their MDA on approach to Sumburgh Airport, UK. The actual cloud base was lower than the original TAF forecast and the cloud base at their nominated alternate had also deteriorated, which probably would have precluded the flight crew from making a successful approach at their alternate.

ATSB investigation (AO-2013-100)

On 18 June 2013, 2 Boeing 737 aircraft were on scheduled flights to Adelaide, South Australia. On nearing Adelaide, the forecast improvement in weather conditions had not occurred and as a result, both aircraft diverted to Mildura, Victoria. Upon arrival at Mildura, the actual weather conditions were significantly different to those forecast, with visibility reduced in fog. The flight crew of the first aircraft conducted an instrument approach and landed below the minima. The flight crew of the second aircraft also conducted an instrument approach and landed below the minima in fog with fuel below the fixed reserve.

ATSB investigation (AO-2009-072)

On 18 November 2009, an Israel Aircraft Industries Westwind 1124A aircraft was operated on an air ambulance flight from Apia, Samoa to Norfolk Island, Australia. When the flight was planned, the aerodrome forecast for Norfolk Island indicated the weather conditions at the time of arrival would be above the alternate minima. However, on arrival at Norfolk Island, there was low cloud and the aircraft had insufficient fuel to divert to another airport. After 4 unsuccessful approaches, the flight crew ditched the aircraft 6.4 km west-south-west of the airport.

National Transportation Safety Board (AAR-91/04)

On 25 January 1990, a Boeing 707 flight from Bogota, Columbia, to New York, United States, was placed in a holding pattern 3 times due to poor weather conditions in the north‑eastern part of the United States for a duration of about 1 hour and 17 minutes. During the third period of holding, the flight crew reported they could not hold longer than 5 minutes, that they were running out of fuel, and could not reach their alternate airport. Subsequently, they executed a missed approach and then lost power to all engines due to fuel starvation and collided with terrain while attempting a second approach.

Safety analysis

Introduction

On the morning of 22 November 2021, a Network Aviation Fokker Aircraft F100, registered VH‑NHV and operating as flight QF1616, departed Perth Airport on a scheduled passenger service to Paraburdoo Airport, Western Australia. On arrival at Paraburdoo, the flight crew conducted 3 missed approaches due to unforecast low cloud. On the fourth approach, the flight crew continued the approach below the landing minima without visual reference to the runway due to the aircraft’s fuel state.

This analysis will discuss the flight crew’s decision not to divert, the eventual landing below minima, and the reason for the unforecast low cloud. The delay in an air traffic control weather update, and limitations associated with in-flight access to weather while holding at Paraburdoo and weather forecasting at the airport, will also be discussed. It will also consider the operator’s procedural guidance and risk management for unforecast weather.

Decision not to divert

After downloading and reviewing their flight plan before take-off, the flight crew noted they had a 60-minute holding fuel requirement for Paraburdoo. However, both the mean and holding weather conditions indicated the lowest cloud was forecast to be above their landing minima. Therefore, they departed Perth with the expectation of landing from their first approach. This expectation was likely reinforced by the automatic weather information service (AWIS) broadcast prior to top of descent, which indicated the lowest cloud was 2,100 ft above the airport. Consequently, their first missed approach at Paraburdoo was unexpected.

The 0730 AWIS update during the descent indicated that low cloud had started to develop at 500 ft above the aerodrome, which was below their landing minima. However, the concurrent air traffic broadcasts on the other radio may have interfered with the flight crew hearing this information as the captain reported that the QNH was the only change noted. Since an accurate QNH must be obtained within 15 minutes of commencing an approach for the minima to be reduced by 100 ft, it was likely that this was their reason for listening to the AWIS during the descent.

When they conducted their first approach, the flight crew momentarily became visual with the runway but realised they would have been too steep to attempt the landing. However, the combination of the visual contact and tailwind on the first approach, provided them with confidence that a second approach to the opposite runway would be successful. Further, the cloud they encountered on the first approach was lower than forecast, which suggested to them that the first approach was likely flown in the worst of the expected conditions. They did not consider at this stage that the conditions might worsen. Therefore, they elected to immediately conduct a second approach, which was also unsuccessful due to low cloud obscuring the runway.

It was after the second missed approach that the flight crew realised the weather was more concerning than expected. At this stage, the deterioration in the actual conditions at Paraburdoo likely resulted in them losing confidence in their flight plan weather forecasts for decision-making purposes.

The weather reports for the airports under consideration for diversion by the flight crew indicated that Karratha Airport was the only suitable diversion. After the second missed approach, the flight management computer (FMC) indicated they were at minimum fuel to divert to Karratha, but the captain was cognisant that this did not allow for the winds they might experience or for an instrument approach on arrival at Karratha if required. In this case, they could not determine if they could reach Karratha with their fixed fuel reserve remaining. Consequently, without knowledge of the actual weather conditions, they elected to disregard Karratha as an option.

Instead, the flight crew requested a weather update for Newman Airport since it was closer, and another aircraft had landed there recently. However, the captain was aware the forecast had a holding requirement and was reluctant to commit to a diversion unless the actual conditions were better than forecast. Solomon Airport was also considered after the third missed approach but was disregarded due to having a higher landing minima than Paraburdoo.

Therefore, as they were still within their 60-minute holding fuel period and did not have immediate access to actual improved weather conditions elsewhere, the flight crew elected to conduct further approaches at Paraburdoo.

Landing below minima

The ATSB’s review of their estimated fuel load found that the flight crew likely had sufficient fuel to divert to Karratha or Newman immediately after their second missed approach, but not after their third missed approach. According to the forecasts and actual conditions, Karratha was suitable, but Newman was not, and an immediate decision was required to divert to Karratha. However, it was only after the second missed approach that the flight crew started to discuss diversion options and the fuel consumption during this period consequently precluded Karratha as an option.

After their third missed approach, a diversion to Solomon was their only other option. However, as the lowest landing minima at Solomon was higher than at Paraburdoo, they disregarded it. At the time, the cloud base at Solomon was below the minima and therefore it would not have been a suitable diversion if the flight crew had received the latest actual weather. Consequently, the flight crew were committed to conducting a fourth approach at Paraburdoo.

Before they commenced their fourth approach the flight crew briefed their plan and duties, and their contingency plan if the approach became unsafe. They subsequently descended below the runway 24 MDA of 584 ft above aerodrome level without visual reference on the approach. On achieving their visual reference at about 293 ft, the aircraft was stable on the glidepath and close to the extended runway centreline, which enabled them to land without further incident, 57 minutes after their first missed approach.

Cloud base

On the night prior to the incident flight, there were no meteorological observations from the Pilbara region of persistent low cloud. In addition, there was a layer of mid-level cloud overnight that should have limited the overnight surface cooling and had also obscured satellite imagery of any low-level cloud. Therefore, the presence of scattered cloud at 1,000 ft above aerodrome level at the surrounding aerodromes at 0200 was used as the justification for forecasting mean conditions at Paraburdoo of scattered cloud at 1,000 ft, with TEMPO conditions for broken cloud at 1,000 ft. This was above the flight crew’s landing minima for runway 06 and 24 of 604 ft and 684 ft respectively.

There was also an expectation that surface heating would lift the cloud base after sunrise. However, the lifting trend in the modelling did not occur and the cloud base lowered, remaining below the highest alternate minima from 0730 for 3 hours 26 minutes.

Distinct from the forecast conditions, at 0730, 16 minutes before the first missed approach, scattered cloud at 500 ft was reported by the automatic weather station (AWS). This deteriorated to broken cloud at 400 ft before the last approach. The AWS was still reporting broken cloud at 400 ft at 0900, 17 minutes after the aircraft landed. This deterioration was consistent with the flight crew’s observations that they experienced low cloud at the approach minima for all 4 approaches, and broadcast after landing that patches of low cloud were present at 250-300 ft.

It was likely that evaporation of rainfall added moisture to the atmosphere (wet bulb effect), as indicated by a reduction in the reported visibility from greater than 10 km at 0730 to 6,000 m at 0751. While the surface wind had not yet backed around to the west, the tailwind component reported by the flight crew on their first approach to runway 06 suggested the winds above the surface already had a westerly component. Airflow from the west is forced to rise over the terrain to the west of the airport and will cool, which results in the development of low cloud if the air becomes saturated (orographic uplift). Therefore, the low cloud that developed below the forecast conditions, was likely a combination of moistening of the airmass from rainfall and orographic uplift from the local terrain.

These conditions were considered difficult to forecast due to the absence of low cloud observed on the evening prior, any low-level cloud being obscured on the satellite imagery, and the lifting trend in the modelling not occurring. This discrepancy between the forecast and actual conditions resulted in the flight crew losing confidence in their flight plan aerodrome forecasts for diversion decision-making purposes, and initially misled them to believe that conditions would not deteriorate further after their first missed approach.

In-flight access to weather information

A decision to divert is a procedure-based decision-making exercise, which is also known as rule‑based decision-making. This is dependent on the situational awareness or knowledge of the problem, and knowledge of options (Flin, O’Connor, Crichton, 2008). When the flight departed Perth, the flight crew had incorrect knowledge of the weather situation that would unfold at Paraburdoo when they arrived. Although they passed within range of the Meekatharra automatic en route information service (AERIS), which would have provided them with the current weather for Karratha, there was no operational need for it at that stage, based on their assessment of the forecast conditions.

After the second missed approach, the flight crew’s discussions and actions indicated they had updated their assessment of the situation and were now actively seeking additional information about the weather conditions. This included the Paraburdoo AWIS (which was checked before each approach), air traffic control, and the Paraburdoo safety car officer. At this stage, they were holding at about 4,100 ft, which meant they were out of range of the Meekatharra AERIS, which required an altitude of about 36,500 ft to receive the broadcast.

The aircraft was fitted with the hardware for the aircraft communications addressing and reporting system (ACARS), which could be used to immediately access current weather information. However, the system was not operational, and therefore could not be used. If the system had been operative, they would have required a satellite link to use it, as they were holding below the required altitude of at least 11,000 ft to receive information from the nearest VHF datalink service at Newman. Therefore, with no other means to obtain current weather information while holding at Paraburdoo, the flight crew were reliant on air traffic control (ATC) to access weather information for alternate aerodromes.

If the flight crew had access to updated weather information using the AERIS or ACARS, it would have informed them that the cloud base was above 10,000 ft and visibility was greater than 10 km at Karratha. This would have indicated that Karratha was a suitable diversion location. However, without current weather information for alternative aerodromes, the flight crew elected to remain at Paraburdoo.

Atmospheric data

During the incident, a rain band and associated middle and high-level cloud was observed across north-western Australia by the Bureau of Meteorology (BoM). Their model traces had indicated saturated levels through to near to the surface. However, modelling in northern Australia was subject to false alarms for widespread low cloud. Therefore, some form of surface verification and/or satellite observations were required for the BoM to have confidence in the modelling. On the night prior to the incident, mid-level cloud made it difficult to utilise satellite observations to observe low cloud and confirm the modelling.

Light rain or drizzle had been falling at Paraburdoo. However, the extent of the rain was uncertain as Paraburdoo was outside the optimal range for the nearest weather radar stations. Therefore, it appeared clear on their weather radars at the time of the incident, despite the presence of low cloud and rain.

According to the BoM, the depth of moisture through the atmosphere is important in determining the potential for low cloud development. The sources available to indicate the depth of moisture are weather balloons and aircraft meteorological data relay (AMDAR). Data obtained from weather balloons allow forecasters to plot an aerological diagram and forecast cloud bases and tops. However, the nearest weather balloon stations were more than 160 NM from Paraburdoo and may not necessarily be representative of the conditions experienced at Paraburdoo. Furthermore, as Paraburdoo was not part of the AMDAR network, no AMDAR profiles were available to support the BoM forecasts for Paraburdoo.  

The accuracy of forecasting is dependent on the data available. As Paraburdoo did not have the means to provide forecasters with a vertical profile of the moisture through the atmosphere, and satellite imagery was not available due to being obscured by mid-level cloud, the forecast was dependent on observations at other airports in the region. Therefore, the lack of atmospheric measurements increased the risk of an inaccurate projection of the conditions for Paraburdoo including unforecast low cloud below the instrument approach landing minima. While the current BoM plans for upgrading weather balloon and weather radar stations around Australia do not include Paraburdoo Airport, the ATSB did not identify a trend from the last 10-years of data associated with this airport to warrant a safety issue at this stage.

Diversion procedure

The forecast conditions for Paraburdoo required 60 minutes TEMPO holding fuel, but no alternate was required. Despite this, the flight crew were expecting to obtain visual reference with the runway before reaching their minimum descent altitude for the approach. This expectation was likely reinforced by the AWIS recording before top of descent, which indicated the lowest cloud base was 2,100 ft above the aerodrome. However, on arrival, the flight crew were confronted with 2 unforecast weather hazards. The cloud base had deteriorated below their landing minima, and it did not lift within the 60-minute TEMPO period.

As discussed previously, a diversion is a procedural decision-making exercise, which requires knowledge of both the problem and the options available (Flin, O’Connor, Crichton, 2008). Therefore, a diversion decision-making procedure should serve the purposes of guiding the flight crew to correctly assess the problem and then select an appropriate course of action.

The operator had published a procedure, which limited the number of missed approaches to 2, but they did not believe a prescriptive decision-making procedure was necessary. However, even after the first missed approach, the flight crew were expecting to land from their second approach and there was no discussion of the limits to conducting missed approaches nor consideration of their fuel reserve for a diversion.

After the second missed approach, the flight crew only had a few minutes in which to decide to divert to Karratha, which was the nearest suitable alternate airport. However, they had not briefed this option. Therefore, instead of committing to a diversion after the second missed approach, they entered a holding pattern and started to diagnose the actual weather conditions and their options.

The operator’s limit to missed approaches did not provide guidance for flight crew to brief their divert options before arrival or on encountering unforecast weather at their destination. The arrival briefing procedural guidance from the International Civil Aviation Organization (Doc 8168, 2018) included ‘alternate aerodromes and fuel considerations’, and while this was within the context of ‘relevant conditions’, unforecast weather is a hazard frequently reported to the ATSB and that has been the subject of previous accident and incident investigations. In this case, if the flight crew had briefed their divert options before arrival, they would have been better placed to manage the unforecast weather conditions they encountered at Paraburdoo. Therefore, a diversion procedure should be considered within an organisation’s risk controls and the absence of this decision‑making guidance increased the risk that flight crew would not be prepared for a diversion.

Risk management

The 3 United Kingdom Civil Aviation Authority’s (CAA) bowtie risk assessments for controlled flight into terrain (CFIT) were largely retained by the Qantas Group Flight Operations Steering Committee (FOSC) and subsequently Network Aviation, with minor amendments. One of the notable amendments was the replacement of the CAA CFIT 3.1 threat 8: Flt crew continue approach below the MDA/DH without visual reference with the FOSC CFIT 3.1 threat 8: Flt crew operate below the appropriate minimum altitude (exc. instrument approach). This was considered by the operator to be the closest risk assessment to the incident.

It was also noted that the operator’s CFIT 3.2 and 3.3 risk assessments for instrument approaches had not captured CAA CFIT 3.1 threat 8. Consequently, there were no weather-related threats identified in the operator’s CFIT bowties. In which case, there was no requirement to identify controls or treatment plans to manage these threats, despite a recent CFIT research and analysis report finding that adverse weather was cited as a contributing factor in 51% of accidents (IATA, 2018).

The operator’s CFIT threats relied on preventive risk controls such as visual reference and human performance for monitoring, detecting and correcting problems to maintain situational awareness. While the latter appeared to be inherited from the UK CAA bowties, research conducted by the International Air Transport Association indicated that operating in adverse weather conditions, poor visibility, and a lack of visual reference were considered contributing factors or threats to CFIT rather than risk controls. It was also noted that other procedural controls were used by the operator, but not included in the bowtie risk assessment. These included their arrival briefing and approach checklist, which, according to International Civil Aviation Organization (ICAO) Doc 8168 (2018), are designed to enhance situational awareness and therefore reduce the likelihood of an unintentional descent below the minimum altitude.

A reliance on human performance as a control to monitor, detect and correct problems within a risk assessment can result in an inherently unsafe system. If there is a human performance safety requirement associated with a specific threat, then this should be managed with the appropriate controls, such as training, procedures, and warning devices, as indicated by the International Air Transport Association CFIT mitigation strategies (2018) and ICAO (Doc 9683, 1998). They would then be subject to the safety assurance activities for that risk assessment.

The key environmental threat from this investigation that operators and flight crew need to manage is unforecast instrument meteorological conditions below minima at the destination. While forecast weather below minima is routinely effectively managed with a prescriptive ruleset, unforecast weather may be more likely to result in the need for an approach below minima without visual reference due to the development of a fuel-critical situation. Therefore, the absence of this threat from the operator’s CFIT risk assessment increased the risk that controls required to manage this threat would not be developed, monitored, and reviewed at a management level.

Weather update delay

Although the flight crew were aware that Newman had similar conditions to the Paraburdoo forecast, including a 60-minute holding fuel requirement, another aircraft had landed there between QF1616’s first and second missed approaches. This suggested to the flight crew that Newman might be a suitable diversion. As such, the captain informed ATC that they had conducted a second missed approach due low cloud at Paraburdoo and requested the latest weather for Newman. However, there was no urgency associated with this request and ATC asked them to standby for a response. Following this request, the flight crew and ATC diverted their attention to their other tasks, which included traffic inbound to Paraburdoo.

There was a delay of about 15 minutes before ATC queried if the flight crew still required the weather for Newman. At this stage, they had conducted a third missed approach and were likely below the minimum fuel required to divert to Newman, therefore the captain declined. While this delay precluded the flight crew considering the option of a diversion to Newman, both the cloud and weather data groups for Newman were not available for the period from 0600-1000. Without a meteorological observer at Newman, the latest METAR was the only current weather ATC could have provided the flight crew. In addition, the captain was reluctant to divert to another airport that had a holding fuel requirement they could not meet and might be subject to a similar weather pattern as Paraburdoo, unless the actual weather was better than forecast. As the current METAR did not provide an improvement to the forecast, it was unlikely that the provision of the latest weather information would have influenced the flight crew to divert to Newman and the delay was not considered contributory to the incident.

Despite this, ATC was the only option for the flight crew to obtain current weather for an alternate airport and the report of missed approaches at Paraburdoo associated with the request for the latest weather for Newman suggested this was likely a time-critical request. While the flight crew were within their TEMPO fuel holding period at Paraburdoo, they were approaching a fuel critical situation for a diversion to Newman. In this scenario, the inclusion of ‘minimum fuel’ with their request for the latest Newman weather could have reduced the likelihood of a delay, but probably would not have changed the outcome.

Newman automatic weather information service

The Airservices Australia new filtering system for SPECI reports was dependent on the conditions that trigger such reports being detected at the aerodrome. On the morning of the incident flight, there were 11 weather reports issued from the Newman AWS from 0600-1000. This included 2 SPECI reports for a reduction and subsequent improvement in visibility at 0934 and 0944. However, the cloud and weather data groups were not available throughout this period, which meant that Newman could have entered SPECI conditions undetected during this period.

As there was a delay in the information and the captain subsequently declined the weather update for Newman, this did not influence their decision to remain at Paraburdoo. However, if a SPECI condition is not detected at the source by an AWS, unforecast weather conditions may not be captured and disseminated by ATC to airborne aircraft as a hazard. While this is not a substitute for flight planning and in-flight weather update requests before reaching a point-of-no-return, the broadcast of unforecast SPECI conditions may provide a timely alert to flight crew to avoid a fuel-critical situation developing.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the unforecast weather and flight below minimum altitude involving Fokker Aircraft F100, registration VH-NHV, at Paraburdoo Airport, Western Australia, on 22 November 2021.

Contributing factors

  • The flight crew lost confidence in their flight plan weather forecasts after two missed approaches at Paraburdoo Airport. Without immediate access to actual weather information, they elected to conduct further approaches instead of diverting.
  • After the third missed approach, the flight crew had insufficient fuel to divert to a suitable airport and were committed to landing in conditions below their landing minima due to the continuing deteriorating cloud base.
  • The actual weather conditions encountered by the flight crew on arrival at Paraburdoo Airport were worse than the flight plan forecast, below the landing minima and deteriorating. This event was difficult to forecast accurately due to the lack of observed lower cloud, satellite imagery and meteorological modelling limitations.
  • The aircraft was not fitted with an operational aircraft communications addressing and reporting system (ACARS) and was out of range of the Meekatharra automatic en route information service (AERIS) while holding at Paraburdoo Airport. Therefore, the flight crew were reliant on air traffic control to access actual weather information for alternate aerodromes.
  • Paraburdoo Airport did not have a means of detecting the moisture content in the atmosphere above the surface. This increased the risk that low cloud below the instrument approach landing minima might not be forecast.
  • Network Aviation did not provide their flight crew with a diversion decision-making procedure for the circumstances where their flights encountered unforecast weather below landing minima. This increased the risk that their flight crew would not anticipate and be adequately prepared for a diversion. (Safety issue)
  • Network Aviation did not include the threat of unforecast weather below landing minima in their controlled flight into terrain risk assessments. This increased the risk that controls required to manage this threat would not be developed, monitored, and reviewed at a management level. (Safety issue)

Other factors that increased risk

  • The flight crew did not convey a sense of urgency to air traffic control when they requested the actual weather information for Newman Airport. This, combined with the controller's workload at the time, resulted in a delay of about 15 minutes before the information was offered. However, Newman Airport had a holding fuel requirement the flight could not comply with and as the actual weather did not include an improvement of conditions it was unlikely that this information would have influenced their decision to divert.
  • The Newman Airport automatic weather station cloud and weather data groups were not available at the time the flight crew requested the latest weather from air traffic control. While this did not influence the flight crew’s decision to remain at Paraburdoo, it increased the risk that a deterioration in the cloud base below the forecast conditions at Newman would not be broadcast by air traffic control to airborne aircraft as a hazard.

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out or are planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Diversion procedure

Safety issue number: AO-2021-048-SI-01

Safety issue description: Network Aviation did not provide their flight crew with a diversion decision-making procedure for the circumstances where their flights encountered unforecast weather below landing minima. This increased the risk that their flight crew would not anticipate and be adequately prepared for a diversion.

Risk management

Safety issue number: AO-2021-048-SI-02

Safety issue description: Network Aviation did not include the threat of unforecast weather below landing minima in their controlled flight into terrain risk assessments. This increased the risk that controls required to manage this threat would not be developed, monitored, and reviewed at a management level.

Safety action not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Additional safety action by Network Aviation

Internal safety advisory notice

Network Aviation issued an updated internal safety advisory notice to their flight crew, which highlighted the operating parameters and limitations associated with automatic weather information services (AWIS).

Airport risk assessment

Network Aviation updated their Paraburdoo Airport risk assessment to capture the risk of variable weather conditions and the procedural risk controls introduced in response to this incident.

Company fuel policy

Network Aviation amended their company fuel policy to mandate additional alternate fuel requirements for nominated airports (operator approved variations). Airport classification is assessed based on alternate availability, instrument approach availability, aerodrome forecast reporting and historical accuracy, local mesoscale weather phenomena, and topography/terrain.

Access to expanded port briefings

Network Aviation established access for flight crew to obtain expanded briefings on ports (with operator fuel policy approved variations) from internal company meteorologists.

Update to the Aerodrome and Route Manual

Network Aviation updated the company’s Aerodrome and Route Data Manual to provide a new section on weather planning tools and resources, and a new section explaining the limitations of ceilometers and visibility meters installed in automatic weather information stations throughout the company network.

Enhanced training reference library

Network Aviation enhanced the company’s training reference library for flight crew to support pilot knowledge and decision making. Additional content in the library is focused on company learnings from QF1616, which includes:

  • fuel management
  • threat management and contingency planning
  • time management in areas of vulnerability
  • pilot in command responsibilities.
Update to take-off and landing data cards

Network Aviation have updated their take-off and landing data cards to provide a dedicated section for recording the alternate aerodrome, estimated time interval, fuel burn and fuel on arrival.

Glossary

AAL                  Above aerodrome level

ACARS             Aircraft communications addressing and reporting system

AIP                   Aviation information publication

AMDAR            Aircraft meteorological data relay

ATC                  Air traffic control

AWIS                Automatic weather information service

AWS                 Automatic weather station

BoM                 Bureau of Meteorology

CAA                 Civil Aviation Authority (UK)

CFIT                 Controlled flight into terrain

DH                   Decision height

FL                    Flight level

FMC                 Flight management computer

FMS                 Flight management system

FO                    First officer

GNSS               Global navigation satellite system

IATA                 International Air Transport Association

ICAO                International Civil Aviation Organization

LNAV                Lateral navigation

MDA                 Minimum descent altitude

METAR             Meteorological aerodrome report

PAPI                 Precision approach path indicator

PF                    Pilot flying

PM                   Pilot monitoring

RNAV               Area navigation

SA                    Situational awareness

SPECI              Special meteorological aerodrome report

TAF                  Aerodrome forecast

UK                    United Kingdom

VHF                  Very high frequency (radio frequency in the range 30-300 MHz)

VNAV               Vertical navigation

YMEK               Meekatharra Airport

YNWN              Newman Airport

YPBO               Paraburdoo Airport

YPKA               Karratha Airport

YSOL               Solomon Airport

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Aerodrome Management Services
  • the Bureau of Meteorology
  • Civil Aviation Safety Authority
  • data from the cockpit voice recorder and flight data recorder
  • the flight crew
  • Network Aviation management personnel:
    • chief pilot
    • manager fleet technical
    • safety manager
    • manager fleet safety and regulatory compliance.

References

Air Accidents Investigation Branch (United Kingdom) (2016) Report on the accident to AS332 L2 Super Puma helicopter, G-WNSB on approach to Sumburgh Airport on 23 August 2013 (AAR 1/2016). Retrieved from https://www.gov.uk/aaib-reports/aircraft-accident-report-aar-1-2016-g-wnsb-23-august-2013

Aircraft Accident Investigation Bureau (India) (2016) Final report on serious incident to M/s Jet Airways Boeing 737-800W aircraft VT-JFA at Cochin on 18/08/2015. Retrieved from https://skybrary.aero/bookshelf/final-report-b738-vt-jfa-vicinity-trivandrum-india-18-aug-2015

Australian Transport Safety Bureau (2017) Fuel planning event, weather-related event and ditching involving Israel Aircraft Industries Westwind 1124A, VH-NGA, 6.4 km WSW of Norfolk Island Airport on 18 November 2009 (AO-2009-072 reopened). Retrieved from /publications/investigation_reports/2009/aair/ao-2009-072

Australian Transport Safety Bureau (2016) Landing below minima due to fog involving Boeing 737s, VH-YIR and VH-VYK, Mildura Airport, Victoria on 18 June 2013 (AO-2013-100). Retrieved from /publications/investigation_reports/2013/aair/ao-2013-100  

Civil Aviation Safety Authority (2015) Extended Diversion Time Operations (EDTO) (Civil Aviation Advisory Publication 82-1(1), January 2015, Canberra.

CGE Risk Management Solutions B.V. (2019) Bowtie software user manual revision 39. Retrieved from https://bowtierisksolutions.com.au/wp-content/uploads/2019/08/BowTieXP-User-Manual-V9.2-Rev-39.pdf

Flin R, O’Connor P and Crichton M (2008) Safety at the sharp end: a guide to non-technical skills, Ashgate, Farnham.

International Air Transport Association (2018) Controlled flight into terrain accident analysis report, 2018 edition. Retrieved from https://www.iata.org/contentassets/06377898f60c46028a4dd38f13f979ad/cfit-report.pdf  

International Civil Aviation Organization (2018) Aircraft Operations (Doc 8168): Volume 3 – Aircraft Operating Procedures (1st ed). ICAO, Montreal.

International Civil Aviation Organization (2013) Safety Management Manual (Doc 9859) (3rd ed). ICAO, Montreal.

International Civil Aviation Organization (1998) Human factors training manual (Doc 9683-AN/950) (1st ed). ICAO, Montreal.

National Transportation Safety Board (1991) Aircraft accident report: Avianca, the airline of Columbia Boeing 707-321B, HK 2016 fuel exhaustion Cove Neck, New York January 25, 1990 (AAR-91/04). Retrieved from https://www.ntsb.gov/investigations/accidentreports/reports/aar9104.pdf

Stolzer AJ, Halford CD and Goglia JJ (2008) Safety management systems in aviation, Ashgate, Aldershot.

United States Department of Defence (2012) System safety standard practice (MIL-STD-882E), United States Department of Defence, Washington DC.

World Meteorological Organization (2017) Guide to aircraft-based observations (WMO-No. 1200), World Meteorological Organization, Geneva.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • flight crew
  • Network Aviation management personnel
  • Civil Aviation Safety Authority
  • Bureau of Meteorology
  • Airservices Australia
  • Air Accidents Investigation Branch (United Kingdom).

Submissions were received from:

  • the United Kingdom Air Accidents Investigation Branch
  • Airservices Australia
  • Civil Aviation Safety Authority
  • Bureau of Meteorology
  • Network Aviation Management.

The submissions were reviewed and, where considered appropriate, the text of the draft report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2023

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1]     Western Standard Time (WST): Coordinated Universal Time (UTC) + 8 hours.

[2]     Minimum descent altitude (MDA) is the minimum altitude for a non-precision approach to obtain visual reference and decision altitude (DA) is the altitude at which a missed approach must be commenced from a precision approach if visual reference is not obtained.

[3]     Aerodrome forecast (TAF): a statement of meteorological conditions expected for a specific period of time in the airspace within a radius of 5 NM (9 km) of the aerodrome reference point.

[4]     Cloud cover is reported using words that denote the extent of the cover – ‘few’ indicates that up to a quarter of the sky is covered, ‘scattered’ indicates that cloud is covering between a quarter and a half of the sky, ‘broken’ indicates that more than half to almost all the sky is covered, and ‘overcast’ indicates that all the sky is covered.

[5]     Cloud data is height above aerodrome elevation.

[6]     TEMPO: a temporary deterioration in the forecast weather conditions, during which significant variation in prevailing conditions are expected to last for periods of between 30 and 60 minutes.

[7]     Landing minima: specified meteorological conditions of cloud ceiling and visibility. For an aircraft to land at an aerodrome, the actual weather conditions need to be at or above the landing minima.

[8]     INTER: an intermittent deterioration in the forecast weather conditions, during which a significant variation in prevailing conditions is expected to last for periods of less than 30 minutes duration.

[9]     Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 350 equates to 35,000 ft.

[10]    Pilot Flying (PF) and Pilot Monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.

[11]    Automated weather information service (AWIS): actual weather conditions, provided via telephone or radio broadcast, from Bureau of Meteorology (BoM) automatic weather stations, or weather stations approved for that purpose by the BoM.

[12]    QNH: the altimeter barometric pressure subscale setting used to indicate the height above mean seal level.

[13]    Dewpoint: the temperature at which water vapour in the air starts to condense as the air cools. It is used, among other things, to monitor the risk of aircraft carburettor icing or the likelihood of fog.

[14]    On the cockpit voice recorder, most of the broadcast was inaudible due to traffic on the ATC frequency, except for the wind 040° at 4 kt and QNH 1013.

[15]    A QNH obtained from an approved source within 15 minutes of conducting an instrument approach may be used to lower the MDA by 100 ft if the procedure is in a grey shaded box. Network Aviation standard operating procedures require their flight crew to fly a continuous descent profile for non-precision approaches and add 50 ft to the MDA.

[16]    Due to the Melbourne Centre flight information area frequency volume, some of the flight crew discussions and automated weather information service broadcasts during the flight were inaudible due to concurrent radio traffic on the Melbourne Centre frequency.

[17]    Pilot activated runway and taxiway lighting (PAL): PAL is activated by a series of timed transmissions using the aircraft’s very high frequency radio on a designated frequency.

[18]    Precision Approach Path Indicator (PAPI): a ground-based system that uses a system of coloured lights used by pilots to identify the correct glide path to the runway when conducting a visual approach.

[19]    In accordance with the Network Aviation Flight Administration Manual standard operating procedure 8.50: Automatic flight shall be used when possible for all instrument approaches when Instrument Meteorological Conditions (IMC) exist. Vertical speed mode (vertical navigation) and NAV mode (lateral navigation) were used for all approaches as per company recommendation for an RNAV approach.

[20]    The operations normal call time provided the next expected transmission time from this aircraft to indicate operations were normal.

[21]    QF1618 flight plan fuel load had 1,694 kg more than QF1616.

[22]    MAYDAY: an internationally recognised radio call announcing a distress condition where an aircraft or its occupants are being threatened by serious and/or imminent danger and the flight crew require immediate assistance.

[23]    The ground proximity warning system is intended to alert the flight crew to a situation that could lead to ground contact and to warn of impending ground contact. During the incident flight, the system provided callouts to the flight crew on each approach, commencing from 2,500 ft above ground level.

[24]    The aircraft’s flight data recorder did not record either fuel flow or fuel load parameters. Therefore, the flight data could not be used to analyse this information, which was the critical parameter for the flight crew in this incident.

[25]    Tanker fuel is extra fuel uplifted from airports with a lower fuel price, such as capital city airports.

[26]    Required navigation performance (RNP) levels refer to the performance required from the navigation system. RNP 0.3 means the aircraft navigation system must be able to calculate its position to within a circle with a radius 0.3 NM.

[27]    The temperature to which air must be cooled, at constant pressure and water vapour content, in order for saturation to occur. If the air is cooled further, some of the water vapour will condense to liquid.

[28]    The light pulse is scattered by aerosols including water droplets (clouds), and the component of light scattered back towards the ceilometer is measured.

[29]    When operating instrument flight rules, the instrument approach chart will show the ceiling (cloud base height) and visibility minima to be compared with the meteorological forecasts and reports to determine both the need to provide for an alternate aerodrome and the suitability of that aerodrome as an alternate (ENR 1.5 section. 6: Alternate weather minima).

[30]    The optimal range is generally within 110 NM of the weather radar station, terrain dependent, to capture rainfall echoes from clouds about 10,000 ft above mean sea level.

[31]    Precipitation: Any product of the condensation of atmospheric water vapour that falls under gravity.

[32]    Dewpoint depression: The difference between the temperature and dewpoint temperature at certain height in the atmosphere.

[33]    A principal cloud type, forming in the low levels of the troposphere (the lowest layer of the atmosphere) and normally existing as a flat layer that does not exhibit individual elements.

[34]    Calculations are based on nil wind from the start of the take-off roll with anti-icing on.

[35]    A diversion decision-making procedure is a requirement for extended diversion time operations, but this was not applicable to the operator’s F100 fleet. Refer Civil Aviation Advisory Publication 82-1(1): Extended Diversion Time Operations (EDTO); ‘6.6.1 The operator’s operations manual must establish procedures for flight crew outlining the criteria that indicate when a diversion or change of routing is recommended whilst conducting an EDTO’.

[36]    On 2 December 2021, 10 days after the incident, the new Civil Aviation Safety Regulations flight operations regulations commenced. This required all Part 121 operations to plan at least one destination alternate aerodrome when the relevant forecast weather was: less than 1,000 ft above the landing minima determined by the operator under regulation 121.185, or when the forecast visibility was less than the greater of 5km, or the landing visibility determined by the operator under regulation 121.185 plus 2 km.

[37]    Instrument meteorological conditions (IMC): weather conditions that require pilots to fly primarily by reference to instruments, and therefore under instrument flight rules (IFR), rather than by outside visual reference. Typically, this means flying in cloud or limited visibility.

[38]    While MIL-STD-882E, dated 2012, was the current version at the time of this incident, the original version was issued in 1969.

Occurrence summary

Investigation number AO-2021-048
Occurrence date 22/11/2021
Location Paraburdoo Airport
State Western Australia
Report release date 24/03/2023
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Unforecast weather
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Fokker B.V.
Model F28 MK 0100
Registration VH-NHV
Serial number 11482
Aircraft operator NETWORK AVIATION PTY LTD
Sector Jet
Operation type Air Transport High Capacity
Departure point Perth Airport, Western Australia
Destination Paraburdoo Airport, Western Australia
Damage Nil

Collision with terrain involving Kavanagh E-240 Balloon, VH-LUD, near Yamanto, Queensland, on 8 October 2021

Final report

Report release date: 01/11/2022

Executive summary

What happened

On 8 October 2021, a Kavanagh Balloons E-240 balloon, registered VH-LUD and operated by Floating Images Aust. Pty Ltd was conducting a morning scenic flight about 45 km south‑west of Brisbane, Queensland. On board was a pilot and 9 passengers. About 55 minutes into the flight, the pilot commenced a descent to locate a suitable landing area. During the descent, the balloon entered an area of localised fog where visibility reduced to 10 m.

