Collision with water involving EC135 P2+ helicopter, VH-ZGA, 37 km north-north-west of Port Hedland Heliport, Western Australia, on 14 March 2018

Final report

Report release date: 16/06/2022

Safety summary

What happened

On the night of 14 March 2018, Heli-Aust Whitsundays Pty Ltd was operating a twin-engine EC135 P2+ helicopter, registered VH-ZGA, on a flight from its base at Port Hedland, Western Australia. This flight, conducted under the night visual flight rules, was to position the helicopter for a marine pilot transfer (MPT) from an outbound bulk carrier.

The pilot in command was a company instructor who was supervising line training with a recently recruited pilot. Earlier in their rostered shift, the pilot under supervision had passed a line check for day MPT and, having a total of 10 MPT flights, was approved for day operations. The instructor then introduced the pilot under supervision to night MPT operations and they completed 2 night MPT flights.

At 2330 local time, the helicopter was lifted off and climbed on track to the outer markers of the shipping channel (C1/C2), about 39 km from the port. Although the weather was suitable for the flight, there was no moonlight, and artificial lighting in the vicinity of C1/C2 was limited. Consequently, the approach to the ship was conducted in a degraded visual cueing environment that increased the risk of disorientation.

From a cruise altitude of 1,600 ft, the pilot under supervision descended the helicopter to join a right circuit around the carrier at the specified circuit height of 700 ft. During the base segment the helicopter’s altitude started to increase, reaching 850 ft soon after completing the turn onto final at an airspeed of about 70 kt. Although the helicopter was higher than the target height of 500 ft, a consistent descent was not established, and the helicopter remained above the nominal descent profile.

When the helicopter was about 300 m from the landing hatch, it was descending through 500 ft at a rate of about 900 ft/min. At about this point, a go‑around was initiated, but the helicopter descended to about 300 ft before a positive climb rate was achieved.

The helicopter was turned downwind for another approach and subsequently reached 1,100 ft. A descent was then initiated without coupling a vertical navigation mode of the autopilot. This was not consistent with standard operational practices and significantly increased the attentional demands on both pilots and associated risk of deviation from circuit procedure.

During the downwind and base segment of the circuit, the pilots did not effectively monitor their flight instruments and the helicopter descended below the standard circuit profile at excessive rate with decaying airspeed. Neither pilot responded to the abnormal flight path or parameters until a radio altimeter alert at 300 ft.

The instructor responded to the radio altimeter alert, reducing the rate of descent from about 1,800 ft/min to 1,300 ft/min. This response was not consistent with an emergency go-around and did not optimise recovery before collision with water.

After the unexpected and significant water impact in dark conditions, the helicopter immediately rolled over, and the cabin submerged then flooded. The instructor escaped through an adjacent hole in the windscreen and used flotation devices until rescued; however, the pilot under supervision was unable to escape the cockpit and did not survive.

What the ATSB found

In the context of a line training flight carried out in a degraded visual cueing environment, the ATSB found that a combination of factors contributed to the abnormal flight path and ineffective go-around. Firstly, the instrument panel was configured for single-pilot operation, which had a detrimental effect on the capacity of an instructor or training/check pilot to monitor the flight path and take over control if required.

In addition, the instructor had not been able to ensure that previous circling approaches flown in degraded visual cueing environments were consistent with the operator's standard operating procedures (SOPs), which probably limited the support provided to the pilot under supervision on the occurrence flight. As a related risk factor, the instructor did not report the previous deviations from SOPs or take other preventive/corrective action.

These limitations on the instructor’s capacity were coincident with the introduction of the pilot under supervision to night MPT operations without any day MPT consolidation or preparatory night flying. Given the pilot under supervision was transitioning from a different helicopter type and operational environment, this contributed to high cognitive workload for both pilots and increased the risk of sustained flight path deviations.

The ATSB also identified a number of other factors that increased the risk of the MPT operation. This included the pilot under supervision probably experiencing a level of fatigue known to adversely influence performance, due to a combination of limited sleep in the 48 hours prior to the accident and extended wakefulness on the day of the accident.

In addition, the operator's fatigue risk management system (FRMS) relied extensively on a sleep reporting spreadsheet (sleep log), and multiple pilots on multiple occasions had entered unrealistic or inaccurate sleep times, and there were limited effective controls in place to assure that the sleep times being entered by pilots was accurate. The ability of pilots to identify fatigue risks was also undermined by coding errors in the sleep log. At a higher level, the operator's FRMS did not describe the roster pattern or night shifts worked by line pilots based at Port Hedland, and the operator did not conduct a formal risk assessment of the roster prior to commencing MPT operations at Port Hedland.

In relation to the operator’s processes and procedures for MPT, the ATSB found there was a lack of assurance that personnel proficiency and helicopter equipment were suitable for the conduct of training at night in degraded visual cueing environments. In addition, the circuit and approach procedures for MPT did not minimise pilot workload or specify stabilised approach criteria with a mandatory go-around policy.

The operator rostered the pilot under supervision for MPT flying without ensuring that helicopter underwater escape training (HUET) had been completed in accordance with the operations manual. Although the pilot under supervision had completed HUET in 2009 and 2011, the lack of recency reduced their preparedness for escaping the helicopter following submersion.

The installed emergency locator transmitter (ELT) was not secured to the required primary load carrying structure of the helicopter, which increased the risk of non-activation during an accident.

Finally, although the operator’s primary helicopter activity was conducting MPTs, regulatory oversight activity by the Civil Aviation Safety Authority had not specifically examined the operator’s procedures and practices for conducting approaches and landings to ships at night in degraded visual cueing environments.

What has been done as a result

The operator carried out a safety investigation and introduced revised:

  • training and checking specifications for MPT to address flight instrumentation, instructor/training/check pilot assurance, and pilot induction process
  • MPT circuit procedures with defined stable approach criteria
  • a fatigue risk management system for pilots, including modified tools.

The operator also:

  • added emergency breathing system to pilot life jackets
  • introduced a requirement for HUET every 2 years
  • ensured ELT mounting conformance in its helicopter fleet.

The Civil Aviation Safety Authority (CASA) checked that MPT operators were complying with their own requirements for HUET recency and assessed the operator’s arrangements for crew scheduling and fatigue management at Port Hedland. As part of the new regulations introduced in December 2021, CASA clarified the guidance material regarding equipment requirements for training, checking and testing in aircraft designed for single pilot operation.

Safety message

The risks associated with marine pilot transfer operations in a degraded visual cueing environment are generally higher than conventional passenger-carrying activities and may require additional measures for safety assurance. Operators who conduct specialised flying are advised to assess the suitability of their pilot training/checking system and procedures for critical phases of flight. These should address flight path management, including the use of automation, stabilised approach criteria, and mandatory go-around requirements.

Flight crew fatigue is an insidious problem that is difficult to predict for each individual on an ongoing basis and can have subtle effects that undermine performance of critical tasks. Management of fatigue risk is a shared responsibility between operators and pilots and relies on sound principles, effective systems, and accurate recording.

Although the crashworthiness of helicopters is improving, there is an inherent tendency to roll and invert after a ditching or collision with water. Helicopter underwater escape training (HUET) provides familiarity with a crash environment and confidence in an emergency. Interviews with survivors from helicopter accidents requiring underwater escape frequently mention they considered that HUET had been very important in their survival. Training provided reflex conditioning, a behaviour pattern to follow, reduced confusion, and reduced panic.

From a regulatory perspective, the operator had demonstrated compliance with the standard requirements. However, if regulations do not have specific applicability to specialised operations, any safety-related audit of operators should assess the management of mission-specific hazards.

 

The occurrence

During the evening of 14 March 2018, a Eurocopter Deutschland GMBH[1] EC135 P2+ (EC135) helicopter, registered VH-ZGA, was being operated by Heli-Aust Whitsundays Pty Limited [2] on a series of marine pilot transfer (MPT) flights at Port Hedland, Western Australia. The helicopter was being operated from the heliport located at the port and the flights flown under the visual flight rules (VFR) in the charter operational category.[3]

These flights were normally conducted as a single-pilot operation. However, in this case, a pilot recently employed by the operator (pilot under supervision), who had not previously conducted MPT flights at night from Port Hedland, was flying the helicopter under the supervision of a company instructor pilot. Both pilots had been rostered for the night duty period (1800–0600 Western Standard Time).[4]

A total of 5 MPT flights were scheduled that evening and into the early morning of the next day. The first 2 flights were to transfer marine pilots from the port onto inbound bulk carriers[5] at the anchorage pilot boarding ground, about 9 NM (17 km) north of the heliport. The first transfer was completed during daylight and the helicopter landed back at the heliport just before sunset. The second transfer departed for the pilot boarding ground just after sunset. The 3 subsequent flights were to transfer marine pilots back to port from outbound bulk carriers near the end of the shipping channel at marine navigation beacons Charlie 1 (C1) and Charlie 2 (C2), about 21 NM (39 km) north-north-west of the heliport (Figure 1).

The first 3 MPT flights were completed without any reported incident. During the fourth scheduled transfer and on approach to the bulk carrier Squireship at C1/C2 to pick up the marine pilot, the helicopter crew initiated a go-around because the approach path had become too steep and began positioning the helicopter for another approach. During that manoeuvring, the helicopter descended and collided with the water.

The helicopter capsized immediately on impact and the cockpit flooded with water. The wreckage floated for a short time before sinking. The instructor pilot escaped from cockpit and was rescued a short time later. The location of the other pilot was unknown, and a search continued throughout the night and into the following days. On 17 March 2018, the helicopter wreckage was located on the seabed and the missing pilot was found inside the cockpit.

Figure 1: Chart showing relevant features at the seaport of Port Hedland

Figure 1: Chart showing relevant features at the seaport of Port Hedland

Source: Port Hedland electronic navigational chart produced by The Australian Hydrographic Office, modified by the ATSB

Departure from Port Hedland and transit to C1/C2

After completing the third transfer, the pilots did not shut down the helicopter due to the short turnaround prior to departing for the fourth transfer. At about 2330, the pilot under supervision lifted off from the heliport, set course for C1/C2 and climbed to an altitude of 1,600 ft.

At 2337, the helicopter was about 7 NM (13 km) south-south-east of the bulk carrier and the pilot under supervision established radio contact with the marine pilot on board the vessel. The marine pilot provided operational information to the helicopter crew, which included the direction and speed of the relative wind[6] across the vessel’s deck, which was 90° left of the bow at 15 kt (28 km/h) and clearance was provided for the helicopter to land. That wind direction necessitated an approach to the bulk carrier’s landing hatch from its starboard (right) side.

The marine pilot on board the bulk carrier recalled that the wind was light and there was no moon. Stars were visible and the lights of helicopter were seen as it approached the vessel. Data broadcast by the helicopter’s Automatic Dependent Surveillance Broadcast (ADS-B) equipment[7] and the bulk carrier’s Automated Identification System (AIS)[8] indicated that descent from cruise altitude commenced about 1,500 m from the vessel.

The instructor recalled[9] that as the helicopter approached the vessel, it was well-lit, with floodlighting of the deck and accommodation quarters. The weather conditions were described as fine, with no cloud, rain or obstructions to visibility.

Figure 2 depicts the track of VH-ZGA as it was manoeuvred in the vicinity of the bulk carrier. ADS‑B and derived data at the alphabetically labelled points ‘A’ to ‘L’ is summarised in Table 1. Figure 3 graphically depicts the ADS-B and derived data while VH-ZGA was being operated in vicinity of the bulk carrier.

Figure 2: Manoeuvring of VH‑ZGA in the vicinity of Squireship

Figure 2: Manoeuvring of VH‑ZGA in the vicinity of Squireship

This figure shows a representation of the flight path derived from ADS-B data recorded while VH-ZGA was being operated in the vicinity of Squireship. The white helicopter track is derived from positions recorded by Airservices Australia ADS-B receivers. Where that data was not available, positions recorded by the FlightRadar24 internet server were utilised and represented as the yellow flight path.[10] Data relevant to the annotated labels A to L is presented in Table 1 and marked as labelled index points in Figure 3. The light blue dots represent the AIS position of the bulk carrier recorded by the Australian Maritime Safety Authority receiver at corresponding times during the approaches of VH‑ZGA. The bulk carrier was 288 m in length, with the AIS position 248 m from the vessel’s bow.

Source: ATSB

Table 1: ADS-B and derived data, associated with the flight path of VH-ZGA depicted in Figure 2

PositionTime
(WST)
Estimated
range to
landing
hatch (m)
Derived
airspeed
(kt)[1]
Groundspeed
(kt)
Altitude
(ft)[2]
Geometric
altitude rate
of change
(ft/min)
A2341:37-83911,200-513
B2342:21-8598722-576
C2343:022,3007882722-64
D23:43:442,0756862825+194
E23:44:299255048775-256
F23:45:052753130525-894
G2345:27-78783250
H2346:13-59721,100+831
L2347:131,7757783822-896

[1] Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. Where significant, the airspeed calculation has been adjusted for the effect of the descent flight path vector.
[2] Altitude is either geometric altitude or pressure altitude reported in the ADS-B data set, corrected for atmospheric pressure. Geometric altitude is reported in increments of 25 ft, pressure altitude in increments of 100 ft.

Figure 3: VH-ZGA derived airspeed, altitude and geometric altitude rate of change in vicinity of C1/C2

Figure 3: VH-ZGA derived airspeed, altitude and geometric altitude rate of change in vicinity of C1/C2

Graphical summary of aggregated ADS-B and derived data, while VH-ZGA was in the vicinity of the bulk carrier during the accident flight. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude is derived from the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted in Figure 2 and Table 1.

Source: ATSB

First approach

The pilot under supervision positioned the helicopter for the approach and landing by flying a circuit around the vessel in a clockwise direction. The helicopter passed about 600 m astern of the bulk carrier while descending through a geometric altitude[11] of about 1,400 ft, at about 450 ft/min and at an airspeed estimated to be reducing through 87 kt.[12]

During the descent, the geometric altitude rate of change reported by the helicopter’s ADS-B equipment was about 500 ft/min, consistent with the upper mode of the automatic flight control system (AFCS - see the section titled Autopilot and stability augmentation system) being engaged in the altitude acquire (ALT.A) mode. After passing astern the vessel, the helicopter was turned right to circle around and position for the final approach.

The ADS-B data indicated the pilot under supervision levelled the helicopter at about 700 ft above the water during the downwind leg of the circuit, before it climbed slightly during the base leg of the circuit. The instructor recalled that the pilot under supervision completed the pre‑landing checklist, which included the arming the helicopter’s emergency flotation system.

At 2343:44, the helicopter was still climbing slightly as it was being turned onto final approach, with the airspeed reducing gradually through about 68 kt. The geometric altitude was increasing through 825 ft and the helicopter was about 2,000 m from the bulk carrier’s landing hatch. During the initial stages of final, the wind drift angle was estimated to be about 6° right. As the airspeed reduced, the size of the drift angle increased. ADS-B data indicated that, soon after the final track was established, the helicopter reached 850 ft then started to descend on the final approach. At this time, the helicopter was approximately 1,600 m from the landing hatch at an airspeed of about 60 kt.

The instructor recalled that the AFCS remained engaged until the helicopter was aligned on the final approach. The ‘upper’ autopilot modes were then decoupled, and the helicopter passed through the ‘entry gate’ with an airspeed of 50–60 kt at 500 ft.

The ADS-B data indicated that during the first 45 seconds of the descent, the helicopter’s geometric altitude reduced by 125 ft (commencing from 850 ft), before the descent rate gradually started to increase. At 2345:05, the helicopter was about 275 m from the landing hatch on the deck of the bulk carrier, descending through a geometric altitude of about 525 ft at a rate of about 900 ft/min. The airspeed gradually reduced to about 31 kt with a wind drift angle of about 19° right.[13]

The airspeed then began to increase, which was consistent with the recollection of the instructor that a missed approach (go-around) was commenced because of the steepening approach angle to the vessel. During the initial stages of the go-around, the airspeed continued to increase but the helicopter continued to descend, at a gradually reducing rate. The change in the ADS-B pressure altitude during this period was broadly consistent with the changes indicated by the ADS‑B geometric altitude and geometric altitude rate of change.[14]

Second approach

At 2345:14, the instructor radioed the marine pilot and said, ‘We’ll just have a second go at that, be with you shortly’. The ADS-B data indicated that, at that stage, the helicopter was passing overhead the deck of the vessel at about 375 ft, descending at about 500 ft/min and the airspeed was increasing through 60 kt. Soon after, the airspeed increased to about 80 kt and a positive rate of climb was established (325 ft altitude) and within a further 10 seconds, the geometric altitude rate of change was greater than +1,000 ft/min. The instructor recalled that a standard missed approach was flown, the AFCS upper modes were recoupled, and preparations commenced to make another approach. The helicopter was climbing through 700 ft when the crew turned the helicopter right, to position for another approach.

The available ADS-B data indicated that the helicopter reached an altitude of about 1,100 ft early on the downwind leg of the circuit. The airspeed reduced to about 60 kt during the final stages of the climb but started to increase again to about 75 kt as the helicopter flew downwind and commenced a descent. The instructor advised that the helicopter’s emergency flotation system remained armed from the previous approach, and that with the floats armed, the maximum airspeed limitation was 80 kt. Figure 4 depicts the track of VH-ZGA as it was repositioned for another approach. The ADS-B and derived data at the alphabetically labelled points ‘H’ to ‘R’ is summarised in Table 2. Figure 5 graphically depicts the ADS-B and derived data while VH-ZGA was being repositioned for the second approach.

Figure 4: VH-ZGA flight profile during the second approach

Figure 4: VH-ZGA flight profile during the second approach

This figure shows a representation of the flight path derived from ADS-B data recorded while VH-ZGA was being operated in the vicinity of Squireship. The white helicopter track is derived from positions recorded by Airservices Australia ADS-B receivers. Where that data was not available, positions recorded by the FlightRadar24 internet server were utilised and represented as the yellow flight path. Data relevant to the annotated labels H to R is presented in Table 2 and marked as labelled index points in Figure 5.

Source: ATSB

Table 2: ADS-B and derived data, associated with the flight path of VH-ZGA depicted in Figure 4

PositionTime (WST)Derived
airspeed (kt)[1]
Groundspeed (kt)Altitude (ft)[2]Geometric
altitude rate
of change (ft/min)
H2346:1359721,100+831
I2346:2361731,122+704
J2346:4574861,122-512
K2346:5177891,022-832
L2347:137783822-896
M2347:196769722-1,088
N2347:255350522-1,024
O2347:304032475-1,344
P2347:363422300-1,794
Q2347:45302175-1,406
R2347:49302222-1,280

[1] Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The airspeed derived from ADS-B groundspeed can slightly under-read at high rates of climb/descent due to the extra distance flown by the helicopter through the air, when compared to the horizontal distance used by the GPS receiver to calculate the speed across the ground. The size of that error increases as the rate of change in altitude increases and/or the groundspeed reduces. For this table, the derived airspeed has been adjusted for any effect of that climb/descent vector.
[2] Altitude is either geometric altitude or pressure altitude reported in the ADS-B data set, corrected for atmospheric pressure. Geometric altitude is reported in increments of 25 ft, pressure altitude in increments of 100 ft.

The airspeed started reducing again on late downwind and the descent continued. As the crew commenced the base turn, the airspeed was reducing through about 77 kt and the helicopter was passing through about 800 ft. Flight data also indicated that the rate of descent increased and exceeded 1,000 ft/min.

At 2347:25, the helicopter was part-way through the base turn and about 1,900 m east of the bulk carrier. The ADS-B data indicated that both the helicopter’s altitude and airspeed continued to reduce, while the rate of descent remained about 1,000 ft/min (see Table 2 and Figure 5).

Figure 5: VH-ZGA derived airspeed, altitude, geometric altitude rate of change and derived heading during second circuit

Figure 5: VH-ZGA derived airspeed, altitude, geometric altitude rate of change and derived heading during second circuit

Graphical summary of aggregated ADS-B recorded data and parameters derived from that dataset, during the second circuit of the bulk carrier and during the final descent. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Figure 4 and Table 2.

Source: ATSB

The instructor recounted the following events on the second approach:

  • the helicopter was turned inbound on the final approach
  • the AFCS upper modes were decoupled
  • they again passed through the ‘entry gate’
  • the deck of the bulk carrier was in sight[15]
  • the pilot under supervision reduced power/torque to commence the descent and again soon after.

The instructor recalled pointing out the descent rate to the pilot under supervision, requested an increase in power and was satisfied that the necessary correction was being made.

By contrast, a review of ADS-B data identified that, at about this time (2347:30), the helicopter was still about 1,900 m east of the bulk carrier, on a south-westerly track and not turning towards the vessel. On that track, the bulk carrier was to the right of the helicopter’s nose, with the lights of Port Hedland and the vessels at anchor to the left. The altitude and airspeed continued to reduce, and the rate of descent was about 1,300 ft/min and increasing.

From the deck of the vessel, the marine pilot could see the helicopter’s anti‑collision strobe light[16] and the green navigation light on the right side of the helicopter. The marine pilot did not recall seeing the red navigation light on the left side of the helicopter, nor any light from the helicopter’s steerable searchlight which was normally used during the final stages of the approach to illuminate the landing area. The marine pilot became concerned about the helicopter’s approach path and assessed that the helicopter was descending low on the horizon compared to observations of other flights.

The instructor recalled hearing the radio altimeter annunciating ‘check altitude, check altitude’. The radio altimeter was programmed to make this annunciation when the radio altitude reached the preselected altitude. The operator’s standard procedure was to set a radio altitude of 300 ft prior to take-off. The instructor recalled immediately taking over control of the helicopter and announcing to the pilot under supervision that they were conducting a missed approach (go‑around). The instructor did not remember hearing any alarms or other alerts from the helicopter’s warning systems.

The ADS-B data indicated that at a geometric altitude of 300 ft, the rate of descent was between 1,725 and 1,794 ft/min, the derived airspeed was about 34 kt and the altitude derived from the ADS-B reported pressure altitude was about 322 ft.

Soon after, the helicopter collided with the water surface. The ADS-B data indicated that about 12 seconds elapsed between the radio altimeter alert at 300 ft and the water contact. In that time the rate of descent reduced to about 1,280 ft/min while the airspeed remained about 30 kt.

The marine pilot watched the helicopter as it descended and recalled seeing a splash of water lit by a flash from the helicopter’s strobe light. Returning immediately to the bridge of the bulk carrier, the marine pilot alerted the port authority.

Post-accident

The instructor recalled that the cockpit immediately flooded with water and being submerged before being able to take a full breath of air. While still strapped in the seat, the instructor tried to operate the emergency door jettison, but had difficulty recalling the jettison action and did not believe that the door had released. The instructor then felt around and identified an alternative exit pathway through a break in the left front windscreen and kept hold of that opening using their left hand.

The instructor unsuccessfully attempted to unplug the helmet communications cord from the overhead console. Consequently, the instructor released the chinstrap and removed the helmet before releasing the seat belt. As recounted by the instructor, both hands were used to pull through the opening in the windscreen to escape the cockpit.

After vacating the cockpit, and while still underwater, the instructor identified and pulled one of the 2 inflation toggles on their personal flotation device. The chamber inflated normally and assisted the instructor to reach the surface. The instructor had no recollection or awareness of the other pilot’s location, movement, or actions in the cockpit after the water collision.

After reaching the surface, the instructor saw the helicopter was still afloat but inverted and then clung onto the helicopter’s left landing skid. The instructor could not see the pilot under supervision and was unsure of their location. The helicopter’s emergency flotation system had not automatically deployed on collision with water and inversion of the fuselage.

After a short time, the instructor remembered that the helicopter’s 2 life rafts[17] could be deployed using handles mounted on the underside of the rear cross-tube of the helicopter’s landing skids. The instructor pulled one of those handles and a life raft inflated and deployed from each landing skid. The life raft deploying from the left landing skid was trapped under the skid and unusable. The life raft from the right landing skid deployed normally and the instructor boarded that raft. The instructor recalled that the helicopter floated for a period of time before sinking, with the pilot under supervision still unaccounted for.

The crew of a surface vessel recovered the instructor from their life raft about 1 hour after the accident. The instructor had sustained only minor injuries.

The search for the missing pilot and wreckage continued during the night and over the next 2 days. A vessel mobilised by the port authority commenced a sonar search of the seabed. On 17 March 2018 that vessel located the helicopter wreckage, approximately 675 m north-north-west of the last received ADS-B position. The helicopter was substantially intact and resting on its right side on the seabed in about 20 m of water. Divers from the Western Australia Police Force located the missing pilot in the helicopter cockpit.

  1. The holder of the type certificate is now Airbus Helicopters.
  2. Heli-Aust Whitsundays Pty Limited was the holder of the Air Operator Certificate issued by the Civil Aviation Safety Authority. The operator’s trading name for their Port Hedland operations was Port Hedland Helicopters.
  3. The operator did not operationally differentiate between flights carrying a marine pilot and flight sectors where there was no marine pilot on board. The Civil Aviation Safety Authority indicated that MPT flights were only charter category when a marine pilot was carried and at other times those flights would be categorised as positioning flights (in the aerial work category).
  4. Western Standard Time (WST): Coordinated Universal Time (UTC) + 8 hours.
  5. On bulk carriers, a cargo hatch cover was usually designated for use as a helicopter landing area.
  6. The relative wind reported by the marine pilot was the result of the surface wind velocity in that vicinity combined with the wind velocity due to the vessel’s motion. .
  7. The ADS-B equipment transmitted flight data that enabled air traffic service providers to track aircraft. Airservices Australia recorded the transmissions received by their network of ground-based ADS-B receivers. That data could also be received by other aircraft with suitable equipment and privately-operated ground-based equipment feeding information to flight tracking websites.
  8. The departing vessel was equipped with the maritime Automated Identification System (AIS) that transmitted data, including GPS position. That data was recorded by the Australian Maritime Safety Authority (AMSA).
  9. Instructor recollection at interview with the ATSB, a few days after the occurrence.
  10. In all of the figures that show ADS-B data, the line representing the flight path is a series of straight lines between successive data points. When the helicopter is in stable flight and the time interval between data points is short, the derived flight path is a close approximation of the actual flight path. As the time interval between data points increases, it is possible that the derived path does not closely reflect the actual flight path, although the trend over a series of points should be taken into account.
  11. The geometric altitude was calculated by the helicopter’s global positioning system (GPS) receiver using the GPS satellite constellation and is the height of the helicopter above the WGS-84 earth ellipsoid. The geometry of the satellite constellation and acceleration of the helicopter can affect the accuracy of the geometric altitude calculation.
  12. Airspeed was not a parameter transmitted by the helicopter’s ADS-B equipment. All airspeeds expressed in this report are derived from the ADS-B groundspeed and track, using the 10-minute average wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature.
  13. That is, to maintain the track across the ground indicated by the ADS-B data with the C2 recorded wind velocity and the derived airspeed, the nose of the helicopter would be pointing into wind, 19° left of the actual ground track.
  14. The pressure altitude transmitted by the helicopters ADS-B equipment was measured independently from the other parameters calculated by the helicopter’s GPS receiver. The correlation between the change in pressure altitude and the geometric altitude/geometric altitude rate of change is an independent verification of the altitude-related data trends identified in the GPS calculated data.
  15. This implies that the helicopter was tracking towards the bulk carrier on final approach.
  16. VH-ZGA was equipped with a red anti-collision beacon strobe light, that was mounted on top of the top of the Fenestron housing at the tail of the helicopter. Examination of the helicopter wreckage found the switch for this anti-collision beacon in the ON position. The switch for the white anti-collision strobe lights was found in the OFF position. .
  17. The life rafts were fitted to the helicopter’s landing skids and were stowed under protective covers, together with the bags for the emergency flotation system. When activated, the emergency flotation system or life raft inflated from under their protective covers.

Context

Personnel information – pilot under supervision

Licence, rating, and general operating experience

The pilot under supervision obtained a commercial pilot licence (helicopter) in 2005 and air transport pilot licence (helicopter) in 2014. When these licences were transitioned to the equivalent Civil Aviation Safety Regulations (CASR) Part 61 qualifications in August 2015, they included a helicopter night VFR rating and helicopter multi-engine helicopter instrument rating, endorsed for conduct of 2-dimensional (2D) instrument approach operations and limited to non‑pilot in command duties.[18]Table 3 provides an outline of the pilot’s operating history.

Table 3: Pilot under supervision operating history

YearOperating history
2005Flight training for commercial pilot’s licence with R22, R44 and Bell B206 type endorsements
2006–2009Aerial work and charter operations with associated entity of occurrence operator; primarily in remote areas, including some tourist flights to/from ships
2010Transferred to predecessor of occurrence operator [1] at Mackay, Queensland – endorsed on Bell 222 (co-pilot) and EC135 types
2010–2011Marine pilot transfer (MPT) flying as co-pilot on BH222/430 night/IFR and pilot in command on B206 and EC135 day/VFR. Last EC135 flight of this period was in October 2011.[2]
2012–2014Joined a different operator at an inland base - remote area flying in B206L helicopters in support of the resource industry.
2015Overseas travel seeking flying work. Nil recorded flight time.
2016Re-joined B206L operator for inland remote area operations. Night vision imaging system (NVIS) rating issued in B206L type.
2016–2018Tours of duty at inland base – on standby to operate medical evacuation flights from remote areas at night in B206L helicopters utilising NVIS.
2018Recruited to operate EC135 on MPT flights from Port Hedland (non-NVIS)

[1]  Although this was the same air operator’s certificate (AOC) held by the occurrence operator, it was held by a different corporate entity.

[2]  The flight reviews for the EC135 type rating and BH222/430 type rating expired on 31 August 2014. The flight review for the co‑pilot multi-engine helicopter instrument rating (2D) expired on 31 May 2012.

According to the operator’s electronic flight crew records, the pilot under supervision had logged a total experience of 4,057 flight hours, consisting of 3,666 hours single engine and 391 hours multi‑engine. Most of the multi-engine experience was co-pilot with 85 hours as pilot in command of EC135 helicopters. When dual and supervised flying was taken into account, the pilot’s total EC135 experience was 106.4 hours. The only night flying in the EC135 was 1.9 hours on the night of the accident.

Total night experience was recorded as 318 flight hours, which included 269 hours as co-pilot. Total instrument flying time was 117 hours consisting of 112 hours as co-pilot and 5 hours in a simulator.

In the 12 months prior to re‑joining the MPT operator, the pilot under supervision operated B206L helicopters for a total of 27.5 hours. This included 22.9 hours of night flying with 18.4 hours using a night vision imaging system (NVIS). The last night flight of this period was an NVIS proficiency check on 15 February 2018.

The operator’s chief pilot recruited the pilot under supervision in mid-February 2018 to fill a short‑notice vacancy in the pilot group operating from Port Hedland. This selection process was informal and based in part on the pilot under supervision holding an EC135 endorsement with sufficient experience to satisfy the contract requirement for a minimum 100 hours flying experience on the EC135 type. Other considerations for the chief pilot were previous MPT flying for the operator in 2011 and recent night flying experience in remote areas using NVIS. The chief pilot was aware that the pilot under supervision had been engaged in an emergency response role for the previous 3 years, which limited hours flown during that period.

Between 5 and 7 March 2018, the pilot under supervision was at the operator’s base in Mackay, Queensland for the initial induction and ground training process. Then, on 8 March 2018, the pilot under supervision travelled to Port Hedland for EC135 operational training.

Proficiency check and flight review status

All of the CASR Part 61 ratings were subject to periodic operational proficiency checks or flight reviews. Operator records and Civil Aviation Safety Authority (CASA) flight crew licencing data indicated that the pilot under supervision had completed the proficiency checks and reviews in Table 4.

Table 4: Previous operator checks or reviews with pilot under supervision

DateProficiency check or flight reviewExpiry
4 September 2016Night VFR flight review – B206L30 September 2018
15 February 2018NVIS rating Grade 2 proficiency check – B206L28 February 2019

Immediately following the night VFR flight review conducted by the previous operator on 4 September 2016, training started for the NVIS rating. Most of the subsequent flying for this operator utilised NVIS.

The flight instructor (for the previous operator) who supervised the pilot under supervision on a practice NVIS flight the night before the proficiency check on 15 February 2018 recorded that instrument flying (when required) was well flown but some procedures, such as radio broadcasts, downwind checks, and airspeed versus groundspeed checks, were not consistently applied. Overall, the standard of NVIS operations was considered to be improving. No comments were recorded for the successful NVIS check conducted by a company flight instructor/examiner the following night.

The instructor on the accident flight supervised 3.5 hours of EC135 flying by the pilot under supervision at Port Hedland on 10 and 11 March 2018 as revision for type-specific normal and emergency procedures. A helicopter type knowledge examination was also completed. For the combined EC135 flight review and VFR base check on 12 March 2018, the pilot under supervision operated to the pilot boarding ground, C1/C2 and Port Hedland Airport for 2.5 hours. The instructor recorded that normal circuits and various emergency procedures were conducted to a satisfactory standard. Having completed 6 hours of EC135 flying, the pilot under supervision was considered by the instructor to be ready for line training (supervised MPT) operations, starting the next day (13 March). No practice instrument or night flying was carried out during this pre-line training phase.

The operator was required to carry out periodic emergency procedures training in accordance with Civil Aviation Order (CAO) 20.11 and they also carried out initial and recurrent non-technical skills (NTS) training. The chief pilot assessed the pilot under supervision’s knowledge of emergency procedures applicable to the EC135 on 5 March 2018 and found it to be suitable.

According to the operator’s operations manual, pilots engaged in MPT were required to complete helicopter underwater escape training (HUET) at 3-year intervals. The pilot under supervision completed initial HUET in February 2009 and a second course in May 2011, with the training organisation recommending that training was valid through to 2013. Survival aspects associated with HUET are addressed in section Helicopter underwater escape training.

Marine pilot transfer experience

According to the operator’s electronic flight crew records, the pilot under supervision had conducted 253 deck landings by day and 76 deck landings by night. These figures included legacy data from 2010 and 2011 when deck or ship landings and offshore experience was recorded by a different method or not recorded at all. As such, the actual number of ship landings might have been higher.

It is likely that the pilot’s night deck landings were carried out while operating as co-pilot for BH222/430 MPT flights. One of the captains for this operation advised the ATSB that these night flights were to ships about 110 NM (204 km) offshore from Mackay. The co-pilot was required because the helicopters were not equipped with an autopilot.

The standard practice was for the captain to carry out the ship landing with the co-pilot in a supporting role. If the conditions were suitable, captains might allow the co-pilot to carry out a ship landing to gain experience, though these were generally not recorded.

The pilot under supervision commenced line training for Port Hedland MPT day operations on 13 March and night operations on 14 March 2018. Information about those activities and the relevant associated events are contained in the section Preliminary activities at Port Hedland in March 2018.

Medical information

The pilot under supervision held a Class 1 civil aviation medical certificate that was issued without restriction, valid to 18 April 2018. A review of CASA medical records did not identify any pre-existing condition or underlying health issue potentially relevant to the circumstances of the accident. The CASA records did not indicate the use of any prescription or over the counter medications. The pilot under supervision’s partner also indicated that the pilot was not experiencing any significant medical issues.

Police divers recovered the pilot under supervision from the cockpit of the helicopter. At the time of recovery, the pilot was not secured by the seat belt or wearing a helmet (see Survivability aspects - Helmets, communication cords and seat belts).

A post-mortem examination conducted by a forensic pathologist on behalf of the South Hedland Coroner did not identify any preceding pathology or injury. The pathologist’s post-mortem report indicated that it was not possible to ascertain the cause of death due to the elapsed time between the accident and location of the helicopter wreckage; only limited toxicology analysis was able to be performed.

Recent history

The pilot under supervision’s partner said the pilot normally slept about 9 hours each night, from about 2100 to 0630–0700. The operator’s pilots were required to record their hours of sleep and duty (in 1-hour blocks) in a sleep log (described in section Sleep logs). To develop a timeline of the periods the pilot was probably working and had opportunity to sleep,[19] the ATSB reviewed the pilot’s sleep log and other available information. This included the recorded times of phone calls and text messages, the content of text messages, and the recorded times that the pilot accessed the operator’s Port Hedland facility.

Based on the available information, key points included:

  • The pilot under supervision woke early on 8 March to travel from Mackay to Port Hedland. A text message[20] indicated check-in for a flight at Mackay by 0500 Eastern Standard Time (0300 Western Standard Time).[21] Another text message indicated the pilot obtained a small amount of sleep during the day.
  • The pilot under supervision performed various tasks (with no flying duty) on 9 and 10 March and then various tasks including some flying on 11 and 12 March. The available evidence indicated normal sleep periods during the nights of 8 to 11 March.
  • During the morning of 12 March, the pilot under supervision received a night VFR flight planning assessment to complete prior to conducting planned night flying on 14 March. In text messages, the pilot expressed some concern regarding the completion of the assessment as their personal study notes were not in Port Hedland. There were indications the pilot did some reading for the assessment during the evening of 12 March.
  • On 13 March, the pilot under supervision was rostered on a day shift (that is, from 0600–1800) to conduct MPT operations with the instructor. The first flight was scheduled for 0615 and, as indicated in text messages, the pilot under supervision planned to start work at 0430. Building access records indicated arrival at the operator’s premises at 0417, which correlated with a wake time of 0330. At 0413 the pilot sent a text message indicating they did not have a good sleep. The estimated sleep opportunity on the night of 12 March was about 5.5 hours.
  • Text messages indicated the pilot under supervision left work at 1820 on 13 March, which meant completion of a duty period up to 14 hours duration.[22] The content of text messages indicated it had been a long day and the pilot was feeling ‘stuffed’. Flight records indicated that 9 MPT flights were conducted.
  • On 14 March (the day of the accident), the pilot under supervision was rostered for a night shift (1800–0600) to conduct the second session of MPT operations with the instructor. Text messages indicated that, ‘as expected’ the pilot was awake at 0600 (with a weary face emoticon) and had slept well but wished it was for a longer period. The estimated sleep opportunity on the night of 13 March was 9 hours.
  • Later on 14 March, the pilot under supervision indicated an intention to rest that afternoon, ‘if I get this flight plan done’, referring to the night VFR flight planning assessment. Other text messages indicated a degree of stress or frustration associated with completing the assessment. That afternoon, there were further messages stating that the assessment was completed and an attempt to sleep was unsuccessful. Another text message indicated that the last (and third) scheduled flight that night was at 0130, which was accompanied by a grimacing emoticon. Building access records and text messages indicated that the pilot returned to the operator’s port facility at 1609, prior to the start of the night shift.[23]
  • The instructor recalled that, after completing the first 2 flights on the evening of 14 March, the pilot under supervision was advised to refuel the helicopter, conduct a daily maintenance inspection, and then take advantage of a break in the MPT schedule to retire to the nearby accommodation. Building access records and text messages showed the pilot under supervision left the operator’s premises at about 2000 and returned at about 2152. The instructor described this arrangement to the ATSB as providing the pilot under supervision with an opportunity to relax and did not believe the pilot under supervision needed to, or would, sleep in this time.

In summary, the available information indicated that the pilot under supervision obtained significantly less than their normal amount of sleep on the night of 12 March and, although they slept longer on 13 March, this was not as much sleep as they would have liked. At the time of the accident on 14 March (2348), the pilot under supervision had probably slept for at most 6 hours in the previous 24 hours and 12.5 hours in the previous 48 hours and had been awake for about 18 hours.

The instructor recalled that the pilot under supervision appeared ‘normal’ on the day of the accident and held no concerns about the pilot under supervision’s fitness for duty. There were no other available reports about the pilot under supervision’s alertness on the day of the accident.

The pilot under supervision’s partner recalled that the pilot was happy to be working for the operator and was feeling good about their performance on the initial flights and the feedback provided by the instructor. The partner also recalled that the pilot was concerned about having enough time to complete the night line check prior to the instructor leaving Port Hedland on 16 March. The partner recalled the pilot saying their hotel accommodation was noisy, including at night, and there were some difficulties with sleep.

Personnel information – flight instructor

Licence, rating, and general operating experience

The instructor held an air transport pilot licence in the aeroplane and helicopter categories with a multi-engine instrument rating and night VFR rating in both categories. Additional ratings included a grade 1 flight instructor rating for aeroplanes and helicopters and flight examiner rating for helicopter licences and ratings, including night VFR and EC135 ratings. Table 5 provides an outline of the instructor’s licences and ratings.

Table 5: Sequence of the instructor’s licence and rating issue

YearLicence and rating issued
1992Commercial pilot licence (aeroplane)[1]
2000Commercial pilot licence (helicopter)
2006Grade 1 aeroplane instructor rating[1]
2007Air transport licence (aeroplane)[1]
2009Air transport licence (helicopter)
2009Grade 1 helicopter instructor rating
2012Multi-engine helicopter instrument rating
2014EC135 type rating
2015Started with EC135 operator
2016 – 2018EC135 MPT and flight training/assessing
[1]  At the time of the occurrence the instructor was not maintaining the aeroplane licences and ratings.

Prior to starting with the operator in 2015, the instructor was chief pilot and chief flying instructor of a flying school that provided CASR Part 61 flight training and reviews for the operator.

According to the operator’s electronic flight crew records, the instructor had logged a total of 6,285 hours experience consisting of 2,114 hours aeroplane and 4,171 hours helicopter. Most of the helicopter experience was light single-engine helicopters ranging from R22 to AS350 Squirrel types.

Total multi-engine helicopter experience was 758 hours consisting of 41 hours AS355 twin squirrel and 717 hours EC135. As pilot in command of EC135 helicopters, the instructor logged 467 hours by day and 188 hours by night. A further 62 hours were training or checking under the supervision of an instructor.

Of the total 703 hours night experience, 100 hours were aeroplane and 603 hours were helicopter. Most of this helicopter time was various single-engine types with 200 hours EC135.

Total instrument time was 499 hours, consisting of 234 hours in a simulator and 265 hours flight time. That instrument flight time was divided into 93 hours aeroplane and 172 hours helicopter, including 54 hours EC135.

The instructor’s pilot’s logbook showed total instructional experience of nearly 4,000 hours consisting of 1,700 hours aeroplane and 2,250 hours helicopter. Instructional experience included EC135-specific instruction of 164 hours by day and 48 hours by night.

Proficiency check and flight review status

All of the CASR Part 61 ratings were subject to periodic operational proficiency checks or flight reviews. Based on CASA records, the instructor had completed the checks and reviews that were relevant to the occurrence (see Table 6).

Table 6: Instructor’s proficiency checks and flight reviews

DateProficiency check or flight reviewExpiry
24 May 2016Night VFR flight review – EC13524 May 2018
24 May 2016Flight instructor proficiency check – EC13531 May 2018
27 October 2016Multi-engine helicopter/EC135 type flight review (with IPC)31 October 2018
7 June 2017Instrument proficiency check (IPC)30 June 2018
8 June 2017Flight examiner proficiency check (EPC)30 June 2019

Based on records and interviews with flight examiners, the instructor had demonstrated compliance with the requirements of the various Part 61 proficiency checks and flight reviews. The ATSB noted that the recent EPC in June 2017 was carried out in a company EC135, VH‑ZGP, which was configured with an instrument panel that allowed for 2-pilot IFR operation.

The instructor advised that the flying and knowledge assessments were carried out in a wide variety of environments and flight regimes by experienced and qualified personnel. According to the instructor, at no stage was any significant deficiency identified and there was no evidence of inconsistent flying or varying commitment to flight safety.

The instructor’s logbook indicated that the flight instructor proficiency check (May 2016) was completed in VH-ZGZ. That helicopter did not have flight instruments at the instructor’s seating position. The logbook entry indicated the flight was flown by day and included multi-engine operations and emergencies.

The operator reported that it had not checked the instructor’s proficiency flying from the left seat of an EC135 equipped with a single set of flight instruments situated diagonally across the cockpit from the instructor seating position, in degraded visual environments.

Operator-managed training and assessing status

In addition to the CASR Part 61 checks and reviews, the following flight training and checks were recorded as carried out on behalf of the operator. All except the first check were within expiry dates at the time of the occurrence (see Table 7).

Table 7: Instructor’s additional checks and assessments

DateTraining, proficiency check or flight reviewExpiry
9 September 2015Helicopter underwater escape training9 September 2018
6 March 2017Instructor standardisation check – EC135 (day)6 March 2018
15-17 March 2017Refresher training in emergencies – EC135 simulator (day)[1]Not applicable
17 March 2017Base check – EC135 (day)[2]17 March 2018
5 April 2017MPT line check – EC135 (night)5 April 2018
25 May 2017Human factors flight operations refresher training25 May 2019
17 July 2017CAO 20.11 emergency procedures assessment – EC13517 July 2018
16 August 2017CFIT/ALAR recency16 August 2018

[1]  This refresher training was conducted by the helicopter manufacturer at their factory simulator centre in Germany.

[2]  Recorded in the operator’s recency database.

Based on records and interviews, the instructor had demonstrated conformance to the requirements of the various training and assessments. However, there was anomalous information about the MPT line check flight conducted on 5 April 2017.

That flight was a night flight to Pacific Treasure at the pilot boarding ground then to Shandong Zheng Tong at C1/C2. The chief pilot recorded this flight as a line check of the instructor, but the instructor recorded the same flight as fulfilling the requirements of a night VFR flight review of the chief pilot. The ATSB queried both pilots about the anomaly about 3 years after the occurrence.

Neither pilot could recall any specific details about the flight and could not definitively account for the anomaly. In retrospect, the chief pilot considered it was a line check of the instructor (as pilot controlling the helicopter from the right seat) and the flight review certified by the instructor was based on the chief pilot as pilot in command of that night VFR flight. The instructor advised the ATSB that applicants for a night VFR flight review were required to demonstrate helicopter handling, including manoeuvring with reference to instruments, before the review could be certified complete.

To resolve this anomaly, the ATSB obtained and analysed the ADS-B data for the flight on 5 April 2017. This was compared to ADS-B data for all MPT flights conducted at night by the chief pilot and instructor, respectively, at Port Hedland in January 2018. The ADS-B data for the flight on 5 April 2017 is presented in graphical and tabular form at Appendix C.

Data for the flight on 5 April 2017 showed that circling to both ships was conducted at about 1,000 ft, which was higher than the specified circuit height of 700 ft. Additionally, on both approaches the derived airspeed through 500 ft was about 40 kt, which was lower than the specified 60 kt for the ‘finals gate’.

When that data was compared with data for previous night flights conducted by the chief pilot and instructor at Port Hedland in January 2018, there was a higher correlation with the flights conducted by the instructor. Given the data for the flight on 5 April 2017 was consistent with a typical MPT operation and had a higher correlation with flights conducted by the instructor, the ATSB assessed that the flight was more consistent with a line check than a night VFR flight review. Based on the available information, ATSB was unable to further resolve the anomalous records for this flight.

Marine pilot transfer experience

The instructor was inducted into the marine pilot operation in August 2015 and received EC135 revision training with a flight review. After a month of operating a B206 helicopter and supervising some IFR training on a flight training device, the instructor completed further EC135 revision flying and began EC135 MPT operations under supervision. Over a 3-month period, the instructor conducted a mix of MPT as pilot in command under supervision, flight reviews and other training with company pilots.

On 4 January 2016, the chief pilot conducted a day line check with the instructor from the Mackay (Hay Point) base. The chief pilot recorded the instructor completed 6 ship landings and flew the EC135 well. Based on a satisfactory standard, the instructor was cleared to line for day MPT from Hay Point.

After being cleared to line, the instructor conducted 42 ship landings in daylight conditions, including 7 as pilot in command under supervision. From 11 February 2016, night line training started.

On 8 March 2016, the chief pilot conducted a night line check with the instructor from Hay Point. The chief pilot recorded in the check report that the instructor achieved a sound standard, with comments about lift-off technique, standard call‑outs, ship overflight, and positioning for into-wind approaches. The instructor was also reminded to keep the approach to the vessel relatively steep in case of an engine failure. On completion of the check the instructor had conducted 13 night ship landings and was cleared to line for night MPT.

After being fully checked to line, the instructor was engaged in MPT operations and continued to conduct some flight training and assessments under the approval of the associated flying school.

A review of the operator’s electronic flight crew records and the instructor’s logbooks covering the period 1 January 2017 to the date of the accident, indicated about 370 hours had been flown, mainly in the EC135 type. Of those hours, about 270 were completed in the role of instructor/examiner, which would have been consistent with operations from the left seat.

During that same period, about 180 ship landings were recorded, with about half of those being conducted on night operations. Of the night ship landings, about 30 were in the role of instructor/examiner, consistent with operations from the left seat.

The operator’s electronic flight crew records indicate that the instructor had completed a total of about 450 ship landings. Those records also indicated for the EC135, a total of about 160 hours of day instructing and about 50 hours of night instructing.

For operations at Port Hedland, a total of 10 night flights to C1/C2 were identified, with 3 flown from the right (command) seat in January 2018 and the 7 remaining flights in the role of instructor/examiner from the left seat during April 2017 and March 2018.

Previous night operations at Port Hedland

The ATSB obtained the ADS-B data for the instructor’s transfer flights conducted in January 2018. In addition to the 3 night flights to C1/C2, the instructor conducted 2 night flights to the pilot boarding ground. The data for the 5 night approaches, all in the early morning of 8 January 2018, is presented in graphical, and tabular form at Appendix B.

Moonrise on 7 January 2018 was at 2314 and moonset at 1131 the next day with about 60% of the moon’s visible disc illuminated. For the 5 flights, the moon would have been above the horizon and moving in an arc between 34° and 64° altitude.

An analysis of satellite imagery and meteorological data conducted by the Bureau of Meteorology indicated a large area of scattered to broken stratus cloud (covering between a quarter to almost all of the sky) offshore from Port Hedland with a cloud base estimated to be about 1,200 ft.

With broken stratus cloud and the moon still relatively low in the eastern part of the sky, conditions below the cloud base would have been generally dark, with some patches where the moonlight may have penetrated the cloud layer to illuminate the sea surface. Depending on the angle of approach, the reflection of moonlight on clouds may have been visible. If the stratus cloud was scattered, there would have been better illumination of the sea surface.

The ATSB noted the following:

  • On each arrival the instructor conducted a circuit of the vessel to position for final approach.
  • Other than the first approach, altitude on downwind was inconsistent and non-conforming with the operator’s procedures. Analysis of the ADS-B data indicated that an autopilot upper mode was not used for vertical navigation during operation in the circuit.
  • Other than the first approach, the rate of descent on base was higher than industry practice.
  • Other than the first approach, when established on final approach the helicopter height and airspeed did not conform to the operator’s final gate parameters.
  • The final approach profile was not consistent and on the fourth approach, the rate of descent exceeded the operator’s limit for continuing the final approach below 300 ft.
  • On the second and fourth approaches, the final approach profile was corrected soon after 300 ft, which correlated with the radio altimeter warning.
  • Although there was a partial moon, surface illumination was probably attenuated by cloud.
  • Operations above 1,200 ft, during climb, cruise and descent, might have been affected by cloud.

The ATSB noted that the chief pilot was also carrying out leave relief flying in Port Hedland at the same time and was not advised of any anomalies. Additionally, no report was submitted to the operator’s safety management system.

Medical information

The instructor held a Class 1 civil aviation medical certificate that was valid until 2 October 2018. The certificate required the instructor have reading correction available while exercising licence privileges. Consistent with this restriction, the instructor was wearing prescription spectacles for reading correction.

The instructor said that glasses were always worn when flying. These were bifocal with a focal point customised to the distance from the right-side pilot seat to the instrument panel of the EC135.

There were no other restrictions on the instructor’s medical certificate and the instructor said that there had been no recent illness.

Recent history

The instructor travelled to Port Hedland on 5 March 2018 and was nominally rostered from 0900–1700 between 6 and 15 March. These shifts primarily related to the instructor’s role as head of training and checking and included training and checking flights for other pilots based at Port Hedland. Conducting those tasks would require both day and night operations and the instructor was expected to manage their duty activities during that period and comply with the operator’s fatigue risk management system (FRMS). Information about the operator’s FRMS is discussed in the section Operator’s fatigue risk management system.

The ATSB reviewed the instructor’s sleep log and other available information to determine likely hours of duty and sleep opportunity in the days leading up to the accident. The ATSB observed numerous anomalies when comparing the recorded sleep times in the instructor’s sleep log against other information (see section Review of data in sleep logs). Based on the available information, key points included:

  • The instructor had a sleep opportunity of about 7–8 hours during each night from 5 to 8 March.
  • On 9 to 11 March, the instructor conducted work tasks, including training flights, in the afternoon and evening. There were sleep opportunities of about 5 hours, 6.5 hours and 7.5 hours over those 3 nights.
  • On 12 March, the instructor conducted work tasks from about 1200 to 1900 and recorded sleep in the sleep log from 2200 on 12 March to 0600 the following morning. However, building access records indicated the instructor arrived at the operator’s premises at 0430 and, therefore, had probably been awake before 0400. It is likely there was a sleep opportunity of about 5.5–6 hours, assuming sleep from 2200 as recorded.
  • On 13 March, the instructor was rostered for MPT operations with the pilot under supervision from 0600–1800. The instructor arrived at work at 0430 and was still onsite until at least 1917. The sleep log indicated a sleep period from 2200 until 0600 on 14 March (8 hours), though it was unclear whether the instructor had recorded these times (as these were the default values included in the sleep log tool). Phone records indicated the instructor was awake from about 0530 on 14 March, and probably had an overnight sleep opportunity of about 7.5 hours.
  • When interviewed a few days after the accident, the instructor recalled sleeping well on the night of 13 March and waking late in the morning of the day of the accident. The instructor followed their normal routine and advised of sleeping in bed from about 1400–1600 in preparation for the night shift starting at 1800. Phone records showed no activity from about 1100 to 1600, although a draft email was saved at about 1500 in the afternoon.[24] Accordingly, it is possible the instructor obtained some sleep in the afternoon. The instructor arrived at work at 1648.

In summary, the available information indicates that the instructor had restricted sleep opportunity (5–6.5 hours) on the nights of 9, 10 and 12 March. There were opportunities for 7.5 hours sleep on each night of 11 and 13 March, with a reported 2 hours additional sleep during the day on 14 March. At the time of the accident on 14 March (2348), the instructor had probably slept at most 7.5 hours in the previous 24 hours, and 13.5hours in the previous 48 hours, assuming 2 hours sleep during the day of 14 March as reported.

None of the pilots the ATSB spoke to described seeing the instructor on the night of the accident, although one pilot recalled seeing the instructor on the day before the accident and being concerned about their level of fatigue. According to that pilot, the instructor had red, tired-looking eyes with the appearance of ‘burning the candle at both ends.’ The instructor recorded a relatively high fatigue evaluation at or near the end of the day on 13 March (see section Pilot self-assessments of fatigue).

When interviewed by the ATSB a few days after the accident, the instructor reported feeling alert prior to starting work on the day of the accident. A self-rated fatigue level at the time of the accident was between 2 and 3 out of 7[25]. Immediately prior to the accident flight, the instructor was not feeling completely fresh but did feel rested due to the sleep achieved during the day.

The chief pilot at the time of the occurrence advised that the 14‑hour duty period on 13 March was not normal and was not in accordance with the operator’s FRMS. Pilots were expected to start duty about 30-45 minutes before a scheduled lift-off and to complete their duty within 12 hours unless there was a split shift. The chief pilot noted that it was common for pilots to stay at the office for social reasons after a shift finished, so all the time at the office did not necessarily correspond to duty time.

Helicopter information

General information

The EC135 P2+ helicopter is a light multi-purpose twin-engine helicopter manufactured by Eurocopter Deutschland GMBH. The occurrence helicopter (serial number 777) was built in 2009 and imported into Australia from the United States (US) and registered as VH-ZGA in early 2017. The helicopter was maintained in accordance with the manufacturer’s continuous maintenance program.

At the time of the occurrence, the total time in service of the helicopter was 3,739 hours and time in service since last maintenance was 24.2 hours. Although the maintenance release was not with the helicopter when it was recovered from the seabed, there was no report of any defects prior to the occurrence. Furthermore, a general review of the maintenance records did not identify any anomalies.

The helicopter was powered by 2 Pratt & Whitney PW 206 B2 engines that were equipped with full authority digital engine control (FADEC) systems. When both engines were operating, the 5‑minute take-off torque limit[26] for each engine was 78% and maximum continuous was 69%. Adherence to these limits was dependent on pilot inputs (through the collective control). In an engine inoperative situation, up to 128% torque was available from the operating engine for up to 30 seconds, followed by 125% torque for 2 minutes.

Torque from the engines was transferred by the main transmission to a hydraulically-controlled 4‑bladed rigid main rotor. Antitorque was provided by a Fenestron-type system.

For maintenance purposes, data was transmitted by the electronic engine control (EEC) unit to the data collection unit (DCU) for each engine. Data was only recorded by the DCUs when parameter thresholds were exceeded.

The operator’s 2 EC135 helicopters based at Port Hedland were fitted with aftermarket single-pilot IFR kits in accordance with a supplemental type certificate (STC) approved by the US Federal Aviation Administration. This STC was generally installed to optimise the utility of the helicopter for special mission operations such as aeromedical. The STC was not required for the MPT operation and had no significant effect on the conduct of routine MPT flights. The helicopter was fitted with dual flight controls.

The helicopter cabin incorporated a hinged door adjacent to each pilot seating position and a sliding door on either side of the rear cabin for passenger access. An optional door jettisoning kit was installed that allowed the pilot door hinge pins to be released in an emergency. To jettison the door in accordance with the placard, the pilot was required to open the door (via normal open/close handle) then push the jettison lever downwards.

The helicopter was also equipped with an emergency flotation system[27] that comprised skid‑mounted inflatable floats. The floats could be either manually or automatically activated. Manual activation used a mechanical handle mounted on the pilot’s cyclic control. Automatic activation was via operation of a water immersion switch. Electrical power was required to initiate inflation of the automatic inflation mechanism. The helicopter was also equipped with 2 life rafts that could be manually deployed using a cockpit handle or external handles fitted to either side of the rear cross‑tube of the landing skids.

VH‑ZGA and other EC135 helicopters in the operator’s fleet were not fitted with a helicopter terrain awareness and warning system (HTAWS). An enhanced ground proximity warning system (EGPWS) was available from the manufacturer as an option. At the time of the occurrence, and writing, HTAWS was not required for the category of helicopter and type of operation.

Autopilot and stability augmentation system

The helicopter was equipped with an automatic flight control system (AFCS) supplied by the manufacturer as an option. This system enabled single-pilot operations in instrument meteorological conditions.

The AFCS consists of 3 independent elements: stability augmentation system (SAS), pitch damper, and 3-axis autopilot system. Each element operated as part of an integrated system according to programmed control laws and pilot selectable modes. The AFCS was selected ON for normal operations.

Stability augmentation was provided by a yaw SAS and pitch and roll SAS. These systems computed yaw rate and used attitude sensor data to drive actuators connected in series or parallel to the pedal and cyclic flight control circuits. In the default condition, feedback was provided to each pilot’s cyclic control.

Pitch damping utilised computed rate data to control an actuator within the cyclic pitch circuit. When the autopilot was operative, it directly commanded movement of the pitch damping actuator.

The autopilot system comprised the autopilot module (APM) and autopilot mode selector (APMS), which was located on the centre console panel. The APM was interfaced with multiple flight state data sources, SAS sensors and actuators.

In typical operation, the pilot selected the autopilot ON before take-off, which engaged the default automatic trim mode (A.TRIM). This basic autopilot function provided attitude hold that allowed ‘hands-off’ operation for reduced pilot workload. If A.TRIM was selected off, the system entered an autopilot SAS mode requiring ‘hands-on’ operation and some autopilot modes were not available.

When operating in the A.TRIM mode, the pilot could make adjustments to pitch and roll attitude by manipulating the cyclic control (Figure 6) in one of 3 ways. First, the pilot could simply override the A.TRIM control inputs to move the cyclic as required. On pilot release of cyclic input, the (unchanged) trim forces would return the cyclic and associated attitude to the pre-input values. This method could be used for short term attitude adjustments.

Second, the pilot could press and hold the force trim release (FTR) switch on the cyclic grip while moving the cyclic as required. Actuation of the FTR switch opened the actuator clutches and removed resistance to cyclic movement. When the switch was released, the actuator clutches closed and the A.TRIM was synchronised to the current cyclic position and associated attitude. Use of this method for significant and sustained attitude adjustments was common.

Finally, the pilot could manipulate the 4-way BEEP TRIM switch to ‘slew’ the attitude reference at 2–4° per second (depending on airspeed and axis). Without further pilot input, the helicopter would change attitude smoothly to the new reference. This was the preferred method for small attitude changes or fine adjustments.

Figure 6: Cyclic grip switch arrangement (side and front view)

Figure 6: Cyclic grip switch arrangement (side and front view)

Source: EC135 Approved Rotorcraft Flight Manual

In addition to the basic autopilot mode, when the helicopter was at or above 65 kt airspeed, the AFCS allowed the pilot to engage ‘upper’ modes:

  • altitude (ALT), to maintain the current barometric altitude
  • heading (HDG), to select, intercept, and maintain a magnetic heading
  • airspeed (IAS), to maintain the airspeed at the reference value
  • altitude acquire (ALT.A), to acquire and perform an automatic level-off to capture a selected barometric altitude
  • vertical speed (V/S), to maintain the vertical speed at the reference value
  • various other modes used during en route navigation and instrument approaches.

The active upper mode(s) were displayed to the pilot on the primary flight display (PFD) by a green upper axis mode label and illumination of the corresponding push-button on the APMS panel.

Another mode, go-around (GA), could be selected on the collective grip. Depending on the software version, this acquired and maintained an airspeed of 75 kt or acquired and held a vertical speed of 1,000 ft/min. In VH-ZGA the installed software had a vertical speed target parameter.

When operating in upper modes other than IAS, the minimum height limit was specified as 500 ft above ground level (AGL). If an upper mode was engaged and airspeed reduced below 60 kt, all upper modes of the AFCS were inhibited except IAS mode (minimum airspeed 40 kt). When this occurred, an amber DECOUPLE caution illuminated on the cockpit cautions and advisories display (CAD) and the label on the PFD was replaced by a flashing green box for 10 seconds before extinguishing. There was no audible warning to indicate decoupling of upper modes.

For complete disengagement of the SAS and AFCS, the pilot could select the SAS/AP CUT switch on the cyclic grip. To re-engage SAS and pitch damper functions, the pilot could manipulate the 4-way P&R/P-D/YRST switch on the cyclic grip. If the pilot wanted to cancel all upper modes, actuation of the APMD DCPL switch on the cyclic grip resulted in reversion to A.TRIM mode.

Instrument panel configuration

One of the features of the single-pilot IFR STC was modification of the instrument panel to extend the panel to the right of the helicopter with variation to type and location of avionics and instrumentation. The panel of VH-ZGA is shown in Figure 7 and for comparison an exemplar of the standard instrument panel fitted to the operator’s other EC135 helicopters is shown in Figure 8. Note: although the avionics and instrument layout for the 2 Port Hedland-based EC135 helicopters was similar, the panel in VH-ZGA retained panel area to the left of the centre console and the panel in VH-ZGZ was truncated to the left of the centre console.

In both non-standard instrument panels, the PFD and navigation display (ND) were both offset to the right (relative to the standard location) by the width of the displays. A further variation was installation of an integrated standby attitude module in place of the set of analogue standby instruments in the standard configuration.

Figure 7: Single-pilot IFR instrument panel fitted to VH-ZGA

Figure 7: Single-pilot IFR instrument panel fitted to VH-ZGA

Source: Helicopter operator

Figure 8: Operator’s EC135 standard instrument panel

Figure 8: Operator’s EC135 standard instrument panel

Source: Reproduced with permission

Primary flight display

The PFD and ND fitted to each of the Port Hedland-based EC135s were SMD 45H multifunction colour displays designed for helicopters. These units were described as a high resolution, 4 x 5 inches (102 x 127 mm), active-matrix liquid crystal display. Brightness of the display was pilot adjustable. A typical display layout is shown at Figure 9.

As shown below, all of the critical flight information was presented on the PFD with conventional representation of attitude and digital representations of airspeed and altitude as scrolling vertical tapes. Other information such as AFCS mode and navigational data was usually presented with cautions/warnings related to non-normal equipment status.

An airspeed trend indicator aligned with the airspeed value predicted in 5 seconds. Vertical speed was indicated by the position of a white bar relative to an analogue scale and an associated numerical value to indicate the vertical rate in hundreds of feet. Above 2,000 ft/min in either climb or descent, the white bar was at full-scale deflection and did not provide an accurate analogue indication. In that circumstance and with the white bar at full-scale deflection, the numerical value correctly indicated the vertical rate.

Radio altimeter height information was depicted relative to ground/water level on the altitude tape, by a brown coloured terrain symbol (radio height zero). Radio height was displayed as a digital readout on the lower part of the attitude ball when within 500 ft of the surface. Above 500 ft of the surface, the radio height was also displayed within 500 ft of the selected decision height. The radio height was also displayed as a tape style readout on the right side of the ND. Magnetic heading was shown at the bottom of the PFD on a linear scale, which represented the arc of a circle.

Figure 9: Typical SMD 45H configured as primary flight display

Figure 9: Typical SMD 45H configured as primary flight display

Typical depiction of flight parameters on a SMD 45H configured as primary flight display. The information displayed indicates the helicopter is in a slight nose-up pitch attitude, descending through an altitude of 6,900 ft at 300 ft/min and an airspeed of 129 kt. The green symbols at the top of the display indicate that the AFCS IAS and HDG upper modes are active. The radio altimeter decision height has been set to 300 ft. The decision height flag is displayed on the on the attitude ball, with the radio height (220 ft) displayed below. The level of terrain relative to the helicopter’s current altitude is depicted on the altimeter scale.

Source: Eurocopter EC135 training manual, modified by the ATSB

A range of guidance material for the design and certification of aircraft states that key flight parameters (such as attitude, altitude and airspeed) should be placed within a pilot’s primary field of view, which is normally defined as being within 15° horizontally each side of straight ahead. This area corresponds to the highest visual acuity and can be searched with minimal or no head movement, and information placed outside of the primary field of view may not be detected as quickly (Yeh and others 2016).

Aircraft certification requirements for normal category rotorcraft stated that each flight and navigation instrument must be ‘easily visible’ to the pilot. Accordingly, the Federal Aviation Administration (FAA) Advisory Circular 27-1B (Certification of normal category rotorcraft) have recently defined this as meaning that high priority information and primary flight information should be displayed in the primary field of view (defined as 15° each side of straight ahead).[28]

The PFD’s location on VH-ZGA was in the primary field of view for a right-seat pilot and was located at about 57° to the right of straight ahead for a left-seat pilot. The PFD was located about 800 mm away from a right-seat pilot and about 1,120 mm away from a left-seat pilot.

A range of factors can affect the readability of alphanumeric characters, including their size. Various sources recommend a minimum height of 24 minutes of visual angle for aircraft environmental conditions (Yeh and others 2016). This equated to a minimum height on a right-side PFD of about 5.6 mm for a right-seat pilot and 7.8 mm for a left-seat pilot. The size of the numerals on the altitude display were about 8 x 4 mm for the major numbers (to indicate the thousands of feet) and 6 x 3 mm for the minor numbers (to indicate the hundreds of feet). When viewed from a significant angle, the width of the numerals would also appear smaller. Significantly, when operating below 1,000 ft, the major number displayed zero and the minor number indicated the helicopter’s altitude, in hundreds of feet. Consequently, for a pilot sitting in the left seat and using the PFD on the right side of the cockpit, the altitude indication when operating below 1,000 ft was smaller than the minimum size commonly recommended for readability.

During the initial interview with the ATSB a few days after the accident, the instructor said the standby flight instruments in VH-ZGA were small, and the primary flight instruments were the best for flying. The instructor said that the primary instruments were clearly visible from the left seat, but there was an increase in workload associated with looking outside, looking inside, and looking across the cockpit. In that context, the instructor preferred to have their own set of primary flight instuments. When interviewed again in early 2020, the instructor advised of difficulty viewing vertical speed information, including at night over water while trying to transition to a missed approach. To the instructor, this was because the vertical speed indicator was at the far side of the right-seat pilot’s PFD.

The ATSB spoke to other EC135 pilots who had experience flying from the left seat, but in helicopters equipped with a single set of primary flight instruments. The chief pilot from the time of the accident said that a pilot in the left seat had a good view of the primary flight instruments to preform the task of monitoring the helicopter’s flight path, but that in an emergency recovery situation, it would be difficult not having your own instruments to use. The head of training and checking appointed to the operator after the accident said that you could not read the displayed information (such as airspeed, rate of descent and altitude) as clearly with the primary flight instruments across the other side of the cockpit. The operator no longer conducted training and checking in helicopters that were not equipped with primary flight instruments at the instructor’s seating position. Other EC135 pilots with experience flying from the left seat considered that for night operations, and at other times when operating in degraded visual environments, it was important to have primary flight instruments at the instructor’s seating position.

Standby attitude module

The 2 helicopters based at Port Hedland were each equipped with a MD302 standby attitude module mounted in a central location relative to both pilots. The 2-inch (51 mm) format digital displays (Figure 10) presented an attitude indicator with heading numerals and an adjacent set of scrolling tape indicators with windows for airspeed and altitude data. This module was installed to satisfy the night VFR and IFR requirement for a backup set of flight instruments. Note: the arrangement of the instrument display screens in VH-ZGA and VH-ZGZ were transposed, with the attitude indicator displayed on the right screen and the airspeed and altimeter on the left screen.

Figure 10: MD302 standby attitude module

Figure 10: MD302 standby attitude module

Source: Mid-Continent Instruments and Avionics Pilot’s Guide MD302 Standby Attitude Module

On the right edge of the module, rate of climb/descent was represented by a magenta altitude trend bar adjacent to the moving altitude scale. The trend bar was anchored to the central fixed altitude pointer and expanded up if climbing (as per example) or down if descending, by an amount proportional to the rate of vertical change. At the upper or lower end of the bar, respectively, the adjacent increment/figure was the projected altitude if the current vertical trend was maintained for a 6-second period.

For 500 ft/min rate of descent, the trend bar would expand downward to indicate 50 ft less than the indicated altitude, which was equivalent to 25% of the lower-half scale. Those parameters would double for 1,000 ft/min. In this occurrence, when VH-ZGA was passing 300 ft with a descent rate of 1,700 ft/min, the trend bar would have extended down by 170 ft (85% of the lower-half scale) to be adjacent to 130 ft.

The standby attitude module was located about 840 mm from a left-seat pilot, about 38° to the right of straight ahead. The instructor reported difficulty viewing the vertical speed information, describing the standby vertical speed information as tiny and badly lit.

Standard standby instrumentation

The standby instruments installed in the operator’s standard EC135 helicopters were an airspeed indicator, attitude indicator, and altimeter (Figure 11). These were conventional analogue instruments classified as 3 1/8 inch (80 mm). Note there was no vertical speed indicator (VSI).

Figure 11: Typical EC135 standby instrument configuration

Figure 11: Typical EC135 standby instrument configuration

Source: Helicopter operator

Central panel display system

The central panel display system (CPDS) comprised a vehicle and engine multifunction display (VEMD) and CAD. On the upper screen of the VEMD, the first limit indicator (FLI) page was normally selected to display key engine parameters digitally and represent the limiting parameter as an analogue pointer (Figure 12). Other data such as mast moment[29] and messages was also presented.

Operationally, the FLI provided an easily interpreted scale and guide for engine/torque settings.

Figure 12: Typical first limit indicator page

Figure 12: Typical first limit indicator page

Typical depiction of the helicopter’s FLI page on the CPDS, extracted from the helicopter manufacturer’s EC135 P2+ flight manual. In this example, the digital readout indicates that the left and right engines are producing 78% torque and the adjacent solid white rectangles denote that these are the first-reached limits being displayed by the analogue FLI needles. Although the small split in needle indication illustrates the existence of 2 needles (indicating the torque produced by each engine), the position of the needle for the right engine is not representative of the torque indicated by the corresponding digital readout. For a normal-indicating situation where both engines were producing 78% torque, the 2 needles would both be aligned and pointing to the index mark at 10 and the corresponding red line radial denoting the 5-minute, 2 engine take-off power limit. Operation of the engines within in the yellow arc was limited to 5 minutes. A countdown timer on the face of the FLI indicated the time remaining at the relevant limit. The bottom of the yellow arc (index mark 9) denotes the 2-engine maximum continuous power (69% torque).

Source: Eurocopter EC135 P2+ flight manual

Internal lighting

Instrument lighting

The helicopter was equipped with instrument lighting for night operation. A 3-position switch on the overhead console panel controlled the lighting with selections for DAY, NIGHT and NVG [night vision goggle], together with an adjacent dimmer rheostat control. When selected to NVG, the lighting was modified to minimise the amount of NVG-sensitive illumination (such as near infrared) for optimum imaging in low-light environments.

After recovery of the wreckage to Port Hedland, the overhead console switch for instrument lighting was found in the NVG position and the dimming rheostat set close to fully dimmed. Although the instrument lighting selector was set to the NVG position, there was no evidence that the visible light range of the instrument lighting was insufficient for unaided night operations.

The SMD 45H primary flight display, VEMD, and CAD displays were fitted with brightness dimmer controls. All of these displays were compatible for use with NVIS.

Helicopter emergency egress lights

The helicopter was not fitted with helicopter emergency egress lights (HEEL). Although the cockpit overhead switch panel was fitted with a switch position and markings for that system, there was no switch installed at that location. There was no regulatory requirement for provision of emergency exit egress lighting.

When installed, the HEEL system was designed to automatically activate and assist occupants in an emergency to locate the door opening/jettison handles and exits, using illuminated markings and lighting for the emergency exits and operating handles. Green strip lights surrounded the doors used as emergency exits, green strip lights at the corners of the emergency exit windows and orange lights near the door opening/jettison handles.

Although there was no HEEL system installed, each exit and the relevant operating handles displayed the required placards and markings.

External Lighting

Controllable search/landing light

A steerable search/landing light was installed on the helicopter’s lower front fuselage and retracted flush with the fuselage when not in use. Switches on each collective control enabled either pilot to select the light ON/OFF and control the direction of the beam.

After recovery of the wreckage to Port Hedland, the right search/landing switch was found in the ON position and the left in the OFF position. Pilots conducting MPT operations reported that the controllable searchlight was effective during the later stages of final approach and was used to illuminate the landing area/hatch.

Nose-mounted traffic identification light

The helicopter was fitted with a nose-mounted traffic identification light that could be selected to ON (steady illumination) or PULSE (flashing illumination). This light was controlled by a switch on the overhead panel. After recovery of the wreckage to Port Hedland, the selector switch was found in the OFF position.

Position lights, anti-collision light and strobe lights

The helicopter was equipped with position, anti-collision and strobe lights. The position lights were steady red, green and white lights. The white light was mounted on the tail of the helicopter, the red light was mounted on the left horizontal stabiliser and the green light mounted on the right horizontal stabiliser. The anti-collision light was a flashing red light on the tip of the helicopter’s tail and the strobes were flashing white lights on the tip of each horizontal stabiliser.

After recovery of the wreckage to Port Hedland, the position and anti-collision lights were found in the ON position and the strobes were OFF. That configuration was consistent with a night VFR operation when operating close to reflective surfaces, to reduce potential disorientation.