The pilot continued the descent into the fog until a tree was observed in the path of the balloon. The pilot attempted to avoid the tree by initiating a climb, but the balloon collided with, and came to rest on the side of the tree, damaging the lower part of the balloon envelope. The pilot subsequently climbed the balloon off the tree and above the fog. The flight continued to an uneventful landing in a nearby paddock that was clear of fog. There were no injuries.

What the ATSB found

The ATSB found that, contrary to the visual flight rules visibility requirement, the pilot entered an area of reduced visibility in which the visibility was 10 m. This did not allow sufficient time to complete an avoidance manoeuvre when an obstacle was observed, as a result the balloon collided with a tree and the balloon envelope was damaged.

Safety message

In some circumstances, balloons are permitted to fly in significantly lower visibility than other types of aircraft. While this is mainly due to their inherently low flight speed, it also considerably reduces the available time to see obstacles. Additionally, as balloons can only manoeuvre vertically and significant time may be required to transition from a descent to a climb, they have limited capability to avoid obstacles.

Therefore, to reduce the collision risk if a balloon enters an area of visibility less than that permitted by the visual flight rules, pilots should ensure that an immediate recovery is commenced.

 

The investigation

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

On 8 October 2021, the pilot of a Kavanagh Balloons E-240 balloon, registered VH-LUD, was preparing for a morning scenic charter flight for 9 passengers from a location 45 km south‑west of Brisbane, Queensland. The pilot reported releasing a small helium balloon from the Ipswich Visitor Information Centre, located about 6 km to the east of RAAF Base Amberley (Figure 1), at 0425 Eastern Standard Time,[1] to observe wind speed and direction. The pilot also checked the wind observations recorded at the nearby RAAF Base, which were variable[2] at 3 knots.

Following an assessment, via the observation balloon, that the wind was from the west‑north‑west, the pilot planned the flight to commence at Rosewood Golf Club with an intent to track south-east, to the south of RAAF Base Amberley, and continue towards Yamanto (Figure 1). The pilot commented that there was no fog present at the departure time.

The 9 passengers arrived at the Ipswich Visitor Information Centre at about 0425 and they were taken to Rosewood Golf Club. The passengers were briefed on the 3 stages of balloon flying: inflation, flight, and landing. The pilot then inflated the balloon, and the passengers were boarded.

Although the pilot planned the flight in non-controlled Class G airspace[3] around RAAF Base Amberley, they made a telephone call to RAAF Amberley air traffic control and left a message on their answering machine with details of the balloon flight. The pilot reported that this was in case RAAF Amberley airspace became active during the period of the balloon flight and the airspace reverted to military Class C airspace[4] (see the section titled Airspace).

The balloon took off at around 0520 and tracked towards the east-south-east as expected from the wind observations. The pilot reported clear skies with some localised fog present to the south‑east of the RAAF base. The pilot estimated the fog to be from the surface to a height of 500 ft.

Figure 1: Flight path of VH-LUD

Flight path of balloon

Source: Google Earth, annotated by the ATSB

After about 55 minutes of flight time the pilot commenced a descent to visually identify and select a suitable landing area. As the balloon descended below 1,000 ft the wind backed[5] to a south‑westerly. As a consequence of that wind change, the balloon began tracking north-east towards the previously‑identified fog bank (Figure 2).

The pilot approached the fog expecting to be able to maintain visual requirements for landing. However, upon entering the fog, the pilot recalled observing that it was significantly thicker than they expected or had flown in before with visibility of about 10 m. The pilot continued to descend at approximately 200 feet per minute into the fog until they sighted a tree directly ahead of them. In response, the pilot immediately commenced burning on all 3 burners to arrest the descent and transition to a climb, but the balloon collided with the tree at a speed of about 4 knots. The balloon came to rest on the side of the tree at a height of about 60 ft above the ground. 

Figure 2: Descent of VH-LUD to Yamanto

Flightpath of balloon

Source: Google Earth, annotated by the ATSB

The pilot continued operating the burners and the balloon commenced a climb away from the tree. The pilot climbed the balloon until they were out of the fog and conducted an uneventful landing in a nearby paddock, clear of the fog. There were no injuries to the pilot or passengers, however multiple sections of the lower portion of the balloon envelope required repair or replacement due to damage by tree branches. The balloon returned to service 7 days later.

Context

Pilot experience

The pilot held a Civil Aviation Safety Authority (CASA) Commercial Pilot Licence (Balloon) that was issued in January 1995. At the time of the occurrence the pilot had accrued a total flying time of 2,904 hours with approximately 2,000 hours on type. The pilot held a current CASA class 2 aviation medical certificate.

The pilot also held a CASA Maintenance Authority to conduct maintenance on the Kavanagh balloon.

Balloon information

VH-LUD was a Kavanagh Balloons E-240 manned free balloon manufactured as serial number E24-527 in 2016 by Kavanagh Balloons Australia Pty Ltd. The E‑240 balloon has an envelope capacity of 240,000 cubic feet and a maximum take-off weight of 2,000 kg. It is powered by three burners connected to two independent fuel systems. At the time of the occurrence VH‑LUD had accumulated a total time of 492.8 hours in service.

Flight conditions

The pilot obtained weather observations, noting isolated fog was forecast and that the wind was variable at 3 knots. The pilot also commented that if there was visible fog at their nearby residence prior to departure, as a general practice they would reschedule the flight.

An Amberley terminal area forecast (TAF) was issued at 0209 EST for the 24 hours from 0300 with an amendment issued at 0318 (Figure 3). A further TAF was issued at 0515, about the same time the balloon took off. All 3 forecasts predicted variable winds at 3 knots and a 30% probability of fog, in which visibility would reduce to 500 m.

Figure 3: RAAF Amberley terminal area forecast

NOTAM

Source: Airservices Australia, annotated by the ATSB

Airspace requirements

RAAF Base Amberley is surrounded by Class G non-controlled airspace, which allows aircraft to operate without air traffic control (ATC) permission. This airspace becomes military Class C when the air traffic control tower is active. Permission is required from Amberley ATC to operate in Class C airspace. At the time of the flight, the air traffic control tower was not active, therefore, Class G airspace procedures applied.

The pilot reported telephoning RAAF Base Amberley air traffic control and leaving a message on their answering machine with the balloon flight details. The pilot had conducted this process for a number of years. The pilot also reported monitoring the Amberley common traffic advisory frequency for traffic during the flight.

In Class G airspace, the required visibility for a balloon operating below 1,500 ft above ground level and clear of cloud, is 5,000 m. However, a balloon operating below 500 ft above ground level and beyond 10 NM of an aerodrome with an approved instrument approach procedure only requires 100 m visibility.

On this occasion, as this flight was conducted within 10 NM of RAAF Base Amberley, an aerodrome having approved instrument approach procedures, the balloon was required to maintain at least 5,000 m visibility and remain clear of cloud irrespective of its operating height.

Balloon performance

The pilot reported that at the time the tree was observed the balloon was descending at a rate of about 200 feet per minute and was flying at a velocity of about 4 knots. As soon as the pilot saw the tree, they commenced burning on all three burners.

The pilot stated the balloon took 20-30 seconds to arrest the descent and commence climbing. The pilot reported the balloon ‘settling’ on the side of the tree in a slow speed collision.

Damage to balloon

The balloon envelope consisted of a total of 460 sewn panels in a combination of four differing sizes. A total of 19 panels were damaged during the occurrence. These panels were either repaired or replaced by the operator in accordance with the Kavanagh Balloons maintenance manual.

Safety analysis

The RAAF Base Amberley TAF listed a 30% probability that fog would be present in the area, in which visibility would be 500 m. The pilot reported that during flight preparation there was no fog present. During the flight, fog was observed in a localised area to the south-east of RAAF Base Amberley.

The flight was conducted in Class G airspace within 10 NM of the RAAF Base. Due to the RAAF Base having an approved instrument approach procedure, the balloon operating under the visual flight rules was required to remain clear of cloud and maintain a minimum visibility of 5,000 m.

The pilot commenced a descent with the intention of locating a suitable landing area. During this descent, the wind backed, and the balloon began tracking towards the area of localised fog. Instead of remaining above the localised fog and descending in the clear air beyond, the pilot continued the descent and entered the fog believing that adequate visibility would exist for the landing. The visibility subsequently reduced to 10 m.

The pilot observed a tree, and in an attempt to prevent a collision, lit the burners to transition to a climb. However, due to the 20-30 seconds required before the descent could be arrested and a climb commence, there was insufficient time for the tree to be avoided due to the limited visibility. Given the climb performance of the balloon, even if the circumstances around the airspace allowed for the flight to be conducted in visibility conditions down to 100 m, the collision would still have occurred.

After the collision, the pilot climbed the balloon off the tree and up into clear air. The balloon was then flown to the edge of the localised fog and an uneventful landing was carried out.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following finding is made with respect to the collision with terrain involving Kavanagh E-240 Balloon, VH-LUD, at Yamanto, Queensland.

Contributing factors

  • Contrary to the visibility requirement for visual flight rules flight, the pilot entered an area of fog that did not permit sufficient time to see and avoid obstacles. As a result, the balloon collided with a tree, damaging the balloon's envelope.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the pilot of VH-LUD
  • Civil Aviation Safety Authority
  • RAAF Base Amberley air traffic control.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • the pilot of VH-LUD
  • Civil Aviation Safety Authority.

Submissions were received from:

  • the pilot of VH-LUD
  • Civil Aviation Safety Authority

The submissions from those parties were reviewed however, they did not result in any amendment to the text of the draft report.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2022

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1]     Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours

[2]     Variable: used when the forecasting of mean wind direction is not possible. Usually due to low wind velocity.

[3]     Class G: This airspace is not subject to air traffic control (ATC). Both instrument flight rules and visual flight rules aircraft are permitted and neither require ATC clearance.

[4]     Class C airspace: Controlled airspace surrounding major airports. Both instrument flight rules and visual flight rules aircraft are permitted, but pilots must obtain a clearance to operate and maintain continuous radio contact with air traffic control.

[5] Backed: A counter‑clockwise shift in the wind direction.

Occurrence summary

Investigation number AO-2021-042
Occurrence date 08/10/2021
Location Near Yamanto
State Queensland
Report release date 01/11/2022
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Kavanagh Balloons
Model E-240
Registration VH-LUD
Serial number E240-527
Aircraft operator FLOATING IMAGES AUST. PTY LTD
Sector Balloon
Operation type Part 131 Balloons and hot air airships
Departure point Rosewood, Queensland
Destination Yamanto, Queensland
Damage Minor

Cabin pressurisation issue involving Boeing B737-36E SF, ZK-FXK, near Darwin Airport, Northern Territory, on 4 November 2021

Final report

Report release date: 16/05/2023

Safety summary

What happened

On 4 November 2021, a Boeing B737-36E SF, registered ZK-FXK, was being operated on a scheduled freight flight from Darwin, Northern Territory, to Brisbane, Queensland. After take-off, the flight crew observed that the aircraft did not pressurise as expected and the indicated cabin altitude was climbing much quicker than normal.

As the cabin altitude kept increasing, the crew stopped the aircraft’s climb at 11,000 ft and soon after commenced descent to 10,000 ft. As the aircraft passed 10,300 ft on descent, a cabin altitude warning alert occurred. The crew completed the required checklist actions but were unable to establish control of the pressurisation. Subsequently, the equipment cooling fan failed, the electronic flight information system reverted to a monochrome display output, and the weather radar failed.

The crew decided to return to Darwin. On arrival they identified that the guarded cargo/depress switch was on. This switch was normally only used in the event of a main cargo deck smoke event, when it will depressurise the aircraft to assist smoke removal. Switching this off returned the aircraft to serviceability.

What the ATSB found

The ATSB found that the cargo/depress switch had been turned on by the engineer as a means to cool the flight deck during pre-flight preparation. However, the engineer had omitted to turn it off prior to completing their duties, which prevented the aircraft from pressurising. Using the cargo/depress switch in this manner was not authorised but it had become normalised by the operator’s staff in Darwin, who were not aware that this practice would not be effective on the B737-36E SF aircraft in their fleet.

Although the cargo conversion operations manual supplement required the switch to be checked, this information was not incorporated into the operator’s flight crew operating manual, nor was the supplement information otherwise available to the flight crew. As a result, the crew did not identify that the switch was on during pre-flight activities. The operator also did not provide sufficient training during the introduction of the B737-36E SF to its fleet to ensure its personnel understood the differences of these aircraft to the rest of their B737 fleet.

The flight crew were accustomed to checking pressurisation after take-off to ensure the aircraft was pressurising as expected. As a result, the flight crew identified the pressurisation problem early, which enabled prompt action and prevention of a more serious incident.

What has been done as a result

The operator issued communications to its staff to immediately cease the unauthorised practice and remind staff to only operate equipment in accordance with approved documentation. Additionally, they commenced a review of operational documentation and completed incorporating the requirements of the operations manual supplement.

The operator also commenced a review of its training and aircraft induction processes to ensure sufficient staff and documentation were available to conduct support these processes.

Safety message

This incident highlights the risks associated with undertaking unauthorised practices and using equipment in a manner other than for its intended purpose. Without formal assessment of its efficacy or its potential for unintended consequences, combined with no documentation or training, there is no assurance that an unauthorised practice would be carried out consistently or safely.

This incident also demonstrated how essential training and up-to-date documentation is in ensuring correct understanding and operation of an aircraft.

 

The occurrence

On 4 November 2021, a Boeing B737-36E SF, registered ZK-FXK and operated by Airwork Flight Operations, was scheduled for a freight flight from Darwin, Northern Territory, to Brisbane, Queensland. The aircraft was crewed by 2 pilots.

The engineer assigned to prepare the aircraft commenced their tasks at about 1615 local time. The flight crew arrived at about 1630. At this time, the engineer was inside the flight deck conducting their pre-flight procedures but vacated to allow the crew to commence their aircraft preparation. The first officer commenced pre-flight procedures inside the flight deck and the captain commenced the external inspection. No anomalies were identified with the aircraft or its systems.

The aircraft departed Darwin at about 1754. Following the after take-off checks, the flight crew identified that the aircraft was not pressurising as expected. They noted that the cabin pressure differential[1] was lower than normal and that the cabin altitude was increasing at a higher than expected rate of 2,000 ft/minute.

The crew monitored the pressurisation and, as the aircraft was nearing 10,000 ft, noted the cabin altitude was about 8,000 ft and increasing. (Above cabin altitudes of 10,000 ft, flight crew are required to use supplemental oxygen to avoid the possibility of hypoxia.)

The crew attempted contact with air traffic control in order to stop the aircraft’s climb at 10,000 ft, but they were unable to due to radio congestion. After contact was made, the controller cleared the crew to stop the climb at flight level (FL)[2] 110, and subsequently to descend to 10,000 ft. The cabin altitude was below 10,000 ft at this stage, but still climbing.

At about 1800, while passing 10,300 ft on descent, a cabin altitude warning occurred. The alert consisted of the master caution light and a warning horn, and indicated that the cabin altitude was above 10,000 ft. The crew commenced the required immediate actions in response to this warning, which included the use of supplemental oxygen. However, very soon after the aircraft reached 10,000 ft, at which time supplemental oxygen was no longer required.

The cabin altitude warning checklist required changing the pressurisation mode to manual and selecting the outflow valve to fully closed.[3] The crew recalled that the outflow valve was already closed and completing the checklist actions did not establish positive control of the pressurisation.

At about this time, the master caution alert on the overhead panel presented. Looking at the overhead panel, the crew identified the equipment cooling fan(s) had failed. The crew selected the alternate fans in accordance with the quick reference handbook (QRH) procedure, but this did not restore the operation of the equipment cooling fans. Subsequently, the electronic flight information system (EFIS) reverted to monochrome display output, which was a system design feature to reduce heat output.

A short time later the weather radar also failed. The crew stated that, although they were visual at the time, there were thunderstorms in the area, for which the weather radar was a required system. With numerous systems malfunctioning, the crew decided to return to Darwin. The crew conducted a normal approach and landed at 1915.

After shutting down the aircraft, the captain moved to the jump seat to complete the post-flight log. In the darker ambient conditions compared to departure, the captain noticed an unexpected amber light on the aft overhead panel. The light was from the guarded cargo/depress switch, indicating it was in the ON position. The flight crew realised that this was the reason why the aircraft did not pressurise, as the switch was normally only used in the event of smoke in the main cargo deck.[4]

The crew discussed the occurrence with the engineer, who advised that they had selected the cargo/depress switch to ON with the intention of cooling airflow into the flightdeck while the aircraft was on the ground. The engineer stated they had omitted to select the switch off prior to completing their duties, nor had they informed the crew of the switch selection.

After turning the switch off, the aircraft was considered serviceable, and it was operated on its freight service. The systems malfunctions did not occur again nor was there any further incident.

Context

Personnel information

Captain

The captain held an Air Transport Pilot Licence (Aeroplane) and Class 1 aviation medical certificate. They had flown for the operator for about 4 years and had previously flown the B737 for 2 other airlines. The captain had also flown a variety of aircraft with regular public transport, charter and general aviation operators. They had 12,150 flight hours in total, with 3,500 hours on B737 aircraft.

First officer

The first officer (FO) held an Air Transport Pilot Licence (Aeroplane) and a Class 1 aviation medical certificate. They had been at the operator for about 1 year on the B737 but had also flown the B737 for other operators in Australia and overseas. Their previous experience included various aircraft types in regular public transport and regional operations. The FO had 17,300 flight hours in total, with 13,000 hours on B737 aircraft.

Engineer

The engineer was a licensed aircraft maintenance engineer with over 30 years' experience maintaining B737 aircraft. The engineer stated that they had only maintained B737 aircraft but had also held a maintenance manager’s position prior to commencing at the operator about 4 months prior to the occurrence.

Aircraft information

General

ZK-FXK was a Boeing B737-36E Special Freighter (SF) aircraft. It was manufactured in 1991 as a passenger aircraft with serial number 25256. It was then modified for freight operations in 2004 by Israel Aircraft Industries Limited (IAI). The aircraft was acquired by the operator in 2019.

Cargo/depress switch

The cargo/depress switch was part of the main deck smoke detection system. It was on the main deck cargo smoke detector panel, which was located on the aft overhead panel of the flight deck (Figure 1, Figure 2). The panel was located behind the flight crew seats and was not within normal line of sight for a flight crew.

Figure 1: Main deck cargo smoke detector panel

Figure 1: Main deck cargo smoke detector panel

Source: Airwork

The cargo/depress switch was a push-button type switch that illuminated when selected ON. It was guarded by a clear, flat plastic cover. The switch could be on or off with the guard in place (Figure 2). This was in contrast to other guarded switches on the aircraft, where the guard had to remain raised to allow the toggle type switch to be on. The only indication that the switch had been selected ON was the illumination of the switch itself.

Figure 2: Main deck cargo smoke detector panel (view from left seat)

Figure 2: Main deck cargo smoke detector panel (view from left seat)

Source: Captain of ZK-FXK, modified by the ATSB

The only situation for which the switch was to be used was if smoke was detected within the main cargo deck. The flight crew operating manual (FCOM) stated that when the switch was:

Depressed:

Will depressurize aircraft and provide limited ventilation to flight deck.

  • closes right and left main deck airflow shutoff valves
  • right pack valve closes
  • left pack valve closes to low flow (15-18% of normal output)
  • R/H flow control valve will be closed
  • forward outflow valve opens

The main deck cargo smoke, fire or fumes checklist further explained that:

Selecting this switch will depressurize the airplane and provides restricted heat and ventilation for exclusion of fumes and smoke from the cockpit.

As the aircraft departed with the cargo/depress switch on, ZK-FXK was prevented from pressurising.

No problems were identified with the weather radar or electronic flight information system (EFIS). Changes to the status of these systems during the flight was consistent with them being exposed to increased heat due to the cooling fan failure. The quick reference handbook explains that a cooling fan failure may be an indicator of a cabin pressurisation problem.

Operational manual supplement

An operational manual supplement (OMS) was produced by IAI to reflect all changes to the configuration and operation of the aircraft following its conversion from a passenger aircraft to a freighter. The OMS included a requirement that some of its pages must be inserted into the FCOM adjacent to their respective pages. This was to ensure the FCOM was fully amended with the latest information and procedures.

The operational manual supplement stated:

Depressing this switch will depressurize the aircraft to minimize airflow to the main cabin. The following valves will be activated.

  • both left and right air condition shutoff valves will close
  • right pack control flow valve will close
  • left pack control flow valve will drive to low flow
  • forward outflow valve will drive to open

In the preliminary flight deck preparation section of the normal procedures, the OMS required the main deck cargo smoke detector control panel to be checked as follows:

Main deck cargo smoke detector control panel – check

Check detector lights (12) – extinguished

Check detector fault light – extinguished

Check smoke light – extinguished

Main smoke no flow light – extinguished

Check depress switch, normal extinguished position, plastic cover stowed.

Both pilots stated that, after identifying the incorrect switch position on return to Darwin, they reviewed the FCOM and noted that it did not include any reference to pre-flight check requirements for the panel. During interview, the FO stated they were not aware of the OMS requirement and therefore they did not check the panel or switch during their pre-flight checks.

The ATSB reviewed the FCOM and confirmed that it had not been amended with the changes to the pre-flight procedures for checking the cargo/depress switch, as required by the OMS.

Flight crew pre-flight procedures

The FO conducted the flight deck preparation at the same time as the captain conducted the external inspection. The FO recalled that, while they were seated in the jump seat, they had looked at the overhead panel. However, rather than looking vertically up at where the cargo/depress switch was located, they looked across the panel at eye level, paying specific attention to various switches for correct positions. They described Boeing switches as being toggle types, all operating in the same direction to easily identify if they were on or off.

The FO stated that during this scan, in the bright ambient conditions, they did not notice that the cargo/depress switch was illuminated. As the clear plastic guard was able to be closed when the switch was on, and as this was different to the guard on the toggle type switches, the ability to visually determine its state was reduced. The FO recalled that at no stage was the main deck cargo smoke detector panel specifically checked. Following this activity, the FO continued the next section of pre-flight scans from their FO seat on the right side of the flight deck. From this seat, the cargo/depress switch was now behind their head and out of view.

When returning to the flight deck after the external inspection, the captain did not notice that the cargo/depress switch was on, nor were they required to check that panel. Both pilots mentioned conducting the light test to determine if lights were functional on the front, lower console and overhead panels. This test illuminated all lights but was not able to assist the pilots in visually identifying that the cargo/depress switch was on.

Prior to taxiing, the crew conducted the recall check of the master caution system annunciator panel during the before taxi checklist.[5] They also conducted this check again while attempting to establish the reason for the aircraft not pressurising. They received no alerts at those times. The crew and operator later identified that the cargo/depress switch was not connected to this system. This was not the crew’s expectation, given what systems the cargo/depress switch would affect and that it was outside of their normal line of sight.

The captain stated that the only training they received on ZK-FXK’s differences to the operator’s other B737 aircraft was related to operation of the main deck cargo door.

Cooling the flight deck

The engineer arrived at the aircraft about 1.5 hours prior to the scheduled departure time of 1745 to prepare the aircraft. They noted it was a very hot day and the aircraft interior had also become quite hot as a result. After turning the air conditioning on, the engineer then selected the cargo/depress switch to ON. The aircraft operator did not supply ground support equipment (GSE) capable of providing external air-conditioning.

At that time, the engineer believed that selecting the cargo/depress switch to ON would shut off airflow to the main deck and increase airflow to the flight deck to accelerate cooling there. The engineer stated that using the cargo/depress switch on the ground for cooling was not a documented procedure. They had learned to do this practice in Darwin from other engineers but had also seen some pilots do it. The engineer explained that they had not received any formal training on the differences between the operator’s 737 aircraft when they commenced employment with the operator.

The engineer explained that they would normally select this switch to ON, complete their aircraft preparation duties, then turn the switch to OFF prior to leaving the aircraft. On this occasion, the engineer felt that they needed to vacate the flight deck when the flight crew arrived earlier than expected. In doing so, they forgot to turn the switch off.

The operator identified that the same practice of cooling the flightdeck was used on all of their B737 aircraft by the engineers at Darwin.

Operator’s other 737 aircraft

The operator had 14 B737 freighter aircraft:

  • 12 aircraft that had been modified by Aeronautical Engineers, Inc (AEI)
  • 2 aircraft that had been modified by IAI (including ZK-FXK).

The AEI-modified aircraft were also fitted with a smoke detection system for the main cargo deck, however that system operated differently from that on the IAI-modified aircraft like ZK-FXK. On the AEI-modified aircraft, there was a cabin air shut-off switch that, when selected on, worked like the system on ZK-FXK to shut off air to the main deck, but it differed from ZK-FXK in that this system did not restrict air flow to the flight deck. Instead, all airflow was redirected to the flight deck to exclude smoke from the flight deck via positive pressure. This switch to control this system was the guarded toggle type and in the same position on the aft overhead panel as the cargo/depress switch on ZK-FXK.

Both pilots stated that the FCOM for the AEI-modified aircraft included a pre-flight operational check of the cabin air shut-off switch. The FO explained that the check required the guard to be lifted and the switch turned on to check the system operation. They explained there would be a very noticeable increase in air flow into the flight deck. The switch was then turned off and the guard closed.

The captain noted that the flow of air into the flight deck of the AEI-modified aircraft was significant to the point of distracting, and they would switch the system off if it was on. They did not notice any such air flow in ZK-FXK.

Pressurisation monitoring

The FCOM did not require that the aircraft pressurisation (cabin altitude and cabin pressure differential) be checked during flight. However, the FO stated they were in the habit of doing so due to experiences with B737 simulator instructors at a previous airline who would fail a student if they had not detected a pressurisation problem before the aircraft’s cabin altitude warning presented. The captain had a similar mindset with regard to checking the aircraft pressurisation.

It is likely that the cabin altitude warning would have presented while the aircraft was still climbing, however this did not occur because the flight crew had identified the pressurisation problem, monitored the cabin altitude, and then took action to avoid the cabin altitude rising above 10,000 ft.

Operator comments

The operator’s investigation report noted that the OMS for the IAI-modified aircraft was received by its maintenance control department when the aircraft was acquired. However, this manual was not provided to the engineering, flight operations or training departments prior to the aircraft entering service.

The report also identified that the training provided to flight crew was limited and focused on the operation of the main cargo door and escape slides. Engineers were not provided any formal training on the aircraft to identify the differences from other B737 aircraft in its fleet.

In summary, the operator identified that there were insufficient procedures as part of its aircraft induction process to ensure that all operational documentation was correctly distributed and that staffing deficiencies within the training department had impacted the oversight and delivery of training.

Safety analysis

Introduction

During pre-flight preparation, the engineer turned on the cargo/depress switch in an attempt to cool the flightdeck of ZK-FXK. The engineer omitted to turn the switch off prior to completing their duties and this was not identified by the flight crew. This prevented the aircraft from pressurising as expected and the cabin altitude subsequently rose above 10,000 ft.

The use of the cargo/depress switch in this manner was not authorised but had become normalised by the operator’s staff in Darwin.

The analysis will examine the issues related to unauthorised procedures and how documentation and training are essential for correct aircraft operations.

Normalised, unauthorised procedure

‘Normalisation of deviance’ was a process defined by Dianne Vaughan (1996) during the Space Shuttle Challenger investigation whereby unacceptable practices become accepted as the norm. The unacceptable practice is repeated without catastrophic results, reinforcing its normalisation.

Although the occurrence involving ZK-FXK did not have the same potential for a catastrophic outcome, it was an example of normalised deviance. The operator’s staff were using an aircraft system in a manner for which it was not designed (that is, using the cargo/depress switch on the ground). This practice was not authorised but had become accepted because of the perceived benefit of cooling the flight deck of its B737 aircraft in Darwin while working on the aircraft.

The engineer believed that in doing so they would be forcing air into flight deck but did not realise that this would not occur on ZK-FXK. It was identified that limited training on the B737-36E SF aircraft’s differences with the operator’s other type meant that operator’s staff were not aware that the desired result would not be achieved.

There was no evidence to suggest that anyone conducting this practice had undertaken a formal assessment of its efficacy or its potential for unintended consequences. The absence of formal documentation, procedures or training meant there was no assurance that the practice would be carried out consistently or safely. This was demonstrated by the engineer forgetting to deselect the switch, which is likely to have been a result of their normal routine being interrupted by the earlier than expected arrival of the flight crew. Lapses are common when interruptions occur and the absence of controls such as a documented procedure meant that the lapse was not recognised.

The absence of ground support equipment to provide external cooling appears to have instigated the unauthorised practice and it is likely that the practice may have continued given the frequently hot conditions in Darwin.

Aircraft documentation

Although the cargo conversion had taken place prior to the operator acquiring the aircraft, the operator did not ensure that all the aircraft documentation was adequately reviewed prior to entry into service. As a result, the flight crew operating manual (FCOM) had not been amended to include all changes detailed in the operational manual supplement (OMS), notably the requirement to check the main deck cargo smoke detector panel. The pilots were not aware of this requirement, thus removing a defence against the unauthorised use or incorrect position of the cargo/depress switch. Not checking the system also increased the risk of not detecting potential issues in the system.

The B737 is a very common aircraft but can be operated in various configurations which may differ between numerous operators. It is essential that aircraft documentation adequately reflect the correct aircraft configuration and procedures to prevent the aircraft being operated incorrectly.

Training on aircraft differences

Although the pilots had some training on the newly introduced aircraft, it was focused on the cargo door itself and not on all of the new procedures or systems following the cargo conversion. The engineer did not receive any formal training on the differences between the operator’s B737 aircraft. As such, the pilots and engineer were not provided with the opportunity to become fully aware of the aircraft they were required to operate.

In this occurrence, the limited training on aircraft differences reinforced the unauthorised use of the cargo/depress switch. Had the correct system knowledge been provided, it may have discouraged its use if it was known it would not work in the desired manner (at least on the B737-36E SF aircraft). The absence of training on required procedures also removed a defence against departure with an incorrect configuration.

Pilot vigilance

The pressurisation problem was identified early, enabled by the flight crew having developed the habit of monitoring pressurisation during their previous B737 experience. As the FCOM did not require a specific check of pressurisation during the after-take-off checks or climb phase, the pressurisation problem would still have triggered the cabin altitude warning albeit later in the climb. The crew’s heightened vigilance of pressurisation allowed them to identify and monitor the situation, take appropriate action promptly and thus avoid a more serious pressurisation incident.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors. 

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the incorrect configuration and cabin pressurisation issue involving the Boeing B737-36E SF, registered ZK-FXK, near Darwin Airport, Northern Territory, on 4 November 2021.

Contributing factors

  • While preparing the aircraft for flight, the engineer selected the aircraft’s cargo/depress switch to ON then omitted to switch it off prior to leaving the aircraft.
  • During their pre-flight activities, neither of the flight crew identified that the cargo/depress switch had been selected ON. Although the aircraft operational manual supplement required this switch to be checked, neither pilot was aware of this requirement.  
  • During the aircraft’s climb, the cargo/depress switch was in the ON position. This prevented the aircraft from pressurising as expected and the cabin altitude subsequently rose above 10,000 ft, triggering the cabin altitude warning.
  • The aircraft system to be used in the event of a main deck cargo smoke event on the operator’s B737 fleet was being routinely used by the operator’s engineering personnel in Darwin as a means to cool the flight deck. This practice had become normalised as a result of the perceived benefit of doing so, but there were insufficient risk controls in place to ensure that the aircraft would be returned to the correct configuration prior to departure. (Safety issue)
  • The operator did not provide sufficient training during the introduction of the B737-36E SF to its fleet to ensure its personnel understood the differences between these aircraft and the rest of its B737 fleet.
  • The operator’s flight crew operating manual for the B737-36E SF aircraft had not been fully amended to incorporate all revisions as detailed in the cargo conversion operational manual supplement.

Other findings

  • The flight crew were accustomed to checking cabin pressurisation during climb to ensure the aircraft was pressurising as expected. As a result, the flight crew identified the pressurisation problem involving ZK-FXK early, which enabled prompt action and prevention of a more serious incident.

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Normalised, unauthorised procedure

Safety issue number: AO-2021-047-SI-01

Safety issue description: The aircraft system to be used in the event of a main deck cargo smoke event on the operator’s B737 fleet was being routinely used by the operator’s engineering personnel in Darwin as a means to cool the flight deck. This practice had become normalised as a result of the perceived benefit of doing so, but there were insufficient risk controls in place to ensure that the aircraft would be returned to the correct configuration prior to departure.

Safety action not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Additional safety action by Airwork Flight Operations Limited

Airwork advised that:

  • A review of the B737-36E SF flight crew operations manual and quick reference handbook was completed to ensure full compliance with the operations manual supplement. Work was in progress to implement an application in conjunction with the flight crew’s electronic flight bag to allow aircraft specific tail number data to be provided immediately to crew.
  • Training packages for both flight crew and engineering staff were developed, and a training manager/coordinator will be introduced to oversee flight operations and maintenance training.
  • The aircraft induction process was reviewed, and an improved induction checklist was created to ensure data is transferred between engineering and flight operations.

Glossary

AEI                   Aeronautical Engineers, Incorporated

ATC                 Air traffic control

EFIS                Electronic flight information system

FCOM              Flight crew operations manual

FDR                 Flight data recorder

FL                    Flight level

FO                   First officer

GSE                 Ground support equipment

IAI                    Israel Aircraft Industries Limited

OMS                Operations manual supplement

QRH                Quick reference handbook

SF                    Special freighter

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • the flight crew of ZK-FXK
  • the engineer
  • Airwork Flight Operations Limited (the operator).

References

Vaughan, D. (1986) The Challenger Launch Decision: Risky Technology, Culture and Deviance at NASA. University of Chicago Press; 1st edition.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • the flight crew of ZK-FXK
  • the engineer
  • Airwork Flight Operations Limited (the operator)
  • the Civil Aviation Safety Authority
  • the Civil Aviation Authority of New Zealand
  • the Transport Accident Investigation Commission (New Zealand)
  • the National Transportation Safety Board (United States of America).

Submissions were received from:

  • the captain of ZK-FXK
  • the engineer
  • Airwork Flight Operations Limited.

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2023

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1]     Cabin pressure differential was the difference between cabin pressure and atmospheric pressure.

[2]     Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 110 equates to 11,000 ft.

[3]     The normal mode for pressurisation is AUTO, whereby the system will automatically adjust the position of the outflow valve in order to modulate cabin pressure. Manual mode will give full control of the system to the flight crew.

[4]     The passenger area of ZK-FXK’s cabin had been converted to a cargo compartment and was known as the main cargo deck.

[5]     The recall check is used to verify if a master caution condition exists. Pushing the system annunciator panel will illuminate the appropriate system annunciator and master caution light. These systems will have their control/display panels out of the flight crew’s normal line of sight. If this occurs, the flight crew will be required to take further action to verify correct system operation.

Occurrence summary

Investigation number AO-2021-047
Occurrence date 04/11/2021
Location Near Darwin
State Northern Territory
Report release date 16/05/2023
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Incorrect configuration
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer The Boeing Company
Model B737-36E SF
Registration ZK-FXK
Serial number 25256
Aircraft operator Airwork Flight Operations Limited
Sector Jet
Operation type Air Transport High Capacity
Departure point Darwin Airport, Northern Territory
Destination Brisbane Airport, Queensland
Damage Nil

Runway incursion involving Beech Aircraft Corp. 58, VH-NSK, Bankstown Airport, New South Wales, on 26 October 2021

Final report

Report release date: 18/02/2022

Safety summary

What happened

On the 26 October 2021, a Beech Aircraft Corp. 58, registered VH-NSK, operated by Little Wings Limited, was prepared for a private flight from Bankstown Airport, New South Wales. The purpose of the flight was to test the stall warning system following maintenance. The pilot was the sole person on board.

The aircraft was cleared to enter and line up on runway 29 right (29R) however, the pilot crossed the runway and entered occupied runway 29 centre (29C) without a clearance. As the pilot was cleared to take-off, the controller identified the error and instructed the pilot to hold position on the runway. At the same time, the pilot detected an Embraer 190, which was conducting high power engine runs on the upwind end of runway 29C and did not commence the take‑off.

What the ATSB found

The ATSB found that the pilot typically departed Bankstown from the centre runway, under the instrument flight rules procedures. This likely created an expectation that they were using this runway, despite reading back the correct runway to the controller. This resulted in them crossing runway 29R and entering runway 29C without a clearance.

Additionally, while the air traffic controller watched the aircraft enter 29R, due to subsequent focused attention on two helicopters in the vicinity of the airport, they did not identify its continued movement on to the occupied runway 29C.

Safety message

This incident illustrates the importance of pilots focusing on the specific instructions given by air traffic controllers. In 2012, the United States Federal Aviation Administration Safety Team (FAASTeam) released notice NOT4214 Pilot safety tip – Expectation bias stating that ‘analysis of runway incursion data shows that expectation bias is one of the most common causal factors for pilot deviations’.

The notice went on to say that pilots ‘need to understand that expectation bias often affects the verbal transmission of information. When issued instructions by air traffic control, pilots should “focus on listening and repeat to yourself exactly what is said in your head — and then apply that information actively”.’

Runway incursions remain an ongoing safety concern globally. In October 2016, Airservices Australia released A pilot’s guide to Runway Safety. This guide focused on seven important areas in surface operations and identified safety measures to help reduce the errors that lead to runway incursions. In addition, Airservices Australia have released specific guidance for pilots flying at Bankstown Airport Tips for flying at Bankstown, along with tips for flying at other metropolitan airports: Moorabbin, Parafield, Jandakot and Archerfield.

 

The investigation

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

On the morning of 26 October 2021, a Beech Aircraft Corp. 58, registered VH-NSK and operated by Little Wings Ltd, was prepared for a private flight under the visual flight rules (VFR) from Bankstown Airport, New South Wales (Figure 1). The purpose of the flight was to test the aircraft’s stall warning system following maintenance. The pilot was the sole person on board.

Figure 1: VH-NSK

VH-NSK

Source: JETPHOTOS, Gavin Louis, modified by the ATSB

The operator had requested that the pilot conduct the test flight prior to conducting an instrument flight rules (IFR) flight, later that day. The pilot advised that they had not flown under the VFR or to the Bankstown training area for over 40 years. As such, they prepared themselves by researching the airspace around Bankstown Airport and revising the procedures for the flight test.

The next morning, the pilot conducted their normal pre-flight checks and started the engines. As the pilot taxied across the apron, they contacted the Bankstown surface movement controller (SMC), to obtain their taxi clearance. The SMC instructed them to taxi to holding point A8 for runway 29R[1] (Figure 2). This clearance automatically included an approval for the aircraft to enter a run-up bay to conduct the pre-flight engine checks and then taxi to the runway holding point. The pilot was not aware of this and advised the SMC that they needed to taxi to the run-up bay, which the SMC advised they were cleared to do. During this exchange, the pilot advised the SMC that they had not been to the Bankstown training area for over 40 years.

As the pilot was conducting their engine checks in the run-up bay, the crew of an Embraer 190 (Embraer) requested, and received, clearance to taxi to holding point A2 (Figure 2), the upwind end of runway 29C, to conduct high power engine runs for maintenance purposes.

When the pilot of NSK completed their checks in the run-up bay, they clarified with SMC that they were approved to taxi to holding point A8. The SMC confirmed they were approved and instructed them to contact Bankstown Tower at the holding point.

Figure 2: Bankstown Airport showing the route NSK took to the holding point

Figure 2: Bankstown Airport showing the route NSK took to the holding point

Source: Google Earth, annotated by ATSB

At 1114, the crew of the Embraer contacted Bankstown Tower and was cleared to enter runway 29C.

On reaching holding point A8, the pilot of NSK changed frequency to Bankstown Tower. At 1117, they contacted the Tower controller and advised they were ‘on A8 holding short of runway 29R ready for an upwind departure’. The Tower controller instructed them to hold position.

At 1118, the Tower controller instructed ‘NSK runway 29R line up and wait’. The pilot read back ‘line up and wait right NSK’. The Tower controller advised that aircraft would initially taxi along the same path if they were crossing runway 29R or lining up on that runway to depart.

After watching NSK commence taxiing, the Tower controller directed their attention to two helicopters. One helicopter was operating north of Bankstown Airport, with a second departing to the north. The Tower controller passed traffic information to both helicopter pilots, to assist them to identify each other. During the period the Tower controller’s attention was diverted, NSK crossed runway 29R, then entered and lined up on runway 29C.

At 1119:23, after the helicopter pilots advised they had each other sighted, the Tower controller instructed ‘NSK runway right clear for take-off’. As they were finishing the instruction, they detected that NSK was on 29C and immediately instructed ‘NSK hold position, hold position you are lined up on Centre, hold position’. The controller then instructed NSK to ‘Stop, hold position’. At 1119:35 the controller again instructed ‘NSK Stop, hold position’ and 5 seconds later stated ‘NSK Stop, stop, stop, hold position’.

At this time, the Bankstown tower frequency had at least one occasion, where a pilot over transmitted while the controller was broadcasting on the radio.

The pilot of NSK advised that as they were turning to line up on the runway, the controller cleared them to take-off. They immediately detected an Embraer at the other end of the runway and reported they advised the controller that there was a jet on the runway and they would hold position, however this was not heard by the controller. This was likely the over transmission on the frequency. At 1119:42 the pilot of NSK read back ‘NSK Stop, stop, stop, holding position’.

At 1121, after giving instructions to a number of other aircraft in the area, the controller instructed the pilot of NSK to hold short of runway 29R. The pilot of NSK responded by stating ‘I am holding at the threshold 29’. The controller then advised ‘NSK you are currently lined up on 29C hence why I told you to hold position. Vacate to the right and hold short of runway 29R’. NSK responded ‘Roger, vacating to the right hold short of 29R, NSK’.

The Embraer completed their engine runs and exited the runway onto taxiway A1, taxiing around runway 29R (Figure 2).

The controller then cleared NSK to enter and take off from runway 29R. The pilot advised they observed the Embraer taxiing at the end of the runway, but they were unsure if the Embraer was on the runway or was on the taxi way behind the runway. They advised that they waited until the Embraer had cleared the take-off overrun, before commencing the departure. The test flight and return to Bankstown were conducted without issue.

Context

Pilot

The pilot held an Air Transport Pilot’s Licence (Aeroplane) with over 23,500 hours of aeronautical experience.

They were volunteering their time to fly for the operator while they were stood down from an airline which had reduced international flights due to COVID 19 restrictions. The pilot had been flying the Beech Aircraft Corp. 58 regularly on IFR flights for the previous 18 months, with their most recent flight being circuits on the night before the incident.

They advised that they felt uncomfortable doing a VFR flight to the training area due to the different procedures and had never departed from runway 29R prior to that day. They reported that they thought the controller had instructed them to use runway 29C and had no recollection of reading back 29R.

They advised they had slept well and were fit and healthy.

Air traffic controller

The controller had almost 20 years experience, with around 14 years at Bankstown Airport. They advised they were feeling ‘fine’ at the time, having received their normal amount of sleep over the previous days. They had been operating as the tower controller for about 15 minutes prior to the occurrence and advised that they did not consider the workload to be high.

Bankstown Airspace

Bankstown Airport uses Class D airspace procedures. It has three parallel runways aligned in the 29/11 direction (Figure 2). When runway 29 was the operational runway:

  • runway 29R was used for departing and arriving VFR aircraft
  • 29C was used for departing and arriving IFR aircraft and overflow if 29R was busy
  • 29L was used mainly for circuits.

When the airport was busy, 29L was controlled by one controller and 29 R and C were controlled by a second controller. When it was quiet, a single controller controlled all three runways.

On this morning, the tower controller was controlling all three runways. There were two aircraft in the circuit area, two aircraft inbound, a helicopter operating north of the airport and another helicopter departing to the north.

Safety analysis

The experienced pilot had been conducting IFR flights for the operator on a regular basis over the previous 18 months. On these flights, they had only conducted IFR departures using the centre runway. This most likely led to them having an expectation they were going to depart from runway 29C. According to Skybrary Flight crew expectation bias:

Expectation bias occurs when a pilot hears or sees something that he or she expects to hear or see rather than what actually may be occurring. That expectation often is driven by experience or repetition. For example, if a pilot is regularly cleared to cross a particular runway during operations at a familiar aerodrome, he/she may come to “expect” the clearance. This could cause a potentially dangerous situation if on a particular day, the pilot actually is instructed not to cross the runway in question due to another aircraft landing or taking off.

Despite confirming the instruction to line up and wait on runway 29R, the pilot reported no recollection of this. It is likely the pilot was thinking ahead to conducting the VFR departure, narrowing their focus to their actions after the departure. Consequently, their attention was probably not on the clearance to enter the runway, rather reverting to what they had done previously.

The controller had no indication from the pilot’s readback that the pilot had a different understanding of what was instructed. Therefore, when the aircraft commenced taxiing as expected, they diverted their attention to other tasks.

Both the pilot and the controller detected an issue and stopped the departure prior to the aircraft commencing the take-off run, although at this stage the pilot was still unaware, they were not on their cleared runway.

The air traffic control system is dependent on radio communication which requires both pilots and controllers to clearly and accurately articulate what they are doing. An analysis of runway incursion data conducted by the United States Federal Aviation Administration Safety Team in 2012, found that expectation bias is one of the most common contributing factors to pilots deviating from a clearance instruction.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the runway incursion involving Beech Aircraft Corp. 58, VH-NSK at Bankstown Airport, New South Wales, on 26 October 2021.

Contributing factors

  • Despite correctly acknowledging the clearance to enter and line up on runway 29R, the pilot crossed runway 29R and entered runway 29C without a clearance, probably due to expectation bias associated with previous operation only from 29C.
  • The controller watched VH‑NSK enter 29R however, due to subsequent focused attention on two helicopters in the vicinity of the airport, they did not identify its continued movement on to the occupied runway 29C.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • pilot
  • controller
  • Airservices Australia

References

SKYbrary, Flight crew expectation bias

Federal Aviation Administration (FAA) Safety Team 2012, Pilot Safety Tip – Expectation Bias Notice number NOT4214, September 2012

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • pilot
  • controller
  • Airservices Australia
  • Little Wings Limited

No submissions were received.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2022

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1.  Runway number: the number represents the magnetic heading of the runway. The runway identification may include L, R or C as required for left, right or centre.

Occurrence summary

Investigation number AO-2021-046
Occurrence date 26/10/2021
Location Bankstown Airport
State New South Wales
Report release date 16/02/2022
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Runway incursion
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer Beech Aircraft Corp
Model Baron 58
Registration VH-NSK
Serial number TH-106
Aircraft operator Little Wings Limited
Sector Piston
Operation type Private
Departure point Bankstown Airport, New South Wales
Destination Bankstown Airport, New South Wales
Damage Nil

Aircraft details

Manufacturer Embraer-Empresa Brasileira De Aeronautica
Model ERJ 190-300
Sector Jet
Damage Nil

Collision between a passenger train and a motor vehicle, near West Dapto Road level crossing, Kembla Grange, New South Wales, on 20 October 2021

Final report

Report release date: 25/10/2024

Safety summary

What happened

In the early hours of 20 October 2021, NSW Trains’ passenger train service (C012) collided with an abandoned motor vehicle on the rail line south of the West Dapto Road level crossing and Kembla Grange railway station.

The collision with the motor vehicle caused the first carriage of the train to derail and separate from the rest of the train. The front carriage collided with a high voltage stanchion, then tipped on its side, sliding into the adjacent land of the rail corridor.

The driver received serious injuries and two passengers in the lead carriage were also injured. They and the guard were taken to hospital for observation. The other eight passengers were assessed on site and medically cleared.

There was significant damage to the rolling stock, rail infrastructure and overhead wiring as a result of the collision.

What the ATSB found

On 27 October 2021, NSW Police charged an individual with endangering passengers on a railway and obstructing a railway. On 15 November 2022, the individual pleaded guilty to these offences and eight other separate offences. The actions of the individual directly contributed to the collision when the motor vehicle was abandoned after it was driven onto the railway tracks and became stuck.

This individual was captured on Kembla Grange railway station’s closed-circuit television (CCTV). They moved the level crossing cameras away from the level crossing to face directly downwards about 45 minutes before the collision. Sydney Trains Security did not detect camera tampering at this time. A CCTV Upgrade Project was scoped to install and commission tamper alarms on high‑risk CCTV cameras, but the alarms were not operating on these cameras at the time. If the tamper alarm functionality on the CCTV cameras was activated and working as intended, security may have detected the camera tampering.

A member of the public called triple zero, alerting police of the motor vehicle on the rail line about 4 minutes prior to the collision. The call was not treated as an emergency by all parties involved, and the actions taken to alert the train crew of the motor vehicle on the rail line did not allow the train crew time to act and avoid the collision.

After the incident, the guard tried to make an emergency call on the Digital Train Radio System (DTRS) located at the guard’s workstation. The DTRS was not working as it had gone into standby mode as a result of the control circuit breaker tripping – which likely occurred during the separation of carriages.

The guard's training and the other available resources did not provide the guard the knowledge to reboot the DTRS. In this instance, mobile phone coverage was available and the lack of knowledge about the DTRS was not a factor in being able to communicate. The use of a work issued mobile phone allowed the guard to report the incident to Network Control in a timely manner.

The Sydney Trains’ Security Control Centre Standard Operating Procedure contained conflicting instruction for incident response. It referred to the Train Services Delivery Manager (TSDM) in the Incident Response Checklist in addition to the Network Incident Manager (NIM). This potentially added an additional step in communications during incident response before the information reached someone with the ability to warn or stop train services.

The derailment brought down potentially live 1,500 V overhead wires to ground level and whilst the guard and first responders were moving around the wreckage to help passengers, this overhead wiring had not been confirmed as isolated. While this presented a risk to the guard and first responders attending to the driver and injured passengers, the guard had identified the potential sources of electricity and informed the first responders to stay clear.

This investigation also reviewed the status of the remaining open recommendations and actions from the Special Commission of Inquiry into the Waterfall Rail Accident. This was to determine if any outstanding actions had influence and/or importance to the outcomes of this investigation. The review found there were no outstanding actions that influenced or had importance to the outcomes of this incident.

What has been done as a result

Sydney Trains conducted post‑incident technical and systemic investigations and made 14 internal recommendations for their organisation to address key safety issues from this incident. Sydney Trains reported all recommendations of its internal report were completed and closed. 

Key actions taken to address the safety issues raised in this report and the 14 recommendations of Sydney Trains’ internal report are detailed below. 

To address the safety issues raised in this investigation, the Security Control Centre Standard Operating Procedure was aligned with the Sydney Trains Network Incident Management Plan with Security Control Centre Operators required to contact NIMs rather than TSDMs.

Security Control Centre Operators' initial training in responding to emergencies was upgraded to improve communications during emergencies and a recertification module was developed to be provided as refresher training.

CCTV software was upgraded to allow use of a centralised server-based analytics engine to provide alarm functionality. At the time of publication, Sydney Trains was in the process of development, testing and trialling alarm functionality to enable detection of incidents such as the tampering at the West Dapto Level Crossing while reducing the false alarm rate.

The additional actions taken by Sydney Trains to address their internal recommendations included sharing of learnings with other key stakeholders, assessing feasibility of improving emergency lighting circuitry on Tangara Sets, reviewing actions of key personnel to ensure alignment with emergency procedures and reviewing and updating risk registers and procedures to account for learnings from this incident.

Safety message

All obstructions reported on the rail line should be treated as an emergency, and priority given to urgently stopping trains on the network to avoid collision by the most effective means available.  

Rail operators should assess their risk exposure in circumstances where they have been unable to implement planned controls. They should consider implementing alternative or short-term controls to reduce the risk exposure until the agreed controls are in place. 

The processes and procedures that are established by accredited rail operators are the mechanisms by which the accredited operator has provided assurance they are able to manage risks safely. Rail operators should regularly review their controls to ensure they remain effective and continue to achieve their intended purpose. 

When introducing new or changing existing procedures, change control processes should consider the impact on other related procedures to ensure the integrity of risk controls is maintained. Consistency in these procedures throughout the organisation should be confirmed to ensure controls remain effective.

 

The occurrence

On 20 October 2021, NSW Trains’ passenger service (C012) departed Kiama at 0339 en route to Central Station in Sydney. As the train approached Kembla Grange Station at approximately 0409 it collided with an abandoned motor vehicle on the rail line. This motor vehicle had been left on the rail track approximately 68 m on the south-west side of West Dapto Road level crossing at Kembla Grange.

When the first carriage of the train struck the motor vehicle, it derailed and separated from the other carriages, collided into a high voltage stanchion, tipped onto its side, and slid into the adjacent land of the rail corridor. The driver and two passengers in the first carriage were injured and required hospitalisation. The guard was also taken to hospital for further observation. The remaining eight passengers were assessed on site and medically cleared. There was no-one in the motor vehicle at the time of the collision.

Police were onsite within minutes of the incident, having received an earlier notification of a motor vehicle on track from a member of the public via triple zero. The police assisted with the injured driver and passengers who were taken to hospital.

There was significant damage to the rolling stock, rail infrastructure and high voltage overhead wiring as a result of the collision.

Motor vehicle on the rail line 

At 0313 (EDT)[1] a Sydney Trains’ security camera located on the Kembla Grange Station platform recorded an individual moving the security camera. The camera was moved to focus away from the West Dapto Road level crossing towards the ground. There was no mechanism to alert the Security Control Centre Operators (SCCO)[2] at the Sydney Trains Security Control Centre to this event.

At 0326 a second security camera, also located on the Kembla Grange Station platform, recorded being moved from its focus on the West Dapto Road level crossing towards the ground. This movement was also not alerted to or detected by the SCCO at the Sydney Trains Security Control Centre.

Likely between 0326 and 0405, when police received the first report of a motor vehicle on track, a vehicle was driven onto the railway tracks and abandoned after it became stuck on the rail.

Police forensics marked the location of the motor vehicle at 91.732 km, 68 metres from the West Dapto Road Level Crossing (see Marker A in Figure 3).

Train service C012

At 0339 C012, a 4‑carriage Tangara passenger train service departed Kiama Station en route to Sydney Central Station. As part of the scheduled stops, the train arrived at Dapto Station to pick up passengers and departed shortly after at 0407. The driver gradually accelerated the train to the track speed limit of 100 km/h.

At 0408:40, the driver moved the power notch to the off position and allowed the train to coast (from a speed of 103 km/h) as the train passed the Area 013 transponder (Wollongong South)[3] located at 93.400 km.

At 0409:06, the train passed the track circuit that activated the West Dapto Road Level Crossing warning bells and lights (92.672 km). 26 seconds later, at 0409:32, the driver made an initial brake application (91.944 km). It was estimated the train was approximately 200 m from the motor vehicle at this time. Three seconds later the driver applied full braking (91.860 km) and within the second after, applied emergency braking.

Figure 1: Approach to level crossing

Figure 1: Approach to level crossing

Front of train footage taken from a subsequent train journey at the same time of day. The location of the motor vehicle was 268 m beyond the 92 km posts. At this time the motor vehicle was likely in relative darkness. 

Source: Sydney Trains

Notification to Network Control

At 0405:52 police received a triple zero phone call and were notified of a motor vehicle on the rail line just off the Racecourse and West Dapto Road, near Kembla Grange Station.

At 0407:37, Sydney Trains Security Control Centre received a call from police.

At 0408:47, after confirming the location of the motor vehicle on track from police, the Sydney Trains SCCO called the Train Services Delivery Manager – South West (TSDM)[4].

At 0409:08, the TSDM called the Wollongong Coast Panel Signaller (WCP Signaller)[5] advising them there was a report of a motor vehicle on track and to stop all services immediately.

At 0409:35, 2 minutes from when Sydney Trains received the call from police, the WCP Signaller made a point to point (direct not emergency) call to C012 using the Digital Train Radio System (DTRS), however the call was not answered.

The collision and derailment

At 0409:36, the driver of C012, travelling at approximately 90 km/h, applied emergency braking on the train. Over the next 4 seconds, the train collided with the abandoned motor vehicle on track and derailed to the left of the track in the direction of travel.

The front carriage travelled approximately 125 m upright in a derailed state before the right side of the carriage impacted and flattened a stanchion supporting overhead high voltage wire.

The first carriage tipped onto its right side and jack-knifed so that the rear of the carriage separated from the second carriage, and then slid a further 25 m off to the side of the rail track. The remaining 3 carriages stayed upright with the second carriage derailing and the third and fourth carriages remaining on track and alongside Kembla Grange Station platform (Figure 2).

Figure 2: C012 after the collision and derailment

Figure 2: C012 after the collision and derailment

C012 alongside Kembla Grange Station after collision and subsequent derailment

Source: Sydney Trains, annoted by ATSB

Post occurrence

Thirty seconds after the WCP Signaller had attempted to reach the driver of C012, they attempted to reach the driver with a second point-to-point call which was also unsuccessful. Shortly after, the WCP Signaller received a call from the TSDM. The WCP Signaller initially told the TSDM, C012 had gone through Kembla Grange.

When the TSDM said they could see the track was occupied, they asked if the driver had reported seeing a motor vehicle. The WCP Signaller told the TSDM that they had a few attempts to contact the driver of C012, however each attempted call kept terminating. The WCP Signaller then commented that it appeared now that C012 was not moving.

The TSDM directed the WCP Signaller to make an emergency call to the driver which differed from a point-to-point call as it would be broadcast in the cab on the radio and to all other trains in the area. The WCP Signaller made the Rail Emergency Call (REC) using the emergency function of the DTRS, but there was no response.

At 0411:56, 2 minutes and 16 seconds after the collision, the signaller on the adjacent Wollongong panel (WP Signaller)[6] received a call from the guard of C012, from the guard’s work‑issued mobile phone. The guard told the WP Signaller that the train had been in an accident at the level crossing. The train radio was not working, and they were going to check on the welfare of the driver. The WP Signaller then told the guard to check on the welfare of any passengers. The guard confirmed there were passengers on board, and they would walk through the train to check on the welfare of the passengers and the driver.

As the guard checked the train, they remained on the call to the WP Signaller and confirmed that the second car had derailed and was leaning to the side with lights out and that the lead car had derailed and was lying on its side. The guard also requested an ambulance for the driver.

During this call, the guard told the WP Signaller that the police were onsite. The guard spoke with the police, which could be heard in the background. The police asked the guard about passengers and if the train was live. The guard responded, ‘stay away from the overhead, and that portion of the train is still live’.

The guard then resumed conversation with the WP Signaller. The WP Signaller told the guard that they would advise the Network Incident Manager South (NIM)[7] and the TSDM so that they could arrange for a power outage.

The WP Signaller then informed the TSDM that C012 had derailed, and they had received the call from the guard on C012. The TSDM confirmed with the WP Signaller that protecting signals had been placed at STOP with blocking facilities applied[8].

At 0412:55, 3 minutes and 15 seconds after the collision, the TSDM informed the NIM of the incident. Approximately a minute later, the Electrical Operations Centre (EOC)[9] informed the NIM of a sustained fault on the overhead wire supply from Unanderra to the countryside of Dapto Station, which included the incident site. The NIM then advised the EOC of the incident they had just been informed of by the TSDM.

The NIM then received a call from the WP Signaller who relayed information they had received from the guard on C012.

Next the NIM received a call from the SCCO who said they had received news of the derailment from the NSW Police Radio Operations Group (ROG)[10] and would confirm that all rescue personnel had been contacted regarding the potential for fallen overhead wires to be live. The SCCO also stated the ROG advised that passengers were injured.

At 0415 the NIM called the Incident Rail Commander (IRC) South Coast[11] and requested they attend Kembla Grange.

At 0416:23, in a three-way call between the NIM, EOC and WCP Signaller, the NIM confirmed with the EOC that power would remain off and that the power outage was from Coniston to the countryside of Dapto Station. The NIM then confirmed with the WCP Signaller that signals were at STOP with blocking facilities applied. After speaking with the NIM, the EOC requested the Work Group Leader (WGL) Traction[12] to attend Kembla Grange to verify the power outage. The WGL advised the workgroup would be there in 30 minutes.

At 0419, 9 minutes and 20 seconds after the collision, a Level 2 incident[13] was declared by the NIM. The NIM also updated the Duty Control Manager (DCM)[14] and advised a sustained overhead wire fault from Unanderra to Dapto Station was reported at 0413. The NIM then advised the SCCO of the sustained fault and that a Rescue Power Outage (RPO)[15] was to be issued. Until the RPO was issued, wires were to be treated as live. The SCCO then called the ROG directing to inform emergency personnel onsite to treat the wires as live.

At 0435 the IRC arrived onsite at Kembla Grange and took charge as the Rail Commander under Sydney Trains’ Command and Control structure. At this time a Level 3 Crisis[16] had been declared.

The RPO was issued by the EOC to the NIM at 0444, approximately half an hour after the event, which confirmed the power outage. The EOC then informed the IRC that while the RPO had been issued to the NIM, personnel onsite were still to treat all wiring as live. The EOC also stated that an Emergency Authority[17] was in process and once completed, the Emergency (electrical) Authority would be conveyed to the IRC to enable workers to sign on to it.

The NIM then informed the WCP Signaller, WP Signaller and the TSDM of the RPO details. Both signallers confirmed that blocking facilities had been applied.

At 0524 hours the incident location was declared a crime scene by police.

At 0550 hours Electrical Authority E62/21 was issued for Kembla Grange K171 to ensure power remained isolated in the incident area during incident recovery. The NIM informed the TSDM that the RPO would be overlapped with the Electrical Authority and power would be formally removed.

The NIM was informed by the IRC onsite there was a total of 12 people on board: 2 NSW Trains’ crew, one off-duty guard travelling as a passenger and 9 other passengers. The train crew and 2 passengers with minor injuries were conveyed to hospital. A bus was arranged to transport the remaining passengers to their home.

By 0600 all uninjured passengers were on a bus and departed Kembla Grange Station.

NSW Police maintained control of the site until 11:00 at which time the site was handed to the ATSB.

By 12:00, the site was handed back to Sydney Trains to allow infrastructure repairs and train recovery to commence.

Figure 3: Point of collision and abandoned motor vehicle

Figure 3: Point of collision and abandoned motor vehicle

The motor vehicle was abandoned on the rail line at yellow marker A and pushed by the train to the location in the picture.

Source: OTSI

Context

Criminal act

On 27 October 2021, NSW Police charged an individual with endangering passengers on a railway and obstructing a railway amongst other charges.

On 15 November 2022, the individual pleaded guilty to 8 separate offences, including endangering passengers on a railway and obstructing a railway.

The actions of this individual were key contributing factors to the collision of C012.

In the individual’s attempts to steal a go-kart from the Wollongong Kart Raceway, located close to the West Dapto Road level crossing, they undertook a series of activities which led to the motor vehicle being stuck on the rail line and abandoned.

At 0313 and again at 0326 on 20 October 2021, a Sydney Trains CCTV recorded the individual moving cameras to face away from the West Dapto Road level crossing (Figure 4).

Figure 4: Level crossing cameras at Kembla Grange Station

Figure 4: Level crossing cameras at Kembla Grange Station

CCTV cameras facing the ground and away from the level crossing, moved by the convicted felon as captured on CCTV.

Source: OTSI

Security cameras

CCTV Upgrade Project

Sydney Trains operated a CCTV camera network system with approximately 13,000 cameras to cover the rail network which extends over 800 km of rail track and 170 stations.

Sydney Trains highlighted in their internal investigation that the tamper alarm functionality on Sydney Trains’ network of CCTV cameras was not activated on all cameras as part of the CCTV Upgrade Project contract that commenced in 2015.

The contract required tamper alarms to be installed on all cameras. However, the cameras were prone to vibration caused by passing freight trains and other anomalies resulting in high false alarm rate. Security Control Centre staff could not manage the excessive number of tamper alarms being generated causing installation to be stalled.

The requirement of the contract was subsequently amended so that the tamper alarm functionality was activated only on “high risk” cameras (including cameras that monitored level crossings) but at the time of this incident the functionality had not been activated on the West Dapto Road Level Crossing.

The Sydney Trains Network Maintenance group took charge of the project in December 2020 and a CCTV Operational Working Group was formed to continue progress from February 2021. 

To make changes to the CCTVs on the network, the Sydney Trains Security Group had to submit a request to the CCTV Operational Working Group to get the tamper functionality installed.

Following this incident, Sydney Trains Security group worked with the contractor to find out what was stopping the implementation of the tamper alarm functionality. An issue raised was poor detection on outdoor cameras due to lighting conditions. At the time of authoring this report, other solutions were still under consideration such as electro-mechanical tamper alarms and/or more bespoke high‑end video analytics were being trialled on cameras used to monitor level crossings.

Location

Kembla Grange Station

The station is located 91.586 km from Central Station on the South Coast rail line. It is within the Sydney Trains’ electrified network, which extends as far south as Kiama Station. Kembla Grange is a single platform station situated on the SSE side of the bi-directional rail line.[18]

There were multiple CCTV security cameras at the station, including security cameras mounted on a pole on the western point of the platform intended to face towards the West Dapto Road Level Crossing (Figure 4). These cameras were able to be viewed by staff at Sydney Trains Security Control Centre.

Kembla Grange Station was not staffed but was fitted with a customer access point where the travelling public could reach NSW Trains’ customer service attendants at any time of the day or night. The station is located along the coast between Wollongong and Shellharbour, as seen in Figure 5. The South Coast rail line skirts the west of Lake Illawarra.

Figure 5: Kembla Grange Station

Figure 5: Kembla Grange Station

Source: Google Maps

West Dapto Road Level Crossing

The West Dapto Road level crossing was located approximately 150 m west along the West Dapto Road from The Princes Highway. Approximately 20 m from the western most point of Kembla Grange Station platform. 

It was a Type F level crossing with boom gates, audible warning devices and roadside flashing lights. These safety features activate automatically when a train approaches and were designed to be failsafe. The level crossing was functional and operating as required at the time of the incident.

Figure 6 shows the level crossing and how its design affords access into the rail corridor. The individual likely accessed the rail corridor in their motor vehicle from the southwest entry on the downside (left side) of the railway line. 

The individual likely drove the motor vehicle along the side of the track until they reached the high voltage stanchion. They then attempted to drive the motor vehicle over the rail track onto the upside (right side). This is when the motor vehicle got stuck on the rail line.

Figure 6: West Dapto Road Level Crossing

Figure 6: West Dapto Road Level Crossing

View in both directions, Southwest is down direction away from Sydney, Northeast is up direction towards Sydney

Source: Google Maps

Rolling stock

The passenger train was a Tangara (Set T42) en route to Sydney from Kiama as service C012. There were 4 carriages in the train consist. The lead carriage was 6212, followed by 5213, 5211 and 6211.

The Tangara train set was a double-deck 4-carriage set with 2 motor carriages in the centre and 2 driving control trailer carriages at each terminal end. All carriages were built by A Goninan & Co at Broadmeadow NSW between 1987 and 1997 and were first introduced into service on 12 April 1988.

The control trailer carriage had a compartment for the driver at the front and pantographs[19] on top of the carriage at the rear. The seating capacity of the control trailer carriage was 98 and it weighed 42 tonnes. The motor carriage had a seating capacity of 112 and weighed 50 tonnes.

The Tangara trains were made in two sub classes, the "T sets" for the suburban lines and the "G sets" for the outer-suburban lines. They could run as a set of 4 carriages, or 2 sets could be coupled together to run as an 8‑carriage set. On this morning, train C012 was running as a 4‑carriage Tangara set and was a substitute for the usual Oscar train set (H set) that was regularly servicing the South Coast rail line.

Figure 7: Tangara four-car set

Figure 7: Tangara four-car set

Source: Sydney Trains

Digital Train Radio System

Sydney Trains had a Digital Train Radio System (DTRS) for meeting its train radio communication requirements on its rail network. DTRS was the primary train radio system providing voice and data services to the Sydney Trains electric passenger fleet for day-to-day train operations. It enabled communications between train crews, network controllers, mechanical control and other rail staff.

The DTRS on Set T42 did not work for the guard when they attempted to call the signaller after the incident. The WCP Signaller also attempted to contact the driver on the DTRS after the incident, but was unsuccessful.

Sydney Trains investigated the functionality of the DTRS after the incident. They found the DTRS was working. However, the guard was unable to contact the signaller using the radio as the radio unit had gone into standby mode. Likely as a result of a short circuit tripping the guard’s Control Circuit Breaker unit when the first carriage separated from the train.

The event recorder data revealed unexpected voltage spikes on the unpowered trainline ‘Door Open’ wires at the time that Car 1 (6212) was separating from Car 2 (5213). Sydney Trains concluded that the powered ‘Door Close’ trainline wire suffered a short circuit during the separation which tripped the guard’s Control Circuit Breaker in Car 4 (6211).

For the DTRS to work again, it required the guard to reset it.

DTRS instructions

NSW Trains had a train working procedure NTTWP 182 Digital Train Radio System. This working procedure provided instruction on how to use the system including how to Start Up and conduct a Network Audio Test and how to identify cab radio and Transponder faults during start‑up. The procedure did not cover how to reset the system and in which situations the DTRS would need to be reset. 

The quick guide to the DTRS for guards ‘how to’ video, available on Sydney Trains Intranet provided instructions on how to use the various functions of the DTRS, including how to start up, conduct the various tests, and make emergency calls. There was no instruction on what to do if the DTRS went into standby mode.

Other procedures that provided instruction to train crew on how to respond to an incident, such as, the Operator Specific Procedure NTOSP 12 Responding to an incident and NTTWP 154 Responding to an incapacitated Driver or Guard/Passenger Service Supervisor, focus on what information to provide when reporting an incident, not how to operate the device used to report the incident.

Rail Operations Centre (ROC)

The Rail Operations Centre (ROC) was a purpose-built operations centre for running the Sydney Trains Rail Network. The goal of the ROC was to enable the network to run more efficiently, improve punctuality and achieve faster incident recovery. Teams from Sydney Trains and NSW TrainLink worked together to manage all aspects of the network.

The ROC Control Room Floor (CRF) was established in March 2019, and Security, Operations, Customer Information and NSW TrainLink all began operating from the site. Signal Box Operations later joined the CRF from July 2019. While most signal operations were managed from the ROC, a few signal operations still operated from external signalling control complexes. For instance, Wollongong Signalling Complex controlled the signals on the south coast rail line.

The CRF at the ROC comprised of the following directorates and agencies: Engineering and Maintenance (ICON), Operations Delivery (Service Delivery and Security), Customer Service (Customer Information Unit and Customer Operations), Train Crewing and Support (TCO), and NSW TrainLink. 

Network Operations Reform

Prior to the ROC, Sydney Trains’ rail network operations was primarily managed from the Rail Management Centre (RMC). Commencing in late 2018, Sydney Trains changed its operating model to prepare for the future move into the ROC.

A key objective of the new operating model was to improve the way incidents and service disruptions were managed. The operating model previously used by Sydney Trains had been the same for almost a century, with the role of the Train Controller historically managing both ‘Train Service Delivery’ and ‘Incidents’ across the rail network. 

During this reform, Sydney Trains broke up the key functions of the Train Controller and introduced two new roles:

  • Train Service Delivery Manager (TSDM), whose role would be to focus on managing train services across the network.
  • Network Incident Manager (NIM), whose focus would be to manage incidents on the rail network and any unplanned possessions and work on track authorities.

During this transition, several communications were released to ensure staff understood the scope of the changes. A summary of the changes was provided in the document ‘Network Operations Changes’ and specific information on the Network Operation Reform was provided to stakeholders, such as Security and Train Crewing, so they could understand how the changes affected them.

A key change included defining where responsibilities lay with the new roles. A table comparing responsibilities from the old Train Controller to the new TSDM and NIM was provided to all\\stakeholders.

The table of responsibilities below was provided to Security:

Table 1 – NOR Stakeholder Information – Security

Train Controller, TSDM and NIM responsibilities
TodayAs of 2 December 2018
Train ControllerTSDMNIM

Receives all calls from Security

 

Manage incidents

Receives all initial calls from Security, if Security not already dealing with an incident

TSDM will escalate the call to the NIM if required

Receives follow up calls from Security or escalated from the TSDM regarding incident

Manage incidents

The stakeholder communication stated all initial calls needed to go to the TSDM which contradicted Sydney Trains’ overarching Command and Control structure.

The stakeholder information also clarified the new network control boundaries and who was responsible for the area.

The previous Train Controller boundaries had broken the rail network into 6 train control areas.

New boundaries for the TSDM were broken into 5 train control areas, with 2 NIM areas to cover the entire rail network, a North and South, which overlaid the TSDM boundaries (Table 2).