Although the marine pilot who witnessed the accident advised that the water impact was partially illuminated by a strobe light, the as‑found position of the steerable search/landing light and strobe switches could indicate the light flash at impact was water being illuminated by the downward-pointing search/landing light.

Communication

The instructor and pilot under supervision were both wearing flight helmets, equipped with a boom microphone and headphones. The pilots and any passengers wearing a headset could communicate with each other using an intercom system. The intercom system could be either voice or push-button activated, with the mode selected on each audio controller panel located in the centre console between the seats.

The communication jack on the left (instructor) side of the cockpit was fitted with a quick-release, short-length break-away connector. Although that connector was still plugged into to the cockpit jack following the helicopter’s recovery from the water, the instructor’s flight helmet had been recovered from the search area the morning after the accident.

After recovery of the helicopter to Port Hedland, the ATSB noted the switch positions on the audio controller panels. Both intercom selectors were found selected to voice activation and the instructor’s audio switch was selected to NORMAL. However, the pilot under supervision’s audio switch was selected to ISO/EMERG.

Each audio switch was toggled between the 2 positions with a simple forward/rearward movement. Given the location of the panel and the switch being unguarded, the ATSB considered that the switch could have been unintentionally moved during the accident sequence or prior to recovery. However, there was no damage to the audio controller panel and no significant variations between the other switches on each respective panel to indicate that this had occurred.

If the audio switch had been selected to ISO/EMERG during the flight, from that point onwards there would have been no intercom communication between the instructor and pilot under supervision. The instructor did not advise of any communication difficulties; so, in this scenario, the instructor might have issued instructions to the pilot under supervision that were not heard or complied with.

Helicopter manufacturer’s operating procedures

The helicopter manufacturer’s aircraft flight manual (AFM) for the EC135 specified operational limitations and checks to ensure that systems were properly configured for normal flight and a selection of emergency and malfunction conditions.

The AFM specified pre-landing checks of instruments, warnings, and cabin security and recommended landing procedure from 50 ft AGL. No procedures were provided for circling approaches or night operations, and none were required by regulation.

Simulator training provided by Airbus Helicopters to the instructor was oriented to general operation of the EC135 and the management of emergencies.

Meteorological and environmental conditions

Meteorological information

The Bureau of Meteorology (BoM) reported light, variable winds, generally below 10 kt (19 km/h) during the day and night of the accident. There was little to no cloud present and no rain.

The port operator’s meteorological equipment and hydrographic sensors recorded that the surface wind conditions in the vicinity of the pilot boarding ground (PBG) and the C2 channel marker, were generally westerly flows, with the wind strength increasing slightly as the evening progressed. The maximum wind gust recorded during each of the 10-minute intervals was less than 3 kt (6 km/h) above the average wind for the period. The BoM grid point wind and temperature (GPWT) forecast for 2300 predicted similar wind speeds at the 1,000 ft and 2,000 ft levels, with a minor change in wind direction. The GPWT wind direction and speed forecast for 1,000 ft, were generally consistent with the 10-minute average winds recorded at the channel markers (Table 8).

Table 8: Average recorded wind velocity and GPWT forecast

Time (WST)10-minute average W/V recorded near PBG (deg True/kt)10-minute average W/V recorded at C2 (deg True/kt)2300 WST GPWT forecast wind, 1,000 ft (deg True/kt)2300 WST GPWT forecast wind, 2,000 ft (deg True/kt)
2300245/08251/08270/08300/06
2310246/08247/08--
2320243/09250/10--
2330194/10256/10--
2340237/12255/10--
2350230/12253/11--


Data from a Waverider buoy in the vicinity of C2 around the time of the accident indicated a swell wave height of 0.29 m at 10 second intervals and a sea wave height of 0.19 m at 8.3 second intervals.[30] The combined result of swell and sea height would have produced total wave heights of less than 0.4 m. The sea temperature was 30.6 °C.

Hydrographic data from the port authority’s equipment at C2 recorded a near surface current of 0.2 kt (370 m/hr) running in a north-north-westerly direction.

Sunset and moon information

Sunset at Port Hedland on 14 March 2018 was 1822 and the end of civil twilight[31] (last light) was 1845. Civil nautical twilight[32] was 1910 and astronomical twilight[33]1936. The moon was a waning crescent, rising at Port Hedland at 0356 on 15 March, with about 0.14% of the visible disk illuminated. As a result, dark night conditions existed after civil nautical twilight for all flights away from sources of artificial lighting.

Artificial/cultural lighting

In the vicinity of Port Hedland there were significant areas of flood lighting associated with ground infrastructure, which included industrial facilities, port infrastructure and lighting associated with suburban areas. During offshore operations, this lighting would have been in the distance, to the south of the pilot boarding ground and to the south-south-east of the C1/C2 channel markers.

Overall, the location of the C1 and C2 channel markers, about 21 NM (39 km) north-west of Port Hedland, meant there was very little environmental lighting in the vicinity. Pilots who were experienced in MPT operations from Port Hedland said C1/C2 was very dark at night.

Vessels at anchor

At the time of the accident, there were 17 vessels anchored at the eastern anchorage, awaiting access to the port. At night, those vessels were illuminated by their deck flood lighting. The anchorage was just over half-way between the C1/C2 channel markers and Port Hedland. Figure 13 depicts the relationship between the flight path of VH-ZGA, vessels at anchor and another vessel underway (Ormond) at the time of the accident.

The instructor told the ATSB that the visual environment made the approach to vessels at C1/C2 very challenging, and the channel marker lights did not assist with navigation. The instructor said that, other than lights on the target ship (Squireship), there were no visual references and the ship effectively appeared as a single light source.[34]

Following the go-around, the instructor may not have been able to sight the target ship for brief periods, due to the location of the other pilot and window posts.

Figure 13: ADS-B flight path for VH-ZGA, including relative position of Port Hedland, vessels at anchor and vessels underway at the time of the accident.

Map of flight path

This image shows the helicopter flight path during the accident flight and the surface track of the departing bulk carrier in vicinity of C1/C2. Also shown is the position of the bulk carrier, Ormond underway along the shipping channel at the time of the accident, together with the vessels at anchor.

Source: Port Hedland electronic navigational chart produced by The Australian Hydrographic Office, modified by the ATSB

Wreckage recovery and examination

Wreckage disposition

The helicopter was found on the seabed, on the right side of its fuselage in about 20 m of water (Figure 14). Video recorded by police divers showed all doors in the closed position. Almost all the left main cockpit windscreen was missing, with some perspex remaining in the lower section behind the instrument panel and around the sides of the frame. The left chin window had also broken. The right main cockpit windscreen and right chin window were intact.

Figure 14: Sonar image of helicopter resting on its right side

Figure 14: Sonar image of helicopter resting on its right side

Source: Pilbara Ports Authority and contractors working on their behalf

The left cockpit door (adjacent to the instructor) was visible in the initial police dive footage (Figure 15). The door’s operating handle was in the closed position and the latch pins were holding the rear edge of the door flush with the fuselage. The front of the door was slightly ajar from the door frame and the 2 hinge pins had been retracted, consistent with the position of the door’s emergency jettison handle that appeared to be in the DOWN position.

The right cockpit door (adjacent to the pilot under supervision) was not visible in the initial police dive footage because of the disposition of the helicopter on the seabed. After the first attempt to lift the helicopter, the orientation of the helicopter changed, and subsequent dive footage showed the door was securely attached with the door operating handle in the closed position.

Figure 15: Image of instructor’s cockpit door captured from police dive video, showing deployment of the door’s emergency jettison system and a partial door release

Figure 15: Image of instructor’s cockpit door captured from police dive video, showing deployment of the door’s emergency jettison system and a partial door release

This image shows the helicopter as found on the seabed, on the right side of its fuselage. The instructor’s cockpit door (left) is shown with the forward hinge pins retracted and the door’s front edge slightly ajar from the fuselage. The door operating handle used for normal door operation is still in the closed position and the latching mechanism is holding the rear edge of the door closed.

Source: Western Australia Police Force dive video, annotated by the ATSB

Wreckage recovery

The Pilbara Ports Authority and their contractors recovered the helicopter wreckage from the seabed during 18 and 19 March 2018 (Figure 16). The wreckage was moved into secure storage where it was examined by the ATSB.

Figure 16: VH-ZGA being lifted onto the dock

Figure 16: VH-ZGA being lifted onto the dock

Source: ATSB

Wreckage examination

The helicopter was substantially intact, although the main rotor head and transmission gearbox separated from the airframe during the recovery.

Three of the main rotor blades sustained significant damage near their blade roots during water impact and one of the main rotor blades had struck the upper surface of the helicopter tail boom. The flexible coupling of the main gearbox drive output shaft had sheared. The Fenestron blades exhibited evidence of rotational damage.

A review of police dive footage indicated that the main rotor transmission deck was damaged during the initial water impact, with the main gearbox and main rotor assembly tilting in a forward‑of‑centre position and tearing through the surrounding cowling panels. The disrupted transmission deck structure was most probably the result of reactive forces during the water impact of a powered main rotor system. Additional damage to the helicopter transmission deck, gearbox and rotor assembly and associated systems was sustained during the wreckage recovery.

Figure 17: Main rotor blades and main transmission, showing damage in vicinity of the blade roots

Figure 17: Main rotor blades and main transmission, showing damage in vicinity of the blade roots

Source: ATSB

Damage to the engine compressors and associated housings indicated that both engines were rotating at impact. To the extent possible, due to the nature of the accident damage and wreckage recovery, continuity of the flight controls was established.

The left cockpit door (adjacent to the instructor) detached from the fuselage during the recovery operation and was not located. It was confirmed that the emergency door jettison handle was in the DOWN (release) position and the safety wire to the instructor’s handle was broken.

The right cockpit door (adjacent to pilot under supervision) had been opened during the recovery operation, indicating that there was no defect with the latching mechanism. It was confirmed that the door’s hinge pins were engaged, and the emergency door jettison handle was in the UP (secured) position with intact safety wire.[35]The emergency jettison for that door was functionally tested and found to operate normally.

The helicopter’s emergency flotation system had not deployed. Examination of the panel-mounted cockpit arming switch was consistent with the switch being in the armed position. The immersion switch for the automatic inflation system was functionally tested and found to operate normally. The immersion switch required to be submerged in water for several seconds before the circuit closed to enable the automatic deployment of the flotation system. Electrical continuity was demonstrated between the circuit breaker panel, the immersion switch and the linear actuator. Inspection of the actuator indicated that neither an automatic nor manual inflation had been initiated. The linear actuator was functionally tested and found to be capable of normal operation.

Electronic component examination

The ATSB recovered various electronic components from the helicopter engines and airframe to assess the data stored in their non-volatile memory. This data included information about system conditions and faults, typically used for maintenance and troubleshooting purposes. The units recovered included the:

  • electronic engine control (EEC) for each engine
  • data collection unit (DCU) for each engine
  • cockpit warning unit (WU)
  • cautions and advisories display (CAD)
  • vehicle and engine multifunction display (VEMD).

ATSB investigators removed the required logic boards from the WU, CAD and VEMD at the ATSB technical facilities. Arrangements were then made for the French Bureau d’Enquêtes et d’Analyses (BEA) to complete the specialised cleaning and drying of components, prior to attempting the data recovery on behalf of ATSB.

The logic boards for the WU,[36] CAD[37] and VEMD[38] were dispatched from Canberra on 29 May 2018 as an international air freight consignment but were lost in transit. Extensive checking and investigation by the freight provider to locate the tracked consignment was unsuccessful. Consequently, any information stored on these components could not be retrieved for analysis.

The DCU and EEC for each engine were shipped to the Transport Safety Board (TSB) of Canada on 28 March 2018 to enable specialised desalination, cleaning and drying of components in preparation for the data download attempt. The data recovery task was successful, and data was obtained from each of the components.

Analysis of the data stored in the DCU indicated that both engines were coupled to the main transmission and operating when the DCU recordings were made. The recordings were associated with events occurring to the helicopter engines as a consequence of the water impact. The recorded values for some parameters may have been affected by structural integrity or system degradation due to the impact forces. The speed of the main rotor was not a parameter provided to the DCU.

The first event recorded to the left engine’s DCU was because of the engine control governing on the maximum fuel flow rate. At this time, the left engine torque was at 61.4% and the ‘cross-talk’ torque for the right engine was 48.9%. The split between the torque recorded for the left and right engines can be attributed to the variability in the events happening to the engines, the main rotor, and the engine to transmission connections. At the time of that recording, the power turbine was rotating at 99.1%, the gas generator at 81.6%, measured gas temperature 615.3 °C and the collective lever raised to 33.8°.[39]

The first event recorded to the right engine’s DCU was a consequence of the engine control governing on the minimum fuel flow rate. At that time, the right engine torque was at 38.2% and the ‘cross-talk’ torque for the left engine was 43.7%. At the time of that recording, the power turbine was rotating at 93.1%, the gas generator at 81.7%, measured gas temperature 605.8 °C and the collective lever at 82.6°.

Relevant engine limitations specified in the AFM indicated that for 2 engine operation, take-off power was 78% torque each engine, for a limit of 5 minutes and maximum continuous power 69% torque each engine. The maximum speed for the gas generator was 98.7% for take-off power and 97.4% maximum continuous maximum power. The relevant limit for the power turbine outlet temperature was 869 °C and 835 °C respectively.

Those limits would be indicated on the first limit indicator (see the section titled Central panel display system) as ‘10’ for the 5-minute take-off power setting and ‘9’ for maximum continuous power.

Although the data stored in the DCU indicated engine power significant to demonstrate the operation of both engines, that data did not represent a power setting consistent with a go-around or emergency application of power.

Operator organisational information

Operator history

In 2016, the helicopter operator successfully tendered to provide helicopter services for the transfer of marine pilots at Port Hedland, Western Australia. The contract required provision of helicopters and pilots commencing 1 April 2017. For the contracted services, the operator based 2 EC135 P2+ helicopters at Port Hedland and 8 helicopter pilots, who operated on a rotating 3‑week fly-in/fly-out touring roster.

The initial staffing for the Port Hedland contract comprised 4 pilots recruited from the outgoing helicopter contractor, 3 pilots transferred from the operator’s other bases and a recently re‑recruited pilot. The previous contractor had conducted MPT operations using single‑engine EC120 helicopters. As part of their induction at the new company, the 4 pilots from the previous contractor were provided ground school training and an endorsement to operate the EC135.[40]

Air Operator’s Certificate

At the time of the accident, the operator held an air operator’s certificate (AOC) issued by the Civil Aviation Safety Authority on 18 December 2017 and due to expire on 31 August 2019. This certificate authorised airwork and charter operations utilising a variety of helicopters including the EC135 type and flying training in accordance with CASR Part 142 for EC135 type ratings. An approval certificate issued in accordance with CASR Part 141 allowed for flight training for various licences and ratings.

Chief pilot information

As the holder of an AOC authorising aerial work and charter, the operator was required to appoint a chief pilot subject to approval by CASA. The chief pilot at the time of the occurrence had been in that role since nomination and approval in 2013.

At the time of nomination, the chief pilot held an air transport pilot licence (helicopter) and multi‑engine helicopter instrument rating. Total helicopter flying experience was recorded as 3,957 hours including 1,832 hours multi-engine and 1,365 hours multi-crew. Total night experience was recorded as 1,072 hours and total instrument flight as 440 hours. The chief pilot did not have any flight instructing qualifications or experience and this was not a requirement.

The assigned CASA inspector completed the internal checklist for approval of a chief pilot. This recorded that the desktop assessment, interview, and briefing were conducted with a satisfactory result. As part of the interview process, the CASA inspector assessed knowledge of applicable regulations and observed a MPT flight.

The ATSB noted that as part of the CASA assessment, the chief pilot was requested to outline the induction process for a new pilot including the type of proficiency check conducted prior to releasing a new pilot to line operations. There was no requirement for an assessment of the chief pilot’s capability to conduct a proficiency check or flight training and none was conducted during the approval process.

Safety management system

At the time of the occurrence, charter operators were not required to have a formalised safety management system (SMS). In this case the operator had voluntarily implemented a SMS, so the ATSB carried out a limited-scope review for context.

The operator issued version 5 of their SMS manual in November 2017. This outlined the safety function and defined the policy, activities, and assessments that were aimed at proactive and reactive management of risk. A group safety manager was employed to maintain the system with support from base safety officers and the participation of all company personnel. Reporting and recording could be done through operational management software.

According to the SMS manual, the operator intended to identify areas of vulnerability to human performance limitations and address these with non-technical skills training. This included external computer-based courses: controlled flight into terrain/approach-and-landing accident reduction, crew resource management, and human factors for helicopter flight crews and internal training on fatigue risk management.

Overall, the SMS records showed that safety meetings were taking place regularly and matters were being reported and generally addressed. Development of fatigue risk management and fatigue concerns were a consistent theme. Safety investigations had been conducted in response to damage from heliporter[41] use (initially undetected) and in‑flight detachment of an engine cowling.

A hazard and risk register was maintained to record the risk of a number of potential events before and after mitigation were assessed. This addressed flight operations and other aspects of the operation such as engineering and work health and safety. As a ‘living’ electronic document, a version history was not recorded.

The SMS specified annual safety surveys,[42] which were completed in February 2015, January 2017, and January 2018. As the survey methodology changed after 2015, only the results of the 2 later surveys were considered. There were 16 respondents in 2017 and 35 in 2018 but the number of potential respondents for each survey was not recorded.

Both surveys comprised questions that addressed the operator’s management of safety and effectiveness of safety reporting. The responses in both surveys were consistently positive for all of the questions except for the question about confidence that staff would report events and actions with potential for damage or injury/death. In 2017, all of respondents recorded ‘Yes’ but in 2018, 66 % of the respondents recorded ‘Yes’ and 34 % recorded ‘No’. Some of the ‘No’ responses were associated with the heliporter damage incident that was initially unreported.

There were no records kept of the following activities specified in the SMS manual or referenced in safety meetings:

  • flight operations audit
  • risk assessment for helicopter operations (recorded as ongoing)
  • data trend analysis.

The operator maintained a change log with reference to various plans for the transition into the Port Hedland operation by April 2017. In relation to MPT, there was nothing to indicate that night VFR operation in a degraded visual cueing environment (see the section titled Flightpath management) or the offshore environment was recorded as a specific threat and subject to formal risk assessment and mitigation. There was also no recorded risk assessment as to the suitability of the single-pilot IFR helicopters (VH-ZGA and VH-ZGZ) for night VFR training and checking at Port Hedland.

External audits

In May 2017, an aviation consulting organisation conducted an operational and technical safety audit of the operator’s Port Hedland base on behalf of a mineral resource company. Audit scope included organisational, operational, and engineering elements defined by the resource company. No major non-conformances were reported by the auditors.

For flights at night and/or under the IFR that carried resource company personnel, it was recommended that the operator conduct the flights with 2 pilots or request a dispensation from the company. Given the helicopters based at Port Hedland were not equipped with weather radar, it was recommended that the operator seek a dispensation. The ATSB noted that the recommendation for 2 pilots for flights at night and/or under the IFR in helicopters was based on the resource company requirement for a safety pilot rather than for a 2-pilot operation.

In June 2018 (3 months after the occurrence), the operator contracted an aviation consulting company to carry out an audit in accordance with the basic aviation risk standard (BARS)[42] offshore helicopter operations safety performance requirements. This was the inaugural BARS offshore audit for the operator and was conducted at Mackay Airport. Further information related to the BARS audit is provided in the section titled Non-regulatory guidance – Flight Safety Foundation.

The BARS audit did not identify any Priority-1 safety critical findings, although a number of Priority-2 findings were reported. One of those findings related to an inappropriate policy for use of automation and another related to absence of a mandatory go‑around requirement for unstabilised approaches. Another finding related to the absence of a documented procedure for radio altimeter alerts.

Surveillance audits carried out by CASA are detailed in a following section.

Operations manual guidance

Regulatory guidance for operations manuals

The Civil Aviation Safety Authority was empowered to provide directions as to operations manual content and provided guidance to industry in the form of civil aviation advisory publication (CAAP) 215-1, as revised. Operators were required to ensure that operations manuals contained the necessary information, procedures, and instructions for safe conduct of operations. This included provision of standard operating procedures (SOPs) and a framework for training and checking.

For each section of a manual, CASA set out a typical structure with headings to be addressed by the operator and explanations of the required information. Under the sub-heading of VFR flight at night, CASA noted that in conditions of no visual horizon or insufficient visual cues (ground lighting), aircraft should be equipped for instrument flight and flown by an IFR-qualified pilot.

In the approach and landing section, operators were advised to provide general approach and landing precautions, including stabilised approach criteria. Operators were then advised to set out the company policy and procedures relating to joining and flying in the circuit, airspeed and altitude limitations and operations with strong crosswinds.

Marine pilot transfer was listed as a special operation that required procedures and specifications in accordance with CAO 95.7.3. This was an exemption to allow single-engine helicopters to be engaged in charter at night for the purpose of transferring marine pilots, subject to equipment, crewing, and training conditions.

Guidance relating to training and checking was referenced to Civil Aviation Regulation (CAR) 217 and CASR Part 61 (for flying schools). Operators were required to describe the selection, recent experience and completion standards for training and checking personnel.

Regulator guidance and recommended practices for night VFR operations

As part of the transition to CASR Part 61 flight crew licencing, CASA published an advisory circular to provide advice and guidance to illustrate a means, but not necessarily the only means, of complying with the regulations related to the night VFR rating. The ATSB identified the following extracts that were relevant to this occurrence:

Night visual flight rules (NVFR)

CASA strongly recommends that NVFR operations take place only in conditions that allow the pilot to discern a natural visual horizon or where the external environment has sufficient cues for the pilot to continually determine the pitch and roll attitude of the aircraft.

Even if visual reference is available at night, it can often be misleading and can further disorient a pilot attempting to fly visually. Integrating visual and basic instrument flying is essential when flying at night under VFR.

Aeronautical and underpinning knowledge - Instrument flying

Night operations require proficiency in instrument flight (IF).

Instrument flying skills are intrinsic to night flying; therefore, it is also desirable that IF proficiency be demonstrated before commencing actual night flying.

Hazards and risks

The ability to discern objects and terrain, together with their availability, is referred to as the ‘visual cueing environment’ and is related to the amount of natural and manmade lighting available, and the contrast, reflectivity, and texture of surface terrain and obstruction features.

A degraded visual cueing environment exists when high visual cueing conditions are not present (i.e. in conditions where the ability to discern objects and terrain is compromised).

Operations in a degraded visual cueing environment result in a perceived degradation in the effective rotorcraft handling qualities. The degraded handling qualities result in a substantial increase in pilot workload just to control the rotorcraft, leaving little excess workload capacity to maintain adequate situational awareness. This workload can easily exceed 100 percent of the pilot’s capacity, a situation which significantly increases the probability of a serious error.

In order to conduct operations safely and legally at night in a rotorcraft, the visual cueing environment must be accounted for in the planning and execution of NVFR rotorcraft operations.

The primary defence against sensory illusions during instrument flight in an aeroplane is to ignore the physical sensations and to maintain orientation by reference to the flight instruments. Attempting to use external visual reference at night can cause further confusion. Correct instrument scanning technique uses the flight attitude indicator (i.e. artificial horizon) in place of the natural horizon as the primary source of attitude information. Performance instruments, air-speed indicator (ASI), altimeter (ALT) indicator and vertical speed indicator (VSI) are used to confirm that the attitude being maintained is providing the desired aircraft performance.

Controlled flight into terrain is the result of a loss of situational awareness and is a significant problem worldwide both in NVFR and IFR operations. The common factor in this type of accident is that, due to the pilot's lack of awareness of either the horizontal or the vertical position of the aircraft, it is flown into the ground or water under full control.

The advisory circular also addressed threat and error management (TEM), risk management, human fatigue, situational awareness, task management, and decision-making.

Non-regulatory guidance – Flight Safety Foundation

Introduction

The Flight Safety Foundation produced BARS documents that specified a framework of safety performance goals necessary to assure safe offshore helicopter operations. This framework supplemented national and international regulations and was applied to contract specifications. The following standards have been extracted from the documents issued in May 2021, and slightly edited.

This information has been included to present industry best practice at the time of writing the investigation report for comparative analysis and safety education purposes.

Competency

To ensure safety critical personnel are competent to fulfill their duties by having appropriate training, qualifications, knowledge, skill and experience:

The aircraft operator must have an appropriate procedure for the initial selection of flight crew that considers aptitude and compatibility.

Where agreed by the company, the aircraft operator may use Competency Based Training in lieu of minimum experience requirements if the training program has been evaluated and meets the requirements of Flight Safety Foundation Offshore Safety Performance Requirements Flight Crew Competency Based Training Framework.

Flight crew must receive annual training to the standards of the responsible regulatory authority with two flight checks annually (or every six months for long term contracted operations). The flight checks must include an annual instrument rating renewal (where applicable), proficiency or base check (non-revenue) and a route check (revenue-flight permissible).

Flight crew members are to conduct training in suitable Flight Simulation Training Devices (FSTD) every 6 months.

Before commencing flight duties in a new location on long-term contract, all flight crew must receive a documented line check that includes orientation of local procedures and environment when these differ from their previous operating location.

Check and training procedures should include the syllabuses and procedures for initial training and approval and the processes for conducting periodic training, evaluation and ongoing standardization of check and training personnel, supported by appropriate training records.

Continuous monitoring of stabilized criteria should be required during all approaches.

Flight path management

To ensure a safe flight path with early identification of deviations and timely corrective action:

Aircraft operators must define procedures for critical phases of flight operations (inclusive of taxi, takeoff, cruise, approach and landing). This must include applying stabilized approach procedures that consider energy state for all flights. Aircraft operators must include no-fault, mandatory go-around requirements in the operations manual.

The Aircraft operator should conduct a gap analysis between its procedures and each revision of the HeliOffshore Flightpath management [recommended practice], identifying and justifying any differences to the [recommended practice].

Aircraft operators are encouraged to develop and implement a policy for mandatory, internal reporting of occurrences involving aircraft destabilization and any go-around. Tracking of such reports, alongside FDM analysis, within the aircraft operator’s SMS will assist with the identification of possible specific risks or considerations that may exist in the conduct of approaches.

Information from the HeliOffshore Flightpath management [recommended practice] is presented in the next section.

Effective use of automation

To ensure the maintenance of controlled flight:

An autopilot or automatic flight control system must be fitted. This must be a four-axis system for multi-engine helicopters unless risk assessed and endorsed by a competent aviation specialist.

The aircraft operator must have an automation policy that ensures the appropriate use of automation to reduce cockpit workload. Specific consideration should be given to automation training requirements to ensure all protection modes are fully understood.

Surface/obstacle conflict

To prevent an airworthy helicopter in the control of flight crew flying into the ground (or water):

All offshore helicopters must be equipped with at least one radio altimeter (RADALT) with dual displays (including analogue indication), with a visual alert and automated voice alerting device (AVAD) capability. The aircraft operator must have procedures for any user adjustable AVAD features and for actions to be taken by the flight crew in the event of an alert.

Non-regulatory guidance – HeliOffshore

Flightpath management

HeliOffshore is a global association of the offshore helicopter industry and a forum for expert collaboration about safety. One of their publications is Flightpath Management (FPM) Recommended Practice for Oil and Gas Passenger Transport Operations (Version 2). The FPM guidance is intended to eliminate offshore helicopter approach incidents by expanding on the airline industry’s adoption of stabilised approach principles. The content in this section is adapted from the FPM and has been included to present industry best practice at the time of writing the investigation report for comparative analysis and safety education purposes.

The recommended practice incorporates the key elements considered fundamental for stabilised helicopter approaches, including energy state, monitoring procedures, and use of automation.

The guidance notes that the use of standard repeatable approach profiles enhances the ability of crews to monitor and detect deviations. Three examples of standardised offshore approaches (when established on the final approach track) were provided:

  1. A defined 5° profile from 500 ft circuit height to landing decision point (typically 40 ft above deck height) with simple distance-height calculations at 0.2 NM/100 ft increments (Figure 18)
  2. Stabilisation criteria for 0.5 NM (926 m) from destination then up to committal point with crew call-outs
  3. A fully coupled approach at a consistent approach speed to 300 ft, maintained while reducing speed by selection of a suitable nose up attitude. Stabilised point was 0.5 NM (926 m), with further descent initiated when the final descent profile was intercepted (Figure 19).

Figure 18: Example 1, defined 5° profile

Figure 18.jpeg

Source: HeliOffshore, Flightpath Management (FPM) Recommended Practice for Oil and Gas Passenger transport Operations, Version 2.0. September 2020

Figure 19: Example 3, day DVE (degraded visual (cueing) environment) or night offshore approach

Figure 19.jpeg

Source: HeliOffshore, Flightpath Management (FPM) Recommended Practice for Oil and Gas Passenger transport Operations, Version 2.0. September 2020

In day visual meteorological conditions (VMC, see the following section), any of the above approaches can be flown with primary reference to a standard ‘sight picture’. However, offshore approaches at night or in a day DVE may require a more formalised structure of gates and checkable parameters. Operators were advised to consider 0.5 NM (926 m) as the stabilised gate for an offshore approach and to define criteria that required a go-around if the approach became unstable between the gate and committal point. As this was a relatively high-risk phase, continuous monitoring of energy state parameters - power setting, airspeed, and rate of descent – with standardised call-outs for multi-crew operations was necessary.

HeliOffshore considered that crews have a strong tendency to continue approaches despite deviations, and missed approaches are often mismanaged. In that context, operations manuals should have clear simple guidance on how to conduct go-arounds. This should be supported by training, so crews are prepared to apply take-off power, adjust pitch to accelerate to VTOSS[43] then VY,[44] and track to avoid obstacles. As flight in instrument meteorological conditions (IMC) can be more difficult at low airspeeds, training for these conditions with consideration of automation is good practice.

The guidance for monitoring procedures related to the use of detailed briefings and standard call‑outs in a multi-crew environment. An approach briefing was recommended for every landing to address the details of the approach and management of the helicopter. A discussion of the possibilities that may lead to a go-around and briefing of the procedure was recommended. Pilots were advised to make deviation calls as soon as one was observed, and all such calls should be acknowledged and acted upon immediately.

Safe and effective use of automation is an important principle. For offshore approaches at night or in a DVE, a straight-in approach and landing is preferred. If a circling approach is unavoidable, it shall be flown coupled in 4-axes/3-cue automation with the pilot adjusting ALT, HDG and IAS through beep trims while maintaining visual cues until the committal point. The use of automation should be integrated in the specified approach profiles.

As previously outlined, the autopilot/AFCS in VH-ZGA was designed for 3-axis function above 60 kt and was not approved for operations below 500 ft AGL. While, the autopilot could be used for the downwind and base phases of circling, it was not recommended for a constant-angle decelerating final approach from 500 ft.

Stabilised approach guidance

In accordance with revisions to legacy guidance, the last suitable point to ensure that final landing configuration was selected and verified was 1,000 ft AGL. From that point, the helicopter should be transitioned to the specified speed and power settings to be stabilised by 500 ft. Although 500 ft was a suitable point to verify stable approach criteria, a go-around was not mandatory if the helicopter was not yet stable when attaining this altitude.

For offshore approaches, the final gate was defined as 0.5 NM (926 m) from the installation or 300 ft above the landing site elevation. The approach criteria should be checked just before reaching the gate and if identified as ‘stabilised’ the approach could continue. If the helicopter was ‘Not stabilised’ by this point (or later became unstable), the response was to ‘go-around’ immediately.

An approach was considered stabilised when the following conditions existed:

  • the helicopter was in the correct landing configuration
  • the helicopter was on the correct flight path within tolerances that could be maintained using angles of bank and rates of descent within stabilised limits
  • airspeed was fixed for an instrument approach or appropriate to the distance to go for visual approaches
  • rate of descent was no greater than 700 ft/min
  • steady power setting relative to conditions
  • bank angle variation was less than 20°
  • within navigational tolerances for an instrument approach.

Regulatory framework for night operations

General conditions

In Australia, night flying could be conducted under the night visual flight rules (night VFR) or instrument flight rules (IFR). Some operators conducting specialised operations also had approval to utilise night vision imaging systems (NVIS) for enhancement of pilot vision at night.

To operate a helicopter under the night VFR in uncontrolled airspace, the following conditions applied:

  • visual meteorological conditions (VMC) – flight visibility of 5,000 m or greater and clear of cloud (below 3,000 ft above mean sea level)
  • when at or below 2,000 ft above the ground or water, navigation by reference to ground or water
  • forecast conditions indicate that the flight can be conducted in VMC at not less than the lowest safe altitude (LSALT) - defined as 1,000 ft above the highest obstacle within 10 NM (19 km) either side of the planned track
  • provision for an alternate aerodrome or helicopter landing site if:
  • more than scattered cloud below 1,500 ft and visibility less than 8 km was forecast for the destination
  • approved navigation not available.

On arrival, descent below the LSALT was permitted when the aircraft was established within 3 NM (5.5 km) of the destination and the approach for a landing was predicated on visual manoeuvring in continuous VMC.

Pilot qualification and experience requirements

To operate a flight under the night VFR, the pilot is required to hold a night VFR rating. This is granted when a pilot meets the following requirements:

  • holds a private, commercial or air transport pilot licence
  • meets the requirements for granting of at least one night-VFR endorsement
  • records 10 hours of aeronautical experience at night in an aircraft or approved flight simulation training device (including 5 hours dual cross-country flight time at night under the VFR in an aircraft)
  • passes the night-VFR flight test.

The requirements for a helicopter night VFR endorsement were similar to the associated rating and specified 3 hours of dual flight, 1 hour of solo night circuits, and at least 3 hours of dual instrument time.

A flight test for a night VFR rating included an approach and landing at an aerodrome remote from ground lighting and a go-around procedure. In addition, the candidate was required to perform instrument flying in full panel and limited panel configurations, including recovery from 2 different unusual attitudes in either configuration.

The holder of a night VFR rating was authorised to conduct a flight under the VFR at night if the following recency conditions were satisfied:

  • successful completion of an applicable flight review, flight test, or operator proficiency check in applicable aircraft within the previous 24 months
  • one take-off and landing at night or competency assessment in previous 6 months
  • if flight involves carriage of passengers – 3 take-offs and landings in applicable aircraft with previous 90 days.

Night flying competency standards

The competency standards for night VFR ratings were specified in the CASR Part 61 manual of standards. These included instrument flying, visual approaches, and go‑arounds (missed approaches).

A night VFR rated pilot required the skills and knowledge to perform normal flight manoeuvres and recover from unusual attitudes with reference to both full and limited instrument panels. Essentially, pilots were required to apply their knowledge of scan techniques and attitude/power requirements to interpret the instruments and carry out various normal manoeuvres such as descending and turning. For full instrument panel manoeuvres, pilots were expected to achieve, and maintain, a specified flight path while operating within defined flight tolerances.

Limited instrument panel manoeuvres were defined as non-normal situations without reference to the primary attitude indicator/display, the primary heading indicator/display, or reliable airspeed indications. In those cases, pilots were expected to use secondary (standby) instruments to carry out normal manoeuvres to achieve the nominated performance.

Recovery from upset and unusual attitudes in simulated IMC was a requirement with a full instrument panel and a limited instrument panel. Unusual attitude training and assessment conducted in aircraft was limited to daylight conditions for safety reasons.

A visual approach in the night VFR context was primarily the conduct of a traffic pattern around a runway for a landing. The circuit entry and pattern were required to be performed visually with reference to the runway environment and a safe altitude maintained by reference to aircraft instruments and runway lighting. Helicopter operation was specifically addressed in relation to take-off only.

The night VFR competency standards included the conduct of an approach and landing at an aerodrome remote from extensive ground lighting.

Discontinuation of an approach in the night VFR context was known as a go-around and in the instrument rating context as a missed approach. During a visual approach at night, the pilot was required to recognise the need for a go-around and to conduct it from any point on base and final approach legs.

Flight review

An applicant for a night VFR rating flight review is required to demonstrate relevant knowledge, including the use of instrument systems and operations below lowest safe altitude. For the flight assessment, the applicant was required to conduct an operation at night under the VFR and perform manoeuvres within specified tolerances. At a professional level, the general helicopter tolerances for altitude was +/- 100 ft and for airspeed was +/- 5 kt.

The practical flight standards referenced the competency standards as described in the previous section and specified that some elements were not required for a flight review. These non‑required items included operations to an aerodrome remote from ground lighting and engine failure after take-off. Some other elements such as flight planning and ‘manage hazardous weather conditions’ were not required if addressed in a flight review within the previous 24 months.

Helicopter equipment requirements

At the time of the occurrence, CASA specified the minimum equipment requirements for helicopters in CAO 20.18. The instruments required for night VFR included the basic VFR flight instruments plus an attitude indicator (with redundancy), heading indicator, and vertical speed indicator. For operations onto vessels or platforms at sea by night, an instantaneous vertical speed indicator was also required.

If a night VFR flight involved flights over land or water where the helicopter attitude could not be maintained by use of visual external surface cues (such as ground or celestial lighting), an approved autopilot system/stabilisation system or a qualified 2-pilot crew was required. For all IFR operations, an approved autopilot system/stabilisation system was required.

At the time of the occurrence, there were no requirements for helicopters to be equipped with an EGPWS or HTAWS.

Revised regulatory framework for marine pilot transfer (night operations)

From December 2021, MPT operations were authorised under a CASR Part 138 aerial work certificate and conducted under the general operating and flight rules contained in CASR Part 91, with addition or variation of those rules according to Part 138.

For night VFR operations under CASR Part 91, the general conditions such as VMC, navigation, and minimum altitude requirements remained the same as the previous regulations. The pilot qualification and experience requirements for a night VFR rating (CASR Part 61) also remained unchanged.

CASR Part 91 and Part 138 stated that any required equipment must be visible, and usable, from the pilot’s seat. The equipment requirements for rotorcraft night VFR and IFR were essentially the same as those specified in CAO 20.18. This included an ongoing requirement for an autopilot/stabilisation system for all IFR or single-pilot night VFR in conditions where the attitude could not be maintained by use of visual external cues (ground lighting and/or celestial illumination).

All operators conducting aerial work under CASR Part 138 were required to manage crew fatigue in accordance with existing rules and conduct risk assessment and mitigation processes. An operator who conducted MPT flights was also required to have a training and checking system and safety management system if currently required or according to deferral criteria.

The holder of a CASR Part 138 aerial work certificate could carry 1 or 2 passengers on VFR flights at night in multi-engine rotorcraft such as the EC135 type, subject to certain conditions. Carriage of 3 to 9 aerial work passengers in VFR flights at night was conditional on the use of multi-engine rotorcraft with equipment for flight under the IFR and/or in an approved NVIS operation. If marine pilots were winched to and from ships at night, the pilot in command was required to use NVIS for the operation.

An EGPWS or HTAWS was not required for CASR Part 138 aerial work operations.

Operator’s standard operating procedures

Introduction

As an AOC holder, the operator produced an operations manual to promulgate general policy and standardised procedures for EC135 MPT flights from bases at Gladstone, Mackay (Hay Point), and Port Hedland. The version of the operations manual current at the time of the accident was issued by the operator on 28 February 2018.

For operations to ships at sea, the operator specified requirements for flight planning, helicopter performance, shipboard landing areas, with instructions for various phases of an MPT flight. The standard operating procedures (SOPs) relevant to the occurrence are addressed in the following section.

The operator referred pilots to the respective Aircraft Handbook and Approved Flight Manuals for normal and emergency procedures. If any procedures required clarification these were addressed in the operations manual.

Circuit, approach, and landing procedures

Ships were generally underway when helicopter landings and take-offs occurred and there were no guidance systems to assist the helicopter pilots make their approaches to the ship. As such, pilots were required to descend, approach and land in visual meteorological conditions.

The SOPs for day and night approaches to ships at sea were essentially the same and both were conducted as visual manoeuvres. The following extract from the operations manual pertained to offshore night approaches:

Once the ship has been identified and the aircraft is established within the circling area, an approach may be commenced.

An approach to the ship will be made using normal circuit flying techniques (downwind 700 ft at 70‑80 kts). Aim to roll out on ‘final’ - with a headwind component at 500 ft AMSL with a 60 kt ground speed, and so as to position the ship upwind and within a sector 30°–45° degrees either side of the aircraft (the final ‘window’), so a normal (7°) approach sight picture is obtained.

For the EC135 type specifically:

Position the helicopter at a finals ‘gate’ of 500 ft above the landing site at 65 kt.

From this position, carry out a constant angle reducing speed sight picture approach to an [out of ground effect] hover position abeam the ship.

The extract pertaining to offshore night approaches continued:

In the event that visual reference with the ship is lost during the approach, the aircraft shall be established in the climb and a go-around within the circling area to LSALT/MSA initiated. The aircraft should be navigated so as to remain clear of other ships. Once at LSALT/MSA and visual reference has been re-established, an approach may be recommenced.

Further instructions were provided for the downwind, base, and final segments of the circuit without differentiating between day and night operations:

Downwind is to be flown at 700 ft AMSL and 70/80 kt. Judicious use of the aircraft’s navigational instruments should be employed to help maintain situation awareness. For example, the OBS/CDI in combination with the HDG bug may be particularly useful for circuit orientation.

On the base leg descent from downwind altitude to the final gate altitude of 500 ft should be achieved. The aircraft should be turned so as to position the ship in the final ‘window’. Descent below 500 ft should not commence until the aircraft is established into wind and aligned on the final approach path. In two-pilot operations, the pilot not flying was to assist the pilot flying.

Aim to roll out on ‘final’ with a headwind component at 500 ft AMSL with a 60 kt ground speed. On achieving the final ‘gate’, a constant angle approach is made to the over water termination area or FATO. The pilot is to ensure that the aircraft’s radar is in standby mode, the landing light is switched on and the floats are armed.

The operator also provided the following general advice for pilots conducting approaches to ships:

Turns below 500 ft AGL are not permitted while the pilot flying (PF) is controlling the aircraft by reference to flight instruments.

The chief pilot advised that circuit procedures for MPT operations were developed from past practice and the 700 ft circuit height provided a terrain clearance buffer at one of the locations. For operations at Port Hedland, the chief pilot had no objection to a local practice that abbreviated the circuit pattern (such as straight-in approach) according to the inbound track and final approach alignment based on relative wind at the ship.

Ship night approach and landing

The chief pilot advised that ship night approaches and landing were challenging and prospective MPT pilots required training to develop their judgement of descent profiles. Once pilots were established on the final approach track (not below 500 ft or above 60 kt groundspeed), they were expected to commence a descent according to the guidelines summarised in Table 9.

Table 9: Nominal descent parameters on final approach

AltitudeGroundspeedRate of descent
500 ft60 kt reducing500 ft/min
400 ft40 kt400 ft/min
300 ft30 kt300 ft/min
200 ft20 ktReducing
100 ftReducingReducing

The chief pilot advised that the approach angle gradually steepened so that at 300 ft the helicopter was basically beside the ship and the helipad was visible in the chin bubble (lower window). From 300 ft, indicated by the radio altimeter, the pilot would generally be committed to carry out the landing. The EC135 could be operated with assured one engine inoperative performance that allowed a go-around in almost all phases.

For night approaches where there was no moon and no local illumination (black-hole approach), the chief pilot expected MPT pilots to maintain a continuous scan pattern of ‘airspeed/height/rate of descent/ship’ to ensure that all of the parameters were reducing. The chief pilot stated that, in general, it was better to be slower rather than faster to avoid a flare that could result in an overshoot. However, there had been occasions during training when pilots had been affected by night visual illusions and slowed the helicopter to no forward speed while still descending.

Stabilised approach criteria

Under the operations manual heading of ‘Stabilised approach criteria’, the operator specified the following:

(a) Broadcast your intentions on the appropriate frequency;

(b) Complete the downwind checks …;

(c) A normal sight picture to the landing area shall be established below 500 ft;

(d) The approach shall be stabilised below 300 feet with a decelerating disc attitude and airspeed …;

(e) The PIC shall ensure that obstacle clearance is maintained and compliance with CASR’s in relation to occupied buildings;

(f) A lookout shall be maintained throughout the approach;

(g) Curved approaches are permitted, however all approaches shall be terminated with a headwind component.

In the context of final approach in day or night conditions, the operator provided the following guidance for offshore operations:

When airspeed is below 30 kt, rates of descent in excess of:

(a) 500 ft/min should be avoided; and

(b) If a 700 [ft]/min (or higher) ROD should occur, a go-around should be conducted.

No guidance was provided for airspeeds above 30 kt or other parameters such as bank angle, pitch angle or engine torque. The chief pilot advised that pilots were expected to go-around when a landing was not feasible. In most cases pilots could recover from a below-profile approach but a go-around was necessary when high and close to the ship.

Missed approach/go-around

In the context of offshore operations, the operator provided the following guidelines for missed approaches:

Circumstances may arise in which an approach must be discontinued. In these circumstances, either pilot may call “Missed Approach” and issue the following instructions to the PF:

“Pull in climb/cruise power”

“Establish positive ROC”

“Maintain Vy until above 500 ft”

“At 500 ft adjust attitude for 80 knots”

“Level out at LSALT”.

The PF will then re-adjust for climb power and speed and fly the missed approach procedure. The PIC will re-assess the next approach.

If at any stage there is a requirement for the pilot in command to take over the controls, he/she will call “taking over” and the co-pilot will confirm “handing over”. The pilot in command will take control of the aircraft.

Use of automation

The operator specified that the EC135 flight director or upper modes of the 3-axis autopilot may be engaged at the pilot’s discretion after take-off above 500 ft AGL. No guidance regarding use of the autopilot in the circuit was provided in the operations manual.

The chief pilot advised the ATSB that for MPT operations in degraded visual environments, including at night, pilots were trained to use the upper modes of the autopilot until established on final approach at 500 ft and not below 60 kt. The autopilot interface was considered easy to use and capable of reducing pilot workload. From the chief pilot’s perspective, unless large and rapid flight path changes were required, there was higher risk and no benefit when operating without the autopilot (above 500 ft) in degraded visual cueing environments.

For manoeuvring in a normal circuit, the chief pilot expected pilots to use the beep trim as the primary means to command the autopilot. The use of force trim release was usually limited to momentary activation to quickly reset trim references. Based on initial and recurrent training and assessing conducted by the chief pilot, pilots were using the automation to manage the flight path without difficulty.

The instructor advised that, in general, ‘the autopilot needs to be on from 500 ft after take-off to 700 ft established in final approach’ and they were ‘very strict on use of the autopilot, especially in low visibility conditions’. However, the instructor also advised that, in benign conditions, if pilots chose to select the ‘autopilot off as they got to the circuit area, that’s a decision that they would make but would be accountable for.’

Night VFR

The operations manual specified that the pilot in command of a company helicopter operating under the night VFR shall hold a current night VFR rating and meet the standard recency requirements. This comprised 3 circuits or a flight test at night within the previous 90 days.

There was no other substantive content applicable to MPT operations at night.

Two-pilot operation

The occurrence flight was conducted as a single-pilot operation under supervision of a second pilot. Extracts of the operator’s SOPs for 2-pilot operations are provided for comparison and reference.

For operations that required 2 pilots, the operator specified roles, coordination protocols, and deviation criteria. One of the pilots operated as the flying pilot (FP) to manipulate the controls or manage the autopilot while the other pilot was the non-flying pilot (NFP). The NFP was required to assist the FP in any way necessary to allow the FP to concentrate on physically flying the helicopter.

At any stage of the flight if the FP failed to maintain control of the helicopter within accepted tolerances the NFP was required to bring the deviation to the attention of the FP. If corrective action was not initiated by the third call, the NFP was to take over control saying, ‘Taking Over’ and the other pilot would then relinquish control saying ‘Handing Over’.

In the context of offshore operations, on downwind the NFP should at all times maintain visual reference with the ship and should assist the FP by calling out any required HDG or speed changes. Then, on base, the NFP was to assist the FP by calling out the required final HDG. During final approach, the NFP was to concentrate on the helicopter’s instruments and call out airspeed, altitude, and vertical speed.

The operator specified significant deviation call outs during flight in IMC including the following:

  • IAS +/- 10 KIAS
  • altitude +/- 100 ft (+50 ft, -0 ft on final)
  • rate of descent greater than 1,000 ft/min on final approach.
Absent procedures

Without implying any non-conformance, the ATSB noted that the operator did not specifically address the following topics in the operations manual:

  • operations in degraded visual cueing environments
  • use of radio altimeter
  • unusual attitudes/energy states
  • spatial disorientation
  • controlled flight into terrain (CFIT)/Approach and landing accident reduction (ALAR) considerations.

The chief pilot advised that the risk of operating in degraded visual environments at night was controlled by the VMC requirements, use of automation, and application of instrument flying skills. Pilots were also trained to set the radio altimeter warning to 300 ft for approaches to ships. As these controls applied to all operations at night in VMC, there was no specific reference to degraded visual cueing environments in the operations manual.

The chief pilot also considered that the identification of, and recovery from, unusual attitudes was part of CASR Part 61 training and assessment and was therefore not addressed in the operations manual. Spatial disorientation and CFIT/ALAR were addressed in periodic online training provided by the operator.

Operator pilot training and assessing

Overview of pilot competency requirements

As the holder of a certificate that authorised charter and aerial work operations, the operator was subject to a number of general conditions. Some of these related to establishing and maintaining the competence of flight crew.

The operator provided charter and aerial work services and was not required to provide a CASA‑approved training and checking organisation. Nevertheless, CAO 82.0 and CAO 82.1 imposed obligations on the operator in relation to the competence of flight crew.

Before a pilot could operate a helicopter type and model, there was a requirement for the chief pilot to be satisfied that the pilot was competent to operate in accordance with the specific instructions provided in the operations manual and pilot operating handbook or AFM. Stated CAO 82.0 responsibilities of a chief pilot included monitoring operational standards, maintaining training records and supervising the training and checking of flight crew. A chief pilot was not allowed to delegate training and checking duties without the written approval of CASA.

Additional requirements applied to operators that conducted training and assessment related to licences, ratings, and endorsements issued in accordance with CASR Part 61. For flight training up to commercial pilot level (other than integrated training), an approval in accordance with CASR Part 141 was required. For other types of flight training, such as granting of a type rating, an approval in accordance with CASR Part 141 or 142 was required.

Management of line pilot competence

The operator specified training and checking requirements to ensure that company pilots met and maintained a high standard of knowledge and expertise in the overall operation of company operated helicopters. These specifications in part 4 of the operations manual were intended to satisfy the regulatory and corporate requirement to carry out internal operational checking of pilots within the guidelines of CAO 82.0. Extracts from Part 4 of the operations manual included:

Duties and responsibilities

The chief pilot is responsible to higher management to ensure appropriate training and checking procedures are in place.

As authorised by CAO 82.0 Appendix 1 the Chief Pilot is responsible for: …

Ensuring that all Company employed pilots undergo training and checking at intervals not exceeding 12 months;

The training and checking requirements are to be used to induct pilots for Company operations.

Selection and experience requirements for training and checking personnel

Training and checking personnel will be selected and approved by the Chief Pilot after consultation with the General Manager.

The Chief Pilot shall ensure that any instructor designated for training and checking duties has the appropriate operational experience, endorsements (including winch and sling) and ratings prior to being approved for training and checking duties.

Training and Checking duties on Company helicopters, both multi-engine and single engine, for pilots involved in MPT operations, may only be conducted by Check Pilots who have received the specific approval of the Chief Pilot. These pilots shall hold a current instructor rating with multi-engine training approval as well as a current command instrument rating.

Training and approval of training and checking personnel

Additional training for qualified instructors approved after selection should not be necessary.

The Chief Pilot or his/her delegate shall conduct the routine Base and Line Checks on all Company approved training and checking pilots conducting multi-engine or MPT operations.

Induction and training requirements

A pilot on joining the Company, will be briefed by the Chief Pilot on Company operating and administrative procedures. The pilot shall also be checked on the type/types of aircraft he/she will be rostered to fly.

All pilots employed by the Company will undergo air training or flight evaluation prior to commencing normal line operations.

Training syllabi and checking programs

Training Syllabi are located in “Air Maestro”[45]at the Forms Register under the control of the Chief Pilot.

All company pilots are to undergo two proficiency checks in each calendar year. The two checks shall be:

(a) Base check which may include the renewal of a Command Instrument rating, and

(b) Line check.

The base check will be directed to basic flying skills, aircraft handling, knowledge, and practice of emergency procedures.

The line check will be a normal revenue flight of at least two sectors, one of which should be at night if the pilot’s duties include night operations. The Initial Line Check shall be completed at the conclusion of ICUS (in command under supervision) flying.

Ship operational training

Multi-engine helicopters by day: Ten ICUS landing and take-offs

Multi-engine helicopters by night: Ten ICUS landing and take-offs

Demonstrate competence in all aspects of offshore operations to the satisfaction of the Chief Pilot or his/her delegate or an approved Check Pilot.

The forms in Air Maestro listed criteria for different phases of flight with provision to record the applicable assessment and comments.

The chief pilot, who did not hold an instructor rating, advised that the qualifications, experience, and approvals of the head of operations (as defined in CASR Part 141/142) and other instructors was considered to be suitable for the conduct of operator-specific training and assessing.

Flight training and assessment activity

From 1 November 2017, the operator held authorisations to conduct flight training in accordance with CASR Part 141/142 and the CASA-approved exposition,[46]This included flight training for night VFR ratings, instrument ratings, and EC135 type ratings.

In a parallel structure to the charter/airwork operation, the instructor in this occurrence was the head of operations (HOO) for the CASR Part 141/142 organisation and reported to the chief executive officer. Any flight instructors and examiners operating under the approvals reported to the HOO. The chief pilot was nominated as the operations officer to liaise with the HOO for rostering of instructors, helicopter allocation, and program changes.

To ensure that standardised training was delivered safely by competent and qualified instructors, the HOO managed an internal training and checking system. This system provided for annual refresher training for human factors/non-technical skills (HF/NTS) training and annual standardisation and proficiency (S&P) checking.

The S&P checks included a review of each instructor’s competency to deliver long and pre-flight briefings and flight instruction in accordance with the applicable syllabus and lesson plans. Between CASR Part 141/142 approval and the occurrence, the instructor conducted S&P checks on a line pilot/instructor and an external flight instructor/examiner. There was no record of the instructor undergoing a S&P check in the previous 12 months.

According to the pilot’s logbook, the last instructor standardisation check was carried out by an external instructor on behalf of the contracted flying school on 6 March 2017. This expired on 6 March 2018, 8 days before the occurrence. The last standardisation check was carried out in an EC135 equipped with dual flight instruments.

A key function of the CASR Part 141/142 organisation was to conduct flight reviews and proficiency checks with company pilots for maintenance of their Part 61 licences and ratings. For that function, reference was made to the CASR Part 61 manual of standards. There was no reference to base or line training/checks in the Part 141/142 exposition.

Summary observations

Although the CAO 82.0/82.1 and CASR Part 141/142 processes operated in parallel with different functions and accountabilities, in practice the chief pilot relied on the HOO and other instructors from the CASR Part 141/142 organisation to carry out type-specific base checks and some line training/checks.

Outside of CAR 217, there were no standards or guidance in support of the requirements for the chief pilot to be satisfied that the pilot was competent and for monitoring of operational standards. In the absence of training and checking system requirements, the operator mimicked aspects of CAR 217 and CAO 82.1 manual requirements without addressing training schedules, management of ICUS, or instructor competency in relation to supervision of MPT operations.

Although it was just over 12 months since the instructor’s last recorded S&P check (required annually), that check was oriented to generic CASR Part 61 requirements and was not considered to be significant.

To differentiate the operator’s management of pilot competence from a CAR 217 training and checking system, the term ‘training/assessing’ is used throughout the report.

Preliminary activities at Port Hedland in March 2018

Based on the arrival date at Port Hedland following initial training at the operator’s Mackay base, 10 consecutive days were available to complete the pilot under supervision’s operational EC135 training followed by a couple of non-rostered days. From that point (21 March), the pilot under supervision was rostered for day and night MPT operations for the balance of the 3‑week roster cycle.

The instructor travelled to Port Hedland on 5 March 2018 to conduct scheduled flight reviews and proficiency checks with the established line pilots, along with operational induction of the pilot under supervision. Although the chief pilot had allowed nearly 3 weeks overall for the instructor to complete those tasks, the roster showed the instructor had leave scheduled for the weekend at the end of the second week. As the training and assessing progressed, the instructor discussed the possibility that if the tasks could be completed by the end of the second week, a return to Port Hedland after weekend leave would not be required.

On the first duty day at Port Hedland, the instructor utilised the operator’s flight training device at the heliport for 1.3 hours of instrument time that included various instrument approaches. Between 6 and 11 March, the instructor conducted various flight reviews and proficiency checks with 5 of the established line pilots.

One of the line pilots did not meet the requirements of a night VFR flight review conducted by the instructor on Saturday 10 March. In consultation with the chief pilot, that pilot was withdrawn from rostered night duties. To fill the resulting roster gap, the instructor was rostered for a day duty on Tuesday 13 March and the next vacant night duty starting on evening of Wednesday 14 March.

For the remainder of the day (10 March) and during the 2 following days the instructor supervised some local EC135 flying by the pilot under supervision. That included general familiarisation flying, a helicopter type flight review, and base check. No practice instrument or night flying was carried out during this pre-line training phase.

On the afternoon of Monday 12 March, the instructor emailed the chief pilot in Mackay, Queensland with a plan to complete training and checking commitments at Port Hedland by Friday morning. To accomplish this, the instructor intended to fly with the pilot under supervision in accordance with the following schedule:

  • Monday (12 March): completion of EC135 refresher training including base check and helicopter (EC135 type rating) flight review
  • Tuesday (13 March): normal day shift line operations including any remaining helicopter flight review items
  • Wednesday (14 March): night line operations on normal roster
  • Thursday (15 March): night line check and night flight review

The chief pilot replied shortly afterwards with affirmation of the plan.

Based on recent experience and flight reviews/checks with the previous operator, the pilot under supervision met the regulatory requirements for night VFR operations. The ATSB noted that the flying for the previous operator was carried out in single-engine B206L helicopters equipped with analogue instrumentation and was conducted with the assistance of night vision imaging systems. As the previous operator’s B206L helicopters were not equipped with an autopilot or stabilisation augmentation system, the flight path was managed directly through continuous pilot control inputs.

Line training – session 1

Consistent with the schedule advised by the instructor to the chief pilot on 12 March, line training for day operations started early on 13 March 2018 with flight to a ship with a landing and take-off, possibly demonstrated by the instructor. A further 8 landings to a mix of inbound and outbound ships were conducted by the pilot under supervision of the instructor.

As recorded by the instructor, the pilot under supervision improved significantly with practice to consistently operate to a ‘good solid standard’ and was competent and safe. The instructor considered that at that stage, the pilot under supervision ‘just needs practice doing the transfers so the process was more automatic.’ Total flight time was recorded as 6.4 hours and the pilots were on duty for about 14 hours.

Line training – session 2

The instructor and pilot under supervision were rostered for the normal night duty on 14 March 2018 to continue line training. Although night duty nominally started at 1800, the pilot under supervision was at the operator’s port facility at various times during the day to complete induction-related tasks. The pilot under supervision then returned to the port facility at about 1610 to prepare for the flights scheduled that evening followed by the instructor at about 1650.

Five transfer flights were scheduled for the shift: the first 2 with marine pilots to the pilot boarding ground then 3 to pick up marine pilots from outbound ships near C1/C2. The first flight departed at 1753 and returned to the heliport at 1813. This flight, in daylight, was counted as the tenth MPT operation for the pilot under supervision, who was assessed by the instructor as performing to a solid standard and was recommended for day VFR MPT approval.

The second flight of the shift departed the heliport at 1859 (about 15 minutes after last light) and returned to the heliport at 1924. Operator records indicated that, following this flight, the pilot under supervision fully refuelled the helicopter. The instructor recalled that the pilot under supervision also conducted a daily inspection on VH-ZGA, preparatory to certifying the daily inspection for the next day’s flying.

After completion of those activities, the instructor suggested the pilot under supervision return to the nearby accommodation for a break prior to the next flight. The instructor remained at the heliport, to complete administrative tasks.

The third flight departed the heliport at 2252 and picked up a marine pilot from an outbound ship near C1/C2. During the flight back to Port Hedland, another marine pilot scheduled to be picked up from the next bulk carrier radioed the crew of VH-ZGA and amended their pick-up time to 2345. Consequently, on arrival at Port Hedland at 2327, the marine pilot was disembarked with the engines running to enable a quick turnaround.

Flight data review

For context and comparative analysis, the ATSB obtained the automatic dependent surveillance broadcast (ADS-B) and automatic identification system (AIS) data for the line training flights preceding the occurrence flight. A preliminary review of the data for the 9 ship approaches during the day on 13 March 2018 and first flight (during daylight) on the accident day did not identify anything that was inconsistent with the instructor’s assessment.

Data for the second and third line training flights on 14 March, both conducted at night, is presented in graphical and tabular form at Appendix A.

Meteorological conditions for both flights were similar to the occurrence flight. Although the second flight (of the shift) departed about 15 minutes after last light, the transit, circuit and landing on the carrier was completed before nautical twilight. As such, some scattered and diminishing light might have been evident on the western horizon.

The second flight departed the heliport at 1859 to transfer a marine pilot to an inbound bulk carrier (Anangel Explorer) at the pilot boarding ground. The initial descent from cruise altitude appeared to have been initiated using an upper vertical navigation mode. However, as the descent continued and the helicopter approached to pass abeam the bulk carrier, the rate of descent increased above 1,000 ft/min before an abrupt transition to level the helicopter at 700 ft. The helicopter was then manoeuvred around the ship at about 700 ft until established on final approach about 1,700 m from the landing hatch at 55 kt. In general, the final approach was conducted at a consistent angle with steady deceleration and a rate of descent varying between 0–450 ft/min.

The third flight departed the heliport at 2252 and tracked to C1/C2 to pick up a marine pilot from an outbound bulk carrier (Cape Aster). Descent was conducted at about 500 ft/min and continued as the helicopter circled the ship until it was levelled at 550 ft. While the helicopter was turning onto final approach about 1,500 m from the landing hatch, it started descending again and the airspeed reduced through 60 kt. The descent and reduction in airspeed continued to about 275 ft at 38 kt, about 700 m from the landing hatch.

As the approach continued, the helicopter climbed to 375 ft, with airspeed reducing through 35 kt about 300 m from the ship. The helicopter then descended to 150 ft at up to 1,000 ft/min with airspeed reducing to 15 kt. This descent rate then reduced to 300 ft/min while maintaining about 15 kt. The helicopter landed on the bulk carrier at about 2307.

Summary observations
  • The pilot under supervision was involved in 10 MPT operations during daylight and was assessed by the instructor as competent.
  • The instructor transitioned the pilot under supervision from day to night line training without any further day flying or preparatory night or instrument flying.
  • The second flight of the shift, and first line training conducted at night, was to the pilot boarding ground. Although the transition to circuit height was abrupt, the base turn and final approach generally conformed to the operator’s procedures and parameters for ship approaches.
  • The third flight of the shift was to C1/C2. Circuit height and descent profile on final approach did not conform to the operator’s procedures and parameters for ship approaches. Additionally, the conduct of the 2 night circuits was not consistent with use of a vertical upper mode of the autopilot.

Fatigue risk management

Operator’s fatigue risk management system

The operator managed the risk of fatigue-related incidents and accidents using a fatigue risk management system (FRMS) as an alternative compliance method for the flight and duty limitations prescribed in CAO 48.1 (Flight time limitations – pilots). The use of the operator’s FRMS as a compliance method was based on a CASA-issued exemption under subsection 4 of CAO 48.0. The exemption was issued by CASA in September 2014 and, in April 2017, it was extended to 30 April 2018.[47] The conditions applicable to the exemption required the flight and duty limits to be included in the company operations manual. The exemption also required the operator and each flight crew member to comply with the fatigue limits specified in the FRMS manual. The change record in the FRMS manual showed no updates since April 2014.

The operator’s FRMS described a system of shared responsibility, with pilots required to ensure they had sufficient sleep and were not impaired by fatigue prior to commencing flying duties. A key component of the operator’s FRMS was the requirement for each pilot to maintain a sleep log, which tracked the extent to which their sleep and duty time was within specified limits (see below).

The FRMS also prescribed rostering rules including a maximum duty period of 12 hours, a maximum flying time of 10 consecutive hours, a maximum 4 consecutive night shifts, and a maximum 100 duty hours in a 14-day roster period. A duty period could be extended by the chief pilot if a task was underway, although that was limited to 1 hour for day VFR operations and 2 hours for 2-pilot crews.

As part of the FRMS, pilots received fatigue awareness training and training regarding the operation of the FRMS. The fatigue awareness training included a description of the causes of fatigue and advised that fatigue was very difficult to self-diagnose and could only be prevented by achieving sufficient sleep.

Roster pattern at Port Hedland

The roster for line pilots at Port Hedland included days that were allocated as duty, off duty or standby. The FRMS defined duty as any task that a pilot was ‘required to carry out associated with the business of the operator’. Off duty was defined as time ‘free of all duties associated with any type of employment’, and standby was defined as periods where a pilot was required to be available for a duty period.

The rosters for Port Hedland pilots typically followed a set pattern, beginning with travel to Port Hedland followed by a series of 4-day blocks comprising:

  • a day of standby
  • a day shift (0600–1800)
  • a night shift (1800–0600, commencing 24 hours after the end of the day shift)
  • a day off duty.

Pilots were rostered on for 3 weeks, in which they would normally have about 4 or 5 day shifts and 4 or 5 night shifts. Time during a day shift, night shift or standby period was only considered as duty time if the pilot conducted a flight duty or other task associated with their employment.

The operator’s FRMS was produced prior to the commencement of MPT work at Port Hedland, with the manual stating that all operations would normally be based in Mackay and Gladstone. The manual also showed rosters for IFR and day VFR operations that were conducted at those bases. These roster patterns involved 14-day periods containing blocks of 4.5 days continual 24‑hour standby for IFR pilots (commencing at 0600), and 5 days continual day shifts for VFR pilots (from 0600–1800).

The roster worked by the Port Hedland base pilots was not described in the FRMS manual. There were no updated fatigue management procedures for any of the operational differences between Port Hedland and the other bases. The operator had suitable air-conditioned rest facilities at its Port Hedland base where pilots could sleep during a day shift or night shift. In addition, the residential units generally used by the pilots were situated only a short distance from the operator’s facility at the port. Each pilot would typically have access to their own 2-bedroom unit during their tour.

The FRMS manual included a discussion of the assessment of risk associated with different types of tasks. For MPT tasks, there was a discussion of risk for IFR tasks (2 pilots at night, single pilot by day) and day VFR tasks (single pilot), but no discussion of single pilot night VFR tasks. In terms of IFR tasks, the manual stated:

The route is fixed and the location of the ship and the base are also fixed, the details of the ship (nationality, size, hatch number for landing and weather) are known and communication with the ship exists. The major risk may be fatigue impairment leading from consecutive night operations, particularly those flown between the times of 10 PM to 6 AM which conflict with the circadian rhythm. The task is assessed as an M category task [moderate risk] …

The company does not expect a Pilot to fly for more than four consecutive late night operations …

Sleep logs

Under the FRMS, pilots were required to obtain the sleep necessary for flight duties. The manual stated:

A flight crew member will require between 6 and 8 hours sleep per night to satisfy his needs. The exact amount of sleep is dependent on the individual’s physiology. While it is desirable that the flight crew member has had that sleep before undertaking duty he may undertake duty in accordance with the PSWR …

PSWR is a rule that sets out the minimum sleep requirements before any duty may be performed. Duty may be performed in accordance with this rule with less than the normal sleep for a forty eight hour period. The rule states that the amount of ‘useful wakefulness’ that occurs is equal to the amount of sleep in the preceding 24 hours and the 24 hours before that. The minimum sleep needed prior to starting duty in a twenty four hour period is 5 hours and in a forty eight hour period 12 hours ...

During night operations it is unlikely that flight crew will gain all their normal sleep-in daylight hours. Flight crew members should therefore consider extending their normal sleep in a duty period between the hours of 6 PM and 6 AM in one of the following ways. They should gain a duty-free period of four hours in which they have some sleep or alternatively a nap, preferably for up to two hours, while remaining on duty. It is up to the flight crew member to ensure that in a period of night duty he has the sleep required for the duty to be performed and if this does not occur, he is to inform the tasking officer.

Further information regarding the prior sleep wake rule (PSWR) and prior sleep wake model (PSWM) is provided in Appendix E.

Pilots recorded their hours of sleep and duty using a Microsoft Excel spreadsheet known as a ‘sleep log’. The sleep log was developed by a consultancy group and was programmed to identify fatigue risk based on the PSWR as well as the operator’s maximum duty period of 12 hours. Pilots coded each hour of every day (or each cell) as either sleep (S, coloured grey), duty (D, coloured light blue) or flying (F, coloured dark blue). Other time awake but not on duty or flying was left or recorded as blank (light yellow). A separate spreadsheet in the same Excel file also required pilots to record their actual flight and duty times after each shift.

The FRMS manual stated that the sleep logs should be ‘maintained in an up-to-date state on a daily basis’. It also stated:

The sleep to be recorded is any sleep. That means dozing for ten minutes to a sleep break of five hours. The period that is recorded is entirely up to you, for example if you wake up and make a toilet visit this period should not be detracted from the sleep period. On the other hand, if you are lying in bed with your eyes closed and your mind in neutral that should not be recorded as sleep …

The sleep log tool provided some additional guidance. It instructed pilots to record times as duty from ‘notice to move’ (for a flying task) until back in resting accommodation (after a flying task), and record flight times using the engine operating time from the helicopter flight log, rounded to the nearest full hour.

The sleep log pre-loaded the hours of 2200–0600 each day as sleep, and pilots had to overwrite these times if they intended to record them as awake (blank), duty or flying.

When data was being entered, the sleep log automatically highlighted cells in various colours if a relevant rule was breached. More specifically:

  • If a pilot recorded less than 5 hours sleep in the 24 hours prior, or less than 12 hours sleep in the previous 48 hours, cells would highlight red.
  • If a pilot recorded being awake for more than the sleep in the sum of the previous 24 hours and 48 hours, cells would highlight orange (see also later this section).
  • If a pilot recorded 9 or more hours consecutive duty, the 13th and subsequent hours after the start of the duty period would highlight yellow.[48]

Figure 20 shows 2 examples of simulated sleep and work information recorded in the sleep log. In the top image, the pilot recorded 4 hours sleep in the 24 hours to 0600 on 21 March, and 10 hours in the 48 hours to that time. As a result, all cells after 0600 highlighted red. In the bottom image, the addition of 1 hour sleep between 0600 and 0600 removed the red alerts, since the pilot now had recorded 5 hours sleep in the previous 24 hours.

Figure 20: Exemplar sleep log

Figure 20: Exemplar sleep log

Using simulated data, the ATSB observed that the sleep log tool was highly transparent and easy to modify. When entering sleep, duty and flying into the sleep logs, it was obvious when a rule had been breached or would be breached. Similarly, it was obvious what a pilot could do to change the recorded data to remove or prevent cells being highlighted.

The ATSB also determined that the rule embedded in the sleep log associated with extended wakefulness (and orange highlighting) contained a coding error; it counted both the sleep in the previous 24 hours and the total sleep in the previous 48 hours, and therefore it double-counted sleep in the period 25–48 hours prior to the relevant point in time. As a result, a pilot sleeping 8 hours a night would need to be awake for over 24 hours before this rule identified a fatigue risk, whereas the intended function of the rule was to identify fatigue risk after 16 hours. In other words, it was very unlikely that pilots could trigger an orange alert when entering in their normal range of sleep and other times.

Review of data in sleep logs

Sleep log information recorded by pilot under supervision

The ATSB reviewed the sleep log information recorded by the pilot under supervision and compared it to other information, including phone records and the operator’s building access records. Table 10 shows the sleep and duty times reported by the pilot under supervision in their sleep log for the period 8 March to 14 March 2018. Table 10 also shows times where the ATSB identified the pilot was probably sleeping and working, based on other sources of information.

The recorded sleep times were considered accurate unless other information indicated that the pilot was not asleep. However, it is noted that recorded sleep times are in 1-hour blocks, and sleep could have commenced any time within the first 1-hour block and ceased any time within the last 1-hour block.

Table 10: Pilot under supervision recorded sleep log and related information (click for larger image) 

Table 10 -  Pilot under supervision recorded sleep log and related information

Colour-shaded cells show sleep and wake recorded by the pilot under supervision. Periods of sleep are shaded grey, periods of work (including flying) are shaded blue and other periods of wakefulness are shaded white. The pilot under supervision did not record any work for 14 March and the reported sleep time probably reflected the sleep log pre-filled sleep periods. Text-filled cells show the times of sleep and work determined by the ATSB based on various sources. Periods of potential sleep are shown by the letter ‘S’, and work-related duty are shown by the letter ‘D’.

The pilot under supervision commenced recording data in the sleep log for the night of 8 March (after arriving at Port Hedland). The most notable anomaly between the recorded times in the sleep log and other information occurred on 13 March. The pilot recorded sleeping until 0500, before working from 0600 to 1800. However, building access records showed the pilot arrived at work at 0417 and would have awoken before 0400. Text messages indicated the pilot left work at 1820.

The pilot under supervision’s sleep log showed recorded sleep from 2100 on 13 March until 0600 on the day of the accident, with no entries for duty that day and sleep recorded from 2200 that night. This was consistent with the pre-loaded default hours of sleep. It is probable the pilot did wake at about 0600 given text messages sent that morning and had not yet updated the sleep log during 14 March. The pilot under supervision was doing additional work for an assessment during the day on 14 March (included in Table 10). There was probably additional study on the night of 12 March, but this has not been included in the table as the time involved is unknown.

Given the sleep recorded on the 12, 13 and 14 of March, had the sleep logs been configured correctly for the PSWR extended wakefulness rule, any non-sleep times after 2200 on 14 March would have produced an orange alert. As the pilot had not removed the pre-loaded default sleep from the night of 14 March, no alert would have been produced even if the sleep log tool had been coded correctly.

Sleep log information recorded by instructor

Sleep log information recorded by the instructor was also compared to other sources of information (Table 11). The instructor’s phone records showed several calls made and messages sent during the hours recorded as sleep, and the building access records showed a number of instances where the instructor was at work after the reported duty finish time. Overall, this showed the instructor probably obtained less sleep and worked more than was recorded in the sleep log.

Table 11: Instructor recorded sleep log and related information

Table 11: Instructor recorded sleep log and related information

Colour-shaded cells show sleep and wake recorded by the instructor. Periods of sleep are shaded grey, periods of work (including flying) are shaded blue and other periods of wakefulness are shaded white. Text-filled cells show the times of sleep and work determined by the ATSB based on various sources. Periods of potential sleep are shown by the letter ‘S’, and periods of work are shown by the letter ‘D’.

On the nights starting 8, 10 and 11 March, the instructor recorded a period of 12 hours sleep[49] and on the night of 7 March recorded a period of 11 hours sleep. Available information from phone records indicated that the instructor woke significantly earlier than recorded on these and other days. More specifically, on the 5 nights of 7 to 11 March, the recorded sleep period extended until 0900, 1100, 1100, 1000 and 1000, and phone records indicated the instructor was awake at 0630, 0900, 0700, 0600 and 0700 respectively. On another trip to Port Hedland in January 2018, the instructor recorded one period of 14 hours sleep and one period of 16 hours sleep. On each of these occasions phone records indicated the sleep period was much less than recorded.