Table 2 – NIM and TSDM area boundaries

NIM North

NIM South

TSDM 
Main

TSDM 
North

TSDM 
Central Coast

TSDM 
Illawarra

TSDM 
South-West

 

Involved parties in the ROC

Key roles located in the ROC who were involved in this incident included the Duty Control Manager (DCM), Network Incident Manager (NIM), Train Services Delivery Manager (TSDM), and the Security Control Centre Operator (SCCO).

Duty Control Manager (DCM)

The DCM oversees the daily operations for everyone on the CRF. As the lead for Service Delivery and Customer Operations on the CRF, their role was described in the Sydney Trains document Control Room Floor Roles, as responsible for creating a collaborative work environment to support and empower others to make informed decisions promptly. They drive continuous improvement, encourage technology adoption including systems and procedures, and aimed to achieve improved operational efficiencies while building customer advocacy, amongst other responsibilities.

The DCM was also responsible for managing Level 2 – Critical incidents on the rail network. This is further explained below in Network Incident Management Plan.

Figure 8: ROC Control Room Floor

Figure 8: ROC Control Room Floor

Source: Sydney Trains

Network Incident Manager (NIM)

The NIM was responsible for end-to-end management of operational rail incidents that happen on the network. They played a key role in communicating with operational employees and updating internal and external stakeholders about incidents. The decisions they made were focused on providing a safe process for people on and about the track and safe transportation of customers.

The NIM was responsible for managing Level 1 – Routine incidents on the rail network. This is further explained below in Network Incident Management Plan.

As their primary role was managing routine rail incidents, the NIM was provided access to the DTRS which enabled them to communicate directly with train services on the rail network.

Train Services Delivery Manager (TSDM)

The TSDM was responsible for the day-to-day management of train service delivery and ensuring smooth running of services on the Sydney Trains network.

They provided thorough communication of real-time information of service status updates and changes to train plans to other business areas.

TSDMs did not have direct access to the DTRS. To pass information to train crew, the TSDM would need to go through the NIM or a Signaller.

The Security Control Centre Operator (SCCO)

The SCCO is part of Rail Network Securityand is discussed later in the report.

Other involved parties

Signallers

Signallers are responsible for the control and supervision of rail traffic movements, the operation of signalling equipment and coordinating train movements within their area of control in accordance with safeworking regulations.

Train operations at Kembla Grange were controlled by a signaller located at the Wollongong Signalling Complex who operated points[20] and signals[21] to permit rail traffic movements. The complex was located approximately 12km from Kembla Grange Station and the location of the incident. 

Signallers used a push button panel which allowed the control and interaction with signalling infrastructure from a remote location. The signallers used the panel to set start and stop points for the intended routes. As the train enters the controlled area, lights illuminate on a large visual display board indicating the location of the train. This allowed the signaller visibility of trains within their designated area.

They could communicate with trains in their area using the DTRS. This communication could occur through either point-to-point calls to specific trains, or emergency broadcasts to all trains on the local network. 

Wollongong Coast Panel Signaller (WCP Signaller)

The WCP Signaller involved in this incident was located at the Wollongong Signalling Complex. They were responsible for operation of the track circuited territory on the South Coast rail line from Berry to Kembla Grange (Figure 9).

In this incident, the TSDM made a call to the WCP Signaller to request all trains be stopped once they learned there was a motor vehicle on track.

Wollongong Panel Signaller (WP Signaller)

The WP Signaller was also located at the Wollongong Signalling Complex and seated alongside the WCP Signaller. As both signallers were in the same room, it was easier for them to communicate about the incident.

The WP Signaller was responsible for operation of the track circuited territory from Port Kembla to Wollongong, including Port Kembla Yards and Inner Harbour (Figure 9).

The WP Signaller received the emergency call from the Guard at 0411:56 from the guard’s work‑issued mobile phone. At this time, the TSDM and the WCP Signaller were also on a call, which was when the TSDM requested the WCP Signaller to make an emergency call to stop all services.

Figure 9: Signalling Panel Boundaries

Figure 9: Signalling Panel Boundaries

 

The boundary of responsibility for the Wollongong Coast Panel Signaller in Orange, Wollongong Panel Signaller in Purple.

Source: Sydney Trains

Incident Rail Commander (IRC)

IRCs provided 24/7 operational response coverage for all major rail incidents on the Sydney Trains network (area bounded by Newcastle, Lithgow, Macarthur, Nowra).

The role of the IRC was to provide onsite incident management for rail incidents within Sydney Trains’ network to ensure effective and timely resolution of operational problems, and safety of all staff, contractors, commuters, and emergency services personnel.

Electrical Operations Centre (EOC)

The EOC was one of 6 maintenance operations centres that combined to form the Infrastructure Control Centre (ICON). The EOC was responsible for high voltage supply control, 1,500 V traction supply control, emergency repair coordination and electrical incidents.

A call from the EOC was made to the NIM when they detected a sustained fault of the high voltage supply between Unanderra and Dapto Stations.

Police Radio Operations Group (ROG) 

The ROG was the radio dispatch and contact centre providing 24/7 assistance and service to the NSW Police Force and members of the community.

The ROG had Communications Officers who were responsible for processing incoming calls from police and the community, including emergency triple zero calls. 

The ROG also had Radio Dispatch Channel (RDC) Operators who were responsible for tasking and coordinating activities of police resources responding to incidents, using both the police radio network and the Computer Aided Dispatch (CAD) system. They provided timely information to operational police to enable appropriate action to be taken.

The Communications Officers and RDC Operators were required to complete training in telephony and police dispatch business systems. They and other general duties police officers did not receive specific training in managing emergencies and other risks on the rail network.

In this incident, communication about the motor vehicle on the rail line between the ROG and Sydney Trains occurred between an Assistant RDC Operator and the SCCO. The sequence of communication from the emergency triple zero call is described in Incident Communication and Timelines.

Driver

The driver commenced working on the New South Wales railways in 2011. They worked in the south and west region, South Coast area as part of the Wollongong crew. Review of the driver’s training records indicated they were appropriately qualified, with the most recent competence assurance assessment conducted in November 2020.

The driver was on their third shift after 4 days off. The 3 shifts were all early starts, with the earliest start of 0200 on the morning of this incident. 

At interview the driver stated they felt alert while driving, the early start was a regular starting time and they had adjusted to the early starts. The investigation did not find fatigue to be a contributing factor to the collision.

Guard

The guard had worked on the rail since 2006. They also worked in the south and west region and South Coast area as part of the Wollongong crew. Review of the guard’s training records indicated they were appropriately qualified with the most recent competence assurance assessment conducted in December 2020. The guard completed Digital Train Radio System Cab User training in July 2016. They had not received any refresher training or additional training in the use of the DTRS.

The guard was on their third shift after 2 days off. The 3 shifts were all early starts, with the earliest start of 0154 on the morning of this incident. The investigation did not find fatigue to be a contributing factor to the collision.

Security

Since the opening of the ROC in 2019, Security merged its two functions of the Security Control Centre and the Security Monitoring Facility and both share a location on the CRF (Figure 8).

Security Control Centre

The Security Control Centre (SCC) provided the security incident command and control function and liaised with the NSW Police and emergency services to manage real-time response to incidents on the rail network. The SCC acted as a communication bridge between external stakeholders and internal stakeholders within the ROC as well as Sydney Trains and NSW Trains employees.

The Security Control Centre was tasked with real‑time monitoring of security cameras on the network. 

Security Monitoring Facility

The Security Monitoring Facility (SMF) was a security support operation. The SMF provided CCTV footage when requested from authorised GIPA staff from NSW Police, Media Unit, Workplace Conduct Unit, and NSW TrainLink. They were the only approved provider of CCTV for Sydney Trains. 

The two functions, the SCC & SMF, were led by one supervisor at the ROC.[22]

SCC Supervisor

The Supervisor of the Security section at the ROC was called the Security Control Centre Supervisor (or SCC Supervisor). This supervisor was responsible for managing and directing the activities of the Security section during the course of a shift whilst managing a team of security operators as the first line of supervision.

In emergency or crisis situations, the SCC Supervisor assisted the Rail Operations Centre and external Security Services in coordinating appropriate emergency responses. This was done in accordance with Sydney Trains’ procedures and response frameworks.

Security Control Centre Operator (SCCO)

The SCCO was responsible for utilising systems deployed within Sydney Trains Security Control Centre, to provide real time responses to security incidents and other emergencies on the rail network. 

They assisted the SCC Supervisor to achieve the functions of the Security Control Centre, such as ensuring passenger safety, preventing equipment damage and theft to assist in improving the customer experience and the overall operations of Sydney Trains.

Amongst the stated responsibilities and operational duties in the Security Control Centre standard operating procedures, the SCCO had a duty to proactively monitor live CCTV cameras across the rail network. This was over 13,000 station-based CCTV cameras and 12,000 train‑based cameras. They were also required to monitor over 800 Help Points, the Alarm Management System and the Injury Hotline.

Emergency response

At the time of this incident, the Sydney Trains emergency response processes had changed from the Incident Management Framework Parts 1, 2 and 3 to the Emergency Preparedness Framework and the Network Incident Management Plan. These documents were developed and implemented in April 2021 to accommodate the Command and Control System that Sydney Trains was adopting for management of emergencies.

Emergency Preparedness Framework

This document described the process for developing and implementing both strategic and local incident management plans to ensure Sydney Trains responded effectively and safely to critical and other emergency situations.

The framework provided the need for the development of an Incident Response Guide and Network Incident Management Plan.

Incident Response Guide

This document contained instructions for first actions to be taken when responding to an incident. It covered a number of scenarios, including train collision/derailment and security threat amongst 15 other scenarios.

On the opening page it clearly defined contact points for rail and non-rail incidents. For rail incidents the 2 key contact points were the local area controller (signaller) and/or Security Control Centre.

Network Incident Management Plan

The Sydney Trains’ Network Incident Management Plan (NIMP) established the appropriate response measures, command and control structure, roles, responsibilities, and functions to be implemented in case of an incident within the Sydney Trains Network.

The NIMP recognised incidents range in severity and must be continually monitored and assessed. They were categorised based on impact and severity before being escalated accordingly through the hierarchy of management/command in the ROC.

As stated in the NIMP, Sydney Trains used a Command and Control System that established strategic, tactical and operational hierarchy to manage rail operations. The ROC Control Room Floor (CRF) created an environment of central coordination, led by the Duty Control Manager (DCM), drawing on the knowledge and experience of key Subject Matter Expert (SME) teams.

The NIMP divided incidents into 2 categories: rail incidents and non-rail incidents.

For managing rail incidents, Sydney Trains has a 3‑tier incident management process, categorised into: 

  • Routine Incident – Level 1
  • Critical Incident – Level 2
  • Crisis Event – Level 3.

As per the NIMP, a Critical Incident (Level 2) was defined as the following;

…any threat, act, event or incident, the acute impact of which severely disrupts business or causes a sustained disruption to Sydney Trains business efforts or reputation. This category includes situations where Sydney Trains may be supporting a State response to a wider disaster or emergency.

The NIMP also stated that incidents that escalate to the Critical level must be raised with the DCM for awareness and monitoring. During a Critical Incident the NIM would maintain their primary functions as indicated in the Routine incidents category, supporting the incident tactically in collaboration with the DCM. The NIM must deploy an IRC to the incident site to assume the role of Rail Commander.

This incident was escalated to a Level 2 incident at 0419, at which point the NIM informed the DCM as required. The NIM had deployed an IRC to the incident at 0415.

Section 4 of the NIMP detailed Incident Response. In the Initial Incident Response, Sydney Trains stated:

Once an incident is imminent or occurs, the alarm should be raised as soon as reasonably practicable so that assistance can be given to protect life, property and the environment. Often this means that first contact needs to be made to workers controlling train movements on the affected track section, the contact points are: 
• Local Area Controller (Signaller); or 
• Security Control Centre (SCC) 

It also states the SCC can contact the police ROG and triple zero directly and is an efficient and timely reporting strategy. In other situations, a member of the public or an emergency service communication centre could raise the alarm.

In this incident, an alarm was raised by a member of the public calling triple zero which started a chain of communications commencing with the police ROG, to the SCCO, the TSDM, then to a Signaller and NIM and eventually through to the DCM.

Security Control Centre Standard Operating Procedures

The Security Control Centre (SCC)’s standard operating procedures (SOP) was a single document of 119 pages. Version 1.3 dated June 2021 consisted of 10 different sections. The tenth section contained 16 separate miscellaneous procedures.

The first 9 sections contained information that was duplicated from other Sydney Trains documentation. 

Duplications included Section 5 Chain of Command and Key Relationships, Section 6 The Rail Operations Centre, Section 7.1 General Control Room procedures, 7.2 Emergency communications, 7.3 Network Rules and Procedures, and Section 8 Command and Control Incident Management System. These sections covered parts of the Sydney Trains documentation that were most relevant to Security.

In Section 8, the SCC SOP recognised the command and control responsibilities with section 8.1 specifically highlighting the NIM managing incident response for Level 1 – Routine Incidents, the DCM responsible for managing Level 2 – Critical Incidents and the Crisis Event Chair (CEC) managing Level 3 – Crisis Events. 

Section 9 of the SOP covered Dispatching and Coordinating Incident Response. It stated that, ‘for ALL incidents managed by the SCC, the ‘Incident Response Checklist should be used…’

In section 9.2 the Incident Response Checklist for incidents that have an effect/impact on the rail network, the procedure prompted the SCCO to inform relevant TSDM/ NIM – MAKE SAFE. There was no reference to the Incident Response Guide developed as part of the overarching emergency management framework.

Communications

NTOSP12 – Responding to an Incident

This NSW Trains document provided the instructions for workers who became aware of or were involved in an incident. The worker was required to report the incident immediately to the relevant Network Control Officer and provide sufficient detail for the NCO to assess the severity of the incident and decide on a response.

The guard reported the incident to the Wollongong Panel Signaller at 0411:56, which they did with a work‑issued mobile phone. The guard said the train had derailed at the level crossing after colliding with a car on the tracks. The guard confirmed that there were passengers on the service and that they would walk through the train to check the welfare of passengers and the driver. The guard confirmed that the second car had derailed and was leaning to the side with lights out and that the lead carriage had derailed and was lying on its side. The guard also requested an ambulance for the driver.

NGE 206 Reporting and responding to a Condition Affecting the Network

This Sydney Trains document prescribed the rules for reporting and responding to unsafe conditions affecting or potentially affecting the network.

The rule stated conditions that can or do affect the safety of operations in the network must be reported promptly to the Signaller responsible for the affected portions of line. The rule further stated the signaller must promptly report the details of the Condition Affecting the Network (CAN) to the Network Controller and tell other affected Signallers.

Network Controllers are defined as qualified workers who on a day-to-day basis manage the safe and efficient operation of the Network. This includes the TSDM and the NIM.

The Signaller in this incident responsible for the affected portion of line was the WCP Signaller.

The report of the motor vehicle on track, which was the CAN, started from a triple zero call, which passed to the Police, the SCCO, the TSDM and then the WCP Signaller. It was highlighted in the Sydney Trains Investigation that all parties involved in the initial report of the motor vehicle on the rail line treated the incident as a routine Condition Affecting the Network (CAN) instead of an emergency.

Incident Communication and Timelines

When the emergency triple zero call was made by a member of the public, the call was initially received by a telecommunications officer who diverted the call to the Police as requested by the triple zero caller. 

This happened at 0405:52, 3 minutes and 43 seconds before the WCP Signaller made the call to the driver of C012.

The call was then received by an ROG Communications Officer who recorded relevant information and started a CAD incident which was then sent onto the relevant Radio Dispatch Channel (RDC) Operator. The RDC Operator reviewed the CAD incident and broadcast over the radio channel for in field police units to respond. The RDC Operator also arranged for an assistant RDC Operator to call the Sydney Trains SCCO. 

This call happened at 0407:37, 1 minute and 58 seconds before the WCP Signaller made the call to the driver of C012.

As per the SCC SOP, the SCCO called the TSDM at 0408:47, 48 seconds before the WCP Signaller made a call to the driver of C012.

The TSDM called the WCP Signaller at 0409:08, 27 seconds before the WCP Signaller made the call to the driver of C012.

By the time the WCP Signaller was told to stop all train services, then acted to call C012 directly to tell them to stop, it was 0409:35. Only 1 second before the driver of C012 applied emergency brakes.

Waterfall recommendations

The train set involved in this incident was the same type and configuration of the train that was involved in the 2003 Waterfall Rail Accident. As some recommendations from the Special Commission of Inquiry (SCOI) had actions against them that had not yet been completed and/or closed, they were reviewed as part of this investigation.

The review was to determine any influence and/or importance to the outcomes of this incident. While each recommendation and the associated actions are discussed below, the investigation concluded that the outcomes from this incident were not directly influenced by the status of the actions to address the Waterfall SCOI recommendations.

The Special Commission of Inquiry (SCOI) into the Waterfall rail accident released its final report on 17 January 2005. The report, titled the Final Report of the Special Commission of Inquiry into the Waterfall Rail Accident, made 177 recommendations (127 recommendations and 50 sub‑elements).

The implementation of these recommendations from this significant SCOI have been monitored by the Rail Regulator since 2005. 

As specified in the Waterfall SCOI Annual Status Reports published on the Office of the National Rail Safety Regulator (ONRSR) website, ONRSR will continue to provide the Minister with annual reports for tabling in the NSW Parliament, in relation to the SCOI Final Report. ONRSR’s public reporting will continue until all recommendations are implemented, with reports being published on ONRSR’s website. At the time of authoring this report, 3 documents on ONRSR’s website provided the status of the recommendations. These were:

  1. Waterfall Report No 39 2019
  2. Waterfall Annual Status Report – All open and closed recommendations – April 2018 to March 2019
  3. Waterfall Rail Accident Recommendations – Closed Subject to Implementation of an Approved Program or Plan – April 2018 to March 2019 

These documents reported that all recommendations from the SCOI report were considered closed except for two. These recommendations had an acceptable response or acceptable alternative response. Six other recommendations were closed subject to implementation of an approved program or plan. That is, the Rail Regulator had agreed that the planned action or alternative action, when completed would meet the recommendation or satisfy the objective of the recommendation. 

Open recommendations

No.32 – RailCorp should progressively implement, within a reasonable time. Level 2 automatic train protection (ATP), and

No.38 – There must be compatibility of communications systems throughout the rail network. It is essential that all train drivers, train controllers, signallers, train guards and supervisors of trackside work gangs in New South Wales be able to communicate using the same technology.

Recommendation No.32 – Automatic Train Protection

At the time of authoring this report, Transport for NSW (TfNSW) had implemented ATP (European Train Control System Level 1 Limited Supervision) on the Sydney Trains Network (excluding Erskineville to Bondi Junction and the Sydenham-Bankstown Line). 

TfNSW was in process of implementing the ‘Digital Systems Program’ (DSP) which upgrades the technology to European Train Control System Level 2 (ETCS L2). 

This program introduces the ETCS L2 and Traffic Management System (TMS) to parts of the T4 Line from Sutherland to Cronulla and from Redfern to Bondi Junction (Tranche 1). It will then be rolled out on North Shore, City Circle, City Area and Sydney Terminal (Tranche 2)as indicated in Figure 10.

System integration testing commenced in December 2023 and would be run in 3 phases and is planned for completion by end 2024.

ETCS L2 and TMS will replace current signalling and train control technology and allows trackside equipment to communicate with trains constantly. This provides better location and train information, to better manage train movements across the network. 

The relationship to Recommendation No.4 – Precise Location is discussed below. 

DSP rollout was planned in stages (tranches) and will cover the entire network including the South Coast rail line. The future tranches will be aligned with asset replacement (conventional signalling) and network needs and is subject to funding approval.

Figure 10: ETCS Level 2 rollout

Figure 10: ETCS Level 2 rollout

 Source: Transport for NSW

Recommendation No.38 – Digital Train Radio System

It was noted, the action to address Recommendation 38 became the focus of implementing a Digital Train Radio System (DTRS). A DTRS was installed in the incident train and serving as the main means of communications between the train crew and network control.

When the guard attempted to contact Network Control after the collision and derailment, the DTRS did not work. However, post‑incident testing of the DTRS established the DTRS had become inoperable due to a short-circuit tripping the guard’s Control Circuit Breaker likely because of the collision and derailment. The DTRS returned to “stand‑by mode” which required the system to be reset to be operable again. This could have been done by the guard, however the guard called Network Control using a work‑issued mobile phone.

In Sydney Trains’ investigation, a safety action was taken to communicate to train crew that the DTRS can be made operable by resetting the guard’s Control Circuit Breaker switch. However, in this incident, the decision by the guard to use the secondary mechanism of communication (the mobile phone) was likely a quicker and just as effective method of contacting Network Control due to the time required to restart the system.

Had the incident occurred on a part of the network with poor mobile reception, then the guard would need to rely on the DTRS being operable. So, the safety action to remind train crew the DTRS can be reset was relevant. Additionally, the same reset function applied to the public announcement (PA) system, which had also been tripped and rendered inoperable.

The focus of recommendation 38 was to ensure compatibility of communication systems throughout the rail network. While the DTRS was not used by the guard to contact Network Control, it was not due to incompatibility of communication systems.

To ensure the intent of this recommendation is met, the Regulator will continue to ensure functionality and compatibility requirements are met across the rail networks in New South Wales.

Closed recommendations subject to implementation of an approved program or plan

No. 4    The Rail Management Centre should be equipped by RailCorp with a transcriber system, or mimic board, or such other system as is necessary to enable identification of the precise location at any time of any train on the RailCorp network. 

No.88   The RailCorp passenger containment policy must be abandoned. (RailCorp: Implemented – containment policy abandoned). Note: This recommendation will be finalised once Sydney Trains completes the rollout of its Internal Emergency Door Release (IEDR) retrofit program. 

No.89   There must be a minimum of two independent methods of self-initiated emergency escape for passengers from all trains at all times. 

No. 90  All passenger trains must be fitted with an internal passenger emergency door release. 

No. 92  The internal passenger emergency door release should be fitted with a facility which prevents it from operating unless the train is stationary. 

No. 93  The operation of train doors should have an override facility whereby the driver or the guard can override an internal passenger emergency door release system if the door release is interfered with when there is no emergency. There should be an alarm, together with an intercom, in the guard’s compartment so that, if a passenger attempts to initiate an emergency door release, there is an appropriate delay during which time an alarm sounds in the guard’s compartment and the guard can then, after first attempting to speak via the intercom to the individual concerned, if necessary, override the door release, and make an appropriate announcement over the intercom system in the train.

Recommendation No.4 – Precise Location

At the time of this incident, the South Coast Branch Line, where Kembla Grange Station is located, was in a track circuited territory where the system of safe working relied on track circuits to detect the presence of rail traffic.

As a train traverses a track circuited area, it disrupts the electrical currents flowing through the rails which can then be used to indicate the position of the train. Lights are illuminated on a train location board (see Figure 11) to allow the network controller to get an indication of the location of the train.

The distance between Dapto Train Station and Kembla Grange Train Station is 3.4 km and the network controller has several location indicator lights between these 2 stations to provide an indication of where the train is located.

While this by no means provides a precise location of a train, it could be argued that this is a reasonable indicator for the network controller to know where a train is at a given time.

This was evidenced in this incident when the WCP signaller was aware C012 was in the track section between Dapto and Kembla Grange and was able to respond to the TSDM by saying they would make direct contact with C012, when the TSDM said to stop all services.

Figure 11: Train location board – Wollongong Signalling Complex

Figure 11: Train location board – Wollongong Signalling Complex


Source: Sydney Trains. Kembla Grange located top left, Dapto located top right. C012 was travelling from Dapto towards Kembla Grange at the time of the incident.

The ability for network controllers to identify the precise location of a train on the rail network has been further enhanced as Sydney Trains continues to improve train position reporting.

The implementation of ETCS involves the installation of balises (electronic transponders) that are placed along the rail line and communicate with the train’s onboard system to provide location information.

The ETCS onboard system continuously estimates the current location of the train based on the distance travelled since the last balise was read using onboard odometry information and sends this position information to the ETCS trackside. A Network Controller can review an ETCS fitted trains’ reported location; however, this information is not presented on the Traffic Management System (TMS) screen in real time. The reported location information is limited by odometry accuracy.

The ETCS L2 system will enhance the train location information available to network controllers by

• Enabling smaller sections

• Providing more granular estimated train location information

Note – Track circuits are replaced by axle counters in ETCS L2 areas.

Recommendation No.88 – Containment

The train in this incident had not been retrofitted with the Internal Emergency Door Release (IEDR). At the time of this incident, a project aimed at enhancing the existing Tangara Fleet of trains in Sydney had commenced. The Tangara Technology Upgrade (TTU) Project was a collaborative endeavour, with TfNSW, Sydney Trains, contractors, and industry experts working together to enhance the Tangara trains. It was scheduled to be completed by 2025.

At the time of authoring, the current TTU project scope did not include internal emergency release mechanisms. However, internal emergency door release mechanisms would be installed as part of another project being managed and delivered by Sydney Trains, the Tangara Fleet Life Extension (TFLE) project. In the upgraded Tangara trains, passengers would have the ability to manually release doors from the inside, allowing for swift evacuation if needed. This enhancement aligned with modern safety standards and provided an additional layer of security for commuters.

It was however, noted that extraction of the passengers from the first carriage, that had tipped over, was completed by entry and exit through the rear of the carriage where there remained an opening from the first and second carriages separating. This opening provided a more accessible means of entering and exiting the carriage, compared to opening a side door and having to climb up and out.

The driver was also able to be rescued from the front cab of the carriage as the front emergency door could be opened (Figure 12).

Recommendation No.89 – Emergency escape

On the Tangara the 2 independent methods were the external sliding doors and the intercar doors into the next carriage. In the Kembla Grange incident as there was a separation between the first and second carriages as a result of the derailment, the intercar doors served as the means of entry and exit for the passengers from these carriages.

As the IEDR had not been installed on these carriages at the time of the incident, the second independent method of self-initiated emergency escape for passengers was not available.

The driver was extricated from the emergency door at the front of the train.

Figure 12: Emergency door at front of train

Figure 12: Emergency door at front of train

 Source: OTSI

The other 3 closed recommendations (90, 92, and 93) all relate to the installation and functionality of an internal emergency door release. As mentioned above, this train set had not yet had the IEDR retro fitted. 

Similar related incident

Collision of NSW Trains Intercity train N169 with abandoned motor vehicle Woy Woy, NSW 19 April 2024

At approximately 1756 hours on Friday 19 April 2024 at Rawson Road level crossing Woy Woy, New South Wales, an eastbound motorist turned left at the level crossing and accidentally drove their motor vehicle into the railway corridor. The driver exited the motor vehicle after it became stuck on the railway tracks.

Two witnesses arrived at the scene at approximately 1757 and reported they observed the motorist exiting the vehicle and a bystander getting into the vehicle to assist the driver to move it.

At around this time Witness 1 called a tow truck driver.

Witness 2 tried to confirm with bystanders onsite whether triple zero had been called. When they did not receive a response, they called triple zero, confirmed from phone records to have been at 1759. 

Witness 2 reported experiencing delays through the triple zero triage process as the operator appeared to have difficulty comprehending the situation and the location. When eventually dispatched through to the police the witness reported the car stranded on the tracks. 

After the phone call to the tow truck driver was completed, Witness 1 contacted the Network Incident Manager (NIM) by dialling the phone number displayed on the lineside signage and level crossing identification number for fault reporting. This call was received by the NIM at 1802:04. 

An approaching train activated the Rawson Road level crossing at 1802:30, which was heard in the background of the phone call between the NIM and the witness. This call was terminated and the NIM placed a priority call to both the Central Coast and Hornsby North Signalling panel operators, to initiate an emergency “All Stop” message through the Digital Train Radio System (DTRS). 

Central Coast issued an emergency all stop at 1802:55. The train driver reported hearing the broadcast just prior to the vehicle being struck.

At 1803:22 approximately 4 minutes after the triple zero call was made, and after the vehicle had been struck, the Police Radio Operations Group (ROG) Operator contacted Sydney Trains SCCO with the first notification of the motor vehicle on the tracks at Rawson Road level crossing. The ROG Operator conveyed police patrols had reached the site and the train had just collided with the car and that the car was unoccupied.

In social media footage of the collision police sirens can be heard in the background indicating police had been despatched to the incident prior to the ROG Operator reporting the obstruction to the SCCO. It is possible that had Sydney Trains received a call advising of the track obstruction from:

  • Witness 1 before they rang the tow truck driver
  • the ROG Operator immediately after the triple zero call from Witness 2, 

the train driver of N169 may have received advice of the vehicle on the rail line in time to slow or stop short and prevent the collision.

Sydney Trains investigated this incident. During their investigation they found the NIM was unable to make Rail Emergency Calls (RECs) using their DTRS as the function was not switched on. This decision was made at the time the ROC commenced operations. It was noted that the NIM DTRS could still make point to point calls to trains. 

Sydney Trains commented, given the NIM’s span of management over the network, point to point calls may not be practical in an emergency situation, hence the decision made by the NIM, in the Woy Woy incident, to bring in the Area Controllers was the best method of stopping trains at that time.

Rail Operations Management in Sydney Trains were not aware of the REC facility not being available to NIM terminals and this was not detected in their investigation of the Kembla Grange incident. 

Safety analysis

Trespassing in the rail corridor and abandoning a motor vehicle on the rail line led to the collision and derailment of train C012 just south of the West Dapto Road Level Crossing at Kembla Grange.

The incident presented some opportunities which may have led to mitigation of the incident, and these have been discussed below.

Opportunities to mitigate risk

There were 2 opportunities which may have led to train C012 being stopped before it collided with the abandoned motor vehicle.

The first was when the individual who abandoned the motor vehicle tampered with the security CCTV cameras. The cameras were located on the Kembla Grange Station platform and positioned at the West Dapto Road Level Crossing. The individual tampered with the CCTV cameras approximately 45 minutes before the collision occurred.

The second opportunity to mitigate the event arose when a member of the public called triple zero to notify the police of the abandoned motor vehicle on the rail line approximately 4 minutes before the collision occurred.

Both opportunities are discussed further below.

After the collision and derailment occurred, there was a risk of further escalation of the incident. The Digital Train Radio System was not available for the guard to report the incident and there was potentially live 1,500 V overhead wires at ground level post‑incident on the accident site.

These issues are also discussed further below.

Security Control Centre operators unaware of camera tampering

On the morning of the incident at 0313 a Sydney Trains’ security camera located on the Kembla Grange Station platform recorded an individual moving the security camera. CCTV then captured images of the same individual moving the level crossing cameras away from the level crossing to face directly downwards at 0326, approximately 45 minutes before the collision.

Sydney Trains Security Control Centre was not aware the camera had been moved until 0412:57, 3 minutes 17 seconds after the collision. The SCCO identified the camera movement during the phone conversation with the ROG, which occurred after the collision and derailment.

There was an opportunity for Sydney Trains to detect a security risk at 0313 and 0326, and perhaps stop the sequence of events which led to the vehicle on the track.

Had the camera movements been detected there may have been an opportunity for the Security Control Centre to deploy rail security or police to the scene. These responders may have stopped the individual from attempting to cross the track or detected the presence of a vehicle on the tracks.

While it cannot be said with certainty that events after the detection of a camera being tampered with would have prevented the motor vehicle being stuck, early detection of, and proactive response to camera tampering may provide the opportunity to intervene when security risks such as this occur.

CCTV monitoring

The Security Control Centre’s Standard Operating Procedures (SCC SOP) suggested the Security Control Centre provides proactive monitoring of the entire Sydney Trains rail network. Page 10 states that operators proactively monitor over 13,000 station‑based CCTV cameras and 12,000 train‑based cameras, over 25,000 cameras in total. 

The SCC SOP detailed the floor plan and desk set‑up for the Security Control Centre operators and provided the minimum staffing levels for given shifts. While much of the time 4 Security Control Centre operators were rostered to live monitor the rail network, there could be up to 5 Security Control Centre operators on some shifts or during night shifts as few as 3 operators.

The task of monitoring some 25,000 station and train‑based cameras was, therefore, as detailed in the SCC SOP, expected to be effectively managed by 3 to 5 individual operators depending on the numbers on shift.

The Security Control Centre operators were each assigned a particular area to monitor e.g. Console 4 live monitors the Illawarra and Bankstown Lines. This operator was responsible for live monitoring over 3,000 cameras.

This monitoring involves an individual overseeing many cameras on monitors at a desk. As a result, it is not possible to effectively monitor all assigned cameras at the same time, or reliably monitor camera changes, as in this incident where camera tampering was not detected.

Tamper alarms 

Installation of tamper alarms on cameras was identified and agreed to by Sydney Trains as a reasonable measure to improve the security of the rail network. Tamper alarms provide an opportunity to improve proactive live monitoring as Security Control Centre operators in principle should be immediately alerted to a tampering event. This would then enable the Security Control Centre operator to act expeditiously. 

A CCTV Upgrade Project to install tamper alarms on all cameras across the rail network was started in 2015. The scope of the CCTV Upgrade Project was amended during implementation, when excessive false alarms were encountered. The scope was amended to place tamper alarms on all cameras that were under 2.4m in height or were covering specific assets, such as level crossings, or any camera with a history of vandalism. Sydney Trains identified in their investigation of this incident that the revised tamper alarm functionality had not yet been fully implemented. Including activation of the tamper alarms on the West Dapto Road Level Crossing, even though it was identified for activation.

The Sydney Trains Network Maintenance group took charge of the project in December 2020 and a CCTV Operational Working Group was formed to continue progress from February 2021. Progress on installing these tamper alarms was continuing at the time of publishing this report.

The opportunity for detecting these types of events remains significantly lower while the installation of tamper alarms or alternative solutions remained outstanding. 

No alert to train crew

In this incident, the train crew was not alerted to the abandoned motor vehicle on the track in time for them to slow or stop the train to avoid a collision or mitigate the outcomes. The recorded radio call from the WCP Controller to C012, highlighted the WCP Controller attempting to call C012 at 0409:35 and there was no response. 

There was an opportunity for the collision and derailment to be avoided when a report of a motor vehicle on track came from a triple zero call from a member of the public at 0405:52. Sydney Trains was not alerted to this until 0407:37, which meant there remained approximately 2 minutes for a message to be provided to C012 to stop prior to the collision at approximately 0409:35.

This time was taken up with the passing of information from the SCCO to the TSDM and then to the WCP Signaller, who then made the call to C012 via the DTRS at about the same time the driver of C012 applied emergency brakes on the train.

The audio recording of these calls highlighted emergency awareness as an area for improvement. If the message had reached the driver of C012 in time, they could have slowed or stopped the train which could have prevented the collision from occurring or lessened the outcome.

Rail emergencies

The definition of an emergency in the railways is essentially any incident requiring urgent action which might involve death or serious injury, health and safety effects and/or significant damage to property or infrastructure[23].

A vehicle obstructing the rail line presents an immediate threat to the safety of train crew and the travelling public and therefore requires immediate action to stop all train services in the vicinity to prevent collision and escalation.

There is a level of understanding about rail operations that the ROG would glean over time through the interactions they have with the Sydney Trains Security Control Centre, however a firm understanding of what constituted an emergency on the rail line would not be expected to be known by the ROG without clear instruction or rail emergency training. As the ROG is the first contact point from a triple zero call about a rail emergency, it would be reasonable to review whether rail emergency awareness training should be provided to ROG Communications Officers and RDC Operators.

The SCCO is the first point of call into Sydney Trains from the ROG for these types of emergencies.

As a rail employee, the SCCO receives relevant training to identify rail emergencies. However, Sydney Trains stated in its internal investigation that the SCCO had not received any training in responding to emergencies since 2017.

Emergency situations are times when people are required to make fast and deliberate decisions and take actions to mitigate further escalation of consequences. As the SCCO had not received regular emergency refresher training in the preceding 4 years, their appreciation and understanding of how to react in an emergency was likely not at a competency level required for an effective response.

The SCCO’s response reflects this as they took considerable time to verify and confirm with the Assistant RDC Operator that there was a motor vehicle stuck on the rail line before they made the call to the TSDM. The Assistant RDC Operator stated there was a report of a car stuck on the rail line 19 seconds into the conversation with the SCCO. Valuable time was used up and at 47 seconds into the conversation the SCCO asked if it is confirmed a motor vehicle is on the train tracks? Then at 58 seconds asks, are “they” inside the corridor? To which the Assistant RDC Operator needs to confirm if the SCCO means the deployed NSW Police. All taking up critical time to potentially stop a collision and further escalation.