As with the pilot under supervision, there was inconsistency between the sleep log and other information on 13 March. The instructor reported sleeping to 0600 then working from 0600 until 1800. However, building access records showed the instructor entered the operator’s premises at 0430 and remained at work until at least 1917, longer than the 1800 recorded. The instructor had not yet recorded any information in the sleep log for 14 March.

The analysis of the instructor’s activities was complicated due to the nature of some of the recorded phone information. There were instances of very long phone calls between the instructor and their partner, including late at night. For example, one recorded phone call started at 1907 on 12 March and ended at 0400 on 13 March. The ATSB asked the instructor (in late 2020) about the long phone calls. The instructor explained that, around the time of the accident, they sometimes fell asleep while on the phone with their partner. Although unable to recall if this had occurred on 12 March, the instructor said they would not have gone flying if awake all of the previous night. For the purpose of fatigue analysis, the ATSB assumed the phone call on the night of 12 March ended prior to the instructor’s recorded sleep time start of 2200.[50]

Information recorded by other pilots

The ATSB reviewed the sleep logs completed by the operator’s other pilots based at Port Hedland from late 2017 through to the date of the accident (14 March 2018). There were no instances of pilots recording flight or duty times when the sleep logs identified a fatigue risk (that is, there were no flight or other duties reported in highlighted cells).

The ATSB recalculated the data for the extended wakefulness rule, to correct the coding error in the sleep log tool. After this correction, there were 55 instances of pilots reporting either flying or other duties when they had been awake for longer than the sum of their recorded sleep in the prior 48 hours.

The ATSB compared the sleep, work and rest times reported by pilots with other information about pilots’ probable activities. Operational records from the company’s 2 helicopters showed which pilot flew each flight and building access records showed when each pilot opened doors to the operator’s premises at Port Hedland. This analysis showed pilots recorded sleep on their sleep logs when they could not have been sleeping. Excluding data associated with the pilot under supervision and the instructor:

  • There were 32 instances when a recorded sleep period significantly overlapped (greater than 10 minutes) with times the pilots were recorded entering the operator’s premises. Of these, 7 instances involved a probable sleep loss of 1 hour or more, and the maximum sleep loss was 8 hours.
  • There were 11 instances of pilots recording a sleep period when flight records showed they had been flying a helicopter.
  • There were 23 instances involving 6 different pilots where a continuous period of 12 or more hours sleep was recorded.

If the pilots had not recorded these periods as sleep, in some instances the sleep logs would have highlighted subsequent duty times as being a fatigue risk. In other instances, no fatigue risk would have been identified due to the problem with the coding of the extended wakefulness rule.

The ATSB did not obtain phone records of the operator’s pilots, apart from the 2 pilots involved in the accident. It is possible that there were other instances of sleep misreporting that were not identified in the building access and operational records.

The ATSB reviewed pilot rosters for March 2018 and compared the rostered shifts with the times of duty and non-duty recorded in the pilots’ sleep logs. This showed that pilots sometimes worked during their standby days. The sleep logs also showed that pilots often recorded having sleep during the first few hours of a rostered shift, finished duty prior to the end of the rostered shift, or obtained a mid-shift nap, presumably depending on the operational requirements as dictated by the shipping schedule. It was unusual for pilots to record 12 hours of consecutive duty

Pilot self-assessments of fatigue

The FRMS manual stated that pilots should self-assess their levels of fatigue and:

If when asked to perform duty a flight crew member feels that he is unable to do so in that he does not comply with the standards set out in this FRMS or he does not feel rested enough to undertake duty he is to inform the tasking officer of the situation. In doing so he is to recognise that his decision is totally supported by the CEO [chief executive officer] in that it complies with the procedures of the FRMS.

In addition, pilots were required to record self-assessments of fatigue in the Excel file (in a separate spreadsheet to the sleep log). These evaluations were based on a scale from 0% to 100%, as summarised in Table 12. They were required to be completed at the end of a shift (termed a ‘mission’ in the sleep log).

Table 12: Fatigue ratings used in sleep logs

Fatigue evaluationDescription
0%Just awake and well rested
>33%Tired but feel ok to take on a new mission
>66%Too fatigued to accept another mission. Assessed as bearing too much risk on fatigue related errors.
100%Dead tired. Very fatigued. Need sleep.

Following the duty on 13 March, the instructor reported a fatigue rating of 60%, which was higher than recorded on previous days (previous highest being 40%). The pilot under supervision reported a rating of 30%, higher than the 10% recorded for all previous days. The instructor and the pilot under supervision recorded duty periods of 11.8 and 12.0 hours, respectively, however both records substantially understated the times the pilots were at work.

Between December and March 2018, there were several instances of pilots recording ratings of 70 to 90%. However, as these were recorded at the end of their shifts, the operational meaning of such ratings was unclear (as the pilots would not generally be assigned any additional tasks after the end of their assigned shift).

Fatigue occurrence reporting and monitoring

The FRMS manual stated:

A flight crew member is to inform the Chief Pilot of his inability to undertake duty because of illness, fatigue or because he has not met the requirements of this system…

In other words, if a pilot felt fatigued, they were to advise the chief pilot. In addition, if they had recorded less sleep than required by the PSWR, they were to inform the chief pilot and they were also, under the FRMS, ‘not available to undertake duty’.

In simple terms, if a pilot had a red or orange alert in their sleep log, they were not able to fly or conduct duty during that time. If this occurred, the chief pilot was required to ‘find a suitable flight crew member who can perform the duty, pass the task to another operator or cancel the task’.

The FRMS manual did not provide any allowance for exceedances of the PSWR and there was no guidance regarding types of mitigators to consider for different types or levels of exceedance of the PSWR.

The FRMS manual stated that the chief pilot was responsible for continually monitoring the operation of the FRMS, and was to ‘review and initial pilots’ sleep logs and flight and duty records at least once per week’. There were no records of any such review and approval having been conducted.

The FRMS stated that pilots should submit fatigue occurrence reports to the chief pilot after an ‘adverse event’, so the chief pilot could review factors such as recent sleep. The ATSB sought records for the operator for fatigue occurrence reports during 2016–2018. There was one report, which was submitted in September 2016 and related to a pilot based in Mackay being unable to achieve sufficient rest. This report was closed in January 2017 with no action taken. There was no indication in the records for this event that there were factors in common with the accident involving VH-ZGA.

Pilot perceptions of the roster and use of sleep logs

During discussions with the ATSB after the accident, some of the operator’s pilots expressed their opinion that the sleep logs were an insufficient tool that did not accurately capture fatigue risk. Pilots felt that a key deficiency in the sleep logs was how easy the system was to manipulate. Pilots could see in real-time the effects of adding and removing periods of sleep and duty, and therefore it was easy to identify how to prevent fatigue alerts (or violations of the PSWR) from being generated in the logs.

Several pilots described perceiving implicit and explicit pressures to adjust the data they recorded in sleep logs to prevent any fatigue alerts. One pilot told the ATSB that if they submitted a sleep log showing a fatigue alert, the chief pilot would tell them to ‘make it work’. Another pilot described adjusting their sleep log to appease management and described an anecdote of another pilot being pressured to do the same. Other pilots described similar implicit and explicit pressures for adjusting their sleep logs to prevent fatigue alerts, including feeling that if they reported as unfit for duty they could lose their jobs.

Some of the operator’s pilots told the ATSB they perceived that the line pilot roster at Port Hedland created difficulties for achieving sufficient restorative sleep. Pilots described finding it difficult to sleep following the end of a night shift at 0600, particularly later in the morning and into the early afternoon. Pilots said that they were sometimes only able to achieve a couple of hours sleep in these situations but reported longer sleeps in the sleep logs to avoid generating fatigue alerts. The pilots said that if they recorded their actual sleep following these night shifts, the sleep log would show fatigue alerts towards the end of a subsequent night shift (in cases where they were required to work 2 night shifts in a row due to limited pilot availability).

Some pilots also believed the fatigue (mission) evaluations were of limited value, explaining that they found it very difficult to put a percentage figure on their level of fatigue. These pilots perceived there was an expectation that they would ensure their self-assessed fatigue was below the threshold 66% value.

The chief pilot (at the time of the accident) advised the ATSB that pilot concerns about the operator’s rostering pattern related to comparisons with the pattern used by previous operator at Port Hedland. The pilots who had been employed by the previous operator wanted to return to a 12-12 (midnight to midday/midday to midnight) roster and the previous fatigue management system (using FAID, see next section). However, this was not compatible with the new operator’s systems, which continued to be utilised.

After 12 months, the new operator was going to trial 12-12 rosters and turned on the FAID function of the flight management software to evaluate it. The chief pilot advised the ATSB that, before the trial, pilots were required to operate in accordance with the operator’s FRMS and that was the context for telling pilots ‘to make it work’. The chief pilot advised that pilots were not pressured (implicitly or explicitly) to adjust their sleep logs or given any indication that they could lose their jobs if they were fatigued.

The chief pilot advised that they did an evaluation of the 12-12 roster and noted various concerns, including:

  • If pilots did not get any significant sleep before midnight, they were rostered until midday, working in the Port Hedland heat.
  • Every flying shift was within the core hours of sleep 2200–0600.
  • With the existing roster, the pilots were doing a normal day shift, then a night shift finishing at 0600, then a day off. This seemed to be less fatiguing than every shift within the core hours of sleep.
  • Towards the end of the shift, the pilots would have been operating in the window of circadian low. If they were doing 12-12 they still would have been operating within this period but with sunrise and morning heat to work through.

Use of a biomathematical model of fatigue

A biomathematical model of fatigue (BMMF) uses mathematical algorithms to predict the effect of different patterns of work on measures such as subjective fatigue, sleep or the effectiveness of performing work. Each model uses different types of inputs and produces different types of outputs, and each model is based on many assumptions and has limitations. The models are designed to be one element of a system for evaluating and comparing work rosters (see Civil Aviation Safety Authority 2014, Dawson and others 2011, Gander and others 2011).

Many transport organisations include a BMMF as part of their FRMS, and the FAID [51] BMMF has been widely used in the Australian rail and aviation industries since the early 2000s. It uses hours of work (start time and end time) as its inputs, and it produces a score based on an algorithm that considers the effects of the length of the duty periods, time of day of the duty periods, and the amount of work over the previous 7 days (Roach and others 2004). The higher the FAID score, the higher the potential for fatigue.[52]

The operator’s FRMS did not include the use of a BMMF to evaluate roster patterns or recorded duty times. However, pilots reported that, up until a few months prior to the accident, the operator provided them with access to FAID scores associated with their recorded duty times and predictions for future shifts. Some pilots advised the ATSB that they believed the FAID scores provided them with a more objective indication of fatigue risk, and were less easy to manipulate, than the sleep and duty times recorded in the sleep log.

Some pilots recalled some FAID scores showed a high level of fatigue exposure associated with the Port Hedland roster, particularly when there was reduced pilot numbers. These pilots told the ATSB that access to the FAID scores was removed when concerns about the scores and the implication of excessive fatigue associated with the roster were brought to the attention of the operator’s management.

The operator advised that access to FAID was provided for ‘comparison information to test relevance of predicted work practices ...’, which some of the Port Hedland pilots were requesting. The operator rejected the implication that removal of FAID was intended to hide fatigue risk.

The ATSB used FAID to analyse a standard Port Hedland pilot roster (including a 12-hour day shift, a 12-hour night shift and then 2 days with no duty assigned over multiple weeks). This analysis predicted a FAID score of 79 towards the end of each night shift, with the scores being above 60 from about 0300 each night shift and above 70 from about 0430 each night shift.[53] This analysis assumed a pilot was on duty for the full length of their shifts (which would be very rare), and it also assumed that a pilot was not allocated work tasks on their standby day (which occurred to some extent).

The ATSB conducted further FAID analysis using the reported hours of duty from all line pilots based at Port Hedland during March 2018, which incorporated self-reported napping and shift start and finish times as recorded in the sleep log. With one exception, this analysis did not indicate that there were systemic issues in the fatigue exposure associated with the patterns of work of the line pilots.

In October 2021, the ATSB received documents relating to the operator’s application for CASA approval of an FRMS trial under CAO 48.1 Instrument 2019. These documents included a ‘scientific safety case’, which stated

Recently, a whole year of flight duty and flight time data were subjected to analysis for the Gladstone and Port Hedland operations ... For the Port Hedland operation there was a median of 4 flights per flight duty period and a total of 2.99hrs of actual duty time (including all flight time and an allowance for daily pre-flight and end of shift activities).

These flight and duty data were subjected to bio-mathematical modelling using the FAID Quantum software. Across both datasets there were no instances of a FAID score greater than 60 in either operation, suggesting an overall low level of inherent fatigue-related risk. The FAID Quantum model indicated that for less than two percent of duty periods flight crew were predicted to have obtained less than five hours sleep in the prior 24 hours. This predicted exposure to instances of restricted sleep is less than observed in datasets from objective monitoring of flight crew internationally and again demonstrates an inherently low level of fatigue-related risk.

The ability to obtain sleep during the 12-hour duty periods is an important consideration that significantly lowers the inherent risks associated with long duty periods, especially at night. Within the Heli-Aust Whitsundays operation, all flight crew have access to suitable sleeping accommodation when on duty, and evidence suggests that this is utilised during breaks between taskings.

The ATSB notes that the duty times included in this analysis were only associated with flying activities and did not include other duty. The analysis was also based on duty times from a different period of time and may not have reflected the situation that existed in March 2018.

FRMS internal reviews

The FRMS manual stated that the chief pilot should produce a written review of the FRMS every 12 months. The ATSB sought records of internal reviews of the FRMS over the period 2016–2018; the operator advised that no review had been conducted.

Records from the operator’s safety meetings noted the following:

  • In October 2017, concerns were raised about the consistency of pilots recording of duty times across the helicopter records, Air Maestro and the sleep logs.
  • In December 2017, the deputy chief pilot noted that they had received feedback about the duty period and sleep cycle ‘one pilot is following’ and stated that they had adjusted the roster and would continue to monitor. The deputy chief pilot also said that ‘pilots are reminded that if they are fatigued, then they should not fly and ensure they notify the General Manager’.
  • In January 2018, the deputy chief pilot said the operator was trialling a new roster at Port Hedland.
  • In February 2018, the chief pilot noted ‘Fatigue concerns with the roster for Port Hedland was closed out and has now reopened due to ongoing feedback. A risk assessment is being carried out on the current PH roster.’

The ATSB sought clarification from the operator about the roster trial and risk assessments alluded to in the safety meeting minutes from early 2018. The operator advised that, although there was consideration of a roster pattern of shifts starting at 0000 and 1200, no trial was commenced.

Other occurrences

Introduction

As a standard practice, ATSB investigations research other occurrences with similar themes as a reference for analysis and, in particular, identification of risk factors and assessment of safety issues. A search for this type of occurrence – inadvertent descent during a visual approach at night in a degraded visual (cueing) environment (DVE) involving a helicopter – did not yield any results in the ATSB database.

The ATSB has investigated occurrences involving VFR operations at night in a DVE, including the loss of control involving AS355F2 (Twin Squirrel), VH-NTV, in outback South Australia on 18 August 2011.[54] During departure, the pilot became spatially disoriented[55] for reasons that included workload and absence of an autopilot. Following this event, CASA enhanced guidance for night VFR operations and required an autopilot or second pilot for air transport operations at night.

Three occurrences outside of Australia, detailed below, were identified that featured a visual approach or visual element of an instrument approach in a DVE. Although these were 2-crew IFR operations and 2 involved larger helicopters, the same hazards were present in the operating environment.

Nova Scotia, Canada Sikorsky S-92A

The Transportation Safety Board of Canada (TSB) investigated an inadvertent descent during a visual approach involving a Sikorsky S-92A on 24 July 2019 in the Nova Scotia region. This was a 2‑pilot operation under the IFR carrying 11 passengers from Halifax to a fixed offshore facility. The following information is adapted from TSB safety investigation report A19A0055. Instrumental to the investigation was data recovered by the TSB from multi-purpose flight recorders (including voice), health and usage monitoring system, and flight management system computers. This data was integrated with ADS-B and satellite-based flight-following services.

On arrival at the facility the crew attempted 2 instrument approaches, but low cloud and poor visibility prevented a landing. During the second missed approach, the flight crew exited cloud at about 300 ft and sighted the helideck above the fog layer. The crew levelled at 500 ft and after assessing the conditions manoeuvred for a visual approach.

The helicopter rolled out on final approach 0.6 NM (1.1 km) from the facility at 500 ft, which was above the cloud layer with forward visibility of about 5 km. Shortly afterwards, the pilot flying disengaged altitude hold and held the cyclic trim release button to manually fly the approach. At about the same time the pilot flying lowered the collective to descend. (The angle to the helideck was 7.1°, which was steeper than the company’s standard 4.7° approach angle.)

As the approach progressed, the pitch attitude increased to 17°, the airspeed decreased below 40 kt, and the rate of descent was 670 ft/min and increasing. Although the pilot monitoring called the pitch attitude through 15°, neither pilot was aware of the increasing rate of descent, low engine torque setting, or increasing sideslip.

By 250 ft, all forward motion had been lost and the rate of descent was 1,200 ft/min and increasing with a large sideslip angle (lateral groundspeed of 18 kt. The pilot flying realised the helicopter was getting low and applied moderate then high engine torque. At the same time the rate of descent increased to 1,800 ft/min and helicopter descended below helideck elevation (174 ft). Both pilots recognised the helicopter was in fog and a go-around was initiated.

As the helicopter descended through 100 ft the water was sighted and by 70 ft the collective was raised to the full up position. A significant over-torque occurred accompanied by low main rotor RPM (with alert) and when the helicopter was at 40 ft it yawed uncontrollably to the right for 2 rotations. Due to the low rotor RPM, the main generators dropped offline and various electrical systems including the AFCS and some flight displays were depowered.

The crew arrested the descent within 13 ft of the water in reduced visibility due to fog.

Under control of the captain, the helicopter was then climbed and accelerated with high power settings and increasing main rotor RPM. The helicopter reached 1,350 ft then began descending and accelerating while the crew were trying to engage the AFCS. Initially unnoticed by the crew, the airspeed increased to 148 kt while descending through 650 ft at 1,700 ft/min. This descent was arrested at about 500 ft and the helicopter climbed for a return to Halifax where conditions would allow a visual approach.

Of the 18 findings issued by the TSB, the following were of particular relevance:

[The operator’s] standard operating procedures provided flight crew with insufficient guidance to ensure that approaches were being conducted in accordance with industry-recommended stabilized approach guidelines.

The pilots experienced attentional narrowing due to increased workload while attempting a non‑standard offshore visual approach in a degraded visual environment. This led to a breakdown in the pilots’ instrument cross-check, which prevented the timely recognition that the approach had become unstable.

Depressing and holding the cyclic trim release button, while operating in a degraded visual environment, increased pilot workload and contributed to control difficulties that resulted in an unstable approach that developed into vortex ring state.

If manufacturers’ flight manuals and operators’ standard operating procedures do not include guidelines for the use of the cyclic trim release button, it could lead to aircraft control problems in a degraded visual environment due to the sub-optimal use of the automatic flight control system.

Prerow, Germany BK117

The German Federal Bureau of Aircraft Accident Investigation (BFU) investigated an accident during night hoist training to a sea rescue vessel at sea near Prerow, Germany, involving a BK117 C-1 helicopter on 28 February 2014. This was a 2-pilot operation under the night VFR with a hoist operator and emergency physician onboard. The following information is adapted from BFU investigation report 3X006-14.

The sea rescue vessel was a relatively small ship with minimal lighting and there was no cultural lighting in the vicinity. It was a dark night due to light rain and no moonlight.

On arrival, the first approach was terminated because of low visibility and late identification of the ship. The co-pilot (in the left seat) then conducted a tight left circuit to the ship. That circuit and all of the subsequent manoeuvring in the vicinity of the ship was conducted manually.

After 3 hoist exercises to the ship were completed, the pilot in command (in the right seat) flew away from the ship and conducted a left circuit for another approach. During the approach the crew lost sight of the ship and by the time it was resighted the helicopter had inadvertently climbed. The pilot in command discontinued the approach and manoeuvred for another left circuit at 500 ft.

Based on directions from the co-pilot, the PIC turned onto base, decelerated, and descended. As the helicopter descended through 150 ft with an airspeed about 35 kt, the co-pilot advised the PIC to turn. The PIC called ‘150’ and at the same time the radio altimeter annunciated ‘decision height’ (pre-selected to 100 ft). The co-pilot acknowledged ‘150’ then the PIC called ‘100’ followed by an exclamation from the hoist operator. Within 3 seconds the helicopter impacted the water. The co-pilot was the only survivor.

The helicopter was equipped with a combined cockpit voice recorder (CVR) and flight data recorder (FDR). A plot of the FDR data showed that in the 20-second period before impact, the airspeed reduced from about 45 kt to less than 10 kt while the aircraft turned through 60° and descended 200 ft.

The BFU identified the following factors as immediate causes:

  • little experience of the crew regarding the applicable procedures at night over sea
  • the approach deviated from the described approach procedure
  • in regard to the altitude, the airspeed, and the rate of descent, the approach was not stabilised
  • the descent was commenced prior to being on final approach and without visual contact with the ship
  • insufficient monitoring of the flight instruments
  • loss of situational awareness in combination with loss of control
  • non-reaction to visual and audio altitude warnings of the radio altimeter.

The BFU also identified 6 systemic causes including:

  • insufficient company specifications for the use of the flight attitude stabilising functions of the autopilot system during approaches and departures and in traffic circuits above sea
  • lack of go-around criteria for a non-stabilised approach
  • lack of aviation regulations for offshore helicopter flight operations in Germany
  • insufficient assessment of the operator’s procedures by the responsible supervising authority.

Based on the operator’s implemented and planned safety actions, the BFU refrained from issuing safety recommendations to the operator. When the report was published in March 2016, the following safety recommendation (BFU 25/2015) was still in effect:

The LBA (German Civil Aviation Authority) should ensure that Operators conducting VFR-Night approaches to sparsely lit landing sites should specify practical and detailed procedures in their handbooks that are appropriate to the special demands of this type of operation, and which specify systematic, consistent and comprehensive use of the resources available to the conduct of the flight.

Sumburgh, United Kingdom Super Puma

The United Kingdom (UK) Air Accidents Investigation Branch (AAIB) investigated an accident during an instrument approach in the Shetland Islands region of Scotland involving a Eurocopter AS332 L2 Super Puma on 23 August 2013. This was a 2‑pilot operation under the instrument flight rules carrying 16 passengers from an offshore platform in the North Sea to Sumburgh Airport for a refuelling stop. The following information is adapted from AAIB aircraft accident report 1/2016.

On arrival at Sumburgh, the crew conducted a non-precision approach in cloud that at the airport was reported to have a base of 300 ft with reduced visibility in mist. The approach was flown with the autopilot in 3-axes with vertical speed (V/S) mode, which required the pilot flying to operate the collective pitch control manually to control the helicopter’s airspeed. The role of pilot not flying was monitoring the helicopter’s vertical flight path against the published approach vertical profile and seeking the external visual references necessary to continue with the approach and landing.

The procedures permitted the crew to descend to a height of 300 ft, the minimum descent altitude (MDA) for the approach, at which point a level-off was required if visual references had not yet been acquired.

Although the approach vertical profile was maintained initially, insufficient collective pitch control input was applied by the pilot flying to maintain the approach profile and the target approach airspeed of 80 kt. This resulted in insufficient engine power being provided and the helicopter’s airspeed reduced continuously during the final approach. Control of the flight path was lost, and the helicopter continued to descend below the MDA. During the latter stages of the approach the helicopter’s airspeed decreased below 35 kt and a high rate of descent developed.

The decreasing airspeed went unnoticed by the pilots until a very late stage, when the helicopter was in a critically low energy state. The pilot flying’s attempt to recover the situation was unsuccessful and the helicopter struck the surface of the sea approximately 2 NM (3 km) west of Sumburgh Airport. It rapidly filled with water and rolled inverted but was kept afloat by the flotation bags which had deployed. Four of the passengers did not survive.

Of the 6 causal and contributory findings issued by the AAIB, the following were relevant:

The helicopter’s flight instruments were not monitored effectively during the latter stages of the non‑precision instrument approach. This allowed the helicopter to enter a critically low energy state, from which recovery was not possible.

The operator’s SOP for this type of approach was not clearly defined and the pilots had not developed a shared, unambiguous understanding of how the approach was to be flown.

The operator’s SOPs at the time did not optimise the use of the helicopter’s automated systems during a Non-Precision Approach.

The AAIB advised that the commander’s decision to fly the non-precision approach using a reducing airspeed meant that there were 2 parameters changing during the approach. These were: a) the vertical speed, controlled through the autopilot, and b) the airspeed, controlled through manual collective pitch adjustment. This method increased the risk that any significant period of inattention to either parameter would lead to an undesired approach profile.

In relation to the finding that the appropriate flight instrument displays were not being monitored adequately in the latter stages of the approach, the AAIB advised that improved pilot training may be beneficial, and several research projects have been undertaken which have identified a need for revised training in pilot instrument scan techniques.

A number of recommendations were issued by the AAIB to address safety issues associated with the findings and other themes such as provision of operational information, flight data monitoring, helicopter terrain awareness warning systems (HTAWS), onboard image recording, and survivability.

Research and additional occurrences associated with night operations

Research has shown that pilots engaging in simulated ship-borne landing operations experienced significantly degraded visual cues during night conditions, with a reduced ability to make corrections to attitude and horizontal and vertical translational rates. Pilots experienced higher workload and more control inputs were needed to perform the task than in good visual conditions (Wang and others, 2013).

Perceptual difficulties posed by navigation to single-source maritime lights have also been described in investigations of accidents involving night approaches to oil platform helidecks. Excerpts from these include:

  • A difficulty which is relevant to approaches to platforms and ships at night, is that these may be the only light source in an otherwise totally dark environment. A single light source phenomenon has long been recognised by the aviation community as one which contributes nothing to the pilot's judgement of distance. …The usual effects of this phenomenon are that the pilot is deprived of the visual cues normally associated with daylight vision. These are: the relationship of the object to the horizon; the relationship to other objects and the surface texture between the aircraft and the object in view, and the use, for ranging, of the angle subtended at the viewer's eye by the object, because: (a) the absolute size of the object is uncertain, and (b) the judgement of this angle when it is very small is difficult.[56]
  • In dark, overcast conditions, it is likely that some cues were degraded or absent. For example, without a distinct horizon the assessment of pitch attitude and approach angle (by reference to the depression of the deck below the horizon) would be compromised. Without textural cues in the ground plane (in this case the sea surface), judgement of pitch attitude and approach angle by inference from textural perspective would also be compromised, as would the appreciation of the range to the deck. The illuminated deck would have provided limited cues to roll attitude and, by reference to its apparent size, to range. The crew’s judgement of range and rate of closure to the platform would have improved as they approached the platform, but, initially, this would be relatively insensitive.[57]

Survival aspects

Helicopter underwater escape training

Helicopter underwater escape training (HUET) has been in use around the world since the 1940s and is considered best practice in the overwater helicopter operating industry. HUET is designed to improve survivability after a helicopter ditches or impacts into water. Research of such accidents has shown that occupants who survive the initial impact will likely have to make an in-water or underwater escape, as helicopters usually rapidly roll inverted post-impact due to the position and mass of the engine/s, transmission and main rotor system. The research has also shown that drowning is the primary cause of death following a helicopter accident into water.

Fear, anxiety, panic and inaction are the common behavioural responses experienced by occupants during a helicopter accident. In addition to the initial impact, in-rushing water, disorientation, entanglement with debris, unfamiliarity with seat belt release mechanisms and an inability to reach or open exits have all been cited as problems experienced when attempting to escape from a helicopter following an in-water accident.[58]

HUET involves a module (replicate of a helicopter cabin and fuselage) being lowered into a swimming pool to simulate the sinking of a helicopter. The module can rotate upside down and focuses students on bracing for impact, identifying primary and secondary exit points, egressing the wreckage and surfacing. HUET is normally part of a program of graduated training that builds in complexity, with occupants utilising different seating locations, exits and visibility (via the use of ‘blackout’ goggles). This training is conducted in a controlled environment with safety divers in the water.

HUET is considered to provide individuals with familiarity with the crash environment and confidence in their ability to cope with the emergency situation.[59] Interviews with survivors from helicopter accidents requiring underwater escape frequently mention they considered that HUET was very important in their survival. Training provided reflex conditioning, a behaviour pattern to follow, reduced confusion, and reduced panic.[60]

Like other highly procedural and complex skills, if underwater escape is infrequently practiced, skill decays rapidly.[61] In a UK Civil Aviation Authority (2014) safety review of offshore public transport in helicopters for the oil and gas industries, it was noted that although the frequency of refresher HUET is presently every 4 years in the UK, this is widely regarded by experts as being inadequate.[62]

In Australia, CAO 95.7.3 required all flight crew engaged in MPT operations in single-engine helicopters to have completed a HUET course. The CAO had no requirement for recurrent training and there was no regulatory requirement for multi-engine flight crew conducting MPT to complete HUET.

CASA advised the ATSB that updates to CAO 95.7.3 (made in 1992) were delayed a number of years in anticipation of new flight operations regulations that eventually became effective in December 2021. According to CASA, in the intervening period, it assessed the operations manual content of operators who conducted overwater operations to assess how effectively they were addressing the risks associated with the operation. If required, CASA could issue directions to an operator utilising CAR 215 or an operator could elect to include those requirements in its operations manual.[63]

Operator HUET requirements

Part 4 of the operator’s operations manual (Training and Checking) required all pilots engaged in overwater (offshore) operations to have completed a HUET course with an approved provider during the previous 3-year period. The manual indicated that the chief pilot could extend that period for an individual pilot if circumstances arise which preclude that training being done within the 3-year period. In that situation, the period of extension was to be specified at the appropriate time and would normally not exceed 6 months. The training was to be rescheduled as soon as practicable and a note was required to be made in the pilot’s records.

The pilot under supervision had last completed HUET in May 2011, which was outside the operator’s 3-year recurrent training period. On 6 March 2018, the operator’s chief pilot booked a HUET course for the pilot under supervision but did not make any note of the extended interval in the pilot’s records. The training, scheduled for 24 April 2018, was a full-day course with a Brisbane-based training provider.

The chief pilot reported that there was pressure from the operator’s management to replace a pilot (assigned to Port Hedland) that had recently resigned. As the chief pilot considered this was not a normal circumstance, and the operations manual allowed for an extension (not normally more than 6 months), the chief pilot applied the extension until the next available HUET course. (This was equivalent to an extension of 3 years and 11 months.)

The instructor had completed HUET within the last 3 years. The operator also provided the ATSB with records of HUET course information for 24 other company pilots, all of who had completed their HUET training within the required period.

There were also procedures included in Part 3 of the operator’s operations manual (Aerodromes and Routes) that specified HUET requirements for various bases. At the operator’s Hay Point base, a HUET course was required every 2 years, but could be extended to 3 years at the discretion of the chief pilot. Other bases included the requirement for a HUET course before conducting night transfers of marine pilots but specified no other requirements in terms of recurrency or training requirements for day operations. The operations manual required all pilots and marine pilots at the Port Hedland base to have completed a HUET course before conducting night transfers.

The conflicting information contained in the operations manual had potential to confuse personnel as to the operator’s requirements for HUET. That ambiguity could result in a situation where personnel were complying with the requirements contained in one part of the operations manual, but inadvertently breaching a requirement contained in another part of the manual.

Emergency breathing systems

Underwater escape from a flooded cabin is a recognised hazard after an accident or ditching on water and where the cabin becomes submerged. In that situation, occupants of the helicopter typically have a very short timeframe to complete the necessary actions to assure their survival. Those actions include orientating themselves in the cabin relative to their emergency exit pathway, correctly operating and opening the emergency exit, releasing their seat belt, escaping cabin and swimming to the surface.

The time available to escape a flooded cabin can be extended using a compressed air emergency breathing system (EBS). These systems vary in design and capacity but are usually carried on the occupant’s life jacket/personal flotation device and provide a small quantity of supplemental air for use during their escape.[64]

EBS are critical for survival in situations where the occupant’s likely escape time exceeds their breath hold capability/capacity. Factors affecting breath hold capability includes the temperature of the water and the suddenness of immersion, particularly when the occupant does not have opportunity to take a full breath as the cabin floods. EBS are commonly used in larger passenger-carrying transport category helicopters operating over-water in hazardous environments, where there are a relatively large number of passengers to evacuate the cabin through the available emergency exits.[65]

In 2013, the United Kingdom’s Civil Aviation Authority published a report on the experimental work conducted in support of developing a technical standard for helicopter EBS.[66] The draft technical standard identified ‘Category A’ EBS for use in water impact accidents with little or no warning and which could be deployed underwater. Those systems should be capable of being fully deployed with one hand in less than 12 seconds following submersion.

In 2020, the European Union Aviation Safety Agency published a literature review relating to helicopter evacuation and underwater escape and identified gaps in research and provided recommendations for future research.[67] The literature review noted various research studies measuring time for occupants to escape from a helicopter cabin to vary from 15 to 25 seconds, depending on conditions. In addition, the literature review identified a study of offshore workers that measured breath holding times in air and water. In water at 25°C, the overall breath-hold time ranged from 6 to 120 seconds, with a median time of 37 seconds.

There were no Australian regulatory requirements that specified EBS as emergency equipment for occupant use in an underwater escape from a helicopter cabin.

Requirement for recurrent training in emergency procedures at the time of the accident

At the time of the accident, CAO 20.11 specified requirements for crews to complete periodic training in emergency procedures and specific to the type of aircraft being operated. As discussed in the Pilot information section, both the instructor and pilot under supervision had completed this training within the required period.

Relevant to the pilot under supervision was the CAO 20.11 check completed during their company induction 5 March 2018. Although this training included operation of the emergency exits, that training did not include any actual activation of the emergency exits using the door jettison system. However, having recently competed that training the pilot under supervision should have been familiar with the location of the door jettison handle and the correct sequence for operating the door.

In addition to the CAO 20.11 training, the chief pilot had completed the company induction checklist with the pilot under supervision. That checklist included a section titled survival at sea and the item titled HUET procedures had been ticked. The application of that item would have been limited to a check of theoretical knowledge and discussion of the HUET procedure and not an application of the practical skills and/or procedures.

Revised regulatory requirements

New flight operations regulations introduced in December 2021 authorised MPT operations under a CASR Part 138 aerial work certificate, to be conducted under the general operating and flight rules in CASR Part 91 with addition or variation of those rules according to CASR Part 138.

The CASR Part 138 manual of standards (MOS) specified that for flights in helicopters where life jackets and life rafts were required to be carried, flight crew members were required to have training, including an in-water practical component, in:

  • ditching procedures
  • use of life jackets and life rafts (as required)
  • underwater escape.

The MOS specified that training in relation to life jackets, life rafts or underwater escape was to occur at intervals of not more than 3 years.

At the time of the accident, there was no regulatory standard that required crews of multi-engine helicopters flying over water to have completed underwater escape training. However, a requirement existed in the company operations manual for this training to be completed.

Helmets, communication cords and seat belts

Minutes from an operator safety meeting in October 2017 documented that VH‑ZGA and VH‑ZGZ required helmet/headset communication cords to be connected directly to the airframe connector jacks. The meeting minutes identified that in a ditching scenario, those communication cords could impede occupant egress unless they were pulled directly to disconnect the helmet from the airframe. To address this potential issue, short connector leads were to be provided to connect headsets/helmets to the airframe and improve the cord’s breakaway capability.

The instructor recalled being unable to disconnect their helmet communication cord from the overhead console after the water impact, so had unfastened their helmet chinstrap and discarded the helmet during their cockpit escape. This helmet was recovered with the communications cord still attached. Inspection of the helicopter wreckage found that the short breakaway connector remained connected to the instructor’s connector jack in the overhead console.

Police divers located the pilot under supervision in the cockpit of the helicopter, with the 4‑point seat belt unfastened. The pilot’s helmet was located in the cockpit with the chinstrap unfastened. The helmet’s communication cord was plugged into an extension connected to the overhead console. Although there was no short breakaway connector fitted at the overhead console, the extension cord provided similar functionality.

Lifejackets/personal flotation devices

The instructor and pilot under supervision were each wearing a lifejacket/personal flotation device equipped with survival equipment that included a 406 MHz personal locator beacon (PLB) and distress flares. Inflation of the lifejacket/personal flotation device was via a toggle pull that activated a compressed gas cylinder for inflation. The lifejacket/personal flotation device was equipped with 2 gas cylinders and 2 separate buoyancy chambers.

The instructor activated their PLB about 10-minutes after the accident, and that signal was detected by the satellite detection system at 2358. Encoded with the distress signal was the identification of the PLB, together with a GPS distress location. That information was received by the Australian Joint Rescue Coordination Centre (JRCC) at 0000 on 15 March 2018.

The instructor also used several flares from their lifejacket/personal flotation device to signal their position to the responding surface vessels. Two flares were initially deployed and were followed by a third when a bulk carrier appeared to be turning towards their direction. The instructor recalled deploying a fourth flare to mark their position as a launch got closer to their position. The port authority’s daily log included an entry at 0010, with vessels at the scene sighting 2 distress flares.

The lifejacket/personal flotation device worn by the pilot under supervision was uninflated and the inflation system had not been activated. That was consistent with procedures used for escaping underwater, where the lifejacket/personal flotation device is not activated inside the cabin due to the potential for the increased buoyancy to prevent escape.

Emergency locator transmitter

The helicopter was fitted with a battery-operated Artex 406-N HM emergency locator transmitter (ELT) capable of transmitting a unique digitally-encoded distress alert signal from an external antenna on the upper fuselage. On this model of ELT, the unit’s GPS position was also encoded in the signal. The ELT was designed to activate automatically when the helicopter was subjected to g-forces consistent with an accident.[68] It could also be manually activated using a switch mounted on the lower left side of the cockpit centre instrument panel.

About 50 seconds after activation, the ELT would transmit its first 0.5 second burst of digital data on 406 MHz and then repeat a transmission of data approximately every 50 seconds. Those signals could be detected by Cospas-Sarsat satellites, which would then be processed to the relevant search and rescue agency to coordinate a rescue response.

The Cospas-Sarsat satellites did not detect any post-impact transmissions from VH-ZGA, which indicated that the ELT did not activate, or activated without transmitting an effective signal. Examination of the ELT found that the battery compartment and internal electronics had been affected by water ingress and it was not possible to measure battery voltage as an indicator of ELT status. It was however noted that the ELT’s batteries were not due for replacement until August 2018 and the ELT was not waterproof or designed to operate under water. Irrespective of ELT activation, the almost immediate immersion of the ELT antenna would have attenuated any transmission.

The ATSB also identified that the ELT was mounted on the PELICAN[69] rack attached to the avionics deck in the rear passenger cabin. Guidelines issued by the Radio Technical Commission for Aeronautics (RTCA)[70] indicated that for proper operation in an accident, ELTs shall be installed to primary aircraft load carrying structures, such as trusses, bulkheads, longerons, spars, or floor beams.

The helicopter manufacturer advised the ATSB that the PELICAN rack was not an integral or primary load carrying structure and, as such, was not a suitable location for installing an ELT. The helicopter manufacturer confirmed that ELTs at airframe manufacture would be installed to the load carrying structures on the cockpit floor, adjacent to the pilot seat. A review of the available VH-ZGA’s maintenance documentation did not identify any supplemental type certificate, field approval or similar engineering assessment that approved the installation of the ELT to the PELICAN rack.

During the investigation, the ATSB advised the helicopter operator of the potential issue associated with the PELICAN rack mounting method of the ELT. A check of other helicopters in their fleet identified one other helicopter with a similarly mounted ELT, which was subsequently relocated to the cockpit floor, adjacent the pilot seat.[71]

A review of the helicopter’s maintenance records identified that the ELT was installed in July 2009, as part of emergency medical service modifications while the helicopter was on the United States’ aircraft register.[72]

In addition to the airframe mounted fixed ELT, a portable GME MT403G Emergency Position Indicating Radio Beacon (EPIRB) was fitted in the rear passenger cabin. The EPIRB unit activated automatically on water immersion or if not water immersed, it could be manually activated. This model of EPIRB would also transmit a distress signal encoded with the units GPS position. The battery expiration date was September 2023. This unit was found in its cabin mount and had activated on water immersion. The JRCC did not receive any distress signal from this EPIRB during the night of the accident.

Regulatory oversight and approvals

Regulatory framework

The Civil Aviation Safety Authority (CASA) was responsible, under the provisions of Section 9 of the Civil Aviation Act 1988, for the safety regulation of civil aviation in Australia and of Australian aircraft outside of Australia. Section 9(1) stated the means of conducting the regulation included:

(c) developing and promulgating appropriate, clear and concise aviation safety standards;

(d) developing effective enforcement strategies to secure compliance with aviation safety standards…

(e) issuing certificates, licences, registrations and permits;

(f) conducting comprehensive aviation industry surveillance, including assessment of safety‑related decisions taken by industry management at all levels for their impact on aviation safety

The 2 primary means of oversighting a specific operator’s aviation activities were:

  • assessing applications for the issue of or variations to its AOC and associated approvals (including approvals of key personnel)
  • conducting surveillance of its activities, including level 1 surveillance events (such as systems audits) and level 2 surveillance events of shorter duration and narrower scope (such as site inspections and ramp checks).
Previous occurrences and regulatory oversight

Detailed discussion of CASA’s processes for oversighting passenger charter operators for the period up to 2017 was provided in an ATSB report into a fatal Cessna 172 accident.[73] That report (released in October 2019) identified that, although the Cessna 172 operator’s primary activity since July 2009 was passenger charter flights to beach aeroplane landing areas (ALAs), regulatory oversight by CASA had not examined the operator’s procedures and practices for conducting flight operations at these ALAs. The ATSB investigation also identified the following safety issue:

The Civil Aviation Safety Authority’s procedures and guidance for scoping a surveillance event included several important aspects, but it did not formally include the nature of the operator’s activities, the inherent threats or hazards associated with those activities, and the risk controls that were important for managing those threats or hazards.

The ATSB issued a safety recommendation (AO-2017-005-SR-026) to CASA in October 2019 to address the safety issue, and this recommendation was closed in March 2020 after CASA outlined the safety actions it had taken, and was taking, to address the issue. A similar safety issue had been previously identified in another ATSB investigation.[74]

CASA oversight processes were also addressed in the ATSB investigation of a loss of control and collision with water involving a Eurocopter EC120B at Hardy Reef, Queensland on 21 March 2018.[75] The ATSB found that although the operator’s primary helicopter activity was conducting charter flights to pontoons at Hardy Reef, regulatory oversight activity by CASA had not specifically examined the operator’s procedures and practices for conducting operations to these helicopter landing sites.

Pre-occurrence audits

As part of this investigation, CASA provided records of regulatory activities carried out in relation to the operator during the 5-year period prior to the occurrence and up to the end of 2019. The ATSB reviewed these records with a focus on flight operations.

CASA conducted 5 audit or check events between 25 July 2013 and 21 February 2018. The 2 events conducted in 2013 were not applicable to the contemporary operating entity so were not considered.

The most recent audit prior to the occurrence (21 February 2018) was a Level-1 health check of the operator within a defined scope, including crew scheduling, operational standards, authorised activities, and operational support systems. It involved sampling documentation, interviewing key personnel, and reviewing some of the operator’s systems and processes at the operator’s main office in Mackay.

The auditors found that both the chief pilot and head of operations demonstrated adequate control of the flying operations and a high operational standard was expected and maintained. Crew scheduling appeared to be operating and effective. For operational standards, the auditors assessed the system that tracked qualification expiry dates and sampled induction records. They identified that the chief pilot was not licenced for one of the helicopter types on the operator’s approval and this type was subsequently removed from the approval.

The surveillance report noted that crew scheduling ‘appeared to be operating and effective’. CASA advised that this activity did not raise any concerns regarding the operator’s rostering practices or its flight and duty periods. It also noted that the Port Hedland base roster and flight and duty records were not specifically examined. There was no indication in the surveillance report that the operator’s FRMS manual was reviewed.

Prior audits/checks in 2016 and 2017 identified 2 non-compliances that were not directly related to flight operations. An observation issued in September 2016 noted that the level of control the operator had over its functions was limited in the area of chief pilot duties as there was no management process followed to support the chief pilot’s working practices. The operator was not required to respond to observations.

Post-occurrence audits

Following the occurrence, CASA conducted a national desktop audit of helicopter underwater escape training (HUET) for AOC holders conducting MPT operations. On 22 August 2018, CASA recorded that the operator was compliant with their 3-year HUET requirement for all of their MPT pilots.

Between 18 and 20 September 2018, CASA carried out a Level-2 operational check of the operator with a site inspection at Port Hedland in response to concerns raised by pilots about crew scheduling and fatigue management. The surveillance report stated that ‘the surveillance focussed on safety, training and scheduling practices’ of flight crew, and concluded that the operator’s ‘crew scheduling and safety management procedures were found to be suitable and effective in managing fatigue’. The surveillance report also stated that key management personnel were interviewed and the operator’s FRMS manual was referenced. CASA advised that the surveillance activity involved reviewing pilot rosters for the previous 3 months and next 2 months and copies of reported and identified flight and duty breaches in the past 6 months.

Three further Level-2 events were maintenance related or administrative.

Other surveillance events

During the Level-1 health check conducted on 21 February 2018, the auditors compiled an authorisation holder performance indicator (AHPI) questionnaire with input from the chief pilot and the head of operations. This form listed standard questions about scope of operations, organisational stability, and exposure to 2 risks - challenging environments and extension of working hours beyond limits. Based on the responses, the overall risk was recorded as low.

As noted by the auditors, the respondents advised that the 3 highest risks were vessel landings, drones (collision), and weather. There was no further reference to MPT operations and no provision for the associated risk controls to be identified and assessed.

The preceding AHPI in August 2017 produced a similar result. No other preceding AHPIs were available for the contemporary operating entity.

Post-occurrence AHPI results varied in the first 12 months with some higher risk scores associated with maintenance control concerns. Subsequent AHPI scores were lower with notes indicating organisational stability and CASA’s confidence in operational personnel.

Following the occurrence, CASA carried out a regulatory and safety review with reference to the regulatory posture to the operator and any safety action or learning derived from the occurrence. This did not identify any requirements for immediate action or significant learnings. Some minor improvements to processes were identified and a national sector campaign to audit HUET compliance in the MPT sector was initiated.

Application for approvals under CASR Part 141/142 and CAR 217

In September 2016, the operator submitted applications to CASA for flying school activities under CASR Parts 141/142 and training and checking approval under CAR 217.

The operator developed the various elements of their CASR Part 141/142 exposition/manual during 2017 with feedback and guidance from the assigned CASA personnel. In October 2017, CASA personnel assessed that the operator was compliant with the applicable requirements. The AOC was re‑issued (effective 1 November 2017) with approval to conduct CASR Part 142 flying training activities for the singe-engine helicopter class and EC135 type ratings.[76] The operator was also granted a CASR Part 141 flight training certificate for the single-engine class and various ratings such as night VFR and instrument ratings. CASA assessed that the instructor was acceptable for the position of head of operations for the CASR Part 142.

From a CASA perspective, the operator did not develop the CAR 217 application during 2017. In January 2018, the operator applied to CASA for a permission under CAR 217 to train and check aircrew and flight crew that would be involved in EC135 winch operations for MPT. The operator followed up with a proposed training manual based on the existing volume-4 of the operations

  1. Although the pilot under supervision held a Part 61 multi-engine helicopter instrument rating restricted to non-pilot in command duties on the basis of their co-pilot multi-engine helicopter instrument rating, a proficiency check had not been completed since the issue of the Part 61 licence in August 2015.
  2. The term ‘sleep opportunity’ is distinct from the amount of sleep obtained. Sleep opportunity in the context of this report’s analysis of the pilots’ recent histories refers to periods in which the pilots reported sleep in their sleep logs and no other data indicated they were awake. The actual sleep obtained by the pilots was probably less than the sleep opportunity.
  3. The text messages referred to in this section were sent from the pilot under supervision to close personal contacts, including the pilot’s partner. Those contacts provided the content of relevant text messages to the ATSB.
  4. All times in this report are Western Standard Time (WST) unless otherwise stated. WST is UTC + 8 hours and Eastern Standard Time is UTC + 10 hours.
  5. Flight records indicate engine shutdown at 1714 on return from the last flight. Post-flight activities would have included a debriefing with the instructor and general housekeeping/administrative duties, including refuelling of the helicopter.
  6. Flight records indicate engine start at 1743 for the first MPT flight. Prior to this, the pilot under supervision would have needed to complete various sign-on tasks. Those tasks include attending the security gate to perform a routine alcohol screen, a review of weather forecasts for the night’s flying, completion of a pre-flight briefing with the instructor and a pre-flight inspection of the helicopter.
  7. The investigation was not able to obtain a record of all of the instructor’s work-related email activity.
  8. The Samn-Perelli rating scale was used for the self-evaluation of fatigue. The scale ranges from 1 (fully alert) to 7 (completely exhausted). A rating of 2 indicates ‘very lively, responsive, but not at peak’ and a rating of 3 indicates ‘okay, somewhat fresh’.
  9. The specification of engine torque limits was to avoid an over-torque condition causing damage to, or failure of the helicopter’s main transmission.
  10. Emergency floatation system: inflatable bags to provide water buoyancy in an emergency.
  11. The EC135 helicopter was certified by the European Aviation Safety Agency as a small rotorcraft under Joint Aviation Requirements 27 (JAR 27). The certification specifications indicated FAA advisory circular AC 27-1B provided the acceptable means of compliance to the certification specifications. The definition for the primary field of view was included in Change 7 of the advisory circular, published April 2016.
  12. Rigid rotor systems can generate large bending forces to the rotor shaft with cyclic movement or a change in the rotor’s plane of motion while the helicopter is in contact with the ground/deck. To monitor those forces and warn of an exceedance, the helicopter was equipped with a mast moment indicator (MMI).
  13. Sea waves are generated by the local prevailing winds. Swell waves are the regular, longer period waves, generated by distant weather systems. Total wave height is the combined height of the sea and swell waves on open water.
  14. Geoscience Australia (GA) defines the ending of civil twilight as the instant in the evening, when the centre of the Sun is at a depression angle of 6° below an ideal horizon. At this time in the absence of moonlight, artificial lighting or adverse atmospheric conditions, the illumination is such that large objects may be seen but no detail is discernible. The brightest stars and planets can be seen and for navigation purposes at sea, the sea horizon is clearly defined.
  15. GA defines the ending of evening nautical twilight as the instant in the evening, when the centre of the Sun is at a depression angle of 12° below an ideal horizon. At this time in the absence of moonlight, artificial lighting or adverse atmospheric conditions, it is dark for normal practical purposes. For navigation purposes at sea, the sea horizon is not normally visible..
  16. GA defines the ending of astronomical twilight as the instant in the evening, when the centre of the Sun is at a depression angle of 18° below an ideal horizon. At this time the illumination due to scattered light from the Sun is less than that from starlight and other natural light sources in the sky.
  17. The bulk carrier Squireship was about 288 m long and had deck floodlighting at the bow and on the accommodation quarters, which were about 260 m apart. The extent to which the lights would be seen as one light or multiple lights would depend on the distance away, orientation of the vessel relative to the helicopter’s position, meteorological conditions and factors such as diffraction when viewing through a windscreen. Even if multiple light sources were discernible, these would still provide very limited cues for orientation until the helicopter was in close proximity.
  18. The safety wire used has low tensile strength and is easily broken when operating the emergency door jettison handle. A break to the safety wire indicates that the handle has been moved from the secured position and, potentially, the door jettison system may have been partially activated. The emergency door jettison handles on VH-ZGZ, the other EC135 at Port Hedland, were secured by plastic tie wraps (cable ties). Those tie wraps had higher tensile strength than the normal safety wire and would make the handle more difficult to operate in an emergency. The tie wraps fitted to VH-ZGZ were replaced by safety wire a short time after the accident.
  19. The non-volatile memory of the WU retains snapshot data of the last 32 changes to the unit’s visual and audible warnings, typically covering the last 2 to 3 flights.
  20. The non-volatile memory of the CAD retains the last 256 failures, cautions and advisories, associated with a contextual snapshot of parameters such as engine torque, fuel flow and fuel quantity.
  21. The non-volatile memory of the VEMD retains flight report summaries for the last 32 flights and fault codes for the last 256 faults. Any failures and overlimit conditions are associated with the flight report and contextual parameter snapshots are recorded. On EC135 helicopters, the parameter snapshots related to main rotor RPM, torque and turbine outlet temperature.
  22. The position of the collective lever was measured in degrees, from zero at a ‘flat pitch’ rotor position, to about 100° when commanding maximum rotor pitch
  23. Although the helicopter operator did not have the necessary CASA approvals to conduct endorsement training under their own air operator’s certificate (AOC) at this time, the training was provided by qualified instructors operating under an appropriate AOC.
  24. Heliporters are battery operated transporters to assist personnel with helicopter ground handling.
  25. These surveys utilised an online survey development application.
  26. VTOSS: Take-off safety speed. For a rotorcraft, this is the minimum speed at which climb of the rotorcraft is achieved with 1 engine inoperative and the remaining engines operating within the operating limits specified in the rotorcraft’s flight manual for a take off.
  27. VY: Best rate of climb speed. Flying at this speed achieves the greatest increase in altitude over a given time period.
  28. Air Maestro is an online safety and operational tool with various features including for records management and rostering.
  29. This term is used in some regulatory domains for a document or set of documents that describe how an organisation will comply with all applicable legislative requirements, and how they will manage the safety of their operations. An exposition is broadly equivalent to an operations manual in other domains.
  30. The associated CASA instrument extended the FRMS approval of a number of operators at the same time for the same period.
  31. Due to a coding error, if the duty period was extended beyond 12 hours, the cells recorded as duty or flying would remain their normal colour.
  32. That is, 12 consecutive hours in the sleep log recorded as sleep. It should be noted that consecutive hours of sleep could legitimately be recorded on a sleep log even if a person awoke for brief periods.
  33. A phone call on the night of 13 March started at 1908 and lasted about 2 hours.
  34. FAID was initially known as ‘Fatigue Audit InterDyne’. It was subsequently renamed the Fatigue Analysis Tool by InterDynamics.
  35. FAID documentation stated scores of 40–80 were broadly consistent with a safe system of work. However, the threshold for deciding the acceptability of a roster needed to be set by an operator based on a fatigue hazard assessment, taking into account the fatigue-related hazards specific to the role or task, and determining the acceptable level of fatigue tolerance for that role or task. Without this assessment, the FAID program defaulted to a fatigue tolerance level (FTL) of 80.
  36. The ATSB notes that FAID scores (and the scores from any BMMF) need to be interpreted with caution. The Independent Transport Safety Regulator of New South Wales (2010) stated that, due to various factors associated with the model, ‘a FAID score of less than 80 does not mean that a work schedule is acceptable or that a person is not impaired at a level that could affect safety’. In addition, the US Federal Railroad Administration (2010) concluded that in some situations FAID scores between 70 and 80 can be associated with ‘extreme fatigue’.
  37. ATSB investigation AO-2011-102, VFR flight into dark night involving Aerospatiale AS355F2 VH-NTV, 18 August 2011.
  38. Spatial disorientation occurs when a pilot does not correctly sense the position, motion and attitude of an aircraft relative to the surface of the earth. Although not a requisite condition, spatial disorientation is much more frequently encountered in a degraded visual environment, when pilots are unable to establish their spatial position through external visual cues.
  39. Air Accidents Investigation Branch, Air Accident Report 5/88. Report on the incident to Sikorsky S-76A helicopter G BHYB near Fulmar ‘A’ Oil Platform in the North Sea on 9 December 1987.
  40. Air Accidents Investigation Branch, Air Accident Report 7/2008. Report on the accident to Aerospatiale SA365N, registration G-BLUN near the North Morecambe gas platform Morecambe Bay on 27 December 2006.
  41. Rice E,V. and Greear J.F. (1973) Underwater escape from helicopters. In Proceedings of the Eleventh Annual Symposium, Phoenix, AZ: Survival and Flight Equipment Association, 59-60. Cited in Brooks C. (1989) The Human Factors relating to escape and survival from helicopters ditching in water; AGRAD.
  42. Ryack, B. L., Luria, S. M., & Smith, P. F. (1986). Surviving helicopter crashes at sea: A review of studies of underwater egress from helicopters. Aviation, Space, and Environmental Medicine, 57(6), 603-609.
  43. Hytten K (1989) Helicopter crash in water: effects of simulator escape training. Acta Psychiatrica Scandinavica, Suppl. 355: 73-78. Cited in Coleshaw S (2010) Report for the Offshore Helicopter Safety Inquiry. Report No SC176.
  44. Summers F (1996) Procedural skill decay and optimal retraining periods for helicopter underwater escape training. IFAP; Willetton, Western Australia. Cited in Coleshaw S (2010) Report for the Offshore Helicopter Safety Inquiry. Report No SC176.
  45. Civil Aviation Authority (2014) Safety review of offshore public transport helicopter operations in support of the exploitation of oil and gas. CAP1145.
  46. The requirement for an operator to conduct their operations in accordance with an operations manual was contained in the Civil Aviation Regulations 1988, Regulation 215.
  47. The extra time available for emergency escape depends on the design of the system and other variables such as water temperature, water depth and the user’s breathing rate. A user would typically have somewhere between 10 to 20 breaths before the supplemental supply was exhausted.
  48. Those flights are typically conducted in support of the oil and gas offshore industry and during which, the operating environment also requires the use of survival (immersion) suits.
  49. CAP 1034, Development of a Technical Standard for Emergency Breathing Systems, UK Civil Aviation, 2013.
  50. Research Report Underwater Escape from Helicopters, European Union Aviation Safety Agency, 2020.
  51. This model of ELT was designed to activate using a 4.5 ft/sec impact operated g-switch, together with a 5-way g-switch detecting +12.5g along any of the ELT’s 6 orthogonal axes. Operation of either switch would activate the ELT.
  52. PELICAN is an acronym used by the helicopter manufacturer to describe the packing equipment line for integrated concept of avionic nouvelle (new avionics).
  53. RTCA DO-204, Minimum Operational Performance Standard for Aircraft Emergency Locator Transmitters 406 MHz
  54. This helicopter was the other EC135 based at Port Hedland (VH-ZGZ), which had been imported to Australia in 2008 from the United States.
  55. The ELT was not fitted at airframe manufacture but was installed soon after customer delivery.
  56. ATSB AO-2017-005, Collision with terrain following an engine power loss involving Cessna 172M, VH WTQ, 12 NM (22 km) north-west of Agnes Water, Queensland, 10 January 2017.
  57. ATSB AO-2009-072 (reopened), Fuel planning event, weather-related event and ditching involving Israel Aircraft Industries Westwind 1124A, VH-NGA, 6.4 km WSW of Norfolk Island Airport, 18 November 2009 (Released in November 2017).
  58. ATSB AO-2018-026, Loss of control and collision with water involving Eurocopter EC120B, VH-WII, 72 km north-north-east of Hamilton Island, Queensland, 21 March 2018.
  59. The Prescription of Type Ratings Excluded from CASR Part 142 Flight Training (Edition 6) Instrument 2018, signed 4 June 2018, directed that a number of type ratings including the EC135 type rating was not Part 142 training but was Part 141 training. This did not have any implications for the occurrence. 

Safety analysis

Introduction

The operator was contracted to provide helicopter transfers of marine pilots to and from ships at any time of the day or night according to the Port Hedland shipping schedule. These marine pilot transfer flights (MPT) were carried out as charter flights under the day/night visual flight rules (VFR) in twin-engine EC135 helicopters equipped for single-pilot instrument flight rules (IFR) operations. Night vision imaging systems were not required, nor utilised by the operator.

In this occurrence, VH-ZGA descended into the ocean during a positioning flight at night to Squireship, about 20 NM (37 km) offshore. This flight was the third line training flight at night as part of the operator’s process to induct a recently employed pilot into day and night operations at Port Hedland. This pilot was acting as pilot in command under the supervision of a company instructor pilot.

As was standard for this helicopter type, the EC135 was not equipped with a flight data recorder or cockpit voice recorder. In the absence of that data, the ATSB sought data from other sources, including GPS-based automatic dependent surveillance broadcast (ADS-B) data and the surviving pilot. When the ADS-B data was processed and analysed, it indicated that during circling and before final approach, the vertical component of the flight path and airspeed was abnormal for a period leading up to the accident. The surviving pilot was unable to recall specific details of the pre‑accident sequence.

Based on the derived flight path and contextual information such as environmental conditions, operator procedures, and operational capability, the ATSB identified 8 safety factors that contributed to the occurrence and 10 factors that, while not influential in the development of the accident, increased operational risk. These included 5 safety issues that related to helicopter equipment and operator processes, including fatigue management.

Safety issues not related to fatigue management were identified and addressed by the operator soon after the occurrence. Additionally, regulatory changes introduced following the occurrence, although not in response to it, imposed further requirements on MPT operations that will be categorised as aerial work carrying passengers.

This part of the report presents the evidence and arguments that relate to the identified findings. It also details consideration of concerns about aspects of the MPT operation reported to the ATSB that did not have any direct links to the occurrence or any related safety issues.

Local operational conditions

To operate a helicopter at night in accordance with the night visual flight rules (night VFR) while below 3,000 ft above mean sea level (AMSL), pilots were required to be clear of cloud and in sight of ground or water with visibility greater than 5 km. In addition, the Civil Aviation Safety Authority (CASA) strongly recommended that night VFR operations only take place in conditions that allowed the pilot to discern a natural visual horizon, or where the external environment had sufficient cues for the pilot to continually determine the pitch and roll attitude of the helicopter. This was actually a requirement unless the helicopter was equipped with an autopilot/stabilisation system or was a 2-pilot operation.

For the approach and landing to Squireship, there was no cloud or other atmospheric factor to reduce visibility below night VFR minima, but the visual cueing environment was degraded by the dark night conditions (low celestial lighting) and the scarcity of cultural lighting in the offshore environment. In preparation for arrival of the helicopter, the external lighting of Squireship would have been maximised and provided local illumination greater than a single point light source. Although this was useful as a visual reference point for a circuit and as a sight picture for profile management on final approach, it would not have provided sufficient visual cues to determine the helicopter’s pitch and roll attitude throughout the circuit.

Although Squireship was being operated near low intensity lighting associated with marking of the shipping channel, this would have provided only limited visual cues. Furthermore, as Squireship was underway at 12–13 kt, the relationship between the channel markers to the ship landing area was not constant and therefore of limited value as references for a circuit. Similarly, while there were a number of other illuminated ships in the Port Hedland area, these would have provided little to no visual assistance to the pilots.

Operations in a degraded visual cueing environment increases the difficulty of a pilot’s task in terms of continually maintaining awareness of the helicopter’s position, and therefore increases workload. Research by the FAA (Hoh, 1990) has shown that operations in a degraded visual environment result in a degradation of the effective handling qualities … due to a loss of the ability of the pilot to adequately perceive fine-grained detail in the visual environment. The degraded handing qualities result in a substantial increase in pilot workload simply to control the helicopter. This leaves very little excess workload capacity to maintain situational awareness (i.e., awareness of distances and rates with respect to obstacles and the ground)

As the helicopter was equipped with an integrated autopilot/stabilisation system, and the pilots held the appropriate ratings, the circuit and approach to the ship in a degraded visual cueing environment was within the allowable operational parameters. However, manoeuvring safely in this environment at low altitudes was highly demanding and required a high level of instrument flying proficiency integrated with visual flying skills, adherence to procedures, and effective use of automation.

Although pilot workload was generally high in these conditions, it was probably higher for both pilots during the occurrence flight because this was the third flight in the planned sequence of 10 line training flights at night and it was only the second night MPT to C1/C2. In the operational context, as the pilot under supervision had not yet passed a line check, the instructor was required to monitor the helicopter flight path and provide guidance/support as required. Additionally, there were factors discussed later that negated the effectiveness of the instructor.

Contributing factor

During the positioning flight for the third supervised marine pilot transfer at night, circling in the vicinity of outbound bulk carrier Squireship was conducted in a degraded visual cueing environment, with associated increases in pilot workload and risk of disorientation.

Management of automation during visual circling

Introduction

The helicopter was equipped with a stability augmentation system (SAS) and 3-axis autopilot that provided basic attitude hold and pilot-selectable ‘upper’ modes to control airspeed, heading/track, altitude, and vertical speed. In the default SAS mode, the system would hold the last commanded attitude until the pilot made an adjustment by moving the cyclic - with or without force trim release (FTR) - or using the BEEP TRIM switch. If the helicopter was above both an airspeed of 60 kt and 500 ft above the ground or water, the pilot could engage an upper mode(s) to achieve a flight path within specified parameters.

Although the operator did not have a documented procedure for the management of automation during MPT operations, the chief pilot advised pilots to operate with an upper mode engaged during circling at night until the helicopter passed the ‘finals gate’ (500 ft and 60 kt) on final approach. The instructor similarly advised the ATSB that such use of automation was standard practice and would have been implemented on the occurrence flight.

However, as there was no recorded data of automation selections and the instructor recalled limited specific detail of its use, the ATSB sought to characterise the management of automation by analysing the ADS-B data.

First circuit and go-around

Analysis of the ADS-B data identified that the first inbound descent to Squireship was at a steady rate of 500 ft/min and the helicopter levelled at 700 ft in the vicinity of the ship. This was consistent with engagement of the autopilot in a vertical upper mode. Due to a gap in the data, it was not possible to characterise autopilot use in the first part of the downwind segment of the circuit.

By about mid-downwind, data points indicated that the circuit altitude was steady. During the base segment, the helicopter climbed slightly and was about 825 ft turning onto final approach, which was contrary to the SOPs that required a descent from circuit height and join final approach at 500 ft. This indicates that an upper vertical mode was probably no longer engaged, and pilot control inputs were not effective to manage the flight path of the helicopter.

Provided airspeed was maintained above 60 kt, the ALT.A (altitude acquire) autopilot mode was capable of managing the descent from 700 ft to 500 ft during the base turn, and this was the operator’s recommended method until the helicopter was through the ‘finals gate’ and positioned for a continuous descent on the nominated descent profile.

Although the helicopter was about 300 ft higher than the target for commencing the final approach, an effective descent rate was not achieved, and the helicopter remained high on profile. When the helicopter was 275 m from the landing hatch (at about 500 ft and 31 kt), the airspeed started to increase, consistent with initiation of a go-around. However, a further 175 ft was then lost over a 22-second period before a positive rate of climb was established. This height loss in the early stages of the go-around was not consistent with recommended practices that prioritised a climb to a safe altitude. The instructor advised the ATSB that the autopilot was engaged during the climb phase of the go-around and the data supported that recollection.

Sustained deviations from the specified flight path on final approach and height loss in the go‑around can be associated with decrements in visual perception, instrument scan, and/or helicopter handling. The human factors aspects of these potential factors are addressed in a later section.

On final approach, handling of the helicopter by the pilot under supervision would have been influenced by the ongoing transition from a different type of helicopter, including interaction with the SAS. Any of the 3 available methods to adjust the helicopter’s attitude could have been applied on final approach depending on operational imperatives such as the rate, magnitude, and duration of the intended attitude change. Given there was no recorded data or applicable observation, it was not possible to establish the method of attitude adjustment used.

Despite that, as the Transportation Safety Board of Canada found in relation to the S‑92A occurrence in Nova Scotia, use of FTR in a degraded visual environment can increase pilot workload and contribute to control difficulties and an unstable approach. If that occurred, it would have compounded the high workload of the pilot under supervision that was associated with transition from a different helicopter type without the benefit of automation.

Second circuit

By the time the helicopter reached 1,100 ft in the go-around, the helicopter was being turned onto the downwind segment of a circuit to position for another approach in the same orientation to the ship as the first approach. About 30 seconds later the helicopter was on descent. The rate of descent developed quickly to 800–900 ft/min, steadied at about that rate for about 30 seconds, then increased further as the helicopter turned onto a base segment and descended through 500 ft.

Assuming the target circuit altitude was 700 ft in accordance with the operator’s standard operating procedures (SOPs) and consistent with the first circuit, the descent below circuit altitude and the high descent rate (above 500 ft/min) were not consistent with use of ALT.A or other vertical upper mode. This was contrary to the instructor’s recollection that the autopilot was used for circling. However, the ATSB also noted that the instructor did not advise of any confirmatory details, such as specific mode selection and annunciation or conforming flight path. It is therefore possible that the instructor assumed that the expected operator’s autopilot practices were implemented.

In the context of high workload associated with the transition from a go-around to another circuit in a degraded visual cueing environment, it is possible that operating in the default SAS mode rather than making upper mode selections was considered to be easier. Another possibility is that the vertical autopilot mode might have been perceived as unsuitable to manage the intended flight path due to the required higher than usual rate of descent. A further possibility is that either or both pilots incorrectly thought that a vertical mode had been engaged but did not identify the contrary indications such as mode annunciation and abnormal flight path.

The observed general practice during the circuits of previous line training flights (10 by day and 2 by night) was to manage vertical navigation in the pre-final phases with autopilot rather than pilot control inputs. However, it was also noted that the instructor conducted 5 night circuits in January 2018 without apparent use of an autopilot vertical mode to manage the flight path in the circuit prior to joining final approach.

If an autopilot vertical mode such as ALT.A had been used to capture and hold the circuit altitude of 700 ft then descend to 500 ft, the accident would almost certainly have been averted. While there was insufficient evidence to determine why a vertical mode was not selected during the final descent, the potential influence of pilot fatigue and the operator’s circuit procedures are considered later in the analysis.

Contributing factor

Following a circuit, missed approach, and climb to 1,100 ft, a descent was initiated without coupling a vertical navigation mode of the autopilot. This was not consistent with standard operational practices and significantly increased the attentional demands on both pilots and the associated risk of deviation from circuit procedure.

Inadvertent descent below 500 ft

Abnormal flight path and associated parameters

As the helicopter descended through 500 ft, the descent rate increased above 1,000 ft/min while the airspeed reduced below 50 kt. This occurred while the helicopter was turning right from the downwind onto base segment of the circuit, about 1,950 m from Squireship.

The descent rate continued to build rapidly, and the airspeed reduced further, but neither of these significantly abnormal parameters appear to have been detected by either the pilot under supervision or the instructor. According to the instructor, activation of the radio altimeter alert at 300 ft was the first prompt to take over control and initiate a go-around. At about this time the ADS-B data showed the rate of descent was about 1,700 ft/min and the airspeed was just above 30 kt.

Although the instructor advised the ATSB that the helicopter was on final approach before the descent into water, this was not consistent with the position and heading/track of the helicopter as it descended below 500 ft during the base turn. Based on the orientation of the helicopter relative to Squireship, it is likely that the instructor’s view of the ship (from the left seat) was obstructed as it was in the approximate 2‑o’clock position relative to the helicopter nose. The disparity between the instructor’s recollection of helicopter position and the flight data indicates a level of disorientation during the sequence and/or mis‑remembering after the event.

The instructor did not recall any communication with the pilot under supervision regarding the relative position of Squireship during the second circuit. Seated on the right side of the helicopter, the pilot under supervision had relatively unobstructed views of the ship during the right circuit and could be expected to periodically reference Squireship for circuit position information. It is possible to detect changes in height and vertical trend by observing movement of the ship relative to cabin features. For example, during a descent with a consistent attitude, the vertical position of Squireship would have moved up relative to the windscreen or cockpit windows. This, however, would have been low resolution information, disrupted by changes to pitch/roll attitude and attenuated by distance from the ship. Seated on the left side of the helicopter, the instructor’s view of the ship would probably have been obstructed for brief periods.

Irrespective of how the 2 pilots perceived the relative position of the helicopter, it was not tracking toward the ship at any stage of the second circuit. In that context, the SOP was to not descend below 500 ft and not reduce airspeed below 60 to 65 kt. Both pilots were presumably aware of the importance of these limits, especially for night operations, but seemingly did not identify the deviation.

When the descent rate exceeded 500 ft/min and continued to increase, it was outside the industry practice for circling at night over water below 1,000 ft. The descent rate of 1,000 ft/min when the helicopter was passing 500 ft was double the rule-of-thumb amount for descent rate proportional to height. At the maximum descent rate of 1,700 ft/min, passing 300 ft, the helicopter was descending at 5 times more than the rule-of-thumb figure (300 ft/min). As discussed further in a later section, the operator did not specify rate‑of‑descent parameters for operations above 30 kt.

Operational requirements

After the missed approach and climb to 1,100 ft, a descent was required to circuit height and the pilots might have intended a relatively high rate of descent to ensure they were not high on final approach. In that context, the physical (vestibular) sensations associated with the very high descent rates would not have provided a reliable cue for detection of the abnormal flight path.

To manoeuvre an aircraft in a degraded visual cueing environment, the pilot must consistently scan the flight instruments and assimilate pitch and roll information, combined with reference to other instrument indications - airspeed, altitude, rate of descent, heading – according to operational priorities. Visual circling also requires periodic reference to the landing area and any visible terrain features for position information, possibly supplemented by GPS data. These actions are required whether the pilot is controlling the aircraft manually or through autopilot selections. This is a complex information processing task that generally requires a high level of aircraft handling skill and instrument flying proficiency.

To manage the flight path of a helicopter through control inputs, the pilot manipulates power/torque (main rotor thrust) through the collective control in combination with selection of attitude (pitch and roll) through the cyclic control. In simple terms, for a given power/torque, the cyclic input will influence airspeed and rate of climb/descent (see Appendix D for further detail).

Role of pilot under supervision

While the pilot under supervision had held an EC135 type rating for a number of years, experience on that type was not substantial and none of it was recent. This was addressed by refresher training and a type rating flight review on arrival at Port Hedland. After 10 ship landings by day, the pilot under supervision was approved by the instructor for day MPT operations.

As the holder of a night VFR rating and current flight review, the pilot under supervision was considered competent to operate at night in visual meteorological conditions. Although this was a necessary qualification for the MPT operation, further training was required to prepare pilots for the inherent challenges and risks of ship landings and take-offs in an offshore environment at night.

In recent night flying for a previous operator using night vision imaging systems (NVIS), the pilot under supervision had demonstrated instrument flying proficiency as part of normal NVIS flying and simulated system failure conditions. However, due to the enhancement provided by NVIS, the previous flying provided relatively fewer opportunities to maintain proficiency in the integration of instrument and unaided visual data while operating in degraded visual cueing environments.

Since leaving the previous operator, the only night or instrument flying conducted by the pilot under supervision was on the night of the occurrence. The ADS-B data showed that the pilot under supervision was able to conduct the circuits on the previous 2 night flights and on arrival at Squireship, but was having difficulty maintaining the helicopter on a constant-angle final approach.

In the early stages of the transition from previous night operations over land using NVIS to unaided night VFR over water, the relative absence of visual cues might have had a disorienting effect during circling and approach with associated increase to workload. The pilot under supervision was also transitioning from previous operation with analogue instruments to an integrated digital display, which required a different type of scan and more effort (initially) to interpret the data. In addition, considering the pilot was now operating a helicopter with different handling characteristics and equipped with a complex autopilot/stabilisation system, manoeuvring the helicopter was likely demanding during the transition period.