It took 1 minute and 10 seconds before the SCCO made a call to the TSDM.

Without suitable training and practice exercises in emergency situations, the SCCO was possibly slower to respond to the information given to them by the Assistant RDC Operator. In a role that is required to understand and act expeditiously when emergencies arise, the level of training and exercising of the appropriate response for SCCOs is important.

Performing well in a situation that arises on rare occasions is not guaranteed when that individual has not been provided training in emergency response for many years.

A report of a motor vehicle stuck or any significant object on the rail line poses an immediate threat to life and the safety of train services and should be treated as an emergency. With appropriate training and/or instruction the reaction to this information should be to take immediate action to stop train services to avoid collision and prevent escalation.

Management of rail emergencies

As discussed previously, there was inconsistency between the SCC SOP and NIMP.

The NIMP required all incidents to be reported to the NIM or the DCM to be managed, however the report from the SCCO of the incident was directed to the TSDM.

An explanation for this was presented in Sydney Trains’ internal investigation, that being, the SCCO perceived the situation as a routine Condition Affecting the Network (CAN), rather than as an Emergency (which is a type of CAN requiring a more urgent response).

This incident was an emergency as defined by the NIMP and therefore needed to be treated in accordance with the NIMP. The NIMP required that once the incident is imminent or occurs, first contact needs to be made with workers controlling train movements on the affected track section.

This is the accepted and accredited process for Sydney Trains Network Incident Management.

When the SCCO called the TSDM after they were informed of a motor vehicle on the track, the incident was not managed in accordance with the requirements of the NIMP. This incident required a call to the NIM or the DCM to manage. That said, the TSDM in this instance acted quickly to advise the signaller to stop all trains. 

Procedure with conflicting instructions

The Sydney Trains Security Control Centre Standard Operating Procedure (SCC SOP) contained conflicting instructions for incident response. While referencing the Command and Control System as the new Incident Management System that is detailed in the Network Incident Management Plan (NIMP), the SCC SOP also introduced the TSDM to the incident response process.

Page 59 of the SCC SOP contained the 'Incident response checklist'. This checklist is to be used for all incidents managed by the Security Control Centre.

Its purpose, to provide prompts for the SCCO in the event of an incident that may have an effect or impact on the rail network. The SCCO is instructed to "Inform relevant TSDM/NIM - MAKE SAFE."

The SCC SOP introduced the TSDM as a point of contact in an incident, however, the Sydney Trains NIMP only states the NIM and DCM, as the points of contact, for Level 1 and 2 incidents.

The NIMP provides a clear statement of roles and their responsibilities for managing network incidents. There is no mention in the NIMP of a role for the TSDM in the command and control system.

Sydney Trains also identified in their internal investigation an issue with inclusion of the TSDM in the Security Control Centre procedures.

Page 30 of the Sydney Trains Investigation report stated:

The current SCC Standard Operating Procedure v1.3 and informal procedure allowed for the TSDM to be informed of the motor vehicle on the running line to determine the response, instead of specifying only the NIM, introducing an additional line of communication with no access to the DTRS.'

This highlighted that inclusion of the TSDM in the lines of communication slows response to an individual that has access to the DTRS (and hence an ability to STOP train services). Sydney Trains also highlighted in their investigation that an alternative solution to getting the SCC SOP and Sydney Trains NIMP processes consistent, would be to consider the processes that are occurring already as embedded and instead provide the TSDM with the ability to stop all train services when an incident such as this one occurs.

Given the competence displayed by the TSDM in this incident, the alternative solution proposed by Sydney Trains, to give the TSDM access to the DTRS and the ability to stop all train services when required is worthy of assessing for feasibility of implementation.

In the related Woy Woy incident, the NIM still opted to call the signaller to place an emergency broadcast, rather than placing a point to point call themselves, as they determined that this was the most effective means to stop the train. This was required as the REC functionality on the NIM’s DTRS had been turned off. NIMs could still make point to point calls to trains but not emergency broadcasts. This was the status of the NIM DTRS functionality at the time of the Kembla Grange incident, and this status was unknown to Sydney Trains Rail Operations Management. 

However, awareness of the issue has led to further technical advice being sought regarding the practicality of switching on the REC facility on NIM DTRS terminals, with a view to determining the best method/ shortest practical communication chain to stop trains in emergency situations.

Digital Train Radio System

The DTRS on Set T42 did not work when the guard attempted to call the Signaller after the train had collided with the motor vehicle, derailed, and separated. After the derailment and separation, the Signaller made attempts to contact the driver on the DTRS but was unsuccessful.

Sydney Trains investigated the functionality of the DTRS after the incident. They found the DTRS was working as required. The radio unit on the train had gone into stand‑by mode likely because of a short circuit in the guard’s control circuit breaker unit, which occurred when the train collided, and the first carriage separated.

For the guard to be able to use the DTRS again, it required the guard to reset it.

In post‑incident testing of the DTRS, a reset of the unit was conducted, and it took approximately 30 seconds for the radio to restart after the guard key in and another 50 seconds to get through the service menu to make an emergency call.

In this emergency where the guard was in a heightened state of arousal, 80 seconds is a considerable time to wait for the radio to be usable again. Had there been no other option, then the DTRS would have been available for the guard to use after a reset, provided they had appropriate instruction on how to reset it.

In this instance the guard had a second option available which was to use a mobile phone to contact the network controller. This option was a quick and effective way of reporting the situation.

High voltage risk

As a consequence of the collision and derailment, the front carriage collided with a high voltage stanchion, bringing it to the ground along with 1,500 V overhead wires.

The Electrical Operations Centre (EOC) was alerted to a sustained fault between Unanderra and Dapto and notified the NIM approximately 4 minutes after the collision. It is highly probable the sustained fault was caused by the front carriage bringing down the high voltage stanchion. This sustained fault meant the power through the overhead wires in this section had been cut off however, verification of power being cut from the overhead had not been conducted.

Instruction from the NIM was for everyone to treat the overhead wires as live until the Rescue Power Outage (RPO) was issued.

At 0411:56, 2 minutes 16 seconds after the collision, the guard was reporting the incident to the WP Signaller. During this call the guard tells the WP Signaller that the police are onsite. 

At this point, the Incident Rail Commander (IRC) had not made it to site to take control and there had been no verification of high voltage power being cut out. With no other qualified person onsite, the guard had assumed the role of Site Controller.

It is important to highlight the competence of the guard, and their training, as it enabled them to inform the police and other first responders to watch out for the high voltage danger of the overhead wires and live portion of the train.

Additionally, a secondary avenue of mitigating risk exposure to the police was in action through the communication chain between the SCCO and Assistant RDC Operator informing emergency personnel on site to treat the wires as live.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the collision between passenger train C012 and a motor vehicle on track near West Dapto Road level crossing, Kembla Grange, New South Wales, on 20 October 2021.

Contributing factors

  • An individual abandoned a motor vehicle on the rail line south of West Dapto Road Level Crossing, Kembla Grange.
  • Train C012 collided with the abandoned motor vehicle south of West Dapto Road Level Crossing and derailed.
  • The driver of C012 was not alerted to the abandoned motor vehicle on the rail line in time to stop the train prior to colliding with the vehicle and derailing.

Other factors that increased risk

  • An Individual tampered with CCTV cameras monitoring the West Dapto Road level crossing at Kembla Grange Station without being detected.
  • Sydney Trains Security Control Centre Operator was not alerted to tampering of the cameras at Kembla Grange Station that monitored the West Dapto Road level crossing.
  • Sydney Trains Security Control Centre Standard Operating Procedure contained conflicting instructions on incident response, which were not aligned with the Sydney Trains Network Incident Management Plan (NIMP).
  • Report of a motor vehicle stuck on the rail line was not treated as an emergency.
  • There was a risk to the guard and first responders who attended to the driver and injured passengers, when the potentially live 1,500 V overhead wires came down to ground level.
  • When the guard tried to make an emergency call on the Digital Train Radio System, they could not use it to contact Network Control in a timely manner.

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the [aviation, marine, rail] industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out or are planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Sydney Trains Security Control Centre Operator unaware CCTV cameras tampered with at Kembla Grange Station

Safety issue number: RO-2021-012-SI-01

Safety issue description: Sydney Trains Security Control Centre Operator was not alerted to tampering of the cameras at Kembla Grange Station that monitored the West Dapto Road Level crossing.

Response by Sydney Trains: CCTV software has been recently upgraded to allow use of a centralised server-based analytics engine to provide alarm functionality. Additionally, Sydney Trains has purchased software licenses to allow development / testing / trialling of this software. It is believed that the more sophisticated analytics available will allow detection of incidents such as the tampering at the West Dapto Level Crossing while reducing the false alarm rate.

ATSB comment: This action is appropriate to ensure a risk control for trespassers on the rail line being detected is in place. In the interim period, while the control is being developed, tested and trialled, without any other control for tamper detection, the trespasser risk remains untreated.

Sydney Trains Security Control Centre Operator procedure contains conflicting instructions on incident response

Safety issue number: RO-2021-012-SI-03

Safety issue description: Sydney Trains Security Control Centre Standard Operating Procedure contained conflicting instructions on incident response, which were not aligned with the Sydney Trains Network Incident Management Plan (NIMP).

Response by Sydney Trains: The Security Control Centre Standard Operating Procedure has now been aligned with the Sydney Trains Network Incident Management Plan with Security Control Centre Operators required to contact NIMs rather than TSDMs, and, Security Control Centre Operators' initial training in responding to emergencies has been upgraded (initial training module - STSCC02C - Knowledge & Skills) so that initial training around communicating during emergencies is improved and a recertification module (STSCC07A - SCC - Competency Assurance Assessment) is currently under development and will be provided as refresher training. 

It is expected that the refresher training will be provided to operators every 12 months.

ATSB comment: The actions taken by Sydney Trains as described above addresses the inconsistencies previously in the safety management system. The safety issue is considered closed adequately addressed.

Glossary

CADComputer Aided Dispatch
CCTVClosed Circuit Television
CRFControl Room Floor
DCMDuty Control Manager
DTRSDigital Train Radio System
EOCElectrical Operations Centre
ETCSEuropean Train Control System
IEDRInternal Emergency Door Release
IRCIncident Rail Commander
NIMNetwork Incident Manager
NIMPNetwork Incident Management Plan
ONRSRThe Office of the National Rail Safety Regulator. Administered and enforced compliance with the Rail Safety National Law and Regulations.
RDCRadio Dispatch Channel
RECRail Emergency Call
ROCRail Operations Centre
ROGRadio Operations Group
RPORescue Power Outage
RISSBRail Industry Safety and Standards Board. Responsible for the provision of standards, codes of practice, guidelines, rules, safety data and analysis for the Australian rail industry.
SCCOSecurity Control Centre Operator
SOPStandard Operating Procedure
TSDMTrain Services Delivery Manager
WCPWollongong Coast Panel
WPWollongong Panel

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the Driver of C012
  • the Guard of C012
  • Train data logger from D6212 and D6211
  • Sydney Trains CCTV cameras
  • Sydney Trains audio communication systems
  • Sydney Trains documented management systems
  • NSW Trains documented management systems
  • Transport for NSW
  • NSW Police Investigation

References

ONRSR annual implementation reports on the NSW Government response.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any individual whom the ATSB considers appropriate. That section allows an individual receiving a draft report to make submissions to the ATSB about the draft report. 

A draft of this report was provided to the following directly involved parties:

  • Driver of C012
  • Guard of C012
  • NSW Trains
  • Sydney Trains
  • Transport for NSW
  • ONRSR
  • NSW Police

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Rail safety investigations in New South Wales

Most transport safety investigations into rail accidents and incidents in New South Wales (NSW) and Victoria are conducted in accordance with the Collaboration Agreement for Rail Safety Investigations and Other Matters between the Commonwealth Government of Australia, the State Government of NSW and the State Government of Victoria. Under the Collaboration Agreement, rail safety investigations are conducted and resourced in NSW by the Office of Transport Safety Investigations (OTSI) and in Victoria by the Chief Investigator, Transport Safety (OCI), on behalf of the ATSB, under the provisions of the Transport Safety Investigation Act 2003.

The Office of Transport Safety Investigations (OTSI) is an independent statutory body which contributes to improvements in the safety of bus, ferry and rail passenger and rail freight services in NSW by investigating safety incidents and accidents, identifying system-wide safety issues and sharing lessons with transport operators, regulators and other key stakeholders. Visit www.otsi.nsw.gov.au for more information.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2024

Title: Creative Commons BY - Description: Creative Commons BY

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1]     EDT: Coordinated Universal Time (UTC) + 11 hours.

[2]     The SCCO was responsible for utilising systems to provide real time responses to security incidents and other emergencies on the rail network (see The Security Control Centre Operator (SCCO) page 17).

[3]     Electronic transponders are located at various locations on the Sydney Trains Network to monitor train speeds.

[4]     The TSDM is responsible for the day-to-day management of train service delivery (see Train Services Delivery Manager (TSDM) page 14).

[5]     The WCP Signaller was responsible for signalling operations on the South Coast rail line from Berry to Kembla Grange (see Wollongong Coast Panel Signaller (WCP Signaller) page 14).

[6]     The WP Signaller was responsible for signalling operations from Port Kembla to Wollongong and sat adjacent to the WCP Signaller in the Wollongong signalling complex (see Wollongong Panel Signaller (WP Signaller) page 15).

[7]     The NIM is responsible for managing operational rail incidents that happen on the network (see Network Incident Manager (NIM) page 14).

[8]     Signals placed at STOP with blocking facilities applied prevents other rail traffic from entering the area.

[9]     The EOC is responsible for the monitoring and repair of overhead wiring systems (see Electrical Operations Centre (EOC) page 16).

[10]    Radio Operations Group (ROG) is NSW Police communications (see Police Radio Operations Group (ROG) page 15).

[11]    IRCs provide onsite incident management for significant and major rail incidents within Sydney Trains network (see Incident Rail Commander (IRC) page 15).

[12]    The Work Group Leader Traction was the Supervisor of the maintenance team responsible for work on Train Traction Systems.

[13]    A Level 2 incident is a Critical event which severely disrupts the business (see Network Incident Management Plan page 18).

[14]    The DCM leads the day of operations for all people on the Control Room Floor (CRF) and is also responsible for managing Level 2 – Critical incidents on the rail network.

[15]    A Rescue Power Outage (RPO) temporarily removes power from the overhead lines for rescue of injured persons where contact with 1500 V overhead wire is a risk.

[16]    A Level 3 incident is a Crisis event and considered an emergency, in line with the State Emergency and Rescue Management Act 1989 definition (see Network Incident Management Plan page 18).

[17]    The emergency authority was the Electrical Authority for Removal of Supply from 1500 V overhead wiring system.

[18]  A bi-directional rail line allows trains to travel, at different times, in both directions on the same rail line.

[19]    A pantograph is a device mounted on the roof of an electric train, tram, or electric bus. It collects power by contacting an overhead wire or line which allows the vehicle to draw electrical energy to operate.

[20]    A track component consisting of paired pieces of tapered rail that can be moved and set to allow tracks to diverge or converge.

[21]    A fixed signal placed near a running line to authorise and control running movements.

[22]    The Security section in the ROC is referred to as the ‘Security Control Centre’ by Sydney Trains and this report will use the term SCC to refer to the entirety of the Security section at the ROC.

Occurrence summary

Investigation number RO-2021-012
Occurrence date 20/10/2021
Location Kembla Grange
State New South Wales
Report release date 25/10/2024
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Collision
Occurrence class Accident
Highest injury level Serious

Train details

Train operator NSW Trains
Train number C012
Type of operation Passenger
Departure point Kiama, New South Wales
Destination Central Station, New South Wales
Train damage Substantial

Derailment of coal train 9QJ5, near Mount Rainbow, Queensland, on 30 October 2021

Final report

Report release date: 30/01/2024

Executive summary

What happened

On 30 October 2021, empty coal train 9QJ5 travelling west to Moura mine, derailed at the 99.270 km point between Mount Rainbow and Dumgree, Queensland. A total of 20 wagons and 2 remote locomotives (mid-train) derailed.

The derailment occurred following ballast undercutting work that had been completed 2 days prior. Two empty coal trains heading west had travelled over the section, without incident, prior to train 9QJ5.

What the ATSB found

The ATSB found that train 9QJ5 derailed likely due to a track irregularity following track disturbance works between Mount Rainbow and Dumgree. The track irregularity likely developed under the passage of the train.

The rail stress-free temperature, near the point of derailment, was not adjusted following the track work as planned. Consequently, the track was likely left in a stressed condition when the track was handed back fit for service.

It was also established that temporary track monuments had not been regularly placed throughout the worksite, being only used for about the final 200 m of work. While this was not considered contributory to the derailment, this increased the risk of the track not being returned to the correct position following track disturbance work.

Further, after the track disturbance works had been completed, a temporary speed restriction of 40 km/h was not applied to assure safe passage over that section of track. This was particularly important given that the rail stress-free temperature was unknown at that time.

What has been done as a result

Aurizon has implemented various safety actions, including developing and implementing a rail stress worker course, conducting roadshows to discuss the Track Stability Manual, reviewing and updating the manual, and creating a rail stress appreciation course. In addition, they have updated the site assessment walkout templates with rail stress information and issued a toolbox talk to infrastructure workers, reinforcing procedural requirements during track-disturbing work to maintain track stability.

Safety message

This accident highlights the importance of assuring track stability following disturbance work through having a correct rail stress‑free temperature, which is critical to rail safety. Likewise, track stability assurance also relies on the use of accurate track offsets, during, and temporary speed restrictions, following, track disturbance work.

 

The investigation

Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

Scheduled maintenance

On 27 October 2021, at about 1230 local time, Aurizon’s RM902 ballast cleaning machine began ballast undercutting work along a section of track between Dumgree and Mount Rainbow, Queensland, from 99.800 km to 98.300 km. The work was part of planned track maintenance on Aurizon Network’s Moura system, integrated possession number 75, between Graham and Dumgree (Figure 1).

Due to operational considerations, ballast undercutting work concluded early at about 2020, completing 554 m between 99.840 km and 99.286 km. The RM902 ballast cleaning machine departed the site at 2255.

On 28 October 2021, ballast resurfacing was conducted over the same section and was completed at 1140. Following this, local level crossings were re-established and, at 2245, the SW05 form (the authority for the work between Mount Rainbow and Dumgree) was provided to the integrated possession protection officer.

On 30 October 2021, at about 0847, the work between Graham and Dumgree was completed, and the track section was re-opened without speed restrictions.

Figure 1: Location of the track works Mount Rainbow – Dumgree, Queensland

Figure 1: Location of the track works Mount Rainbow – Dumgree, Queensland

Source: Aurizon, annotated by the ATSB

The occurrence

At about 1130 and 1215, 2 empty coal trains passed over the re-opened line, heading west, between Mount Rainbow and Dumgree without incident.

At about 1545, empty coal train 9QJ5 passed through Mount Rainbow heading west towards Moura Mine, travelling at about 64 km/h. The train gradually increased speed to a maximum of 77 km/h, before the driver applied dynamic brake to decrease speed for an approaching 60 km/h track speed limit.

When approaching the 99 km, the rail traffic crew noticed a transition in ballast colour from dark to light (Figure 4). A short time later, at 1556:50, the recorded brake pipe pressure began to decrease in the remote distributed power locomotives. At 1556:57, travelling at 54 km/h, the emergency brake was activated (due to a loss of brake pipe air) in the leading locomotive, stopping the train about 160 m later at about 100.220 km. The in-cab telemetry between the leading locomotive and remote locomotives was broken.

After securing the train, one of the drivers walked back, discovered that the wagons had derailed (Figure 2), and reported the derailment to Aurizon network control.

Figure 2: Main wreckage site

Figure 2: Main wreckage site

Source: Aurizon, modified by the ATSB

Context

Train information

General

Train 9QJ5 consisted of 2 leading diesel electric locomotives, 50 empty coal wagons, 2 distributed power diesel electric locomotives, and another 50 empty coal wagons. The total length of the train was 1,714 m with a gross mass of 2,501 t. The train was operated by 2 appropriately qualified Aurizon drivers. Both drivers recalled during interview that the track was smooth as the leading locomotive passed over the recently ballasted track.

Recorded information

The locomotives were fitted with event data recorders. Data from the leading locomotive (4012) showed the train was operated consistent with the advertised track speeds. In addition, the emergency brake automatically activated as a direct result of the brake pipe loss of air due to the train separation.

At the time of derailment, the leading remote distributed power locomotive (4044) recorded a 4 kN tractive effort. The ATSB considered if this force contributed to the derailment through buff (compressive) forces in the couplings between the wagons. It was determined that the 4 kN was erroneous and did not contribute.

Track infrastructure

The narrow-gauge track[1] between Mount Rainbow and Dumgree consisted of 60 kg/m continuously welded rail fastened with resilient fasteners on concrete sleepers nominally spaced at 667 mm on ballast 250 mm deep. There was no overhead wiring electrical traction system or stanchions installed. The track consisted of undulating terrain with multiple tight radius[2] reverse curves (Figure 3 left). The point of derailment was located between 301 m radius reverse curves on a 1 in 153 downhill grade (Figure 3 right).

Figure 3: Track details at the point of derailment

Figure 3: Track details at the point of derailment

Source: Aurizon, annotated by the ATSB

Site and wreckage information

Following the derailment, Aurizon inspected the derailment site and commenced an investigation. Based on the site evidence, Aurizon determined that the leading left wheel of the trailing rear axle of the 31st wagon (behind the 2 leading locomotives, VSAS 50930) climbed over the left rail (in the direction of travel) at 99.277 km (Figure 3). The wheel flange ran along the rail head for about 3.6 m then dropped off the field side.[3]

The following 20 wagons derailed (not including the 35th position wagon) and 2 remote distributed power locomotives derailed (located at position 51 and 52 in the consist). The train travelled about 400 m in a derailed condition. Aurizon specialists inspected the rolling stock in-field and found no pre-existing defects.

Aurizon found evidence of a track misalignment commencing at about 99.270 km, just prior to the point of derailment, where the concrete sleepers had begun to move both vertically and laterally (left and right). The track misalignment progressively worsened beyond the point of derailment (Figure 4). The ballast in the work location was also analysed. Although the ballast failed under 53 mm and 37.5 mm sieve tests,[4] Aurizon determined that the specification failure identified was not considered to have been contributory to the accident.[5]

Aurizon concluded that the recent track maintenance activity had a substantial impact on the compressive stress condition of the track leading up to the point of derailment in the heat of the day. This resulted in the track infrastructure becoming unstable and a flange climb derailment due to track misalignment.  

Figure 4: Point of derailment and track misalignment

Figure 4: Point of derailment and track misalignment

Note: The rear portion of wagons was removed from the site before the above photograph was taken. New ballast is lighter in colour.

Source: Aurizon, annotated by the ATSB

Stress-free temperature

Railway tracks are constructed of steel rails that expand and contract with changes in temperature. When the temperature increases, the rail expands and when the temperature decreases, the rail contracts. These changes in length can cause stresses and strains in the rail, which can lead to breaks, buckling, and other types of lateral instability. To prevent such instability, the rail is designed to have a stress-free temperature.

The design stress-free temperature refers to the temperature at which the rail is neither in compression nor in tension, and is established during track construction. However, this may change due to factors such as rail creep,[6] dynamic train forces (such as train acceleration and braking), and maintenance activities (such as tamping, destressing or ballast cleaning). Therefore, the actual stress-free temperature of the rail may not necessarily be the design temperature. Consequently, the actual temperature should be routinely measured to ensure it remains within the designed tolerances.

Aurizon specified a rail design stress-free temperature of 38°C for the line between Mount Rainbow and Dumgree. Although the line had been regularly inspected and maintained, the actual stress-free temperature of the rail before the track disturbance work commenced was unknown.

Track standards

The track was to be maintained in accordance with Aurizon’s standards including the Civil Engineering Track Standards[7] and Track Stability Manual.[8]

Track consolidation

The Civil Engineering Track Standards stated:

All track that has been recently disturbed must have a speed restriction applied following the work as specified in Table 10.1 Acceptance Criteria for Track Consolidation.

An excerpt of Table 10 is shown in Figure 5 indicating that a temporary speed restriction of 40 km/h or less was required after undercutting works until consolidation of the ballast[9] had occurred through either dynamic stabilisation or having 10 loaded coal trains pass over the track, establishing valid stress-free temperature results and making any rail adjustments.

Figure 5: Excerpt from the Civil Engineering Track Standards detailing the requirements for temporary speed restrictions for track disturbance works

Figure 5: Excerpt from the Civil Engineering Track Standards detailing the requirements for temporary speed restrictions for track disturbance works

Source: Aurizon, modified by the ATSB

Management of track stability

The Track Stability Manual described approved processes and procedures for the management of track stability on continuously welded rail by correct rail adjustment, and improving the track’s resistance to track buckles (compressive force) and breaks (tensile force). The management of track stability involved 2 separate processes:

  • control of rail stress to reduce longitudinal forces in the rail that can lead to buckling
  • maintenance of the ballast profile and condition to improve ability of track to resist these forces.

Figure 6 is an excerpt from the Track Stability Manual showing the track stability requirements for various disturbance works, including ballast undercutting. Ballast control through track consolidation, and rail stress control through stress testing or rail adjustment, were both mandatory requirements. The manual also noted that, as there were different mandatory requirements listed, there may be a situation where 2 or more speed restrictions may apply, and that the more ‘severe restriction’ should always apply. Following ballast undercutting works, in addition to the speed restriction required until ballast consolidation was completed (discussed above), a 40 km/h limit was to be put in place until a stress test with an adequate result or rail adjustment was performed.

Figure 6: Excerpt from the Track Stability Manual detailing the track stability requirements

Figure 6: Excerpt from the Track Stability Manual detailing the track stability requirements

Source: Aurizon, modified by the ATSB

Figure 7 is an excerpt from the Track Stability Manual and shows the level of applied speed restriction based on the ambient air temperature and unknown status of the rail stress‑free temperature. In this instance, based on the unknown status of the rail stress-free temperature and ambient air temperature, a temporary speed restriction of 40 km/h was required until a rail adjustment was performed within the intervention threshold of 3 days (Figure 8).

Figure 7: Excerpt from the Track Stability Manual detailing speed restrictions based on ambient air temperature

Figure 7: Excerpt from the Track Stability Manual detailing speed restrictions based on ambient air temperature

Source: Aurizon, modified by the ATSB

Figure 8: Excerpt from the Track Stability Manual detailing the risk controls for an unknown rail stress-free temperature

Figure 8: Excerpt from the Track Stability Manual detailing the risk controls for an unknown rail stress-free temperature

Source: Aurizon, modified by the ATSB

Planned trackwork

Without dismantling the track, the ballast cleaning machine undercut the ballast bed with a moving chain beneath the rails and sleepers, removing contaminated and degraded ballast. The ballast was replaced with new ballast under the track, shown as the lighter colour in Figure 4.

Ballast undercutting track work, between Mount Rainbow and Dumgree, disrupted track stability between 99.840 and 99.286 km (554 m). This disruption potentially extended to include an influence zone up to 100 m either side of the work.[10] To mitigate the risks associated with track instability, the following key tasks were usually performed during and following disturbance work to assure track stability. They were, but not limited to:

  • using track monuments[11] to measure offsets
  • repositioning the track back to the original position based on the recorded offsets
  • tamping[12] the track to the design curvature and superelevation[13]
  • dynamic stabilisation[14]
  • rail stress testing (if applicable) and subsequent adjustments to the rail
  • using temporary speed restrictions until track stability was assured.

On 27 October 2021, following an initial delay, work commenced at about 1230 and about 350 m was completed before a shift handover.  Following the handover to the afternoon shift, it was noted by the work supervisor that no temporary monuments had been installed. In preparation for continuation of the work, steel star pickets were hammered into the field-side of the track to create a temporary datum or monument points. The pickets were used at intervals of about 50 m to record track offsets, to ensure the track was returned to its original position following undercutting work. The afternoon shift completed about 200 m of undercutting work with monuments installed and track offsets recorded.

Following ballast replacement, the track was realigned using the previously recorded track offsets before design curvature and elevation corrections were made. The track was also dynamically stabilised to consolidate the ballast.

Generally, when ballast undercutting works was conducted, a stress test was completed following that works using a VERSE®[15] stress testing machine. The results of that test determined whether adjustments to the rail were required if found to be outside tolerances. In this case, as the curvature of the track was too tight to use this machine and receive accurate results, a re‑stress was planned to be completed. A re-stress (rail adjustment) involved cutting the rail, measuring the rail gap and temperature, calculating the rail stress-free temperature and required gap, then welding the rail together.

Prior to the work commencing, a rail stress plan was approved to begin following the work on 28 October 2021. Due to staff availability, the planned rail adjustment was not conducted on that date nor was there evidence provided to the ATSB that it had been rescheduled to occur within 72 hours, as specified in the Track Stability Manual (Figure 8). Following the work, a temporary speed restriction (TSR) board was not erected to cover the worksite. The site supervisor believed that other TSRs for the broader work covered that specific worksite.

Environmental information

The closest Bureau of Meteorology weather monitoring station was at Thangool Airport, about 35 km south-south-west from the derailment site. The maximum outside air temperature recorded on 30 October 2021 was 34.2 °C.

Aurizon monitors air and rail temperatures at numerous locations on their network, including Mount Rainbow (7.7 km east) and Dumgree (10.4 km west). Table 1 shows the maximum air and rail temperatures, including near the time of derailment (at 1600).

Table 1: Aurizon recorded temperatures

Location Maximum temperature °CTime of derailment temperature °CTrain at 1130 (°C)Train at 1215 (°C)
Mount Rainbow

Air

Rail

33.1 at 1330 hrs

48.1 at 1400 hrs

31.1

40.1

30.9

47.6

32

48

Dumgree

Air

Rail

35.7 at 1445 hrs

51.6 at 1315 hrs

35.3

49

32.3

48.1

33.8

50.8

Figure 9 and Figure 10 show Aurizon recorded air and rail temperatures at Mount Rainbow and Dumgree between 28 October 2021 and 30 October 2021. The maximum air temperatures on each day were below the design stress-free temperature of 38°Cfor the rails. However, at the time of the derailment, the rail temperature was decreasing and was about 40.1 °C at Mount Rainbow and 49 °C at Dumgree.

Figure 9: Mount Rainbow air and rail temperatures

Figure 9: Mount Rainbow air and rail temperatures

Source: Aurizon, annotated by the ATSB

Figure 10: Dumgree air and rail temperatures

Figure 10: Dumgree air and rail temperatures

Source: Aurizon, annotated by the ATSB

Similar occurrence

ATSB investigation (RO-2018-005)

On 24 January 2018, at about 1347 local time, loaded Aurizon coal train EF01 encountered a track buckle at Duaringa, on Aurizon Network’s Blackwater System between Emerald and Rockhampton, Queensland. The buckle resulted in 17 wagons in the train consist derailing (Figure 11), damaging 502 m of track on the down line and 54 m of track on the adjacent up line, with rails, sleepers and overhead line equipment requiring replacement.

Figure 11: Duaringa derailment site

Figure 11: Duaringa derailment site

Source: ATSB

The ATSB found that the track buckle had formed on a falling 1 in 50 grade at the point of the track where ballast cleaning and track stabilisation work had been completed less than 12 hours earlier. The ballast cleaning operational plan did not consider compressive stress in the continuous welded rail as a risk at this location.

The compressive stress, steep grade, proximity to a turnout and high ambient temperature meant the track structure had a limited capacity to constrain lateral forces. While the ballast cleaning, track resurfacing and dynamic track stabilisation work met Aurizon Network’s civil engineering track standards, negative operational outcomes were not anticipated when a risk assessment was done for the site.

Following this occurrence, Aurizon changed its procedures to ensure a temporary speed restriction was applied to all work sites on which ballast undercutting had been performed. The restriction was to remain in place until rail adjustment or stress testing had been completed and it had been determined that the rail stresses were within accepted limits. In addition, sites with a high risk of compressive rail stress would be identified and added to the site hazard map before conducting ballast cleaning.

Safety actions implemented by Aurizon following the Duaringa derailment had not been applied as part of the planned track work between Mount Rainbow and Dungree and are discussed in the Safety analysis below.
 

Safety analysis

On 30 October 2021, Aurizon empty coal train 9QJ5, derailed while traversing a section of track following disturbance work 7.7 km west of Mount Rainbow, Queensland. This analysis will discuss the track disturbance work and associated requirements following that work.

Track irregularity and derailment

The on-site examination identified wheel flange climb on the outside of the curved section of track between Mount Rainbow and Dumgree, indicating the point of derailment. Once the wheel climbed and dropped off the rail head, it created further damage, which led to further following wagons derailing. At the time, the train was travelling at 56 km/h.

The track in the vicinity of the derailment had been disturbed during ballast undercutting work, which was completed 2 days prior to the accident. This work destabilised the track until such time that it was realigned/tamped, stabilised, and the rail adjusted.  

Further, it was established that the track immediately prior to the point of derailment near where the ballast undercutting transitioned to the original track (within the influence zone) was misaligned. Therefore, as there was no evidence to indicate that any issues with the rollingstock or train handling contributed, it was likely that the derailment occurred as a result of a track irregularity following the recent works.

Rail adjustment

To reduce the risk of lateral instability due to rail stress-free temperature being outside design tolerances, the Aurizon Track Stability Manual relied on the track being placed back into the same position following disturbance work. The stability manual also relied on a rail adjustment or stress test to confirm the rail stress-free temperature before a temporary speed restriction, protecting the area, was removed.

In this instance, a rail adjustment was planned (due to track curvature) as part of the work. However, due to resourcing issues, this was not performed before the track was returned to service as planned. In addition, there was no evidence provided to the ATSB indicating that the rail adjustment was rescheduled to be completed within the 72-hour requirement specified in the manual.

Consequently, the actual stress condition of the track was unknown when the track was returned to service. However, while the 2 other trains had passed over the disturbed track earlier in the day at normal speed without issue, the operator concluded that the track would have been in a compressive state following the works. Therefore, it was likely that the track was likely left in a stressed condition following the disturbance works and the track irregularity developed under train 9QJ5.

Temporary track monuments

Track monuments are used as datum points for the positioning of track within the rail corridor. Based on the records provided, the initial 350 m of work had not been monumented and the offsets not recorded. However, temporary monuments were regularly installed and used for about the final 200 m of the ballast undercutting, near the point of derailment. This meant that the final section of work had likely been realigned/tamped and stabilised in, or very near the original position. Therefore, the lack of track monuments for the earlier works was not considered to be a contributing factor in the derailment.

Irrespective, where permanent track monuments are not installed, the regular installation and use of temporary monuments ensures accurate track offsets are taken and the track is restored to the original position following any track disturbance works. This reduces the risk of affecting the rail stress-free temperature due to incorrect track alignment.

Temporary speed restriction

Following track disturbance work, Aurizon specified the requirements for temporary speed restrictions. In this instance, the track disturbance works required a 40 km/h temporary speed restriction to be applied, covering the works area and influence zones either side. Based on Aurizon requirements, the restriction was required pending the rail adjustment. Although it was not required for ballast consolidation as it had been dynamically stabilised during the restoration process.

However, following the work, a temporary speed restriction was not implemented. Potentially, a broader temporary speed restriction related to other work may have been mistaken as applying to the ballast undercutting area. Furthermore, the missing temporary speed restriction was not detected during the track hand back process to the integrated possession protection officer.

Considering 2 previous trains had passed over the site, in the heat of the day, and at normal track speed (up to 60 km/h) without incident, the contribution of the missing temporary speed restriction was unable to be established. Despite this, Aurizon mandated the implementation of temporary speed restrictions following track disturbance work. This is important to manage the risk of lateral track instability due to unconsolidated ballast and/or incorrect or unknown rail stress-free temperature.
 

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the derailment of coal train 9QJ5 near Mount Rainbow, Queensland, 30 October 2021.

Contributing factors

  • As 9QJ5 travelled between Mount Rainbow and Dumgree at 56 km/h on a curved section of track, the train derailed likely due to a track irregularity following track disturbance works.
  • The track near the point of derailment was not re-stressed (adjusted) following the track work, as planned. Consequently, the track was likely left in a stressed condition when the track was handed back fit for service.