In combination, these factors probably led to a relatively high workload associated with the transition to night operations that would have affected the capability of the pilot under supervision to manage the flight path and monitor critical parameters. Significantly, in a degraded visual cueing environment, a high level of attention to the primary flight display is required to detect and correct abnormal operation.

In addition to high workload, diversion of attention or inattention might have occurred for the following reasons:

  • disproportionate attention to the limited visual cues
  • lower intensity monitoring of flight instruments on the (incorrect) basis that an autopilot vertical mode was engaged
  • instructor communication about the first approach, go-around, and next approach.

During the process of adapting to unaided night VFR it is possible that the pilot under supervision was seeking visual cues that were not available without the enhancement provided by NVIS. Alternatively, the lack of visual cues might have reinforced the need for reliance on instrument flying in the circuit. The pilot under supervision’s successful manoeuvring of the helicopter with reference to the ships in the 2 preceding night flights and first approach to Squireship supports that latter as circling would have required the use of flight instruments.

From the ADS-B data it is apparent that the autopilot was not engaged in a vertical upper mode but could have been engaged in a lateral mode. If that was the case, the pilots might have associated this with a fully coupled condition and not been aware of the mode status. Complicating identification of an uncoupled upper mode is the default SAS mode that will hold the last commanded attitude. Although there is a mode annunciation on the PFD, this might not be a specific item of the routine instrument scan and was not in the primary field of view of the instructor.

Given the lack of detail in the instructor’s recollection, it is not clear if the instructor provided feedback to the pilot under supervision after the first approach and go-around with advice for the next approach. Such feedback would be consistent with the instructor’s training role and the operational imperative to land off the second approach. However, the as-found intercom selection would have isolated the pilot under supervision from the attentional demands of any feedback, depending on when that selection was made.

From the available information it was not possible to determine if any of these elements diverted the attention of the pilots during the second approach to the ship.

Role of flight instructor

The instructor held an instructor rating, night VFR rating and instrument rating with CASA approvals to train and examine pilots for those ratings. In regard to the EC135 helicopter, the instructor held the type rating and CASA approval to issue the rating. As such, the pilot was qualified to conduct, instruct, and assess night and instrument flight from the right or left seat of EC135 helicopters. Based on these qualifications and MPT experience, the instructor met the operator requirements for a training and checking pilot.

In addition to CASR Part 61 requirements, the operator required a base check and line check every 12 months to ensure that pilots were able to operate the EC135 type and conduct MPT in accordance with SOPs. Based on the operator’s pilot records, the instructor was within the validity periods of both checks but there was contradictory information about the last line check. The ATSB analysed all of the available information and concluded that the instructor was probably line checked on 5 April 2017 but there were variations from SOPs that were not recorded.

Since that check the instructor had been operating EC135 helicopters in a mix of line flying and flight training/assessing, including a number of ship landings by day and night. The ATSB analysed the ADS-B data for the instructor’s previous night MPT flights at Port Hedland in January 2018 and identified deviations from SOPs by the instructor.

Having operated EC135 helicopters for about 2.5 years, the instructor was familiar with the format of the integrated digital displays. Although this was an advantage, the 2 EC135 helicopters at Port Hedland were single-pilot variants with modified instrument panel/consoles and flight instrument configuration. For the instructor in the left seat, this could undermine monitoring effectiveness, especially at night. The instrument panel configuration is addressed further in a later section.

During line training for a single-pilot operation, the instructor was the pilot in command but generally not directly involved in operation of the helicopter. This role is primarily to support a pilot with the appropriate licences, ratings, and experience to acquire the knowledge and develop the skills specific to the operation. To do that effectively, the instructor needed to monitor the flight path and critical parameters, alert the pilot under supervision to any sustained deviations from SOPs, and provide advice before, during, and after the flight. Critically, if the pilot under supervision was unable to operate the helicopter within acceptable parameters, the instructor was expected to intervene and take over control before a dangerous situation developed.

As outlined previously, conduct of the line training role in the context of the non-conforming first approach, go-around, and descending transition into the second approach was intrinsically high workload for the pilot under supervision. For the Grade 1 instructor and flight examiner it should have been significantly less so, especially in the context that their role provided the key assurance of safety.

Diversion of attention or inattention might occur in this operational context for the following reasons:

  • disproportionate attention to, or over reliance on, limited visual cues
  • lower intensity monitoring on (incorrect) basis that autopilot vertical mode engaged
  • communication with pilot under supervision about go-around and next approach
  • lower intensity monitoring on basis that pilot under supervision was controlling the helicopter.

In the context of higher workload associated with reference to the primary flight display, the instructor might have prioritised visual cues over instrument data. This might be correlated with the instructor account that the helicopter was on final approach when the water impact occurred. Additionally, when the instructor was flying at Port Hedland in January 2018, altitude maintenance at night was less consistent when the pilot lost sight of the ship during circling.

The instructor advised the ATSB that it was standard practice to use the autopilot including vertical mode until reaching the final ‘gate’. However, as the flying at Port Hedland in January 2018 showed, this does not appear to have been consistently applied. For the instructor in the left seat, the autopilot mode annunciation was also not salient and probably not part of a normal scan.

As discussed in the previous section, it is not clear when the instructor might have been providing feedback on the first approach and go-around with advice for the next approach. If there was difficulty communicating with the pilot under supervision as a result of the intercom selection, this would have been distracting and possibly delayed corrective action.

From the instructor’s perspective, the pilot under supervision was controlling the helicopter until the radio altimeter alert at 300 ft. On that basis and given the pilot under supervision had conducted the 3 previous downwind/base segments at night without apparent problems, the instructor might have been less attentive to the primary flight display or standby instruments during this phase of flight.

Consideration of influence

It is apparent from the right turn onto base late in the sequence that lateral control inputs were being applied. Some reference to the primary flight display or standby attitude indicator might be expected during this manoeuvre but neither pilot identified the excessive descent rate. This suggests a loss of situation awareness and possibly some level of disorientation that also had implications for the recovery actions discussed in the next section.

In line training for a single-pilot operation, the pilot under supervision operates the helicopter as if in command and the supervisory pilot (as pilot in command) monitors, advises, and intervenes as required. When circling at night in a degraded visual cueing environment during a line training flight, both pilots were required to apply instrument flying skills integrated with reference to any relevant visual cues.

If the operational roles for line training were maintained down to 300 ft, as related by the instructor, the implication is that there was a breakdown in the instrument scan of both pilots. For this analysis, this is considered as the default scenario (1).

As discussed, the workload was high for both pilots in their default roles, but their individual qualifications and experience should have been sufficient for either pilot to detect the abnormal flight path. Given their qualifications and experience, this was especially true of the instructor. This infers that both pilots were diverted from, or otherwise inattentive to the primary task of instrument flying, for reasons that could be independent or interrelated. Fatigue as a factor potentially affecting the performance of both pilots is considered later.

In an alternative scenario (2), if the instructor had taken over control of the helicopter after the first approach, the pilot under supervision would not be obligated to monitor the primary flight display. As such, management of the flight path would rely on the instructor, and 2 of the factors to be considered later – instrument panel configuration and capability in degraded visual cueing environments – might have affected the capacity of the instructor to control the flight path.

The ATSB acknowledges that the instructor recalled taking over 300 ft and the ADS-B data shows a partial recovery from that point. However, the instructor did not recall the sequence of events in detail, and recollection of circuit position before the impact was incorrect. Given memory of an event can be distorted by various factors, the ATSB considered the conditions that related to scenario 2.

In principle, the scenario in which the instructor takes over control to relieve the pilot under supervision after the go-around has instructional advantages. By taking over, the instructor can provide feedback with a demonstration of technique and desired outcome while allowing the pilot under supervision to rest, observe and assimilate information.

A further consideration for the instructor is the time available to transfer the marine pilot from Squireship to the port then return to C1/C2 to pick up the marine pilot from the following outbound ship. The shipping schedule did not allow for any additional flying time so after the missed approach, there was an operational imperative to land off the next approach. In that context, it would generally be an advantage for an MPT-qualified instructor to take over control. However, on this occasion the instructor might have considered that workload associated with cross-cockpit instrument scanning, and prior experience in a degraded visual cueing environment nullified the advantages of taking over. And, if the instructor felt fatigued, the monitoring task might have been considered less risk than controlling the helicopter.

The ATSB noted a correlation between the second circuit around Squireship and the instructor’s previously observed actions when flying at Port Hedland to not use a vertical upper mode in the circuit with high descent rates developing during the base turn. This suggests that instructor might have been flying the helicopter during the second circuit but was inconclusive.

The ATSB considered that the evidence related to who was flying the helicopter during the second circuit was ambiguous. Irrespective of who was controlling the helicopter, the prime responsibility of the instructor as pilot in command was to ensure the safety of the flight.

Contributing factor

During the downwind and base segment of the circuit, the pilots did not effectively monitor their flight instruments and the helicopter descended below the standard circuit profile at excessive rate with decaying airspeed. Neither pilot responded to the significantly abnormal flight path or parameters until the radio altimeter alert at 300 ft.

Radio altimeter alert and pilot response

When the radio altimeter alert activated at 300 ft the rate of descent was about 1,700–1,800 ft/min and the airspeed was about 34 kt. As related by the instructor, that alert was the prompt to take over control and conduct a missed approach (go-around). Despite that, by 200 ft, the descent rate was still about 1,700 ft/min then reduced to about 1,300 ft/min at water impact.

Without intervention, the rate of descent would have continued to build and the impact with water may not have been survivable. Although the action reported by the instructor had a positive effect by reducing the rate of descent, the ATSB considered the range of potential actions and outcomes in the accident scenario.

Setting the radio altimeter alert to 300 ft for every approach was intended to be an aural and visual cue for a nominal committal height. Initiation of a missed approach as reported by the instructor implied an awareness that the flight path was abnormal and outside the operator’s stabilised approach criteria (rate of descent exceeding 700 ft/min when operating below 30 kt airspeed). However, the instructor was unable to recall any critical details that might have been derived from the flight instruments or external reference during this phase and the collision with water was unexpected.

The time interval from the radio altimeter alert at 300 ft to water impact was about 12 seconds. From 300 ft, if a nominal reaction time of 4 seconds and descent rate of 1,700 ft/min was applied, the helicopter would have descended an additional 100 ft before pilot inputs were made. This was not reflected in the data, which showed the descent rate stabilised by 200 ft. As such, the pilot response time was shorter, or the helicopter response was almost instantaneous. In either case, the instructor was able to make further inputs during the 7-second period between 200 ft and the water surface.

The ATSB considered the potential for vortex ring state (see Appendix D) to have prevented recovery prior to water contact. However, a review of ADS‑B data identified that the application of collective reduced the rate of descent, so that was considered unlikely.

With both engines operating, the EC135 had a significant surplus of engine power/torque that could be applied through the collective to reduce the descent rate. At the request of the ATSB, Airbus Helicopters replicated the accident scenario in an EC135 simulator and found that the helicopter could be recovered from as low as 100 ft if the appropriate go-around procedures were carried out.

The data collection units (DCUs) for each engine recorded a set of parameters in response to the main rotor impact with the water and engine ingestion of water. Given the high descent rate and rapid inversion of the helicopter, it is likely that the data was recorded early in the accident sequence and is an indicator of engine operation immediately before the impact.

The data indicates that both engines were operating normally up to the collision with water and were not operating at or near maximum power/torque when those parameters were recorded. This is not consistent with optimisation of the performance of the helicopter, as would be expected for a go-around, especially in an emergency situation. This could have reflected the instructor’s disorientation at the time and/or missed approach technique.

The ATSB did not have any comparative data that included a missed approach conducted by the instructor but the missed approach immediately preceding the accident was supervised by the instructor. Although the ADS-B data indicates a missed approach was initiated at 500 ft, the helicopter descended to 325 ft over a period of 22 seconds before a climb was achieved, contrary to standard practice that prioritised obstacle clearance. If that technique was applied to the subsequent missed approach, recovery was unlikely.

It is instructive to look at the flight data from the 5 January 2018 night flights - where the instructor was flying during line operations - for 2 related reasons. Firstly, on 2 of those approaches, the rate of descent exceeded the specified parameters and the instructor recovered without conducting a go-around. Secondly, the data suggests that initiation of some flight path corrections and recoveries were coincident with the routine radio altimeter alert at 300 ft.

It is therefore possible that the instructor responded to the radio altimeter alert in a manner consistent with the pattern evident in the comparison flights in January 2018. That is, collective input was consistent with a profile correction rather than a go-around. The ATSB also identified that the instrument layout in the helicopter probably hampered the instructor’s response following the radio altimeter alert. This is discussed further in a following section.

The radio altimeter alerting function is recognised as an effective risk control for controlled flight into terrain/water. By setting the alert for 300 ft, the operator was conforming to a standard industry practice that appeared to be effective in almost all cases. The ATSB is unaware of a safety case for increasing the height of this alert, although some operators prescribed an additional alert at 500 ft.

Contributing factor

The instructor responded to the radio altimeter alert, reducing the rate of descent from about 1,800 ft/min to 1,300 ft/min, but this response was not consistent with an emergency go-around and did not optimise recovery before collision with water.

Survival scenario and outcomes

Survival scenario

Both pilots were equipped with the standard safety equipment including flight helmets and inflatable personal flotation devices with distress flares and personal locator beacons. At the time of the occurrence the operator did not provide emergency breathing system (EBS) for MPT pilots and was not required to do so. The helicopter was equipped with an emergency floatation system and life rafts.

The instructor advised the ATSB that the collision with water was unexpected, and there was no indication that the pilot under supervision was aware of the helicopter trajectory and impending collision with water. As such, there was no opportunity to attenuate the impact forces (abrupt pitch and/or power changes) and the pilots were not mentally or physically prepared for immersion in the sea.

Although the helicopter descended into the water in a relatively level attitude, it immediately inverted as a consequence of its trajectory at impact, reaction to the main rotor blades striking the water, and its inherently high centre of gravity. The distortion to the transmission deck and the force of water during the impact sequence fractured the left main cockpit windscreen and left cockpit chin window, which flooded the cockpit.

The helicopter was fitted with an emergency flotation system, that was capable of both automatic and manual inflation. Although the system was armed in accordance with the SOPs, the floats did not automatically inflate when the helicopter entered the water. There were no system defects and non-activation was attributed to rapid inversion of the helicopter. Float inflation was not manually selected and it is unlikely that post-impact inflation would have altered the survival outcomes as, even without activation, the helicopter remained afloat for a time period in excess of that required to exit the cabin.

Immediately following the impact sequence, the pilots were strapped in their seats within the inverted helicopter cabin that had quickly flooded with sea water. The helicopter was not equipped with emergency egress lighting and electrical power was probably lost during the accident sequence. Consequently, the pilots were in total darkness and probably experiencing shock from the sudden and unexpected onset of the dynamic impact sequence. In a very challenging survival situation, the initial flotation of the helicopter, sea state, and relatively warm water were advantageous.

However, without air to breathe in the flooded cabin, survival was dependent on escaping the cabin in a critically short time period. Pilots (and passengers) engaged in offshore operations are generally trained to do this by:

  1. orienting themselves in the cabin relative to their emergency exit
  2. operating the emergency exit
  3. releasing their seat belt while retaining a fixed reference point
  4. exiting the cabin and swimming to the surface.

Both pilots were seated next to access doors that functioned as their respective emergency exits. These doors could be fully released from the fuselage by operating the door handle then pushing the jettison lever downwards. The seat belt was released by rotation of the latch.

Neither of the pilot doors had been opened and the left door (instructor side) jettison lever was the only door handle/lever that had been operated to release the hinges. Both seat belts were undamaged and unlatched. The ATSB found that the door mechanisms and seat belts were capable of normal operation.

Instructor escape

Although aware of the jettison lever and door release process, following immersion the instructor was unable to operate the door and did not recall operating the jettison lever. This was not consistent with the recommended practice to identify then operate the emergency exit but was not critical on this occasion.

The instructor advised that the hole in the windscreen was located and the seat belt was released while holding onto the edge of the opening. After being initially restrained by the helmet cord, the instructor managed to swim out and to the surface. The sequence of identifying the exit then releasing the seat belt was consistent with the recommended practice.

From the instructor’s perspective, helicopter underwater escape training (HUET), last carried out in September 2015, helped with the escape and previous diving experience at night probably helped with orientation in the flooded cabin. One of the elements of the annual Civil Aviation Order (CAO) 20.11 check carried out with the instructor in July 2017 was operation of the emergency exits.

Pilot under supervision non-survival

The pilot under supervision did not escape and was later recovered from the cockpit area of the submerged helicopter. As the instructor did not recall any awareness of the pilot under supervision post‑impact, there was limited information about the pilot’s non-survival.

Based on the unfastened seat belt and helmet, and absent any intervention by the instructor, the pilot under supervision was conscious post-impact and had attempted to escape. Non-operation of the door handle or jettison lever for the adjacent exit door indicated that the pilot under supervision was probably disoriented and/or unable to recall or carry out the first 2 steps of the recommended escape sequence. Locating and operating the door handle and jettison handle before releasing the seat belt is essential for maintaining orientation.

At some point, the pilot under supervision might have realised that the instructor had escaped and attempted to follow the same exit path. If the pilot under supervision found the left door on the instructor’s side was still closed, it would have been disorienting, and might account for operation of the jettison lever.

The pilot under supervision had last completed a HUET course in 2011, which was well outside the operator’s requirements for MPT pilots to complete the course at 3-year intervals. This was identified as a safety factor and is addressed later in this section. Having completed the CAO 20.11 check conducted by the chief pilot on 5 March 2018, the pilot under supervision should have been familiar with operation of the EC135 emergency exits and been reminded of recommended underwater escape practices.

Contributing factor

After the unexpected and significant water impact in dark conditions, the helicopter immediately rolled over and the cabin submerged then flooded. The instructor escaped through an adjacent hole in the windscreen and used flotation devices until rescued but the pilot under supervision was unable to escape the cockpit and did not survive.

Helicopter underwater escape training

The chief pilot was aware that the pilot under supervision had not completed HUET in the previous 3 years and had arranged for a course as soon as possible. This was scheduled in the month following the planned line training at Port Hedland. Although the training and checking section of the operations manual allowed the chief pilot to extend the period between HUET courses, any extension was not expected to be more than 6 months. The ATSB noted that the operator’s requirements for HUET varied according to the base of operations, which was potentially confusing, but not a factor in this occurrence.

Marine pilot transfer operations are predominantly over water and often conducted in challenging offshore conditions. By utilising multi-engine helicopters, the operator reduced the risk of a ditching but as this occurrence shows, it did not preclude an inadvertent descent into the water and underwater survival scenario. The ATSB noted that the operator only required HUET for night MPT at Port Hedland, which reflected a higher risk profile than day MPT.

To ensure that pilots were able to manage emergencies in the EC135 type, the operator provided periodic CAO 20.11 checks that included operation of the emergency exits. These checks were primarily knowledge assessments and did not provide opportunities to practice skills in simulated emergencies. Although the recent CAO 20.11 check would have beneficial to the pilot under supervision and provided an opportunity to rehearse HUET procedures with touch drills, this was not considered to be sufficient to reduce the risk of offshore operations.

HUET is widely accepted as a necessary and effective risk control for offshore operations. Through exposure to simulated underwater escape scenarios including an inverted cabin in darkness, pilots (and passengers) are better prepared to implement the recommended procedures in adverse conditions.

Having completed HUET on 2 occasions, the pilot under supervision would have been aware of the principles and challenges of underwater survival. However, the ability to recall the procedures and carry them out after a sudden and unexpected impact sequence and in adverse conditions would been diminished by their lack of recency.

Given the lack of information about the post-impact capability and actions of the pilot under supervision, it was not possible to establish if HUET conducted with the preceding 3 years would have made a difference to the outcome. Despite that, based on the value ascribed to HUET by the offshore industry and the benefit claimed by the instructor in this occurrence, the lack of HUET recency was a factor that increased the risk of disorientation and non-survival.

This issue was discussed in the ATSB preliminary report and a safety advisory notice was issued.

Other factor that increased risk

The operator rostered the pilot under supervision for marine pilot transfer flying without ensuring that helicopter underwater escape training (HUET) had been completed in accordance with the operations manual. Although the pilot under supervision had completed HUET in 2009 and 2011, the lack of recency reduced preparedness for escaping the helicopter following submersion.

Instrument panel configuration

Context

In the context of this occurrence, development of the abnormal flight path was associated with insufficient attention to key parameters displayed on the primary flight display (PFD) or standby flight instruments. One of the factors that could have affected the pilots’ capacity to monitor the flight path and parameters in a degraded visual cueing environment was the instrument panel configuration of the 2 EC135 helicopters based at Port Hedland.

Instead of a centrally-oriented instrument panel with duplicated PFDs/navigation displays (NDs), the instrument panels of VH-ZGA and VH-ZGZ were oriented asymmetrically to the default pilot‑flying position (right seat) with the single set of displays offset to the right of the forward-view centreline. As a related variation from a standard EC135, the standby flight instruments were not the standard analogue set but a digital MD302 standby attitude module.

For the pilot under supervision in the right seat, the offset PFD/ND was adjacent to the standard position and not considered to be a disadvantage for instrument flying. However, when flying a visual approach, the pilot in the right seat had a more restricted external field of view relative to the typical panel. Although pilots generally adjusted to this and there was no evidence it was non‑compliant with certification guidance, it could have contributed to the inconsistent descent profiles of the 2 previous approaches. However, given the abnormal flight path occurred in the phase of flight where instrument reference rather than visual cues required most attention, the panel/console configuration was not considered to have affected the pilot under supervision.

The instructor advised that when operating from the left seat in VH-ZGA and VH-ZGZ, the PFD was the preferred source of flight information because of the relative size and brightness of the digital display. From instructing and assessing in the left seat of the standard EC135s and flying from the right seat of all of the operator’s EC135s, these displays were familiar. The instructor advised that the PFD in VH-ZGA was clearly visible from the left seat and allowed the monitoring role to be performed but cross-cockpit scanning increased workload and duplicate displays in a co-pilot panel were preferred. The instructor also advised of experience with cross-cockpit monitoring of instruments during earlier flying as an aeroplane instructor.

After further consideration, the instructor emphasised the high workload associated with addition of the cross-cockpit scan and their inside/outside scanning pattern. The instructor recalled that on the second approach to Squireship (after the radio altimeter alert occurred at 300 ft), the transition to the PFD and assessment of vertical speed was very difficult. For the instructor, opportunities to identify the rate of descent were limited by the ‘unreadability’ of the altitude trend bar on the standby instrument indication and location of the vertical speed indicator on the far (right) side of the PFD.

Overall, the instructor considered the instrument configuration to be compliant with regulations, consistent with industry practice, and suitable for most operations. However, in the context of the occurrence flight, the instructor found the operation to be difficult and considered that the outcome would probably have been averted if a primary flight display had been located in a co-pilot panel.

Use of the primary flight display

An advantage of cross-cockpit reference to the PFD as advised by the instructor was access to a large format attitude indicator. Even if this advantage was attenuated by higher workload associated with cross-cockpit scanning, operationally significant changes to helicopter attitude were probably detectable from the left-seat position.

Although the digital integrated presentation of primary flight information with other parameters is generally an advantage, this was not necessarily the case for cross-cockpit scanning. The ATSB considered contextual and explanatory factors that might have undermined the advantages of a PFD.

Firstly, the presentation of airspeed and altitude information on digital flight displays differs from analogue displays by utilising a scrolling-tape scale and a fixed pointer rather than a fixed scale and a radial-action pointer. In relative terms, the digital indications provide less salient visual cues to airspeed and altitude trends with more reliance on reading of figures. Although the instructor was familiar with this presentation, in the cross-cockpit scanning and high workload context, the airspeed and altitude information might have been less accessible to quick-glance interpretation.

Secondly, the ability of the instructor to read the airspeed and altitude indicators on the primary flight display from the left seat would have been affected to some extent by the luminosity of the display. Given the general instrument lighting was found on the lowest setting, it is likely that the PFD luminosity was also on a low setting, consistent with standard practice in dark night conditions. This might have further affected the readability of the presented data.

Finally, the instructor’s previous instructional experience in light aeroplanes was not equivalent to the complexity of the EC135 MPT operation and the instructor had limited experience in the left seat at night in VH‑ZGA or VH‑ZGZ. Of those 7 flights, in 2017 there were 2 MPT check flights to the anchorage and 2 non-MPT rating-related flights. In 2018, as part of the current Port Hedland roster period, there were 2 MPT check flights at night with experienced pilots then the line training flights prior to the accident flight.

If those 7 flights are filtered according to MPT operations in a degraded visual cueing environment, the result is one flight – the one before the accident flight. On that basis, the capability of the instructor to monitor the offset primary flight display from the left seat had not been fully exercised until the night of the accident. The risk management and organisational aspects of this is addressed in a later section.

Alternative source of primary flight information

Given the challenges inherent in monitoring the offset PFD from the left seat, the ATSB considered the utility of the MD302 standby attitude module as an alternative source of flight information for the instructor.

Consistent with its purpose, the module provided the critical flight information required for instrument flying in case the PFD failed. An advantage of this module in the context of this occurrence was the relatively accessible position within a secondary field-of-view reference either seat.

The main disadvantage of the module was the size of the 2 adjacent displays relative to a PFD, Given the module was certified for use as standby instrumentation and the instructor advised that their prescribed vision correction was suitable for EC135 panels, there was no apparent reason for the information to be inaccessible. However, the instructor described the indication of vertical speed (altitude trend bar) as unreadable.

Although increased workload and slower interpretation of detailed information might be expected with reference to smaller displays, the rate of movement of the altitude tape and extension of the altitude trend indicator would have been salient cues to the abnormal flight path. As with most instrument flying skills, assimilation of information is improved by familiarity with the representation of normal and abnormal conditions on a particular display.

With duplicated primary flight instrument displays in the standard EC135s, the instructor did not have any reason to refer to the standby instruments during training and assessment conducted in those models. And from the limited instructing or assessing experience at night in VH-ZGA and VH-ZGZ, it can be inferred that the instructor had limited opportunity to become familiar with this type of standby instrument.

Instrument and night‑rated pilots are required to periodically demonstrate their capability to operate in normal and abnormal conditions with reference to a ‘partial panel’, which are generally the flight instruments that continue to function after a primary system failure. As these exercises had been carried out by the instructor in standard EC135s and in an artificial checking environment, they were not representative of the occurrence conditions and it is unlikely that partial panel exercises had any relevant effect.

In the context of this occurrence, it is unclear if the outcome would have been different if the instructor had referenced the standby instrument module instead of the offset primary flight display.

Influence and risk

The instructor assessed that the configuration of the instrument panel and workload associated with cross-cockpit reference to the PFD was a factor in the abnormal flight path and recovery actions. For additional perspectives on the potential influence of the instrument panel configuration, the ATSB conducted a comparative analysis with reference to various certification and regulatory criteria and consulted expert pilots.

The ATSB consulted a range of certification criteria and industry association advice that applied to the positioning of flight instruments relative to the seat positions approved for flight crew. As the EC135 variant was configured for single-pilot IFR operation from the right seat, it was not required to satisfy any instrumentation standards for the left seat occupant. For the comparative analysis, the ATSB considered the extent to which the left cockpit seat conformed to the certification criteria or industry association advice for essential flight crew.

In general, the certification guidance advised that primary flight information was to be in front of each pilot so that it was readily or easily visible. Based on measurements of the other EC135, VH‑ZGZ, the angle between the left‑seat centreline and the primary flight display was 57°. This was not within or near the primary field of view (15° each side of straight ahead), although allowed the instructor to view the primary flight display with a moderate head turn to the right.

Although not addressed directly by certification guidance, viewing distance was considered by comparison with recommendations for the size of characters on displays. When viewed from the left seat position, the smaller numerals on the altimeter tape indicating 100 ft increments were below a commonly recommended height. This was critical when the helicopter was below 1,000 ft.

From an Australian regulatory perspective, VH-ZGA was suitably equipped for the night operation in visual conditions being conducted and for single-pilot IFR. In the absence of a second 5-inch attitude indicator (or other CASA-approved attitude indicator for primary use), it was not equipped for IFR helicopter operations requiring 2 pilots.

Practically, line training for offshore ship landings in a degraded visual cueing environment required both pilots to exercise a high level of instrument flying skill. Those demands were exacerbated by transitioning the pilot under supervision from day to night line training without a consolidation period. Given the similarities between IFR helicopter operations requiring 2 pilots and the line training scenario, the single-pilot panel configuration probably increased relative risk.

Further to the certification/regulatory aspects, the ATSB sought the perspectives of experienced EC135 pilots who had conducted training and assessing in VH-ZGA or VH-ZGZ. The only person with substantive experience was the chief pilot who advised that night line training and assessment was carried out in those variants before the occurrence without any perceived high risk. The chief pilot added that although the instrument panel configuration was considered suitable for monitoring line operations from the left seat, it was not suitable for controlling the helicopter from the left seat. The ATSB noted that after the accident the operator discontinued training/checking in the remaining EC135 variant, VH-ZGZ.

In summary, the ATSB considered that the configuration of the EC135 variant instrument panel disadvantaged the instructor and increased the risk of ineffective monitoring. When occurrence‑specific factors were taken into account, the lack of an accessible high-resolution integrated display of primary flight information probably exacerbated the effect of those factors and contributed to the abnormal flight path and water collision.

Contributing factor

The instrument panels fitted to VH-ZGA and the operator's other EC135 helicopter at Port Hedland were equipped for single-pilot operation under the instrument flight rules. When used for flight training or checking in a degraded visual cueing environment, this configuration has a detrimental effect on the ability of an instructor or training/check pilot to monitor the helicopter's flight path and take over control if required. (Safety issue)

The ATSB considered the CAO 20.18 equipment requirements as a risk control related to this contributing factor.

To be operated at night in visual conditions but without external cues for pitch and roll, the helicopter was required to be equipped with an autopilot or be operated by 2 pilots. The occurrence flight was a supervised single-pilot operation, and the helicopter was equipped with an autopilot. As such, if the pilot controlling the helicopter had utilised the autopilot to advantage while circling the ship, consistent with the CAO 20.18 requirement, the risk of an inadvertent descent would have been greatly reduced. The occurrence flight was not a 2-pilot operation in the conventional sense, so there was no procedural crew coordination and, in normal operation, no requirement for the instructor to control the helicopter from the left seat. As such, there was no regulatory requirement for the helicopter to be equipped with co-pilot flight instruments.

Although the absence of a PFD in the instructor’s primary field of view was an influential factor in this occurrence, the ATSB was not aware of any similar occurrences where this was identified as a factor. As helicopters are often equipped with suitable instrumentation for 2-pilot operation and the relative risk of operations varies, the exposure of the helicopter industry to this risk was difficult to quantify.

The ATSB considers that although CAO 20.18 did not address the equipment requirements for the pilot in command of line training for single-pilot operations, there was insufficient evidence to find that this was a safety issue.

Irrespective of specific regulations, operators are required to identify and mitigate risks, as the operator did after the occurrence. As such, the ATSB makes the following safety observation.

Safety observation

For any operation that relies on the instrument flying skills of a second pilot, consideration should be given to the adequacy of flight instrumentation for that pilot.

Instructor role

Introduction

As previously stated, since the pilot under supervision had not received any preparatory night flying and was conducting the third of 10 planned MPT operations at night, conformance and safety of the operation was heavily reliant on the instructor as pilot in command.

The ADS-B data for flights on the night of the accident indicated that the first 2 approaches to ships at C1/C2 and the go-around were not conducted in accordance with the operator’s SOPs. This indicated that both pilots were having difficulty in their respective roles with respect to flight path management.

The instructor held the necessary qualifications for MPT operations at night in the EC135 type and held a multi-engine helicopter instrument rating. Although the instructor’s proficiency had been checked at the applicable intervals, and no significant deficiencies were identified, the scope of these checks did not include specialist skills such as MPT.

To manage line training generally, the instructor was required to apply knowledge of instructional technique, helicopter systems, and SOPs. For the purpose of training pilots for MPT operations, the instructor also required skill to manage flight paths in degraded visual cueing environments both manually and via the helicopter’s automation. In the early stages of training, the instructor was typically required to apply the requisite knowledge and skill from the left seat to provide pre-emptive advice and feedback to the pilot under supervision with intervention as required for safety.

The Grade-1 instructor had substantial training and assessing experience from the left seat of helicopters and there was no indication of any significant deficiencies related to the knowledge requirements of line training. For the EC135 specifically, the instructor had recorded 164 hours of day instructing and 48 hours of night instructing.

Although instructional qualifications and experience are generally beneficial, these are oriented to the competency standards for CASR Part 61 licences and ratings rather than conduct of specialist operations. Line training and assessing was also carried out by the chief pilot who was not an instructor. As such, flight instructing qualifications and experience was by itself neither necessary nor sufficient for the line training role.

Marine pilot transfer experience

The instructor had been operating EC135 helicopters on MPT operations and flight training/assessing for 2.5 years. This was initially in the Hay Point and Gladstone areas, with the addition of Port Hedland in the year prior to the occurrence. By the time of the occurrence, the instructor had recorded 450 ship landings in day and night conditions. Most of those ship landings were conducted as pilot in command, controlling the helicopter from the right seat.

Given the occurrence was to an outbound ship at Port Hedland and this offshore operation was relatively more demanding at night than some of the other MPT flying conducted by the instructor, the ATSB reviewed the instructor’s experience at night in the Port Hedland area.

The ATSB found that the instructor had limited experience at Port Hedland, having been involved in 10 landings to outbound ships near C1/C2 at night, including 3 single-pilot operations as pilot in command (flying the helicopter from the right seat). These 3 landings were conducted during a night shift in January 2018, along with 2 ship landings to inbound ships at the pilot boarding ground. Although there was moon illumination on those occasions, due to cloud the flights were probably conducted in degraded visual cueing environments.

A review of ADS-B data for the 5 flights in January 2018 identified inconsistent altitude maintenance with varying rates of descent in the circuit. When the helicopter developed abnormal rates of descent on some of the (final) approaches there was a correction towards the nominal 7° flight path, in some cases this correlated with the radio altimeter alert at 300 ft. This indicated that the instructor was finding it difficult to maintain a stable flight path and conform to the SOPs. The ATSB noted that the instructor was controlling the helicopter from the right seat with a PFD in the primary field of view, which might account for the flight path corrections.

In the normal course of line flying or line training/assessing, the instructor did not conduct ship landings from the left seat. There was no record of this occurring, although the instructor indicated that the first line training flight by day and first line training flight by night with the pilot under supervision might have been such occasions. As a training/assessing pilot, the instructor had the opportunity to observe landings to ships at night conducted by experienced MPT pilots.

Line check and flight review/check

The primary means for the operator to ensure that the instructor was proficient at night MPT operations was via initial and ongoing annual night line checks. As MPT pilots were required to hold a night VFR rating and some pilots also held an instrument rating, the flight review and proficiency check for those ratings were also important risk controls for night operations.

According to operator records, the instructor had completed the initial line check at night on 8 March 2016 and a subsequent check at night on 5 April 2017. The chief pilot who conducted both checks recorded that the instructor’s flying was satisfactory on both checks involving a total of 3 ship landings at night.

There was contradictory information about the flight on 5 April 2017 that was recorded by the chief pilot as a line check at night of the instructor and by the instructor as a night VFR flight review of the chief pilot. Although there was insufficient information to conclusively resolve the discrepancy, the ATSB considered it more likely that the instructor was controlling the helicopter, and the flight was probably a line check as recorded by the chief pilot.

Given the line check in 2017 was the most recent check and was carried out at night from Port Hedland with an approach to ships at the pilot boarding ground and near C1/C2, this was considered to be a relevant indicator of the instructor’s MPT proficiency at the time of the accident, noting there may have been some change in the intervening 12 months.

For the flight conducted by the instructor and chief pilot on 5 April 2017, the conditions were suitable for night VFR and there was substantial moonlight (elevation 53° with 68 % of the visible disk illuminated). ADS-B data showed that the approach profiles were generally consistent but circling to both ships was conducted at about 1,000 ft, which was higher than the specified circuit height of 700 ft. And on both approaches the airspeed through 500 ft was about 40 kt, which was lower than the specified 60 kt for the ‘finals gate’.

Based on the flight data review, the ATSB considered that the instructor (as the likely pilot controlling the helicopter) did not demonstrate a capability to operate in accordance with the SOPs at night in relatively favourable night VFR conditions. The chief pilot advised there were no concerns about the instructor’s ability to conduct night MPT operations, and there was no evidence that the instructor identified or addressed those variations. Although a link between the demonstrated level of SOP conformance and a prospective inadvertent descent, such as in the occurrence, was not clear at the time, this check did not provide any assurance that the instructor was proficient at night MPT, especially in a degraded visual cueing environment.

Having completed a night VFR flight review in May 2016 and instrument proficiency check in June 2017, the instructor was within the respective validity period of both ratings. To satisfy either review/check the instructor was required to demonstrate instrument flying capability and recovery from unusual attitudes with full and partial panel. There were no indications of any performance decrements in these areas.

While the night VFR rating was necessary and the instrument rating was advantageous for night MPT, the data review of the instructor’s flight on 5 April 2017 indicated that those qualifications alone were not sufficient to ensure that the instructor was proficient at visual circling at night in degraded visual cueing environments. The ATSB also noted that the flight review and proficiency check were oriented to conventional helicopter operation with circuits and instrument approaches at aerodromes.

Contributing factor

When operating at Port Hedland in degraded visual cueing environments, the instructor had not been able to ensure that circling approaches were consistent with the operator's standard operating procedures. This probably limited the support provided to the pilot under supervision on the occurrence flight and, in combination with other factors, probably contributed to the abnormal flight path and partial recovery.

Safety reporting

Following analysis of the ADS-B data from the night flights conducted by the instructor in January 2018, the instructor was presented with the data and asked about any recollections about those flights. Noting that it was 3 years since those flights, the instructor did not recollect anything about flights from Port Hedland during that roster period.

The chief pilot advised the ATSB that the instructor did not report any significant variations from SOPs or seek any related training. Similarly, no report was identified in the operator’s reporting system. Assuming that the instructor was aware of the SOPs and related variations on those flights in January 2018, it is not clear why a report was not made, or a remedy was not sought. The instructor advised that if those flights had been knowingly flown out of tolerance, they would have been reported and remedial training would have been sought.

According to the safety management system manual, safety hazards and deficiencies such as deviation from SOPs were to be reported through the electronic system accessible via the internet. It was intended that these hazards and deficiencies would be investigated, corrected, and discussed by the safety committee. A key feature of the operator’s ‘Just Culture’ policy was the differentiation of various types of normal human error from intentional non-compliances, with guidance that implied, but did not guarantee, nil disciplinary action for the former.

Over the 3 years the safety management system was operating, there was evidence that the reporting of occurrences and safety hazards was improving, and issues were being addressed. None of these reports involved pilots self-identifying concerns about their proficiency so there was no comparative example. A safety survey reportedly conducted in February 2018 would have been a useful reference for safety culture, but the results could not be located. There was no record of a safety survey in 2017 or 2016.

As the head of operations for the CASR Part 141/142 organisation and nominal head of training and checking, the instructor was partly accountable for the flight standards of the operator’s pilots. As such, it was presumably difficult to self‑report any performance issues or to objectively assess the associated risk.

Over the 3 years the safety management system was operating, there was evidence that the reporting of occurrences and safety hazards was improving, and issues were being addressed. None of these reports involved pilots self-identifying concerns about their proficiency so there was no comparative example. The ATSB considered the safety surveys conducted in 2017 and 2018 as indicators of the operator’s safety culture. Although the surveys did not indicate any systemic issues, the lack of information about survey response rates, and the survey methodology, did not allow a conclusion to be reached.

Other factor that increased risk

Although the instructor was flying when significant deviations from standard operating procedures occurred during night approaches in January 2018, these were not reported to the operator or otherwise addressed by the instructor.

Pilot training and assessment

Line training arrangements

Prior to line training, the instructor provided the pilot under supervision with refresher flying on the EC135 type and assessed this satisfied the requirements of a type rating flight review. This review of normal and abnormal procedures was consistent with the operator’s requirements for a new pilot.

On the first day of line training (the day before the accident), the pilot under supervision was involved in 9 ship landings and was controlling the helicopter for at least 8 of those. At the end of the session, the instructor assessed that the pilot under supervision was competent and safe, and just needed practice for more familiarity in MPT operations.

Line training continued the next day with a ship landing/take-off in the early evening. The instructor counted this as the tenth ship landing/take-off by day and a conforming line check. At this point, the instructor considered the pilot under supervision complied with the operator’s requirement for 10 landing/take-offs as pilot in command under supervision and was competent for line operations by day. There were no contrary indications in the related ADS-B flight data.

Consistent with the schedule emailed to the chief pilot 2 days before, the instructor then transitioned the pilot under supervision into night MPT operations on the next flight. Given the instructor considered that the pilot under supervision was competent for day MPT, there was no policy or procedural impediment to proceeding with the night line training. As such, continuation of the training was at the discretion of the instructor and chief pilot, who did not identify this as a significant risk.

The first landing/take-off at night was to a ship inbound from the pilot boarding ground near the anchorage. It is possible that the instructor conducted this approach. After a 2‑hour rest period, the next flight was to an outbound ship nearing C1/C2 at the end of the shipping channel followed by a quick turnaround for the occurrence flight to the outbound Squireship.

It is apparent from the ADS-B data that the pilot under supervision had been progressively adapting to day MPT operations in the EC135 but was having some difficulties with the introduction of night approaches. This could be anticipated, given the pilot under supervision was transitioning from the Bell 206L to the EC135 helicopter with different handling characteristics, more complex systems with automation, and digital presentation of flight data.

Although these factors were present during day operations, the increased reliance on flight instruments and the higher workload associated with a degraded visual cueing environment would have exacerbated their effects. The transition from flying at night using night vision imaging systems to unaided night VFR in an offshore environment was an additional challenge and potentially disorienting.

Although previous MPT and EC135 experience was an advantage for the pilot under supervision, this was attenuated by the 7-year time interval, relatively low EC135 hours, and limited ship landings/take-offs as pilot flying at night. Overall flying experience in the previous 3 years was predominantly at night but consisted of a relatively low amount of flying hours.

In that context, and consistent with training for pilot licences, it is advisable for instruction to be provided in stages with intervening consolidation periods. That allows the trainee to practice a defined set of unfamiliar skills and reach a certain level of expertise before further complexity and workload is introduced. As a precaution, exposure to more demanding environmental conditions can be controlled to further manage the risk.

As a Grade 1 instructor, the instructor would have been familiar with the principles of training consolidation. The instructor was aware that these principles had been applied to the MPT operation because the chief pilot had arranged for the instructor (after joining the operator) to consolidate day MPT before being introduced to night MPT.

With a deficit of 2 pilots representing 25% of the normal roster group, there was an operational imperative for the pilot under supervision to be trained and cleared for line flying as soon as practicable. In the short term, there was also a requirement for the operator to assign a substitute pilot to the duties originally assigned to a suspended pilot, until that pilot was cleared back to line operations. It is likely that the short notice scheduling of night line training that included the occurrence flight was influenced by both of these factors.

There was another incentive for the pilot under supervision to be trained and cleared for line flying as soon as practicable. If the instructor completed the line training before flying out of Port Hedland for leave over the weekend, there would be no need to return for the remaining days of the rostered duty.

Commercial imperatives and personal incentives are an unavoidable element of the operational environment. In general, operators manage the risks associated with these potential influences by establishing an operational framework that includes SOPs and a safety management system. To ensure conformance and safe outcomes, operators will select and train suitably qualified personnel, then assign duties according to experience level, with an appropriate level of support and ongoing supervision.

If the pilot under supervision was given the opportunity to consolidate day MPT operations after the requisite 10 ship landings, night operations could then have been introduced with lower cognitive workload for both pilots and reduced risk of abnormal flight paths. In the context of this occurrence, this would have provided roster relief for the 0600 to 1800 day period and released an experienced pilot to carry out night flights. As another benefit, in the short term at least, the risk of fatigue for the pilot under supervision would have been lower.

A period of general night flying prior to starting night line flying would also have allowed the pilot under supervision to become more familiar with the digital instrumentation and practice instrument flying in that helicopter type. A pilot will typically learn more effectively from a graduated introduction to more demanding environmental conditions and complex procedures with the added benefit of lower operational risk.

Line training was a key element in the operator’s management of the risks associated with offshore ship landings/take-offs in day and night conditions. Although line training is often carried out on an opportunity basis and requires adjustment to individual capabilities, the specification of a staged training schedule with competency criteria assists the effective management of risk.

Contributing factor

The pilot under supervision was introduced to line flying at night in a degraded visual cueing environment immediately after completion of the minimum-required 10 ship landings by day and without any preparatory night flying. Given the pilot under supervision was transitioning from a different helicopter type and operational environment, the lack of consolidation contributed to high cognitive workload for both pilots and increased the risk of sustained flight path deviations.

Management of pilot training and assessing

Prior to joining the operator, the instructor was chief flying instructor for a flying school associated with the operator and held an EC135 type rating with minimal operational experience. Between August and November 2015, the instructor was inducted into the operation and completed EC135 familiarisation training and a multi-engine instrument proficiency check.

The instructor then operated as an EC135 line pilot for MPT operations on the east coast and carried out some rating proficiency checks and flight reviews as Grade-1 instructor or flight examiner. In March 2017, an external instructor conducted an EC135 instructor standardisation related to licences/ratings and instructors from Airbus helicopters provided further type-related training.

In April 2017, the chief pilot carried out a night line check at Port Hedland with the instructor in the command seat. The chief pilot recorded that the check including one ship landing/take-off carried out satisfactorily near C1/C2. It should be noted that the conditions were not challenging.

In June 2017, a CASA flight examiner evaluated the instructor’s EC135 type and instrument proficiency as the pilot controlling the helicopter in the right command seat then flight examiner proficiency as supervising pilot from the left seat. These were found to be satisfactory and the ratings were renewed/revalidated.

None of the proficiency checks to renew the various CASR Part 61 ratings were oriented to MPT operations and were not intended for that purpose. The function of the line check was to assess proficiency in MPT operations from the right command seat. As a result, the capability of the instructor to supervise MPT operations from the left seat had not been assessed. Also, when training or supervising qualified pilots, there was generally limited need for the instructor to take over control from the left seat.

The appointment of pilots to conduct training or checking was at the discretion of the chief pilot. A company pilot who held an instructor rating with multi-engine training approval, command instrument rating, other applicable endorsements/ratings, and with appropriate operational experience could be approved for training/checking duties. No further training/checking of the instructors was considered necessary by the operator unless the chief pilot identified a specific requirement.

At the time of the occurrence, the operator was approved to conduct flight training and reviews or checks for licences/ratings in accordance with CASR 141/142. The instructor was the nominated head of operations, which was equivalent to the prior role of chief flying instructor in the previous regulatory regime and was on the same organisational level as the chief pilot.

The operator did not maintain a CASA-approved training and checking organisation in accordance with CAR 217, which was not a requirement for charter operations such as MPT. Any flight training or assessment other than CASR 141/142 was carried out as a function of the air operator’s certificate as determined by the operator. Although CAR 217 only applied to the operator if CASA issued a direction, the guidance provided for training and checking organisations is a useful reference.

One of the key components of a CAR 217 organisation is the selection, training, and maintenance of continued competency of training and checking personnel. This is closely related to another component that addressed quality assurance audits and the over-sight of the standards of check pilots.

Although the operator prescribed minimum qualifications, applicable experience, and chief pilot discretion for pilots selected to carry out the AOC-related training and assessment, there was no process to train or assess the initial or ongoing role-competency of those pilots. In an environment where the instructor was the CASA-approved head of operations for the operator’s CASR Part 141/142 organisation and a CASA-approved flight examiner, expertise in those domains was presumed to be sufficient for related elements in similar domain.

Other factor that increased risk

The operator's training and assessing procedures for marine pilot transfer operations did not provide assurance that pilot under supervision experience, helicopter instrumentation, and instructor capability were suitable for line training at night in a degraded visual cueing environment. (Safety issue)

Circuit and approach procedures

Circuit profile and parameters

For operations to ships by day or night, the operator specified a downwind segment at 700 ft above the water and 70–80 kt airspeed, then a turn through 180° on the base segment with combined descent and deceleration to intercept final approach at 500 ft and 60 kt groundspeed ('final gate'). Further descent and deceleration were contingent on the disposition of the helicopter relative to the ‘sight picture’ for a nominal 7° profile.

To carry out a descent while decelerating and turning requires a high rate of information processing with skilful coordination of controls. If that manoeuvre is carried out at night in a degraded visual cueing environment, the processing and skill demands increase further. Compared to a level constant-speed turn, this pilot workload increases the likelihood of an abnormal flight path. When this manoeuvring is in the vicinity of 500 ft (above water), the consequences of any attentional or skill deficits are likely to be significant.

For airspeeds above 60 kt, the upper modes of the autopilot were available to manage the altitude, vertical speed, and heading of the helicopter. However, the pilot was still required to closely monitor the airspeed and rate of descent and could expect to adjust the power/torque as the airspeed varied and the target altitude was reached. By nominating 60 kt as the ‘final gate’ airspeed, the operator did not provide a buffer for any inadvertent airspeed loss during the turn. If the airspeed decayed below 60 kt, the upper modes disengaged, and the helicopter would not necessarily hold the selected altitude (subject to power/torque).

In the company’s east coast operations, there was a contract requirement to overfly the ship on arrival to allow the pilot to inspect the landing site and was the default procedure when the Port Hedland operation started in March 2017. To conduct this arrival procedure in a degraded visual cueing environment at night, the pilot transitions from instrument flying for the ship overflight and visual inspection then back to predominantly instrument flying for the circuit with reference to the ship lights for positioning. Transitions between instrument and visual flying contribute to pilot workload and increase the risk of disorientation.

Straight-in approaches minimise manoeuvring at low level prior to final approach and were preferred by the experienced line pilots at Port Hedland and the chief pilot as more efficient with less risk at night. For offshore approaches at night, HeliOffshore recommended a straight-in approach and landing rather than a circuit (see the section titled Non-regulatory guidance – HeliOffshore).

Although straight-in approaches were allowed by the operations manual, the description of the circuit procedure in the manual suggested that it was the default method. The instructor considered that to be the case and had generally conducted circuits when operating at Port Hedland in January 2018. It is acknowledged that a circuit may be required for various reasons, such as a transition from inbound track to landing direction and after a go-around so related training and assessment is required.

No specific risk assessment was carried out for the Port Hedland operation and the operator did not perceive that it was significantly different to the existing operations.

Automation procedures and practices

One of the contributing factors to this accident was operation of the helicopter on the second circuit without a vertical navigation mode engaged. This was not consistent with standard or expected practice and was an absent risk control for inadvertent descent and controlled flight into terrain/water.

The chief pilot advised that pilots were trained to keep the upper modes engaged until passing the ‘final gate’ and descending below 500 ft on the nominal 7° profile to the ship. From that point onwards, the pilot was required to make manual inputs as the upper automation modes were unavailable below 60 kt. Although this was considered to be the default practice, use of the autopilot and mode selection was effectively at the discretion of the pilot in command.

Following the occurrence, the instructor advised that use of the autopilot upper modes in the circuit was standard practice but did not recall any detail about autopilot use in the circuits around Squireship prior to the occurrence. As noted earlier, when the instructor was flying at Port Hedland in January 2018 the variation in circuit altitude indicated that a vertical upper mode was not used.

Although engagement of the upper modes of the 3-axis autopilot could reduce workload, the pilot was still required to adjust engine power/torque to control parameters such as airspeed or rate of descent. This is a complex coordination task when manoeuvring in accordance with the operator’s circuit procedure in a degraded visual cueing environment. If the pilot is not familiar with the autopilot interface and/or the helicopter is in a dynamic flight state, the high short-term workload associated with managing the autopilot modes might be perceived as a disadvantage.

That said, it is in high workload conditions that the autopilot provides significant safety benefit. The regulatory requirement for the helicopter to be fitted with an autopilot/stabilisation system when operated single-pilot in a degraded visual cueing environment underscores this point.

In addition, the Flight Safety Foundation and HeliOffshore provided standards and guidance to the helicopter offshore industry that specified the provision of a 4-axis (or 3-axis if risk assessment allowed) autopilot with policies/procedures to ensure appropriate use. This included integration of automation in specified approach profiles with coupling of approaches until the committal point. Although the autopilot in VH-ZGA was not usable below 500 ft, it could be used in a circling approach until visual cues were available on final approach.

Another consideration for EC135 operations is pilot interaction with the stabilisation system when the upper modes are not engaged. One advantage of the system is reduced pilot workload because the helicopter will hold an attitude that is selected by the pilot. Although this provides an element of autopilot operation, the pilot was required to manipulate engine power/torque and modulate attitude through movement of the cyclic with/without force trim switch or beep trim.

In their investigation of a Sikorsky S-92A accident in the Nova Scotia region, the Transportation Safety Board of Canada (TSB) addressed use of the cyclic trim release button, which is equivalent to force trim release. It found that depressing and holding the cyclic trim release button, while operating in a degraded visual environment, increased pilot workload and contributed to control difficulties that resulted in an unstable approach that developed into vortex ring state.

Although any use of force trim release in this occurrence was not recorded and was undetermined, this was a potential factor that increased risk. The ATSB noted the TSB caution that: if manufacturers’ flight manuals and operators’ standard operating procedures do not include guidelines for the use of the cyclic trim release button, it could lead to helicopter control problems in a degraded visual environment due to the sub-optimal use of the automatic flight control system. HeliOffshore recommended that when flying a circling approach in a coupled autopilot mode, adjustment of the flight path should be through beep trim until the committal height.

By not specifying that the autopilot upper modes were to be used in the circuit as a standard procedure, the operator did not minimise the risk of disorientation.

Stabilised approach criteria

As the helicopter descended during the second circuit to Squireship, the rate of descent developed to be about 1,700–1,800 ft/min passing 300 ft and the airspeed had reduced to about 30 kt at 75 ft. This was an unstabilised aircraft state that was well outside industry practices.

Specification of stabilised approach criteria is an important risk control for prevention of controlled flight into terrain. It provides clear guidance as to operational boundaries and is designed to assist a pilot or crew to identify and correct unsafe conditions or carry out a go-around. At the time of the occurrence, CASA guidance for operations manuals (CAAP 215-1(3.2) Operations Manuals) simply listed stabilised approach criteria as an item to be addressed.

According to recommended practices developed by HeliOffshore, pilots should select the final landing configuration by 1,000 ft and aim to be stabilised by 500 ft. If the helicopter was not stabilised by 0.5 NM (926 m) or 300 ft above the landing site, an immediate go-around was required. To be stabilised, the helicopter was required to be on the correct flight path at an appropriate speed with rate of descent no greater than 700 ft/min.

In the operations manual under the heading of stabilised approach criteria, the operator provided general advice for conducting an approach and conditions to be avoided when the airspeed was below 30 kt. If the rate of descent exceeded 700 ft/min (when the airspeed was below 30 kt), the pilot was expected to conduct a go-around.

Although this maximum rate of descent was consistent with the HeliOffshore figure, the correlation with low airspeed and lack of other criteria provided limited utility as the decision point for a go‑around. In MPT operations the ships were generally moving, and pilots were required to judge distance to the ship from visual cues. As such, 300 ft above the landing site could be used as the decision point for continuation of the approach or a go-around.

Given the helicopter was not on final approach and the pilots did not detect the exceedance of the operator’s descent rate/airspeed criteria, the absence of criteria recommended by HeliOffshore was not considered to a contributing factor in this occurrence. However, without such criteria it is more difficult for pilots to identify and avoid unsafe conditions or to respond appropriately.

This could be a factor in the deviations from normal procedures observed in ADS-B data when the instructor was flying at Port Hedland in January 2018, and the non-reporting of these to the operator.

In this occurrence, the deviations from normal practices were significant and it is unlikely that either pilot would have attempted to continue the approach if they had been aware of the abnormal flight path. Nevertheless, the provision of stabilised approach criteria would have conditioned pilot attention and response to critical parameters.

Other factor that increased risk

The operator’s circuit and approach procedures for marine pilot transfer operations did not minimise pilot workload or provide the recommended stabilised approach criteria with mandatory go-around policy. These procedures could allow a combination of conditions that increased the risk of a sustained abnormal flight path and collision with terrain/water. (Safety issue)

Fatigue and fatigue management

General background

As discussed in Task requirements, there were elements of the crew’s performance during the accident flight that related to their monitoring of flight parameters such as altitude, vertical speed and airspeed. The helicopter’s deviation from the intended flight path and target parameters was not identified or corrected by the pilots.

The accident occurred during the late evening and at a time when the pilot under supervision had been awake for an extended period, which followed-on from a long duty period involving both pilots the previous day. In that context, the investigation considered the potential effect of fatigue on the performance of the pilots.

Instructor fatigue level

Most people need at least 7 hours of sleep each day to achieve optimum levels of alertness and performance, and research has shown that restricting sleep to 6 hours or less a night over several nights will result in significant performance decrements (Banks and Dinges 2007, Watson and others 2015b).

Based on the available information, the instructor probably had a restricted sleep opportunity (5–6.5 hours) during the nights of 9, 10 and 12 March (and only 7.5 hours on 11 March), and may have achieved less sleep than the available opportunity. There was also an early start on 13 March then a long work day (at work from 0430 to 1917). Overall, at times during this period the instructor was probably experiencing a level of fatigue known to adversely influence performance.

On the night of 13 March, the instructor had a maximum sleep opportunity of 7.5 hours, reported 2 hours sleep during the day on 14 March, and felt rested prior to commencing work that afternoon. Although the workload involved in the MPT tasks at night would have been significant, the instructor had an opportunity for rest breaks between each of the tasks during the evening of 14 March. The time of day of the accident flight was not during the window of circadian low, though also was not during a time of day associated with maximum levels of alertness.

The ATSB analysis of the instructor’s sleep times was complicated by inconsistencies between the recorded sleep times in the instructor’s sleep log, and other information which indicated the instructor was awake when sleep had been recorded. Although the ATSB was able to construct a probable timeline for some of the instructor’s sleep opportunities, for other times (including the sleep on the night of 13 March), the analysis was more reliant on the sleep times recorded by the instructor.

Based on the available information, there was insufficient evidence to establish whether the instructor was affected by fatigue at the time of the accident, though it is likely they were experiencing a level of fatigue in previous days.

Pilot under supervision fatigue level

It was reported the pilot under supervision typically slept for 9 hours per night. Although there appeared to have been sufficient sleep opportunity for the period from 8 to 11 March, there was only 5.5 hours sleep opportunity on the night of 12 March. There was also an early start on 13 March then a long work day. Although the pilot under supervision had 9 hours sleep opportunity on the night of 13 March, no sleep was obtained during the next day. So, at the time of the accident, the pilot under supervision had probably slept for at most 6 hours in the previous 24 hours and 12.5 hours in the previous 48 hours, and had been awake for about 18 hours.

A significant amount of research has shown that a person’s performance starts to decline after 16–18 hours of extended wakefulness (Dawson and others 2021). According to the prior sleep wake rule (PSWR) threshold for extended wakefulness used by the operator, the pilot under supervision should not have conducted any work after 2100.

The quality of sleep will also influence the risk of fatigue and reduced alertness. A text message indicated the pilot under supervision did not sleep well on the night of 12 March. Although the pilot indicated sleeping well on the night of 13 March, they also indicated they did not get sufficient sleep. Sleep quality and quantity are also affected by stress and anxiety (Kim and Dimsdale, 2007), including the stress associated with completing exams (Zunhammer and others 2014). The pilot had reported being concerned about completing the night VFR flight planning assessment. Although there was not sufficient evidence to determine the degree to which the pilot was worried about this, and therefore its potential impact on their sleep, it possibly affected the quality and quantity of the actual sleep obtained on 12 and 13 March

Given the pilot under supervision’s restricted sleep in the previous 48 hours, and the significant time awake before the accident, combined with evidence the pilot was sometimes not sleeping well, the ATSB determined that the pilot under supervision was probably experiencing a level of fatigue known to adversely influence performance.

Although the pilot under supervision was probably experiencing fatigue, it was not possible to reliably determine the extent to which this fatigue contributed to the accident. As described in Inadvertent descent below 500 ft, the ATSB could not establish to a satisfactory standard of certainty which pilot was controlling the helicopter after the go-around. If the pilot under supervision was not flying, the effects of any fatigue-related impairment may not have significantly contributed to the occurrence, given the responsibilities then assumed by the instructor.

If the pilot under supervision was controlling the helicopter after the first circuit go-around, then the fatigue they probably experienced would have reduced their ability to cope with and respond to the conditions encountered during the accident flight. However, other factors, including the dark night conditions and the pilot under supervision’s low level of experience and recency in dark night MPT operations, and the associated workload, would also have affected the pilot under supervision’s ability to manage the go-around and subsequent circuit. Although fatigue increased the risk of the pilot making errors, the extent to which the errors could have occurred even without fatigue was difficult to determine.

Other factor that increased risk

Due to a combination of limited sleep in the 48 hours prior to the accident and extended wakefulness on the day of the accident, the pilot under supervision probably experienced a level of fatigue known to adversely influence performance.

Sleep log recording discrepancies

Although there was insufficient evidence to conclude whether fatigue contributed to this accident, the ATSB’s analysis did identify patterns of work and sleep associated with an increased risk of fatigue. These included the restricted sleep both pilots had on the night of 12 March, and the long day both pilots worked on 13 March.

It is acknowledged that these problems occurred during the context of training a new pilot rather than routine line operations. However, neither of the pilot’s sleep logs accurately reflected their sleep or work on these days. During the course of the investigation, other pilots raised concerns about the effectiveness of the operator’s fatigue risk management system (FRMS) and the validity of the sleep log approach based on the prior sleep wake model (PSWM). The ATSB therefore examined the effectiveness of the FRMS and, in particular the design and usage of the sleep log.

The operator’s FRMS required pilots ensure they had sufficient sleep prior to commencing a duty period, with sufficient sleep being defined in terms of the rules described by the PSWR. Pilots were required to record sleep and duty in a sleep log, which was designed to help pilots identify if they had achieved sufficient sleep by highlighting circumstances where a pilot would not meet the requirements of the PSWR. In essence, the sleep log provided the primary means of ensuring that pilots were sufficiently rested prior to conducting an MPT task.

It is understandable that knowing how much sleep a pilot had in the previous 24 and 48 hours can play a very useful role in determining their fatigue level and fitness for duty. This information can be particularly relevant for rosters involving night shifts and with no pre-defined hours of duty but with some duty likely to be required each allocated shift. It is relatively simple information to record and tailored to each individual’s circumstances.

There are some general caveats to consider when using prior sleep wake information within an FRMS (see also Appendix E). For example, individuals have different sleep needs, and sleep patterns prior to the last 48 hours can influence a person’s level of fatigue. As well as the quantity of sleep and hours awake, a range of other factors can also influence fatigue and alertness, such as the quality of sleep, time of day, type of work and frequency of rest breaks, all of which need to be monitored and/or managed.

In addition, there were significant problems associated with the implementation of the PSWR by the operator. These included:

  • The PSWR values used by the operator were the standard thresholds proposed by Dawson and McCullough (2005). These authors also stated that different thresholds would be appropriate depending on the risk profile of the tasks being performed or their susceptibility to fatigue-related error. However, the operator’s FRMS did not discuss the risk profile of single pilot night VFR MPT operations. It would be reasonable to expect that such operations have a higher risk profile than many other types of work tasks.
  • The operator’s guidance for using the sleep logs encouraged pilots to record any sleep. Given that sleep and duty was only recorded in 1-hour blocks, this effectively resulted in pilots rounding sleep up and over-estimating the amount of sleep they had obtained.
  • According to the FRMS manual, any exceedance of the PSWR (as recorded in a pilot’s sleep log) meant that a pilot could not undertake any duty. Depending on a range of factors, there can be some cases where small exceedances of PSWR thresholds may have minimal effect, and could be managed with the use of appropriate mitigators.
  • There was no explicit means of recording sleep quality, or at least noting problematic sleep quality, in the sleep log.
  • The operator also (and reasonably) encouraged pilots to sleep before and between MPT tasks when on shift. However, there was no discussion in the FRMS manual.[77]

More importantly, the major limitation of applying the PSWR as the primary means of determining a pilot’s fitness for work is that it relies upon accurate sleep information. Inaccurate recording of sleep would fundamentally devalue the potential of the approach to manage fatigue, and when pilots are recording the sleep information there are a range of potential factors that can affect how this information is recorded.

In this case, the instructor (and to some extent the pilot under supervision) over-reported their hours of sleep and under-reported their hours of duty in the days before the accident. The ATSB also observed multiple other pilots misreporting hours of sleep and duty on multiple occasions. This primarily included many instances of pilots recording long sleep periods of 12 hours or more, which research would suggest should be rare, even when workers have significant breaks between shifts (for example, Roach and others 2003). In addition, there were many cases where pilots recorded sleep when other information indicated they were awake. The effect of the misreporting was that the sleep logs did not show the increased fatigue risk associated with problematic hours of work and sleep.

The operator’s FRMS stated that pilots were to report if they felt fatigued and unable to fly, or if their recorded sleep and duty within the sleep log did not meet the requirements of the PSWR. The FRMS also stated that such reporting would be ‘totally supported’ by management. Evidence from some of the operator’s pilots, however, indicated that they perceived implicit and explicit pressure to ensure that they recorded sleep and duty that did not exceed the PSWR thresholds. Pilots reported feeling pressured to ‘make the roster work’, by recording incorrect information.

The simplicity of the PSWR rule set and the design of the sleep log meant it was obvious to pilots what they needed to do to clear fatigue alerts, and when they had reported enough sleep to enable them to conduct a task. Pilots could simply adjust the sleep log values until fatigue alerts disappeared, and pilots reported doing exactly that. In this way, the nature of the sleep logs facilitated any pilot who was motivated to record a pattern of sleep that allowed them to complete the duty allocated to them.

These experiences and perceptions of the operator’s pilots are consistent with the results of an ATSB survey on the fatigue experiences of Australian commercial pilots.[78] This survey showed that most pilots never removed themselves from duty due to fatigue, and that most pilots who did remove themselves from duty perceived this left a negative impression with management. The results also showed that almost half of the pilots surveyed said they were either ‘not comfortable’ reporting as unfit for duty due to fatigue or were only ‘rarely’ comfortable to make this assessment.

It is apparent that problems with inaccurate sleep recording had been occurring for some time prior to the accident. Although the FRMS required the chief pilot to review sleep records, there was no evidence available to show that this had occurred, nor any other oversight activity undertaken to determine the accuracy of the sleep and wake data recorded in the sleep logs. Had the operator compared recorded sleep times with flight records, or queried any sleeps longer than 12 hours, this may have provided an opportunity to identify inaccurate sleep recording and address fundamental issues associated with the operator’s application of the PSWR within its FRMS.

The use of the operator’s FRMS as an alternative method to comply with the flight and duty time limitations prescribed in CAO 48.1 was based on a CASA-issued exemption under subsection 4 of CAO 48.0. The operator’s FRMS did not include the use of a biomathematical model of fatigue (BMMF), which is often used as a key component in many FRMSs that do not include restrictive flight and duty time limits. Instead, the FRMS primarily relied on pilots using the PSWR and recording sleep information to determine their own fitness for duty.

As evidenced by this investigation, an FRMS that fundamentally relies on the PSWM has challenges than need to be carefully managed. Such an approach also fundamentally relies on the fidelity of sleep information. Unless the FRMS can facilitate accurate recording of sleep information, and actively assure that the information is accurate, then additional means of managing fatigue risk will also be required.

Other factor that increased risk

The operator's fatigue risk management system relied extensively on a sleep reporting spreadsheet (sleep log) that was based on the prior sleep wake model, and the spreadsheet had a transparent rule set that made the recorded data easy to modify to achieve results that met the operator’s minimum sleep and wake requirements. In the context of perceived pressure to present as fit for duty, multiple pilots on multiple occasions had entered unrealistic or inaccurate sleep times and there were limited effective controls in place to assure that the sleep times being entered by pilots was accurate. (Safety issue)

Sleep log coding error

The sleep log spreadsheet contained a coding error for the PSWR ‘extended wakefulness’ rule. In effect, it double counted the sleep in the period 25–48 hours prior to the specific time, and therefore increased the allowed period of extended wakefulness for several hours in most situations. The consequence of this error was that the sleep log would not highlight circumstances where a pilot was awake for greater than their sleep in the previous 48 hours.

The spreadsheets also pre-loaded the hours of 2200 to 0600 as sleep for all days. A pilot anticipating a night shift would need to clear the pre-loaded sleeps from that night to identify the times in which they would not have sufficient rest.

The ATSB considered the influence of the sleep log coding error and pre-loaded sleep on the fatigue experienced by the pilot under supervision. A correctly coded spreadsheet may have provided the pilot under supervision with an additional prompt that they would not have sufficient rest when operating late on the night of the accident, which may have further encouraged them to attempt to sleep prior to the accident flight. However, messages sent to the pilot’s partner indicate that, even without this prompt, the pilot wanted to have a nap on the day of the accident, but was unsuccessful in their attempt to rest.

Other factor that increased risk

The sleep log tool used by the operator contained a coding error and it also pre-loaded sleep periods of future nights by default. This combination of factors reduced the likelihood pilots would identify fatigue risks associated with insufficient sleep and extended wakefulness. (Safety issue)

Port Hedland pilot roster change management

The operator’s FRMS had not been updated since 2014, prior to the start of undertaking MPT contract work at Port Hedland in April 2017. Consequently, the rosters described in the FRMS manual were not directly applicable to the work conducted in Port Hedland. That is, they did not include a roster pattern involving a day shift (0600–1800) followed by a night shift (1800–0600), with the potential for additional day or night shifts as required. Because the FRMS did not describe the rosters worked by Port Hedland pilots, this limited the ability of the operator to identify and manage the attendant fatigue-related risks.

In addition, as already discussed, the night shifts at Port Hedland involved single pilot operations under the night VFR. This risk profile for single pilot night operations was not discussed in the FRMS manual. The only night operations with assessments were those involving 2-pilot crews under IFR.

The timing of the Port Hedland night shifts meant that, towards the end of the shift, pilots would be operating in the window of circadian low, or the time of day associated with the lowest level of alertness. In addition, if pilots conducted 2 night shifts in a row, they would potentially be sleeping during the day between the shifts, which was likely to result in restricted sleep quantity and quality.

Analysis of the hours worked by Port Hedland line pilots indicated that, in most cases, they were not associated with significant risks due to the nature of the MPT schedule. Nevertheless, there were risks that needed to be carefully assessed and managed, with relevant controls outlined in the FRMS manual.

A new operational environment with a different roster pattern would generally meet the criteria for a significant change that required risk management. However, there was no evidence of the operator having used a biomathematical model or other means for assessing the roster, or during ongoing oversight of the suitability of that roster. The absence of a formal consideration of the fatigue implications the Port Hedland contract work significantly impaired the ability of the operator to identify and mitigate any attendant risks.

Other factor that increased risk

The operator's fatigue risk management system did not describe the roster pattern or night shifts worked by line pilots based at Port Hedland, and the operator did not conduct a formal risk assessment of the roster prior to commencing marine pilot transfer operations at Port Hedland.

Installation of emergency location transmitters

During the investigation the ATSB noted that the ELT was mounted to the PELICAN rack in the rear of the cabin. The helicopter manufacturer did not mount the ELT in that position and did not consider the PELICAN rack to be structural or load carrying. As such, the installation was inconsistent with the Radio Technical Commission for Aeronautics (RTCA) guidelines.

The ELT was installed as part of the emergency medical service modifications before the helicopter was imported into Australia. The ATSB did not locate any documentation to show that the PELICAN rack had been assessed and approved as a suitable location for installation of crash activated equipment such as an ELT.

An ELT is designed to automatically activate when the unit is subjected to forces in excess of threshold values. If the ELT is not mounted to primary structure, impact forces can be attenuated by mechanisms such as distortion or separation of the secondary structure.

In this occurrence, the vertical impact forces were almost certainly within the range for automatic activation of the emergency locator transmitter (ELT) but the Cospas-Sarsat satellites did not receive any transmissions from the helicopter. However, if the ELT had activated, the transmissions would have been attenuated by the rapid inversion of the helicopter and submersion of the antenna so non receipt of transmissions was not necessarily indicative of ELT non-activation. Due to water ingress damage to the ELT, the ATSB was unable to measure battery voltage as an indicator of ELT operation.

Given the ATSB was unable to establish if the ELT activated, the ATSB was also unable to determine if the mounting of the ELT on non-primary structure had a negative effect on ELT activation. Nevertheless, the ATSB is concerned about the potential for incorrectly mounted ELTs to not activate during accidents with associated delays to search and rescue.

Consequently, the ATSB advises operators of aircraft with a non-standard ELT installations to verify conformance with RTCA guidelines to ensure the maximum probability of automatic activation in an accident.

Other factor that increased risk

The ELT was mounted to the PELICAN rack in the rear of the EC135 cabin rather than to primary load carrying structure, which increased the risk of non-activation during an accident.

Regulatory oversight

Previous ATSB reports have noted that regulatory oversight processes will always have constraints in their ability to detect problems such as restricted time and limited resources. Due to resource constraints, regulatory surveillance by CASA is by necessity sample‑based and cannot examine every aspect of an operator’s activities, nor identify all the limitations associated with these activities.

Nevertheless, in 3 investigation reports released in the last 4 years, the ATSB noted that CASA’s processes for scoping surveillance events did not formally include the nature of the operator’s activities, the inherent threats or hazards associated with those activities, and the risk controls that were important for managing those threats or hazards.

In the 3 years prior to this occurrence involving VH-ZGA in March 2018, CASA recorded 3 surveillance events related to the operator without identifying any significant operational safety concerns. As the surveillance event in 2017 was a desktop assessment of a limited range of airworthiness documentation, MPT operations were out of scope.

The defined scope of the ‘Level 1 Health Check’ carried out 3 weeks before the occurrence included operational standards and authorised activities, but there is no indication that the auditors considered the efficacy of risk controls for MPT operations. This was similarly the case for the ‘Level 1 Systems Audit’ in 2016.

The ATSB noted that the CASA auditors in 2016 had observed there was no management process to support the chief pilot’s working practices. There was no requirement for the operator to address this observation and no indication that the operator responded. In any event, CASA auditors in February 2018 noted that the chief pilot and head of operations demonstrated adequate control of the flying operations.

Post-occurrence, CASA checked that MPT operators were complying with their own requirements for HUET recency and assessed the operator’s arrangements for crew scheduling and fatigue management at Port Hedland. No safety concerns were identified. The regulatory and safety review carried out by CASA in response to the occurrence did not identify any requirements for immediate action or significant learnings.

In addition to time and resource constraints that inhibit scope and sampling, auditing is generally carried out with reference to criteria such as regulatory material and operator manuals. As there were no specific regulations for twin-engine MPT operations, the operator’s manuals were the primary references for any audit of the MPT operation. An assessment of the suitability of the operator’s procedures could be referenced to best practice guidelines.

The German Federal Bureau of Aircraft Accident Investigation (BFU) investigated a BK117 helicopter accident that occurred during circling for an approach to a vessel on a dark night. The BFU found that in the context of no regulations for offshore helicopter flight operations in Germany, the operator’s procedures and assessment by the supervising authority were insufficient.