Other factors that increased risk

  • Temporary track monuments had not been regularly placed throughout the worksite, increasing the risk of the track not being returned to the correct position following track disturbance work.
  • After the track disturbance works had been completed, a temporary speed restriction of 40 km/h was not applied to assure safe passage over that section of track, which had not yet been cleared for operating at the normal speed of 60 km/h.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Safety action by Aurizon

Aurizon advised the ATSB of the following safety actions:

  • A rail stress worker course was developed and rolled out to relevant roles.
  • Roadshows were conducted in all districts, where network asset leaders discussed the intent and application of the Track Stability Manual.
  • The Track Stability Manual was reviewed and updated.
  • A rail stress appreciation course was created and attended by civil supervisors and civil superintendents across the Aurizon network.
  • Site assessment walkout templates were updated to include relevant rail stress related information.
  • A toolbox talk was created and issued to all infrastructure workers, reinforcing procedural requirements when performing track disturbing work to maintain track stability.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the train crew
  • Aurizon

References

Office of the National Rail Safety Regulator. (2019). Guideline - Road Rail Vehicle Management and Operations, Version 1.0. Adelaide, SA: Office of the National Rail Safety Regulator.

Rail Industry Safety and Standards Board. (n.d.). Glossary of Terms. Retrieved from https://www.rissb.com.au/glossary/

Rail Industry Safety and Standards Board. (2018). Track stability (AS7643: 2018). Retrieved from https://www.rissb.com.au/products/as-7643-track-stability/

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • train crew
  • Aurizon
  • Office of the National Rail Safety Regulator.

Submissions were received from:

  • Aurizon
  • Office of the National Rail Safety Regulator.

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2024

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1] Narrow gauge is nominally 1,067 mm.

[2] Aurizon defined a tight radius curve as a 300 m radius.

[3] The side of the rail opposite the gauge face (the inner side of the running rail head).

[4] New ballast contains approximately 40-45% voids and has the size, shape, density, and grading requirements specified to suit the operational requirements and environment. However, although all Australian railway systems have differing grading requirements, all have a maximum size of 53 or 63 mm and are limited to approximately 0.7% of dust passing a 75 μm sieve.

[5] Aurizon Category A investigation report of derailment of 9QJ5.

[6] The permanent or progressive longitudinal movement of rails in track caused by expansion or contraction of the rail or the action of rail traffic.

[7] SAF-STD-0077-CIV-NET Module 10 Civil Engineering Track Standards – Track Stability and Hot Weather Precautions, Ver 1.0, 11/01/2021.

[8] AZN.NA.MAN.12.6170.005 HWD Track Stability Manual – Network, Ver 2.0, 04/01/2021.

[9] The process of recompacting the ballast after track disturbance works, achieved through either the action of loaded trains or mechanical means.

[10] Any rail adjustment or speed restriction resulting from track disturbance works must cover the extent of the site, and an additional length of track beyond the immediately affected area. This is known as the influence zone as defined by Aurizon (Track Stability Manual). For rail adjustments, the influence zone extended 100 m at each end of the affected work area.

[11] A permanent monument located at the side of the track to facilitate the accurate measurement of rail creep. Measurements were taken between a marker on the monument and punch marks made on the side of the rail head. Where no permanent monuments were installed, it was best practice to install and use temporary monuments, such as steel star pickets.

[12] The process by which ballast is packed around the sleepers of a track to ensure the correct alignment for the location, speed and curvature of the line.

[13] Generally, the term superelevation (or cant) is used for intended height difference in the rails (that is, where the track is inclined in a curve), and the term 'cross-level' is used for unintended height difference (that is, due to track irregularity).

[14] Dynamic track stabilisation is a track maintenance technique that uses controlled vibrations to improve the stability of the ballast bed. This is done by applying horizontal vibrations to the track while simultaneously applying a vertical load. The vibrations cause the ballast stones to re-arrange themselves in a denser and more homogeneous structure, which improves the track's resistance to lateral displacement and settlement.

[15] The vertical rail stress equipment (VERSE®) machine is a scientific instrument used to non-destructively measure the stress-free temperature of continuously welded rail.

Occurrence summary

Investigation number RO-2021-013
Occurrence date 30/10/2021
Location 80 km from Moura
State Queensland
Report release date 30/01/2024
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Accident

Train details

Train operator Aurizon
Train number 9QJ5
Type of operation Coal Train
Rail vehicle sector Freight
Departure point Callemondah, Queensland
Destination Moura Mine, Queensland
Train damage Substantial

Landing on closed runway involving Cessna 510, VH-MSU, Temora Aerodrome, New South Wales, on 21 October 2021

Final report

Report release date: 18/05/2022

Safety summary

What happened

A privately operated Cessna 510 Citation Mustang aircraft, registered VH-MSU, was flying from Sunshine Coast airport, Queensland to Essendon Airport, Victoria with a planned stop at Temora Aerodrome to refuel. At about 1857 Eastern Daylight Time, the pilot landed on runway 18 at Temora Aerodrome. On touchdown, the pilot noticed unserviceability markers further along the runway and elected to continue the landing. The pilot slowed to taxi speed and left the runway to refuel prior to reaching the markers. While refuelling, the pilot checked the NOTAMs for Temora Aerodrome and found that runway 18/36 was closed due to runway works.

What the ATSB found

The ATSB found that during pre-flight planning, the pilot dismissed NOTAMs that were deemed irrelevant to the planned operation. This included one stating that runway 18 was closed due to works in progress, which was deemed irrelevant due to the planned landing on runway 05. The pilot did not review NOTAMs when considering changes to the plan during flight. During approach and landing, the pilot did not see evidence of runway works or closure until touchdown and judged that they would be able to stop before the cones.

White crosses had been placed on the runway, but not in locations visible to aircraft conducting a straight-in approach on runway 18. The size and number of unserviceability markings along the runway were insufficient to fulfil the requirements of the Civil Aviation Safety Regulations Part 139 Manual of Standards (MOS) for closed runways.

What has been done as a result

Temora Aerodrome now has obtained larger unserviceability markings. The pilot has adjusted their in-flight decision-making process to check all NOTAMs for an aviation facility when plans change.

Safety message

An essential component of pre-flight planning is to check all NOTAMs relevant to the planned flight, and potential changes to the plan. This includes all NOTAMs regarding all aviation facilities that a pilot plans to use.

To ensure clear communication of changes that may affect the safety of aircraft operations, aerodrome operators must ensure that all works are conducted, and markings displayed, in accordance with the current Civil Aviation Safety Regulations Part 139 Manual of Standards (MOS) for aerodromes.

 

The investigation

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

On 21 October 2021, the pilot of a Cessna 510 Citation Mustang aircraft was conducting a private flight from Sunshine Coast Airport, Queensland to Essendon Airport, Victoria with 4 passengers on board. During pre-flight planning, the pilot checked the weather and NOTAMs,[1] and decided to make a refuelling stop due to diversions around a thunderstorm system in south-east Queensland. The pilot identified Temora Aerodrome, New South Wales (NSW), as an appropriate stop and after calling the fuel provider and checking NOTAMs, planned to land on runway 05 due to weather conditions at the aerodrome.

During cruise, the pilot tuned into the Aerodrome weather information service (AWIS)[2] at Temora Aerodrome and made the decision to land on runway 18 instead of runway 05 due to changes in wind direction and apron accessibility. The pilot did not hear any broadcasts on the Common Traffic Advisory Frequency (CTAF)[3] and elected to land straight-in with a 5-mile final approach to save on time and fuel.

On touchdown, at about 1857 local time, the pilot noticed cones (unserviceability markers) across the runway a long distance ahead of the threshold. They elected to continue the landing after judging that there was sufficient runway to stop safely. The unserviceability markers were located 700 metres from the threshold, just south of intersection D on runway 18/36 (see ‘Locations of unserviceability markers’ in Figure 1). The pilot did not see any other visible markings or obstructions on the runway to indicate that it was closed.

Figure 1: Temora Aerodrome chart (closed pavement in red)

ao-2021-045-picture1.png

Source: Airservices Australia, annotations by the ATSB

After landing, the pilot re-checked the NOTAMs and found that runway 18/36 was closed but available for use as a taxiway. The pilot re-fuelled the aircraft and, while taxing for departure on runway 23, looked for any unserviceability markings near intersection A but did not see any. The pilot departed at about 1920 local time.

Context

Temora Aerodrome

Temora Aerodrome was a certified and non-controlled aerodrome located in southern NSW. It had two asphalt runways, one dirt runway and two grass runways for glider operations. It was primarily used by the Temora Aviation Museum and Temora Aero Club.

Runway 05/23 was 2,040m long and runway 18/36 was 1,469m long. Both runways were 30m wide.

Runway works

Works began on 5 October 2021 to construct a link taxiway to the threshold of runway 23 and complete drainage works at the southern end of runway 18/36. Works were planned to be completed by 30 November 2021. During this time, runway 18/36 was closed. About 640 metres of this runway, between taxiways A and D, continued to be available as the sole taxiway for runways 05/23 and 09/27. At the time of the incident, works markings and a NOTAM outlining these changes to the operation of the airport were active.

Aerodrome markings

A combination of unserviceability markers (cones) and markings (crosses) had been placed on the aerodrome as annotated in Figure 1.

Unserviceability markers, consisting of 50cm high white cones with a red band, were placed at the end of taxiways E and F entering runway 18/36, and across runway 18/36 south of taxiway ‘D’, to prevent aircraft taxiing into the works area.

Three unserviceability markings, constructed with 6-metre-long white lines laid as a cross, were placed on the runway:

  • 116 metres north of the threshold of runway 36
  • halfway between taxiways D and E, and
  • 42 metres south of the runway 18 threshold, between the numbers and ‘piano-keys’.

The distances between these markings were 431 and 750 metres.

Unserviceability markings

As defined by the Civil Aviation Safety Regulations Part 139 Manual of Standards (MOS) for Aerodromes, unserviceability markings are used for temporary and permanent closures of aerodrome surfaces. They consist of white or yellow crosses of various sizes. When used to mark a runway as temporarily unserviceable, the MOS requires:

  • markings to be white
  • markings to be placed at each end of the runway, or portion of a runway, that is declared unserviceable
  • additional markings to be placed so that the maximum interval between markings does not exceed 300 metres.

The size of the markings for unserviceable runways was determined by the width of the runway (Figure 2):

  • for runway widths greater than 30 m – a 36-metre-long by 14.5-metre-wide cross
  • for runway widths from 18 m up to 30 m – a cross with 9-metre-long lines
  • for runway widths less than or equal to 18 m – a cross with 6-metre-long lines.

Figure 2: Unserviceability markings and unserviceability marker specifications

ao-2021-045-picture2.png

Source: Civil Aviation Safety Regulations Part 139 (Aerodromes) Manual of Standards

To allow aircraft to taxi along a runway that has been closed with unserviceability markings, unserviceability markers are required to delineate the serviceable portion of the runway to be used as a taxiway. Additional temporary lighting is required for any night operations.

Unserviceability markers

As defined by the MOS, unserviceability markers were to be a 50 cm tall white cone with a 25 cm wide horizontal red stripe (Figure 2). These markers had to be placed at the entrance to, and across, any part of the movement area of an aerodrome (including runways) that are not to be used by aircraft. Additionally, at least three had to be displayed across the centreline of any portion of a taxiway, apron or holding bay that is unserviceable.

Pre-flight planning

The pilot used the AvPlan electronic flight bag (EFB) application on a tablet for pre-flight planning, including accessing weather information and NOTAMs. Weather information for the flight had been reviewed the previous day and multiple times on the day of the incident. Due to the expectation that diversions around weather would be necessary, Temora Aerodrome was identified as an appropriate additional stop for refuelling. When planning to stop in Temora, the pilot reported calling the fuel provider to confirm availability of Jet-A1 fuel in addition to checking weather and NOTAMs using AvPlan.

The pilot’s NOTAM checking procedure involved using AvPlan to mark NOTAMs as ‘read’ when the pilot determined they were not relevant to their operations. They did this to reduce the cognitive load when referring to relevant NOTAMs, which were left ‘unread’, during further planning and flight. In this case, the pilot planned to land on runway 05 due to a light headwind. The NOTAM regarding closure of runway 18/36, and availability as a taxiway, was marked as read as it had no effect on their planned operation.

In-flight decision making

When in flight, the pilot listened to the AWIS system to retrieve the current weather conditions at Temora Aerodrome. The pilot reported that both the Temora AWIS and Williamtown ATIS[4] broadcast on the same frequency (134.45), which resulted in difficulties hearing the broadcast at cruise altitude. The pilot reported that the AWIS was broadcasting the wind as 090 at 5 knots.

Due to the drop in wind and lack of traffic on the Temora CTAF, the pilot decided to change plans and land on runway 18 to minimise taxiing after landing. At this time, the pilot did not review the NOTAMs issued for Temora Aerodrome.

Safety analysis

NOTAM information

The NOTAM closing 18/36 was dismissed as part of the pilot’s practice of marking irrelevant notices as ‘read’ in AvPlan during pre-flight planning. While this process enabled notices deemed relevant to be referenced more easily during flight, in the event of an emergency, change of plans, or misunderstanding of relevancy, this may result in critical information not being recalled or reviewed.

Had the pilot reviewed all NOTAMs for Temora Aerodrome when considering landing on runway 18 during flight, they would have been alerted to its closure. In this case, the pilot would have continued to land on runway 05 as planned.

Evidence of closure

As well as the active NOTAM at the time of the incident, Temora Aerodrome had a total of three unserviceability markings, crosses with 6-metre-long lines, along runway 18/36. The Civil Aviation Safety Regulations Part 139 Manual of Standards (MOS) required these markings to be 9 metre markings for a 30 m wide runway and be placed no more than 300 m apart. This would mean that at least 5 markings were required for the 1,469-metre runway. As the length of runway being used as a taxiway exceeded 300 metres, temporary taxiway markings would also be required to separate unserviceability markings from the taxi route.

At the time of the incident, the unserviceability markings, were not located in positions that were clearly visible when landing or taxiing on runway 18 and were not of the required size. These factors likely contributed to the pilot not seeing the unserviceability markers during landing or taxi.

Unserviceability markers (cones) located at the entrances to the works area, both on taxiways and on the runway, were placed in accordance with the requirements of the MOS. These markers are primarily designed to be visible from the ground and were identified upon touchdown.

Although the pilot predicted that the aircraft would be able to stop before reaching the cones, they were not aware why the cones were present or consider the possibility of other runway issues (such as holes) being present before the cones. Had the pilot conducted a go-around when encountering unexpected markings, they would have had the opportunity to re-check NOTAMs and identify the closure of the runway.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the landing on closed runway involving a Cessna 510 Citation Mustang at Temora Aerodrome on 21 October 2021.

Contributing factors

  • During pre-flight planning, the pilot regarded information about a closed runway to be irrelevant and did not review the available information when the plan was changed during flight.
  • The pilot did not see the unserviceability markings or markers that were on the runway prior to touchdown, leading to a landing on a closed runway.
  • The pilot elected to continue the landing after seeing unserviceability markers on the closed runway.
  • The runway was not marked in accordance with the Part 139 Manual of Standards to communicate that the runway was closed for take-off and landing.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.

Safety action addressing in-flight decision making

The pilot has advised that they will now review all NOTAMs for an aviation facility when changing plans during flight.

Safety action by Temora Aerodrome operator

Additional 9 metre markings have been purchased for use on both runways.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • Civil Aviation Safety Regulations Part 139 (Aerodromes) Manual of Standards 2019 (as amended 13 August 2020)

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • Temora Aerodrome operator
  • the Civil Aviation Safety Authority
  • the pilot

A submission was received from the pilot.

The submission was reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2022

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. NOTAM: A notice distributed by means of telecommunication containing information concerning the establishment, condition or change in any aeronautical facility, service, procedure or hazard, the timely knowledge of which is essential to personnel concerned with flight operations.
  2. Aerodrome weather information service (AWIS): actual weather conditions, provided via telephone or radio broadcast, from Bureau of Meteorology (BoM) automatic weather stations, or weather stations approved for that purpose by the BoM. [AIP GEN 3.3 – AIR TRAFFIC SERVICES, Section 2 FLIGHT INFORMATION SERVICE (FIS), paragraph 2.9 Aerodrome Weather Information Service (AWIS) and Weather and Terminal Information Reciter (WATIR)]
  3. Common Traffic Advisory Frequency (CTAF): A designated frequency on which pilots make positional broadcasts when operating in the vicinity of non-controlled aerodromes.
  4. Automatic terminal information service (ATIS): The provision of current, routine information to arriving and departing aircraft by means of continuous and repetitive broadcasts during the hours when the unit responsible for the service is in operation.

Occurrence summary

Investigation number AO-2021-045
Occurrence date 21/10/2021
Location Temora Aerodrome
State New South Wales
Report release date 18/05/2022
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Runway - Other
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model 510
Registration VH-MSU
Serial number 510-0300
Aircraft operator Avia Aviation Pty Ltd
Sector Jet
Operation type Private
Departure point Sunshine Coast Airport, Queensland
Destination Essendon Airport, Victoria
Damage Nil

Separation issue involving Saab 340B, VH-ZLV, and Beech Aircraft B200, VH-WXB, near Brisbane West Wellcamp Airport, Queensland, on 21 October 2021

Final report

Report release date: 29/09/2023

Executive summary

What happened

On 21 October 2021, at 0743 local time, a Beech Aircraft B200 aircraft, registered VH-WXB, departed Roma Airport on a passenger charter flight to Brisbane West Wellcamp Airport (Wellcamp), Queensland. At 0806, a Saab 340B aircraft, registered VH-ZLV, departed Brisbane Airport on a scheduled passenger service flight to Wellcamp. Both aircraft were operating under instrument flight rules, and both estimated their time of arrival at the airport to be at 0827.

Prior to each aircraft leaving controlled airspace, the Brisbane Centre air traffic controller passed traffic information to VH-WXB and VH-ZLV in 2 separate broadcasts with an updated arrival time for each aircraft. The pilots of both aircraft made a number of calls on the common traffic advisory frequency to organise separation at the non-controlled aerodrome, however, at about 0828, VH‑WXB conducted a 180° left turn on the active side of the circuit, crossing in front of VH-ZLV. This resulted in the separation between the aircraft reducing to 300 ft vertically and 1,000 m horizontally. As VH-WXB commenced the left turn, VH-ZLV’s traffic alert and collision avoidance system (TCAS) announced a traffic advisory (TA), shortly followed by a resolution advisory (RA). The pilot flying immediately disconnected the autopilot and followed the RA instructions and climbed the aircraft until they were clear of conflict. At about the same time, the pilot of VH-WXB received a TCAS TA and commenced a visual lookout.

The flight crew of VH-ZLV advised VH-WXB they had received a TCAS RA. Further communication occurred between the pilots of the 2 aircraft to confirm and visually identify each other’s position in the circuit and ensure separation. Both aircraft landed safely at Wellcamp Airport.

What the ATSB found

The ATSB found that the pilots of both aircraft had an incorrect mental model of the positions of the other aircraft and neither had positively sighted the other aircraft before the conflict. The flight crew of VH-ZLV broadcast an incorrect position of their aircraft when approaching the circuit, which probably resulted in the pilot of VH-WXB misidentifying VH-ZLV for another aircraft on their TCAS.

This misunderstanding affected the pilot of VH-WXB’s decision to fly opposite the downwind circuit direction while in a descent. The pilot then conducted a 180° left turn in front of VH‑ZLV, as they thought that aircraft was further ahead on the downwind leg. Further, the flight crew of VH-ZLV also did not effectively monitor the radio, resulting in them having an incorrect mental model of VH-WXB’s position, and not identifying it as a threat. As neither the crew in VH‑ZLV and the pilot in VH-WXB had positively sighted the other aircraft, alerted see-and-avoid was limited and the last line of defence was the TCAS, which prevented a potential collision.

What has been done as a result

As a result of this occurrence the operators advised the ATSB of the following actions:

  • The operator of VH-WXB:
    • will ensure there is an increased buffer between a regular public transport (RPT) flight and their aircraft by orbiting at a waypoint further out, to ensure that the RPT flight is on final approach when they join the circuit
    • have briefed their pilots of the event and communicated the need to adhere to the procedures written in CAAP 166 - Operations at Non-Towered Aerodromes. Further, they advised their pilots that when traffic congestion is anticipated, actions such as conducting orbits to allow greater spacing in traffic sequencing should be considered  
    • have discussed the traffic congestion issue with the flight training school based at Wellcamp and have agreed that during the scheduled arrival times of RPT aircraft, the training school will limit the number of their aircraft flying within the area.
  • The operator of VH-ZLV: 
    • has included operations at, and in the vicinity of, non-towered aerodromes as a focus item in the periodic aircrew check cycle
    • will use this occurrence internally as a human factors case study for operations around common traffic advisory frequency airports.

Safety message

The ATSB’s SafetyWatch highlights the broad safety concerns that come out of our investigation findings and from the occurrence data reported by industry. One of the priorities is safety around non-controlled aerodromes. Insufficient communication between pilots is the most common cause of safety incidents near non-controlled aerodromes. Pilots should ensure that the location and intention of surrounding traffic is well understood, and their intentions are clearly communicated while maintaining a visual lookout.

Safe operation at any aerodrome requires pilots to use sound judgement and to follow standard procedures and CASA guidance. Using standard procedures at non-towered aerodromes, unless otherwise stated in the En Route Supplement Australia (ERSA), assists pilots in maintaining situational awareness and separation from other aircraft.

Developing and maintaining situational awareness is essential for the conduct of safe flight, particularly at non-towered aerodromes. In addition to radio communication, systems such as ADS-B and TCAS are valuable sources of information to assist pilot’s situation awareness and decision making.

 

The investigation

Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

On 21 October 2021, at 0743 local time, a Beech Aircraft B200 aircraft, registered VH-WXB (WXB) and operated by Air Charter Coordinators, departed Roma Airport, Queensland on a passenger transport flight to Brisbane West Wellcamp Airport (Wellcamp), Queensland. On board were the pilot and 8 passengers.

At 0806, a Regional Express Saab 340B aircraft, registered VH-ZLV (ZLV), departed Brisbane Airport, Queensland on scheduled passenger service flight ZL5662 to Wellcamp (Figure 1). On board were 2 flight crew, one cabin crew and 9 passengers. The captain was the pilot monitoring (PM), and the first officer was the pilot flying (PF).[1] Both aircraft were operating under the instrument flight rules.[2]

Figure 1: Locations of Brisbane and Roma Airports in reference to Brisbane West Wellcamp Airport

Figure 1: Locations of Brisbane and Roma Airports in reference to Brisbane West Wellcamp Airport

Source: Google Earth, annotated by ATSB.

Prior to each aircraft leaving controlled airspace, the Brisbane Centre[3] air traffic controller passed traffic information to the pilot of WXB and the flight crew of ZLV on 2 separate broadcasts at 0811 and 0820, respectively. The controller advised the pilot of WXB that ZLV was inbound to Wellcamp from Brisbane with an estimated time of arrival of 0829, and advised the flight crew of ZLV that WXB was inbound for Wellcamp with an estimated time of arrival of 0830.

At 0821 the pilot of WXB made a broadcast on the Wellcamp common traffic advisory frequency (CTAF)[4] advising that they were 30 NM west of the airport, on descent, inbound for Wellcamp via waypoint LUKEY.[5] The stated intention was to make a left turn and to join right base for runway 12 (Figure 2), with an estimated time of arrival of 0827. About 1 minute later, the PM of ZLV made a radio call advising traffic they were 20 NM east of Wellcamp, at 8,000 ft, descending shortly to join crosswind for runway 12, with an estimated arrival time of 0827.

As WXB and ZLV approached the airport there were 5 other aircraft operating in the CTAF area. There were 2 Diamond DA 40’s associated with a flight training school operating in the circuit for runway 12, VH‑YNH and VH‑EQV and another DA 40, VH-YTK, which was outbound from Wellcamp via Toowoomba to the north-east operating at 4,600 ft. In addition, a Beech Aircraft 58, VH‑CLE, that was inbound for Toowoomba from the west and another Beech Aircraft B200, VH‑WXN, that was inbound to Wellcamp, 3 minutes behind WXB.

At 0823:56, the pilot of VH-YNH broadcast on the CTAF they were entering and rolling for take-off on runway 12 to conduct circuit training. At 0824:26, the flight crew of ZLV responded to this call, advising they were 11 NM to the east leaving 8,000 ft with the intention to join downwind behind VH-YNH. About 30 seconds later, the pilot of the second DA 40 VH-EQV, which was in the circuit ahead of VH-YNH, advised the pilots of both ZLV and WXB that they were downwind in the circuit for runway 12 for a touch-and-go.[6]

At 0825:07, the pilot of WXB advised the pilots of both ZLV and the DA 40s, that they were 6 NM west of LUKEY, with the intention to soon make a left turn to join a wide right base circuit leg and again advised their estimated arrival time was 0827.

The pilot of VH-EQV responded and advised the pilot of WXB they would be on final when WXB and ZLV joined the circuit and would stay out of their way.

The pilot of WXB then contacted the crew of ZLV at 0825:43 (Figure 2 - positions 1) and advised them they were about to make a left turn at LUKEY and then join the circuit on the base leg for runway 12 at time 0827 and asked if ZLV would be happy if WXB went number 1[7] to them.

Figure 2: Aircraft flight paths and positions during different CTAF broadcasts – WXB in yellow, ZLV in blue, EQV in green and YNH in pink, with numbering showing where each aircraft was at the time of the broadcasts

Figure 2: Aircraft flight paths and positions during different CTAF broadcasts – WXB in yellow, ZLV in blue, EQV in green and YNH in pink, with numbering showing where each aircraft was at the time of the broadcasts

Source: Google Earth, annotated by ATSB based on FlightRadar24 data.

The crew of ZLV acknowledged the request and incorrectly advised that they were positioned on a very early downwind (rather than their actual crosswind position) and would reduce their airspeed and track second to WXB.

The pilot of WXB, thinking that ZLV was already established in the circuit on downwind rather than on an early crosswind, responded and advised they would track as number 2 to ZLV and join the circuit behind them on downwind. The PM of ZLV acknowledged the broadcast.

At 0826:40, the pilot of VH-YNH made a downwind broadcast on the CTAF and advised they would be making a full stop landing.

At 0827:37 (Figure 2 - positions 2), the pilot of WXB broadcast on the CTAF that they were continuing on an easterly heading, passing 3,500 ft on descent to 3,000 ft (circuit altitude), and would be shortly making a left turn to join downwind behind ZLV. The pilot then continued their descent through 3,500 ft, opposite to the circuit direction on the downwind leg.

At about 0828 (Figure 2 – TCAS RA/TA) WXB made a left turn and crossed ZLV’s path from left to right, resulting in a separation of 300 ft vertically (WXB at 3,000 ft and ZLV at 3,300 ft) and 1,000 m horizontally between the 2 aircraft. As this occurred, the crew of ZLV heard their traffic alert and collision avoidance system (TCAS)[8] announce a traffic advisory (TA)[9], shortly followed by a resolution advisory (RA).[10] In response, the PF immediately disconnected the autopilot and following the RA instructions, climbed the aircraft until they were clear of conflict. Around the same time as ZLV’s TCAS alert, the pilot of WXB received a TCAS TA while they were conducting the 180° turn onto downwind.

At 0828:49 (Figure 2 - position 4), the PM of ZLV made a broadcast on the CTAF to ask the aircraft to the south of the field (WXB) to identify themselves. The pilot of WXB responded and advised they were now mid-downwind and asked the pilot of ZLV to confirm their aircraft was positioned on the base leg (Figure 2 - positions 4 and 5).

At the time of this broadcast, VH-YNH was on the base leg and VH-EQV was on the final leg of the circuit. The PM of ZLV advised they were on the downwind leg of the circuit, and had received a TCAS RA. The pilot of WXB then asked the PM of ZLV to confirm their aircraft’s altitude and the PM advised they were abeam (to the left) WXB. The pilot of WXB, who had not visually sighted ZLV at that stage, then advised they would widen out their circuit and come in behind ZLV. The PM again advised WXB they were to the left of them on downwind and were about to commence their descent back to circuit height.

The pilot of WXB again requested ZLV’s level, to which the PM responded 3,100 ft and the pilot of WXB suggested they would track as number 1. After assessing the risk of another potential conflict between the 2 aircraft on base, the PM of ZLV requested WXB climb clear of the circuit. WXB responded and advised they now had ZLV visual and would track as number 2 to them. The pilot of WXB then made a left turn to reposition behind ZLV.

Both aircraft landed safely at 0833 and 0835 respectively.

Animation 1: Aircraft flight paths and positions during different CTAF broadcasts - WXB in orange, ZLV in blue, and YNH in red.

Source: ATSB based on FlightRadar 24 data

Context

Pilot information

VH-WXB

The pilot held a commercial pilot licence (aeroplane) (CPL(A)) and had a total flying time of 5,556 hours, having flown 88.6 hours in the previous 90 days. The pilot was familiar with Wellcamp and had been operating out of the airport since it opened in 2014.

VH-ZLV

The captain held an air transport pilot licence (aeroplane) and had a total flying time of 4,703 hours, and had flown 148 hours in the previous 90 days. The captain was familiar with Wellcamp and had operated there often in the previous 3 years.

The first officer held a CPL(A) and had a total flying time of 3,361 hours, with 154 hours accrued in the previous 90 days. The first officer was also familiar with Wellcamp and had operated there regularly for the previous 2 years.

Pilot reports

VH-WXB

The pilot of WXB reported that they were aware that ZLV would be joining the circuit at the same time. The pilot also stated that they had ZLV visual most of the time and the only time ZLV was not visual to the pilot of WXB was when the left turn was conducted with the intention of positioning behind ZLV on downwind. However, they also advised that, because of the traffic congestion, they were entirely reliant on their TCAS screen to determine the location of ZLV.

The pilot of WXB reported seeing ZLV to the left of WXB’s position on the TCAS screen, just before they turned to join downwind. They reported that they intended to make 2 more broadcasts to ZLV to verify their position and any other information they could collate, but they were unable to do so because the CTAF was too congested.

Once the pilot thought it was safe to do so, they turned left to join the downwind leg.

The pilot’s TCAS screen was congested with numerous aircraft. For the pilot to identify the aircraft they were required to touch the aircraft symbol on the screen to obtain the callsign, level, and closing speed. It was unknown if the pilot did this.

VH-ZLV

The flight crew both recalled the traffic information providing an estimated arrival time for WXB of 0830, prior to switching over to the CTAF.

The crew reported overflying Toowoomba at 5,600 ft to maintain 1,000 ft separation with outbound traffic, VH-YTK. As a result, the crew reported they were 600 ft higher on their normal descent profile into Wellcamp. Once they were clear of VH-YTK, about halfway between Toowoomba and Wellcamp, they commenced their descent.

They determined that the safest course of action, which was not standard procedure, was to descend while on the early crosswind and downwind legs, as they were limited on where they could conduct a descending orbit without interfering with the Toowoomba circuit traffic, or encroaching Oakey airspace to the north or the training area to the south of the field (Figure 3). They also reported that the dead side/non-active side[1] of the circuit was also an area they could not orbit in due to training aircraft frequently operating in there to avoid interfering with incoming and outgoing high-performance aircraft.

After organising separation with WXB and making circuit position broadcasts on the early crosswind and downwind legs, the flight crew thought separation with WXB had been effectively organised and focused their attention on circuit spacing with VH-YNH and configuring the aircraft for landing.

The flight crew did not recall hearing any broadcasts from WXB about joining downwind, and neither pilot saw WXB visually or on the TCAS until it crossed their flightpath ahead from left to right.

Airspace

The airspace surrounding Wellcamp is non-controlled Class G airspace up to 8,500 ft. About 6 NM to the east of Wellcamp is Toowoomba Airport and about 9 NM to the north-north-west is Oakey Army Aviation Centre (Oakey). There are also other aircraft landing areas (ALAs) within a 10 NM radius of Wellcamp, including Wyreema, Colanya, Argyle and Southbrook (Figure 3).

All the above-mentioned airfields and ALAs, including Oakey, operate on the same CTAF when the Oakey airspace is inactive.

Within the airspace surrounding Wellcamp there are identified Danger Areas[2] to the south and west, including a flight training area up to 6,000 ft.

Figure 3: Brisbane Visual Navigation Chart depicting the airport locations and surrounding airspace

Figure 3: Brisbane Visual Navigation Chart depicting the airport locations and surrounding airspace

Source: Airservices, annotated by ATSB.

In 2019, the Office of Airspace Regulation (OAR) within the Civil Aviation Safety Authority (CASA), completed a review of the airspace within 10 NM of Wellcamp. At the time of the review, the flight training school had not established operations at Wellcamp.

The 2019 airspace review found that the airspace surrounding Wellcamp was fit for purpose, however the following recommendations were made:

Recommendation 1: The OAR should monitor the traffic growth at Wellcamp over the next two years, including the integration of flight training operations based at Wellcamp. If appropriate, another review should be conducted post-implementation of flight training at Wellcamp.
Recommendation 2: The OAR should continue to liaise with other business areas of CASA regarding the commencement of flight training at Wellcamp to ensure that the airspace remains fit for purpose.

A further review of Wellcamp was scheduled to commence in February 2023. However, this review was delayed due to unscheduled changes to priorities. The OAR expects that a review of Wellcamp will be included in a Brisbane basin aeronautical study and is scheduled to commence late 2023.

Brisbane West Wellcamp Airport

Brisbane West Wellcamp Airport is a certified aerodrome located 8 NM west of Toowoomba CBD. It was opened in 2014 and consists of one runway orientated 12/30. The airport services a variety of operations including regular public transport, charter, freight, flight training and aero‑medical aviation services.

The En Route Supplement Australia (ERSA)[3] details local traffic regulations and procedures for the airport. These included stipulating the use of published departure procedures whenever practicable to avoid Oakey military Restricted Airspace. Additionally, due to high terrain to the north‑east of the airport, left circuits are to be flown to runway 30 and right circuits to runway 12.

Operations at non-controlled aerodromes

Guidance provided by CASA[4] (2019) defined that an aircraft was in the vicinity of a non‑controlled aerodrome if it was:

  • within airspace other than controlled airspace
  • within a horizontal distance of 10 NM from the aerodrome (reference point), and
  • at a height above the aerodrome (reference point) that could result in conflict with operations at the aerodrome.
Radio Broadcasts

When operating in the vicinity of non-controlled aerodromes on the shared CTAF, as per Regulation 166C of Civil Aviation Regulations (1988), pilots were required to make a broadcast whenever it was reasonably necessary to do so to avoid a collision, or the risk of collision, with another aircraft.

Further guidance from CASA Advisory Circular 91-10 V1.1 to pilots on the recommended positional broadcasts in the vicinity of non-controlled aerodrome for inbound aircraft is provided at Table 1. It does advise pilots may use their discretion in the number and type of broadcasts they make.

Table 1: Recommended positional broadcasts in the vicinity of a non-controlled aerodrome

Table 1: Recommended positional broadcasts in the vicinity of a non-controlled aerodrome

Source: CASA 91-10 (2021)

[1] NOTE: Some distances above refer to the runway threshold and others refer to the aerodrome reference point. Pilots should be aware that a global positioning system (GPS) indication of 3 NM from and aerodrome may not be 3 NM from the runway threshold.

Circuit and arrival procedures

A circuit pattern is a conventional standard path for coordinating air traffic that are taking off or landing on a runway. A circuit pattern consists of 5 legs – upwind, crosswind, downwind, base and final (Figure 4).

The Civil Aviation Safety Authority (CASA) Visual Flight Rules Guide states the following regarding standard circuit procedures at non-controlled airports, such as Wellcamp:

The standard aerodrome traffic circuit pattern facilitates an orderly flow of traffic and is normally a circuit pattern made with all turns to the left. When arriving at an aerodrome to land, a pilot will normally join the circuit upwind, crosswind (mid-field), or downwind (before mid-downwind). Landings and take-offs should be made on the active runway or the runway most closely aligned into wind. Aerodromes that have right-hand circuits are listed in ERSA. Circuit information may also be published or provided by aerodrome operators in other sources of aeronautical information.

The CASA (2019) guidance provided the following caution on arrival into non-controlled aerodromes:

Pilots should not descend into the active side of the traffic circuit from above because of the difficulty of seeing – and being seen by – aircraft directly below the aircraft’s flight path.

The guidance noted that pilots joining the circuit on the downwind leg at a midfield position should enter the circuit at approximately 45° to the downwind leg and give way to aircraft already established in the circuit.

The guidance further noted that joining the circuit on base is not a standard procedure and increases the risk of traffic conflict and/or landing on a closed runway. It is recommended that pilots join the circuit on either crosswind or downwind.

ZLV joined the circuit on the early crosswind leg and WXB joined the downwind leg after conducting a 180° turn on the active side of the circuit.