BFU safety recommendation 24/2015 stated that the German Civil Aviation Authority should ensure that operators conducting night VFR approaches to sparsely lit landing sites should specify practical and detailed procedures in their handbooks that are appropriate to the special demands of this type of operation, and which specify systematic, consistent and comprehensive use of the resources available to the conduct of the flight.

In relation to this occurrence, the operator’s process for line training was not under CAR 217 or CASR Part 141/142 and there was limited criteria for CASA assessments of that process. However, with the introduction of new regulations applicable to MPT operations, the operator will be required to provide a training and checking system with defined standards.

Another element of regulatory oversight was application of the authorisation holder performance indicator (AHPI) questionnaire. Although the operator responded that ship landings were one of its highest risks and they operated in challenging environments, this had no apparent effect on surveillance priorities or risk assessment.

Given that the underlying problem associated with the scoping of surveillance events was extensively discussed in recent ATSB investigations (AO-2017-005 and AO-2018-026), further discussion was not considered necessary in this report. As part of the earlier investigation, the ATSB issued a safety recommendation (AO-2017-005-SR-026) to CASA in October 2019, and this recommendation was closed in March 2020 after CASA outlined the safety actions it had taken and was taking to address the issue. In addition, the Australian National Audit Office (ANAO) commenced an audit in April 2021 into planning and conduct of CASA’s surveillance activities.

Other factor that increased risk

Although the operator’s primary helicopter activity was conducting marine pilot transfers, regulatory oversight activity by the Civil Aviation Safety Authority had not specifically examined the operator’s procedures and practices for conducting approaches and landings to ships at night in degraded visual cueing environments.

  1. Sleep inertia: a short period of time immediately after awakening associated with poorer task performance and a feeling of mental sluggishness.
  2. Fatigue Experiences and culture in Australian commercial air transport pilots (2019). Report published by the Australian Transport Safety Bureau, Canberra.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the collision with water involving EC135 P2+ helicopter, VH-ZGA, 37 km north-north-west of Port Hedland, Western Australia, on 14 March 2018.

Contributing factors

  • During the positioning flight for the third supervised marine pilot transfer at night, circling in the vicinity of outbound bulk carrier Squireship was conducted in a degraded visual cueing environment, with associated increases in pilot workload and risk of disorientation.
  • Following a circuit, missed approach, and climb to 1,100 ft, a descent was initiated without coupling a vertical navigation mode of the autopilot. This was not consistent with standard operational practices and significantly increased the attentional demands on both pilots and associated risk of deviation from circuit procedure.
  • During the downwind and base segment of the circuit, the pilots did not effectively monitor their flight instruments and the helicopter descended below the standard circuit profile at excessive rate with decaying airspeed. Neither pilot responded to the significantly abnormal flight path or parameters until the radio altimeter alert at 300 ft.
  • The instructor responded to the radio altimeter alert, reducing the rate of descent from about 1,800 ft/min to 1,300 ft/min, but this response was not consistent with an emergency go-around and did not optimise recovery before collision with water.
  • After the unexpected and significant water impact in dark conditions, the helicopter immediately rolled over and the cabin submerged then flooded. The instructor escaped through an adjacent hole in the windscreen and used flotation devices until rescued but the pilot under supervision was unable to escape the cockpit and did not survive.
  • The instrument panels fitted to VH-ZGA and the operator's other EC135 helicopter at Port Hedland were equipped for single-pilot operation under the instrument flight rules. When used for flight training or checking in a degraded visual cueing environment, this configuration has a detrimental effect on the ability of an instructor or training/check pilot to monitor the helicopter's flight path and take over control if required. (Safety issue)
  • When operating at Port Hedland in degraded visual cueing environments, the instructor had not been able to ensure that circling approaches were consistent with the operator's standard operating procedures. This probably limited the support provided to the pilot under supervision on the occurrence flight and, in combination with other factors, probably contributed to the abnormal flight path and partial recovery.
  • The pilot under supervision was introduced to line flying at night in a degraded visual cueing environment immediately after completion of the minimum-required 10 ship landings by day and without any preparatory night flying. Given the pilot under supervision was transitioning from a different helicopter type and operational environment, the lack of consolidation contributed to high cognitive workload for both pilots and increased the risk of sustained flight path deviations.

Other factors that increased risk

  • The operator rostered the pilot under supervision for marine pilot transfer flying without ensuring that helicopter underwater escape training (HUET) had been completed in accordance with the operations manual. Although the pilot under supervision had completed HUET in 2009 and 2011, the lack of recency reduced preparedness for escaping the helicopter following submersion.
  • Although the instructor was flying when significant deviations from standard operating procedures occurred during night approaches in January 2018, these were not reported to the operator or otherwise addressed by the instructor.
  • The operator's training and assessing procedures for marine pilot transfer operations did not provide assurance that pilot under supervision experience, helicopter instrumentation, and instructor capability were suitable for line training at night in a degraded visual cueing environment. (Safety issue)
  • The operator’s circuit and approach procedures for marine pilot transfer operations did not minimise pilot workload or provide the recommended stabilised approach criteria with mandatory go-around policy. These procedures could allow a combination of conditions that increased the risk of a sustained abnormal flight path and collision with terrain/water. (Safety issue)
  • Due to a combination of limited sleep in the 48 hours prior to the accident and extended wakefulness on the day of the accident, the pilot under supervision probably experienced a level of fatigue known to adversely influence performance.
  • The operator's fatigue risk management system relied extensively on a sleep reporting spreadsheet (sleep log) that was based on the prior sleep wake model, and the spreadsheet had a transparent rule set that made the recorded data easy to modify to achieve results that met the operator’s minimum sleep and wake requirements. In the context of perceived pressure to present as fit for duty, multiple pilots on multiple occasions had entered unrealistic or inaccurate sleep times and there were limited effective controls in place to assure that the sleep times being entered by pilots was accurate. (Safety issue)
  • The sleep log tool used by the operator contained a coding error and it also pre-loaded sleep periods of future nights by default. This combination of factors reduced the likelihood pilots would identify fatigue risks associated with insufficient sleep and extended wakefulness. (Safety issue)
  • The operator's fatigue risk management system did not describe the roster pattern or night shifts worked by line pilots based at Port Hedland, and the operator did not conduct a formal risk assessment of the roster prior to commencing marine pilot transfer operations at Port Hedland.
  • The ELT was mounted to the PELICAN rack in the rear of the EC135 cabin rather than to primary load carrying structure, which increased the risk of non-activation during an accident.
  • Although the operator’s primary helicopter activity was conducting marine pilot transfers, regulatory oversight activity by the Civil Aviation Safety Authority had not specifically examined the operator’s procedures and practices for conducting approaches and landings to ships at night in degraded visual cueing environments.

Other findings

  • There was insufficient evidence to establish whether the instructor was affected by fatigue at the time of the accident, though it is likely they were experiencing a level of fatigue in previous days.
  • There was no evidence of any helicopter defects or anomalies.
  • When the helicopter was recovered, the right audio controller was found in the pilot isolate configuration and it was not possible to establish if this occurred before, during, or after the impact sequence. If pre-impact, this would have prevented effective communication between the pilots and potentially influenced the occurrence.

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Configuration of instrument panel for instructor or training/check pilot in degraded visual cueing environments 

Safety issue number: AO-2018-022-SI-03

Safety issue description: The instrument panels fitted to VH-ZGA and the operator's other EC135 helicopter at Port Hedland were equipped for single-pilot operation under the instrument flight rules. When used for flight training or checking in a degraded visual cueing environment, this configuration has a detrimental effect on the ability of an instructor or training/check pilot to monitor the helicopter's flight path and take over control if required.

Operator’s training and assessing procedures for marine pilot transfer operations in degraded visual cueing environments 

Safety issue number: AO-2018-022-SI-005

Safety issue description: The operator's training and assessing procedures for marine pilot transfer operations did not provide assurance that pilot under supervision experience, helicopter instrumentation, and instructor capability were suitable for line training at night in a degraded visual cueing environment.

Operator’s circuit and approach procedures for marine pilot transfer operations and criteria for achieving a stabilised approach 

Safety issue number: AO-2018-022-SI-04

Safety issue description: The operator’s circuit and approach procedures for marine pilot transfer operations did not minimise pilot workload or provide the recommended stabilised approach criteria with mandatory go-around policy. These procedures could allow a combination of conditions that increased the risk of a sustained abnormal flight path and collision with terrain/water.

Use of sleep reporting spreadsheet and potential for modification of data input to meet operator’s minimum requirements 

Safety issue number: AO-2018-022-SI-02

Safety issue description: The operator's fatigue risk management system relied extensively on a sleep reporting spreadsheet (sleep log) that was based on the prior sleep wake model, and the spreadsheet had a transparent rule set that made the recorded data easy to modify to achieve results that met the operator’s minimum sleep and wake requirements. In the context of perceived pressure to present as fit for duty, multiple pilots on multiple occasions had entered unrealistic or inaccurate sleep times and there were limited effective controls in place to assure that the sleep times being entered by pilots was accurate.

Risk controls associated with pilots identifying fatigue risks associated with insufficient sleep and extended wakefulness 

Safety issue description: AO-2018-022-SI-01

Safety issue description: The sleep log tool used by the operator contained a coding error and it also pre-loaded sleep periods of future nights by default. This combination of factors reduced the likelihood pilots would identify fatigue risks associated with insufficient sleep and extended wakefulness.

Additional safety action

Additional safety action by Heli-Aust Whitsundays Pty Limited

The operator advised the ATSB of the following additional safety actions taken following the accident:

  • The operator has equipped all personal flotation devices (life jackets) used by pilots with an emergency breathing system (EBS).
  • The operator relocated the emergency locator transmitter installed in VH-ZGZ from the PELICAN rack to primary load carrying structure (cockpit floor, adjacent the pilot seat).
  • Newly recruited pilots are required to complete training in helicopter underwater escape (HUET) and use of EBS prior to commencing flight training/operations.
  • All pilots are required to complete recurrent HUET and proficiency using EBS every 2 years, with an extension of up to 6 months in accordance with the operations manual.
  • With the support of its customer, the operator has introduced night vision imaging systems (NVIS) to the Port Hedland marine pilot transfer operation.
  • With the support of their customer, the operator has supplied the Port Hedland base with 2 Airbus Helicopters H135 equipped with the Helionix avionics suite. This includes terrain avoidance capabilities and a 4-axis autopilot.
Additional safety action by the Civil Aviation Safety Authority

The Civil Aviation Safety Authority advised the ATSB of the following additional safety actions taken following the accident:

  • CASA conducted a national desktop audit of helicopter underwater escape training (HUET) for AOC holders conducting MPT operations.
  • In September 2018, CASA carried out a Level-2 operational check of the operator with a site inspection at Port Hedland in response to concerns raised by pilots about crew scheduling and fatigue management. The surveillance report concluded that the operator’s ‘crew scheduling and safety management procedures were found to be suitable and effective in managing fatigue’.

Previously issued safety advisory notice

Safety advisory notice to all helicopter operators engaged in overwater operations

In May 2018, concurrent with the publication of the preliminary report, the ATSB issued the following safety advisory notice to all overwater helicopter operators.

SAN number:AO-2018-022-SAN-001
SAN release date:3 May 2018

The Australian Transport Safety Bureau advises helicopter operators involved in overwater operations of the importance of undertaking regular HUET for all crew and regular passengers to increase their survivability in the event of an in-water accident or ditching.

Glossary

°CDegrees Celsius
2DTwo-dimensional instrument approach procedure
AAIBAir Accidents Investigation Branch (UK)
ADS-BAutomatic dependent surveillance broadcast
AFCSAutomatic flight control system
AFMAircraft flight manual
AGLAbove ground level
AHPIAuthorisation holder performance indicator
AISAutomated identification system (marine shipping)
ALA(s)Aeroplane landing area(s)
ALTAltitude
ALT.AAltitude acquire
ALARApproach and landing accident reduction
AMSAAustralian Maritime Safety Authority
AMSLAbove mean sea level
ANAOAustralian National Audit Office
AOCAir operator’s certificate
APMAutopilot module
APMSAutopilot mode selector
ASIAirspeed indicator
ATCAir traffic control
A.TRIMAutomatic trim
ATSBAustralian Transport Safety Bureau
AVADAutomated voice alerting device
AWBAirworthiness bulletin
BARSBasic aviation risk standard
BEABureau d’Enquêtes et d’Analyses (France)
BFUBundesstelle für Flugunfalluntersuchung (Germany)
BoMBureau of Meteorology
BMMFBiomathematical model of fatigue
C1Charlie 1, marine navigation beacon
C2Charlie 2, marine navigation beacon
CAAPCivil aviation advisory publication
CADCautions and advisories display
CAOCivil Aviation Order
CASACivil Aviation Safety Authority
CARCivil Aviation Regulation
CASRCivil Aviation Safety Regulation
CEOChief executive officer
CFITControlled flight into terrain
Cospas-SarsatSpace system for the search of vessels in distress - Search and rescue satellite-aided tracking
CPDSCentral panel display system
CVRCockpit voice recorder
DARDigital aircraft recorder
DCUData collection unit
DVEDegraded visual (cueing) environment
EBSEmergency breathing system
EECElectronic engine control
EFISElectronic flight information system
EGPWSEnhanced ground proximity warning system
ELTEmergency locator transmitter
EPC(Flight) examiner proficiency check
EPIRBEmergency position indicating radio beacon
FAAFederal Aviation Authority (US)
FADECFull authority digital engine control
FAIDFatigue audit InterDyne
FATOFinal approach and take-off area
FCOMFlight crew operations manual
FDRFlight data recorder
FLIFirst limit indicator
FPFlying pilot
FPMFlightpath management (HeliOffshore publication)
FRMSFatigue risk management system
FSAGFatigue safety advisory group
FSTDFlight simulation training device
FTLFatigue tolerance level
FTRForce trim release
ftFeet
ft/minFeet per minute
FOFirst officer
GAGo-around
GAGeoscience Australia
GAMAGeneral aviation manufacturers association
GPSGlobal positioning system
GPWTGrid point wind and temperature
HDGHeading
HEELHelicopter emergency egress lights
HF/NTSHuman factors/non-technical skills
HOOHead of operations
HTAWSHelicopter terrain awareness and warning system
HUETHelicopter underwater escape training
IASIndicated airspeed
ICAOInternational Civil Aviation Organization
ICUSIn command under supervision
IFInstrument flight
IFRInstrument flight rules
IMCInstrument meteorological conditions
IPCInstrument proficiency check
JARJoint Aviation Requirements
JRCCJoint Rescue Coordination Centre (Australia)
KIASKnots indicated airspeed
ktKnot
LBALuftfahrt-Bundesamt (Germany)
LSALTLowest safe altitude
MDAMinimum descent altitude
mMetres
mmMillimetres
MMIMast moment indicator
MOSManual of Standards
MPTMarine pilot transfer
MSAMinimum safe altitude
NDNavigation display
NFPNon-flying pilot
NMNautical mile
NTSNon-technical skills
NTSBNational Transportation Safety Board (United States of America)
NVFRNight visual flight rules
NVGNight vision goggle
NVISNight vision imaging system
PBGPilot boarding ground (marine)
PELICANPacking equipment line for integrated concept of avionic nouvelle (new avionics)
PFPilot flying
PFDPrimary flight display
PICPilot in command
PICUSPilot in command, under supervision
PLBPersonal locator beacon
PSWMPrior sleep wake model
PSWRPrior sleep wake rule
RADALTRadio altimeter
RODRate of descent
RPMRevolutions per minute
RTCARadio Technical Commission for Aeronautics
S&PStandardisation and proficiency
SANSafety advisory notice
SASStability augmentation system
SMSSafety management system
SOP(s)Standard operating procedure(s)
STCSupplemental type certificate
TEMThreat and error management
TSBTransport Safety Board (Canada)
USUnited States (of America)
UTCUniversal coordinated time
V/SVertical speed
VEMDVehicle and engine multifunction display
VFRVisual flight rules
VMCVisual meteorological conditions
VSIVertical speed indicator
VTOSSTake-off safety speed
VYBest rate of climb speed
WSTWestern standard time
WUWarning unit

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • instructor pilot of the accident flight
  • pilot under supervision’s next of kin and pilot under supervision’s partner
  • helicopter operator (Heli-Aust Whitsundays Pty Limited), including management personnel, safety personnel and flight crew
  • Bundesstelle für Flugunfalluntersuchung (BFU), the German Federal Bureau of Aircraft Accident Investigation
  • helicopter manufacturer (Airbus Helicopters Deutschland GmbH)
  • Transportation Safety Board of Canada (TSB)
  • engine manufacturer (Pratt & Whitney Canada)
  • Bureau d’Enquêtes et d’Analyses (BEA)
  • Civil Aviation Safety Authority (CASA) and personnel who worked for CASA during the period prior to the accident
  • Airservices Australia
  • Australian Maritime Safety Authority (AMSA)
  • flight examiners and flight instructors who had flown with the flight crew of the helicopter
  • Pilbara Ports Authority (PPA) and their contractors
  • marine pilots who flown with the helicopter crew and/or witnessed the accident
  • Bureau of Meteorology (BoM)
  • Western Australia Police Force

References

Dawson D and McCulloch K (2005) ‘Managing fatigue: it's about sleep’, Sleep Medicine Reviews, 9:365–80.

Dorrian J, Sweeney M and Dawson D (2011) ‘Modeling fatigue-related truck accidents: Prior sleep duration, recency and continuity’, Sleep and Biological Rhythms, 9:3–11.

Hoh R (1990) The effects of degraded visual cueing and divided attention on obstruction avoidance in rotorcraft, Technical report DOT/FAA/RD-90/40, Federal Aviation Administration.

Kim EJ and Dimsdale JE (2007) ‘The effect of psychosocial stress on sleep: a review of polysomnographic evidence’, Behavioral Sleep Medicine, 5:256–78.

National Transportation Safety Board 2011, Airbag performance in general aviation restraint systems, Safety Study NTSB/SS-11/01.

Rupert A, McGrath B, Mortimer B and Brill JC (2020) Multisensory cueing to resolve helicopter drift detection in DVE. Paper presented at the Vertical Flight Society’s 76th Annual Forum and Technology Display.

Sprajcer M, Thomas MJH, Sargent C, Crowther MW, Boivin DB, Wong IS, Smiley A and Dawson D (2022) ‘How effective are fatigue risk management systems (FRMS)?’, Accident Analysis and Prevention, 165:106398.

Thomas MJW and Ferguson SA (2010) ‘Prior sleep, prior wake, and crew performance during normal flight operations’, Aviation, Space, and Environmental Medicine, 81:665–670.

Van Dongen H, Maislin G, Mullington JM and Dinges DF (2003) ‘The cumulative cost of additional wakefulness: dose-response effects on neurobehavioral functions and sleep physiology from chronic sleep restriction and total sleep deprivation, Sleep, 26:117–126.

Wang Y, White M, Owen I, Hodge S, and Barakos G (2013) ‘Effects of visual and motion cues in flight simulation of ship-borne helicopter operations’, CEAS Aeronautical Journal, 4:385–396.

Watson NF, Badr MS, Belenky G, Bliwise DL, Buxton OM, Buysse D, Dinges DF, Gangwisch J, Grandner MA, Kushida C, Malhotra RK, Martin JL, Patel SR, Quan SF and Tasali E (2015a) ‘Recommended amount of sleep for a healthy adult: A joint consensus statement of the American Academy of Sleep Medicine and Sleep Research Society’, Sleep, 38:843-844.

Watson NF, Badr MS, Belenky G, Bliwise DL, Buxton OM, Buysse D, Dinges DF, Gangwisch J, Grandner MA, Kushida C, Malhotra RK, Martin JL, Patel SR, Quan SF and Tasali E (2015b), ‘Joint consensus statement of the American Academy of Sleep Medicine and Sleep Research Society on the recommended amount of sleep for a healthy adult: methodology and discussion’, Journal of Clinical Sleep Medicine, 11:931-952.

Williamson A, Lombardi D A, Folkard S, Stutts J, Courtney TK and Connor J L (2011) ‘The link between fatigue and safety’, Accident Analysis and Prevention, 43:498–515.

Yeh M, Swider C, Yong JJ and Donovan C (2016) Human factors considerations in the design and evaluation of flight deck displays and controls, Technical report DOT/FAA/TC-16/56, Federal Aviation Administration.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • instructor pilot of the accident flight
  • helicopter operator (Heli-Aust Whitsundays Pty Limited)
  • chief pilot of the helicopter operator at the time of the accident
  • Civil Aviation Safety Authority (CASA)
  • Airservices Australia (ASA)
  • Australian Maritime Safety Authority (AMSA)
  • Bundesstelle für Flugunfalluntersuchung (BFU), the German Federal Bureau of Aircraft Accident Investigation and their advisers (including the helicopter manufacturer, Airbus Helicopters Deutschland GmbH)
  • Transportation Safety Board of Canada (TSB) and their advisers (including the engine manufacturer Pratt & Whitney Canada)
  • United States’ National Transportation Safety Board (NTSB).

Submissions were received from:

  • CASA
  • BFU
  • TSB
  • the instructor pilot
  • the helicopter operator, incorporating comments also from the chief pilot at the time of the accident
  • the family of the pilot under supervision (as a party with an involvement).

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Appendices

Appendix A - 14 March 2018, flights preceding the accident flight

First night flight

The first night flight was to embark a marine pilot to the inbound bulk carrier Anangel Explorer at the pilot boarding ground. The helicopter departed the heliport at about 1859. This was about 15 minutes after last light and the sun’s illumination of the nautical horizon was decreasing.

The flight was conducted under night visual flight rules (night VFR) procedures and helicopter was flown to the pilot boarding ground at about 1,600 ft. This was consistent with procedures for night operations, flying en route at or above the lowest safe altitude[79] (LSALT).

The crew of VH-ZGA initiated descent from cruise altitude when the helicopter was about 2 NM (3.7 km) south of the bulk carrier. The rate of change of geometric altitude broadcast by the helicopter’s ADS‑B equipment indicated an initial descent rate of about 400 ft/min at an estimated airspeed [80] of about 85 kt. After about 30 seconds, the descent rate progressively increased, accompanied by a slight reduction in the airspeed. The descent rate continued to increase and exceeded 1,000 ft/min when the helicopter was about 1 NM (1.9 km) south of the bulk carrier, descending through 1,250 ft at an airspeed of about 80 kt.

Figure 21 depicts the flight path flown in vicinity of the bulk carrier. ADS-B and derived data at the alphabetically labelled points ‘A’ to ‘F’ is depicted in Table 13. Figure 22 graphically depicts the ADS‑B and derived data during the approach.

Figure 21: ADS-B data for VH-ZGA, during a night approach to Anangel Explorer at the pilot boarding ground, during the early evening of 14 March 2018

Figure 21: ADS-B data for VH-ZGA, during a night approach to Anangel Explorer at the pilot boarding ground, during the early evening of 14 March 2018

Representation of recorded track data during the first night flight, to transfer a marine pilot to Anangel Explorer at the pilot boarding ground. This flight was conducted at night, under night VFR procedures. The white track is positions of VH-ZGA recorded by the ASA ADS-B receivers, the yellow track is positions recorded on the FlightRadar24 internet server. The annotated labels A to F correspond to the ADS-B helicopter position relative to the bulk carrier’s landing hatch, as derived from shipping data recorded by the Australian Maritime Safety Authority. Data relevant to the annotated labels for VH-ZGA is presented in Table 13 and marked as labelled index points in Figure 22. The bulk carrier was 289 m in length.

Source: ATSB

Table 13: ADS-B and derived data, associated with the flight path of VH-ZGA depicted in Figure 21

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Altitude (ft)[2]Geometric altitude rate of change (ft/min)
A1905:252,23884871,400-831
B1906:047408287725-1,344
C1907:031,9576577684-
D1907:251,8945352684-
E1908:127884944450-381
F1908:423753226300-319

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature.

[2]  Altitude is either geometric altitude or pressure altitude reported in the ADS-B data set, corrected for atmospheric pressure. Geometric altitude is reported in increments of 25 ft, pressure altitude in increments of 100 ft.

      


The ADS-B data indicated that the helicopter was levelled out at about 700 ft as it passed approximately 450 m abeam the bulk carrier on the downwind leg. The helicopter was about 1,200 m astern of the vessel at an altitude of about 700 ft, when it was turned right to make the base turn and position for final approach.

The turn onto final approach was completed about 1,900 m from the bulk carrier’s landing hatch at an altitude of about 700 ft and an airspeed of about 55 kt.

Figure 22: VH-ZGA derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during the first night approach at the pilot boarding ground

Figure 22: VH-ZGA derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during the first night approach at the pilot boarding ground

Graphical summary of aggregated ADS-B and derived data during the evening of the accident, while VH-ZGA was being operated in vicinity of Anangel Explorer as it approached the pilot boarding ground, in night conditions under the night VFR. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where the ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Figure 21 and Table 13.

Source: ATSB

After embarking the marine pilot to the bulk carrier, the crew flew VH-ZGA back to the heliport and landed at about 1924 and the pilot under supervision refuelled the helicopter. Due to the break in the shipping schedule, the pilot under supervision went back to their nearby accommodation, the instructor remained at the heliport to complete administrative tasks.

Second night flight

The second night flight was to disembark a marine pilot from the bulk carrier Cape Aster at C1/C2. The pilot under supervision arrived back at the heliport at about 2150 to prepare for the flight. The crew departed in the helicopter from the heliport just after 2250, set course for C1/C2 while climbing to 1,600 ft.

At 2257 the pilot under supervision made a radio transmission to the marine pilot on-board the departing bulk carrier. The marine pilot provided operational information relevant for the helicopter’s landing, which included the relative wind direction 60° left of the vessel’s bow at 8 kt and cleared the helicopter to land.

Recorded ADS-B data indicated that the crew of the helicopter established a descent from cruise altitude about 1.3 NM (2.4 km) from the bulk carrier and the rate of descent was about 500 ft/min.

Figure 23 depicts the flight path flown by the crew of the helicopter in vicinity of the bulk carrier. ADS-B and derived data at the alphabetically labelled points ‘A’ to ‘G’ is depicted in Table 14. The ADS-B and derived data is graphically depicted in Figure 24.

Figure 23: ADS-B data for VH-ZGA, during a night approach to Cape Aster as it approached C1/C2, which was the flight immediately prior to the accident flight

Figure 23: ADS-B data for VH-ZGA, during a night approach to Cape Aster as it approached C1/C2, which was the flight immediately prior to the accident flight

Representation of recorded track data during the second night flight, to disembark a marine pilot from Cape Aster at C1/C2. This flight was conducted at night, under night VFR procedures. The white track is positions of VH-ZGA recorded by the ASA ADS-B receivers. The annotated labels correspond to the ADS-B helicopter position relative to the bulk carrier’s landing hatch, as derived from shipping data recorded by the Australian Maritime Safety Authority. Data relevant to the annotated labels for VH-ZGA is presented in Table 14 and marked as labelled index points in Figure 24. The bulk carrier was 292 m in length.

Source: ATSB

Table 14: ADS-B and derived data, associated with the flight path of VH-ZGA depicted in Figure 23

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Geometric altitude (ft)Geometric altitude rate of change (ft/min)
A2303:39-81901,000-513
B2304:15-7887750-194
C2304:461,47883835500
D2305:231,6036056500-381
E2306:008054046300-194
F2306:294213639375+319
G2306:541552122200-1,025

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature.

      

The helicopter passed about 600 m astern of the bulk carrier descending through an altitude of about 1,200 ft, at a descent rate of about 500 ft/min and the airspeed was reducing through 100 kt. The helicopter was then turned right to orbit the vessel and position for the final approach. During the orbit of the vessel, the crew levelled the helicopter at about 550 ft.

The helicopter was turned onto final approach, approximately 1,500 m from the bulk carrier. During that turn, the helicopter’s altitude reduced, and the airspeed decreased below 60 kt. Over the next minute, the altitude continued to reduce. The helicopter descended to about 275 ft, at a range of approximately 700 m from the bulk carrier’s landing hatch, then the helicopter’s altitude started to gradually increase. Over the next 25 seconds, the helicopter’s altitude increased 100 ft while the range to the landing hatch continued to reduce.

When the helicopter was about 300 m from the landing hatch, the helicopter’s altitude was about 375 ft with the airspeed reducing through 35 kt. However, as the airspeed reduced through 30 kt, the geometric altitude rate of change then began to increase. As the airspeed continued to reduce the descent rate then increased, and during a 10-second period the altitude of the helicopter reduced from 300 to 150 ft at a rate of descent exceeding 700 ft/min and the airspeed reducing from 20 to 15 kt.

The descent towards the landing hatch was continued and by about 125 ft, the indicated geometric altitude rate of change had reduced below 300 ft/min, with an airspeed of about 15 kt. The helicopter landed on the bulk carrier about 2307 and the marine pilot was disembarked from the vessel.

Figure 24: VH-ZGA derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Cape Aster at C1/C2

Figure 24: VH-ZGA derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Cape Aster at C1/C2

Graphical summary of aggregated ADS-B and derived data during the evening of the accident, while VH-ZGA was being operated in the vicinity of Cape Aster as it approached the C1/C2 channel markers, in night conditions under the night VFR. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Figure 23 and Table 14.

Source: ATSB

Appendix B – Night flights conducted by instructor at Port Hedland during January 2018

The following flights were conducted by the instructor while providing a period of leave relief during early January 2018. During the early morning of 8 January 2018, a series flights were flown at night under visual flight rules (night VFR) procedures and during which 5 marine pilot transfer (MPT) flights were conducted.

For the first transfer, the helicopter departed from the heliport at 0152 and transited to Shandong Ren He at the pilot boarding ground. Figure 25 depicts the flight path flown by the helicopter in vicinity of the bulk carrier. ADS-B and derived data at the alphabetically labelled points ‘A’ to ‘E’ is depicted in Table 15. The ADS-B and derived data is graphically depicted in Figure 26. On arrival, the helicopter flew past the ship and then circled at 800 ft to join final approach at 600 ft and 60 kt. The descent profile on final approach was not constant, with the descent rate varying between 0 and 1,000 ft/min (Figure 26).

Figure 25: ADS-B data for VH-ZGA, during a night approach to Shandong Ren He at the pilot boarding ground (first transfer)

Figure 25: ADS-B data for VH-ZGA, during a night approach to Shandong Ren He at the pilot boarding ground (first transfer)

Representation of ADS-B data (FlightRadar24) while VH-ZGA was being operated by the instructor at night under the night VFR in vicinity of Shandong Ren He as it approached the pilot boarding ground. Data relevant to the annotated labels A to E is presented in Table 15 and marked as labelled index points in Figure 26.

Source: Google Earth, annotated by the ATSB

Table 15: ADS-B and derived data, associated with the flight path of VH-ZGA depicted in Figure 25

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Derived altitude (ft)[2]Geometric altitude rate of change (ft/min)
A0204:28-99991,013-512
B0204:55-84106813-192
C0205:291,4506053713-512
D0206:097005438513-512
E0206:254754326313-640

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature.

[2]  Altitude has been derived from ADS-B recorded pressure altitude using the atmospheric pressure recorded by meteorological equipment at a nearby channel marker.

      


Figure 26: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Shandong Ren He at the pilot boarding ground (first transfer)

Figure 26: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Shandong Ren He at the pilot boarding ground (first transfer)

Graphical summary of FlightRadar24 ADS-B and derived data while VH-ZGA was being operated by the instructor at night under the night VFR in vicinity of Shandong Ren He as it approached the pilot boarding ground. The airspeed of the helicopter is derived from the ADS‑B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude (where available) and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Figure 25 and Table 15.

Source: ATSB

The flight to conduct the second transfer departed from the heliport at 0230 to pick up a marine pilot from the departing vessel Hebei Triumph, near C1/C2. Late in the transit the helicopter climbed to 2,200 ft then descended at up to 2,000 ft/min to circuit height. Late downwind it climbed to 900 ft then descended in the base turn at up to 1,500 ft/min with reducing airspeed to turn final below 500 ft and 30 kt. The descent profile on final approach was not stable, with the descent rate and airspeed decay moderating after 300 ft (see Figure 27, Table 16 and Figure 28).

Figure 27: ADS-B data for VH-ZGA, during a night approach to Hebei Triumph at C1/C2 (second transfer)

Figure 27: ADS-B data for VH-ZGA, during a night approach to Hebei Triumph at C1/C2 (second transfer)

Representation of ADS-B data (ASA) while VH-ZGA was being operated by the instructor at night under the night VFR in vicinity of Hebei Triumph as it approached C1/C2. Data relevant to the annotated labels A to G is presented in Table 16 and marked as labelled index points in Figure 28.

Source: Google Earth, annotated by the ATSB

Table 16: ADS-B data and derived data, associated with the flight path of VH-ZGA depicted in Figure 27

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Geometric altitude (ft)Geometric altitude rate of change (ft/min)
A0242:00-7596725+319
B0242:27-6467950+575
C0242:46-6346700-1,600
D0242:58-4426450-1,150
E0243:099752814300-638
F0243:377253531475+256
G0244:014752821300-450

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. Where relevant, the airspeed calculation has been adjusted for any effect of the descent flight path vector.

      


Figure 28: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Hebei Triumph at C1/C2 (second transfer)

Figure 28: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Hebei Triumph at C1/C2 (second transfer)

 

VFR in vicinity of Hebei Triumph as it approached C1/C2. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Figure 27 and Table 16.

Source: ATSB

The third and fourth transfers were conducted consecutively during the third flight that morning. A marine pilot was transferred to an inbound vessel (Stella Tess) at the pilot boarding ground and the helicopter was then flown to collect a marine pilot from a departing vessel (China Fortune) at C1/C2.

The helicopter departed the heliport at 0305 and the transit to the pilot boarding ground was flown at 1,100 ft, which was below the lowest safe altitude (LSALT) for conducting flight at night under the VFR. After flying past the inbound vessel at 1,100 ft, the helicopter entered a climb (of maximum 900 ft/min) for about 30 seconds then descended in the circuit at between 400–500 ft/min. The entry into the climb would have occurred soon after the instructor lost visual reference with the vessel (see Figure 29, Table 17 and Figure 30).

Late in the base turn, the helicopter was still at 1,000 ft with rate of descent of about 900 ft/min and a derived airspeed of about 85 kt. The descent profile on final approach varied between 9–18° (short final) with a variable descent rate moderating from mid-final.

Figure 29: ADS-B data for VH-ZGA during a night approach to Stella Tess at the pilot boarding ground (third transfer)

Figure 29: ADS-B data for VH-ZGA during a night approach to Stella Tess at the pilot boarding ground (third transfer)

Representation of ADS-B data (ASA) while VH-ZGA was being operated by the instructor at night under the night VFR in vicinity of Stella Tess as it approached the pilot boarding ground. Data relevant to the annotated labels A to G is presented in Table 17 and marked as labelled index points in Figure 30.

Source: Google Earth, annotated by the ATSB

Table 17: ADS-B data and derived data, associated with the flight path of VH-ZGA depicted in Figure 29

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Geometric altitude (ft)Geometric altitude rate of change (ft/min)
A0312:11-921061,0500
B0312:27-871111,200+575
C0312:47-961111,200-450
D0313:121,80084701,000-894
E0313:321,3507559700-831
F0313:469755842500-575
G0314:403253821300-513

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. Where relevant, the airspeed calculation has been adjusted for any effect of the descent flight path vector.

      


Figure 30: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Stella Tess at the pilot boarding ground (third transfer)

Figure 30: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Stella Tess at the pilot boarding ground (third transfer)

 

Graphical summary of aggregated ADS-B and derived data while VH-ZGA was being operated by the instructor at night under the night VFR in vicinity of Stella Tess as it approached the pilot boarding ground. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Figure 29 and Table 17.

Source: ATSB

After disembarking the marine pilot to the vessel at the pilot boarding ground, the helicopter departed and climbed to 2,000 ft for the transit to China Fortune, which was approaching C1/C2. The helicopter commenced descent as it approached the vessel, joining the circuit at an altitude of about 900 ft mid downwind. Before and during the base turn there was a slight climb then descent increasing to 1,350 ft/min turning finals. This transitioned into a climb of 500 ft/min then a descent at 1,100 ft/min at around 300 ft and about 40 kt airspeed. The descent profile on final approach continued to be unstable (see Figure 31, Table 18 and Figure 32).

Figure 31: ADS-B data for VH-ZGA, during a night approach to China Fortune at C1/C2 (fourth transfer)

Figure 31: ADS-B data for VH-ZGA, during a night approach to China Fortune at C1/C2 (fourth transfer)

Representation of ADS-B data (ASA) while VH-ZGA was being operated by the instructor at night under the night VFR in vicinity of China Fortune as it approached C1/C2. Data relevant to the annotated labels A to H is presented in Table 18 and marked as labelled index points in Figure 32.

Source: Google Earth, annotated by the ATSB

Table 18: ADS-B and derived data, associated with the flight path of VH-ZGA depicted in Figure 31

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Geometric altitude (ft)Geometric altitude rate of change (ft/min)
A0327:23-87801,000-638
B0327:44-7886875+194
C0328:151,5756077950-513
D0328:291,2755556700-1,344
E0328:381,1004645500-1,088
F0329:028003736450+575
G0329:294254125300-1,088
H0329:4330021191500

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. Where relevant, the airspeed calculation has been adjusted for the effect of the descent flight path vector.

      


Figure 32: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to China Fortune at C1/C2 (fourth flight)

Figure 32: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to China Fortune at C1/C2 (fourth flight)

Graphical summary of aggregated ADS-B and derived data while VH-ZGA was being operated by the instructor at night under the night VFR in vicinity of China Fortune as it approached C1/C2. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Figure 31 and Table 18.

Source: ATSB

The fourth flight (transfer 5) departed the heliport at 0355 to pick up a marine pilot from Iron Pilbara near C1/C2. The helicopter overflew the ship at 1,375 ft on descent and joined the circuit to be 1,250 ft by mid downwind. As the helicopter descended in the base turn the descent rate briefly reached 1,700 ft/min at about 700 ft then reduced back to level flight to be established on final approach at 375 ft and airspeed below 40 kt. The descent profile flown during base and final was unstable (see Figure 33, Table 19 and Figure 34).

Figure 33: ADS-B data for VH-ZGA, during a night approach to Iron Pilbara at C1/C2 (fifth transfer)

Figure 33: ADS-B data for VH-ZGA, during a night approach to Iron Pilbara at C1/C2 (fifth transfer)

Pilbara as it approached C1/C2. Data relevant to the annotated labels A to G is presented in Table 19 and marked as labelled index points in Figure 34.

Source: Google Earth, annotated by the ATSB

Table 19: ADS-B and derived data, associated with the flight path of VH-ZGA depicted in Figure 33

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Geometric altitude (ft)Geometric altitude rate of change (ft/min)
A0409:10-921131,275-381
B0409:48-51361,000-1,025
C0410:02-5434700-1,600
D0410:12-4932500-1,088
E0410:381,0753619375-63
F0411:205253627300-381
G0411:403502416150+256

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. Where relevant, the airspeed calculation has been adjusted for any effect of the descent flight path vector.

      


Figure 34: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Iron Pilbara at C1/C2 (fifth transfer)

Figure 34: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Iron Pilbara at C1/C2 (fifth transfer)

Graphical summary of aggregated ADS-B and derived data while VH-ZGA was being operated by the instructor at night under the night VFR in vicinity of Iron Pilbara as it approached C1/C2. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Figure 33 and Table 19.

Appendix C – Line check flight or night VFR rating flight conducted 5 April 2017

Figure 35: ADS-B data for VH-ZGA, during a night approach to Pacific Treasure at the pilot boarding ground

Figure 35: ADS-B data for VH-ZGA, during a night approach to Pacific Treasure at the pilot boarding ground

Representation of ADS-B data (ASA) while VH-ZGA was being operated at night under the night VFR in vicinity of Pacific Treasure as it approached the pilot boarding ground. On board the helicopter was the instructor and the operator’s chief pilot. The flight was recorded as either a line check for the instructor or a night VFR flight review for the chief pilot. Data relevant to the annotated labels A to F is presented in Table 20 and marked as labelled index points in Figure 36.

Source: Google Earth, annotated by the ATSB

Table 20: ADS-B and derived data, associated with the flight path of VH-ZGA depicted in Figure 35

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Geometric altitude (ft)Geometric altitude rate of change (ft/min)
A1923:04-92971,075+63
B1923:48-72731,0500
C1924:152,1507882900-256
D1924:391,2755962725-706
E1924:578503840500-769
F1925:3627527293000

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature.

 

      


Figure 36: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Pacific Treasure at the pilot boarding ground

Figure 36: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Pacific Treasure at the pilot boarding ground

Graphical summary of aggregated ADS-B and derived data while VH-ZGA was being operated at night under the night VFR in vicinity of Pacific Treasure as it approached the pilot boarding ground. On board the helicopter was the instructor and the operator’s chief pilot. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Table 20 and Figure 35.

Source: ATSB

Figure 37: ADS-B data for VH-ZGA, during a night approach to Shandong Zheng Tong at C1/C2

Figure 37: ADS-B data for VH-ZGA, during a night approach to Shandong Zheng Tong at C1/C2

Representation of ADS-B data (ASA) while VH-ZGA was being operated at night under the night VFR in vicinity of Shandong Zheng Tong as it approached C1/C2. On board the helicopter was the instructor and the operator’s chief pilot. The flight was recorded as either a line check for the instructor or a night VFR flight review for the chief pilot. Data relevant to the annotated labels A to E is presented in Table 21 and marked as labelled index points in Figure 38.

Source: Google Earth, annotated by the ATSB

Table 21: ADS-B data and derived data, associated with the flight path of VH-ZGA depicted in Figure 37

PositionTime (WST)Estimated range to landing hatch (m)Derived airspeed (kt)[1]Groundspeed (kt)Geometric altitude (ft)Geometric altitude rate of change (ft/min)
A1936:011,5751051091,250-575
B1937:142,42577771,000-319
C1937:391,5506567700-575
D1938:137254039500-513
E1938:543252825300-256

 

 

[1]  Airspeed has been derived from ADS-B recorded groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature.

      


Figure 38: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Shandong Zheng Tong at C1/C2

Figure 38: Derived airspeed, ADS-B reported altitudes and geometric altitude rate of change during a night approach to Shandong Zheng Tong at C1/C2

Graphical summary of aggregated ADS-B and derived data while VH-ZGA was being operated at night under the night VFR in vicinity of Shandong Zheng Tong as it approached C1/C2. On board the helicopter was the instructor and the operator’s chief pilot. The airspeed of the helicopter is derived from the ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for temperature. The helicopter altitude cross-references the ADS-B geometric altitude and the independently measured pressure altitude, adjusted for surface pressure. The geometric altitude is reported in 25 ft increments, the pressure altitude is reported in 100 ft increments. The geometric altitude rate of change was broadcast by the helicopter’s ADS-B equipment, in increments of 6.25 ft/min. Breaks in the continuity of the data indicate periods where ADS‑B broadcasts were not being received. The labelled time markings correspond with the positions depicted for the helicopter in Table 21 and Figure 37.

Source: ATSB

Appendix D – Principles of helicopter operation

Basic helicopter aerodynamics

Acting on any aircraft in flight are the primary forces of thrust/drag and lift/weight. For helicopters in powered forward flight, the upward force generated by the main rotor (rotor thrust) simultaneously provides the vertical lift component and propulsive component in varying ratios according to the tilt angle of the main rotor. The degree to which the vertical component exceeds weight (and any g‑loading) will influence the rate of climb/descent and the extent to which the propulsive component exceeds drag will influence acceleration. Figure 39 depicts the 4 primary forces acting on a helicopter in flight.

Figure 39: Four primary forces acting on a helicopter in forward flight

Figure 39: Four primary forces acting on a helicopter in forward flight

Source: FAA Helicopter Flying Handbook (FAA-H-8083-21B)

The pilot (or autopilot in some cases) controls the total quantity of main rotor thrust by raising or lowering the collective control to increase/decrease blade pitch with associated increase/decrease of engine power (measured as torque in turbine helicopters). At the same time, the pilot controls the tilt angle of main rotor thrust by moving the cyclic control to selectively change blade pitch and consequently helicopter attitude and direction. Rotation of the main rotor produces a torque reaction which is controlled by the pilot through pedals that alter the pitch of the tail rotor or output of alternative anti-torque mechanism.

Basic helicopter performance

In normal operation, helicopter performance can be limited by high gross weight (mass) and low air density (high altitude and/or high temperatures). Given these factors were not present in this occurrence, the primary influence on in-flight performance was airspeed, manoeuvring, and applied engine power/torque. Although wind is a potential effect on performance, this was generally not a significant factor in the approach phase for this occurrence.

Airspeed is a function of the attitude of the helicopter and applied engine power/torque. The amount of engine power/torque required to maintain a specific airspeed or accelerate/decelerate is related to total drag that varies according to airspeed. (Figure 40) At the lowest point of the total drag curve, the power required is at a minimum and the corresponding airspeed is defined as best rate of climb speed (Vy). Therefore, as a helicopter decelerates through Vy, the power required will progressively reduce then start to increase.

Figure 40: Representative drag curves

Figure 40: Representative drag curves

Source: FAA Helicopter Flying Handbook (FAA-H-8083-21B)

Manoeuvres can have 3 inter-related effects on performance with relatively higher power requirements. Any increase to g-loading is equivalent to an increase in weight and tilting of the rotor will reduce the lift component of main rotor thrust. An increase in anti-torque demand requires additional engine power/torque.

To manage the flight path of a helicopter effectively, the pilot anticipates the engine power/torque requirements for that phase of flight, coordinates the flight control inputs (or commands the autopilot), and monitors performance in case further adjustments are required. If engine power is insufficient, the adverse effect on airspeed and vertical speed (rate of descent) can be compounding.

Vortex ring state

If the flight path, airspeed, and rate of descent of a helicopter is mismanaged, an abnormal condition known as vortex ring state (VRS) can develop. When this occurs, the helicopter descends into air already affected by the main rotor downwash, which significantly impairs main rotor efficiency and thrust. In VRS flight conditions, any further application of power/torque will accelerate the downwash and increase the rate of descent with uncommanded pitch and roll.

Main rotor design

The twin-engine EC135 helicopter was designed with a 4-bladed hinge-less and bearing-less main rotor known as a ‘rigid’ system. Rotor blade movement in all axes is enabled by an inboard flexbeam.

The single-engine B206L helicopter was designed with a 2-bladed teetering‑head main rotor system known as a ‘semi-rigid’ system. This allows the main rotor to flap (move up/down) as an assembly.

As a consequence, the handling characteristics of the 2 helicopters were different. In general terms, the EC135 type was relatively more sensitive to control inputs than B206 types.

Appendix E – Research relevant to the prior sleep wake model

Introduction of the prior sleep wake model

Dawson and McCullough (2005) outlined a series of levels associated with fatigue-risk trajectory (Figure 41). To effectively manage fatigue risk, they stated that a fatigue risk management system (FRMS) should develop appropriate controls at each of the levels. In particularly, they noted that, in addition to prescribing hours of service (HOS) limits, an organisation should also specify controls in terms of prior sleep and wake.

Figure 41: Fatigue-risk trajectory from Dawson and McCullough (2005)

Figure 41: Fatigue-risk trajectory from Dawson and McCullough (2005)

Dawson and McCullough stated:

… we would suggest that knowledge of the frequency distribution of prior sleep and wake could form a rational basis for determining the level of fatigue an individual is likely to experience within a given shift. Furthermore, there is potential for both individuals and organizations to use this information as the basis for rational decision making with respect to fatigue-related risk …

As a starting point for this decision, we suggest that a rational FRMS should be based on prior sleep and wake rules, linked to an evaluation of the adequacy of prior sleep and wake. The reasons for this are straightforward:

Unlike subjective estimates of fatigue, prior sleep and wake are observable and potentially verifiable determinants of fatigue;

Prior sleep and wake provide a way of integrating individual and organizational measures of fatigue (levels 1 and 2) since systems-based approaches can deal with probabilistic estimates of sleep and wakefulness, and individual employees can make clear determinations of individual amounts of actual prior sleep and wakefulness; and

Prior sleep and wake measures can be set or modified according to the risk profile associated with specific tasks or workgroups.

The authors also proposed an algorithm, known as the prior sleep wake model (PSWM), which stated that fitness for work could be determined by specifying appropriate values for sleep obtained in the last 24 hours, sleep obtained in the last 48 hours, and the length of time awake until the end of work.

With regard to sleep within 24 hours, Dawson and McCullough (2005) stated:

Following a single night of sleep loss, it would appear that there is little evidence of a clinically significant reduction in any measure of sleepiness/ alertness until TIB [time in bed] is reduced below 6 h. Most measures show significant clinical levels of sleepiness once TIB is reduced to 4 h. Between 6 and 4 h there is some debate based on the measure used (i.e. psychomotor vigilance, reaction time or more complex cognitive tasks); and the degree to which the task is engaging or boring ...

…it is unlikely that individuals would be significantly impaired at most common work tasks until obtained sleep fell below 5 h in the preceding 24. There are a number of caveats to this conclusion …

With regard to sleep over longer periods, the paper reviewed several studies involving multiple nights of sleep restriction. These included studies by Belenky and others (2003) and Van Dongen and others (2003) that demonstrated a dose-response relationship; as the extent of sleep restriction per day increased and as the number of days of sleep instruction increased, then the extent of the performance deficits increased.

Overall, based on their review of relevant research available at the time, Dawson and McCullough (2005) concluded:

We can extrapolate from this data to conclude that it is unlikely that prior to commencing work an individual obtaining less than 5 h sleep in the prior 24 and 12 h sleep in the prior 48 h and who is awake for longer than the amount of sleep in the prior 48 h is likely to be unimpaired at a level consistent with a safe system of work.

In defining this threshold we caution readers that particular occupational tasks may well be more susceptible to fatigue-related error or the consequences of fatigue-related error are so severe as to require threshold values greater than we have specified. Furthermore, these initial values should be viewed as a starting point and subject to revision in the light of actual workplace experience.

Subsequent research

In 2015, the American Academy of Sleep Medicine and Sleep Research Society developed a consensus recommendation for the amount of sleep needed by adults (Watson and others 2015a). It stated that adults should sleep 7 hours or more per night on a regular basis to promote optimal health. It also stated that sleeping less than 7 hours per night was associated with impaired performance, increased errors and greater risk of accidents.

In further discussion, Watson and others (2015b) stated:

Research findings show two consistent cognitive performance dynamics relative to 8 hours TIB for sleep: (1) The shorter the sleep duration, the greater the cognitive performance deficits; and (2) the longer the exposure to sleep restriction, the greater the cognitive deficits. Thus, the less sleep obtained, and the longer this continues, the more quickly cognitive deficits become evident. Self-reported sleepiness does not show the latter dynamic and therefore cannot be used to track increasing performance deficits. In addition, total sleep duration per 24 hours is the critical factor relative to performance, since split-sleep schedules also show the same sleep dose-response effects. Finally, the adverse effects of limited sleep time are especially severe at circadian times when sleep propensity is high …

In summary, Level I evidence demonstrates that cognitive performance involving vigilance attention, cognitive processing speed and working memory, as well as physiological sleep propensity and drowsy driving are all sensitive to sleep duration below 7 hours.

Although less than 7 hours sleep can have a adverse effect on performance (for most individuals), determining exactly how much sleep is necessary to achieve a minimum or appropriate level of alertness and performance has been a subject of debate. As stated above, Dawson and McCullough (2005) proposed 5 hours sleep in 24 and 12 hours sleep in 48 as minimum operational limits. Other research has indicated that more sleep may be appropriate.

For example, Thomas and Ferguson (2010) found the occurrence of crew errors was higher, and performance at managing threats was poorer, during flights when a flight crew included a captain with less than 6 hours sleep or a first officer with less than 5 hours sleep. Road safety research has also shown that 5–6 hours sleep is associated with significantly more risk of an accident than 7–8 hours sleep (Williamson and others 2011).

One study specifically examined the most suitable PSWM values to predict involvement in fatigue-related truck accidents (Dorrian and others 2011). This study found that using the standard PSWM values (5 hours in 24 / 12 hours in 48) correctly classified 65% of accidents. However, using a modified model (6.5 hours / 8 hours) provided a slightly better prediction (71%), and a model using only sleep in the last 24 hours (6.5 hours) provided even better results (75%). The authors noted that, based on their results, the 5-hour value for the last 24 hours may not be conservative enough.

Dawson and others (2021) reviewed relevant laboratory research studies into the effects of restricted sleep in the previous 24 hours conducted since the Dawson and McCullough (2005) paper. It concluded:

While it appears that there are some effects of 6 h sleep and/or sleep opportunities on next-day cognitive performance, these differences tend to be small in magnitude and are inconsistent in the literature. When sleep is restricted to five hours during a laboratory-based protocol, findings are very consistent. Significant performance decrements after ~5 h prior sleep have been seen in measures such as distractibility …, reaction time, and sustained attention…, and increases in both errors of commission and omission ... This is in line with much of the pre-2005 literature, which demonstrates heightened performance decrements with one night of ~5 h sleep ...

Research into sleep duration of 4 h has indicated that there is a very significant likelihood that all individuals will be impaired in a number of cognitive domains…

The paper also noted some road safety research which indicated that drivers who had obtained 5–6 hours sleep had increased accident risk or poorer driver performance compared to drivers who obtained more sleep.

Dawson and others (2021) also reviewed extended wakefulness research, noting there was limited research available to support the PSWM rule for extended wakefulness when it was developed in 2005. They noted that several studies since 2005 had shown cognitive performance begins to degrade after 16–18 hours of wakefulness, with performance deteriorating further as the duration of wakefulness increased.

Additional information

Although specifying minimum levels of prior sleep before conducting work has significant merit, there are a range of other aspects to consider when applying risk controls based on the PSWM. For example, individuals vary in terms of their sleep needs. In addition, restricted sleep prior to the previous 48 hours can also have some influence on a person’s level of alertness (albeit not as much as the previous 24 or 48 hours).

A range of factors other than the quantity of sleep can also influence fatigue, such as the quality of sleep, time of day and the extent to which rest breaks during work tasks are available and used. The type of work tasks being performed is also critically important and, as indicated by Dawson and McCullough, some types of safety-critical tasks should probably use different PSWM thresholds.

In terms of the time of day, the adverse effects of limited sleep are exacerbated at times of day when sleep propensity is higher, such as during the window of circadian low (Watson and others (2015b). In addition, most of the research into the effect of restricted sleep is based on sleep occurring during the night. The extent to which the same PSWM rules should apply to sleep occurring during the day is unclear. As noted by Dawson and McCullough (2005):

While it is true that when sleep is attempted at an inappropriate circadian time it is typically reported as more disrupted and shorter and subjects report the sleep to be less satisfying, the relationship between neurobehavioral performance recovery and sleep duration and quality are typically confounded.

Another key aspect to consider when applying the PSWM is the accuracy of sleep information. Some research has shown that people generally overestimate the amount of sleep they obtain (Lauderdale and others 2008, Jackson and others 2018). People also underestimate the impact of several days of sleep restriction (Banks and Dinges 2007, Watson and others 2015b), and therefore may not recognise the importance of accurately reporting sleep information.

More importantly, within a work context, there are many factors that can influence how people will report information such as their amount of sleep. Depending on the consequences of what they report, employees may be more likely to overestimate the amount of sleep they obtain. The ATSB is not aware of any published research that has examined the accuracy of reported sleep information in the context of an FRMS that uses the PSWM.

Applications of the PSWM

Prior sleep and wake information is used in by many organisations as part of an FRMS (Sprajcer and others 2022), and the ATSB is aware of many aviation and rail organisations who have integrated the PSWM into their fatigue management processes. This has generally been as an additional type of risk control to the use of minimum hours of work requirements and a biomathematical model of fatigue (BMMF) to evaluate planned work schedules. In some cases, the use of the PSWM has only been required when considering an extension or change to a planned work schedule. In other cases, the PSWM information has been provided to employees as educational information for them to evaluate their own fitness for work.

In many cases, the application of the PSWM involved allocating points depending on the extent of any exceedance of the 24-hour, 48-hour and extended wakefulness rules. This individual fatigue likelihood score (IFLS) was then compared with a table of listed score ranges that specified likely fatigue-related symptoms and, more importantly, mandatory and/or optional risk controls to implement to manage the risk associated with the overall score. This approach typically allocated more points for every hour of exceedance of the 24-hour rule than the other rules.

Most applications of the PSWM use the default values stated by Dawson and McCullough (2005). However, some applications use higher thresholds, such as 6 hours sleep in the last 24 hours and 13 hours sleep in the last 48 hours.

Prior to the current investigation, the ATSB had not encountered an FRMS which required operational personnel to record their sleep and wake information and for an organisation to use that information to determine fitness for duty in accordance with the PSWM. The ATSB is not aware of any published research evaluating the effectiveness of an FRMS based primarily on using the PSWM to determine whether operational personnel are fit for duty.

  1. LSALT is 1,000 ft higher than the highest obstacle 10 NM (19 km) either side of planned track.
  2. The estimate of airspeed was derived from ADS-B groundspeed and ground track using the wind velocity and atmospheric pressure recorded by meteorological equipment at a nearby channel marker and corrected for tem

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2022

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Preliminary report

Report release date: 03/05/2018

This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

The occurrence

On 14 March 2018, at about 2330 Western Standard Time,[1] an Eurocopter Deutschland GMBH EC135 P2+ helicopter, registered VH-ZGA and operated by Heli-Aust Whitsundays Pty Limited,[2] departed Port Hedland Heliport,[3] Western Australia to collect a marine pilot from a departing bulk carrier and transfer that person back to Port Hedland.

The flight was being conducted in the charter category, at night under the Visual Flight Rules (VFR). A pilot recently employed by the operator was flying the helicopter, under the supervision of a company training and checking pilot.

At about 2348, while the helicopter was being operated in the vicinity of the bulk carrier, it descended and collided with the water. The training and checking pilot escaped from the helicopter and was rescued a short time later. The location of the other pilot was unknown, and a search continued throughout the night and into the following day. On 17 March 2018, the helicopter wreckage was located on the seabed and the missing pilot was found inside.

This update provides an initial summary of the occurrence circumstances and initial investigation activities.

Background and sequence of events

The operator of the helicopter was contracted by the port operator to transfer marine pilots to and from ships that were berthing and departing Port Hedland. The marine pilots were responsible for the safe navigation of those vessels to and from the port.

Although the helicopters were usually operated on a single-pilot basis, the two pilots had been rostered to fly together on a series of flights during the late afternoon on 14 March 2018, and continuing their duty into that night and the following morning. These flights were the recently employed pilot’s (pilot under check) first night-time marine pilot transfer flights at Port Hedland. The training and checking pilot was the pilot in command and was sitting in the left (copilot) seat of the cockpit. He was supervising the pilot under check, who as the handling pilot for the flights, was seated in the right (pilot) seat of the cockpit. Both seating positions were fitted with fully functioning flight controls.

Marine pilots were normally delivered by helicopter to arriving vessels at the boarding ground for the anchorage. When departing, marine pilots were usually collected from vessels in vicinity of the Charlie One (C1) and Charlie Two (C2) channel markers, about 20 NM north-west of Port Hedland.

During the earlier part of evening, the helicopter crew had completed three flights transferring marine pilots. Two of those flights were at night, one to the anchorage boarding ground to an inbound bulk carrier and the later one to a departing bulk carrier at C1/C2. Soon after that flight arrived back at the heliport and the marine pilot had disembarked, the helicopter pilots departed to collect another marine pilot from C1/C2, on what was to be the accident flight.

Figure 1 depicts Port Hedland, the shipping channel and the location of the channel marker at C2.

Figure 1: Map showing Port Hedland, the shipping channel and Charlie 2

Figure 1: Map showing Port Hedland, the shipping channel and Charlie 2     Source: Pilbara Ports Authority, annotated/modified by ATSB.

Source: Pilbara Ports Authority, annotated/modified by ATSB.

The surviving pilot, who was the training and checking pilot, reported that the flights had proceeded normally and that the first two night flights had been without incident. During night operations, it was standard procedure to use the helicopter’s autopilot during climb, cruise and descent and it would remain engaged until the helicopter was stabilised on final approach, with the landing vessel in sight.

The training and checking pilot recalled that the outbound vessel was sighted and was well-lit with floodlighting of the deck and accommodation quarters. The weather conditions were fine, with no cloud, rain or obstructions to visibility. The wind, relative to the deck of the ship was reported to be ‘red 090, 15 kt’, meaning the environmental wind when combined with the forward motion of the ship, was 15 kt from a relative direction, 90 degrees left of the ship’s bow. That wind direction necessitated an approach to the vessel from its right side, with the helicopter flying a right-direction circuit to land. A circuit was flown around the bulk carrier and the pre-landing checklist was completed, including the arming of the helicopter’s emergency flotation system.

The training and checking pilot reported that the approach continued such that the helicopter was aligned on the final approach. The autopilot ‘upper’ modes were decoupled[4] and the helicopter passed through the ‘entry gate’[5] with an airspeed of 50‑60 kt at 500 ft. Soon after, that approach was discontinued when both pilots agreed that the approach path had become too steep to continue.

The marine pilot awaiting the transfer had sighted the helicopter approaching the vessel. He recalled that there was not a lot of wind, there was no moon but there were stars visible in the sky. The navigation of the shipping channel had been completed and control had been handed back to the ship’s crew. After observing the helicopter circle the vessel, he saw the helicopter again fly past the left side of the vessel, consistent with joining the circuit to land on the deck and he started to make his way down the internal stairwell to the ship’s deck.

After the first approach, the training and checking pilot reported a standard missed approach was flown, the autopilot upper modes were recoupled, and the helicopter was set-up to make another approach. The training and checking pilot recalled that on the second approach, the helicopter was turned inbound on the final approach, the autopilot upper modes were decoupled, they again passed through the entry gate and the deck of the ship was in sight. He recalled that the pilot under check had reduced the power to commence the descent, and again soon after. The training and checking pilot pointed out the descent rate and requested an increase in power and was satisfied that the necessary correction was being made.

By the time the marine pilot had reached the deck of the ship, he could see the helicopter’s anti-collision strobe lights, along with the green navigation light on the right side of the helicopter. He did not recall seeing the red navigation light on the left side of the helicopter, nor the steerable searchlight used by the crew of the helicopter to illuminate the deck of the ship for landing. The marine pilot became concerned about the helicopter’s approach path and assessed that the helicopter was descending low on the horizon compared to previous flights.

The training and checking pilot next recalled hearing the radio altimeter annunciating ‘check altitude, check altitude’. The radio altimeter was programmed to make this annunciation when the radio altitude reduced below the preselected altitude. It was the operator’s standard procedure to set a radio altitude of 300 ft prior to take-off. He stated that he immediately called that he was taking over control of the helicopter and was making a missed approach. He did not recall any alarms or other alerts from the helicopter’s warning systems. Soon after, the helicopter collided with the water surface and the cabin immediately flooded and submerged.

The marine pilot had continued to watch the helicopter as it descended towards the water. He recalled seeing a splash of water, that was lit by a flash from the helicopter’s strobe light and immediately returned to the bridge to commence alerting action with the port authority.

The recorded ground track of the helicopter outbound from the heliport and to the accident site is shown at Figure 2 and the final ground track in vicinity of the vessel can be seen in Figure 3.

Figure 2: Ground track of the helicopter to collect the marine pilot

Figure 2: Ground track of the helicopter to collect the marine pilot. The helicopter was fitted with Automatic Dependent Surveillance Broadcast (ADSB equipment). That equipment enabled air traffic services and other pilots to track aircraft without using conventional ground-based radar installations. The signals transmitted by the ADSB equipment can also be received and recorded by other specialised ground-based receivers, such as those operated by flight tracking websites. Those receivers are situated at n

The helicopter was fitted with Automatic Dependent Surveillance Broadcast (ADSB equipment). That equipment enabled air traffic services and other pilots to track aircraft without using conventional ground-based radar installations. The signals transmitted by the ADSB equipment can also be received and recorded by other specialised ground-based receivers, such as those operated by flight tracking websites. Those receivers are situated at numerous locations around the world and feed data to centralised computer servers and accessed using internet browsers and other utilities. The image displays the server recorded ADSB ground track for the helicopter as it travelled to collect the marine pilot. Source: Background image GoogleEarth, overlaid with FlightRadar24 ADSB track data, annotated by ATSB.

Figure 3: Ground track of the helicopter in vicinity of the departing bulk carrier

Figure 3: Ground track of the helicopter in vicinity of the departing bulk carrier. The image displays the helicopter’s ADSB ground track and pressure altitude (to the nearest 100 ft) while operating in vicinity of the departing bulk carrier. The positions of the distress signal from the PLB and the helicopter wreckage are also depicted. Note that the ADSB data points are not at regular fixed-time intervals. The vessel location was broadcast by its automatic information system (AIS). 
Source: Background

The image displays the helicopter’s ADSB ground track and pressure altitude (to the nearest 100 ft) while operating in vicinity of the departing bulk carrier. The positions of the distress signal from the PLB and the helicopter wreckage are also depicted. Note that the ADSB data points are not at regular fixed-time intervals. The vessel location was broadcast by its automatic information system (AIS). Source: Background image GoogleEarth, overlaid with FlightRadar24 ADSB data, AIS data from Pilbara Ports Authority and annotated by ATSB.

The training and checking pilot recalled that he did not have time to take a breath before the cockpit flooded with water. He was submerged in the helicopter and still strapped into his seat. He tried to operate the emergency door jettison but had difficulty remembering the action and did not believe that the door had released. He felt around in front of him and to the left identified an alternative exit pathway and used his left hand to keep hold of that pathway. Using his right hand, he attempted to unplug his helmet communications cord. The cord did not easily disconnect, so using the same hand, he released the helmet chinstrap and removed the helmet. He also used his right hand to release his harness, then placed that hand on the opposite side of the exit pathway and using both hands, pulled himself through that opening to escape the cockpit. After vacating the cockpit and still underwater, he felt for the inflation toggle on his personal flotation device (PFD) and activated one chamber. The chamber inflated normally and took him to the surface.

After reaching the surface, the training and checking pilot saw the helicopter was still afloat but inverted, so he clung onto the helicopter’s left landing skid. He did not see the other pilot and was unsure of his location. The helicopter emergency flotation system had not automatically activated during the initial collision with water and inversion of the fuselage. After a short time, he recalled that the helicopter’s life rafts could be deployed using manual deployment handles mounted on the underside of the helicopter’s rear skid cross-tubes. He activated one of these handles and two life rafts deployed. The life raft that deployed from the left helicopter skid was trapped under the skid. The life raft from the right helicopter skid deployed normally and he boarded that raft. The training and checking pilot recalled that the helicopter floated for a period of time before sinking.

The training and checking pilot also remembered that his PFD was equipped with a personal locator beacon (PLB) and he activated it. The PFD was also equipped with distress flares, and he used these to visually signal his position.

Nearby vessels responded during the initial stages and as did vessels from the port. The initial response was focussed on the distress position indicated by the PLB and the sighting of the flares. The training and checking pilot was recovered from his life raft about 1 hour after the ditching. He had sustained minor injuries.

A surface search for the missing pilot and wreckage was initiated and continued during the night and the next two days. A seabed sonar search of the area also commenced with a hydrographic survey vessel. The helicopter wreckage was identified on the seabed on 17 March 2018 (see Figure 4 and Figure 5). It was substantially intact and resting on its right side in about 20 m of water.

Figure 4: Sonar image of helicopter resting on the seabed, on its right side

Figure 4: Sonar image of helicopter resting on the seabed, on its right side. Source: Pilbara Ports Authority and contractors working on their behalf.

Source: Pilbara Ports Authority and contractors working on their behalf.

Figure 5: Sonar image of helicopter resting on the seabed, on its right side

Figure 5: Sonar image of helicopter resting on the seabed, on its right side. Source: Pilbara Ports Authority and contractors working on their behalf.

Source: Pilbara Ports Authority and contractors working on their behalf.

Divers from the Western Australia Police Force located the missing pilot in the cockpit of the helicopter. At the time of recovery, he was not wearing his helmet, his harness was unfastened, and his PFD had not been deployed.

Video taken by the police divers during their initial dives on the wreckage indicated that the emergency jettison for the left copilot’s door had been activated, but with the door still remaining with the fuselage. The front left cockpit Perspex windshield was broken.

Wreckage recovery

The Pilbara Ports Authority and their contractors commenced action to recover the helicopter, with the assistance of the police divers. The ATSB placed a Protection Order on the helicopter wreckage and provided the necessary permissions to recover the helicopter and transfer into secure storage.

The helicopter wreckage was recovered from the seabed during 18 and 19 March 2018 (Figure 6). The wreckage was moved into the secure storage area where it was examined by the ATSB.

Figure 6: Helicopter wreckage being lifted onto the dock

Figure 6: Helicopter wreckage being lifted onto the dock. Source: ATSB.

Source: ATSB.

Pilot information

Training and checking pilot

The training and checking pilot held a Civil Aviation Safety Authority (CASA)-issued Part 61 Air Transport Pilot Licence – Helicopter (ATPL(H)) and an Air Transport Pilot Licence - Aeroplane. Relevant checks recorded in his company recency record indicated for helicopters:

  • an instrument proficiency check on 7 June 2017
  • a low-level flight review on 14 October 2016
  • an instructor rating on 24 May 2016
  • a flight examiner rating on 8 June 2017
  • a multi-engine helicopter flight review and EC135 biennial flight review on 27 October 2016
  • a base check on an EC135 on 17 March 2017
  • simulator training H135 on 17 March 2017
  • CAO 20.11 training on EC135 on 17 July 2017
  • a line check on 5 April 2017
  • a night VFR review on 24 May 2016
  • Class 1 pilot medical, valid to 2 October 2018.

The training and checking pilot had last completed helicopter underwater escape training (HUET) on 9 September 2015.

Records indicated that the training and checking pilot had flown to Port Hedland on 5 March 2018 and had been rostered to fly through to 15 March 2018, before flying out from Port Hedland on 16 March 2018. The training and checking pilot had been completing flight reviews and checks on a number of the company pilots in Port Hedland, in addition to a number of days flying with the pilot under check during the accident flight.

Pilot under check

The pilot under check held a CASA-issued Part 61 ATPL(H). Relevant checks recorded in his company recency record indicated:

  • a low-level flight review on 16 August 2016
  • a base check on an EC135 on 12 March 2018
  • CAO 20.11 training on EC135 on 5 March 2018
  • a night VFR review on 4 August 2016
  • Class 1 pilot medical, valid to 18 April 2018.

The pilot under check had last completed HUET on 9 February 2009.

Records indicated that the pilot under check had completed company induction in Mackay the week prior to the accident and had flown to Port Hedland on 9 March 2018. Those records indicated he was continuing training in Port Hedland until 18 March 2018 and due to commence line operations at Port Hedland from 20 March 2018.

Meteorological information

Meteorological and hydrographic information in vicinity of the accident site was routinely recorded by the Pilbara Ports Authority ‘Metocean’ equipment. That information comprised data on the sea state, tidal movements, wind velocity and atmospheric pressure.

During the late evening, light seas and a gentle ebbing tide (less than 1 kt) was being recorded in vicinity of the C2 beacon, the closest recording site to the accident location.

At 2350, the wind was about 11 kt from 253 degrees, with gusts to 13 kt. The atmospheric pressure was 1008.5 hPa.

Last light on 14 March 2018 at Port Hedland was 1845. The moon was a waning crescent with 9 per cent of the visible disk illuminated. The moon had set at Port Hedland at 1619 and was due to rise again at 0356 on 15 March 2018. Consequently, there was no visible moon at the time of the accident.

Helicopter information

The helicopter was powered by two Pratt & Whitney PW 206 B2 engines, both with digital engine control (FADEC) systems. The power from the engines was transferred to the main rotor blades by the main transmission, a two-stage flat design gearbox.

The helicopter was equipped with a four-bladed, hydraulically-controlled rigid main rotor. Antitorque was provided by a Fenestron-type system.

The helicopter cabin had two hinged doors for the pilot and copilot seating positions and two sliding doors on either side of cabin. Each of the hinged doors had the ability to jettison the door via pins securing the door hinges to the fuselage. Each of the rear sliding doors had a pop-out emergency exit.

The helicopter was equipped with a three-axis autopilot and a stability augmentation system. Instrumentation fitted to the helicopter cockpit included an integrated primary flight display, a navigation display and a cockpit warning panel. There was also a central panel display system, that comprised the vehicle and engine multifunction and; cautions and advisories displays.

The helicopter was equipped with an emergency flotation system[6] that comprised skid-mounted inflatable floats. The floats could be manually or automatically activated. Manual activation was using a mechanical handle on the pilot’s cyclic control. Automatic activation was via operation of a water immersion switch. Electrical power was required to initiate inflation of the automatic inflation mechanism. The helicopter was also equipped with two life rafts that could be manually deployed using a cockpit handle or external handles fitted to the cross-tubes of the helicopter’s landing skids.

Wreckage examination

The helicopter was substantially intact, although the hub of the main rotor and the main transmission had separated from the airframe during the recovery.

Several of the main rotor blades had sustained significant damage near their blade roots during water impact and one of the blades of the main rotor had struck the helicopter tail boom. The flexible coupling of the main gearbox drive output shaft had sheared. The tail rotor blades of the Fenestron antitorque system exhibited evidence of rotational damage.

Figure 7 illustrates the separated main transmission and the damage to some of the helicopter’s main rotor blades.

Figure 7: Main rotor blades and main transmission, showing damage in vicinity of the blade roots

Figure 7: Main rotor blades and main transmission, showing damage in vicinity of the blade roots. Source: ATSB.

Source: ATSB.

The compressors and compressor housings for both engines showed evidence of engine rotation at impact. To the extent possible due to the nature of the accident damage, continuity of the flight controls was established.

The right cockpit door (pilot under check) was still attached to the airframe and the lock wire for the emergency door jettison was still intact. The emergency jettison for that door was functionally tested and was found to operate normally. The left cockpit door (training and checking pilot) did not remain attached to the airframe during recovery. The lock wire to the emergency jettison handle had been broken and the handle was in the forward (release) position.

The helicopter’s emergency flotation system had not been deployed. Examination of the panel-mounted cockpit arming switch was consistent with the switch being in the armed position. The immersion switch for the automatic inflation system was functionally tested and found to be operating normally. Electrical continuity was demonstrated between the circuit breaker panel, the immersion switch and the servo actuator. Examination of the actuator indicated that neither an automatic or manual inflation had been initiated.

The ATSB recovered various electronic components from the helicopter engines and airframe to assess the non-volatile memory contents. Those units included the:

  • electronic engine control for each engine
  • data collection unit for each engine
  • cockpit warning panel
  • cautions and advisories display
  • vehicle and engine multifunction display.

The ATSB also recovered the linear actuator for the helicopter’s emergency flotation system and the flotation arm switch.

Helicopter underwater escape training

Helicopter underwater escape training (HUET) has been in use in one form or another around the world since the 1940s and is considered best practice in the overwater helicopter operating industry. HUET is designed to improve survivability after a helicopter has ditched or impacted into water. Research of accidents into water has shown that occupants who survive the initial impact will likely have to make an in-water or underwater escape, as helicopters usually rapidly roll inverted post-impact. The research has also shown that drowning is the primary cause of death following a helicopter accident into water.