Figure 4: Arrival procedure for a non-controlled airport (left direction circuit). The circuit direction was right at Wellcamp

Figure 4: Arrival procedure for a non-controlled airport (left direction circuit). The circuit direction was right at Wellcamp

Source: CASA Visual Flight Rules Guide.

CTAF congestion at Wellcamp

All pilots involved in the incident reported the CTAF can often be quite congested with many calls being over‑transmitted. The flight crew of ZLV reported the CTAF congestion on the day of the incident was manageable and was not a factor in the incident. However, the pilot of WXB reported the CTAF was highly congested. At the time of the incident there were 5 aircraft operating on the CTAF.

In the 3 minutes and 6 seconds from when WXB and ZLV started communicating with each other on the CTAF to just after the incident occurred, 16 broadcasts were made on the CTAF. These had an average length of time of 8 seconds and an average gap of 4 seconds between each broadcast.

Traffic alert and collision avoidance system

Both aircraft in this incident were equipped with a TCAS. In addition to traffic alerts, the TCAS also provides pilots with visual traffic information on a screen. The screen displays other aircraft that are operating in their proximity, and as a result, pilots are able to make decisions based on the displayed information, reducing the risk of collision. The TCAS in WXB only issued traffic advisories and not resolution advisories.

See-and-avoid

When operating in non-controlled airspace, there is no separation service provided by ATC and pilots must rely on their own separation through radio communication with see‑and‑avoid as the last defence.

There are 2 characteristics of see-and-avoid, unalerted and alerted. Unalerted see-and-avoid relies entirely on the pilot sighting another aircraft with no other assistance, while alerted see‑and‑avoid exists when a pilot has been alerted to the existence and approximate location of other traffic. The primary tool of alerted see-and-avoid is radio communication between aircraft and traffic information provided by the air traffic controller. Other tools include ADS-B IN and electronic flight bags that receive traffic information through mobile network or ground-based receivers and TCAS, which provides its own traffic surveillance function.

In the absence of a traffic alert, the probability of a pilot sighting a threat aircraft before impact is low, whereas alerted see-and-avoid can be 8 times more effective.

For further information on the limitations of see-and-avoid, please refer to the 1991 ATSB report Limitations of the See-and-Avoid Principle.

Reported incidents at Brisbane West Wellcamp and Toowoomba Airports

Since 2016, the ATSB has received 17 airspace occurrence reports that occurred within a 30 NM radius of Wellcamp and Toowoomba Airports (Refer to Appendix A – Separation and TCAS events within the circuit area at Wellcamp and Toowoomba for further details).

Fourteen of the occurrences involved separation issues with the involved aircraft either receiving or not receiving a TCAS alert. Eight of these occurrences occurred at or near Wellcamp, including 6 within the circuit area. Only one of these occurrences involved an aircraft turning inside another aircraft already established in the circuit, during circuit operations. The other 6 were at or near Toowoomba, with 3 occurring within the circuit area.

Two of the occurrences were classified as near collisions. In one, the crew of a Beechcraft B300 observed a glider cross their flightpath near Wellcamp. In the other a Bell 412 was on approach for Toowoomba when a Piper PA-38 crossed their track.

A loss of separation was also reported between a Cessna 182 and a de Havilland DHC-8 25 NM (46 km) east of Toowoomba, where the Cessna182 climbed above its assigned altitude.

Safety analysis

Incorrect mental models

Mental models are a form of cognitive structure that enables an individual to effectively interact with their environment by organising knowledge into meaningful patterns (Reynolds & Blickensdefer, 2009). An individual, when performing a task will develop a mental model of what they think will occur during the task being completed. Their mental model is based upon the information available to them at the time.

VH-WXB

The flight crew of ZLV advised the pilot of WXB that they were on early downwind (Figure 2 - position 1), when they were actually on early crosswind for runway 12. At the time of this broadcast, there were 2 other aircraft in the circuit: VH-EQV on mid-downwind and VH-YNH on mid-crosswind.

The pilot of WXB recalled seeing ZLV to the left of their position on their TCAS screen at about the same time as when they broadcast that they were continuing on an easterly heading (Figure 2 - position 2). However, a review of recorded flight data identified that ZLV was not to the left of WXB until after the 2 aircraft had crossed paths and it was VH-YNH to the left of WXB at this time. The pilot of WXB also stated that they had ZLV visual most of the time and the only period that ZLV was not visual to them was when the pilot was conducting the left turn to position behind ZLV on downwind.

After WXB crossed ZLV’s track and was in communication with the flight crew of ZLV, the pilot asked the crew to confirm ZLV was on base. At the time of this broadcast, VH-YNH was on base (Figure 2 - position 5) and ZLV was to the left of WXB on downwind.

The pilot of WXB's description of when they first became aware of ZLV on their TCAS screen and their common traffic advisory frequency (CTAF) broadcasts after crossing ZLVs flight path, suggested the pilot of WXB had sighted VH-YNH and not ZLV visually or on the TCAS screen. The advice from the crew of ZLV that their aircraft was on early downwind when they were on crosswind, would have likely also confirmed the pilot’s assumption that VH-YNH was ZLV and the pilot possibly assumed VH-EQV was VH-YNH.

The decision by the pilot of WXB to fly opposite to the traffic direction on downwind while descending to circuit height, before turning left, across ZLV’s flight path indicates that it is likely that the pilot had not identified ZLV either visually or on the TCAS.

VH-ZLV

Both flight crew members of ZLV recalled WXB’s field estimate was 0830, which was initially given to them by the air traffic controller. However, after they transferred over to the CTAF, the pilot of WXB broadcast their new arrival time of 0827 on 2 separate occasions, including a broadcast directly to ZLV. This was the same estimated arrival time as ZLV. It is evident that the flight crew of ZLV were aware of the potential arrival time conflict as a discussion occurred between the pilot monitoring and the pilot of WXB, for the flight crew to slow down ZLV to go in number 2 to WXB.

Due to the earlier incorrect positioning call from the flight crew of ZLV, leading the pilot of WXB to believe that ZLV was already established in the circuit on downwind, the pilot of WXB advised the flight crew that they would track number 2 to ZLV and join the circuit behind them on downwind. The pilot monitoring of ZLV acknowledged the broadcast.

The pilot monitoring did not recall hearing anymore broadcasts from the pilot of WXB, after they had organised that WXB would track behind them, until after the TCAS resolution advisory was received. The pilot of WXB had made one other broadcast prior to this, just before they conducted the 180° turn onto downwind, that included intentions to descend and to shortly join the circuit via a left turn (Figure 2 - positions 2). If the flight crew of ZLV had of been effectively monitoring the CTAF, this transmission should have been a trigger for them to look for WXB and respond to confirm their mental model. At this time, ZLV was 1,300 ft higher than WXB (4,800 ft vs 3,500 ft) and in the process of conducting a right turn onto early downwind, making sighting of a lower aircraft more difficult.

It is possible that after organising separation with WXB and agreeing that WXB would go number 2 behind them, the crew thought that WXB was aware of their position and therefore discounted WXB as a threat. Believing adequate separation had been organised, focus switched to VH-YNH and configuring the aircraft for landing.

The flight crew’s ineffective monitoring of WXB’s broadcasts and their incorrect mental model meant that they were now dependent on either visually acquiring WXB or the TCAS detecting them.

Neither crew had positively sighted the other aircraft

The pilot of WXB recalled having ZLV in sight both visually and on the TCAS screen prior to the left turn to join the circuit. If the pilot of WXB had accurately identified ZLV’s location, it is very unlikely that they would have assessed that it was safe to turn left in front of ZLV and cross their flight path. Therefore, the pilot of WXB probably did not identify ZLV visually or on the TCAS until the completion of the left turn when both aircraft were on downwind.

The flight crew of ZLV, reported that while they were on early downwind, they did not hear any broadcasts from WXB about joining the circuit. The first indicator they had that WXB was in the vicinity of their aircraft was when they received a TCAS traffic alert followed shortly after by an RA. They recalled, during their initial communications with WXB, being unsure where WXB was planning to join the circuit, which was why they were initially happy for WXB to go first. After organising separation with WXB, they reported being under the impression that WXB would slow down and join the circuit behind them either on downwind or base. They did not recall seeing WXB on the TCAS prior to the RA. The pilot flying recalled seeing WXB visually for the first time when the aircraft crossed their flight track from left to right.

Separation in a CTAF is dependent on pilots organising their own separation through radio communication, as well as conducting standard circuit procedures. Neither crew positively identified the other aircraft’s location while in, and prior to joining, the circuit, so the potential conflict was not recognised.

Conducting standard circuit procedures provides the best opportunity and risk control for aircraft to maintain separation. Finally, if available, it is also important to follow TCAS RA information. In this instance, it prevented a potential collision.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the separation issue involving a Saab 340B, registered VH-ZLV, and a Beech Aircraft B200, registered VH-WXB that occurred at Brisbane West Wellcamp, Queensland on 21 October 2021.

Contributing factors

  • The flight crew of VH-ZLV broadcast an incorrect position of their aircraft when approaching the circuit. This probably resulted in the pilot of VH-WXB misidentifying it for another aircraft in the circuit and influenced their decision to conduct a non‑standard circuit entry contrary to the traffic flow.
  • The flight crew of VH-ZLV did not effectively monitor the radio, resulting in them having an incorrect mental model of VH-WXB’s position and thus not perceiving VH-WXB as a threat.
  • The pilot of VH-WXB manoeuvred their aircraft opposite to circuit traffic direction while descending into the active side of the circuit in the vicinity of the airport resulting in a conflict with VH-ZLV.
  • Neither flight crew identified the other aircraft visually or on their TCAS, leading to VH-WXB turning in front of VH-ZLV and resulting in the crew of VH-ZLV receiving a TCAS RA.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.

Safety action by Air Charter Coordinators

As a result of this incident the operator of VH-WXB advised the ATSB that they:

  • will ensure there is a 4-minute buffer between a regular public transport (RPT) flight’s time in the circuit and theirs by holding[1] at LUKEY, to ensure that the RPT flight is on final approach when they join the circuit
  • have briefed their pilots of the event and communicated the need to adhere to the procedures written in CAAP 166 - Operations at Non-Towered Aerodromes. This included advice that when traffic congestion is anticipated, actions such as conducting orbits to allow greater spacing in traffic sequencing should be considered  
  • have discussed the traffic congestion issue with the training school based at Wellcamp and have agreed that during the scheduled arrival times of RPT aircraft, the training school will limit the number of their aircraft flying within the area.

Safety action by Regional Express Pty Ltd

The operator of VH-ZLV advised the ATSB of the following actions:

  • operations at, and in the vicinity of, non-towered aerodromes have been included as a focus item in the periodic aircrew check cycle
  • this occurrence will be used internally as a human factors case study for operations around common traffic advisory frequency airports.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the pilot in command of VH-ZLV
  • the pilot of VH-WXB
  • Regional Express Pty Ltd
  • Air Charter Coordinators
  • Airservices Australia
  • Civil Aviation Safety Authority
  • Avdata
  • OzRunways

References

Civil Aviation Safety Authority. (2019, August). Brisbane West Wellcamp Airspace Review (D19/265775). https://www.casa.gov.au/airspace-review-toowoomba-wellcamp-airport

Civil Aviation Safety Authority. (2019). CAAP 166-01 v4.2 Operations in the vicinity of non-controlled aerodromes. Civil Aviation Safety Authority. https://www.casa.gov.au/sites/default/files/caap-166-01-operations-vicinity-non-controlled-aerodromes.pdf

Civil Aviation Safety Authority. (2021). Advisory Circular AC 91-10 v1.0 Operations in the vicinity of non-controlled aerodromes. Civil Aviation Safety Authority. https://www.casa.gov.au/sites/default/files/2021-10/advisory-circular-91-10-operations-vicinity-noncontrolled-aerodromes.pdf 

Civil Aviation Safety Authority. (2020). Part 91 (General Operating and Flight Rules) Manual of Standards. Australian Government. https://www.legislation.gov.au/Details/F2021C01308/Html/Text#_Toc90102790

Civil Aviation Safety Authority. (2023). Visual Flight Rules Guide. Civil Aviation Safety Authority. Visual Flight Rules Guide | Civil Aviation Safety Authority (casa.gov.au)

Hobbs, A. (1991). Limitations of the See-and-Avoid Principle. Australian Transport Safety Bureau. /publications/1991/limit_see_avoid/  

Reynolds, R., & Blickensderfer, E. (2009). Crew Resource Management and Shared Mental Models: A Proposal. Journal of Aviation/Aerospace Education & Research, 19(1), 15-24. https://doi.org/10.15394/jaaer.2009.1380

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • the flight crew of VH-ZLV
  • the pilot of VH-WXB
  • the aircraft operators
  • the Civil Aviation Safety Authority

Submissions were received from:

  • the pilot in command of VH-ZLV
  • the Civil Aviation Safety Authority
  • Regional Express Pty Ltd

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Appendices

Appendix A – Separation and TCAS events within the circuit area at Wellcamp and Toowoomba

YearLocationOccurrence typeAircraft 1Aircraft 2Overview
2014Toowoomba

Airborne collision alert system warning | Issues

 

de Havilland DHC-8Unknown helicopterDuring initial climb, the de Havilland DHC-8 crew received a TCAS RA on a helicopter operating within the vicinity. The helicopter did not track as previously advised by its crew.
2014ToowoombaNear collisionBell 412Piper PA-38Passing 400 ft on approach, the pilot of the Bell 412 observed the Piper PA-38 cross in front in close proximity. The pilot of the 412 contacted the crew of the PA-38 which subsequently conducted a missed approach.
2016Brisbane West Wellcamp

Issues

 

Cessna 172Saab 340Passing 300 ft on climb, the Cessna 172 crew turned to maintain separation with the Saab 340 on final approach to the reciprocal runway.
2016Brisbane West Wellcamp

Airborne collision alert system warning | Issues

 

Bombardier DHC-8Beech B200The crew of the Bombardier DHC-8 conducted a missed approach into Brisbane West Wellcamp to maintain separation with the Beech B200 on approach into Toowoomba.
2020ToowoombaAirborne collision alert system warning | IssuesBeechcraft B200Diamond DA 40During initial climb, the pilot of the Beechcraft B200 received a TCAS TA on the Diamond DA 40 and turned to increase separation. It was determined the pilot of the DA 40 was found to be on the incorrect frequency.
2020Brisbane West Wellcamp

Airborne collision alert system warning

 

Saab 340Diamond DA 40During approach, the crew of the Saab 340 received a TCAS RA on the Diamond DA 40 in the circuit area.
2020Brisbane West Wellcamp

Airborne collision alert system warning | Issues

 

Socata TB-10Beechcraft B300During circuit operations, a Socata TB-10 turned inside the Beechcraft B300 that was already established on downwind. The crew of the B300 received a TCAS RA and manoeuvred to maintain separation. No radio calls were heard from the TB-10.
2021Brisbane West Wellcamp

Issues

 

Airbus A350Diamond DA 40During approach to runway 12, the Airbus A350 closed on the slower preceding Diamond DA 40 on approach to the reciprocal runway 30. The crew of the DA 40 were concerned with the horizontal separation and amended their approach to increase separation. The instructor completed a short field landing that damaged the main landing gear tyres and vacated the runway with the A350 on short final.
2021Brisbane West Wellcamp

Airborne collision alert system warning

 

Beechcraft B200Unknown aircraftAs the Beechcraft B200 joined the circuit, the pilot received a TCAS RA on another aircraft operating in the circuit.

Source: ATSB

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2023

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1]     Holding procedure: a predetermined manoeuvre which keeps an aircraft within a specified airspace whilst awaiting further clearance.

[1]     Dead side/non-active side: the area on the opposite side of the runway to where the circuit is flown.

[2]     Danger area: an airspace of defined dimensions within or over which activities of potential danger to aircraft flying over the area may exist.

[3]     En Route Supplement Australia (ERSA): a directory for Australian aerodromes that includes details of an aerodrome and details of available air traffic and ground services, navigation aids and public facilities and any special procedures.

[4]     CASA Civil Aviation Advisory Publication (CAAP) 166-01 v4.2 Operations in the vicinity of non-controlled aerodromes. February 2019. CAAP 166-01 was replaced by CASA Advisory Circular (AC) 91-10 v1.0 in 2021 to align with the new regulations.

[1]     Pilot Flying (PF) and Pilot Monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances, such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.

[2]     Instrument flight rules (IFR): a set of regulations that permit the pilot to operate an aircraft in instrument meteorological conditions (IMC), which have much lower weather minimums than visual flight rules (VFR).

[3]     Brisbane Centre is one of 2 major centres – the other being in Melbourne. From Brisbane Centre, Airservices manages the airspace over the northern half of Australia, representing around 5% of the world’s total airspace. Brisbane Centre’s flight information region (FIR) neighbours include Indonesia, East Timor, Papua New Guinea, Fiji, New Zealand, and the USA.

[4]     A common traffic advisory frequency (CTAF): a designated frequency on which pilots make positional broadcasts when operating in the vicinity of a non-controlled airport or within a broadcast area.

[5]     A waypoint is a specified geographical location used to define an area navigation route or the flight path of an aircraft employing area navigation.

[6]     Touch-and-go landing: a procedure whereby an aircraft lands and takes off without coming to a stop.

[7]     Sequence numbers specify the landing sequence position of an aircraft with respect to any preceding traffic.

[8]     Traffic alert and collision avoidance system (TCAS): a type of airborne collision avoidance system (ACAS).

[9]     Traffic advisory (TA): an alert issued by an airborne collision avoidance system (ACAS) when the detected traffic may result in a conflict. Pilots are expected to initiate a visual search for the traffic causing the TA.

[10]    Resolution advisory (RA): a manoeuvre, or a manoeuvre restriction, calculated by an airborne collision avoidance system (ACAS) to avoid a collision. Pilots are expected to respond immediately to an RA unless doing so would jeopardize the safe operation of the flight.

Occurrence summary

Investigation number AO-2021-044
Occurrence date 21/10/2021
Location Brisbane West Wellcamp Airport
State Queensland
Report release date 29/09/2023
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Separation issue
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Beech Aircraft Corp
Model B200
Registration VH-WXB
Serial number BB-1041
Sector Turboprop
Operation type Charter
Departure point Roma Airport, Queensland
Destination Brisbane West Wellcamp Airport, Queensland
Damage Nil

Aircraft details

Manufacturer Saab Aircraft Co.
Model 340B
Registration VH-ZLV
Serial number 340B-386
Aircraft operator Regional Express
Sector Turboprop
Operation type Air Transport Low Capacity
Departure point Brisbane Airport, Queensland
Destination Brisbane West Wellcamp Airport, Queensland
Damage Nil

Engine malfunction involving Cessna 441, VH-JFU, 100 km north-east of Tindal Airport, Northern Territory, on 7 September 2021

Final report

Report release date: 10/02/2023

Executive summary

What happened

On 7 September 2021, a Cessna 441, registered VH‑JFU, was being operated on a passenger charter flight from Sawfish Camp to Darwin, Northern Territory. During cruise, the pilot observed abnormal indications (torque fluctuations, high oil pressure and high oil temperature) from the right engine and diverted to Tindal. Maintenance checks identified that the air/oil cooler return line and air/oil separator vent line had been (incorrectly) transposed during a recent engine change.

After rectifications and checks were carried out, the aircraft was released to service. During a flight on 28 September 2021, the pilot observed abnormal indications (torque and oil pressure fluctuations) from the right engine. After landing, oil was observed throughout and under the right engine cowling. The reduction gearbox scavenge pump was found to be unserviceable.

What the ATSB found

The oil lines could be easily transposed given that they were flexible and long enough to reach the 2 ports that were adjacent to each other, were the same size, used the same thread and were almost identical in appearance. This presented a risk of the lines being transposed without hindrance.

It was not possible to determine whether there were any individual or environmental factors associated with the error, and the requirements to carry out an independent inspection did not include checking the oil lines.

The incorrect oil flow resulting from the transposed oil lines damaged the air/oil separator, which then increased the reduction gearbox scavenge pump pressure. This compromised the structural integrity of the pump housing and led to its subsequent failure and, ultimately, abnormal engine indications on the later flight.

The engine manufacturer had issued a service information letter (SIL) in 1990 advising that the oil lines had been transposed on several previous occasions. A limited review of previous occurrences involving such transpositions did not identify any that led to in a complete loss of power or an accident.

What has been done as a result

Following the occurrence, the operator, Chartair:

  • commenced a fleet-wide program to add markings to engine oil tanks
  • conducted toolbox talks with engineering staff about distractions during maintenance
  • commenced documenting each stage of engine changes.

In addition, Honeywell (the engine manufacturer) reissued the SIL with additional information and guidance. The manufacturer also indicated that it would revise the inspection/repair manuals with instructions to re-mark the engine oil tanks.

Safety message

The ATSB reminds maintenance engineers that it is important to check relevant documentation rather than relying on experience and memory, and to remain familiar with other data such as manufacturer service information letters.

Furthermore, since maintenance documents do not always provide advice on non-routine technical situations, operators and maintainers should seek technical advice from the manufacturer to ensure that non-routine problems are fully rectified prior to releasing an aircraft to service.

 

The investigation

Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

Previous maintenance

On 30 July 2021, a Cessna 441, registered VH‑JFU and operated by Chartair, commenced scheduled maintenance on the aircraft at Darwin Airport, Northern Territory. The right engine was removed and replaced with an engine removed from one of the operator’s other Cessna 441s. The operator had conducted about 10 such engine changes during the previous 18 months.

Throughout the following week, the engine installation and other maintenance tasks were carried out by several aircraft maintenance engineers. During the installation, the air/oil cooler return vent line and the air/oil separator vent line were inadvertently transposed when fitted to the oil tank. The fluid lines (including the lines that were transposed) were checked for tightness by the engineer certifying for the engine installation.

The engine change was recorded as being carried out in accordance with the airframe and engine maintenance manuals in the aircraft maintenance and certification record. This record was not broken down into specific sub-tasks, such as fitment of the oil lines, so there was no record of which engineer had done the work. In addition, several weeks had passed between when the work was completed and the detection of the maintenance error. As a result, it was not possible to determine the manner and context in which the work was carried out.

On 9 August 2021, engine ground runs and leak checks were carried out. No irregularities were detected. Independent inspections were completed on the engine’s controls after installation. However, the correct fitment of the oil lines was not part of the regulatory or the operator’s independent inspection requirements.[1] The aircraft was released to service on 10 August 2021.

First flight with abnormal engine indications

On 7 September 2021, about 68 flight hours after the right engine was installed, the aircraft was operated on a charter flight from Sawfish Camp to Darwin, with a single pilot and 9 passengers on board.

During cruise, the pilot saw the following indications for the right engine:

  • torque fluctuations (varying by about 200 ft-lb)
  • high and fluctuating oil pressure (between about 30 and 75 psi)
  • high temperature (100 °C).

The pilot diverted the aircraft to Tindal Airport and landed uneventfully.

Subsequent rectification actions

At Tindal, it was identified that the air/oil cooler return line and the air/oil separator vent line had been transposed (each incorrectly fitted to the wrong part of the oil tank) when fitted to the oil tank (Figure 1).

Following consultation with an engine overhaul organisation, the air/oil separator was changed, and the engine oil was checked for contamination. After the oil lines were correctly assembled, an engine run was carried out and no further defects were identified. The aircraft was released to service.

Figure 1: Oil tank fittings as found

Figure 1: Oil tank fittings as found

Source: Chartair, modified by the ATSB

Second flight with abnormal engine indications

During a flight on 28 September 2021, the pilot observed torque and oil pressure fluctuations on the right engine.[2] The flight continued to its destination. After landing, oil was observed throughout and under the right engine cowling. The reduction gearbox scavenge pump was later found to be cracked (see Figure 3). The aircraft had flown about 114 hours since the right engine was installed, and about 46 hours since the transposition of the air/oil cooler return and the air/oil separator vent lines had been rectified.

Context

Aircraft information

The aircraft was a Cessna 441 (Conquest II) 11-seat pressurised aeroplane powered by 2 Honeywell TPE-331-10 engines. It was manufactured in 1980 and first registered in Australia on 2 May 2012.

Engine information

Oil tank and fittings

The externally mounted engine oil tank incorporated 2 adjacent fittings that were almost identical in appearance, were the same size, and used the same thread (Figure 2). These 2 fittings included:

  • an upper fitting for oil returning to the tank from the air/oil cooler
  • a lower fitting for an overboard vent line from the air/oil separator.

The fittings were labelled, but the markings were anecdotally reported to wear off in‑service (Figure 2). These markings were not present on VH-JFU’s right engine at the time of the engine change.

The air/oil separator was mounted inside the oil tank and consisted of a tube that contained a screen and several Teflon ribbons. Air/oil vapour returning to the oil tank passed through the air/oil separator (where the oil vapour adhered to the Teflon ribbons) and, after coalescing, re-entered the oil supply. The remaining air was vented overboard.

When installed on a Cessna 441, separate flexible lines were attached to the air/oil cooler return and the air/oil separator. The lines were removed and installed using the same size spanner and the lines were typically long enough to reach both ports.

Figure 2: TPE331 oil tank assembly

Figure 2: TPE331 oil tank assembly

Source: Honeywell, modified by the ATSB

Service information letter

In May 1990, the engine manufacturer published service information letter (SIL) P331-115 to advise maintenance and engineering personnel that the air/oil cooler return line and the air/oil separator vent line could be transposed. It stated:

There have been several instances in the field where the lines attached to the oil tank were reversed. Specifically, the oil "scavenge return" line has been reversed with the "overboard vent" line. In this case, some of the teflon ribbons in the air-oil separator at the top interior of the oil tank have been forced into the oil tank by the greater pressure exerted by the scavenge return oil. The teflon ribbons may eventually pass from the oil tank through the pressure oil pump in the gearbox and on to the oil filter.

The SIL included 2 illustrations showing the correct orientation of the lines.

The SIL was revised in August 2022 (after the occurrence involving VH-JFU), adding a template for the reapplication of the oil tank markings. It also noted:

Blockage of the air/oil separator from the collapsing teflon ribbons may result in severe damage to the gearbox scavenge pump, including fracture of the pump housing with a resultant loss of oil supply and pressure.

Operator requirements for engine changes

The operator conducted maintenance in accordance with its system of maintenance and the manufacturer’s technical documentation. Technical documentation was produced by the manufacturers of aircraft, engines, and components. Manufacturer documentation was also available from third-party providers.

Aircraft Technical Publishers (ATP) provided operators with an alternative source for maintenance information and was used by the operator for this purpose. The operator used the airframe and engine maintenance manuals for engine removal and installations. The engine removal and installation sections of these manuals correctly showed the orientation of the air/oil cooler return and the air/oil separator vent lines.

Effects of transposed oil lines

The engine manufacturer advised that flow reversal from the incorrect fitment of the air/oil cooler return line to the air/oil separator would have compacted the Teflon[3] ribbons inside the air/oil separator.

After the 28 September 2021 (second) occurrence involving VH-JFU’s right engine, the operator’s maintenance personnel consulted with an engine overhaul facility regarding the possible nature of the defect. The facility suggested the reduction gearbox scavenge pump may be unserviceable and provided a method to check its output pressure. When tested, the pump pressure was considerably lower than specification.

The engine was removed and sent to an overhaul facility. The engine was disassembled, and the reduction gearbox scavenge pump housing was found to be cracked (Figure 3). The engine manufacturer advised the ATSB that the Teflon ribbons would have been compacted inside the air/oil separator following incorrect fitment of the air/oil cooler return line. This would have increased the reduction gearbox scavenge pump pressure and compromised the structural integrity of the pump housing.

Figure 3: Cracked reduction gearbox scavenge pump housing

Figure 3: Cracked reduction gearbox scavenge pump housing

Source: TAE Aerospace and Honeywell, modified by the ATSB

The air/oil cooler return and the air/oil separator vent lines had been incorrectly transposed on other aircraft previously. Although the frequency of this is not known, a limited ATSB search of other occurrences did not identify any that led to a complete loss of power or an accident.

The engine manufacturer advised the ATSB that, as well as being detectable through visual inspection of the engine, an early symptom of this transposition occurring could be excessive engine oil venting out of the vent line. The engine manufacturer advised that, when there was no damage to the engine, this could be resolved by returning the lines to the correct configuration. However, if there was also a loss of reduction gearbox scavenge pump pressure, this might indicate damage to the air-oil separator and gearbox oil scavenge pump.

Safety analysis

Unintentional transposition of oil lines

When the right engine was fitted to VH-JFU, the air/oil cooler return and the air/oil separator vent lines were incorrectly transposed. The airframe and engine maintenance manuals correctly showed the orientation of the air/oil cooler return and the air/oil separator vent lines. Accordingly, there was sufficient accurate information available for engineers to be aware of the possibility of inadvertent oil line transposition.

As there was no record of which engineer had done the work, it was not possible to determine whether there were any individual or environmental factors associated with the error, or the extent to which the available maintenance documentation had been checked.

Memory of how to do specific tasks is not always reliable, especially for tasks that are not performed frequently. Ideally, the potential for this type of foreseeable error needs to be designed out of the task or, if that cannot be practicably achieved, brought to the engineer’s attention (through referral to instructions, diagrams, or other information) as the task is performed.

This type of error was possible because the 2 lines were flexible and could reach (and be fitted to) both ports, which were adjacent to each other. The fittings were the same size, visually similar, and the same spanner would have been used to attach the lines. This presented a risk of the lines being transposed without hindrance. A limited review of occurrences did not identify any previous occurrences that led to in a complete loss of power or an accident.

The manufacturer had implemented controls that would help prevent this error occurring. These included markings showing the correct position of the lines, but they could wear off in service. The markings were not present on VH-JFU’s engine oil tank at the time of the maintenance error and therefore there was no prompt to check the correct fitment. As a result, there would have been no clear indications of which way around the 2 lines should be fitted, and there was a risk of inadvertent transposition.

The engine manufacturer had identified this possibility of these lines being transposed and published a service information letter about it in 1990 and revised in 2022. Although there was no change to the oil tank design, so the possibility of transposition of the oil lines remained, the 2022 service letter included a template for the reapplication of its markings.

The error was not detected by the person carrying out the work or when the certifying engineer checked the engine installation prior to releasing the aircraft. The requirements to carry out an independent inspection did not include checking the oil lines.

Non-detection of engine damage

During the flights totalling 68 hours with the oil lines transposed, the right engine was damaged to an extent that later led to further engine malfunction. This damage was not initially detected during post-occurrence maintenance activities. Since this occurrence, the engine manufacturer added information to the existing service information letter to reduce this risk.

As non-normal configurations such as the oil cooler return line and the air/oil separator outlet line being transposed are generally not included in maintenance documents, operators and maintainers should seek technical advice from the manufacturer to ensure that non-routine problems are fully rectified prior to releasing the aircraft to service.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the engine malfunction involving a Cessna 441, registered VH-JFU, 100 km north-east of Tindal Airport, Northern Territory, on 7 September 2021.

Contributing factors

  • During the installation of the right engine, the oil cooler return line and the air/oil separator outlet line were transposed when attached to the oil tank.
  • The oil cooler return and the air/oil separator outlet flexible lines could be easily transposed given that their fittings were adjacent to each other, of the same size, and visually similar. Additionally, as occurred in this case, their markings on the oil tank could wear off in service.
  • The inspections carried out to check the newly-installed engine did not detect the incorrect transposition of the oil cooler return and the air/oil separator outlet lines.

Other factors that increased risk

  • When the oil lines were returned to the correct position, the damage to the reduction gearbox scavenge pump housing was not detected and the aircraft was returned to service.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Safety action by Chartair

After the occurrence, the operator:

  • commenced a fleet-wide program to apply markings to the oil tanks on its Cessna 441 fleet
  • conducted toolbox talks with engineering staff
  • expanded the maintenance log entry requirements for engine changes.

Safety action by Honeywell

On 18 August 2022, Honeywell (the engine manufacturer) reissued service information letter (SIL) P331-115 about the potential transposition of the oil lines with additional information and guidance. Specifically, the manufacturer provided a template for the reapplication of the oil tank markings. It also noted:

Blockage of the air/oil separator from the collapsing teflon ribbons may result in severe damage to the gearbox scavenge pump, including fracture of the pump housing with a resultant loss of oil supply and pressure.

The manufacturer also advised that it would revise the inspection/repair manuals with instructions to re-mark the engine oil tanks.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • aircraft operator
  • aircraft manufacturer
  • engine manufacturer.

References

Cessna Aircraft Company, Model 441 Maintenance Manual, chapter 71-00-03, 3 September 1984.

Garrett Airesearch, Maintenance Manual TPE331-8/-9, chapter 79-10-01, 31 July 1984.

Submissions

Submissions were received from:

  • the aircraft operator
  • the engine manufacturer.

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2023

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1]     CAR 42G required independent inspections to be carried out on flight control systems when they were disturbed during maintenance. The operator expanded these requirements to include engine controls.

[2]     Details of this flight, such as origin and destination, were not provided.

[3]     Teflon: a trade mark used for polytetrafluoroethylene (PTFE) and other fluoropolymers.

Occurrence summary

Investigation number AO-2021-039
Occurrence date 07/09/2021
Location 100 km north-east of Tindal Airport
State Northern Territory
Report release date 10/02/2023
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Abnormal engine indications
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model 441
Registration VH-JFU
Serial number 441-0158
Aircraft operator CHARTAIR PTY LTD
Sector Turboprop
Operation type Charter
Departure point Sawfish Camp Aerodrome, Northern Territory
Destination Darwin Airport, Northern Territory
Damage Nil

Fuel imbalance and engine shutdown involving Boeing 737, VH-VZT, 135 NM south of Kalgoorlie-Boulder Airport, Western Australia, on 25 October 2021

Final report

Report release date: 28/02/2024

Executive summary

What happened

On the afternoon of 25 October 2021, a Boeing 737 aircraft, registered VH‑VZT and operated by Qantas, was being prepared for a passenger air transport flight from Perth, Western Australia to Adelaide, South Australia. During a routine external aircraft check (‘walk-around’), the captain identified the presence of frost on the wings, resulting from cold fuel from the previous flight in the main tanks located in the wings and presenting a safety risk. To remove the frost, the cold fuel was transferred from the main (wing) tanks to the centre tank, and the main tanks were filled with warmer fuel via refuelling.

Just after reaching the assigned cruise altitude, the flight crew completed a routine procedure to switch the centre tank fuel pumps off and the aircraft began to use main tank fuel. At about 1749 a fuel imbalance alert was displayed, indicating unequal fuel quantities in each main tank. While actioning relevant checklists the flight crew diagnosed the reason for the unequal fuel quantities was a fuel leak and shut down the left engine. The flight diverted to Kalgoorlie, Western Australia where the aircraft landed without incident. Post-flight inspections determined that there was no fuel leak and that the fuel system was serviceable.

What the ATSB found

The licensed aircraft maintenance engineer (LAME) directed the flight crew on the fuel transfer from memory. The procedures required the crossfeed valve to be closed when the operation was completed, however, the valve was not closed. This was likely associated with the crew following the LAME’s instructions rather than referring to the relevant procedure. While this is permissible, referring to procedures is a more reliable method to ensure all steps are carried out.

During pre-flight checks, and later during the climb and level-off, the flight crew did not notice the crossfeed selector in the open position or the associated dimmed blue indicator light on the fuel panel. In flight, after the centre tank fuel pumps were switched off, fuel had been continually pumped from the left main tank to the right engine via the open crossfeed valve as the result of uneven fuel pump pressures. Although the aircraft’s manuals stated that this could occur when the crossfeed valve was open in flight and lead to a fuel imbalance, the flight crew did not recall this at the time. In addition, the Boeing 737 IMBAL (imbalance) checklist did not provide sufficient guidance for a flight crew to identify an open crossfeed valve as being a potential reason for a fuel imbalance. Consequently, the flight crew decided that there could be a fuel leak.

Partly as a result of confirmation bias, stress and perceived time pressure with the aircraft approaching an overwater segment of the flight, the flight crew abbreviated the relevant checklists. Flight crew actions when completing the Fuel leak engine checklist resulted in them mistakenly confirming the presence of a fuel leak, but unknown to the flight crew at the time, the method used to determine the presence of a fuel leak was invalid due to a step being inadvertently performed out of sequence.

As a result, the crew unnecessarily shut down an engine during flight.

What has been done as a result

Following the occurrence, Qantas communicated the factors involved to 737 flight crews.