Fear, anxiety, panic and inaction are the common behavioural responses experienced by occupants during a helicopter accident. In addition to the initial impact, in-rushing water, disorientation, entanglement with debris, unfamiliarity with harness release mechanisms and an inability to reach or open exits have all been cited as problems experienced when attempting to escape from a helicopter following an in-water accident.[7]

HUET involves a module (replicate of a helicopter cabin and fuselage) being lowered into a swimming pool to simulate the sinking of a helicopter. The module can rotate upside down and focuses students on bracing for impact, identifying primary and secondary exit points, egressing the wreckage and surfacing. HUET is normally part of a program of graduated training that builds in complexity, with occupants utilising different seating locations and exits. This training is conducted in a controlled environment with safety divers in the water.

HUET is considered to provide individuals with familiarity with the crash environment and confidence in their ability to cope with the emergency situation.[8] Interviews with survivors from helicopter accidents requiring underwater escape frequently mention they considered that HUET had been very important in their survival. Training provided reflex conditioning, a behaviour pattern to follow, reduced confusion, and reduced panic.[9]

Like other highly procedural and complex skills, if underwater escape is infrequently practiced, skill decays rapidly.[10] In a UK Civil Aviation Authority (2014) safety review of offshore public transport in helicopters for the oil and gas industries, it was noted that although the frequency of refresher HUET is presently every four years in the UK, this is widely regarded by experts as being inadequate.[11]

In Australia, Civil Aviation Order 95.7.3 required all flight crew engaged in marine pilot transfers in single-engine helicopters to have completed a HUET course. The order has no requirement for undertaking periodic refresher training. There was no regulatory requirement for multi-engine flight crew to have completed a HUET course. However, requirements for HUET and periods for recurrent requalification were often stipulated in the operator’s operations manual.[12]

Operator HUET requirements

The operator’s operations manual required all pilots engaged in overwater (offshore) operations to have completed a HUET course with an approved provider during the previous 3-year period. The manual indicated the chief pilot could extend that period for an individual pilot if circumstances arise which preclude that training being done within the 3-year period. In that situation, the period of extension was to be specified at the appropriate time and would normally not exceed 6 months. The training was to be rescheduled as soon as practicable.

Part 3 of the company operations manual in relation to Port Hedland required all pilots and marine pilots to have completed a HUET course before conducting night transfers.

As indicated above (see section Pilot information), the last HUET completed by the pilot under check (who had recently joined the operator) was in 2009 and was outside the operator’s 3-year recurrent training period. On 6 March 2018, the operator’s chief pilot had booked a HUET course for the pilot under check. The training was scheduled for 24 April 2018, a full-day course with a Brisbane-based training provider. The training and checking pilot had completed HUET within the last 3 years.

The operator provided the ATSB with records of HUET course information for 24 other company pilots, all of whom had completed their HUET training within the required period.

Proposed regulations

The proposed Civil Aviation Safety Regulation Part 133 will apply to Australian air transport operations involving rotorcraft (helicopters, gyroplanes or powered-lift aircraft) that undertake charter passenger or cargo operations under subregulation 206 (1) (b) of the Civil Aviation Regulations 1988. A consultation draft of those regulations were made available in June 2012 and the period for receipt of comment closed in August 2012.

The consultation draft issued in June 2012 included the proposal, for all flights where life rafts were required to be carried, that flight crew members had successfully completed training in ditching procedures, underwater escape procedures, and use of life rafts within the previous 3 years.

The CASA website indicated that the draft regulation was being updated prior to a subsequent public consultation, which is planned for mid-2018.

Safety advisory notice

Action number: AO-2018-022-SAN-001

The Australian Transport Safety Bureau advises helicopter operators involved in overwater operations of the importance of undertaking regular HUET (helicopter underwater escape training) for all crew and regular passengers to increase their survivability in the event of an in-water accident or ditching.

Ongoing investigation

The ATSB investigation is continuing and will include the following:

  • Factors associated with the survivability of the accident.
  • Various factors associated with the operation of the helicopter during dark night conditions under the VFR.
  • Pilot qualifications, training, experience, recency and medical information.
  • Operator policies and procedures for training and checking, including normal and emergency procedures.
  • Helicopter underwater escape training requirements.
  • Analysis of contents of the non-volatile memory from the recovered electronic components.
  • Testing of components from the helicopter’s emergency flotation system.
  • Helicopter maintenance history.
  • Operator policies and procedures for management of fatigue and duty time.

The ATSB will continue to consult with the engine and airframe type-certificate holders. In accordance with the provisions of ICAO Annex 13, the Transportation Safety Board of Canada have been provided status as accredited representative to the ATSB investigation as State of Design and Manufacture of the helicopter’s engines. The German Federal Bureau of Aircraft Accident Investigation have been provided status as accredited representative to the ATSB investigation as State of Design and Manufacture of the helicopter type.

Acknowledgements

The ATSB would like to acknowledge the significant assistance provided during the initial investigation response by the Pilbara Ports Authority, their contractors and volunteer agencies and the Western Australia Police Force.

_____________

The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this report. As such, no analysis or findings are included.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Australian Western Standard Time (AWST): Coordinated Universal Time (UTC) +8 hours.
  2. Heli-Aust Whitsundays Pty Limited was the holder of the Air Operator Certificate issued by the Civil Aviation Safety Authority, the primary trading name for the operation at Port Hedland was Port Hedland Helicopters.
  3. Port Hedland Heliport is located at the seaport of Port Hedland, approximately 5 NM north-west of Port Hedland Airport.
  4. On the EC135, the autopilot is always ‘ON’ during normal operations. The ‘upper’ modes provide typical autopilot functionality for horizontal and vertical control of the aircraft.
  5. This term refers to a specific airspeed/altitude and assists with maintaining a stabilised approach.
  6. Emergency floatation system: inflatable bags to provide water buoyancy in an emergency.
  7. Rice E,V. and Greear J.F. (1973) Underwater escape from helicopters. In Proceedings of the Eleventh Annual Symposium, Phoenix, AZ: Survival and Flight Equipment Association, 59-60. Cited in Brooks C. (1989) The Human Factors relating to escape and survival from helicopters ditching in water; AGRAD.
  8. Ryack, B. L., Luria, S. M., & Smith, P. F. (1986). Surviving helicopter crashes at sea: A review of studies of underwater egress from helicopters. Aviation, Space, and Environmental Medicine, 57(6), 603-609.
  9. Hytten K (1989) Helicopter crash in water: effects of simulator escape training. Acta Psychiatrica Scandinavica, Suppl. 355: 73-78. Cited in Coleshaw S (2010) Report for the Offshore Helicopter Safety Inquiry. Report No SC176.
  10. Summers F (1996) Procedural skill decay and optimal retraining periods for helicopter underwater escape training. IFAP; Willetton, Western Australia. Cited in Coleshaw S (2010) Report for the Offshore Helicopter Safety Inquiry. Report No SC176.
  11. Civil Aviation Authority (2014) Safety review of offshore public transport helicopter operations in support of the exploitation of oil and gas. CAP145.
  12. The requirement for an operator to conduct their operations in accordance with an operations manual was contained in the Civil Aviation Regulations 1988, Regulation 215.

Occurrence summary

Investigation number AO-2018-022
Occurrence date 14/03/2018
Location 37 km north-north-west of Port Hedland Heliport
State Western Australia
Report release date 16/06/2022
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Manufacturer Eurocopter
Model EC135 P2+
Registration VH-ZGA
Serial number 0777
Aircraft operator Heli-Aust Whitsundays
Sector Helicopter
Operation type Aerial Work
Departure point Port Hedland Heliport, Western Australia
Destination Port Hedland Heliport, Western Australia, with intermediate landing on MV Squireship
Damage Substantial

Collision with floodwater involving freight train 6792, Little Banyan Creek, Queensland, on 7 March 2018

Final report

Report release date: 30/06/2020

Safety summary

What happened

At 0152 on 7 March 2018, freight train 6792, operated by Aurizon, departed Cairns, Queensland, for a journey on Queensland Rail’s North Coast Line. A condition affecting the network (CAN) due to wet weather had been declared, and the train crew were required to operate at controlled speed for a significant part of the journey, which meant they were to be able to stop short of an obstruction within half the distance of clear line that was visible ahead.

At 0612, the train rounded the curve prior to the Little Banyan Creek rail bridge, which was under 0.6 m of flowing water. With a sighting distance of about 60 m to the bridge, the train’s speed (50 km/h) was significantly in excess of the controlled speed, and the train entered the floodwater. The train crew were not injured, but there was some damage to the train’s rolling stock, caused by immersion in water.

What the ATSB found

The Little Banyan Creek weather monitoring station’s water level sensor had been out of service for 57 days, and therefore no flood alarm was provided to network control and passed on to the train crew. Further, although there was a closed circuit television camera (CCTV) at the location to enable monitoring of water levels, the illuminator to enable effective operation at night had been out of service for 14 days. Queensland Rail (QR) also did not have an effective means of ensuring that, during situations such as a CAN, network control personnel were aware of the relevant weather monitoring systems that were unserviceable. In addition, QR did not have procedures that required network control personnel to actively search for information about track conditions ahead of a train during situations when conditions had the realistic potential to have deteriorated since the last patrol or train had run over the relevant sections.

The ATSB also found that QR did not have any restrictions on the distance or time that controlled speed could be used as a risk control for safe train operation in situations such as a CAN. The effectiveness of controlled speed has the significant potential to deteriorate over extended time periods due to its effect on driver workload, vigilance, fatigue and risk perception. In addition, Aurizon’s procedures and guidance for two-driver operation during situations such as a CAN did not facilitate the effective sharing of duties and teamwork to minimise the potential effects of degraded conditions on driver workload and fatigue.

What's been done as a result

Following the occurrence, QR improved its processes for ensuring the reliability of weather monitoring systems, and its procedures for ensuring network control personnel were aware of any faults. QR also developed new procedures and training for network control personnel for managing a CAN, including for proactively monitoring conditions on the network. In addition, QR is undertaking further work to guide the use and conditions around controlled speed and restricted speed, and Aurizon is undertaking further work to review its procedures for the management of workload in two-driver operations during a CAN.

Safety message

This occurrence highlights the importance of having serviceable weather monitoring stations at known flooding locations on a rail network, especially during the tropical wet season, and ensuring that if these systems are not functioning then all relevant parties are aware of the problem.

This occurrence also highlights the importance of effective communication between all relevant parties during a condition affecting the network. In particular, train controllers need to ensure that all relevant information associated with the conditions is passed on to train crews and track maintenance personnel so that they can effectively perform their roles.

 

The occurrence

Overview

At 0152[1] on 7 March 2018, freight train 6792, operated by Aurizon, departed Cairns, Queensland, for a journey to Brisbane, Queensland.[2] Heavy rain had fallen in some areas of North Queensland in the preceding hours (night of 6 March) and continued to fall during 7 March. At 0612, the train ran into floodwater over the Little Banyan Creek rail bridge, 134 track km south of Cairns. The train crew were not injured, but there was some damage to the train’s rolling stock, caused by immersion in water.

Events prior to train 6792’s departure

During 5–6 March, Queensland Rail’s (QR’s) North Coast Line was closed for a 36-hour period for planned track maintenance near Rockhampton in Central Queensland. In addition, during the first week of March 2018, a significant amount of rain fell in some areas of North Queensland.

On 6 March, the track maintenance supervisor (TMS, see Track inspection procedures) based at Innisfail conducted a patrol of the track between the Babinda to Cardwell section (Figure 1). The patrol started at 0655 and was completed at 1145. No areas of concern were identified.

Figure 1: Section of North Coast Line from Cairns to Cardwell

Figure 1: Section of North Coast Line from Cairns to Cardwell.
The image shows stations and their distance (in track km) from Roma Street Station in Brisbane. 
Source: QR, modified by the ATSB.

The image shows stations and their distance (in track km) from Roma Street Station in Brisbane.

Source: QR, modified by the ATSB.

During 6 March, the Townsville network control centre commenced preparations to run Aurizon freight train 6792 and Pacific National freight train 67P8 south from Cairns, with the first train expected to depart early on 7 March. These would be the first trains on the Babinda to Cardwell section since the 6 March track patrol.

A ‘condition affecting the network’ (CAN) associated with the wet weather was declared before trains 6792 and 67P8 departed. The regional transit manager (RTM) on duty at the network control centre on 6 March (up until 2030) directed that trains 6792 and 67P8 were to run at ‘controlled speed’, which meant they were to be able to stop short of an obstruction within half the distance of clear line that was visible ahead (see Controlled speed).

At 0050 on 7 March, the train crew (consisting of a driver at the controls and a second driver) of Aurizon train 6792 signed on for duty. At 0127, the driver phoned the network control officer (NCO) on the Townsville North control board. The NCO issued the crew with a written authority for rail traffic (form SW50), which directed them to operate their train at controlled speed between Gordonvale (1658.350 km)[3] and Bilyana (1524.150 km) due to the weather conditions. The controller advised the driver that he did not think the conditions were ‘anything to be too concerned about’, but he requested that the train crew provide advice about the weather and track conditions while en route. The NCO advised that there was no opposing traffic and that train 67P8 would be following close behind them.

Cairns to Innisfail

At 0151, train 6792 left Cairns in heavy rain and at 0222 it passed through Gordonvale (1,658.350 km). At 0228, the driver reported very heavy rain at Aloomba (1,652.310 km), and the NCO reminded him to continue to report on the weather conditions as the train proceeded south.

At 0200, the driver of Pacific National train 67P8 contacted the NCO, and the NCO provided the train crew with a form SW50, which directed them to operate the train at controlled speed between Gordonvale and Bilyana due to the weather conditions. Train 67P8 departed Cairns at about 0220 and travelled about 30 minutes behind train 6792.

At 0308, the driver of the Aurizon train 6792 phoned the NCO[4] and advised that the creek at Babinda (1,622.290 km) was about 1 m from the bottom of the bridge and flowing quickly. He also noted that on the previous day the water was 2 m below the bridge. The driver stated that the rain had eased off, but he was unsure of what was happening in the nearby hills, where water could flow down rapidly. Soon after (at 0314), the NCO advised the driver that he could see on closed-circuit television (CCTV) images from Babinda that the water was about 1 m below the rails.

During the phone call, the NCO also provided the 6792 train crew with a form SW50 for the Mamu Road level crossing (1,602.913 km), located between Waugh and Innisfail. The level crossing had been indicating active to road vehicle users all night, and the form SW 50 required the crew to ensure there was no road traffic prior to entering the crossing.

At about 0333, train 6792 passed through Waugh (1,608.130 km). Soon after, the driver and NCO discussed aspects of the shunting the train crew needed to do in Innisfail. The driver reported it was raining heavily at that time.

At 0345, the driver advised they had passed through the Mamu Road level crossing. He also advised that they had stopped at the Garradunga tramway because the signal was incorrectly indicating red. The second driver had inspected the site and could not rectify the problem.

At about 0400, train 6792 arrived at Innisfail (1,594.120 km) and the train crew commenced shunting operations for the next hour. The crew subsequently reported that it was raining heavily at Innisfail during this period.

At 0400 there was an NCO shift change on the Townsville North control board. The incoming NCO received a handover from the outgoing NCO and a briefing from the RTM (on duty since 2030), and he was advised that trains 6792 and 67P8 were required to be running at controlled speed.

The Innisfail track maintenance supervisor (TMS) contacted the NCO by phone at 0456 and they discussed the overnight weather conditions. The NCO advised that there had been a rainfall alarm at Babinda (north of Innisfail) at 2340, indicating more than 25 mm of rain had fallen in an hour. There had also been a flood alarm at Warrubullen Culvert (1,573.575 km, near Silkwood and about 20.5 km south of Innisfail), indicating that the water level had reached 1 m below the rails at 0311.

The NCO and TMS agreed that the TMS should conduct a patrol (See Track inspection procedures) of the 120 km of track between Babinda and Cardwell (south of Innisfail). The NCO advised the TMS of the current and expected rail traffic on the line. The TMS asked the NCO if the train crews had seen anything, and the NCO replied that they had not reported anything yet. The TMS advised the NCO that he would commence duty at 0600 and would arrive at Babinda at about 0630 to begin the patrol, following trains 6792 and 67P8 south. He noted that his patrol would therefore be conducted before QR’s Spirit of Queensland passenger train operated from Cairns to Townsville.

Innisfail to Little Banyan Creek

At 0504, train 6792 departed Innisfail. The driver and the NCO briefly discussed the weather conditions. The driver advised that it was still raining, and the NCO requested that the crew keep providing updates about the conditions.

Train 6792 passed through Boogan and Silkwood and, at about 0552, it passed through El Arish (1,561.48 km). At 0554 the driver phoned the NCO and advised that it was not raining at El Arish, but the water level was 2.5 feet (about 0.75 m) below the rail bridge over Whing Creek and 2 m below the rail bridge over Big Maria Creek (Figure 2). He noted that both creeks were flowing rapidly.

Figure 2: Route map showing features along the North Coast Line between El Arish and Old Tully Road (left) and Old Tully Road to Little Banyan Creek (right)

Figure 2: Route map showing features along the North Coast Line between El Arish and Old Tully Road (left) and Old Tully Road to Little Banyan Creek (right).
Source: QR.

Note: the diagram is oriented so that the train’s direction of travel is upwards (south). Speed limits are shown in yellow circles; distances are shown in blue text.

Source: QR.

At 0610:09, the driver phoned the NCO and reported that all the culverts between Feluga and Birkalla (Figure 2) were full. He also reported that there was a culvert at the Birkalla tramway crossing where the water was about halfway up the ballast (see also Additional information related to wet weather operations). He advised the NCO to monitor that location because if the water got any higher it would start flowing through and start scouring out the ballast.

At 0611:18, the driver asked the NCO to stay on the phone so he could report on the water level in Little Banyan Creek (1,546.100 km). He also noted that it would be interesting to see the condition of Murray Flats (1,534.410 km), given the water level in the previous culverts.

At 0611:35, the train rounded the left curve on the approach to the rail bridge over Little Banyan Creek (Figure 3). The train’s speed was about 50 km/h, with the maximum permitted speed in normal conditions being 70 km/h. The driver saw floodwater covering the bridge and he immediately attempted to stop the train by applying the emergency brake. The train was unable to stop in the distance available, and it entered the water at 0611:50 (Figure 4).

Figure 3: Train 6792’s route on approach to the Little Banyan Creek rail bridge

Figure 3: Train 6792’s route on approach to the Little Banyan Creek rail bridge.
Source: Google Maps, modified by ATSB.

Source: Google Maps, modified by ATSB.

The distance from brake application to the train stopping was 294 m. After it stopped, the train was on the bridge with the locomotive and first three container wagons partially submerged in about 0.6 m of water (Figure 5). Neither of the train crew were injured.

Figure 4: Train 6792’s locomotive passing over the flooded Little Banyan Creek rail bridge

Figure 4: Train 6792’s locomotive passing over the flooded Little Banyan Creek rail bridge.
Source: QR.

Source: QR.

Figure 5: Empty container wagons behind train 6792’s locomotive, standing on the flooded Little Banyan Creek rail bridge

Figure 5: Empty container wagons behind train 6792’s locomotive, standing on the flooded Little Banyan Creek rail bridge.
Source: QR.

Source: QR.

Post-occurrence events

The driver of 6792 was still on the phone to the NCO as the train entered the floodwater and he immediately notified the NCO of the problem.

The train crew were unable to leave the locomotive due to the surrounding water, and they also believed it was unsafe for them to remain in that position. At 0615, after consulting with their supervisor and the NCO, the driver moved the train forward at low speed through the floodwater and into Tully yard.

After the NCO was notified of the collision with floodwater, the relevant section of track was closed and the following train (67P8) was held at Innisfail.

Train 6792’s crew were replaced by a relief crew. Following discussions between train crew and the rollingstock defect coordinator, the coordinator understood that the water ingress to wheel bearings was minimal. On this basis the relief train crew was authorised to continue to the nearest servicing depot at Townsville. At about 1730 on 7 March, the relief train crew restarted the train and continued south. After running 43 km, the locomotive failed and the train was unable to continue any further. Aurizon subsequently reported that, following a detailed inspection of the train, it identified water damage to the traction motors and all wagon wheel bearings that had been submerged in water.

__________

  1. All time references in this report are in local time (Eastern Standard Time).
  2. The train departed from the Portsmith railway yards, about 2.5 km south of Cairns, and the intended destination was the Acacia Ridge intermodal terminal, about 12 km south of Brisbane.
  3. All distances are in km from Roma Street station in Brisbane.
  4. Most of the communications between the driver and the NCO after the train departed Cairns were via train control radio. However, the driver initiated some communications by mobile phone.

Context

Train and train crew information

Train information

Aurizon train 6792 was an intermodal freight train, servicing customers between Cairns (Portsmith) and Brisbane (Acacia Ridge). On 7 March 2018, train 6792 departed Cairns with one diesel electric locomotive (number 2806) and 28 container wagons. During shunting at Innisfail, three wagons were detached and five other wagons were attached, which resulted in the train having 30 wagons and being 603.5 m long with a gross mass of 1.054 t. Many of the containers on the train were empty, but several were loaded with old road vehicle tyres, bananas and tea.

No problems were identified with the train’s braking performance or other relevant systems.

The train was fitted with a data logger and information from the data logger has been included in the report where relevant. All reported speeds have been rounded to the nearest 5 km/h.

Train crew roles and experience

Train 6792 was operated in the two-driver operation configuration, with a planned crew change in Townsville. In this configuration, two qualified locomotive drivers conducted a variety of duties up to a maximum shift length of 12 hours.

Aurizon’s General Operational Safety Manual stated that, when rail traffic was worked in the two-driver operation configuration, driver duties included:

Rail Traffic Driver at controls

  • take charge of running of the rail traffic

Rail Traffic Driver not at controls to monitor

  • other drivers performance
  • signal aspects
  • speed board changes
  • level crossings
  • other safeworking requirements

Note: By agreement with the rail traffic driver at the controls, the other rail traffic driver can take a short break when it is considered safe to do so and when not in or approaching a Safety Critical Zone.

Both drivers of train 6792 on 7 March 2018 were based in Townsville. They advised that they determined their division of duties before the train departed Cairns. Consistent with their normal practice, they intended to swap driving duties at Bilyana, about halfway between Cairns and Townsville. Up until then, one driver would conduct all train driving, safeworking and reporting duties (including all communications with NCOs).

Driver 1 conducted the driving duties up until the time of the occurrence. He confirmed that there were no requirements for drivers to share driving and related duties when operating a train during a condition affecting the network (CAN) or abnormal event, such as in wet weather conditions.

Driver 2 inspected the train prior to departing Cairns, inspected the signals at Garradunga tramway, and handled the shunting duties in Innisfail yard. During the shunting at Innisfail, heavy rain fell and his clothes were saturated. In the period between departing Innisfail and the occurrence, driver 2 put on dry clothes and dried out in the locomotive cab, and conducted monitoring duties.

Both drivers were qualified to work trains between Townsville and Cairns. Driver 1 had a substantial amount of train driving experience, having first qualified as a driver in 1995, and he had a substantial amount of experience on the North Coast Line. In the preceding 12 months, he had worked over the route 65 times. Driver 2 had worked the route 16 times in the preceding 12 months.

Train crew recent history

Over the 4 days prior to the occurrence, driver 1 had worked four duty periods, as shown in Table 1. He conducted no duty periods in the previous 4 days.

Table 1: Actual duty times for driver 1 over previous 5 days

DateWork activityDuty startDuty endDuty timeTime free (of duty)
3 Mar 2018Day off    
4 Mar 2018Townsville–Cairns040013309.5 hours14.5 hours
5 Mar 2018Cairns–Townsville (road vehicle)040010006.0 hours20.0 hours
6 Mar 2018Townsville–Cairns (road vehicle)060011505.8 hours13.0 hours
7 Mar 2018Cairns–Townville (planned)0050125012.0 hours 

Train 6792 normally departed during the day but, due to the backlog associated with the closure of the North Coast Line associated with planned maintenance, a non-standard start time was required. On 6 March driver 1 and driver 2 drove a road vehicle from Townsville to Cairns to position themselves to operate train 6792 back to Townsville. They signed off duty at 1150 and went to motel accommodation to rest.

Driver 1 reported he had some sleep in the afternoon and woke for dinner. He then returned to sleep for a couple of hours and was woken at midnight by a phone call from the train operator. He stated that at that time he was tired, as was normal for a duty time that commenced in the middle of the night. The driver’s planned and actual duty periods met the requirements of the operator’s fatigue management system.

Driver 2 worked the same duty periods as driver 1 on 6–7 March, and had the previous 2 days free of duty.

Rail line information

North Coast Line

Queensland Rail’s (QR’s) North Coast Line extends 339 km from Townsville to Cairns. Most of the line runs along the foot of the coastal ranges or crosses river flood plains, with major rail bridges over the Mulgrave, Russell, Johnstone, Tully, Murray and Herbert Rivers. In several sections, the route crosses hilly terrain where there can be landslips from cutting faces and fallen trees across the line after periods of wet weather. Some sections of the line have relatively poor alignment, with many tight curves, low bridges and level crossings.

Between Gordonvale and Bilyana, there were 10 sections, with a total distance of 134.2 km. Over the 10 sections, there were a significant number of sites that could be associated with potential hazards. These potential hazards included 83 bridges, 56 speed-restricted curves, 20 sugar cane tramway crossings and 79 level crossings (only 14 equipped with active level crossing protection).

There were usually 17 scheduled passenger and freight trains in each direction each week, operated by QR (5), Aurizon (6) and Pacific National (6). These included QR’s Spirit of Queensland passenger train, which ran between Cairns and Brisbane.

Little Banyan Creek

Banyan Creek is part of the Tully River catchment. It has a small catchment, bounded by the Walter Hill Range and Mount Mackay. The creek flows south along the foot of the range, and its major tributary, Little Banyan Creek, flows south-west to a point of confluence about 1 km north-east of Tully. Banyan Creek joins the Tully River downstream about 7 km further south.

QR’s North Coast Line crossed Little Banyan Creek at 1,546.100 km, about 80 m from the confluence with Banyan Creek. The timber trestle bridge was about 40 m long (Figure 6).

Figure 6: Little Banyan Creek rail bridge

Figure 6: Little Banyan Creek rail bridge.
Source: QR.

Source: QR.

Approaching Little Banyan Creek and Tully yard from the north, the rail track curved to the left on a 502 m radius curve after the Vaughan Street level crossing and dropped down to the bridge (Figure 3). Trains were permitted to run at a maximum speed of 70 km/h around the left curve and over the bridge. At the southern side of the bridge, the maximum speed limit changed to 60 km/h.

Train crew visibility going around the left curve before the bridge was restricted by large trees beside the track, on the inside of the curve (Figure 3). This meant that a driver in a locomotive could not see the bridge until they were about 60 m away.

Calculations conducted by QR determined that, for a freight train similar to train 6792, a driver would have to be operating at a speed of 15 km/h in order to stop within 60 m.

Track inspection procedures

The QR Civil Engineering Track Standard (CETS), document MD-10-575, specified the safety standards and good practice guidelines for the construction and maintenance of track owned by QR.

The standard provided for the following types of track inspections:

  • scheduled patrol
  • scheduled general inspection
  • scheduled detailed inspection
  • unscheduled patrol
  • unscheduled general Inspection
  • unscheduled detailed Inspection.

Scheduled patrols were required to be conducted at a maximum interval of every 96 hours. Such patrols involved examining the track and related infrastructure. They were usually conducted by a single infrastructure worker driving an on-track (hi-rail) vehicle[5] along the track, at a speed not exceeding 40 km/h. Scheduled general inspections (maximum interval 4 months) and detailed inspections (maximum interval 4 years) were more detailed in nature.

The CETS stated that unscheduled patrols, unscheduled inspections or operational restrictions had to be applied in response to various events. These included ‘heavy rainfall / inundation / floods / washaways / ingress of ground water’. The standard also required the rail infrastructure manager to prepare and maintain a hazard location register. The register needed to detail the hazards and the required actions (such as unscheduled patrols or inspections) at hazard locations where defined events might rapidly reduce the capability of the track to safely perform the required function. It stated such locations included track adjacent to an overbridge and track subject to flooding.

The hazard location register for the North Coast Line, from Cains to Cardwell, was last updated in August 2017. It listed 29 locations, with the associated condition or situation of 19 of these locations related to flooding. Some referred to specific locations (such as Banyan Creek) whereas some referred to a distance of up to 14 km of track. Most (14) of the locations were north of Banyan Creek and some (4) were south of Banyan Creek.

Table 2 shows the hazard location entries for Little Banyan Creek (1,546.100 km) and the area immediately north or south. Most of the other entries in the register associated with flooding were similar to the first row in the table.

Table 2: Selected hazard location register entries for locations near Little Banyan Creek

LocationActivity, process, condition or situationDefined eventAction if event occursRecord of event
1530.000 to 1544.300 kmFlooding and washoutsAfter heavy rain during wet season. Track starts to flood when Murray River reaches 7.6 metres or Tully River reaches 8.1 m at EuramoCease traffic until inspectedYearly during wet season in extreme heavy rain
1545.300 to 1546.300 kmFlooding and washoutsAfter heavy rain during wet seasonCease traffic until inspectedYearly during wet season in extreme heavy rain

1546.082 to 1546.130 km

Banyan Ck

Flooding and debris on bridgeAfter heavy rain during wet seasonCease traffic until inspectedYearly during wet season in extreme heavy rain. Train ran through flooded bridge March 08
1546.900 to 1547.700 kmFlooding and washoutsAfter heavy rain during wet seasonCease traffic until inspectedYearly during wet season in extreme heavy rain

Source: QR, modified by the ATSB.

The track maintenance supervisor (TMS) based in Innisfail was responsible for the Babinda to Cardwell section of track. He reported that scheduled patrols were normally done twice a week, once in the northern direction and once in the southern direction. The TMS last conducted a patrol on 6 March (the day before the incident) in a southern direction, which was completed at 1145. After a discussion with the NCO at 0456 on 7 March, he planned to commence another patrol in the southern direction starting at Babinda at about 0630 that morning.

The TMS stated that he was not permitted to conduct patrols at night due to various safety concerns. He said that he had only conducted inspection activities at night in recent years in response to specific incidents at specific locations.

Areas prone to flooding

QR’s Townsville network control centre had developed flood hot spot maps for each of its lines. The map for the North Coast Line from Cairns to Townsville, dated 2010, showed 11 flood hot spots between Gordonvale and Bilyana. These included two spots pointing to the area between Tully (1,545.610 km) and Bilyana (1,524.150 km), with an associated table stating these spots included the areas from 1,531.000–1,548.000 km and 1,530.000–1,544.300 km. The location of QR’s weather monitoring stations was also marked. However, the labels for the flood hot spots and the weather monitoring stations did not include specific location names.

The TMS based at Innisfail had been working in that or similar roles for more than 10 years. He stated that the main areas prone to flooding of the track between Cairns and Bilyana included Harvey Creek (1,632.310 km), Codfish Creek (1,627.270 km), Babinda Creek (1,621.510 km) and the area between 1,530–1,550 km, which included crossings at Little Banyan Creek (1,546.100 km), Murray River (1,5434.410 km) and Corduroy Creek (1,530.290 km) (Figure 7).

The TMS also advised that Little Banyan Creek could get flooded due to localised rain. That is, on some occasions the creek would be flooded but Tully River and other nearby creeks and rivers the rail line traversed would not be flooded.

Previous occurrences of trains entering floodwater

QR reported that there had only been one previous occurrence during the period from January 2008 to March 2018 when a train had entered floodwater on the North Coast Line. That event occurred at Little Banyan Creek on 14 March 2008.

QR advised that it could not locate an investigation report for the March 2008 occurrence, and therefore the detailed circumstances associated with that occurrence were not able to be determined. The information available to QR indicated that crews of trains that passed over the Little Banyan Creek rail bridge provided reports of the water levels at 2245 on 13 March 2008 (1.5 m below the rails), 2315 (dropping since last report) and 0020 on 14 March 2008 (same as last report). However, at 0145 freight train 6C55 went through water that was about 1.2 m above the rails. A situation update at 0500 indicated that other creeks along the line were at least 1.9 m below the rails but Little Banyan Creek was still 1 m over the rails at 0630.

Meteorological and environmental information

General information

The North Coast Line between Cairns and Townsville experiences a wet season from about November to March each year. According to QR, during this period it was common for the network to be impacted by localised flooding in the numerous rivers and creeks over which the line crossed.

Tully is one of the wettest towns in Australia, with an average annual rainfall of 4,083 mm and an average March rainfall of 756 mm.

Forecasts and warnings

In the first week of March 2018, heavy rain fell in many areas of North Queensland. Rain forecast maps issued by the Bureau of Meteorology (BoM) on the morning 6 March 2018 indicated that the area between Cairns and Tully would receive up to 50 mm of rain on 6 March, up to 100 mm on 7 March and between 100–200 mm on 8 March.

BoM issued an initial flood watch at 1514 on 6 March 2018 for coastal catchments between Cooktown (north of Cairns) and Ingham (between Cardwell and Townsville). It stated:

  • Areas of heavy rainfall were expected to develop across the flood watch area later on 7 March and continue into 8 March.
  • Minor flood levels were likely across the flood watch area from late on 7 March.
  • Heavy rainfall may lead to local flooding.
  • Catchments likely to be affected included the Mulgrave, Russell, Johnstone, Tully, Murray and Herbert Rivers.

BoM issued an initial minor flood warning for the Tully and Murray rivers (Figure 7) at 0549 on 7 March. It stated that rainfall totals of 70–300 mm had been recorded across the Tully River catchment since 0900 on 6 March, with the bulk of the rain falling overnight, and further showers then rain were expected. For the Tully River, the warning stated:

River levels are rising in upper reaches of the Tully River.

The Tully River at Euramo is currently at 5.53 metres and rising. The Tully River at Euramo will exceed the minor flood level[6] (6.00 m) Wednesday morning. Further rises are likely as heavy showers continue. Predictions will be updated as required.

For the Murray River (south of the Tully River), the warning stated:

River level rises are being recorded in the Murray River catchment.

River levels are expected to remain below minor flood levels at Murray Flats during Wednesday but with further heavy rainfall expected from Wednesday evening rises above the minor flood level are likely during [8 or 9 March].

QR advised that it received the publicly-available weather forecasts and warnings provided by BoM and had processes in place to assess them and their potential impact on its network. It did not have any arrangements in place for BoM to directly contact QR.

Figure 7: Position of rivers, creeks, and weather stations near Tully

Figure 7: Position of rivers, creeks, and weather stations near Tully.
Source: Google earth, annotated by ATSB

Source: Google earth, annotated by ATSB

Rainfall observations

As indicated above, the initial flood watch stated that locations in the Tully River catchment recorded 70–300 mm of rain between 0900 6 March and 0500 on 7 March.

Table 3 shows daily rainfall figures for 6 and 7 March 2018 for the Tully Sugar Mill (1.35 km south-west of the Little Banyan Creek rail bridge) and some other locations close to the North Coast Line in the Tully River catchment (Euramo and Upper Murray) and north of the Tully River catchment (Mulgrave Hill, Deeral and Innisfail).

Table 3: Rainfall for selected locations 6–7 March 2018

Location24-hour rainfall to 0900
6 March 2018 (mm)
24-hour rainfall to 0900 
7 March 2018 (mm)
Mulgrave Hill (Gordonvale)0.088.0
Deeral0.269.0
Innisfail48.6151.0
Tully Sugar Mill (near Little Banyan Creek)71.0226.5
Euramo (near 1,539.000 km)55.074.0
Upper Murray (11.2 km west of Bilyana)106.070.0

Source: QR, modified by the ATSB.

Water level information

The closest locations to Little Banyan Creek with recorded water level data were:

  • Euramo (near a road bridge crossing Tully River, 500 m south-east of the North Coast Line at 1,539.000 km). The water level reached 4.98 m at 0400 on 7 March and was increasing. It reached the minor flood level of 6.00 m at 0712 and the moderate flood level of 8.00 m at 2219. It subsequently reached 8.80 m at 0141 on 9 March, below the major flood level of 9.00 m.
  • Murray Flats (near a road bridge crossing Murray River, 50 m from the rail bridge crossing Murray River at 1,534.410 km). The water level reached 5.05 m at 0400 on 7 March and was increasing. It reached the minor flood level of 7.00 m at 2226, the moderate flood level of 7.50 m at 0414 on 8 March, and the major flood level of 8.00 m at 1138.

Queensland Rail weather monitoring stations

General information

QR had weather monitoring stations at 10 locations between Gordonvale and Bilyana, including at Little Banyan Creek. The stations could provide various types of information to the Townsville network control centre, including air temperature, rail temperature, humidity, rainfall and water level. Some parameters were only available for some locations. If a specific value was exceeded, the station would transmit an alarm message.

The weather monitoring station at Little Banyan Creek provided information on air temperature, rail temperature, rainfall and water level.

In October 2017, QR commenced testing of weather monitoring stations on the North Coast Line prior to the wet season. Accordingly, a 6-month service of the Little Banyan Creek station was conducted on 31 October 2017, and the system was found to be fully operational.

Weather monitoring station sensors in North Queensland are exposed to extreme weather conditions and regularly experienced faults. Such faults were allocated a lower priority, relative to other types of equipment faults, as they were deemed to be ‘non-vital’ assets that did not directly impact on the movement of rail traffic. Vital systems, including level crossings and signalling systems, were recognised as essential to the movement of rail traffic and were generally accorded a higher priority.

The QR weather monitoring stations were independent of other weather monitoring stations, such as those used by BoM for rainfall at the Tully Sugar Mill and the water level at Euramo and Murray Flats (see Meteorological and environmental information).

Water level monitoring

Nine of the 10 QR weather monitoring stations between Gordonvale and Bilyana, including at Little Banyan Creek, had a water level sensor. These sensors were mounted on rail bridges and measured the vertical distance between the water and the top of the rails.

If the distance reached a certain level, the system would send a flood alarm message. The calibrated levels for a flood alarm were 1.0 m, 0.4 m and 0.1 m below the rails, at rail height, and 0.2 m, 0.5 m and 1.0 m above the rails. All flood alarm messages were sent to the relevant network control officer (NCO) workstation and the regional transit manager (RTM) workstation within the Townsville network control centre.

On 10 January 2018, while working on the Little Banyan Creek rail bridge, a QR maintenance gang damaged a cable running from the water level sensor. A technician attended the site and identified that repairs were required.

On 18 January 2018, a QR engineer, who was monitoring cameras at the site, noted the water level in Little Banyan Creek had risen to the top of the sleepers on the bridge, but the flood alarm had not activated. A new water level sensor was ordered, and a technician attended the site in mid-February to install it. However, the technician was unable to calibrate the sensor. At the time of the occurrence on 7 March 2018, the water level sensor had not been calibrated and it was still offline.

In addition to Little Banyan Creek, QR advised that the water level sensors at two other weather stations between Gordonvale and Bilyana had a ‘failed’ status during the period between 0000 and 0600 on the morning of 7 March. These were Swann Creek (1,656.500 km) and Murray River (1,534.410 km). The Murray River sensor, located close to the Murray Flats station used by BoM, had a failed status since 9 February.[7]

QR advised that the only flood alarm message sent to the network control centre during the 12-hour period leading up to the occurrence was at 0311 on 7 March from the Warrubullen weather monitoring station (1,573.575 km), which stated that the water level was 1 m below rail height.

Total hourly rainfall monitoring

All 10 of the QR weather monitoring stations between Gordonvale and Bilyana, including at Little Banyan Creek, recorded rainfall. One of the two rainfall parameters that was monitored was total hourly rainfall, or the total amount of rain recorded over the previous 60 minutes (calculated every 5 minutes).

If the total hourly rainfall was over 25 mm the system would generate a warning alarm message, and if it was over 50 mm the system would generate a critical alarm message. Warning and critical alarm messages for total hourly rainfall were sent to the relevant NCO workstation and critical alarm messages were sent to the RTM workstation.

On 7 March 2018 at 0039, a warning message was recorded indicating that the total hourly rainfall at Little Banyan Creek was more than 25 mm (actual value 25 mm).[8] QR advised that this should have generated a warning alarm message, however no message was sent. QR advised that following the occurrence it identified that the system as delivered by external developers had not been correctly configured, which meant that a higher amount of rainfall (in the order of 30 mm) was required before a warning message was sent from the device to the server. QR also advised that it had commenced an investigation of these types of issues prior to the occurrence.

The only total hourly rainfall alarm message received by the network control centre during the 12‑hour period leading up to the occurrence was at 2340 on 6 March from the Babinda weather monitoring station, which stated that the total hourly rainfall over the last hour was more than 25 mm (actual value 27 mm).

Derived rainfall rate of change monitoring

The other monitored rainfall parameter was derived rainfall rate of change, or the estimated rainfall per hour based on the amount of rain measured over a 5-minute period.

If the derived rainfall rate was over 25 mm/h, the system would generate a critical alarm message. These critical alarm messages for derived rainfall rate were sent to RTM workstation but not the relevant NCO workstation.

For Little Banyan Creek, critical alarm messages were recorded:

  • 6 March at 1503
  • 6 March at 2039
  • 7 March at 0015.

All three messages stated that the derived rainfall rate changed to more than 25 mm/h (actual value 28 mm/h).

Closed-circuit television cameras

Some locations along the North Coast Line had a closed-circuit television (CCTV) system that provided images that were able to be viewed by the relevant NCO and the RTM. The systems included an illuminator, which allowed a camera to capture artificially-illuminated images during the hours of darkness.

Between Gordonvale and Bilyana, there were four CCTV systems, located at Swann Creek (1,656.500 km), Babinda (1,621.510 km), Little Banyan Creek (1,546.100 km) and Murray River (1,534.410 km). The CCTV at Little Banyan Creek was installed in September 2015.

The CCTV systems automatically generated a new still image every 2 hours. In addition, network control personnel could generate a new image manually at any other time.

On 22 February 2018, QR’s Townsville fault coordination centre received a notification that the camera illuminator at Little Banyan Creek had failed. In its failed state, the images taken by the camera at night were too dark for any detail to be discerned.

A technician was sent to Little Banyan Creek to repair the illuminator, but was not able to access the site due to inclement weather conditions. At the time of the occurrence on 7 March 2018, the camera illuminator had not been repaired.

Morning civil twilight[9] on 7 March 2018 at Tully commenced at 0555. The presence of water over the bridge was discernible on the CCTV footage from about 0550.

Network control information

Townsville control centre

QR’s Townsville control centre consisted of seven control boards, one for each line. A separate network control officer (NCO) provided network control services at each board. An NCO was responsible for controlling rail traffic in accordance with safeworking procedures and conducting related duties.

A regional transit manager (RTM) supervised the overall operations of the NCOs on duty, as well as coordinated activities with external parties. A network support officer assisted the RTM.

The Townsville North control board was responsible for the North Coast Line from Purono (1,368.060 km) to Cairns (1,680.580 km). It was also responsible for the Tablelands Branch from Cairns to Croydon. The Townsville North control board’s workstation included several monitors for displaying safeworking (train progress) information. There was also a communications monitor and another monitor that was used for a range of other tasks, including ViziRail[10] monitoring, GPS location assurance, weather monitoring, email monitoring, access to procedures and sourcing other operational information.

The RTM’s workstation also included a monitor that provided weather-related information.

A large monitor in the control centre displayed current weather radar information for the area from the BoM website.

Network control personnel information

The NCO who commenced duty on the Townsville North control board at 0400 on 7 March 2018 was qualified on five control boards, including the Townsville North board. He had about 3.5 years experience as a controller. He reported that he worked mainly as a relief controller, filling in for others as required, and therefore there could be extended periods where he did not work on the Townsville North control board. He stated that he did not have much experience with far north Queensland wet seasons, and was not aware that Little Banyan Creek was a known location prone to flooding.

During the NCO’s shift, the only traffic on the North Coast Line in the area he was responsible for were trains 6792 and 67P8. During the period after civil twilight (0555) he was dealing with some traffic on the Tablelands Branch, including processing a release for one train at 0600 and issuing a warrant for a track vehicle at 0610.

The RTM on duty in the Townsville control centre at the time of the occurrence was normally a network support officer, but acted in the role of an RTM about once per month. He had conducted RTM duties over a 7-year period, and had previously worked as an NCO in the centre for 15 years. He was aware that Little Banyan Creek was a known location prone to flooding.

The RTM signed on at 2100 and was due to sign off at 0630. He stated that the workload during this shift was higher than normal, due to the wet weather and the planned reopening of the North Coast Line after a significant period of closure due to planned maintenance, which affected the Townsville North control board and other control boards.

QR procedures and guidance for managing wet weather events

General rules and procedures

The QR standard MD-12-189 (Queensland Network Rules and Procedures), outlined the safety requirements for all persons who were required to access and perform activities in the network rail corridor managed by QR. The standard included rules and procedures for operating rail traffic in flood-affected areas (QR 3027). It stated that if an NCO was made aware of flood-affected track, the NCO must stop the rail traffic and arrange inspection by a maintenance representative.

QR 3027 also stated that, when ‘the track is affected by flooding’, a maintenance representative must arrange for track workers to monitor the height of any water and report damage to the NCO, tell the NCO about any rise or fall of the water level, check the condition of the track before any traffic travels through flood-affected areas, and advise the NCO of operating restrictions on affected track. The standard noted that the height of water could be checked using automatic weather stations (where fitted).

MD-12-189 also included rules and procedures for reporting and responding to a condition affecting the network (QR 2009). It stated:

Conditions that can or do affect the safety of operations in the Network must be reported promptly to the Network Control Officer responsible for the affected portions of line…

If necessary, the Competent Worker reporting the Condition Affecting the Network must:

  • prevent rail traffic from approaching the affected portions of line, and
  • apply protection for rail traffic or a line in an emergency.

If there is any doubt about the safety of rail traffic, any fault must be treated as an emergency and workers must:

  • tell the Network Control Officer…

The QR standard MD-10-107 (General Operational Safety Manual) outlined the instructions and procedures for rail traffic movements and other matters. With regard to adverse conditions, it stated:

Where it is required to operate rail traffic in adverse conditions such as:

  • heavy rain,
  • high wind, or
  • reduced visibility…

and these conditions affect or have the potential to affect the safe operation of rail traffic and people on the network, the rail traffic crew will operate their rail traffic to suit the current conditions and advise Network Control of the conditions

Network Control should consult with rail traffic crew, Track Maintenance Supervisors and any other resources available and determine other factors which may impact on the running of rail traffic.

Where information is available to Network Control that relates to the condition of the network, the Network Control Officer will advise if it is unsafe for rail traffic to travel.

The Network Control Officer will impose such special conditions as may apply when rail traffic travel under adverse conditions and these include but are not limited to:

  • continual monitoring
  • restricted speed
  • increased exchange of information to ensure safety
  • updates on changes in weather conditions

Local guidance information

Supplementary to the QR rules and procedures, the Townsville Regional Safety Committee published a set of ‘wet weather protocols’ in December 2011 for use by NCOs in the Townsville control centre. These protocols, which were not a formal part of QR’s safety management system, included the following guidance:

  • We will stop trains when conditions are uncertain, or until track inspection verifies safe for traffic. For example…

- Weather monitors alert to a problem

- Water is in the ballast

- Visibility is poor

- There is a report from the last train over the section that indicates a problem…

  • We recognise the importance of sharing information and will focus on the quality of our conversations by:-

- Provide weather report advice to train drivers at the start of their shift when needed.

- Observe and report on conditions that could stop traffic when travelling across the corridor. For example water levels rising, water entering the ballast and or sever localised storms.

- Sharing information from Train Control on weather conditions to trains in transit where applicable…

Safety alerts

In December 2015, an Aurizon freight train derailed near Julia Creek on QR’s Mount Isa Line, following a flooding event that scoured the ballast and formation of the track. The ATSB investigation[11] identified the following safety issues associated with QR’s procedures:

  • The Queensland Rail General Operational Safety Manual (MD-10-107) contained insufficient guidance for rail traffic crews to ensure the timely identification and management of a potential hazard (resulting from a weather event) that might affect the safe progress of the train. [RO-2015-028-SI-01]
  • The Queensland Rail network rules, procedures and safety manual [MD-12-189] provided insufficient guidance to identify the magnitude of the potential hazard from a weather event, or define the response when encountering water that had previously overtopped the track and receded or was pooled against the track formation or ballast. [RO-2015-028-SI-02]

In January 2016, following the December 2015 derailment, QR issued critical safety alerts to rail traffic crew and network control officers. QR advised the ATSB that the safety alerts were to be trialled over the 2016–2017 wet season and then incorporated into relevant manuals. A subsequent version of the critical safety alert for NCOs was issued in November 2016 and reissued in November 2017.

The 2016/2017 critical safety alert stated:

If Train Traffic Crew observe flood water (or evidence of recent flood water such as debris on the track) in the ballast (above the formation) they must immediately stop the rail traffic (in a controlled manner) and report to the NCO. The rail traffic must not proceed until authorised (verbally) by the NCO. The NCO must consult with relevant infrastructure personnel prior to providing this authorisation.

• Note: This rule does not apply to puddles, drainage water or small volumes of water that would not impact on the structural integrity of the track.

NCOs may become aware of a wet weather related conditions that affect or potentially affect the network by:

  • Reports from the field of

- unusually heavy rain;

- water pooling against the formation or on land adjacent to the railway;

- a washout or scouring of ballast or the formation;

- poor visibility;

- high or rising levels in creeks or waterways.

  • Failure of Track Circuits;
  • Remote monitoring station data
  • Meteorological forecasts, observations, warnings and alerts.

NCOs must seek further information from personnel in the field and from Infrastructure personnel if they are unclear on the condition of the network.

NCOs must stop rail traffic if they become aware of a condition that affects or potentially affects the network. The Network should then be inspected…

Network control personnel were required to sign a document to acknowledge they had received and read the alert in November 2017. The NCO and the RTM on duty at the time of the 7 March 2018 occurrence had both signed the document. Both of them recalled in interview that their understanding of the relevant wet weather procedures was that if water was observed to be in the ballast a train should be stopped.

Specific procedures for conditions affecting a network

On 16 January 2018, QR issued version 1.0 of the procedure MD-18-20 (Supply Chain North – Condition Affecting the Network (CAN) Management). The document stated:

This Procedure is intended to provide strategic guidance for Supply Chain North around management of Conditions Affecting the Network (CAN).

The Procedure draws together information from a number of related standards and instructions that guide the Regional Transit Manager (RTM), Network Control Officer (NCO) and/or Asset Maintenance personnel in decision making on receiving reports of “condition affecting the network”. This procedure does not replace or contradict related standards; instead it aims to provide a link between each requirement by guiding the actions of the leaders…

This procedure outlines how the Townsville Control Centre will identify and manage CAN’s, nominating the functional roles, escalation steps, and integration requirements with other groups of the business and supporting agencies…

In terms of defining a CAN, the document stated:

A CAN is a situation or condition that affects, or has potential to affect, the safety of the Network... Activities directly associated with a CAN included in this document, but not limited to:

Track Defect (Rough track-Buckle-Broken Rail- and other Track defects that affect the Network)

Extreme Weather (Heat-Wind-Floods-Earthquake’s and other Extreme Weather Conditions that affects the Network)

Wildfires

In terms of assessing a CAN, MD-18-189 stated that the RTM and NCO were to utilise the resources from various websites (such as BoM and emergency services sites) and information from the field (via train crews, maintenance personnel, members of the public and other sources).

The procedure provided guidance on how to manage various types of conditions. The guidance related to water-related conditions is outlined in Table 4.

Table 4: Procedures for addressing water-related conditions affecting a network

TypeActionResponse
Flood water evident in the ballast above formation level, or recent evidence of flood water in the ballast above formation level or debris on track, or any signs of washouts or scouring of the formation.

Rail traffic reporting CAN to stop immediately.

All subsequent rail traffic “STOP” and not allowed over reported location or nominated area until Asset Management Staff Inspect track and track has been certified fit for service.

All rail traffic to Stop in reported location or nominated location from RTM and rail traffic to be restrained with an SW11 if applicable. Any subsequent rail traffic to enter reported location or location nominated by RTM is not allowed entry until Track has been inspected by Asset Management Staff and certified fit for service.
Reports of unusual heavy rain or water pooling against formation or adjacent land, high or rising levels in creeks or waterways or any other condition that may affect or potentially affect the network

NCO if possible to obtain information from any other rail traffic or personal in nominated area to obtain an additional assessment.

All rail traffic issued an Instruction (WART) over reported location and instruction remains in place for all rail traffic movement until track has been inspected from Asset Management Staff

All rail traffic is to reduce to “Restricted Speed” over entire section of reported location.
Meteorological forecasts, warnings, alerts and observations, Remote Monitoring Stations, Failure of Track Circuits or advice from Members of the Public or Emergency Services about Wet Weather conditionsRail traffic issued an Instruction (WART) over reported location and instruction remains in place for all rail traffic movement until track has been inspected from Asset Management StaffOn validation of warnings/alerts and observations all rail traffic is to reduce to “Controlled Speed” over entire section of reported location.

Network control personnel reported the specific CAN procedure (MD-18-20) had been sent to them by email, but there had been no specific training in relation to the document.

Use of weather monitoring station and CCTV information

As noted in Queensland Rail weather monitoring stations, the weather monitoring stations were configured to send different types of alarm messages to the NCO’s workstation and the RTM’s workstation, depending on the parameter. More specifically:

  • The NCO’s workstation would receive flood alarms and total hourly rainfall warning alarms (more than 25 mm) and critical alarms (more than 50 mm).
  • The RTM’s workstation would receive flood alarms, total hourly rainfall critical alarms (50 mm) and derived rainfall rate critical alarms (25 mm/h).

All alarm messages were required to be acknowledged by the NCO and/or RTM.

If a weather monitoring station sensor failed, the system would send an alarm message to the RTM’s workstation, which was also required to be acknowledged.

In addition to receiving alarms, data from the weather monitoring station (such as rainfall and water level under the rail) could be viewed at the RTM’s workstation (if the relevant sensor was online). To view the data, the user had to log into a software program on a computer at their workstation. They could also view weather information via the internet on the BoM website on the same computer.

To view the CCTV images from a location, the NCO or RTM had to open a software program on a computer at their workstation and select the desired location. It the program was left open, the site would generate a new image every 2 hours. If the user refreshed the location, a new image would be displayed, but network control personnel advised it would generally take several minutes to load a new image.

Recorded data indicated that a user had refreshed the Little Banyan Creek CCTV image on the following seven occasions:

  • 6 March at 2051 (12 minutes after a derived rainfall rate alarm)
  • 6 March at 2139
  • 6 March at 2356
  • 7 March at 0023 (8 minutes after a derived rainfall rate alarm)
  • 7 March at 0033
  • 7 March at 0114
  • 7 March at 0328 (14 minutes after the NCO had viewed the Babinda Creek CCTV).

Network control personnel reported that in general they would not routinely search for weather information or CCTV information for specific locations unless they had previous advice of problems at those locations. They would typically rely on advice from a track maintenance supervisor (TMS), train crew reports, reports from the public and weather monitoring station alarms to provide information about the extent that weather conditions were affecting the network. They also advised that there were no procedures that required them to proactively monitor weather information or CCTV information ahead of a train’s progress during a CAN event.

Awareness of the status of weather monitoring stations and CCTV systems

The Townsville North NCO and the RTM on duty at the time of the occurrence both reported that they were not aware that the water level sensor at Little Banyan Creek was unserviceable at the time of the occurrence. Both of them assumed that, if the water level rose above the threshold level at that location, they would have received a flood alarm message. In addition, both the NCO and the RTM (and other network control personnel) stated they were unaware that the CCTV illuminator at Little Banyan Creek was unserviceable.

Network control personnel stated that there was no formal process in place to ensure that all RTMs and NCOs were aware that weather monitoring equipment or CCTV equipment at specific locations was unserviceable. The handover documentation for both the NCO and the RTM on duty at the time of the occurrence provided no indication to them that either the water level sensor or CCTV illuminator at Little Banyan Creek were unserviceable. Similarly, there were no other formal notices provided to network control personnel advising them of this information.

The TMS based at Innisfail reported that he also was not aware that the water level sensor at Little Banyan Creek and Murray Creek were unserviceable, and he would not normally be provided with such information. QR confirmed that TMSs were not necessarily advised when water level sensors were faulty or offline. If a fault notification was received and a request for repair work issued, then telecommunications personnel rather than the local TMS would receive the work order.

Train operations information

Aurizon procedures and guidance for managing wet weather operations

On 6 January 2016, following the December 2015 derailment near Julia Creek, Aurizon issued a critical safety alert to its train crew. Similar to the QR safety alert, it stated:

Train Traffic Crew must immediately STOP and report to the Network Control Officer:

  • water on the formation and near the ballast
  • any potential track or formation deficiencies
  • if the track formation and / or supporting ballast cannot be seen
  • any signs of washouts or scouring on the side of the ballast or formation…

The safety alert included the following diagram to clarify the difference between the ballast and formation.

Figure 8: Except from Aurizon safety alert showing difference between ballast and formation

Figure 8: Except from Aurizon safety alert showing difference between ballast and formation.
Source: Aurizon.

Source: Aurizon.

On 21 November 2017, Aurizon issued a safety, health and environment guide titled Operation of rail traffic in adverse weather conditions. Its purpose was to provide guidance to train crews operating in severe weather conditions. With regard to wet weather operations, the guide stated:

When it is necessary to operate rail traffic during fog, heavy rain, unexpected storms and similar circumstances where there is reduced visibility, RTC [rail traffic crew] are to take appropriate steps to protect their safety, the safety of the rail traffic and the track infrastructure by driving to the conditions. RTC should assess the situation and regulate the speed of the rail traffic in accordance with the conditions, and advise the NCO and LRC of their intended action, i.e. they are proceeding at reduced speed because of low visibility.

If operation of rail traffic in heavy rain is required, the Rail Infrastructure Manager (RIM) will normally monitor any flood indicator alarms and/or water levels and to take whatever action is necessary to ensure safe rail traffic operations (e.g. speed restrictions, track closures etc.). RTC operating rail traffic on the affected line(s) are to adhere to any instructions received and take whatever other action is necessary to ensure their own safety and the safety of the rail traffic they are operating.

Occasionally, RTC will encounter storms, flash flooding or similar events where advice is not received from the RIM. In these situations, RTC are to observe any water adjacent to the rail infrastructure. Where the water level is such that the sleepers and the supporting ballast is not visible, or there is signs of washouts or scouring on the side of the ballast and/or in the formation (Refer Figure 1, 2 & 3) the RTC is required to stop the rail traffic and advise the NCO and LRC [live run coordinator].

Additional information related to wet weather operations

Driver 1 of train 6792 recalled that the Aurizon safety alert stated that a train could not proceed if water was observed to be in the ballast. As noted in The occurrence, driver 1 advised the NCO that the water in a culvert at the Birkalla tramway crossing was halfway up the ballast. He subsequently reported during interview that the water at Birkalla was level with the bottom of the ballast (and not in the ballast), and that he exaggerated the level of the water in his phone call to the NCO at 0611 to ensure the NCO took notice. He could see that the track was intact and there had been no scouring of the ballast, and he believed the conditions were safe for his train to proceed. However, he was concerned that the conditions would deteriorate prior to the arrival of the following train at this location.

Driver 1 stated that he was aware of the potential flood hazards along the North Coast Line, and that Little Banyan Creek was one of the most likely locations for flooding. However, in the period leading up to the occurrence, he was not concerned about that location as he was aware that it had a flood alarm and a CCTV system that were monitored by network control, and he believed that if there was a problem the NCO would have advised him about it.

Driver 1 reported that the two drivers discussed the potential hazards they could encounter during their journey that day. He also said they were more concerned about other potential flooding locations that were not actively monitored. In particular, they were concerned about Murray Flats (1,534.41 km), located to the south of Tully. Although there was a weather monitoring station at the river crossing, the land for about 2 km to the south of that was also prone to flooding.

Driver 2 stated he was aware that QR had systems in place to monitor water levels at certain bridges, and would advise them if these bridges were affected by water.

Procedures for communicating with network control

The QR standard MD-12-189 (Queensland Network Rules and Procedures) included requirements for communications between rail traffic crew and network control personnel. The document MD‑14‑36 (General Appendix) supplemented the MD-12-89 standard, and outlined operational instructions that applied on the QR network.

The general appendix stated that mobile phones were prohibited within rail traffic crew compartments while undertaking rail traffic crew duties. The only permitted exceptions involved the failure of the train control radio, situations where no other means of communication was available (and the train was stationary) or to allow emergency contact/fault reporting (but only to be answered by a co-driver not involved in safety critical duties).

Aurizon confirmed that, when its personnel were conducting operations on the QR network, they were required to comply with QR’s network rules and procedures.

Aurizon also had an enterprise-wide guidance document on the use of mobile phones. Its general requirements included:

Aurizon workers shall not use a mobile phone / other electronic device if that use would interfere with their safety or the safety of others…

The use of personal electronic devices is prohibited while any safety-related duty is being performed, unless in case of an emergency or exceptional circumstances.

In a section covering the operation of locomotives and safety critical tasks, it stated:

Radios are permitted for use in accordance with radio protocols. If a mobile phone is required to be used in lieu of the radio then applicable radio protocols must be complied with.

Other drivers, workers and passengers traveling spare may use a mobile phone / other electronic devices if it does not interfere with any safety-related duties or distract the driver.

As noted in The occurrence, the driver of train 6792 used a mobile phone to initiate some of the communications with network control personnel. The driver reported that when he was using his mobile phone he used it in hands-free mode.

Communications involving train 67P8

Pacific National train 67P8 was operating about 30 minutes behind train 6792. All recorded communications between the train crew of 67P8 and the NCOs were conducted via train control radio.

The Townsville North control board NCOs did not ask the 67P8 train crew to provide any information about weather conditions en route. At 0345, the NCO on duty at the time checked that the train crew of 67P8 was aware of the signal problem at the Garradunga tramway reported by the 6792 driver (which the driver had broadcast on train control radio). However, the NCOs did not ensure that any of the information provided by the driver of 6792 about weather and track conditions was passed on to the crew of 67P8.

Controlled speed

Operational speed restrictions

QR was the owner and manager of most of the rail network in Queensland. The QR standard MD‑10-107 (General Operational Safety Manual) included two operational speed restrictions that could be used to manage risk in particular circumstances in its network. These were:

  • controlled speed – a speed that allows rail traffic to stop short of an obstruction within half the distance of clear line that is visible ahead
  • restricted speed – a speed that allows rail traffic to stop short of an obstruction within half the distance of clear line that is visible ahead, but limited to a maximum speed of 25 km/h.

QR did not include any limits or guidance on the duration or distance that a train crew may be required to operate at controlled speed.

In Australia, the Rail Industry Safety and Standards Board (RISSB) and Arc Infrastructure (the owner and manager of the rail network in Western Australia) used similar definitions as QR. They also did not specify any limits on the duration or distance that may be travelled at controlled speed.

For operations in New South Wales, the Australian Rail Track Corporation (ARTC) defined ‘restricted speed’ as a ‘speed that allowed rail traffic to stop short of an obstruction within the distance of clear line that is visible ahead’. The definition did not include a maximum operating speed. Therefore, the ARTC definition of ‘restricted speed’ was similar to the QR definition of ‘controlled speed’, although it referred to the distance of line of sight rather than half the distance of line of sight.

In December 2010, a Pacific National grain train collided with the rear of another grain train at Yass Junction, New South Wales. The ATSB investigation[12] into the occurrence identified the following safety issue:

  • The current ARTC definition of restricted speed requires considerable judgement on the part of train drivers. [RO-2010-013-SI-01]

The ATSB report also stated that, when using restricted speed:

Drivers must use their experience to judge a range of factors, in particular the sighting distance and train braking characteristics in the prevailing conditions. That judgement may also vary significantly between different drivers depending on the level of risk perceived and accepted by that driver. While the definition of restricted speed may be a ‘clear and concise instruction’ its application is not precise and it is something that cannot be measured unless an incident, such as a collision, occurs.

Application of controlled speed on 7 March 2018

Network control had issued the requirement for the train crews of 6792 and 67P8 to operate at controlled speed from Gordonvale to Bilyana. These sections included 134.2 km of track, and the normal sectional running time over these sections (including temporary speed restrictions) was 162 minutes.[13]

As previously discussed (The occurrence), recorded data from train 6792’s data logger showed that the train was travelling at about 50 km/h rounding the left curve prior to the Little Banyan Creek rail bridge. The maximum permitted speed around the curve was 70 km/h in normal conditions, decreasing to 60 km/h at the southern side of the bridge. Therefore, the train was travelling about 10 km/h below the upcoming maximum speed limit.

Driver 1 advised that he was fully aware of the meaning of ‘controlled speed’. He said that network control had issued him with requirements to operate at controlled speed on previous occasions, but he had not previously encountered a situation where he had driven into water or had water over the track. He thought that he was operating the train at about 40 km/h when it rounded the left curve (rather than the recorded 50 km/h). He realised that, in hindsight, he should have been travelling slower to fully comply with the controlled speed restriction. However, he did not expect there would be a hazard at Little Banyan Creek because of the monitoring systems that he thought were in place and working (see Additional information related to wet weather operations).

The ATSB reviewed the train’s recorded speed in earlier parts of the journey on 7 March 2018 and compared it with sectional running times published by QR, including adjustments for temporary speed restrictions. The key results were:

  • Between Gordonvale and Waugh (50.2 km),[14] the adjusted sectional running time was 58 minutes and train 6792’s running time was about 71 minutes. The train’s average speed (42 km/h) was 18 per cent less than the average adjusted sectional running time speed (52 km/h). There were 38 bridges, 27 speed-restricted corners and numerous other potential hazards in these sections.
  • Between Innisfail and Little Banyan Creek (48.0 km),[15] the adjusted sectional running time was 63 minutes and train 9762’s running time was about 68 minutes. The train’s average speed (42 km/h) was 7 per cent less than the adjusted sectional running time speed (46 km/h). There were 20 bridges, 15 speed-restricted corners and numerous other potential hazards in these sections.

In terms of other locations that had a curved track prior to a bridge, similar to Little Banyan Creek:

  • At Harvey Creek (1,632.654 km), the maximum permitted speed in normal conditions was 40 km/h, the train was travelling at about 35 km/h, and there was probably a similar sighting distance of the bridge due to vegetation as at Little Banyan Creek (that is, about 60 m).
  • At Frenchman Creek (1,626.218 km), the maximum permitted speed in normal conditions was 40 km/h, the train was travelling at about 30 km/h, and the sighting distance was more than at Little Banyan Creek.

In both cases, the train would not have been able to stop within half the distance of the line of sight, but at Frenchman Creek the train may have been able to stop prior to reaching the bridge. Both locations had a weather monitoring station with a water level sensor.

The ATSB also reviewed the train’s recorded speed at a sample of other locations. The speeds ranged from close to the maximum permitted speed to speeds significantly below (by more than 20 km/h) the maximum permitted speed. Locations where the speed was significantly below the maximum permitted speed were on both sides of Innisfail, including Whing Creek, about 15 km north of Little Banyan Creek.

In its investigation report into this occurrence, Aurizon noted that the requirement to operate at controlled speed from Gordonvale to Bilyana (134.2 km of track) was excessive for driver concentration.

Network control information indicated that train 67P8, following about 30 minutes behind train 6792, was operated at a similar speed to train 6792 between Gordonvale and Waugh.

Implementation of controlled speed on other occasions

QR provided the ATSB with four other recent examples of the application of controlled speed by the Townsville network control centre. These included:

  • 29 January 2019, between Orkabie and Dawlish (distance 60.0 km) on the North Coast Line for 19.4 hours. The restriction was prompted by a flood alarm that indicated water was 1 m below the rail level at Ilbilbie. Significant rain fell on the Central Queensland coast during 28–30 January 2019 and the TMS in Mackay expressed concern about the water level in culverts at Dawlish. The restriction was applied to five sections of track, which included 24 rail bridges and a number of other sites with potential hazards.
  • 3 February 2019, between Ilbilbie and Koumala (distance 15.9 km) on the North Coast Line for 21.3 hours. A weather monitoring station between Ilbilbie and Koumala was reported to be defective and QR maintenance staff were unable to access the site to make repairs. The restriction was applied to a single section of track with a specific location of concern.
  • 16 February 2019, between Jericho and Longreach (distance 193.6 km) on the Central Western Line for 3.5 hours. A report of heavy rainfall and rising water levels in culverts between Alice and Lochnagar prompted network control to apply controlled speed. The restriction was applied to 10 sections of track. Only one train was affected (the westbound Spirit of the Outback passenger service). The train took 3.4 hours to run from Lochnagar to Longreach, but the controlled speed restriction was cancelled at 1808 after it had run under those conditions for 1.5 hours at an average speed of about 50 km/h.
  • 29 March 2019, between Pombel and Ingham (distance 13.1 km) on the North Coast Line for 1.1 hours. Water was reported to be about 0.3 m below the Cattle Creek rail bridge. The restriction was applied to a single section of track with a specific location of concern. The controlled speed restriction was applied until it was confirmed that the water level was dropping, and only one train was affected.
Use of restricted speed in the United States

In the United States, the General Code of Operating Rules (GCOR) were common to most railroads in North America. The GCOR stated:

6.27 Movement at Restricted Speed

When required to move at restricted speed, movement must be made at a speed that allows stopping within half the range of vision short of:

  • Train.
  • Engine.
  • Railroad car.
  • Men or equipment fouling the track.
  • Stop signal.

or

  • Derail or switch lined improperly.

When a train or engine is required to move at restricted speed, the crew must keep a lookout for broken rail and not exceed 20 MPH [32 km/h]…

6.28 Movement on Other than Main Track

Except when moving on a main track or on a track where a block system is in effect, trains or engines move at a speed that allows them to stop within half the range of vision short of:

  • Train.
  • Engine.
  • Railroad car.
  • Men or equipment fouling the track.
  • Stop signal.

or

  • Derail or switch lined improperly…

In other words, the GCOR definition of ‘restricted speed’ was similar to the QR definition, but more explicit about the types of obstructions that were applicable. The equivalent of controlled speed was only applicable off a main track, where only short times or distances would be encountered.[16]

Based on a review of five accidents in 2011, the United States National Transportation Safety Board (NTSB) expressed concern that driver compliance with restricted speed requirements ‘may be an issue affecting a broad segment of the U.S. railroad industry’.[17] The NTSB noted that ideally other mitigators would be in place to prevent collisions, but at times it was necessary for two trains occupy the same section of track and therefore collision avoidance relied on driver compliance with restricted speed requirements. It also noted that collisions in the 20 mph range could have catastrophic consequences, particularly if they involve freight trains carrying hazardous materials.

The NTSB stated that restricted speed was not a numerical value, and that to ensure safe operation of following trains the performance portion of the rule (that is, stopping within half the distance of line of sight) needed to be stressed rather than any maximum speed. Based on its review of the five accidents in 2011, the NTSB issued the following recommendation to the Association of American Railroads, the Brotherhood of Locomotive Engineers and Trainmen and the United Transportation Union:

Through appropriate and expeditious means, such as issuing and posting advisory bulletins on your website, use the occurrences of five recent rear-end collisions of freight trains—(1) Red Oak, Iowa, on April 17, 2011, (2) Low Moor, Virginia, on May 21, 2011, (3) Mineral Springs, North Carolina, on May 24, 2011, (4) DeWitt, New York, on July 6, 2011, and (5) DeKalb, Indiana, on August 19, 2011—to urge your members to undertake a review of their operations to identify the potential for similar occurrences and to take appropriate mitigating actions.

Some research has indicated that restricted speed compliance is the most common operational rule compliance problem in the US (Cohen, 1999). Recent research into US railroad accidents identified that the rate of accidents associated with the appropriate application of restricted speed remained constant during the period 2000–2016 (Zhang and Liu, 2019). In comparison, the rate of some other accident types, and the overall accident rate, decreased.

There is limited published research about the reasons for non-compliance with restricted speed requirements. In some cases trains exceeded the 20 mph limit, and some of these exceedances have been associated with factors such as fatigue and distraction. There has also been some indications that compliance with the sighting distance aspect is more problematic for a driver than the maximum limit of 20 mph, and that a low level of expectancy of particular types of hazards can be problematic (Cohen, 1999).

__________

  1. Light vehicle capable of operating on rail tracks and the road network.
  2. BoM’s description of minor flooding included ‘Causes inconvenience. Low-lying areas next to watercourses are inundated. Minor roads may be closed and low-level bridges submerged...’
  3. In addition, the weather monitoring stations at two other locations were temporarily offline (for all parameters) during 7 March, including Harvey Creek (1,632.310 km) during 0108–0245 and 0545–0612 and Corduroy Creek (1,530.290 km) during 0246–0740.
  4. The same message was also recorded on 6 March 2018 at 0358.
  5. There are three phases of twilight: civil, nautical and astronomical. The sun is below the horizon in each phase, but in civil twilight there is sufficient natural light to carry out most outdoor activities.
  6. Train scheduling, monitoring and reporting software module.
  7. ATSB Transport Safety Report, Rail Occurrence Investigation RO-2015-028, Derailment of freight train 9T92, near Julia Creek, Queensland, 27 December 2015. Report issued 9 December 2016. Available at www.atsb.gov.au.
  8. ATSB Transport Safety Report, Rail Occurrence Investigation RO-2010-013, Collision between grain trains 3234N and 8922N at Yass Junction, New South Wales, 9 December 2010. Available at www.atsb.gov.au.
  9. QR published sectional running times for some types of trains to enable rail operators to plan their activities. It also published advice about additional time required for any temporary speed restrictions. Published running times did not include any allowance for starting or stopping, or associated with other traffic.
  10. The train stopped several minutes after passing Waugh to allow the crew to inspect the Garradunga tramway crossing, so the time between Waugh and Innisfail did not provide a reliable indication of the train’s operating speed in that section.
  11. The adjusted section running time between Innisfail and Tully was 64 minutes, and 1 minute was deleted for the 600 m between Little Banyan Creek and Tully.
  12. CSX Transportation differed from other American rail operators in its requirement that a train should not exceed 15 mph under restricted speed. It also included a controlled speed restriction, defined as ‘A speed that will permit stopping within one-half the range of vision’.
  13. NTSB Accident Report NTSB/RAR-12/2, Collision of BNSF Coal Train With the Rear End of Standing BNSF Maintenance-of-Way Equipment Train, Red Oak, Iowa, April 17, 2011. (Available at www.ntsb.gov.)

Safety analysis

Introduction

At 0612 on 7 March 2018, the Little Banyan Creek rail bridge was under 0.6 m of flowing water. The train crew of Aurizon freight train 6792 were unaware of the problem and, after their train rounded the left curve on approach to the bridge, they were unable to prevent the train colliding with the floodwater. The train did not derail and there were no injuries. However, the consequences had the realistic potential to be much worse.

This analysis will first consider the reasons why none of the relevant parties were aware that the bridge was under water before the train arrived. The use of unscheduled patrols, weather monitoring stations, active monitoring of conditions ahead of a train and communication between relevant parties are discussed. The analysis will then discuss potential reasons associated with why the train was travelling in excess of ‘controlled speed’ on approach to the bridge, and the driver therefore did not have sufficient time to stop prior to the collision.

Use of patrols or inspections

The last patrol of the track from Babinda to Cardwell was conducted on the morning of 6 March, and no trains subsequently used those sections because the line was closed for planned maintenance further south. After the declaration of a condition affecting the network (CAN) due to wet weather, another patrol would ideally have been conducted ahead of the two freight trains (6792 and 67P8) that were planned to depart Cairns early on 7 March.

However, there was no specific requirement to conduct a patrol or inspection, with any decision to be made based on an interpretation of whether specified conditions had been met. Queensland Rail’s (QR’s) CAN procedures stated that an inspection was required if there were ‘reports of unusually heavy rain or water pooling against formation’, ‘high or rising levels in creeks or waterways’, or relevant advice from meteorological warnings, weather monitoring stations or the public about wet weather conditions. Similarly, the hazard location register stated a patrol or inspection was required for particular locations along QR’s North Coast Line ‘after heavy rain’ and at one location (Tully River and Murray Flats) if floodwater had reached a specified level.

In this case, the Bureau of Meteorology (BoM) had issued an initial flood watch for the general area on the afternoon of 6 March, indicating local flooding from late on 7 March. Although rain had fallen in the area overnight, prior to train 6792 departing Cairns, there had been no flood alarms or reports of any water-related problems with the track. The water levels at Tully River and Murray Flats were also well below the levels of concern. However, given the flood watch, the conditions had the potential to deteriorate over the coming days.

If a patrol had been conducted prior to train 6792 departing, it could have only commenced at about 0600 (during daylight), using a hi-rail vehicle with a maximum speed of 40 km/h. This would have further delayed the train by about 6 hours, and potentially longer if the Spirit of Queensland passenger train was then given priority.

In these circumstances, the decision to run trains 6792 and 67P8 without another patrol could be understood. However, the decision meant that train 6792 was in effect being used to prove the integrity of the network following the declaration of the CAN. It also meant that the other controls and processes in place to ensure track conditions were serviceable had to be effective.

Serviceability of weather monitoring stations

Little Banyan Creek was one of several locations on the North Coast Line known to be prone to flooding. In addition, it was a location where the flooding could be localised, and not able to be predicted by the conditions at other nearby locations.

Accordingly, QR had installed a weather monitoring station with a water level sensor, which would provide network control with a flood alarm if the water reached within 1 m of the rails on the Little Banyan Creek rail bridge. It had also installed a closed-circuit television system (CCTV) at the bridge.

However, the water level sensor at Little Banyan Creek had been out of service for 57 days prior to the occurrence. The CCTV’s illuminator, which enabled images of the bridge to be viewed in dark conditions, had also been out of service for 14 days. In addition, the water level sensor at Murray Creek, another known flooding location 12 km south of Little Banyan Creek, had been out of action for 28 days.

Given that the region was still in its wet season, it would have been appropriate for relevant weather monitoring systems at known flooding locations to be allocated a relatively high priority for repair. At the time of the occurrence however, other types of systems directly related to the movement of train traffic received a higher priority. Nevertheless, attempts to repair the Little Banyan Creek water level sensor and CCTV illuminator had been undertaken, but the problems had not been able to be resolved.

If the relevant systems could not be repaired, then it was important for network control personnel to be aware of the problems. However, neither the network control officer (NCO) or the regional transit manager (RTM) on duty in the period leading up to the occurrence were aware that the Little Banyan Creek water level sensor or the CCTV illuminator were unserviceable. Had they been aware of the problem with the water level sensor, it is likely they would have advised the 6792 train crew of the situation, and/or taken action to obtain more information about the status of the bridge prior to the train’s arrival.

When a weather monitoring station parameter first developed a fault, a message was sent to the RTM’s workstation as well as to QR’s fault coordination centre. After the message was acknowledged, there was no ongoing process of communicating the status of the system to network control personnel.

More specifically, QR did not have a formal process for ensuring that network control personnel were aware of which relevant weather monitoring systems or CCTV systems were unserviceable or operating in a degraded mode prior to commencing a shift. Although such a process would be useful in all situations, it was particularly important when a CAN due to wet weather was declared.

Processes for actively monitoring conditions ahead of a train

Regardless of the status of relevant weather monitoring systems, it would have been useful for network control personnel to have actively obtained information about track conditions ahead of train 6792. Such a process would have provided more redundancy in the case of problems with the weather monitoring systems, and provided more advance notice of potential problems even if the flood alarms were operational.

However, QR did not have procedures that required network control personnel to actively search for information about track conditions ahead of a train during a CAN associated with wet weather conditions, or in other situations where conditions had the realistic potential to have changed since the last patrol had been conducted or the last train had operated over the section.

It is likely that some network control personnel would actively monitor conditions ahead of a train in some situations, even without specific procedures requiring them to do so. However, there was no indication that this was done in the period immediately leading up to the collision with floodwater. Network control personnel also indicated it was not something that was normally done, and generally they only searched for information if they had already received advice of a problem, such as via a weather monitoring station alarm or a report from an external party. This occurred on the morning of 7 March when the NCO on duty up until 0400 checked the water level at Babinda on the CCTV at 0314, soon after the driver of 6792 had already provided advice about the water level.

Little Banyan Creek was the next location south of Babinda that had a CCTV system. It appeared that one or more network control personnel did attempt to view CCTV images, or at least obtain refreshed images, from the Little Banyan Creek CCTV during the 5 hours prior to train 6792 departing Cairns, and on one occasion after it had departed. This last occasion occurred at 0328, soon after the NCO on duty had checked the CCTV at Babinda. These attempts at viewing the conditions at Little Banyan Creek would have been unsuccessful, given they all occurred at night and the CCTV system’s illuminator was not working. There was no attempt to view conditions at the creek after civil twilight (0554) and prior to the train arriving at the creek (0612).

In addition to the CCTV information, network control personnel could also have obtained current information on various parameters from weather monitoring stations at the RTM’s workstation. If they had done this, they would have identified that there was no water level information available for Little Banyan Creek or Murray River, which should have generated an increased level of caution. Such a search would have been prudent, given that the RTM’s workstation had received derived rainfall rate alarms at 2039 on 6 March and 0015 on 7 March.

To some extent, the ability to actively search for information on conditions ahead of a train will always be dependent on the workload of the network control personnel, and on this occasion the RTMs and NCOs were conducting some other tasks. Nevertheless, a formal process to actively monitor conditions ahead of a train during a CAN or similar situation should ensure that an elevated priority is given to such search tasks, increasing the likelihood that they will be able to be conducted within an appropriate time period.

The active search for information about track conditions would be facilitated if the relevant systems were easy to use and the information was readily available and prominently displayed. From the evidence available, it appeared that obtaining refreshed CCTV images and current weather parameter information from weather monitoring stations was not without some difficulty. Nevertheless, a formal procedure, with appropriate priority for this type of situation, should still ensure that relevant information would be obtained within an appropriate time period.

Communications between operational personnel

During a CAN due to wet weather or similar abnormal situation, it is essential for operational personnel to exchange relevant information to ensure that each of them can effectively perform their roles. During the morning of 7 March, however, there were several aspects of the communications involving network control personnel, trains crews and the track maintenance supervisor (TMS) that were problematic.

Firstly, the Townsville North control board NCOs requested that the 6792 train crew pass on any observations about the weather and track conditions, and the driver of 6792 provided relevant information on several occasions. Unfortunately, the driver of 6792 initiated these communications via mobile phone. The train crew of 67P8 and the TMS (after he commenced duty at 0600), listening to the train control radio, were therefore not directly aware of the reported information. The use of mobile phones is a necessary part of communications on some networks, but they were not permitted for use on the North Coast Line due to associated safety concerns.

Secondly, the NCOs were aware of some weather monitoring station alarms at locations on the North Coast Line, and when the TMS contacted the NCO on duty at 0456, the NCO on duty provided some information about the alarms that had been received. However, this information was not passed on to the train crew of 6792 or the crew of the following train (67P8). In addition, the NCOs did not pass on the relevant information about weather and track conditions provided by the driver of train 6792 (such as the water level at Babinda) to the TMS or the crew of train 67P8.

In normal operations, there would be limitations on the amount of information that needed to be communicated between these parties on the train control radio frequency. However, given a CAN due to wet weather had been declared, a recent track patrol had not been conducted, and only two trains were on the line between Cairns and Townsville at the time, increased sharing of relevant information was warranted.

Although enhanced communications between the relevant parties would have provided more assurance that hazards would be identified and managed, it is unlikely that this would have prevented the occurrence. The more fundamental problem was the absence of known information about the conditions at Little Banyan Creek.

Another communications aspect of note was that the driver of train 6792 advised the NCO at 0610 that there was water halfway up the ballast at the Birkalla tramway. According to the relevant procedures, if a train crew observed water in the ballast they were to immediately stop their train and advise network control. However, the train driver later stated that the water was not in the ballast, and it was not possible for the ATSB to verify the exact status of the water. In addition, the NCO did not have an opportunity to stop the train, as the driver was still providing his report on conditions at the time, and indicated that he had already proceeded through the area of concern.

Train operating speed

Use of controlled speed

In the absence of a recent track patrol, a serviceable water level sensor at Little Banyan Creek and/or active monitoring of the track conditions ahead of the train, the final risk control in place to reduce the risk of a collision with floodwater or a related occurrence was the requirement for the train crew to operate at ‘controlled speed’.

In normal operation, a driver may assume the integrity of the network has been proven by a recent track patrol (or rail traffic) and remote monitoring. They can then drive in accordance with the displayed signals and speed limits, with the assumption that they have right of way on the track unless the signals indicate otherwise. When a controlled speed restriction is applied, the driver is required to drive a train in a manner in which it can be stopped short of an obstruction within half the distance of clear track that is visible ahead.

Instead of operating to well-known speed limits, a driver has to estimate target speeds in real time, based on their route knowledge, expectation of potential hazards on the track ahead, perception of the current visibility at the time and judgements about stopping distance in the prevailing conditions. In addition to flooding at known flooding locations, wet weather could also involve a range of other potential hazards to consider, such as signal irregularities or debris on the track. In some cases under controlled speed, a driver may be able to operate at or near the maximum permitted speed limit, whereas in some other cases they may have to operate at speeds well below the maximum speed limit. Overall, the task of estimating controlled speed would vary in complexity during a journey.

Given that the line of sight to the Little Banyan Creek rail bridge was 60 m, and the speed required to stop the train within 60 m was 15 km/h, the driver had to be travelling at much less than 15 km/h to stop within half the distance of line of sight, even if the driver had a rapid response time.

The driver of train 6792 reported that he was operating the train at about 40 km/h, and the data logger indicated the speed was about 50 km/h. Although 50 km/h was conservative relative to the maximum permitted speed of 70 km/h (in normal conditions), it was still far in excess of the controlled speed at that location.

More broadly, during the journey from Cairns, the driver operated the train at a speed that was less than the normal running time speed, indicating that he was applying a level of caution. There was evidence that the train was probably travelling at (or less than) controlled speed at some locations, but there was also evidence that the train’s speed was higher than controlled speed at some other locations, including locations similar to Little Banyan Creek.

There is no detailed research that has examined train driver compliance with controlled speed and the reasons why trains have exceeded the controlled speed at particular types of locations. In contrast, a substantial amount of research has determined that road vehicle drivers reduce their speed in reduced visibility or other adverse conditions, but the adaption is not sufficient and speeds are often still inappropriate for the conditions, and a wide range of motivational, perceptual and other factors can be involved (European Commission, 2018).

The ATSB considered a range of potential reasons as to why the driver of train 6792 did not effectively comply with controlled speed on the approach to Little Banyan Creek. These reasons included expectancy, workload and fatigue.

Expectancy

The most obvious reason that the driver was operating the train in excess of controlled speed at Little Banyan Creek was that he did not expect there would be a problem at that location. He was aware that network control had access to a weather monitoring station with a flood warning and CCTV, and he believed that they would advise the train crew if there was any problem at the bridge. The fact that he appeared to be driving more cautiously at some locations that did not have a weather monitoring system, and reported that he was more concerned about locations without a weather monitoring system, is consistent with this explanation.

A person’s risk perception of a situation, or expectancy that they will encounter a problem, can decrease after prolonged exposure without any adverse consequences. More specifically, the driver of train 6792 may also have been affected by a low level of expectancy of a problem because he had encountered little evidence of any flooding in the previous 112 km of the journey.

In this regard, the train’s average speed was lower (relative to the normal running time speed) in the first half of the journey (Cairns to Waugh) compared to the second half (Innisfail to Little Banyan Creek). However, a range of other factors may account for this difference, including variations in the nature of the track, actual weather conditions at the time and number of perceived hazards given the conditions. The driver also applied a similar approach to approaching other bridges with similar characteristics as Little Banyan Creek (which had weather monitoring stations), prior to reaching Waugh. Overall, there was insufficient evidence to conclude that the driver was operating less cautiously over time during the journey.

Workload and divided attention

Workload is also a relevant consideration. Workload refers to the interaction between a specific individual and the demands associated with the tasks they are performing. High workload leads to a reduction in the number of information sources an individual will search, and the frequency or amount of time these sources are checked (Staal, 2004). It can result in an individual’s performance on some tasks degrading, tasks being performed with simpler or less comprehensive strategies, or tasks being shed completely (Wickens and Hollands, 2000).

Driving a freight train in normal conditions involves a high level of expertise managing the mass and energy of the train in sections of track with undulating terrain and a significant number of curves and changes in speed limits, such as on the North Coast Line. In this case, the driver’s workload was exacerbated by the requirement to operate at controlled speed and operating at night in weather conditions that included heavy rain. In addition, his workload was increased by passing on reports about the weather and track conditions to network control.

One potential problem with this higher than normal workload was the potential for the driver’s attention to be divided at a critical time, resulting in an important task not being conducted in an effective or timely manner. For example, at the time the train was approaching the curve prior to the Little Banyan Creek rail bridge, the driver was engaged in a conversation via mobile phone about the current conditions with the NCO. A substantial amount of research has shown that the use of a mobile phone can adversely affect road vehicle driver performance, particularly in terms of reaction time and stimulus detection, with no difference in effect between handheld or hands-free use (Caird and others, 2018, Horrey and Wickens, 2006).

Given the available sighting distance after rounding the left curve prior to the bridge, the driver could not have prevented the collision, regardless of how promptly he reacted to the situation. Nonetheless, the available evidence indicates he promptly identified the hazard and reacted accordingly. The extent to which the driver’s workload may have influenced other aspects of his performance at the time, such as his consideration of potential hazards and monitoring of the train’s speed, could not be determined based on the available evidence.

Workload and sustained attention

Another aspect of the driver’s tasks and workload was the potential for his sustained attention to be affected. Research has shown that when an individual has to detect specific types of targets or stimuli over an extended period, their performance level will decrease, often typically within the first 30 minutes (Wickens and Hollands 2000). This problem, known as the vigilance decrement, has been demonstrated in a wide range of tasks, and a number of factors can influence its severity. For example, the problem increases as the salience of the targets (or hazards) decrease, the uncertainty about when the targets will occur increases, and the likelihood of encountering a target decreases.

Although there has been no specific research examining the nature of the vigilance decrement on a task such as driving a freight train at controlled speed, there is the realistic potential for a driver’s vigilance to be affected if they are performing the task for an extended period. In this case, the driver of train 6792 was operating with the controlled speed requirement for 68 minutes after departing Innisfail, and had operated with a controlled speed requirement for a longer period between Gordonvale and just passed Waugh. However, as discussed above, there was insufficient evidence to conclude that the driver’s performance changed or deteriorated over time.

Fatigue

Fatigue can have a range of adverse influences on human performance, including slowed reaction time, decreased work efficiency, reduced motivational drive, increased variability in work performance and more lapses or errors of omission (Battelle Memorial Institute, 1998), as well as various effects on decision making (Harrison and Horne, 2000). More specifically, research has shown that fatigue can lead to an increased risk of speed violations in freight train driving (Dorrian and others, 2007), and that fatigued drivers will drive faster and use brakes less in some situations, such as approaching a reduced speed limit on a downhill grade (Dorrian and others, 2006).

Sleep is vital for recovery from fatigue, with both the quantity and quality of sleep being important. Most people need at least 7–8 hours of sleep each day to achieve maximum levels of alertness and performance. Research has shown that obtaining less than 5 hours sleep in the previous 24 hours is inconsistent with a safe system of work (Dawson and McCulloch, 2005), with some research indicating less than 6 hours sleep can increase risk (Thomas and Ferguson, 2010, Williamson and others, 2011). In addition to sleep, a number of other factors can increase fatigue, including time of day, time awake and the nature of work activities.

The driver of train 6792 was woken at midnight after obtaining less than a normal amount of sleep. There is always the potential of reduced sleep and alertness in such situations, even if sufficient rest opportunity has been provided, and this is consistent with many transport activities being conducted overnight. The driver’s sustained workload could also have exacerbated any fatigue.

Overall, there was insufficient evidence to conclude that the driver was experiencing a level of fatigue likely to have a demonstrated influence on performance. It was unclear how much sleep the driver actually obtained and, as discussed above, there was insufficient evidence to indicate that the driver’s response times or other aspects of his performance deteriorated during the journey.

Summary

In summary, a range of factors had the potential to adversely influence the driver’s effective use of controlled speed during the 112 km (over 3 hours of driving) from Gordonvale to Little Banyan Creek, including the last 48 km (68 minutes) since departing Innisfail. Based on the available evidence however, the only factor that can be concluded as probably influencing his use of controlled speed at Little Banyan Creek was his expectancy that there was unlikely to be any problems at the bridge, given that he had received no advice from network control about any potential problem.

Requirements to operate at controlled speed

As indicated in the previous section, the application of a controlled speed requirement on a train crew is in effect the final risk control in place to prevent a train from encountering a hazard during a condition affecting a network (CAN) or similar situation. It is undoubtedly also an important risk control to apply in many situations.

However, the effectiveness of controlled speed as a risk control has significant potential to deteriorate if it is required to be used by a train crew for an extended period. As already discussed, its application can significantly increase driver workload, and the potential for problems with divided attention as well as maintaining sustained attention (or vigilance). The workload involved can also increase the potential for driver fatigue. In addition, if the requirement is in place for an extended period and no hazards are encountered, there is the potential for a driver’s expectancy of a hazard or risk perception to decrease.

Given these considerations, it would have been appropriate to have any restrictions on time or distance that controlled speed could be used as a mitigation measure for safe train operation in degraded conditions. However, QR had no such restrictions in place, and it did not provide detailed guidance for network control about how controlled speed could be applied to minimise the risk of its use for extended periods by train crews.

Network control personnel generally applied controlled speed as a risk control for specific hazards at specific locations. In such cases, it is relatively easy for drivers to comply with the requirement, particularly if they know the specific types of hazards involved. However, on the 7 March 2018, the requirement was applied for a 134.2 km of track, which involved at least 162 minutes of operation in normal operating speeds (and much longer if controlled speed was applied). As no specific locations or types of hazards were stated in the written authority, the range of potential hazards was also quite large. Network control had also applied a controlled speed requirement for significant distances (193.6 and 60.0 km) associated with wet weather conditions on two other occasions in early 2019.

Alternatives to using controlled speed for extended periods could include using ‘restricted speed’, with a maximum speed limit, for some or all of the distance involved. Train drivers would find this easier to comply with over extended periods, but the 25 km/h limit would significantly increase running time.

If controlled speed is applied for an extended period, other associated risk controls need to be effective. As already discussed, this includes having serviceable weather monitoring systems, procedures to ensure network control (and other parties) are aware of any relevant weather monitoring systems that are unserviceable, and active monitoring by network control of conditions ahead of the first train.

It could be argued that, if a more appropriate procedure for implementing controlled speed was in place, then the crew of train 6792 would not have had to be using controlled speed for such a distance without other risk control, such a recent track patrol, also being in place. However, based on aspects already discussed, it seems likely that the occurrence would still have resulted even if the requirement for controlled speed had only been applied for a relatively short section of track that included Little Banyan Creek.

Management of train crew workload

The problems with attempting to comply with controlled speed for an extended period for a two-driver operation could be reduced, to some extent, by the drivers effectively sharing their duties.

Aurizon’s procedures for two-driver operation required one driver to operate the train and the other driver to conduct monitoring duties. The train crew reported that it was normal practice for the operating driver to handle all communications with external parties, and the drivers would swap roles halfway through the journey. Aurizon had no additional procedures or guidance for a condition affecting the network (CAN) due to wet weather, or similar situation.

The ATSB is aware than this approach to sharing duties in a two-driver crew is common across many routes and many rail operators. However, this traditional approach exacerbates the adverse effects of operating at controlled speed (or restricted speed) for an extended period. The effects could be reduced by the monitoring driver conducting some of the operating driver’s duties (such as communications with network control), and/or more frequent swapping of roles between the two drivers. Alternatively, procedures requiring clear verbal nomination and agreement of potential hazards and target speeds could be introduced.

Research in aviation and some other fields has shown the important role that effective teamwork, sharing of duties and use of non-technical skills can play in managing fatigue, or at least making teams more resilient to the effects of fatigue (Dawson and Thomas, 2019). Although efforts to introduce rail resource management in rail operations have been ongoing over many years, further development is needed.

Introducing more effective application of teamwork in two-driver operations in normal situations may be a challenge for many rail operators. Nevertheless, in situations such as a CAN due to wet weather, or other situations likely to increase the normal workload and/or fatigue of the operating driver, having more detailed requirements and guidance about how to share tasks to minimise risk would certainly be beneficial.

Findings

From the evidence available, the following findings are made with respect to the collision with floodwater involving Aurizon freight train 6792 at Little Banyan Creek, Queensland, on 7 March 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • The Little Banyan Creek rail bridge was under 0.6 m of flowing water, due to heavy rainfall in the Banyan Creek catchment in the hours prior to train 6792 approaching the bridge.
  • The Little Banyan Creek weather monitoring station’s water level sensor had been out of service for 57 days, and the closed circuit television camera (CCTV) illuminator, which enabled effective operation at night, had been out of service for 14 days.
  • The network control officer and regional transit manager on duty in the period leading up to the occurrence were not aware that the Little Banyan Creek water level sensor was out of service. Consequently, they expected to be alerted to any problem by a flood alarm, and did not actively search for additional information about the water level at the bridge prior to train 6792 arriving.
  • Queensland Rail did not have an effective means of ensuring that, during situations such as a condition affecting the network (CAN), network control personnel were aware of the relevant weather monitoring systems that were unserviceable. [Safety issue]
  • Queensland Rail did not have procedures that required network control personnel to actively search for information about track conditions ahead of a train during situations such as a condition affecting the network (CAN), when conditions had the realistic potential to have deteriorated since the last patrol or train had run over the relevant sections. [Safety issue]
  • The crew of train 6792 expected there were no flooding problems at Little Banyan Creek, based on not receiving any advice of a flood alarm from the network control officer.
  • Train 6792 was travelling at about 50 km/h as it rounded the curve prior to the Little Banyan Creek rail bridge. With a sighting distance of about 60 m to the bridge, this speed was significantly in excess of the ‘controlled speed’, and the driver was unable to stop the train before it entered the floodwater.

Other factors that increased risk

  • Although the driver of train 6792 provided regular updates on the operating conditions, he conducted these communications via mobile phone rather than train control radio, limiting the potential for other relevant parties to obtain the information.
  • Network control personnel did not pass on all the relevant information they had about the operating conditions during the condition affecting the network (CAN) to the crews of trains 6792 and 67P8 and the track maintenance supervisor.
  • During the journey south from Cairns, the driver of train 6792 was experiencing an elevated workload due to operating at night in adverse weather conditions and the requirement to operate at controlled speed. He was also providing reports of the operating conditions to network control, including providing a report via mobile phone as the train approached Little Banyan Creek.
  • Queensland Rail did not have any restrictions on the distance or time that controlled speed could be used as a risk control for safe train operation in situations such as a condition affecting the network (CAN). The effectiveness of controlled speed has the significant potential to deteriorate over extended time periods due to its effect on driver workload, vigilance, fatigue and risk perception. [Safety issue]
  • Aurizon’s procedures and guidance for two-driver operation during situations such as a condition affecting the network (CAN) did not facilitate the effective sharing of duties and teamwork to minimise the potential effects of degraded conditions on driver workload and fatigue. [Safety issue]

Safety issues and actions

The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the rail industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

The initial public version of these safety issues and actions are provided separately on the ATSB website to facilitate monitoring by interested parties. Where relevant the safety issues and actions will be updated on the ATSB website as information comes to hand.

Advice of weather monitoring station serviceability

Safety issue number: RO-2018-007-SI-01

Safety issue description: Queensland Rail did not have an effective means of ensuring that, during situations such as a condition affecting the network (CAN), network control personnel were aware of the relevant weather monitoring systems that were unserviceable.

Procedures for actively monitoring conditions ahead of a train

Safety issue number: RO-2018-007-SI-02

Safety issue description: Queensland Rail did not have procedures that required network control personnel to actively search for information about track conditions ahead of a train during situations such as a condition affecting the network (CAN), when conditions had the realistic potential to have deteriorated since the last patrol or train had run over the relevant sections.

Application of a controlled speed requirement by network control

Safety issue number: RO-2018-007-SI-03

Safety issue description: Queensland Rail did not have any restrictions on the distance or time that controlled speed could be used as a risk control for safe train operation in situations such as a condition affecting the network (CAN). The effectiveness of controlled speed has the significant potential to deteriorate over extended time periods due to its effect on driver workload, vigilance, fatigue and risk perception.

Procedures for sharing workload in two-driver operation

Safety issue number: RO-2018-007-SI-04

Safety issue description: Aurizon’s procedures and guidance for two-driver operation during situations such as a condition affecting the network (CAN) did not facilitate the effective sharing of duties and teamwork to minimise the potential effects of degraded conditions on driver workload and fatigue.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Queensland Rail
  • Queensland Rail personnel involved in network control and track maintenance
  • Aurizon
  • the data logger from train 6792
  • the driver of train 6792
  • the Bureau of Meteorology.

References

Battelle Memorial Institute 1998, An overview of the scientific literature concerning fatigue, sleep, and the circadian cycle, Report prepared for the Office of the Chief Scientific and Technical Advisor for Human Factors, United States Federal Aviation Administration.

Caird JK, Simmons SM, Wiley K, Johnston KA & Horrey WJ 2018, ‘Does talking on a cell phone, with a passenger, or dialling affect driving performance? An updated systematic review and meta-analysis of experimental studies’, Human Factors, vol. 60, pp.101–133.

Dorrain J, Roach GD, Fletcher A & Dawson D 2006, ‘The effects of fatigue on train handling during speed restrictions’, Transportation Research Part F, vol. 9, pp. 243–257.

Coplen MK 1999, Compliance with railroad operating rules and corporate culture influences – Results of a focus group and structured interviews, US Department of Transport / Federal Railroad Administration report DOT/FRA/ORD-99/09.

Dawson D & McCulloch K 2005, ‘Managing fatigue: It’s about sleep’, Sleep Medicine Reviews, vol. 9, pp. 365–380.

Dawson D & Thomas MJW 2019, ‘Fatigue management in practice – It’s just good teamwork’, Sleep Medicine Reviews, vol. 48, pp. 1–3.

Dorrian J, Roach GD, Fletcher A & Dawson D 2007, ‘Simulated train driving: Fatigue, self-awareness and cognitive disengagement’, Applied Ergonomics, vol. 38, pp. 155–166.

European Commission 2018, Speed and speed management, downloaded from www.erso.eu.

Harrison H & Horne JA 2000, ‘The impact of sleep deprivation on decision making: A review’, Journal of Experimental Psychology, vol. 6, pp. 236–249.

Horrey, WJ & Wickens CD 2006, ‘Examining the impact of cell phone conversations on driving using meta-analytic techniques’, Human Factors, vol. 48, pp. 196–205.

Staal MA 2004, Stress, cognition, and human performance: A literature review and conceptual framework, National Aeronautics and Space Administration Technical Memorandum NASA/TM-2004-212824.

Thomas MJW & Ferguson SA 2010, ‘Prior sleep, prior wake, and crew performance during normal flight operations’, Aviation, Space, and Environmental Medicine, vol. 81, pp. 665–670.

Wickens CD & Hollands JG, 2000, Engineering psychology and human performance, 3rd edition,

Prentice-Hall International Upper Saddle River, NJ.

Williamson A, Lombardi DA, Folkard S, Stutts J, Courtney TK & Connor JL 2011, ‘The link between fatigue and safety’, Accident Analysis and Prevention, vol. 43, pp. 498–515.

Zhang Z & Liu X 2019, ‘Safety risk analysis of restricted-speed train accidents in the United States’, Journal of Risk Research, published online July 2019, pp. 1–19.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to Queensland Rail, the network control officer and regional transit manager on duty at the time, the track maintenance supervisor, Aurizon, the driver of train 6792, and the Office of the National Rail Safety Regulator (ONRSR).

Submissions were received from Queensland Rail (safety action only), Aurizon (safety action only) and the ONRSR. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2018-007
Occurrence date 07/03/2018
Location Little Banyan Creek, Tully
State Queensland
Report release date 30/06/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Track and Civil Infrastructure Irregularity
Occurrence class Incident
Highest injury level None

Train details

Train operator Aurizon
Train number 6792
Type of operation Freight
Departure point Portsmith, Queensland
Destination Acacia Ridge, Queensland
Train damage Minor

Grounding of Bulk India, Dampier, Western Australia, on 11 March 2018

Final report

Report release date: 11/09/2020

Safety summary

What happened

On 11 March 2018, during departure from Dampier, Western Australia under harbour pilot guidance, the bulk carrier Bulk India experienced an electrical blackout resulting in loss of propulsion and steering control. As a result, the ship exited the channel and ran aground. The ship was recovered into the channel with the aid of tugs, before being taken out the channel, to anchor, for further investigation.

What the ATSB found

The electrical blackout occurred because the auxiliary diesel generator engines shut down after the cooling water temperature controller malfunctioned, resulting in overheated cooling water. The ship’s engineers did not immediately identify the problem and were unable to manually operate the cooling water temperature control valve in time to prevent the blackout.

The ATSB also found that the problems in the engine room started about 13 minutes before the blackout, however the two pilots on board were not informed of the situation. This removed the opportunity for the pilots to prepare for the loss of control, and delayed actions that may have assisted in a more timely or more effective response.

Further, it was found that Bulk India’s emergency generator was not fit for service. When the blackout occurred, the engine started but shut down shortly after, due to overheating. The radiator fan belt had failed several months prior but had not been replaced. The operator, Kowa Marine Service did not have in place adequate procedures to ensure that critical spares were identified and their inventory level maintained, to guarantee availability when required on board.

What's been done as a result

Kowa Marine Service has undertaken a fleetwide program of continual improvement of its safety management and operating systems, and staff education and training processes. This included actions directed at identification, operation, maintenance and spare parts management relating to critical plant and machinery.

Rio Tinto have revised escort towage arrangements for ships departing their facilities in Dampier on the basis of extensive simulation exercises and a review of existing risk assessments. As a result, attendance by a second tug has been extended to number 3 beacons. Further, a comprehensive guidance manual for ship towage operations in Dampier and Port Walcott has been developed.

Safety message

Ship operators and crewmembers should ensure that systems, machinery and equipment, critical to the continued safe operation of the ship, are thoroughly understood, as well as appropriately maintained and tested. This will reduce the likelihood of an emergency situation relating to these items developing and provide a defence against adverse outcomes, should such a situation arise.

 

The occurrence

At 1806[1] on 8 March 2018, the 289 m bulk carrier Bulk India (Figure 1) was all fast alongside the Parker Point number 5 berth, Dampier, Western Australia. The ship had moved from anchorage after a ballast voyage from Zhoushan, China. During this port call, the ship was to load iron ore for export and take on stores and spares.

In addition to routine stores, the ship had been awaiting replacement fan belts for the emergency generator diesel engine since August 2017. The belts had not reached the ship in multiple previous ports, but on 9 March 2018, they were delivered to the ship as part of a normal delivery of ship’s spares. However, neither the master nor chief engineer were aware of their arrival, as it was usual practice to check the packages and their contents once the ship was at sea.

Figure 1: Bulk India

Figure 1: Bulk India

Source: DDGHANSA, Shipspotting.com

Departure preparations

During the morning of 11 March, all on board were preparing to depart Dampier on the afternoon tide (high tide 3.37 m due at 1618) bound for Zhoushan. Bulk India was loaded with 169,789 t of iron ore and had departure draughts of 17.49 m forward and 17.51 m aft.

At 1200, 1 hour’s notice of departure was provided to the engineers. In the engine room, the main engine was prepared and tested ahead and astern. A second diesel generator (number 3 – AuxDG3) was started and brought on-line to supply electrical power in parallel with the first diesel generator (number 1 – AuxDG1). The third diesel generator (number 2 – AuxDG2) was started but not connected to supply power. It was usual practice on board to have two diesel generators providing power during manoeuvring (about 250 kW each), with the third running but not supplying power.

By 1300, all navigational equipment had been checked and recorded in the navigation log as being in good working order. On the bridge were the master, third mate as the officer of the watch (OOW) and an able seaman (AB) on the helm. The engine room was attended by the chief engineer, first engineer, third engineer and an oiler. At 1330, two harbour pilots, consisting of a pilot-in-charge (PiC) and a peer,[2] boarded the ship. They were escorted to the bridge and the PiC and Bulk India’s master commenced the master-pilot exchange of information (MPX). The peer pilot prepared for assessment duties and also set up the PiC’s portable pilotage unit (PPU) in position at the front of the bridge.

During the MPX, the Dampier Pilots’ MPX form and Bulk India’s pilot card were worked through (see Appendices B and C). The PiC received confirmation that relevant equipment had been tested: the main engine had been run ahead and astern, the steering gear had been checked, and the anchors were cleared and ready for use. The master also confirmed that there were no machinery or equipment deficiencies that would affect the pilotage.

The prevailing weather and current conditions were discussed—wind from the north-east at 15 to 20 knots,[3] and current about 0.8 knots to the south-west. The PiC also mentioned that there would be a south-westerly set and they would tend to stay middle of the channel, favouring the northern side. This would mean that the ship would be best positioned through the departure channel bend to account for the maximum tidal flow. The master and PiC signed the forms to show agreement to the plan, and the conduct of the ship transferred to the PiC. The PiC then completed a steering test with the OOW and AB, and checked that the steering operated in hand and non-follow up operational modes.

Two harbour tugs were in attendance and were made fast—Pilbara Titan (bollard pull[4] 65 t) on the port shoulder[5] and Pilbara Vulcan (bollard pull 65 t) centre lead aft.[6] On instruction from the master, the mooring parties (fore and aft) let go lines and all were recovered on board. The tugs moved the ship into the Parker Point Departure Channel (maintained depth of 15.5 m) and at 1404, the main engine was started dead slow ahead and the ship was under way (Figure 2 and Appendix A).

Diesel generator engine overheating

At 1418, the ship’s speed was 5 knots and in the channel, well clear of the wharf area. Pilbara Titan was let go and it was manoeuvred aft of the ship, to escort position off the starboard quarter. The second tug, Pilbara Vulcan, remained made fast.

At 1420, as the main engine was increased to full ahead, AuxDG1 went into alarm due to high temperature (85°C) of the cooling fresh water outlet. The third engineer went to investigate and reported to the chief engineer that the diesel generator engine cooling fresh water control valve was in the ‘bypass open’ position, rather than the ‘cooler open’ position. This meant the cooling water was bypassing the fresh water cooler and was not being cooled.

The chief engineer went to inspect the equipment as the third engineer attempted to manually operate the control valve via the hand wheel fitted to the top of the valve. However, the hand wheel could not be turned in the direction indicated (counterclockwise, to raise the valve spindle and open flow to the cooler) despite the use of a wheel key and considerable force.

The chief engineer instructed the first engineer to open the emergency/maintenance cooling water supply from the main engine cooling system. However, this had little effect and the cooling water temperature continued to rise. The chief engineer then telephoned the bridge and discussed the problems with the master.

Meanwhile, the PiC remained unaware of the engine room events. The main engine remained at full ahead, and the ship’s speed increased to 7.7 knots. The ship remained positioned in the middle of the channel, passed the Mid Ground buoy and followed the starboard turn into the Rio Tinto Channel.

Figure 2: Bulk India's track from berth to grounding and recovery

Figure 2: Bulk India's track from berth to grounding and recovery.
Source: Australian Hydrographic Service, annotations by ATSB

Source: Australian Hydrographic Service, annotations by ATSB

Blackout—navigation/pilotage actions

At about 1428, AuxDG1 tripped due to excessively high cooling water temperature (90°C). All electrical load transferred to AuxDG3.[7] The chief engineer called the master and provided an update of the situation in their native language (Filipino). The details were not shared with either of the pilots.

At 1430, the turn into the Rio Tinto Channel had been completed. The PiC was satisfied that the ship was safely positioned in the fairway and, as there was no further assistance required from it, Pilbara Titan was released. Pilbara Titan fell back and turned to return to Parker Point. Pilbara Vulcan remained made fast and trailed close astern. At this stage, the ship had a speed of 8 knots (Table 1, Figure 3).

At 1431, as the ship was lined up and steadied in the channel, the PiC asked the AB to steer 008° and at 1432:30, 009° to account for the tidal flow pushing the ship to port. The rudder had been put to starboard, arresting a slow turn to port and the rate of turn (RoT) increased to starboard. At 1433:06 the AB reported that the ship was on 009° and applied port rudder which slowed the RoT to starboard. At about this time, the rudder was put 20° to port.

At 1433:23, AuxDG3 tripped on excessively high cooling water outlet temperature and the ship lost all electrical power (blackout). The emergency generator started and soon after, shut down due to overheated cooling water. Multiple alarms sounded on the bridge, signalling that the ship had lost electrical power and propulsion.[8] Loss of power to the steering gear meant that the rudder remained at 20° to port.

Table 1: Selected data (from AIS and PPU) at time of the blackout and grounding

Time (LT)SOGHDGCOGRoTComment
1430:007.93.0358.77.3Pilbara Titan released from escort towage
1430:307.95.82.74.9 
1431:008.07.27.6-0.6PiC orders steer 008°
1431:308.07.06.31.0 
1432:008.07.87.8-0.6 
1432:308.17.26.5-0.4PiC orders steer 009°
1433:008.28.16.12.7Rudder to 20° to port
1433:238.29.08.51.2BLACKOUT
1433:308.29.09.1-0.3 
1434:008.18.69.6-1.7 
1434:307.97.89.2-2.7 
1435:007.86.48.2-4.0 
1435:307.74.96.8-3.9 
1436:007.52.55.3-5.7 
1436:307.3359.43.4-8.0 
1437:006.8355.0359.6-2.4Ship departs channel and contacts bottom
1437:305.5357.7357.36.8 
1438:004.20.64.95.3 

Local time (LT) - UTC +8 hours; SOG is speed over the ground in knots; HDG is heading in degrees true; COG is course over the ground in degrees true; RoT is rate of turn in degrees per minute – negative indicates turn to port.

Figure 3: Bulk India movement data taken from PPU

Figure 3: Bulk India movement data taken from PPU.
Rate of turn in degrees per minute—negative indicates turn to port.
Source: Marine Services Western Australia, annotated by the ATSB

Rate of turn in degrees per minute—negative indicates turn to port.

Source: Marine Services Western Australia, annotated by the ATSB

The grounding

The PiC went to the helm and determined that all control of the steering had been lost. The applied port rudder had taken effect and the ship had stopped turning to starboard and the RoT increased to port. The PiC directed the master of Pilbara Vulcan to take the stern to port, with full power, in an attempt to stop the turn. Anchors were ready and available but the PiC advised the master not to release them at this stage, in case they passed under the ship and holed the hull.

The peer pilot assumed communications responsibility and provided information and updates to the PiC. At 1433:45, Dampier vessel traffic service (VTS) was contacted and notified of the situation. The peer pilot also used the radio to alert all stations to the ship having blacked out and of a port emergency, and requested all tugs to attend the ship. Pilbara Titan was then radioed and the tug master asked to return to Bulk India. The tug was just over 1 nautical mile (NM) away and was immediately turned around and steamed back toward the ship under full power. Another tug, Pilbara Neptune (bollard pull 65 t) was approaching Parker Point wharf when the port emergency call was made. Pilbara Neptune’s master immediately turned the tug and increased speed to go to the ship’s aid.

Despite the loss of rudder effectiveness when the main engine stopped, and the efforts of the tug, the RoT to port increased from 2°/min at 1434, to 4°/min by 1435.

At 1435, the master directed the second mate (at the aft mooring station) to go to the steering gear room and engage the emergency steering. The second mate was aware that the emergency generator had started and upon checking inside the accommodation, realised the ship had blacked out. Once at the steering gear (directly below the aft mooring station), the second mate radioed the bridge and informed the master that emergency steering could not be engaged because there was no power to either of the steering motors.

The PiC realised that control of the steering would not return and that the ship was going to turn out of the channel and run aground. The priority for the PiC changed from arresting the turn to slowing the ship, to limit any damage from contact with the bottom. The master of Pilbara Vulcan was directed to reposition and apply full transverse arrest[9] while continuing to take the stern to port.

The ship’s speed began to slow while the RoT increased. At 1435:45, the peer pilot informed the PiC that the ship was going out of the channel—the ship had speed of 7.6 knots and a rate of turn to port of 5°/minute. The PiC directed Pilbara Vulcan to direct all power to slowing the vessel in order to reduce the severity of the imminent hull contact with the channel side. VTS was informed that the ship was departing the channel and running aground. At 1437, at 7.2 knots, on heading 355° and with a rate of turn of 10°/min to port, Bulk India took the bottom.

The ship contacted the bottom at an angle of about 15° to the channel side. The ship rode up the channel side, heeled and slewed to starboard, coming back parallel with the channel. It slid along the bottom and slowed. The PiC asked the peer pilot to call the port authorities, including the harbour master and pilot manager, and inform them of the incident. The peer pilot referred to the pilotage company emergency checklist and informed the necessary parties.

By 1440, Bulk India had slowed to 2 knots. With the port bow still in contact with the bottom, momentum took the ship’s stern to starboard and into the channel, which kept the ship’s propeller and rudder in deep water. The PiC directed Pilbara Vulcan to counter the swing to prevent the stern from turning across to the other side of the channel.

The ship continued to slow and closed in on the number 5W channel beacon. At 1441, the master of Pilbara Titan contacted the PiC, and was directed to the port shoulder to push up on the port bow and take it clear of the channel beacon. The tug was about 0.4 NM astern of Bulk India, closing fast at about 12 knots.

Blackout—engine room actions

The engineers eventually applied sufficient force to move the cooling water control valve manual hand wheel in the ‘cooler open’ direction. However, the valve spindle remained in the ‘bypass open’ position. In addition to this, opening the cooling water supply from the main engine system had no effect. The engineers dismantled the control valve pneumatic actuator and, when the control air pressure was released, the valve moved to ‘cooler open’ position. However, it was about this time that AuxDG3, AuxDG2 and, shortly after, the emergency generator shut down due to the high cooling water temperature.

The engineers dismantled the control valve actuator and found that the thrust bearing and disc fitted to the end of the manual operating hand wheel shaft had come adrift. The set screws normally holding these components in place had broken, allowing the assembly to fall off the shaft. The set screws were replaced and the control valve actuator reassembled.

The time taken to repair the valve actuator allowed the engines to cool a little and, at 1435, the temperature of AuxDG2’s cooling fresh water outlet returned to within normal limits (83°). This allowed the engine to be restarted, which commenced circulation of the cooling water. Electrical power and services were then slowly restored as control of the engine temperatures was regained by manual operation of the control valve. By 1440, all three cooling water temperatures were within the normal operating range.

At 1443, the chief engineer spoke with the master on the telephone (in Filipino) regarding the blackout and attempts to restore power. They discussed the restoration of power using the main generators and the failure of the emergency generator to operate correctly.

Recovery to anchor

The channel beacon was about 200 m ahead of the bow as Pilbara Titan passed up the port side of the ship. At 1444, the tug was in position and applied weight to the port shoulder.

At about 1445, alarms began to sound and lighting flickered on the bridge, indicating that restoration of power was underway in the engine room. However, no communication was received from the engine room regarding the return of power.

At 1447, Pilbara Neptune was approaching Bulk India and the PiC directed the tug to the starboard shoulder to assist the ship’s bow back into the channel. The ship slowed below 0.5 knots and then stopped for a short period.

At about 1448, electrical power was restored. The engineers continued to restore services and check systems in preparation for restarting the main engine. In the minutes following, the master directed the second mate to engage emergency steering and move the rudder to midships.

At this time, with power available to mooring winches, three tugs were in attendance and made fast: Pilbara Vulcan on the centre lead aft, Pilbara Titan on the port shoulder and Pilbara Neptune on the starboard shoulder. The PiC directed the tug masters to manoeuvre the ship back into the channel. A fourth tug, Riverwijs Rowan (bollard pull 84 t), responded to the request for assistance and at 1451, was under way from the King Bay Supply Base, about 4 NM from the ship.

From this time, the ship’s speed was slowly increased as it came free of the channel edge and cleared beacon 5W. At 1452, the ship was back in the channel and proceeding at 0.5 knots, with Pilbara Vulcan pushed up on the stern and the two forward tugs controlling the bow. As the PiC manoeuvred the ship with the tugs, the master and ship’s crew confirmed that power and services had been reinstated. The second mate engaged emergency steering and by 1455, the rudder was centred and operation of the steering gear tested. The ship’s speed steadily increased through 1 knot as the ship moved into the middle of the channel.

At 1457, the master spoke with the chief engineer and confirmed that the main engine was available. At 1458, the main engine was started at dead slow ahead and propulsion was restored At 1500, as the ship passed between number 5 channel beacons, at 2 knots, the main engine speed was increased to half ahead.

At 1506, the master of a fifth tug, Pilbara Thor (bollard pull 65 t), contacted VTS to notify that the tug was underway to Bulk India. It was about 5 NM away at that time and proceeded at full speed.

Riverwijs Rowan arrived off Bulk India at 1513, by which time the ship was passing number 4 beacons at a speed of 4.5 knots. The ship’s speed was increased further, until it reached 5 knots (a speed the pilots were comfortable with) at 1520. At 1530, after receiving a request from the harbour master, the master confirmed that tank soundings showed that the ship’s hull had not been breached.

At 1547, as the Fairway beacon was passed, Pilbara Thor reached the ship. With 2 tugs port and starboard forward (on the shoulders), two tugs aft under the bridge wings, the fifth tug astern, and the main engine at half ahead, Bulk India was taken out the channel, past the Sea Buoy and to anchor.

At 1830, the starboard anchor was let go at anchorage WA17. At 1845, the pilots departed the ship by helicopter and at 1848, finished with engines was rung.

Subsequent events

As a consequence of the incident, the Australian Maritime Safety Authority (AMSA) detained the ship as unseaworthy.

On 13 March, a ClassNK[10] surveyor attended the ship and oversaw a dive inspection of the hull. Evidence was found of contact with the bottom but no significant damage. The surveyor also inspected the cooling water system, including the control valve repairs, and the emergency generator condition and operation. The systems were tested to the surveyor’s satisfaction. The AMSA detention order was lifted on 13 March, and at 2248 the same day, standby was called and the ship departed the anchorage to continue its voyage.

A ClassNK recommendation was issued for the installed emergency generator fan belts to be replaced with correctly sized belts as soon as possible and within one month. On 29 March the ship was attended by ClassNK while alongside in Ningbo, China. The emergency generator fan belts were confirmed to have been replaced with the correct sized belts from the original equipment manufacturer. The class recommendation was cleared.

__________

  1. All times referred to in this report are Western Australia local time, Coordinated Universal Time (UTC) + 8 hours.
  2. The second harbour pilot was conducting a peer review pilotage assessment of the pilot-in-charge.
  3. One knot, or one nautical mile per hour, equals 1.852 kilometres per hour.
  4. Bollard pull is a measure of the pulling power of a tug, expressed in tonnes.
  5. A shoulder is the area where a ship’s hull form changes from the bow shape to the parallel mid-body.
  6. Centre lead aft—a guide for a mooring line (a fairlead) which enables the line to be passed through a ship bulwark without snagging or fouling and is mounted on the centreline of the ship (centre) at the stern (aft).
  7. No evidence was provided to show that AuxDG2 was brought on load or that the electrical preferential trips activated to reduce the load on AuxDG3.
  8. Many of the main engine systems and services (including engine control) are provided by electrical machinery and equipment. Consequently, when electrical power was lost the main engine also stopped.
  9. Transverse arrest is a method of using a tug to slow the speed of a ship by having the tug on a line astern with its thrusters pointing at 90° to the travel. Large forces can be generated due to the athwartships component of the tug propeller wash creating drag.
  10. ClassNK—the ship’s classification society. See later Classification section in Context for more detail.

Context

Bulk India

At the time of the incident, Bulk India was registered in Panama, operated by Kowa Marine Service Co Ltd (Japan), owned by Southern Route Maritime S.A. and Nissen Kaiun Co Ltd (Panama), and classed with ClassNK (Nippon Kaiji Kyokai).

Bulk India’s navigation bridge was equipped with navigational equipment consistent with SOLAS[11] requirements. The layout included a control console with radars, Electronic Chart Display and Information System (ECDIS), main engine controls, a machinery alarm panel, a steering stand and communications equipment. The console was located on the ship’s centreline, just forward of the chart table

Crewmembers

Bulk India had a complement of 23 Philippines nationals all qualified for the positions which they held.

The master had 33 years’ experience at sea, 20 years with Kowa Marine Service, held a Philippine master’s certificate of competency and had sailed as master since 2011. The master had joined Bulk India during November 2017.

The chief mate had 37 years of sea-going experience, worked for Kowa Marine Service for 5 years, held a Philippine certificate of competency and had sailed as chief mate for 1 year.

The chief engineer had 35 years of sea-going experience, 26 years with Kowa Marine Service, held a Philippine chief marine engineer’s certificate of competency and had sailed as chief engineer for 3 years.

The first engineer had 19 years of sea-going experience, 2 years with Kowa Marine Service, held a Philippine marine engineer’s certificate of competency and had sailed as first engineer for 4 years.

The third engineer held a Philippine marine engineer’s certificate of competency, had worked for Kowa Marine Service for 10 years and had sailed as third engineer for 5 months.

The chief mate and the chief and third engineers joined Bulk India during October 2017. The first engineer had joined the ship during May 2017.

Machinery

Bulk India’s main engine was a Mitsui MAN B&W 6S70MC delivering 16,860 kW via a directly driven, fixed pitch propeller at 91 rpm. The ship had three Daihatsu 5DK-20 auxiliary diesel generators. Each provided 560 kW of electrical power at 60 Hz.

Auxiliary cooling fresh water system

Bulk India’s auxiliary diesel generator engine cooling fresh water system was a closed system with contents maintained via an expansion tank. Water was circulated through each engine and the common auxiliary fresh water cooler via engine driven pumps (Figure 4). Sea water for the cooler was supplied by external electric motor driven pumps. The temperature of the fresh water returning to the pump suctions was monitored and a pneumatic controller adjusted a three-way control valve to control the temperature.

Without electrical power and with all engines stopped, the cooling water (fresh and sea water) was not circulated. Therefore, temperature control during engine start-up relied upon thermal inertia within the engine mass and the volume of cooling water in the system to provide time for the cooling system to become effective. If the engine did overheat, safety interlocks prevented it from being restarted until the cooling fresh water outlet temperature reduced below a threshold and the shutdown circuit reset.

The main engine fresh water cooler could be used in place of, or to supplement, the auxiliary fresh water cooler if the need arose (during maintenance or for emergency cooling). However, this arrangement continued to rely on the auxiliary engine cooling water temperature controller and control valve. Therefore, the temperature of the cooling water for the ship’s main source of electrical power was reliant upon operation of the one controller and one control valve.

Figure 4: Auxiliary diesel generator engines cooling fresh water system

Figure 4: Auxiliary diesel generator engines cooling fresh water system.
Source: Kowa Marine Service, annotations by ATSB

Source: Kowa Marine Service, annotations by ATSB

Pneumatic temperature controller

The pneumatic automatic indicating controller sensed the cooling water temperature in the line to the pump suctions and compared this to the desired temperature. The difference in temperatures was converted to air pressure which was sent to the control valve to adjust the valve position and water flow accordingly.

The controller was supplied with air from the ship’s 0.7 MPa control air system. The control air mains was filtered and dried before a branch line passed through a filter-regulator unit at the input to the controller. The controller internal components included fine nozzles, orifices and pathways for air flow, the blockage of which would cause the controller to malfunction. Reliable operation of the controller therefore depended upon the quality of the air supplied and regular maintenance.

At the time of the incident, Bulk India’s planned maintenance system (PMS) included maintenance tasks for the control air system including checks of the reservoirs, in-line filter, dehumidifier, auto drains and reducing and relief valves. The PMS did not include maintenance tasks (for example, function tests over the full range of operation in manual and automatic modes) for control equipment for individual systems such as the auxiliary cooling water.

Control valve

The final control element in the auxiliary engine fresh water cooling system was the three-way control valve with pneumatic actuator and manual hand wheel (Figure 5). The valve position was controlled by air pressure from the controller, which pushed the valve spindle down against spring pressure. The hand wheel was not physically connected to the diaphragm or the valve spindle. In automatic mode the hand wheel was in the fully up position (turned fully counterclockwise) so that it remained clear of the diaphragm and did not impede the full range of motion.

Figure 5: Three-way, single-acting pneumatic temperature control valve

Figure 5: Three-way, single-acting pneumatic temperature control valve.
Source: Kowa Marine Service, annotations by ATSB

Source: Kowa Marine Service, annotations by ATSB

In the non-energized condition (fail-safe with no air pressure applied), the valve allowed full flow from the cooler outlet to the pump suction (flow from the engine outlets was closed). All water flow from the engines was directed through the cooler (Figure 6 left). The valve body position indicator pointed to this as ‘cooler open’.

Figure 6: Control valve flow positions

Figure 6: Control valve flow positions.
Line A – to engines, B – from engines, C – from cooler.
Source: Kowa Marine Service, annotations by ATSB

Line A – to engines, B – from engines, C – from cooler.
Source: Kowa Marine Service, annotations by ATSB

As air pressure was applied on top of the diaphragm, the valve spindle moved down and warmer water from the engine outlet bypassed the cooler and mixed with the cooler water from the cooler. The full air, extreme position was the ‘bypass open’ position with no flow through the cooler (Figure 6 right).

For manual operation, the hand wheel acted in place of the air pressure. When pressure was vented, the spring moved the valve spindle (and diaphragm plate) fully up, against the thrust piece attached to the end of the hand wheel spindle. This (upper) position initially provided full flow through the cooler. The hand wheel was then wound down or up to decrease or increase cooling respectively, as required.

Previous blackout

On 26 February 2018 (2 weeks before the incident), Bulk India had a blackout due to auxiliary diesel generator high cooling fresh water outlet temperature. Afterwards, the sea water side of a limited number of engine coolers (lubricating oil and charge air) were cleaned. No evidence was recorded to show whether the fresh water cooling or temperature control systems were identified as faults.

Emergency generator

When the mains power supply is lost, a ship’s emergency generator is required to automatically start and supply power to essential equipment, including the steering gear and emergency lighting.[12],[13]

Bulk India was fitted with a Demp[14] MAN type D2866TE emergency generator providing 140 kW at 60 Hz. The engine cooling water was circulated by an engine driven pump and cooled through a front end mounted radiator with engine driven fan.

Fan belt

About 7 months before the incident, on 29th July 2017, Bulk India was loading cargo at San Nicolas, Peru. During routine testing of the emergency generator, the fan belt failed. This failure was reported to shore management, accompanied by a request for replacement belts. The requisition indicated that there were no spares on hand and was marked urgent. This stores request was repeated a month later in August 2017.

Some delays were experienced in sourcing the parts and they were not supplied to the ship before it departed Peru almost 3 weeks later. From then, until arriving into Dampier on 9 March 2018, Bulk India visited nine ports. The required emergency generator fan belts did not reach the ship at any of these ports. The company was unable to provide an explanation as to how this occurred.

The master and chief engineer stated that the emergency generator would start and take load but could only run for a short time before overheating and shutting down. However, no officials, including in the ports visited, or other authorities such as the flag Administration or Class were made aware of this situation.

Bulk India maintenance records showed that the emergency generator was inspected and test run each week. The generator was shown to be in good condition, with no defects recorded since July 2017. A blackout test was conducted on 30 December 2017 while the ship was at anchor. No record of fan belt condition, that spares were on order, or other relevant details were recorded on the inspection sheets.

Critical equipment and functions

The International Safety Management (ISM) Code[15] required that ship operators identify equipment and technical systems the sudden operational failure of which may result in hazardous situations—that is, critical systems. The company’s safety management system (SMS) should provide for specific measures aimed at promoting the reliability of such equipment or systems and these should be included in the ship’s maintenance routines. The measures should include the regular testing of stand-by arrangements and equipment or technical systems that are not in continuous use. It follows that systems associated with the operation of critical equipment should also be identified. This includes maintenance and spare parts.

At the time of the incident, Kowa Marine Service did not have in place systems and procedures to monitor and maintain the reliability of identified critical equipment, including maintaining spare parts inventory.

Port of Dampier

The Port of Dampier is one of Australia’s largest bulk export ports and is located about 1,550 km north of Perth, Western Australia. The port comprises public and private port terminals, which predominantly service the iron ore industry of the Pilbara region and the oil and gas fields of the North West Shelf (together more than 94 per cent of cargo throughput).

The terminals are functionally separate (including separate towage and pilotage services), legislatively governed by the Pilbara Ports Authority (PPA).[16] The PPA provides Vessel Traffic Services (VTS) for multi-user facilities, port communications, and oversees marine safety and port security. The PPA also issues licences for port services including pilotage, towage, lines boats, bunkering, pilot boat transfers, security, stevedoring and waste management. The PPA provides information and directions on ship operations within Dampier port limits with specific terminal information provided by the individual terminal operators.

During financial year 2017-2018, the port had more than 9,500 vessel movements and in excess of 177,000,000 t cargo throughput. Of this, more than 145,000,000 t of iron ore was exported, representing 82 per cent of the port’s total cargo throughput.

Vessel Traffic Service

The Pilbara Ports Authority—Port of Dampier was authorised as a Vessel Traffic Service (VTS) Authority and provided an Information Service (INS) and a Traffic Organisation Service (TOS).[17] All areas within port limits and anchorage areas immediately adjacent were covered by the VTS service.

Pilotage

The PPA was to ensure pilotage services were provided within the port, ensure pilotage providers were licensed, and approve individual pilots. Pilotage within port limits was compulsory for all vessels over 35 m in length or 150 gross tonnes, unless the master held a current exemption certificate.

Three pilot service providers had been licensed by the PPA with Marine Services Western Australia (MSWA) the supplier of pilotage services under contract to Rio Tinto in Dampier. The MSWA website provided relevant pilotage information, including waypoint passage plans and master-pilot exchange of information forms (www.mswa-pilots.com.au).

The pilot in charge (PiC) on board Bulk India joined MSWA in 2011 and was a fully licensed (unrestricted) pilot for the Port of Dampier. The PiC first went to sea with the Royal Australian Navy in 1985, moved to the offshore industry in 1998, completed a master Class 1 certificate of competency in 2001 and moved to pilotage in 2008. Recent activities involved up to two, or infrequently, three pilotages per day. After being well rested, Bulk India was the PiC’s second pilotage for 11 March.

The peer pilot had an unrestricted licence, had been piloting in Dampier for 6 years after obtaining a master Class 1 certificate of competency in 1992 and had more than 15 years’ pilotage experience in New Zealand and Australia. On 11 March, the peer pilot was conducting a routine peer review of the PiC to satisfy MSWA and the PPA requirements.

Towage

The PPA issued licences for Dampier port towage services. At the time of the incident, Westug was licensed to provide towage services to Rio Tinto, under contract. This included operating and maintaining the Rio Tinto fleet of 11 tugs plus lines and pilot boats.

The Rio Tinto Dampier and Port Walcott Port Handbook (July 2016) provided guidance on typical towage requirements for all Rio Tinto berths. For departure from Parker Point berth 5, the guidance stated that two tugs were to be in attendance with one tug to escort the ship into the Rio Tinto Channel and accompany the ship to the Fairway beacon.

Rio Tinto—Dampier

In the Pilbara region of Western Australia, Rio Tinto operated an integrated network of 16 iron ore mines, four port facilities, a 1,700 kilometre rail network, and related infrastructure. Dampier port facilities comprised the Parker Point and East Intercourse Island terminals, and Rio Tinto had exclusive use of the channels servicing these terminals. This included the Rio Tinto Channel and the Parker Point Departure and Approach channels.

Specific terminal and berth information and guidance for ships calling at Rio Tinto’s Dampier terminals was available via the Rio Tinto Dampier and Port Walcott Port Handbook (accessible at the time of the incident via the Rio Tinto website).

Pilotage from Parker Point

Ships departing Parker Point transited a 15 NM channel and sea-track maintained to a depth of 15.5 m (Figure 7). From the Parker Point berthing pocket, the channel led on 270° before curving north. After about 2 NM it met the channel from East Intercourse Island at a point called Mid Ground (MG). A single straight channel extended from MG about 5 NM to the Fairway channel marker (FW), where ships continued along a natural deep water track to the sea buoy (SB). The transit from berth to sea buoy took about 2 hours.

At the time of the incident, usual practice was for ships departing Parker Point, once clear of the wharf, to be escorted by a single tug, tethered centre lead aft until FW. From FW, the ship proceeded under its own engines along the deep water track to sea. However, on a trial basis, and in the case of Bulk India, two tugs were to escort ships until past MG, with the second (short escort) tug made fast on the port shoulder. The short escort tug remained until the ship completed the turn into and straightened up in the Rio Tinto Channel and it was considered to be of no more assistance. At this point, usually in the vicinity of channel beacon 7E, the tug was released from duty and departed. The aft tug remained made fast until FW before being dismissed.

Figure 7: Navigation chart Aus58 of the Port of Dampier showing the track from Parker Point to sea. Inset shows part of navigation chart Aus60 with detail from Parker Point

Figure 7: Navigation chart Aus58 of the Port of Dampier showing the track from Parker Point to sea. Inset shows part of navigation chart Aus60 with detail from Parker Point.
Source: Australian Hydrographic Service, annotated by the ATSB

Source: Australian Hydrographic Service, annotated by the ATSB

Tug escorting assessments

Rio Tinto risk management defined the tolerable frequency for any grounding event as once in 10 years. To quantify the risk, in 2012 and 2016 Rio Tinto engaged third parties to conduct studies into the risks of loaded ships grounding during departure from the Dampier port. These studies used ship movement and incident data collected for ships servicing Rio Tinto’s Dampier facilities. The 2016 study used improved data collection methods and results, as well as experience from simulation training completed by harbour pilots and tug masters. This study assessed the risk of ship groundings for variations in the method and distance for tug escorting out of the port.

The study found that the majority of groundings were likely to occur within the channel,[18] before FW. Out-of-channel groundings were most likely to occur beyond FW. The most likely outcome was an in-channel grounding, resulting in no environmental release and impacting the port for one day during salvage. The grounding risk was found to lie on the threshold of Rio Tinto acceptance and required active monitoring.

In 2016, the usual practice was to maintain a single escort tug to FW. The study found that more tugs, escorting for longer, would reduce the probability of a single ship experiencing a grounding event. If two tugs were used for escort, there was a significant reduction in risk of a grounding event, compared to no tug escort or the use of a single tug escort. The 2016 study recommended adoption of this lower risk escort strategy.

Towage training

Marine Services Western Australia (MSWA) and Westug had undertaken programs of simulator-based emergency response training for MSWA pilots and Westug Dampier tug masters. The exercises were intended to provide familiarisation in standard escort tug manoeuvres and competence in their use. The aims were to equip pilots and tug masters with enhanced knowledge and techniques so as to locate assets in the most effective/efficient positions, taking into account the conditions at the time.

As part of the training, pilots and tug masters completed exercises together.[19] Emergency and contingency manoeuvres were performed to identify options available to keep the ship safe. Differing locations for the tugs and variations of indirect and direct towage were trialled to determine limitations or unnecessary risk to assets. To reduce the risk of confusion, the exercises also included the use of standard communication techniques, commands and terminology.

The simulator training programs included attendance by and input from Rio Tinto personnel and the Dampier harbour master. Specific scenarios and outcomes were discussed amongst all attendees with simulation results then used to guide port towage policies and procedures.

The PiC of Bulk India had completed simulator training during October 2017. Experience gained and techniques practised during the simulator exercises were employed by the pilots and tug master(s) during the incident and recovery from it.

Classification—ClassNK (Nippon Kaiji Kyokai)

A classification society is a non-governmental organization that establishes and maintains technical standards for the construction and operation of ships and offshore structures. Classification is to verify the strength, integrity, function and reliability of a ship’s structure and systems in order to maintain essential services on board.[20] Classification societies aim to achieve this through the development and application of their own rules and by verifying compliance with international and/or national statutory regulations on behalf of flag Administrations. Activities which generally fall outside the scope of classification include such items as design and manufacturing processes. ClassNK advised the ATSB that Class is not a designer who considers the philosophy behind a design. Rather, Class is the inspector who validates and reports that the ship's construction is in accordance with relevant international regulations.

ClassNK rules[21] required that special consideration be given to the reliability of essential machinery and equipment that affects the normal operation of the propulsion machinery, such as the main source of electrical power or sources of water pressure. Rules governing cooling systems were restricted to the more general piping systems rules. Pumping requirements were prescribed, but specific cooling system automation or control requirements were not.

In addition to main sources of electrical power, the rules required ships to have a self-contained emergency source of electrical power. When this was an emergency generator, it must start automatically within 45 seconds of failure of the main source of electrical power. It must also be capable of supplying sufficient power to all services that are essential for safety in emergencies, including lighting, communications, navigation and steering systems.

The rules also list the minimum spare parts required for machinery installations, including diesel engines, generators or auxiliary machinery essential for main propulsion, but not emergency generators. The requirements did not extend to the identification of spare parts for support systems such as cooling water.

Ship inspection

Ship vetting (RightShip)

RightShip[22] is a commercial organisation that provides risk management and environmental assessment to the maritime industry. The company provides an online ship vetting tool (RightShip Qi), which uses predictive analytics to determine the likelihood that a ship will have an incident in the following 12 months. The customer is then provided with an indication of the risk involved in selecting a particular ship for charter. The system utilises analysis of data and records from multiple sources and questionnaires to assess the ship against RightShip and customer criteria. When a ship is vetted, it undergoes a risk assessment to determine its relative safety for a particular voyage.

The system assesses against criteria related to terminal requirements include ship mooring capabilities, cargo/ballasting capabilities, ship loader compatibility, gangway details, helicopter capability, senior officer experience and ship details. The question of condition of the ship machinery and equipment is limited to Port State Control history, validity of certification (including Class), and incident history.

A RightShip Qi vetting of Bulk India was requested on 22 February 2018 for the voyage from Dampier to China. Records show that the terminal questionnaire was marked ‘satisfactory’, and the ship had no adverse reports and was recommended for approval. The RightShip risk star rating at the time was four stars.[23] Bulk India had undergone the RightShip vetting process on at least six occasions since the start of 2014. Of these, one vetting was unacceptable due to the ship being unable to fulfil all customer requirements.

Under some circumstances (including age, ship modification or customer request) a ship may have a physical inspection. The RightShip ‘Dry bulk inspection’ is used to validate a ship’s condition, capabilities and application of its safety management system. The RightShip ‘Inspection and Assessment Report for Dry Cargo Ships (FOD06)’ checklist includes determining if ‘All stores/spares requisitions are filled in less than 30 days’. No record of Bulk India having undergone a physical vetting inspection was provided.

Port State Control inspections

Port State Control (PSC) is an internationally agreed program for the inspection of foreign ships in other national ports. International conventions and the United Nations Convention of the Law of the Sea (UNCLOS) give responsibilities to flag States to check and control ships in their waters, so that they do not pose threats to ship and crew safety or to the marine environment. If a ship is found to have deficiencies, it may be detained until the issue is resolved.

Bulk India had been subjected to 15 Port State Control (PSC) inspections, including follow-up inspections, since 2012. The most recent inspection prior to the incident was during November 2017 while the ship was in Lianyungang, China. None of the inspections highlighted issues with power generation or with the emergency generator.

__________

  1. SOLAS - The International Convention for the Safety of Life at Sea, 1974, as amended.
  2. SOLAS Chapter II – 1 Reg 43: Ch II-1 Construction – Structure, subdivision and stability, machinery and electrical installations, Part D Electrical installation, Reg. 43 Emergency source of electrical power in cargo ships
  3. Classification society (ClassNK) rules require that the emergency generator must automatically supply power within 45 seconds and supply the steering system for at least 30 minutes of continuous operation.
  4. Demp – Danish engineering and marine power
  5. The International Management Code for the Safe Operation of Ships and for Pollution Prevention
  6. Pilbara Ports Authority (PPA) operates as a Western Australian Government Trading Enterprise, and is governed under the Port Authorities Act 1999 WA.
  7. Information Service (INS) is defined as provision of relevant information at appropriate times and on request for the VTS area. Traffic Organisation Service (TOS) is defined as a service to prevent the development of dangerous maritime traffic situations and to provide for the safe and efficient movement of vessel traffic within the declared VTS area.
  8. The study defined an in-channel grounding as one which occurred on the channel boundary and obstructed about 60 m of the channel width. Out-of-channel grounding occurred within 3,000 m of the channel boundary, beyond which it was assumed not to have grounded.
  9. The simulator facilities used provide multiple bridge simulators and a tug simulator which can be used individually or configured to interact and complete the same scenario.
  10. Refer to International Association of Classification Societies (IACS) for additional information
  11. Rules for the Survey and Construction of Steel Ships, Part D Machinery and Part H Electrical Installations.
  12. Information available at www.rightship.com
  13. Rightship analysis for 2014-2015 showed that a 1-star bulker was 19 times more likely to have an incident than a 5-star bulker.

Safety analysis

Bulk India ran aground as a result of an electrical blackout, which caused a loss of propulsion and steering control. This analysis will explore the equipment and machinery factors leading up to the blackout and recovery from it. This will include the condition and operation of the electrical generators and associated systems, maintenance and spare parts. In addition to this, bridge communications and the implications on emergency event response and recovery will be discussed.

Grounding

After the blackout occurred at 1433, the failure of the emergency generator meant the ship lost all power. This resulted in the loss of steering control which meant that the rudder could not be moved from 20° to port. Bulk India had commenced turning to port when all power was lost and, in the limited time available, Pilbara Vulcan was unable to stop the ship from continuing the turn. About 90 seconds after the loss of power, the PiC determined that the ship was going to run aground and redirected the tug so as to limit any damage.

It is likely that had the emergency generator worked as designed, control of the rudder would not have been sufficient to prevent the turn to port continuing, and the ship running aground. Several factors have led to this conclusion, including:

  • the time for the emergency generator to start and take load (45 seconds)
  • the time for bridge personnel (ship and pilots) to assess the situation, react and verify control of the rudder
  • the time to turn the rudder from port to starboard
  • the time to reposition the tug and apply weight
  • the reduced effectiveness of the rudder due to the reduced flow over its surface
  • the time taken for the tug and rudder to overcome the turn momentum of the loaded ship and turn it away from the channel side.

Auxiliary generator overheating

The exact cause of the cooling water temperature control malfunction was not determined. However, air pressure remained applied to the diaphragm until the engineers removed the air supply pipe. That is, the controller continued to supply air to the valve even though increasing temperature of the cooling water to the pumps should have led to the air pressure being reduced. It was therefore likely that this was caused by an air pathway blockage within the pneumatic controller.

Temperature control via a single-acting, spring return, pneumatically controlled three-way valve is a common arrangement used on ships. However, when the control valve was stuck in the cooler bypass position, the engineers did not know how to manually operate it. Had the air pressure been vented and the valve changed to manual control when first discovered, it is likely that the temperature of the cooling water would have been controlled and the engines would not have overheated.

As a single point of failure, this equipment should have been identified as critical and its associated systems understood by the crew and regularly tested. This would include maintenance of the valve, as well as the control air supply and system. It would also include understanding of, and familiarity with, auto-manual operation of the controller and the valve.

Emergency generator

The emergency generator overheated and shut down because the radiator fan drive belt had failed several months prior and had not been replaced. As a result, the engine would only run for a few minutes because there was no fan belt. Regular routine testing meant that the condition of the machinery was well known.

ClassNK rules required that the emergency generator start automatically, within 45 seconds of a blackout, and supply sufficient power for at least 30 minutes’ continuous operation of the steering gear (longer for other emergency services such as lighting). Bulk India’s emergency generator was not capable of meeting these requirements and was therefore unserviceable and not fit for purpose. This represented a condition that directly affected the safety of the ship. It was also a reportable deficiency that should have been rectified as soon as possible.

Critical spares

At the time, Bulk India and the wider Kowa Marine fleet did not have an adequate procedure or system to monitor and maintain reliability of critical equipment. Had they done so, the emergency generator fan belts would have been identified as critical to the safe operation of the ship and their inventory level maintained to ensure that replacement belts were always available at short notice.

Furthermore, there were no procedures in place that progressed and tracked an urgent request for spare parts. As a result, the ship was not notified that these critical spares were en route or when to expect them to arrive. As a consequence, the emergency generator fan belt had not been replaced, despite having been received on board. It also meant that Bulk India had sailed for more than 7 months with an emergency generator that was unserviceable and would not operate as required.

Communication during pilotage

The pilots were not informed of machinery problems which could directly affect the safe navigation of the ship (including the state of the emergency generator) at any time prior to the blackout occurring. Conversations between the master, chief engineer and others, relevant to the deteriorating situation in the engine room, were not in a language the pilots could understand, which removed an opportunity for the pilots to be informed. Even so, the master had opportunity outside of these conversations to inform the pilots, but did not do so.

The first opportunity was soon after the first cooling water high temperature alarm at 1420; 13 minutes before the blackout occurred. Secondly, after AuxDA1 tripped at 1427, at least two phone conversations were held between the bridge and engine room in the following 2 minutes. This was still about 4 minutes before the blackout. Without this knowledge, the short escort tug, Pilbara Titan, was released from duty at 1430, 10 minutes after the initial alarm and 3 minutes before the blackout. Had the pilots been aware of the escalating problems, their actions would have most probably changed, including that the short escort tug would not have been released when it was. This may have led to a more favourable outcome, including the possibility of avoiding the grounding.

The absence of effective communication therefore removed the opportunity for the pilots to prepare for the loss of power and control. Consequently, reactions which may have assisted in a more timely or more effective response were unnecessarily delayed.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the grounding of Bulk India during departure pilotage from Dampier, Western Australia on 11 March 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • Whilst Bulk India was transiting the Rio Tinto Channel, all electrical power was lost. Control of the ship and its manoeuvrability were lost and the rudder remained fixed at 20° to port. The ship turned to port and contacted the channel side, running aground.
  • Electrical power was lost when the auxiliary diesel generator engines shut down due to overheating of the cooling water. A fault in the pneumatic controller resulted in the cooling water bypassing the cooler and overheating.
  • When the temperature control valve stuck in the cooler bypass position, the engineers did not know how to manually operate the valve. Had the valve been correctly manually operated when first discovered, it is likely that the temperature of the cooling water would have been controlled and the engines would not have overheated.
  • Bridge communications were ineffective and the pilots were not informed of the machinery problems prior to the blackout occurring. This removed the opportunity for the pilots to prepare for the loss of control and delayed actions which may have assisted in a more timely or more effective response.