Safety message

Checklists are designed to minimise performance variability under workload and stress, and thereby increase the likelihood that all required actions are successfully carried out. The importance of precision when following checklists, especially when under stress and time pressure, is highlighted by this occurrence.

 

The investigation

Decisions regarding the scope of an investigation are based on many factors, including the level of safety benefit likely to be obtained from an investigation and the associated resources required. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

Pre-flight activities

On the afternoon of 25 October 2021, a Boeing 737-838 aircraft, registered VH‑VZT and operated by Qantas, was being prepared for a passenger air transport flight from Perth, Western Australia to Adelaide, South Australia.

The first officer (FO), who was undergoing line training,[1] was assigned the pilot flying role and the captain (a check and training captain) was the pilot monitoring.[2] The captain was responsible for the external aircraft check (‘walk-around’), and the FO had responsibility for conducting the flight deck pre-flight procedure.[3]

The captain made their way to the apron for the walk-around at about 1627, and at the same time the refueller positioned their vehicle at the aircraft to commence refuelling.[4] During the walk‑around, the captain saw extensive cold soaked fuel frost[5] (CSFF) on the lower surfaces of both wings, which had formed after the previous flight (see Cold soaked fuel frost).

At the completion of the walk-around, the captain located the licenced aircraft maintenance engineer (LAME) responsible for the aircraft’s line certification and maintenance. They discussed the presence of CSFF, and noted that the temperature of the fuel onboard was -4° C (there was 4.2 tonnes of fuel remaining after the previous flight, with 2.1 tonnes in each of the 2 main, or wing, tanks). The LAME suggested conducting a ground transfer of fuel to attempt to remove the CSFF, to which the captain agreed. This process transfers cooler fuel from the 2 main tanks to the centre tank, making room in the main tanks to receive warmer fuel when the aircraft is refuelled to melt the CSFF. At about 1631, the captain returned on board the aircraft. The captain recalled that after boarding the aircraft they went to the washroom, and then returned to the flight deck.

Ground transfer of fuel

The following sequence of events was reconstructed mainly from CCTV recordings and interviews with the flight crew and LAME. The cockpit voice recorder (CVR) data was later overwritten, and the other on-board recorders did not contain data relevant to this period.

The FO recalled that the fuel transfer began with the captain on the flight deck, after the captain returned from the walk-around, and that the captain mentioned the presence of CSFF. However, the captain recalled that a fuel transfer (to remove the CSFF) was underway when they returned to the flight deck.

At about 1631, the LAME placed an access stand (moveable ladder/platform) under the fuelling station located near the leading edge of the right wing. About this time, the LAME asked the refueller to delay the fuelling to allow for the fuel transfer to be conducted. The LAME then opened the defuel panel (located next to the fuelling station) and opened the manual defueling valve.

Based on the CCTV recording, the LAME got the flight crew’s attention at about 1633. The LAME recalled instructing the FO to switch on all the main tank fuel pumps and to open the crossfeed valve. The FO recalled that both flight crew heard this over the flight deck speakers. The FO recalled complying with the LAME’s verbal instructions (without referring to the written procedures) by reconfiguring the forward overhead fuel panel, under the captain’s supervision. As stated previously, the captain recalled returning to the flight deck after the fuel transfer was begun.

The CCTV showed the LAME returning to the right wing and accessing the defuel panel at about 1634. The LAME recalled that they opened the centre tank fuelling valve switch, and monitored the fuel transfer via the tank quantity gauges on the fuelling panel.

Between 1637:02 and 1637:22, the LAME inspected the right and left lower wing surfaces, then returned to monitor the fuel transfer. Because of fuel pump operating limitations, this allowed for 1 tonne of fuel to be safely transferred to the centre tank from the main tanks. The LAME recalled assessing that, based on the planned uplift of fuel, moving 500 kg of fuel out of each main tank into the centre tank would not be sufficient to allow enough warmer fuel to be uplifted to melt the CSFF.

The planned total amount of fuel for the next flight was 8.6 tonnes (requiring 4.4 tonnes to be uplifted by the refueler). The LAME recalled they contacted the flight crew 3 times to request an increase to the fuel order and that their requests were not accepted until the third time.[6] According to the LAME, shortly after this they saw that the fuel was pumping out of the right tank faster than the left tank and instructed the FO to turn off the right main tank fuel pumps.

The FO recalled only one discussion about an increase to fuel and that the captain was present at the time. The captain recalled one discussion during which the LAME advised that a patch of CSFF remained on one of the wings and recommended adding extra fuel to melt it.

Ultimately the captain requested an additional 1 tonne of fuel be uplifted. The LAME recalled that not long after this, they instructed a flight crew member to switch off the left main fuel pumps and to close the crossfeed valve. The LAME could not recall with certainty who they spoke to but believed it was the FO. The FO did not recall hearing back from the LAME regarding the completion of the fuel transfer.

The Before start checklist required the crew to ensure the fuel pumps were on, the switches for which were on the same overhead panel as the crossfeed selector. As the FO was undergoing line training, the captain scanned the overhead panel. They recalled looking at the fuel pump switches but not the crossfeed selector. Additionally, they did not notice the dimmed[7] blue light located on the overhead fuel panel which indicated the crossfeed valve was open. The captain stated glare from the sun may have hindered their ability to notice the dimmed light.

Preparation for pushback and taxi

At 1638:39, upon completion of the fuel transfer, the LAME closed the defuel valve and the defuel panel. The LAME recalled advising the refueller of the revised fuel order and that fuelling could commence, and removed the access stand clear of the aircraft.

Fuelling was completed at 1648. Both flight crew recalled the flight deck fuel indications showing 9.6 tonnes, and the captain observed the fuel distribution between the centre and main fuel tanks was as expected. The FO did not recall any communication with the LAME about the crossfeed valve at this time. The FO recalled the captain requesting all fuel pumps be turned on and interpreted this to be the end of the fuel transfer procedure but could not recall the fuel crossfeed valve position. Furthermore, the FO did not recall a discussion that the frost had been removed from the aircraft wings.

After the passengers were on board, the flight crew conducted the before start procedure and at 1702 the aircraft was pushed back from the bay and commenced taxi to the runway for take-off. At this time, the fuel quantity in each main tank was approximately equal.

Commencement of imbalance

The aircraft took off from Perth at 1711, and by 1731 had reached the cruising altitude of 39,000 ft. At 1733, the annunciator light FUEL illuminated. Both flight crew recalled looking at the overhead fuel control panel and as they expected at this point in the flight,[8] observing both centre tank fuel pump LOW PRESSURE amber lights illuminated (which can indicate low fuel in that tank). After confirmation by the FO, the captain selected both centre tank fuel pumps off. Neither flight crew recalled observing any other light illuminated on the fuel panel.

At about this time, the captain made a mental calculation adding the quantity of fuel used to the current fuel quantity remaining in each main tank and confirmed the total was equal to the departure fuel quantity.

Recorded data indicated that the fuel quantities in the left and right fuel tanks began to differ at this time, as the fuel used by the engines was mostly drawn from the left fuel tank (see Operation with the fuel pumps on and crossfeed valve open). The rate of fuel imbalance change over the next 35 minutes averaged about 1,700 kg/h, with significantly more fuel being used from the left fuel tank than the right throughout this period. Fuel flow to each engine was approximately equal throughout the flight until the left engine was later shut down.

At about 1748, an amber fuel IMBAL (imbalance) alert appeared on the upper display unit in the centre of the instrument panel. This alert is triggered when the difference in fuel quantity between the main tanks is more than 453 kg for at least 60 seconds and is not associated with an audible indication or master caution.

Identification of imbalance and conduct of relevant checklists

The following events are mainly based on the flight crew recollections, and it was not possible to determine their actual sequence.

When the flight crew noticed the IMBAL alert, they looked at the fuel control panel and confirmed that the main fuel tank pumps were all on.

At 1753, the FO wrote down the left and right fuel tank quantities and the current time. The captain recalled that this was done when they saw the IMBAL alert. The quantities were consistent with the recorded data at this time, and the fuel imbalance (difference between the quantities) was 630 kg.

More than half of the aircraft’s planned flight path to Adelaide was over water, and the latter half would be at night. The captain reported feeling time pressure to determine the most appropriate actions as the aircraft approached the coastline; at this time the aircraft was less than 15 minutes from crossing it. The FO reported experiencing elevated stress with the increasing workload and recalled becoming focused more on flying the aircraft.

The flight crew initiated the quick reference handbook (QRH) IMBAL (fuel imbalance) non-normal checklist (NNC) with the captain (as pilot monitoring) referring to the physical book on the flight deck (see Fuel imbalance and engine fuel leak checklists for the content of the relevant checklists). Step 3 of the IMBAL checklist stated that a fuel leak should be suspected if the total fuel remaining is less than planned, or if an engine has excessive fuel flow. If a fuel leak was suspected, the checklist directed flight crews to the Fuel leak engine checklist.

The captain saw the fuel quantity indication for the left tank reduce at a high rate and thought that there must be a fuel leak. The captain also confirmed around this time that other engine and fuel indications appeared normal.

While neither criterion had been met, the flight crew agreed that a fuel leak was suspected and commenced the Fuel leak engine checklist. Step 3 of this checklist required the flight crew to confirm that the crossfeed selector was closed (or close it). According to the captain’s recollection, while actioning the checklist, the captain identified that the crossfeed valve switch was in the open position and moved it to the closed position. At the time, neither pilot recalled that flight with the crossfeed valve open would lead to a progressive fuel imbalance (see Aircraft fuel system). With the crossfeed valve closed, each engine would draw fuel only from the same-side tank.

Step 5 of the Fuel leak engine checklist required the flight crew to record the main tank fuel quantities and the current time. Step 6 of the checklist stated that a fuel leak is ‘confirmed’ if:

  • fuel spray is observed from an engine or strut, or
  • if there is a change in fuel imbalance of 230 kg within 30 minutes or less (equivalent to 460 kg/h).

The captain contacted the cabin service manager (CSM) and requested they look out a rear cabin window for signs of a fuel leak. The CSM advised the captain they could not see any indication of a fuel leak.

The FO recalled checking the fuel imbalance again about 2 minutes after writing the quantities down, showing an increase in imbalance greater than 230 kg per 30 minutes, although the exact time at which this assessment was done could not be established. The actual imbalance increased by 230 kg within 10 minutes. Within the limitations of the recorded data,[9] the average imbalance rate appeared lowest from about 1753–1755, at about 225 kg/h.

Aware of the risk of commencing the overwater section of the flight with an apparent fuel leak and likely imminent engine shutdown, the flight crew considered diversion options, which included Perth and Kalgoorlie-Boulder, Western Australia. Accordingly, the flight crew prepared for a diversion to Perth.

Diversion, engine shutdown and landing

At 1800, the flight crew advised air traffic control of their intention to return to Perth and commenced a turn at 1801. The flight crew then discussed Kalgoorlie-Boulder Airport was closer and had fire services available. At 1805 the flight crew declared a PAN[10] and prepared for a landing at Kalgoorlie-Boulder Airport, commencing descent at 1806.

Continuing the Fuel leak engine checklist, and having considered the rapid reduction of fuel in the left tank being indicative of a fuel leak, the flight crew shut down the left engine at 1806:58. At this time there was about 6,423 kg of fuel on board, including about 3,701 kg in the right tank. The checklist did not require the crossfeed valve to be reopened unless there was a Fuel LOW alert. At 1807:41 the flight crew started the auxiliary power unit (APU) in accordance with the Fuel leak engine checklist. The APU, which draws fuel from the left main tank, consumed about 34 kg over the remainder of the flight.

From about 1808 to 1812, the fuel quantity in the left main tank was steady. From 1812 to the end of the flight, the fuel quantity in each main tank decreased at an almost equal rate (indicating that the crossfeed valve was open during this period).

The aircraft landed at Kalgoorlie-Boulder Airport on runway 29, coming to a stop on the runway at 1852 with about 5,357 kg of fuel remaining on board, including 3,225 kg in the right tank. The flight crew then made an alert announcement to the cabin. The left engine was inspected and declared safe by the Aviation Rescue Fire Fighting Service (ARFFS), and the cabin alert was cancelled. The aircraft was then taxied to the bay and the passengers were disembarked.

The aircraft was inspected and tested at Kalgoorlie by aircraft maintenance engineers. They determined that:

  • there were no fuel leaks or other relevant unserviceabilities
  • when tested, the fuel used by both engines was within normal limits
  • the fuel quantities in each tank after landing (2.05 tonnes in the left main tank and 3.18 tonnes in the right main tank) met the criteria for a fuel imbalance.[11]

After receiving information from the flight crew, the operator concluded that the crossfeed valve had likely been open during the occurrence flight, and this led to the fuel imbalance (see Operation with the fuel pumps on and crossfeed valve open). The aircraft was then returned to service.

Context

Personnel information

Captain

The captain held an Air Transport Pilot (Aeroplane) Licence (ATPL) and was appropriately qualified and authorised to conduct the flight. The captain had almost 12,000 hours total flying experience with over 5,000 hours on 737 variants. The captain was a check and training pilot for the operator and had flown about 110 hours in the previous 90 days.

As a result of the Qantas response measures to COVID-19[12], the captain was stood down from mid-April 2020 until 23 September 2020. Upon completion of simulator training, they returned to flying duties at the end of September 2020. Although the captain remained stood up after that time, their monthly rostered flying hours were lower than was usual prior to the pandemic. In the 12 months prior to the event, they flew 40% of the hours they had flown in the 12 months prior to stand down. In the 3 months immediately prior to the event flight, their monthly average flying hours were roughly half their pre-pandemic average. The captain reported that while being comfortable to fly, because of the stand down and reduced flying hours, they noted a degradation in their skills.

First officer

The FO held a Commercial Pilot (Aeroplane) Licence and was appropriately qualified and authorised to conduct the flight. The FO had about 1800 hours total flying experience and about 110 hours on the 737. The FO had flown about 24 hours in the previous 90 days. The FO was undergoing line training and was qualified to act as a first officer on revenue flights alongside a check and training captain.

The FO joined Qantas as a second officer on the Boeing 787 fleet. In 2019 they commenced FO promotion and 737 type rating training, however soon after this was delayed. The FO’s training recommenced in May 2021. As a result of Qantas’ COVID-19 response measures, the FO was stood down between September and October 2021, re-commencing flying duties mid-October 2021.

Licenced aircraft maintenance engineer

The LAME was employed by Qantas, and the holder of an Australian Aircraft Maintenance Engineers Licence. The LAME’s licence was appropriately endorsed, and they were authorised to conduct maintenance on Boeing 737-838 aircraft in the Qantas fleet.

Recorded data

Flight data (Figure 1) showed that after the fuel in the centre tank had been consumed, an imbalance between the left and right main fuel tanks began to develop and was maintained for the remainder of the flight.

Figure 1: Fuel quantities on the occurrence flight

Figure 1: Fuel quantities on the occurrence flight

Image source: ATSB.

Aircraft manuals

The Boeing aircraft maintenance manual (AMM) contained procedures to carry out maintenance and testing on the aircraft. It was primarily used by maintenance personnel and generally not available to flight crews. The Qantas fuelling manual contained procedures for maintenance personnel, fuel company staff, and flight crew.

The aircraft’s flight crew operation manual (FCOM) was prepared by Boeing and reproduced by Qantas. It comprised of 2 volumes plus a quick reference handbook (QRH). Volume 1 included guidance for ground transfer of fuel. Volume 2 contained systems information.

Cold soaked fuel frost

Background

Aircraft such as the 737 typically cruise at altitudes around 40,000 ft where the outside air temperature can be as low as -57° C. On longer flights such as Australian transcontinental flights, the temperature of the fuel in the main tanks decreases considerably, a phenomenon known as cold-soaking. After a flight, the temperature of the fuel in the main tanks may be at a sufficiently low temperature such that it lowers the wing skin temperature to below the freezing point.

Between flights, if there is rain or high humidity and regardless of the ambient temperature, ice can form on the upper and lower surfaces of the cold-soaked wings and accumulate over time. This ice can be invisible to the eye (referred to as clear ice) or visible frost.

The presence of any ice or frost on the wings of an aircraft prior to flight can significantly reduce lift, and therefore compromise take-off and flight performance. The US Federal Aviation Administration (FAA) approved de-icing program update[13] stated:

Frost has the appearance of being a minor contaminant and does not display the same obvious danger signal as do other types of contamination, such as snow or ice. However, frost is a serious threat to the safety of aircraft operations because it always adheres to the aircraft surface, is rough, and causes significant lift degradation and increased drag.

For the 737, take-off is permitted with cold soaked fuel frost (CSFF) on the wings provided strict conditions are met. Outside these conditions, ice or frost formations on upper or lower wing surfaces must be removed. General guidance in the Qantas de-icing/anti-icing procedure manual stated:

During conditions conducive to aircraft icing during ground operations, takeoff shall not be attempted when ice, snow, slush or frost is present or adhering to the wings, propellers, control surfaces, engine inlets or other critical surfaces. This is known as the “Clean Aircraft Concept”. Any deposit of ice, snow or frost on external surface of an aircraft, except as permitted in the Flight Crew Operations Manual, may drastically affect its performance due to reduced aerodynamic lift and increased drag resulting from disturbed airflow.
Removal of cold soaked fuel frost by fuel transfer

In colder climates, frost, snow, and ice is removed with fluids applied to the aircraft with dedicated equipment. For ports where this equipment is unavailable, the cold soaked fuel can be transferred into the aircraft’s centre tank making room for the wings to be refuelled. The introduced fuel is warmer, and therefore frost and ice can be prevented or removed.

Qantas advised that fuel transfers were usually carried out by LAMEs, however during the COVID‑19 pandemic flight crew were sometimes required to carry out the flight deck actions because of quarantine requirements (keeping flight and ground crews more separate).

There were 3 documents available to Qantas staff that contained the procedural requirements to carry out a fuel transfer – the Boeing AMM used by maintenance personnel, the Qantas fuelling manual used by maintenance personnel and flight crews, and the flight crew operation manual (FCOM) used by flight crews. The procedures to transfer fuel differed, with several steps presented in a different order across the 3 documents.

Aircraft fuel system

Description and operation

The 737 fuel system (Figure 2) comprised the following major components:

  • 3 fuel tanks – left and right main tanks in the wings, and a centre tank
  • 2 fuel pumps for each tank
  • an engine and APU fuel feed system (including a crossfeed allowing engines to be fed from any tank)
  • a fuel quantity and temperature indicating system
  • a refuel / defuel system.

Figure 2: Fuel system schematic

Figure 2: Fuel system schematic

Image source: Boeing, annotated by the ATSB.

Operation with the fuel pumps on and crossfeed valve open

The description of the fuel system in Volume 1 of the FCOM stated that the fuel pumps supplied both engines from the centre tank until the centre tank quantity decreased to near zero. The fuel pumps normally then supplied the engines from their respective main tanks. The centre tank fuel pumps produced higher pressure than the main pumps to ensure that centre tank fuel was used before the main tank fuel, even with all fuel pumps in operation.

The FCOM also stated that continued flight with the crossfeed valve open would result in a progressive fuel imbalance. The 737 flight crew training manual (FCTM) stated:

…the fuel pumps in the airplane have allowable variations in output pressure. If there is a sufficient difference in pump output pressures and the crossfeed valve is opened, fuel feeds to the operating engine from the fuel tank with the highest pump output pressure. This may result in the fuel unexpectedly coming from the tank with the highest output pressure.

Fuel imbalance condition

The FCTM stated that aircraft controllability was not significantly affected by a fuel imbalance but that its structural life could be reduced by frequently operating with an out-of-limit fuel balance condition. It stated that the primary purpose of fuel balance alerts is to prevent higher fuel consumption that results from increased trim drag.

Diagnosis of a fuel imbalance condition

The FCTM stated:

One [fuel] tank indicating abnormally low can be caused by a fuel leak, engine out or a crossfeed problem. With an engine out, if the totalizer and calculated values are tracking as expected, a fuel leak would not be suspected. A fuel pump with higher pressure and a faulty crossfeed valve can cause one tank to provide fuel to more than one engine, causing one tank to indicate low. In this case, the fact that total fuel should still match planned fuel, a fuel leak would not be suspected.

The FCTM additionally stated:

Any time an unexpected fuel quantity indication, FMC [flight management computer] fuel message, or imbalance condition is experienced, a fuel leak should be considered as a possible cause. Maintaining a fuel log and comparing actual fuel burn to the flight plan fuel burn can help the pilot recognize a fuel leak.
Some fuel-related checklists (for example, IMBAL) list reasons that a fuel leak should be suspected. This list is not exhaustive and, in all cases the Flight Crew should use their knowledge of the fuel system and current operating conditions to determine whether a fuel leak should be suspected.

On the position of the crossfeed valve after an in-flight engine shutdown, the FCTM stated:

There is a common misconception among Flight Crews that the fuel crossfeed valve should be opened immediately after an in-flight engine shutdown to prevent fuel imbalance. This practice is contrary to Boeing recommended procedures and could aggravate a fuel imbalance. This practice is especially significant if an engine failure occurs and a fuel leak is present. Arbitrarily opening the crossfeed valve and starting fuel balancing procedures, without following the checklist, can result in pumping usable fuel overboard.
 
Fuel imbalance and engine fuel leak checklists

The QRH provided instructions for abnormal situations and to where possible return the aircraft to a normal operating state. Flight crews accessed the section relevant to the abnormal situation and followed the QRH procedural steps sequentially. Decision points in the QRH procedural steps in some cases led to another QRH section depending on the nature of the abnormal situation that was being diagnosed.

The QRH IMBAL checklist is shown in Figure 3. From step 5, the checklist contained steps to verify the functionality of the crossfeed valve, rectify the imbalance if the valve is serviceable, and then close the valve.

Relevant sections of the Fuel leak engine checklist are shown in Figure 4 and Figure 5. From step 11, the checklist contained steps to shut down the affected engine, including starting the APU when available and (only when a fuel low alert is shown) opening the crossfeed selector.

Figure 3: QRH IMBAL checklist

Figure 3: QRH IMBAL checklist

Image source: Boeing.

Figure 4: QRH Fuel leak engine checklist (first 2 pages)

Figure 4: QRH Fuel leak engine checklist (first 2 pages)

Image source: Qantas.

Figure 5: QRH Fuel leak engine checklist (remaining pages)

Figure 5: QRH Fuel leak engine checklist (remaining pages)

Image source: Qantas.

Safety analysis

Introduction

When carrying out an exterior inspection of the aircraft prior to departure, the captain observed extensive cold soaked fuel frost on the lower surface of both wings. The presence of frost is a risk to flight safety, and the captain and the attending licenced aircraft maintenance engineer agreed on removing the frost by a ground transfer of fuel. This was carried out by the engineer and the first officer (FO). Transferring fuel from the main tanks to the centre tank required the crossfeed selector (in the flight deck) to be opened to commence the transfer and closed once completed.

The procedural step to close the crossfeed valve was not carried out, and the aircraft was dispatched. This resulted in a progressive fuel imbalance, which was misdiagnosed by the flight crew as a fuel leak. As a result, the left engine was shut down in flight unnecessarily and the aircraft was diverted to Kalgoorlie-Boulder.

The analysis will examine the coordination of pre-departure fuel transfer procedures, and the flight crew’s management of the fuel imbalance.

Fuel transfer coordination

The licensed aircraft maintenance engineer (LAME), who was licenced on the aircraft type, drew on their technical knowledge of the aircraft’s systems to facilitate the fuel transfer, and the FO recalled being directed to carry out the required actions in the flight deck. It could not be established when the captain arrived on the flight deck but the captain was present later to approve the additional fuel.

The recollections of the LAME, captain and FO differed in regard to the completion of the fuel transfer. As the captain needed to authorise the change in fuel uplifted, it is likely that both flight crew were on the flight deck at the conclusion of the fuel transfer when the crossfeed valve was to be closed.

However, the procedural step to close the crossfeed valve was not carried out. This was likely associated with the FO and/or captain following the LAME’s instructions rather than referring to the relevant procedure. While this is permissible, referring to procedures is a more reliable method to ensure all steps are carried out. In any case, there was insufficient evidence to determine the reasons for the crossfeed valve not being closed.

There are numerous tasks that may be carried out without referring to a procedure. However, for tasks that are infrequently performed or that may be unfamiliar, the use of a procedure increases the likelihood they will be accomplished successfully.

Flight with open crossfeed valve

During subsequent preparations for the flight, the captain and FO did not identify that the crossfeed selector had remained in the open position, and at the time its accompanying ‘valve open’ light would be dimmed. As the fuel panel was out of the normal field of view, the selector position and indicator light would not be readily detectable.

Neither flight crew member noticed the crossfeed selector was positioned to open or the dimmed blue ‘valve open’ light immediately above it on the overhead fuel panel during the first part of the flight. There was no requirement for the selector or indicator to be checked in normal flight.

The IMBAL (imbalance) alert does not usually require immediate attention as an imbalance condition is itself a relatively minor concern, and not a strong indicator of a serious problem. It is presented as an amber warning on the fuel tank quantity indication and is not associated with an aural alert. Associated with this manner of indication, the flight crew probably did not notice the alert immediately.

Use of checklists in response to the in-flight fuel imbalance

Introduction

The correct response to an IMBAL alert is to commence the IMBAL (imbalance) checklist. The objective of this checklist was to decide if a fuel leak is suspected and, if not, balance the fuel. With a suspected fuel leak, the IMBAL checklist led to the Fuel leak engine checklist. The objective of this checklist was to confirm the existence of an engine fuel leak and either shut down the affected engine or continue with normal operations if there was no fuel leak.

The following sections discuss the flight crew’s application of these checklists and the reasons for the diversion and erroneous shutting down of the aircraft’s left engine.

Not recognising crossfeed issue when using the IMBAL (imbalance) checklist

When the imbalance alert was triggered, the flight crew commenced actioning the QRH IMBAL non-normal checklist. The IMBAL checklist stated that the alert may be caused by a fuel leak, an inoperative crossfeed valve or a fuel imbalance; it did not state that it could be the result of the crossfeed valve being open. This meant that a critical piece of information was absent from the flight crew’s awareness at the time; had they recalled this knowledge or if it had been included in the checklist as a note or step, they may have re-evaluated the possibility of a leak and continued the IMBAL checklist. This would have directed the flight crew to perform steps to verify the functionality of the crossfeed valve and then rectify the imbalance if the valve was serviceable.

Although the presence of crossfeed information probably would have led to a different outcome in this case, a fuel imbalance condition is itself usually minor and a flight crew erroneously progressing to the Fuel leak engine checklist should still usually be able to detect or rule out a more serious condition such as a fuel leak.

Misdiagnosing fuel leak

The IMBAL checklist stated that a fuel leak should be suspected if the total fuel remaining is less than planned, or if an engine has excessive fuel flow. Neither of these conditions existed, but the crew reported they felt time pressure to take action prior to the aircraft crossing the coastline.

Consequently, although there was no evidence that the remaining fuel was less than expected and no leak was visible, the flight crew formed a mental model that there was a fuel leak, originating with and/or reinforced by the rapid reduction of fuel in the left main tank. Consequently, the flight crew progressed to the Fuel leak engine checklist.

The Fuel leak engine checklist had a step to check that the crossfeed valve was closed. It was not possible to conclusively determine whether, or at what time, the flight crew did this due to the limitations of the recorded data and the flight crew’s recollections. However, until around the time the left engine was shut down, more fuel was being used from the left tank than the right. From 1753-1755, the average imbalance rate reduced to about 225 kg/h, which may indicate that the crossfeed valve may have been closed during all or part of this period. However, the imbalance continued to increase through this period, with each engine having a comparable fuel flow, and the imbalance increased again after this period. This indicates that if the crossfeed valve had been closed at about 1753 it was likely also opened again, but the evidence suggests that it was more likely than not open throughout this period. Also, fuel flow rates after this indicate that the crossfeed valve was closed at about the same time the left engine was shut down (1807), and then reopened about 4 minutes later, staying open for the rest of the flight. In either case, the step of the Fuel leak engine checklist to close the crossfeed valve (and keep it closed) was not carried out correctly. If there had been an actual leak from the left engine fuel system, having the crossfeed valve open would have resulted in a greater loss of fuel than would otherwise have occurred.

After this step, the checklist required crews to record the fuel quantities and ‘the current time’ and monitor for a change in imbalance of more than 230 kg ‘within 30 minutes or less', and to check for visual indications of fuel spray. If either or both of these conditions are met, a fuel leak was to be considered ‘confirmed’.

The relevant step in the checklist, to ‘record the main tank fuel quantities and the current time’, required that the fuel record was to be contemporaneous. However, the flight crew calculated the rate of imbalance change using the fuel quantity that was recorded prior to commencing this checklist, so it included a period of time during which the crossfeed valve was open. Therefore, the imbalance was continuing to increase because the fuel for both engines was mostly being drawn from the left fuel tank.

While it is prudent to record fuel quantities as soon as practicable after a fuel leak is suspected, the effect of changing the order of the two checklist steps was probably not apparent to the crew. The decision to use the quantity that they previously recorded was probably influenced by perceived time pressure of approaching the coastline, at night, with a suspected fuel leak. Had the flight crew recorded the fuel quantities again they would have had to wait several more minutes to assess the rate of imbalance change. Furthermore, the monitoring condition could be misread or misunderstood by a flight crew experiencing stress and time pressure.

During this period, the imbalance changed by more than 230 kg within 10 minutes. As a result, one of the conditions to confirm a fuel leak appeared to be met, but unknown to the crew at the time, was based on incorrect information as the relevant checklist was not followed precisely.

This is likely an example of confirmation bias, which is the tendency for people to seek information that confirms their hypotheses, interpret ambiguous evidence as supporting their hypotheses, and either discount or not seek information that contradicts their hypotheses (Wickens and others 2013).

Although the flight crew may have realised that the crossfeed valve had been open when they later closed the crossfeed valve, by this time they had erroneously ‘confirmed’ the presence of a fuel leak based on what information they considered at the time, and likely did not recall the systems knowledge about the effect of an open crossfeed valve and did not have enough contradictory information to question their now well-established mental model of a fuel leak, nor to question the validity of the imbalance calculation. Accordingly, the flight crew decided to follow the checklist steps that ultimately led to an engine shutdown.

With ample fuel on board for the 46-minute descent and landing, even accounting for the hypothetical potential to lose all fuel from the left main tank, in principle the flight crew now had time to reconsider the situation. However, they did not have enough information at hand to give them a compelling reason to perform a new calculation of the imbalance rate, or of the fuel remaining compared with the expected amount. Further, while it is likely that these actions would have provided correct information, it would also have contradicted the information previously used and potentially confused the flight crew further.

Stress and time pressure

Both flight crew members reported stress and time pressure with diagnosing the reason for the fuel imbalance. Research has shown that stress may result in ‘attentional narrowing’, resulting in people drawing upon fewer information sources (Staal 2004), and narrowing their perception of the most relevant or threatening cues (Burian and others 2005, Wickens and Hollands 2000).

The ability to carry out complex tasks and access working memory is impaired (Burian and others 2005). People can also act more impulsively (Dismukes and others 2007), and the capacity to retrieve information from long term memory is affected (Dismukes and others 2015). When under time pressure, trained and experienced individuals often make decisions based on their recognition of a situation rather than methodically reviewing all available options (Klein 1998).

This occurrence is an example of how stress and time pressure can affect decision-making by reducing the effective search for information and the ability to evaluate a solution. This impacted the flight crew’s ability to recall and gather information, such as checking the crossfeed selector or recalling the effect of it being open, carefully evaluating the fuel used against the expected amount.

This led to a cautious and conservative but somewhat hasty decision to suspect a fuel leak. In turn, and further associated with stress and time pressure, a step in the Fuel leak engine checklist—to record the fuel quantities at the current time—was skipped or overlooked in favour of using the fuel quantities recorded earlier. This inadvertently led to an incorrect fuel imbalance calculation and, ultimately, an unnecessary engine shutdown.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the fuel imbalance and engine shutdown involving Boeing 737, VH-VZT, near Esperance, Western Australia, on 25 October 2021.

Contributing factors

  • Under instruction from the engineer, the flight crew conducted steps to perform a ground transfer of fuel (to remove cold soaked fuel frost from the wings) without referring to the relevant procedures. Consequently, an error was made in not closing the fuel crossfeed valve before flight.
  • During pre-flight checks, and later during the climb and level-off, the flight crew did not notice the crossfeed selector in the open position or the associated dimmed blue indicator light on the fuel panel.
  • The Boeing 737 IMBAL (imbalance) checklist did not provide sufficient guidance for a flight crew to identify an open crossfeed valve as being a potential reason for a fuel imbalance.
  • Partly as a result of confirmation bias, stress and perceived time pressure, the flight crew abbreviated the relevant checklists. As a result, the flight crew’s calculation of the rate of fuel imbalance change was invalid, and they misdiagnosed the fuel imbalance as being the result of a fuel leak, resulting in an unnecessary inflight engine shutdown.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.

Safety action by Qantas Airways

After the occurrence, Qantas communicated the factors involved to 737 flight crews.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Airservices Australia
  • the flight crew and cabin crew on board VH-VZT
  • the licenced aircraft maintenance engineer
  • Qantas Airways Limited.

References

Burian BK, Barshi I & Dismukes K 2005, The challenge of aviation emergency and abnormal situations, National Aeronautics and Space Administration Technical Memorandum NASA/TM-2005-213462.

Dismukes RK, Berman BA & Loukopoulos LD 2007, The limits of expertise: Rethinking pilot error and the causes of airline accidents, Ashgate Aldershot UK.

Dismukes RK, Goldsmith TE & Kochan JA 2015, Effects of acute stress on aircrew performance: Literature review and analysis of operational aspects, National Aeronautics and Space Administration Technical Memorandum NASA/TM-2015-218930.

Klein G 1998, Sources of power: How people make decisions, Massachusetts Institute of Technology.

U.S. Department of Transportation Federal Aviation Administration 2022, Notice 8900.636 – Revised FAA-Approved Deicing Program Updates, Winter 2022–2023.

Staal MA 2004, Stress, cognition, and human performance: A literature review and conceptual framework, National Aeronautics and Space Administration Technical Memorandum NASA/TM-2004-212824.

Wickens CD & Hollands JG 2000, Engineering psychology and human performance, 3rd edition, Prentice-Hall International Upper Saddle River, NJ.

Wickens CD, Hollands JG, Banbury S & Parasuraman R 2013, Engineering psychology and human performance, 4th edition, Pearson Boston.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • flight crew of VH-VZT
  • licenced aircraft maintenance engineer
  • Boeing
  • Qantas Airways
  • Civil Aviation Safety Authority (CASA).

Submissions were received from:

  • captain of VH-VZT
  • licenced aircraft maintenance engineer
  • Qantas Airways.

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2024

CC BY logo

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

[1] First officers undergoing line training were qualified to act as first officers on revenue flights alongside a check and training captain.

[2] Pilot flying (PF) and pilot monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.

[3] The FCOM pre-flight procedure included verifying that the fuel crossfeed selector was closed and that the blue valve open light was not illuminated.

[4] See Aircraft fuel system.

[5] See Recorded data.

[6] Only the captain could authorise changes in the quantity of fuel to be loaded.

[7] The blue coloured crossfeed valve open light is brightly lit when the valve is in the process of opening or closing. The light is dimmed when the valve is fully open and off when the valve is closed.

[8] It was normal practice to use fuel from the centre tank prior to the wing tanks.

[9] The nature of the recorded data did not allow the determination of imbalance or fuel change rate over periods of less than about 5 minutes.

[10] PAN PAN: an internationally recognised radio call announcing an urgency condition which concerns the safety of an aircraft or its occupants but where the flight crew does not require immediate assistance.

[11] For the 737, a fuel imbalance is when the difference in the quantity of fuel in one main tank compared to the other is greater than 453 kg for more than 60 seconds.

[12] The COVID-19 pandemic was a public health emergency of international concern between 30 January 2020 and 5 May 2023.

[13] Notice 8900.636 – Revised FAA-Approved Deicing Program Updates, Winter 2022–2023 (U.S. Department of Transportation Federal Aviation Administration, 2022).

Occurrence summary

Investigation number AO-2021-043
Occurrence date 25/10/2021
Location 135 NM south of Kalgoorlie-Boulder Airport
State Western Australia
Report release date 28/02/2024
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Fuel systems
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer The Boeing Company
Model 737-838
Registration VH-VZT
Serial number 34186
Aircraft operator Qantas
Sector Jet
Operation type Air Transport High Capacity
Departure point Perth Airport, Western Australia
Destination Adelaide Airport, South Australia
Damage Nil