Other factors that increased risk

  • The emergency generator was not fit for service as it was unable to provide sustained electrical power to the ship and steering. The engine overheated and shutdown because the radiator fan drive belts had failed several months prior and had not been replaced.
  • No procedure or system was in place to ensure critical spares were identified and their inventory controlled to ensure availability when required. As a consequence, the fan belts for the emergency generator had been on order for several months. [Safety issue]

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the marine industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Critical spares

Safety issue number: MO-2018-004-SI-001

Safety issue description: No procedure or system was in place to ensure critical spares were identified and their inventory controlled to ensure availability when required. As a consequence, the fan belts for the emergency generator had been on order for several months.

Safety action not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Additional safety action addressing Dampier port operations

Rio Tinto Iron Ore (RTIO) and Rio Tinto Marine (RTM), both part of the Rio Tinto group of companies, advised that changes have been made to several areas of business operations in response to investigations into the grounding of Bulk India. Actions included:

  • Following the incident, ‘immediate containment’ changes included extension of the short escort tug attendance to number 5 beacons. This remained in effect until additional reviews of towage arrangements had been completed.
  • Rio Tinto actively engaged with Dampier port stakeholders (marine pilots, towage, Dampier harbour master and port operations) to undertake a risk-based review of vessel escorting practices and procedures. The current Dampier (and Port Lambert) escort towage risk assessments were reviewed and multiple simulation exercises were completed to determine the effectiveness of escort towage practices (including in emergency situations). The assessments, exercises and discussions resulted in changes to escort towage arrangements for vessels departing Dampier—in particular, the short escort tug was extended to number 3 beacons (Figure 7) with the primary escort tug remaining to the Fairway buoy.
  • RTM, in conjunction with Marine Services Western Australia (MSWA) pilots and Westug towage, have developed a ‘Guidance manual for ship towage operations: Dampier and Port Walcott’. This manual was aimed at providing clear ‘guidance for personnel associated with terminal towage and pilotage operations in order to address risk mitigation, maintain the highest industry standards and meet regulatory compliance.’
  • RTM circulated a safety bulletin to vessels, brokers and owners advising of actions expected to be taken immediately: all critical machinery to be checked and operational; associated machinery and plant to be in good order; to identify and ensure sufficient stock of critical spares; review and to reiterate bridge resource management techniques including command and communications.
  • Completing improvements to ship vetting (including RightShip) through improved oversight, amended frequency of ship inspections and audits.
  • Improving engagement with global ship owners and managers (for example through shipping safety forums) to enhance relationships and clarify standards and expectations in relation to vessel safety, asset quality and maintenance.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the master and crew of Bulk India
  • Kowa Marine Service
  • Rio Tinto Marine (Dampier)
  • Rio Tinto Iron Ore (Dampier)
  • Marine Services Western Australia (MSWA)
  • Westug
  • ClassNK
  • the Australian Maritime Safety Authority
  • Bulkseas Marine Management.

References

ClassNK (Nippon Kaiji Kyokai) 2018, Rules for the Survey and Construction of Steel Ships, ClassNK. Available at www.classnk.or.jp

International Maritime Organization (IMO) 2014, The International Convention for the Safety of Life at Sea (SOLAS) 1974 as amended, IMO, London.

International Maritime Organisation (IMO) 1995, International Management Code for the Safe Operation of Ships and for Pollution Prevention (ISM Code) as amended, IMO, London.

Oil Companies International Marine Forum (OCIMF) 2018, Safety Critical Equipment and Spare Parts Guidance, OCIMF, London. Available at www.ocimf.org

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • master and chief engineer of Bulk India
  • the pilot in charge
  • the peer pilot
  • Kowa Marine Service
  • Rio Tinto (Dampier)
  • Pilbara Ports Authority – Dampier harbour master
  • Marine Services Western Australia (MSWA)
  • Westug
  • Australian Maritime Safety Authority
  • Panama Maritime Authority
  • Bulkseas Marine Management.

Submissions were received from:

  • Kowa Marine Service
  • Australian Maritime Safety Authority
  • Pilbara Ports Authority – Dampier harbour master
  • Rio Tinto (Dampier)
  • Marine Services Western Australia (MSWA)
  • Westug
  • Bulkseas Marine Management.

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

General details

Ship details

Name:Bulk India
IMO number:9284271
Call sign:H3WC
Flag:Panama
Classification society:ClassNK
Ship type:Dry bulk carrier
Builder:Mitsui Engineering & Shipbuilding Co. Ltd, Chiba, Japan
Year built:2004
Owner(s):Southern Route Maritime S.A. and Nissen Kaiun Co Ltd, Panama
Manager:Kowa Marine Service Co. Ltd., Japan
Gross tonnage:88,490
Deadweight (summer):177,640 tonnes
Summer draught:17.975 m
Length overall:289.00 m
Moulded breadth:45.00 m
Moulded depth:24.40 m
Main engine(s):Mitsui MAN B&W 6S70MC
Total power:16,860 kW at 91 rpm
Speed:14.7 knots, fully loaded
Damage:Nil reported

Appendices

Appendix A—Table of selected AIS data for Bulk India’s departure from Dampier

Time (LT)[24]TelegraphSOG[25]COG[26]HDG[27]Comment
1354STOP0.8213All clear of wharf
1404DSAhd0.3210  
1405SlowAhd0.4227266 
1413HalfAhd2.6284294 
1418HalfAhd5296302Pilbara Titan let go
1420FullAhd5.9304310

Passing 9W beacon

AuxDG1 high JCW temperature

1427FullAhd7.7334340

AuxDG1 trip

Passing Mid Ground

1430FullAhd7.83554

Lined up in Rio Tinto Channel

Pilbara Titan released from duty

1433FullAhd8.169Blackout – AuxDG3 trip
1435:45STOP7.774Ship departing channel
1437STOP7.22354Ship touches bottom
1440 2.0250 
1443 0.710352Closing on Beacon 5W (about 200 m)
1444 0.5341354Pilbara Titan applies weight port shoulder
1445 0.5320358Commence power restoration – alarms on bridge
1447 0.730613Pilbara Neptune alongside starboard shoulder
1448 0.233318Power restored – rudder to midships
1449 0.19117 
1452 0.42611Clear of channel edge and beacon 5W
1455STOP1.1817Rudder checked, ship mid-channel
1458DSAhd1.62114Main engine started
1500HalfAhd2.2811 
1513 4.5910Fourth tug alongside
1520 4.999 
1547 5.11016

Pass Fairway beacon

Fifth tug arrives

1710 5.83838Pass Sea Buoy
1848FWE   Finished with engines, ship at anchor

Appendix B—Bulk India Pilot card

Appendix B—Bulk India Pilot card

Appendix C—Marine Services Western Australia master/pilot exchange of information (MPX) form

Copy of MPX form in use on the day. Page 1:
Appendix C—Marine Services Western Australia master/pilot exchange of information (MPX) form - Page 1
Marine Services Western Australia master/pilot exchange of information (MPX) form. Page 2:
Appendix C—Marine Services Western Australia master/pilot exchange of information (MPX) form - Page 2

__________

  1. UTC +8 hours.
  2. Speed over the ground in knots.
  3. Course over the ground in degrees true.
  4. Heading in degrees true.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number 341-MO-2018-004
Occurrence date 11/03/2018
Location Rio Tinto channel, Dampier
State Western Australia
Report release date 11/09/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Marine
Marine occurrence category Grounding
Occurrence class Serious Incident
Highest injury level None

Ship details

Name Bulk India
IMO number 9284271
Ship type Iron ore
Flag Panama
Manager Southern Route Maritime S.A. and Nissen Kaiun Co Ltd, Panama
Departure point Dampier, Western Australia
Destination Qingdao, Shandong, People's Republic of China
Damage Nil

Water ingress into steering gear compartment onboard Goliath, Bass Strait, Tasmania, on 7 March 2018

Final report

Report release date: 25/01/2019

What happened

At about 1454 Eastern Daylight‑saving Time[1] on 5 March 2018, the 143 m, self‑unloading cement carrier Goliath (Figure 1) arrived in Melbourne, Victoria, after a 21-hour voyage from Devonport, Tasmania. Cargo operations commenced and continued into the following day. At about 2330 on 6 March, the master was informed that there were problems with the cargo quality making it difficult to discharge, and consequently departure would be delayed. At midnight, the third mate completed his cargo watch and prepared for the vessel’s departure but, as departure was delayed, at 0200 he was relieved of his duties by the master and retired for rest. The chief mate was roused from sleep at 0230 to attend to the cargo issues and cargo discharge was completed soon thereafter. The chief mate then remained on duty for departure and for his normal 0400 to 0800 navigation watch.

Figure 1: Goliath

Figure 1: Goliath. Source: Lester Hunt, MarineTraffic.com

Source: Lester Hunt, MarineTraffic.com

At 0315, on 7 March, under the guidance of the pilot exempt master,[2] stand-by for departure was called. At 0718, Goliath commenced sea passage bound for Devonport. At 0800, the chief mate handed the navigation watch to the third mate. During watch handover, in addition to navigation information, the planned ballast water exchange operation was discussed. The chief mate also advised that he would be inspecting the cargo holds during the morning.

In addition to normal navigation and shipboard routines, a shore-based trainer had embarked in Melbourne to conduct a programme of onboard training during the voyage to Devonport. Two sessions were to be held, from 1300 to 1500 and 1530 to 1730. The navigation watches were altered to allow the rostered officer of the watch (OOW) to attend one of the training sessions.

At 0815, the third mate, as OOW, commenced the routine ballast water exchange as required under the ship’s ballast water management plan.[3] Ballast movements (water in or out) followed a prescribed sequence and timing, as laid out in the plan. The ballast pumps and remotely operated valves were controlled and their status (open or closed) monitored by the OOW from the ballast control panel located in the ship’s wheelhouse. Assistance around the ship was provided by the duty integrated rating (IR), who operated manual ballast valves, sounded tanks (measured water levels), and removed tank access covers as required. There was no way to remotely monitor the status of the manual valves, and no record was routinely taken of the valves in use and their status. Verification of the manual valve status was reliant upon communications between the OOW and the duty IR, via the ship’s handheld UHF radios.

Goliath’s ballast system consists of eleven tanks. Ten tanks are located forward of the engine room and one tank aft, the after peak. The system is serviced by two 500 m³/hr ballast pumps via a ring main which could be split via an isolating valve at the bow. This allows number 1 ballast pump to be configured to service the after peak tank and the starboard side ballast tanks, and number 2 pump to service the fore peak tank and the port side ballast tanks. This effectively segregated the two pumping systems, was the usual configuration, and was in use on 7 March.

At 1200, the second mate took over the watch and the ballasting operations. Elsewhere, the chief mate had completed hold inspections and rested until 1500 after which he was scheduled to attend the training. The second mate attended training from 1300, and the third mate returned to the bridge at that time to take the watch.

At 1420, the ballast system was configured to complete the after peak tank water exchange. At 1453 the second mate returned to the bridge to again take over the watch. However, the third mate retained the watch to complete the after peak tank ballasting which involved lowering the level to 8.5 m for ship stability requirements.

At 1500, the third mate contacted the duty IR and asked that the two after peak manually operated valves be closed (Figure 2). For reasons that could not be determined, the requested valve closures were not actioned. The third mate did not confirm with the IR that the message had been received and actioned so he was unaware that the valves connecting the after peak tank to the starboard ballast main had not been closed.

The watch was handed to the second mate who then continued with the next scheduled ballast movement of exchanging the water in the fore peak tank, also unaware that the valves to/from the after peak tank remained open. The third mate left the bridge and attended training before going to bed thereafter. The chief mate attended the same training session and the second mate remained on watch beyond 1600, when the chief mate usually took the watch.

At 1620, flow-through water exchange[4] of port and starboard ballast tanks commenced. This involved the use of both ballast pumps and systems. At 1730, the chief mate came onto the bridge and took over the watch.

Shortly thereafter, at 1736, an engine room alarm (aft bilge well high level) activated and the duty engineer (first engineer) responded. Upon entering the engine room, the first engineer noticed water flowing over the doorstep through the open steering gear room door. This water drained to the aft engine room bilge, resulting in activation of the alarm. The first engineer discovered water coming from a scupper pipe in the steering gear room, which drained into the steering flat bilge well. This bilge well was not fitted with an alarm and was manually drained to the engine room bilge. Consequently, it had overflowed, leading to flooding of the deck to a depth of about 10 cm. The water then overflowed the doorstep, into the engine room, and to the aft bilge well.

Figure 2: Part of the ballast system piping diagram showing valve configuration for pumping out the after peak tank (APkTk)

Figure 2: Part of the ballast system piping diagram showing valve configuration for pumping out the after peak tank (APkTk). Source: CSL Limited, annotated by ATSB

Source: CSL Limited, annotated by ATSB

The first engineer noted that the water was salt water but could not find an obvious source in the adjacent spaces. He contacted the chief engineer and the bridge, informed them of the flooding, and inquired about the ballasting process. He also contacted the third engineer and requested he attend the engine room to assist. The first engineer then returned to the engine room to begin transfer of the aft bilge well contents to the bilge holding tank.

At 1745 the ballasting operations were stopped and tanks sounded. The after peak tank sounded at 11.54 m, 3 m higher than at the completion of after peak tank ballasting at 1500. At 1752, after checking stability conditions, the chief mate started pumping down the after peak. The chief mate also directed the duty IR to check the after peak tank ballast line valves. Both valves were found to be open.

Continuing investigations then found water coming up the drain in the CO2 room, (located on the deck above and atop the starboard side of the steering flat). The senior officers discussed the situation and agreed the most likely cause was a holed scupper pipe running through the after peak tank.

At 1802, the chief engineer informed the master that water had stopped coming from the scupper pipe in the steering flat. The after peak tank was now at 8.37 m and was further lowered to 4.64 m. At 1830, the ballast pump was stopped. Other spaces were checked and tanks sounded. At 1918, a sounding of the after peak tank confirmed that the level was unchanged.

It was determined that the leak had been stopped and the ship was safe to continue passage. At 2224 on 7 March, Goliath was all fast alongside in Devonport.

A tank entry and inspection of the after peak tank found the scupper line from the CO2 room holed, on the outboard (back) side of the pipe, adjacent to the ship’s side, just below the tank top (Figure 3). This line ran through the after peak tank before passing through the steering gear room bulkhead to drain into the steering gear room bilge well. The rear of the elbow piece directly below the tank top was heavily corroded and wasted with most of the pipe wall missing.

The tank was rarely filled to a depth which covered the holed section of pipe. However, when the starboard ballast tank was pressed up to overflowing, the open valves to the after peak tank allowed it to also fill. As the tank neared full, water covered the hole in the pipe, drained into the steering gear room bilge well and overflowed.

Figure 3: Scupper pipe in after peak tank showing corroded and holed elbow

Figure 3: Scupper pipe in after peak tank showing corroded and holed elbow. Source: CSL Limited, annotated by ATSB

Source: CSL Limited, annotated by ATSB

A condition of class was placed on the ship until suitable repairs had been completed. In the meantime, any ballasting was to be completed with additional monitoring of this area of the ship and tank levels. Procedures were amended to require the duty officer to keep a log of all manual valve operations and ballasting of the after peak tank was to be conducted only during daylight hours. In addition, a status tracking board was made for the manual valves with moveable pegs to be used to show the status of each valve.

Initial repairs involving renewal of the CO2 room drain line (about 7.5 m), deck and bulkhead penetrations were completed on 10 March. Final repairs, survey and testing were completed on 18 March and the condition of class was lifted.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The request to manually close the after peak tank ballast line valves was not confirmed or actioned as expected. This led to undetected filling of the after peak tank during subsequent ballasting operations.
  • The after peak tank filled to a level sufficient for water to leak into the holed scupper line within the tank and drain into the steering gear room bilge well. This overflowed and flooded the steering gear room.
  • There was no structured or formalised system of logging or tracking the status of ballast system manually operated valves. Thus, when closure of the after peak valves was not actioned or confirmed, there was no record at the ballast control panel to show the status of the valves.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Ship owner/operator – CSL Australia

As a result of this occurrence, CSL Australia has advised the ATSB that further to the immediate actions referred to earlier, the following safety actions have also been taken.

  • Ballast tank inspection procedures have been reviewed and updated with added emphasis on internal tank fixtures
  • During scheduled drydocking of Goliath in 2018 it:
    • fitted a ballast water treatment system in compliance with the Ballast Water Management convention which will remove the need for ballast water exchange
    • had the ballast tank remote sounding and alarm system replaced
    • had steelwork in the ballast tanks, including piping in the after peak tank, replaced.

General details

Ship details

Name:Goliath
IMO number:9036430
Flag State:Australia
Classification society:Lloyd’s Register
Owner(s):CSL Australia
Manager:CSL Australia
Year built:1993
Gross tonnage:11,754
Length overall:143.00 m
Moulded breadth:23.50 m
Summer draught:8.335 m
Main engine(s):Sulzer 5RTA52, 6,400 kW

Safety message

Disruption of normal routine, increased workload and changes of shift personnel increase the potential for error. This is particularly important during short sea voyages. All activities carried out during these times need careful and particular attention to ensure all individual tasks are completed and/or their status passed to new personnel.

About this report

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope, fact-gathering investigation was conducted in order to produce a short summary report, and allow for greater industry awareness of potential safety issues and possible safety actions.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Daylight Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. Goliath’s master had a pilot exemption for Melbourne and Devonport and piloted the ship into and out of each port. The master also acted as the ship’s agent.
  3. Under Australian and International law, from 8 September 2017 all vessels are required to manage their ballast water in accordance with the International Convention for the Control and Management of Ships’ Ballast Water and Sediments, 2004.
  4. Flow-through ballast water exchange involved removal of the tank access lids and continually overflowing the tank for a prescribed period of time.

Occurrence summary

Investigation number 340-MO-2018-003
Occurrence date 07/03/2018
Location Bass Strait, about 112 km north-west of Devonport
State Tasmania
Report release date 25/01/2019
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Marine
Marine occurrence category Structure
Occurrence class Incident
Highest injury level None

Ship details

Name Goliath
IMO number 9036430
Ship type Cement carrier
Flag Australia
Manager CSL Australia
Departure point Melbourne, Victoria
Destination Devonport, Tasmania

Engine failure involving Airbus Helicopters AS355F-1, VH-SEV, Bankstown Airport, New South Wales, on 12 March 2018

Final report

Report release date: 12/03/2020

Safety summary

What happened

At about 0828 Eastern Daylight-saving Time (EDT), on 12 March 2018, an Airbus Helicopters AS355F-1 helicopter, VH-SEV, operated by Rotor Head, air taxied from the hangar to the maintenance facility at Bankstown Aerodrome, New South Wales with the pilot and one passenger on board.

After about 5 minutes in flight, the pilot commenced the landing. As the skids touched the ground, the pilot observed the right-hand engine chip light illuminate and smoke coming from the right-hand side of the aircraft. The pilot immediately shut down the right-hand engine. Mechanics from a nearby workshop ran out and extinguished the engine fire.

The aircraft sustained significant damage to the engine and minor heat damage to the surrounding structure.

What the ATSB found

A single third-stage turbine wheel blade failed due to fatigue cracking, resulting in secondary damage to the engine and total engine failure. The rapid fatigue crack progression was probably caused by a momentary dwell in the speed avoidance range.

A number of fatigue cracks were present but not detected during the last inspection of the third-stage wheel. The size and nature of the cracks meant there was a low probability of detection using the method specified.

What's been done as a result

Rolls-Royce are in the process of redesigning the third-stage turbine wheel to improve its tolerance to fatigue cracking and operation at responsive wheel modes.

Safety message

Any operator, irrespective of their level of experience, can find themselves confronted with an unexpected failure. Therefore, it is important for operators to monitor aircraft performance parameters continuously for abnormal indications. Acting quickly to shut down malfunctioning hardware and following failure management procedures will ensure the best possible safety outcome, as demonstrated by the pilot in this occurrence.

During this investigation, Rolls-Royce advised the ATSB of a few key points regarding the operation of the Rolls-Royce 250 enhanced power turbine engine:

  • A dwell in the order of a few seconds can be enough to initiate damage and propagate a crack to failure.
  • The best way for an operator to monitor the transition through the speed avoidance range is to watch the needle on the N2 tachometer. If the needle stops, that constitutes a dwell.
  • If an operator recognises or suspects an inadvertent dwell in the speed avoidance range, contact Rolls-Royce for advice.

Third-stage turbine wheel removed from VH-SEV showing damage

Third-stage turbine wheel removed from VH-SEV showing damage
Source:  ATSB

Source: ATSB

 

The occurrence

At about 0828 Eastern Daylight-saving Time (EDT)[1] on 12 March 2018, an Airbus Helicopters AS355F-1 Helicopter, registered VH-SEV (SEV), operated by Rotor Head, air taxied from the hangar to the maintenance facility at Bankstown Airport, New South Wales for a routine maintenance inspection with the pilot and one passenger on board.

After about 5 minutes in flight, the pilot commenced the landing. As the skids touched the ground, the pilot recalled hearing a loud squeal from the right-hand side of the aircraft. The pilot scanned the instrument panel and observed the engine gas generator speed (Ng) drop to 55 per cent and the right-hand engine chip light illuminate. A few seconds later, the pilot saw smoke coming from the right-hand side of the aircraft and he immediately shut down the right-hand engine. Mechanics from a nearby workshop witnessed the event and acted quickly to extinguish the fire on the right-hand engine.

The incident resulted in substantial damage to the right-hand engine and minor heat damage to the surrounding structure on the aircraft.
__________

  1. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.

Context

Aircraft information

The aircraft was an AS355F-1 helicopter manufactured in 1982 and first registered in Australia in 1994 (VH-SEV). It was a six-seater, twin-engine helicopter powered by two Allison 250-C20F turboshaft engines (Figure 1), with enhanced power turbine wheels.

Figure 1: Right-hand engine from VH-SEV

Figure 1: Right-hand engine from VH-SEV.
Source: ATSB

Source: ATSB

Engine maintenance

On 31 January 2018, a heavy maintenance inspection was conducted on the engines installed on SEV. The maintenance included actions required for compliance with the relevant airworthiness directive (AD) and commercial engine bulletins (CEB) (see the section titled Aircraft safety alerts). Some of the maintenance items on the turbine section (Figure 2) of the right-hand engine included:

  • replacement of the first-, second- and fourth-stage turbine wheels
  • fluorescent penetrant inspection (FPI) on the third-stage turbine wheel (there were no crack indications identified during the inspection).

The reliability of FPI is measured in terms of probability of detection (POD) and is dependent upon the component material and geometry in addition to the nature of the defect.[2] The engine manufacturer had not developed POD curves specifically for the third-stage wheel, however, based on industry reports, they advised that the POD of a 0.070 inch[3] long crack was 0.95 and for cracks smaller than 0.045 inches in length, the POD was considered to be around 0.4.

The aircraft was returned to service on 5 February 2018 and operated for 24 flight hours (22 cycles) before the right-hand engine failed.

Figure 2: Rolls-Royce (Allison) 250 engine cross section

Figure 2: Rolls-Royce (Allison) 250 engine cross section. 
Source: Rolls-Royce, annotated by the ATSB

Source: Rolls-Royce, annotated by the ATSB

Aircraft safety alerts and operations manual

Airworthiness directive 2017-18-14 and commercial engine bulletin 1407

AD 2017-18-14 was released in October 2017.[4] The AD was initially prompted by turbine wheel blade failures on the third- and fourth-stage wheels, which led to engine failure and damage to the aircraft.

The AD stipulated a number of measures that affected SEV, which included:

  • Every 1,775 hours, remove the third-stage turbine wheel to perform a visual inspection and FPI for cracks.
  • Remove and replace any turbine wheels found to have cracks at the trailing edge (near the fillet at the rim) of the turbine blades.

CEB 1407 was released in association with AD 2017-18-14 and provided additional guidance on how to conduct the FPI and visual inspection on the third-stage turbine wheels.

Commercial engine bulletin 1400

CEB 1400 provided advanced notification of actions pertaining to the third- and fourth-stage turbine wheels that were later incorporated into all applicable Model M250 Series II engine operation and maintenance manuals.

CEB 1400 was first released in December 2006. At the time of the incident, CEB 1400 revision 5 was in effect. The bulletin enforced a speed avoidance range for some Rolls-Royce M250 engines, which included the C20 series. The speed avoidance range was designed to reduce engine vibrations at resonant frequencies (or responsive wheel modes), which are known to accelerate fatigue cracking on the third- and fourth-stage wheel turbine blades.

For the parts installed on VH-SEV[5], a mandatory 75‑88 per cent engine N2[6] steady-state speed avoidance range was required for all flight and ground maintenance operational practices. Transient operation only was permitted in the speed avoidance range 75‑88 per cent N2. All other operation in the band was prohibited; in particular steady-state or continuous operations (any dwell of more than 1 second).

The Rolls-Royce service bulletin did not provide actions to carry out in the event of an inadvertent dwell in the speed avoidance range. Rolls-Royce advised, however, that operators should contact them for further advice should this occur.

M-250 C20 Operations and maintenance manual

At the time of the occurrence, the operations and maintenance manual for the engine specified the speed avoidance range and directed the user back to CEB 1400 for further guidance relating to the speed avoidance restriction.

Above the speed avoidance range notation, the consequence of not complying with the limitations was stated as:

WARNING: TO PREVENT SERIOUS ENGINE MALFUNCTION OR CRUCIAL LOSS OF POWER, DO NOT OPERATE THE ENGINE IN EXCESS OF ANY SPECIFIED LIMIT.

Pilot-related information

The pilot of VH-SEV (SEV) was an experienced helicopter pilot, with about 10,600 hours total flying time and about 4,400 hours on type.

The 71-88 per cent N2 speed avoidance range observed by the pilot was a conservative range that encompassed the engine manufacturer’s guidance (see the section titled Aircraft safety alerts and operations manual). The avoidance range was marked at the bottom of the instrument panel (Figure 3). The pilot’s standard start-up and shut-down procedures were to transition between ground idle (approximately 63 per cent N2) and 100 per cent N2 in a continuous motion through the speed avoidance range. The pilot stated that there were no operational parameters that required operation in the avoidance range.

Figure 3: VH-SEV instrument panel showing decal with speed avoidance range

Figure 3: VH-SEV instrument panel showing decal with speed avoidance range.
Source: Rotor Head

Source: Rotor Head

Engine examination specialist reports

Engine examination report

Following the incident, an engine examination was conducted at an engine maintenance facility with the assistance of Rolls-Royce. The following observations were made during the examination:

  • The damage was limited to the turbine section of the engine.
  • One blade on the third-stage turbine wheel had liberated, resulting in substantial secondary damage to the wheel (Figure 4).
  • Damage to the other engine components was consistent with secondary damage caused by rotor imbalance and impact damage from debris (Figure 5).[7]

Figure 4: Third-stage turbine wheel removed from VH-SEV showing damage

Figure 4: Third-stage turbine wheel removed from VH-SEV showing damage.
Source: ATSB

Source: ATSB

Rolls-Royce failure analysis

Following the engine examination, Rolls-Royce conducted metallurgical failure analysis on the third-stage wheel. The laboratory report included the following findings:

  • The microstructure, chemistry and hardness of the third-stage turbine wheel were consistent with the engineering requirements.
  • Using FPI, 21 of the remaining 34 third-stage turbine wheel blades were found to have crack-like indications on the trailing edge. The indications ranged in length from 0.007 inches to 0.045 inches.
  •  One third-stage turbine wheel blade fractured and separated due to fatigue cracking. The fracture surface showed two distinct fatigue regions:
  • The initial portion of the crack was consistent with the crack-like indications in the trailing edge of the blades. It was 0.069 inches in length and characterised by oxidation across the fracture surface. The number of fatigue striations indicated that this portion of the crack was present at the time of the maintenance inspection. However, the exact size of the crack at the time of the inspection could not be determined.
  • The crack then transitioned to a high cycle fatigue cracking mechanism, progressing towards the leading edge, before the blade liberated in overload (Figure 5).

One of the blades with crack-like indications was selected for further analysis. The blade was lab-fractured and the fracture surface compared to that of the liberated blade. The crack was measured to be 0.045 inches in length and the crack morphology was found to be consistent with the initial portion of the failed blade.

Figure 5: Fracture surface of liberated blade on third-stage turbine wheel

Figure 5: Fracture surface of liberated blade on third-stage turbine wheel.
Source: Rolls-Royce, annotated by the ATSB

Source: Rolls-Royce, annotated by the ATSB

Third-stage turbine wheel failures

Since the release of the enhanced third-stage turbine wheel (as installed on SEV) in 1999, there have been nine reported in-service failures. At the time of writing this report, the enhanced fleet (C20 Series, C20R Series, B17 Series, and B17F Series engines) had accumulated approximately 8.2 million flight hours. The failure rate of the third-stage wheels is therefore 1 in 911,111 flight hours. Rolls-Royce is working on design changes to reduce the risk to 'As low as reasonably practicable' (ALARP).

Additionally, 21 third-stage wheels have been returned to Rolls-Royce after crack-like indications were identified during the maintenance inspections required by AD 2017-18-14 (and previously released versions).

Of the nine reported in-service failures:

  • Four investigations were conducted (three by the National Transportation Safety Board (USA) and one by the Transportation Safety Board (Canada)) between 2003 and 2017.
  • In each instance, at least one blade on the third-stage turbine wheel liberated because of fatigue, resulting in an engine failure. Analysis showed similar crack morphology to that found on the third-stage wheel of SEV.
  • At the time of those investigations, Rolls-Royce was unable to identify a single root cause for the liberation of the turbine blades.

Examination of the returned turbine wheels and further simulated analysis enabled Rolls-Royce to develop a better understanding of the failures. With improved knowledge, Rolls-Royce has now stated that high cycle fatigue crack progression only occurs when there is steady-state operation of the engine at a responsive wheel mode. The responsive wheel modes were identified in CEB 1400 and are specified as the speed avoidance range.

In 2011, Rolls-Royce learnt that there was an issue with the maintenance practices for MD Helicopters (in particular the MD-500, which had seen 2 blade failures in the 1999-2009 period). This error resulted in the maintenance personnel sometimes dwelling the engine in the speed avoidance range while doing track and balancing of the main rotors. In 2011, MD changed their track and balance procedure specifically to address this issue.

Additional information

Rolls-Royce provided the following additional information to the ATSB regarding the engine failure:

  • Fatigue crack growth under normal operational loading is very slow. Cracks initiated under this regime on the trailing edge of the turbine wheel blade will not propagate to failure in the life of the wheel (4,550 flight hours, 6,000 flight cycles) if the aircraft is operated in accordance with CEB 1400.
  • There does not need to be a pre-existing fatigue crack on a blade for the steady-state engine operation at a responsive wheel mode to cause blade failure.
  • The blade failure event and operation on a responsive wheel mode may not have occurred simultaneously.
  • A dwell in the order of a few seconds in the speed avoidance range is sufficient to cause a crack to propagate in high cycle fatigue.
  • A pilot can identify a dwell by watching the needle on the tachometer. If the needle remains stationary for any period of time this would indicate a dwell.

The pilot did not recall any incidents where the N2 speed had dwelled in the speed avoidance range between the last maintenance inspection (see the section titled Engine maintenance) and the incident flight. The pilot indicated that while he was aware of the speed avoidance range and was careful to avoid continuous operation within it, he was not aware that a dwell in the order of a few seconds could result in total failure of the engine.

__________

  1. Experimental estimation of POD usually requires a large number of service-expired engine turbine disks. Alternatively, the POD studies can also be carried out using laboratory induced samples containing various sizes of defects.
  2. The imperial unit for length. 1 inch (in) is equal to 25.4 mm.
  3. The AD was first released as AD 2012-14-06 in 2012. The AD was subsequently revised and replaced with AD 201502-22 in 2015 and then again in 2018 by AD-2017-18-14
  4. SEV was fitted with third-stage wheel part number 23065818 and fourth-stage wheel part number M250-10445.
  5. N2: the rotational speed of the power turbine.
  6. Based on the manufacturer’s previous experience and comparison with examination of other engines known to have a liberated blade on the third-stage wheel.

Safety analysis

Engine failure

Metallurgical analysis of the fracture surface of the single liberated turbine blade showed conclusively that the blade had failed under fatigue loading. The fracture type and location of the primary crack was as described in AD-2017-18-14.

Damage was limited to the turbine section of the engine, with the power turbine exhibiting a significant amount of scoring inside the engine casing and a fractured turbine to compressor coupling shaft. This damage is consistent with damage from rotor imbalance resulting from the release of a turbine blade. With the exception of the third-stage wheel, the remainder of the damage was identified as impact damage from debris. In addition, Rolls-Royce stated that the damage to the SEV engine was consistent with that found during previous examinations on engines known to have third-stage wheel failures.

In summary, a single third-stage turbine wheel blade failed due to fatigue cracking, resulting in secondary damage to the engine and total engine failure.

Third-stage turbine wheel fatigue cracks

Rolls-Royce’s analysis of the failed and lab-fractured blade concluded that at least two fatigue cracks existed at the time of the last maintenance inspection. Given the large number of blades found with crack-like indications, it is likely that some or all of the indications on the remaining blades were present at the time of the inspection.

In the event that any of the cracks had been detected, the correct course of action (per the requirements of AD-2017-18-14) would have been to remove the wheel from service. The primary fatigue crack on the liberated blade was measured to be 0.069 inches and the remainder of the crack-like indications were a maximum of 0.045 inches long. The probability of detection of any one crack less than 0.045 inches was estimated to be 0.4. Therefore, the indications existing at the time of inspection were likely to be so small that the probability of detecting any one of the cracks in the turbine blades was low.

It was therefore concluded that a number of fatigue cracks were present but not detected during the last inspection of the third-stage wheel. However, due to the size and nature of the cracks there was a low probability of detection using the specified method.

Rapid fatigue crack progression

The primary fatigue crack on the liberated blade was no greater than 0.069 inches in length at the time of the inspection. Within 24 flight hours (22 flight cycles) the fatigue crack progressed to more than 50 per cent of the blade cross section. That is, it propagated to the critical crack length in under 0.5 per cent of the expected life of the wheel.

The manufacturer’s analysis showed that under normal operational loading, a crack indication at the trailing edge of the blade would not progress to failure within the life of the wheel (4,550 flight hours, 6,000 flight cycles). Physical examination of the fracture surface verified that the blade did not fail because of a material or component defect, or impact damage. Rolls-Royce identified that the crack propagated under high cycle fatigue loading, which it determined was the result of steady state operation of the engine at a responsive wheel mode (defined as the speed avoidance range). Without recorded flight data, however, a dwell in the speed avoidance range could not be verified.

The pilot had significant experience on this aircraft and had never had any previous engine failures using his standard power up/down process. The pilot was aware of the speed avoidance range and did not recall dwelling in the range between the engine maintenance and the incident flight. However, given that the damage can occur in the order of a few seconds, it is possible that a momentary distraction during the power-up or -down phase could have resulted in an inadvertent, unnoticed dwell.

While it was not possible to verify the operation of the aircraft, based on examination of the fracture surfaces and expert opinion, the rapid fatigue crack progression in the third-stage wheel was probably caused by a momentary dwell in the speed avoidance range.

Findings

From the evidence available, the following findings were made with respect to the engine failure involving Airbus Helicopters AS355F-1, registered VH-SEV at Bankstown Aerodrome, New South Wales on 12 March 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • A single third-stage turbine wheel blade failed due to fatigue cracking, resulting in secondary damage to the engine and total engine failure.
  • The rapid fatigue crack progression in the third-stage wheel was probably caused by a momentary dwell in the speed avoidance range.

Other factors that increased risk

  • A number of fatigue cracks that would have required removal of the third-stage turbine wheel from service were present, but not detected during the last inspection. The size and nature of the cracks meant there was a low probability of detection using the specified inspection method.

Safety issues and actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action.

Rolls-Royce

To reduce the risk of engine failure events, Rolls-Royce is re-designing the third-stage turbine wheel to improve the strength and durability of the component. The main feature of the new design is a larger fillet at the blade trailing edge, which will reduce the stress at the critical location, resulting in a more durable component with greater tolerance to fatigue cracking and operation at responsive wheel modes. The new design was expected to be released at the end of 2020.

Since this occurrence, Rolls-Royce has also updated CEB 1400 (Revision 7) and the operations manual to simplify the speed avoidance range and more clearly articulate the possible consequence of dwelling. The operations manual now states:

WARNING: TO PREVENT POSSIBLE POWER TURBINE FAILURE, TRANSIENT OPERATION ONLY IS PERMITTED IN THE N2 SPEED AVOIDANCE RANGE. ALL OTHER OPERATION IN THIS RANGE IS PROHIBITED.

Airbus Helicopters

Airbus Helicopters published Safety Information Notice No. 3289-S-72 in October 2018 (Appendix A and available at www.airbushelicopters.com/techpub/) to highlight CEB 1400 and the risk of malfunction from an engine dwell within the identified resonant ranges.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • engine manufacturer (Rolls-Royce)
  • engine maintenance provider
  • aircraft owner
  • pilot.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the pilot, the aircraft owner/operator, the engine manufacturer (Rolls-Royce), the engine maintenance provider, the Civil Aviation Safety Authority and the French Bureau d’Enquêtes et d’Analyses pour la sécurité de l’aviation civile (BEA).

Submissions were received from the pilot, Rolls-Royce and BEA. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Appendices

Appendix A – Airbus Helicopters safety information notice

Appendix A – Airbus Helicopters safety information notice.
Source: Airbus

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2018-021
Occurrence date 12/03/2018
Location Bankstown Airport
State New South Wales
Report release date 12/03/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Engine failure or malfunction
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Airbus Helicopters
Model AS355F-1
Registration VH-SEV
Serial number 5272
Aircraft operator Rotor Head
Sector Helicopter
Operation type Aerial Work
Departure point Bankstown, New South Wales
Destination Bankstown, New South Wales
Damage Minor

Collision with water involving Cessna 206 floatplane, VH-LHQ, Southport Broadwater, Queensland, on 4 March 2018

Final report

Report release date: 23/10/2018

What happened

On 4 March 2018, the pilot of a Cessna 206 floatplane, registered VH-LHQ (LHQ), operated by Cloud 9 Seaplanes, was due to pick up two passengers from a park next to Sea World Resort at Southport Broadwater, Queensland, for a short charter flight to Stradbroke Island.

At about 0845 Eastern Standard Time,[1] the pilot arrived at the aircraft’s base and conducted a pre-flight inspection. At about 1000, he conducted a 6-minute positioning flight from LHQ’s base to Southport Broadwater, where he was due to collect the passengers. No problems or defects were identified during the pre-flight inspection or the positioning flight.

At about 1030, prior to the passengers boarding the floatplane, the pilot briefed them on the safe entry and exit procedures. The passengers boarded LHQ and, at about 1040, the pilot began taxiing. During the taxi, the pilot completed the passenger safety briefing. As part of the briefing, the passengers were shown the location of their life jackets and the location and operation of the emergency exits. To ensure the passengers understood how to operate the emergency exit, the pilot asked the passenger in the rear seat to practice opening the exit.

The floatplane had a relatively long taxi to avoid a large boat travelling south. After the boat passed, the pilot taxied to the eastern side of the western channel (Figure 1), passing over the boat’s wake.

Figure 1: Approximate aircraft taxi and take-off path

Figure 1: Approximate aircraft taxi and take-off path. Google maps, annotated by ATSB

Source: Google maps, annotated by ATSB

Shortly after, the pilot applied take-off power. The take-off run was normal and the pilot put the aircraft on the step.[2] The pilot reported that take-off run was a little bumpy, due to the wakes of some speedboats in the vicinity, but he did not consider it out of the ordinary. At about 30 kt, the aircraft started to ‘wobble’ from side-to-side. Moments later, the nose pitched down and the propeller contacted the water. In response, the pilot pulled back the power and mixture and attempted to steer the aircraft in a straight line – there was little steering control.

The aircraft came to a stop about 300 m from the shore. The pilot reminded the passengers of how to put on their life jackets, before he got out of the aircraft to assess the floats for damage. He found the front spreader bar of the floats had fractured but the floats were intact. As they were intact, he decided not to evacuate the passengers. No one had been injured.

The pilot then deployed and secured the floatplane’s anchor. About a minute after the occurrence, a parasailing boat whose occupants had witnessed the accident came alongside the aircraft. The passengers were transferred to the boat and taken ashore.

After another couple of minutes, a voluntary marine rescue boat arrived at the scene, and arranged to tow the substantially damaged aircraft onto a nearby beach (Figure 2).

Figure 2: The damaged Cessna 206 aircraft

Figure 2: The damaged aircraft. Source: Operator

Source: Operator

Floats

The aircraft was equipped with Aerocet seaplane floats. These floats incorporated composite float hulls, separated by two aluminium spreader bars and mounted to the aircraft with aluminium struts. Flying wires stabilised the mounting to the aircraft, and the spreader bars were attached to a socket inside the float.

The manufacturer provided an inspection regime for the floats, which included 25, 100 and 200‑hour inspections. The maintenance manual included repair procedures for minor damage and information on when the manufacturer should be consulted about damage and repairs. The floats did not have a service life limitation and operated ‘on condition’.

The maintenance manual, however, did indicate that ‘exceptional inspections’ were necessary to identify possible damage to the floats. The manual listed the following scenarios that could make such inspections necessary:

  • Landing on grass or other runway
  • Harsh landings
  • Impact with submerged objects
  • Suspected damage during tie-down or mooring, such as from wind or wave action
  • Excessive water during pump-out or pre-flight inspection

The floats were installed new in June 2016, after the operator acquired LHQ. At the time of the accident, the floats had about 370 hours in service. The maintainer had conducted a visual inspection of the floats 22 hours prior to the accident – no defects to the spreader bar were identified. The operator stated that he always carried out a visual inspection of the floats during the aircraft’s daily wash. The aircraft was last washed the day prior to the accident. No defects were identified during the wash or pilot’s walk around on the morning of the accident.

After the accident, the spreader bars were inspected and a fatigue crack was identified in the front spreader bar that had propagated to the point of failure. The failure was located about 3.5 cm inside the float so the fatigue crack was not visible (Figure 3). Cracks were also identified extending from the boltholes of the rear spreader bar. It could not be determined if these were a result of the accident or were pre-existing.

Figure 3: Front spreader bar fatigue failure located within the float

Figure 3: Front spreader bar fatigue failure located within the float. Source: Operator

Source: Operator

The spreader bars were returned to the manufacturer for further analysis. As a result of that analysis, the manufacturer reported that there was ‘no apparent autogenous condition such as occlusions in the base material. It appears that repeated overloading of the float structure occurred leading to cracking in a difficult to detect location.’

Previous failure

In October 2015, the operator found a fatigue crack in a spreader bar in a similar location during his daily inspection on another set of Aerocet C206 floats. In that instance, the crack extended outside the floats and was detectable. The crack had extended to about 50 per cent of the spreader bar. The operator reported that failure to the manufacturer and provided the Civil Aviation Authority (CASA) with a defect report.

The manufacturer stated that no other operator had reported similar failures.

Operating environment

After the accident, the operator identified a number of factors that may have increased the stresses on the floats. These included:

  • Conducting a high number of 5-minute scenic flights that increased the number of take-off and landing cycles per flying hour.
  • When the seaplane is beached at Sea World resort, due to the angle of the beach, large boat wakes can hit the seaplane at a 45-degree angle. This results in the floats and spreader bars shuddering.
  • During take-off and landing at Sea World and Couran Cove, cross wakes (two boat wakes colliding) can cause large waves and create a bumpy ride and excessive bounce and stress on the float hardware.
  • Retrieval of the seaplane at the end of the day sometimes caused the seaplane to rock on the boat ramp when the plane was being loaded onto the trailer.

Safety analysis

During the take-off of LHQ, the floats’ front spreader bar fractured. This resulted in the floats separating forward of the floatplane’s centre of gravity and its propeller impacting the water.

The float system was designed and constructed with the spreader bar attached to a fitting within the float. This resulted in a section of the spreader bar that could not be visually inspected as it was also within the float. In this accident, the fatigue crack was located in that internal section of the spreader bar, which meant that it was not possible to visually identify it during normal operation and maintenance.

The operator had previously identified a fatigue crack in a spreader bar on another aircraft. In that instance, the crack had extended outside of the float and been identified prior to structural failure.

The operating environment increased stresses on the float assembly due to the short flights increasing the take-off and landing cycles per flight hour as well as increasing the amount of taxiing time per flight hour. This increased flight frequency, along with operating in a high water traffic environment, increased the loading on the floats.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • During the take-off roll, the floatplane’s front spreader bar fractured resulting in the floats separating and the aircraft pitching down sufficiently for the propeller to contact the water.
  • The origin of the fracture was a fatigue crack in the spreader bar section located inside the float, which meant routine visual inspections could not have detected the crack.
  • Frequent, short flights in an area of high-water traffic exposed the floats and associated structure to high cyclic loading and stresses, increasing the likelihood of material fatigue.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Cloud 9 Seaplanes

The aircraft operator advised the ATSB that they had taken the following safety actions as a result of this occurrence:

Proactive safety action
  • A borescope will be used to inspect spreader bars at intervals of 100 service hours. 
  • In addition to the 25 hourly inspection, the floats and hardware will be inspected while the floatplane is on the water. This will help to determine if there is any play in the fittings and hardware.
  • Passenger loading has moved from Sea World Resort, to a location with a beach with less exposure to boat wake.
  • Passengers and ropes will be used to keep the plane at a 90-degree angle to the water at all times when boat wakes are present. This will reduce uneven loading on the floats.
  • A review of the take-off and landing areas and times will be carried out, to reduce rough and bouncy landings. 
  • The number of 5-minute scenic flights will be minimised to reduce the number of take‑off and landing cycles.
  • The end of day procedure will be modified to reduce stresses on the floats when loading the seaplane onto the storage trailer.

Safety message

Scheduled maintenance inspections and the pilot’s daily inspection are a central element of the continuing airworthiness of the aircraft. However, continuing airworthiness also relies on inspections that allow the identification of damage, so that parts can be repaired or replaced prior to failure. In addition, where a structure may have experienced excessive loads (for example, hard landings) additional inspections may be required.

As was the case in this accident, it is important that defects are reported to regulators and aircraft manufacturers because they depend on accurate data to ensure the ongoing continued airworthiness of the aircraft. Defects reported to CASA through the Defect Report Service (DRS) system, and to the manufacturer, provide the opportunity for fleet trend monitoring and allow issues to be identified and rectified.

About this report

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope, fact-gathering investigation was conducted in order to produce a short summary report, and allow for greater industry awareness of potential safety issues and possible safety actions.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Standard Time (EST): Universal Coordinated Time (UTC) + 10 hours.
  2. The step position is the attitude of the aircraft when the entire weight of the aircraft is supported by hydrodynamic and aerodynamic lift, as it is during high-speed taxi or just prior to take off. This position produces the least amount of water drag. The step is also called the planing position.

Occurrence summary

Investigation number AO-2018-020
Occurrence date 04/03/2018
Location Southport Broadwater
State Queensland
Report release date 23/10/2018
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model C206
Registration VH-LHQ
Serial number U20603773
Aircraft operator Cloud 9 Seaplanes
Sector Piston
Operation type Charter
Departure point Southport Broadwater, Queensland
Damage Substantial

Fuel exhaustion and forced landing involving Cessna 441, VH-LBY, 39 km east-south-east of Broome Aerodrome, Western Australia, on 2 March 2018

Final report

Report release date: 27/05/2021

Safety summary

What happened

On 02 March 2018, at 1549 Western Standard Time, a Skippers Aviation Cessna 441 Conquest, registered VH-LBY, departed on a scheduled passenger service from Fitzroy Crossing to Broome, Western Australia with one pilot and nine passengers on board.

During descent, the FUEL LEVEL LOW annunciators illuminated. The pilot observed that both fuel quantity gauges indicated sufficient fuel remaining and continued flying towards Broome. The right engine began surging, followed by similar surging from the left engine. Subsequently, the right engine lost power and the pilot conducted the engine failure checklist.

The pilot declared a MAYDAY and advised air traffic control that, as the left engine was still operating, the aircraft would be able to reach Broome. However, the left engine also lost power and both engines were unable to be restarted. The pilot landed the aircraft safely on the nearby highway. There were no injuries, and the aircraft was undamaged.

What the ATSB found

Due to water contamination in the fuel tanks, the aircraft’s fuel quantity gauges were significantly over reading on the day of the occurrence and on previous days. The water contamination had existed for some time without being detected by multiple pilots’ fuel quality testing.

Although the pilot routinely compared indicated versus calculated fuel quantities, and indicated versus flight-planned fuel quantities, the pilot did not routinely conduct two other methods stated in the operator’s procedures for cross-checking fuel quantity gauge indications.

In addition, although the operator had specified multiple methods of cross-checking fuel quantity gauge indications for its C441 fleet, there were limitations in the design, definition and/or application of these methods. The primary method used (indicated versus calculated fuel) was self-referencing in nature, and not able to detect gradual changes in the reliability of fuel quantity gauge indications. Pilots also did not record (and were not required to record) sufficient information on flight logs to enable trends or patterns in fuel quantity gauge indications to be effectively identified, and pilots did not routinely cross-check information from fuel quantity gauge indications with information from the independent fuel totaliser.

The FUEL LEVEL LOW annunciators likely illuminated approximately 30 minutes before the fuel was exhausted in each tank, and when the aircraft was still within range of suitable alternative airports. However, the pilot disregarded the annunciations, and relied on the (erroneous) fuel quantity indications and continued to Broome until the engines lost power, at which point a forced landing on a highway was the only remaining option.

What has been done as a result

The operator increased the frequency of a fuel quantity comparison checks to a known quantity to ensure continued quantity measurement accuracy, specified clearer requirements for determining discrepancies when using fuel totaliser figures, implemented additional fuel management record keeping and increased management oversight of its Broome operations. It also increased focus on fuel management procedures during training.

Safety message

Accurate fuel management is a critical aspect of flight operations, and it is important to utilise all available means in order to gain the highest assurance that fuel quantity measurement is accurate. It is essential that a reliable quantity cross-check is adopted, utilising at least two independent methods and a conservative approach. Pilots also should understand the functionality of the low fuel warning system on their aircraft and treat any warning annunciations as being accurate unless there is overwhelming evidence otherwise.

Further reading is available in the ATSB research report, Starved and exhausted: Fuel management aviation accidents (AR-2011-112). This report discusses methods that pilots can use to ensure they will have sufficient fuel to land at their destination.

 

The occurrence

Previous sectors

On 2 March 2018, Skippers Aviation was operating a twin turboprop Cessna 441 Conquest (C441), registered VH-LBY, on a four-sector scheduled passenger flight from Broome to Fitzroy Crossing, then to Halls Creek, returning via Fitzroy Crossing to Broome, Western Australia. The flight was conducted as a single-pilot operation under instrument flight rules. No significant weather was forecast for Broome and there was a risk of afternoon thunderstorms at the other destinations.

The pilot flew the same aircraft on the previous day. At the end of that day’s flying, the pilot recorded on the aircraft’s flight log that the fuel gauges were indicating a total of 1,300 lb[1] usable fuel.[2] Prior to the first flight on 2 March, 600 L (1,050 lb) of fuel was uploaded, which resulted in a calculated fuel on board of 2,350 lb. This amount was sufficient to conduct all four sectors.

After arriving at Halls Creek following the second sector on 2 March, the pilot recorded the fuel quantity gauges as indicating a total of 1,430 lb usable fuel. The pilot stated that the indicated fuel quantities after the first two sectors were consistent with the expected (flight-planned) fuel burns for those sectors. The pilot also reported that the first three sectors were conducted without incident and on schedule.

Prior to departure from Fitzroy Crossing

The aircraft arrived at Fitzroy Crossing after the third sector at 1532 Western Standard Time.[3] The pilot recorded the fuel quantity gauges as indicating a total of 1,300 lb. This indicated that the fuel burn for the third sector was 130 lb, although the pilot recorded 230 lb on the flight log. The flight-planned fuel burn for the third sector was 357 lb, and the pilot was expecting a fuel quantity indication of about 1,110 lb rather than 1,300 lb.

The pilot’s flight plan estimated 977 lb was the minimum required for the final sector (included reserves). Noting that the indicated fuel quantity (1,300 lb) was above the minimum required according to the flight plan, the pilot did not consider the difference between the expected fuel quantity and indicated quantity any further.

Departure and cruise

The pilot and nine passengers were on board for the last sector from Fitzroy Crossing to Broome (Figure 1).

The pilot reported that, during the taxi for departure at Fitzroy Crossing, the right fuel transfer pump (R X-FER PUMP FAIL) annunciator illuminated momentarily. The pilot attributed this to fuel moving within the tank during the left turn onto the runway from a downward sloping taxiway. The pilot also noticed an imbalance between the quantity indications (left tank higher than right) and selected the right engine crossfeed (both engines supplied from the left tank). The pilot reported that the quantity indications for both sides were similar prior to take-off.

The aircraft departed Fitzroy Crossing at 1549. The pilot reported that the take-off and climb to flight level 260 (FL 260)[4] were normal.

Figure 1: Aircraft track (just prior to top of climb until landing) and highway

Aircraft track (just prior to top of climb until landing) and highway

Source: Google Earth, modified by the ATSB

The aircraft reached top of climb at 1607. The pilot stated that, shortly after, the left main boost pump (fuel pump) circuit breaker opened, and the left auxiliary boost pump (L AUX BOOST ON) annunciator illuminated (indicating automatic activation in order to maintain fuel supply). After a short delay to allow the fuel pump to cool, the pilot reset the circuit breaker. The pilot recalled that the circuit breaker opened again, so they conducted the main and auxiliary fuel boost pump failure checklist.

At 1613, the pilot contacted air traffic control (ATC) and advised that the aircraft was maintaining FL 260 at about 90 NM from Broome. ATC cleared the pilot to descend when ready to 7,000 ft. About a minute later, the pilot commenced descent. At this point the aircraft was approximately 27 NM south of Curtin Airport and 42 NM south of Derby Airport (Figure 1).

At about this time, the pilot observed a fuel imbalance (right tank higher than left) that was not consistent with the fuel quantity indications on departure and the fuel flow observed during climb. The pilot selected left engine crossfeed (both engines supplied from the right tank), but the right auxiliary boost pump (R AUX BOOST ON) annunciator did not illuminate as it should for this crossfeed selection. The pilot assessed this as an annunciator fault as the left tank quantity showed an expected increase.

The pilot stated that, during the crossfeed, the R X-FER PUMP FAIL annunciator flickered on and then off, prompting the pilot to stop the crossfeed. The R FUEL LEVEL LOW annunciator then illuminated. The pilot observed that both fuel gauges indicated sufficient fuel to continue to Broome. Shortly after, the R X-FER PUMP FAIL and right fuel pressure low (R FUEL PRESS LOW) annunciators also illuminated. A few minutes later, the corresponding left fuel system annunciators also illuminated.

Engine power losses

The pilot recalled that, soon after the annunciators illuminated, the right engine began surging, prompting the pilot to conduct the partial/intermittent engine power checklist. During the checklist actions, the left engine also started to surge. Following completion of checks for the right engine (with no success), the pilot conducted the checks for the left engine. During this activity, the right engine lost power and the pilot then conducted the engine failure checklist.

At 1623, the pilot contacted the Broome tower controller and declared a MAYDAY.[5] The aircraft was approximately 47 NM east of Broome at FL 155. By this time, the aircraft was now a similar distance from Derby and Curtin (Figure 1).

At 1627, the tower controller asked the pilot if the aircraft would still be able to reach Broome. The pilot advised that the left engine was still operating, and they would be able to reach Broome. At this time, the aircraft was descending through 10,800 ft and approximately 38 NM from Broome. However, shortly after, the left engine also lost power. The pilot attempted to restart the left engine. It regained power for a brief time before surging and losing power again. Further restart attempts were made on both engines without success.

Diversion and forced landing

With both engines not providing power, the pilot assessed that the aircraft would not reach Broome and they tracked to the south towards the Great Northern Highway in the vicinity of Roebuck Plains.

At 1633, the pilot notified Broome tower of the ‘dual engine failure’ and intentions for the forced landing. The aircraft was approximately 22 NM east of Broome at approximately 4,000 ft. The pilot was unable to extend the landing gear normally and conducted an emergency extension of the gear. Although a passenger brief was conducted, the passengers were not instructed to brace for the emergency landing.

The pilot landed the aircraft safely on the highway approximately 21 NM east-south-east of Broome without injuries or aircraft damage (Figure 1).

After landing, the pilot made radio contact with another aircraft in the area, and the pilot of that aircraft relayed their status and requirements to Broome tower. All passengers were subsequently transferred to Broome via road. The aircraft was towed and secured at a nearby truck stop.

A photo of the fuel quantity gauges taken approximately 1 hour after landing indicated about 1,120 lb fuel on board (Figure 2). Subsequent inspections identified that little or no usable fuel was on board.

Figure 2: Fuel gauges after forced landing

Fuel gauges after forced landing

The image shows the fuel gauges indicating a total of about 1,120 lb of fuel on board, about 1 hour after landing on the highway. With the addition of fuel calibration card corrections, the indicated amount should have represented 1,220 lb.

Source: Pilot of VH-LBY following occurrence flight

__________

  1. The Cessna 441 Pilot’s Operating Handbook and instrumentation refers to fuel quantity as a weight in lb. The operator specified a conversion factor of 1.74 (1 L equals 1.74 lb). A quantity of 1,300 lb equated to 747 L.
  2. Unless otherwise noted, the indicated fuel quantities in this report include the application of fuel calibration card corrections.
  3. Western Standard Time (WST): Coordinated Universal Time (UTC) + 8.0 hours.
  4. Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 260 equates to 26,000 ft.
  5. MAYDAY: an internationally recognised radio call announcing a distress condition where an aircraft or its occupants are being threatened by serious and/or imminent danger and the flight crew require immediate assistance.

Context

Pilot information

The pilot held a valid commercial pilot (aeroplane) licence with a multi engine command instrument rating and a valid medical certificate. The pilot joined Skippers Aviation in May 2017 and had been qualified on the Cessna 441 (C441) since June 2017. They had a total of 2,403 hours flight time, of which 402 hours were on the C441. The pilot had also flown a number of single engine aircraft, including the Cessna 172, 206 and 210, and other multi-engine aircraft, including the Beechcraft Baron and Cessna 402 and 404.

The pilot’s training records for conversion to the C441, check to line and the most recent instrument proficiency check did not contain any major issues or concerns regarding the pilot’s performance or capability.

The pilot was one of four pilots based in Broome that operated C441 aircraft for the operator.

Aircraft information

General information

The C441 is a pressurised twin engine turboprop aeroplane, accommodating up to 11 people.

VH–LBY, serial number 0023, was manufactured in 1978. It was first registered in Australia in May 1986 and Skippers Aviation was the registered operator from November 1992. The aircraft had accumulated over 25,000 hours total time in service. The aircraft was one of three C441s based in Broome used by the operator.

Fuel tank system

The C441 fuel system includes fuel tanks as integral portions of each sealed wet wing. Each fuel tank normally supplies the engine on the same side of the aircraft. The total usable fuel capacity is 3,168 lb or 1,800 L (1,584 lb per side). Fuel systems schematics are provided in Appendix A – Fuel System Schematics. 

Each fuel tank incorporates an open-top hopper tank (located inboard), which accumulates fuel to ensure continuous supply for the two electric boost pumps (main and auxiliary) situated in the bottom of the hopper. The main boost pumps supply fuel under pressure to the respective engine and transfer ejector pumps. If the main boost pump fails, the auxiliary boost pump will automatically activate, and the associated annunciator (L/R AUX BOOST ON) will illuminate. 

The transfer ejector pumps in each tank utilise high pressure fuel flow from the respective boost pumps (motive flow) in conjunction with a venturi to produce a high-volume flow. Provided a boost pump is operating (main or auxiliary), the respective ejector pumps will operate continuously to transfer fuel from the lowest points in the forward and rear of each tank into the hopper to maximise the amount of usable fuel available to the engine. 

If the boost pumps are off, the transfer ejector pumps will not transfer fuel from the tank to the hopper. If more than 580 lb of fuel is in the tank, the fuel level will be sufficient to overflow into the open-top hopper tank and keep it full. If there is less than 580 lb of fuel in the tank, then fuel will not overflow, and the fuel level in the hopper will lower.   

For each fuel tank, the associated X-FER PUMP FAIL annunciator is actuated by a float switch near the top of the hopper tank. The annunciator will illuminate when: 

  • less than 80 lb of fuel is in the hopper tank (with boost pumps on), or 
  • less than 580 lb of fuel in the tank, including in the hopper tank (with boost pumps off). 

Illumination of the X-FER PUMP FAIL annunciator is usually associated with failure of the respective transfer ejector pumps. That is, a failure to ensure the hopper tank remains full. 

However, this feature can also be used on the ground to determine if a tank’s quantity is above or below 580 lb by turning the fuel boost pumps off and observing the annunciator. Illumination of the annunciator indicates a fuel quantity in the tank less than 580 lb. 

In case of an engine failure or fuel tank imbalance, a crossfeed system allows the pilot to select one of the engines to be supplied from the tank on the other wing. For example, if both engines are operating and the left engine crossfeed is selected, the following would occur without further pilot action: 

  • interconnection of the output from the two tanks 
  • left main boost pump de-energised 
  • right auxiliary boost pump energised (in addition to right main boost pump) 
  • both engines supplied from the right tank 
  • excess fuel leaving the right tank transferred to the left tank. 

Two drain valves are fitted to the lower inboard surface of each fuel tank and two are fitted to the crossfeed lines to allow samples to be extracted for visual and chemical detection of water and other contaminants. The standard design of VH-LBY did not include drain valves in the hopper floor panel and none were fitted at the time of the occurrence. 

The manufacturer advised that the drains were located at low points in the fuel tank system, which was in front of the hopper tanks. It also noted that the pre-flight checklist called for the sumps in each wing, and the two crossfeed line sumps, to be drained and checked for water and contamination before each flight. It stated that draining those fuel sumps before every flight would remove water that has entered the fuel tank and prevent that water from being fed into the hopper tank. 

Fuel quantity indications 

The fuel quantity indicating system (FQIS) is a capacitance-type system with five probes in each tank, connected to a signal conditioner in each wing that converts probe values to an electrical output. This output is transmitted to two gauges on the instrument panel, which display the quantity of usable fuel in increments of 50 lb (Figure 2, Figure 3). 

Each probe is an assembly of concentric tubes acting as plates of a capacitor with fuel or air acting as the normal dielectric medium between plates. The value of probe capacitance is proportional to the submersion of the probe in the fuel. Probes are not adjustable but are subject to regular testing to establish serviceability. The signal conditioner can be adjusted to maximise the accuracy of the quantity indications. 

If a contaminant is in contact with the probes, then the quantity indications will be altered based on the capacitance property of that contaminant. Water has a much higher dielectric constant than fuel. Therefore, the presence of water on the probes would likely cause an over reading of the fuel quantity. 

The aircraft also has a low fuel warning system, activated by a magnetic float switch co-located with the inboard fuel probe. The L or R FUEL LEVEL LOW annunciator illuminates when the associated tank contains between 150–250 lb of usable fuel and the main and/or auxiliary fuel boost pumps are operating. The low fuel level warning is independent of the fuel quantity gauges. 

VH-LBY and the operator’s other C441 aircraft were fitted with fuel flow transducers that transmitted information to fuel flow gauges located on the instrument panel. This fuel flow information was also transmitted to the Garmin GNS 530 GPS/navigation system, which had a fuel totaliser function. A fuel on board figure was required to be manually entered prior to flight and/or after refuelling. Following this, the Garmin GNS 530 would then be able to accurately monitor the fuel consumed and calculate the residual fuel at any point. Senior pilots reported that the fuel burn figures produced by the Garmin 530 totaliser function were accurate. 

The aircraft was not equipped with a mechanism to directly read the fuel quantity in each tank, such as a drip/magna stick or sight gauge. It was only possible to visually determine the quantity of fuel on board the aircraft by viewing the fuel via the open fuel filler cap when the tanks were full. 

FQIS maintenance requirements 

The operator’s system of maintenance required that the FQIS was calibrated every 12 months. The procedure started with empty tanks and adjusting or verifying the zero indication of the gauges. Following this, fuel was added incrementally, and gauge indications were recorded for each added amount. A calibration card was then compiled, allowing pilots to make applicable corrections to the gauge readings to reflect actual fuel on board. 

The last calibration for VH-LBY was conducted in April 2017 and the calibration card was current until April 2018. For both tanks, the card required the addition of amounts of about 10 per cent of the indicated quantity. Similar values were evident in previous calibrations. 

In addition to the annual calibration, the operator required a comparison check of the FQIS at intervals of 150 hours flight time. The procedure required the tanks to be drained of all fuel, and then 500 lb per tank added in 100 lb increments. A comparison of gauge indications and fuel added was made to verify accuracy of the FQIS. 

The aircraft had been operated for about 66 hours since the comparison check, which was conducted on 6 January 2018. 

Post-occurrence actions and maintenance 

On the day following the occurrence (3 March 2018), a fuel drain was conducted and a significant but unquantified amount of water was drained. The aircraft was then refuelled with 650 lb of fuel from sealed drums and the subsequent fuel drain did not contain a significant amount of water. The engines were ground run and no fuel leaks were evident. The fuel pump pressure low and fuel level low annunciators were checked to be operating as satisfactory. 

Based on this evidence, and an assessment that both engines had likely lost power due to fuel exhaustion, the Civil Aviation Safety Authority (CASA) issued the operator with a special flight permit to allow the aircraft to be flown to Broome. The ferry flight was conducted without incident. 

On arrival in Broome, all usable fuel was drained from the aircraft by diverting boost pump output into drums. Accounting for the quantity of fuel added on the highway and consumed during the ferry flight, the operator estimated there was little or no usable fuel on board the aircraft at the time of landing on the highway. The operator also noted that the fuel quantity gauges indicated 370 lb per tank even though all the usable fuel had been drained (Figure 3). 

Figure 3: Fuel quantity gauges after defueling in Broome 

Figure 3.jpeg

The image shows the fuel gauges indicating 370 lb per tank, though all usable fuel had been drained from both tanks. Source: ATSB 

The aircraft was inspected in Broome by licenced aircraft maintenance engineers employed by the operator’s maintenance organisation, in consultation with observers from the ATSB and CASA. To allow inspection of the fuel tanks and system components internal to the tanks, the fuel drains were opened, and the underwing access panels were removed. As the panel forming the floor of the hopper (and boost pump mount) was removed, fuel was released into a container with some unavoidable spillage onto the floor. It was estimated that about 500 mL of water was in the fuel released from the hopper. 

Inspection of the tank interiors showed significant water beading on the internal surfaces and on the fuel quantity probes. A grey substance, later identified as fungus, was also observed in the tanks, although not on the probes. 

When tested, the probes did not conform to capacitance specifications. The probes were cleaned and dried overnight. When retested, the probes passed the capacitance test, and the fuel quantity gauges indicated the correct zero fuel state (Figure 4). 

Figure 4: Fuel quantity gauges after cleaning and drying the probes 

Figure 4.jpeg

The image shows the fuel gauges indicating zero usable fuel on board, following cleaning and drying of the fuel quantity probes. 

Source: ATSB 

During the process of removing fuel from the tanks, approximately 1 L per side of fuel was collected for analysis. The sample from the left tank was cloudy with a small amount of settled contaminant. About one fifth of the right tank sample was a distinct contaminant and the rest was clear. Specialist analysis subsequently identified water as the only contaminant. 

Due to the significant water contamination and fungal growth, several engine fuel system components and the main fuel boost pumps were removed for overhaul. The engineers observed minimal component damage, suggesting that water was not present for an extended period. 

As part of return-to-service maintenance, the FQIS was calibrated and found to be serviceable. During this process, the left and right fuel level low warning system was checked and found to switch the annunciators on/off at 160 lb per side, which was within the specified range. 

Additionally, both fuel transfer pump fail annunciators switched on/off when the fuel level reached about 580 lb per side (and the boost pumps were off), in accordance with specifications. 

Fuel system maintenance 

In January 2018, VH-LBY underwent a scheduled maintenance check. Fuel system related inclusions were a fuel drain and check for evidence of moisture, fuel gauge to fuel quantity comparison check, and various fuel system component inspections. No fuel system related issues were identified during this check. 

In February 2018, the left fuel computer was replaced due to intermittent dropouts. 

In terms of previous problems with fuel quantity readings, in March 2017 the right fuel gauge was reported as being unreliable. All right-side fuel probes were removed and reinstalled after testing within limits. In February 2017, the left-side fuel gauge was reported as over reading. The inner fuel probe was replaced after being tested as out of limits. 

Fuel contamination opportunities 

The operator and the ATSB reviewed operational records for VH-LBY since the comparison check on 6 January 2018 to identify the potential source of the water. 

On 13 February 2018, VH-LBY was involved in a towing incident, during which the right wingtip was damaged and required repair. Due to hangar availability and maintenance on other aircraft, VH-LBY was not always inside a hangar. Repairs were completed and the aircraft returned to service on 26 February 2018. 

During this period, Broome received heavy rainfall associated with tropical cyclone Kelvin. On 17 February 2018, 377 mm was recorded at Broome Airport. It is possible that the aircraft was exposed to some heavy rainfall, allowing the ingress of water through the damage in the right wingtip, but specific information about the extent to which this occurred was not available. There was no evidence that the fuel caps were incorrectly secured or that the fuel cap seals were degraded. 

The aircraft was refuelled on 22 February 2018 and on five other occasions before the day of the occurrence. All but one of these refuels were at Broome Airport and there were no reports of any fuel quality issues from the fuel supplier or other operators. One of the operator’s other C441 aircraft based in Broome was inspected after the 2 March occurrence and no contamination was found. 

Since the aircraft was returned to service on 26 February, and up to the day of the occurrence, the aircraft was operated on 4 days by three pilots. The pilot of the occurrence flight conducted flights on the 1 and 2 March, and the other pilots conducted flights on 27 February and 28 February. 

Overall, 12 flights totalling 13.0 flight hours were conducted prior to the occurrence flight. For each of the 4 days, the flight log was signed to certify that the daily inspection had been carried out. Noone reported that fuel drains conducted prior to each flight were anomalous, and there were no indications in the aircraft’s technical log or daily flight logs of any problems. 

Fuel quality management 

Regulatory requirements regarding fuel quality 

Civil Aviation Order (CAO) 20.2 (Air service operations — safety precautions before flight) (15 May 2006) directed that the operator and pilot in command must ensure that inspections and tests for the presence of water in the fuel system of the aircraft are made. CAO 20.2 provided the following as guidance: 

Note  It is important that checks for water contamination of fuel drainage samples be positive in nature and do not rely solely on sensory perceptions of colour and smell, both of which can be highly deceptive. The following methods are acceptable: 

  1. Place a small quantity of fuel into the container before taking samples from tank or filter drain points. The presence of water will then be revealed by a visible surface of demarcation between the two fluids in the container. 
  2. Check the drainage samples by chemical means such as water detecting paper or paste, where a change in colour of the detecting medium will give clear indication of the presence of water. 
  3. In the case of turbine fuel samples, tests should also include inspection for persistent cloudiness or other evidence of the presence of suspended water droplets, which will not necessarily be detected by methods mentioned in notes 1 and 2. Should any doubt exist of the suitability of the fuel, the checks specified in the aircraft Operators Maintenance Manual should be followed. It is advisable to allow turbine fuel a reasonable period of stagnation before drawing test samples from fuel drain points; this allows settling of suspended water which is a slower process in turbine fuel than in aviation gasoline. 

The CAO also stated: 

If, at any time, a significant quantity of water is found to be present in an aircraft fuel system, the operator and pilot in command must ensure that all traces of it are removed from the fuel system, including the fuel filters, before further flight. 

Note  In eliminating water from an aircraft fuel system, it is important that consideration be given to the possibility of water lying in portions of the tanks or fuel lines where, because of the design of the system or the existing attitude of the aircraft, it is not immediately accessible to a drain point. 

Operator requirements regarding fuel quality 

The operator’s Flight Operations Manual (FO1) required that a pilot conduct a fuel drain prior to the first flight of the day and following each refuel. The fuel sample was to be visually checked for water and other contaminants. If any water was evident, further drains were to be conducted until water was no longer evident. Once water was no longer visually evident (via draining), a sample was to be chemically tested for water using a water detection capsule. If the water test resulted in a positive detection of water, the aircraft was not to be flown and a defect report raised. Further details of the operator’s procedures are provided in Appendix B – Fuel System Testing. 

The operator did not provide guidance as to what amount of water was considered excessive or out of the ordinary, nor did it require any reporting or recording (in a maintenance log or similar) of any water drained from the tanks. It appeared that the assessment of excessive or out of the ordinary was reliant on an individual pilot’s experience and the knowledge gained from instructor pilots during training. 

The operator’s procedure did not include guidance to allow fuel to stagnate for a period to enable suspended water to settle, or that water may be in areas not immediately accessible via drain points. 

Fuel quality management actions and events 

In the case of the flights conducted on 2 March 2018, the pilot reported that a fuel drain was conducted during the pre-flight inspection at Broome prior to refuelling but no testing was conducted with the water detection capsules. The pilot did not report any concerns regarding their observations of the fuel samples. 

The pilot stated they did not conduct a fuel drain after the aircraft was refuelled (at Broome). The pilot explained during interview that, following the pre-flight inspection at the hangar, they drove to the passenger terminal to conduct check-in duties and ordered fuel once check-in was complete. The pilot was not present at the aircraft during refuelling and the aircraft was towed to the terminal by an engineer. The pilot could not offer any explanation for not conducting the additional water test. 

Fuel quantity management 

Regulatory requirements regarding fuel quantity 

At the time of the occurrence, Civil Aviation Regulation (CAR) 234 (Fuel requirements) stated that the pilot in command and the operator had to take reasonable steps to ensure that an aircraft carried sufficient fuel ‘to enable the proposed flight to be undertaken in safety’. No specific cross check requirements were stated in the regulation. 

The Civil Aviation Safety Authority issued Civil Aviation Advisory Publication (CAAP) 234-1(1) (Guidelines for aircraft fuel requirements) in November 2006. With regard to establishing fuel on board, the CAAP stated: 

Fuel gauges, particularly on smaller aircraft may occasionally be unreliable. In addition, except when the tank is full, it is extremely difficult to establish the quantity of fuel in a tank unless the aircraft is perfectly level and the manufacturer has provided an accurately graduated dipstick, sight gauge, drip gauge or tank tab. 

In terms of fuel quantity cross-checks, the CAAP stated: 

Unless assured that the aircraft tanks are completely full, or a totally reliable and accurately graduated dipstick, sight gauge, drip gauge or tank tab reading can be done, the pilot should endeavour to use the best available fuel quantity crosscheck prior to starting. The cross-check should consist of establishing the fuel on board by at least two different methods such as 

  1. Check of visual readings (tab, dip, drip, sight gauges) against fuel consumed indicator readings: or 
  2. Having regard to previous readings, a check of electrical gauge or visual readings against fuel consumed indicator readings: or 
  3. After refuelling, and having regard to previous readings, a check of electrical gauge or visual readings against the refuelling installation readings: or 
  4. Where a Series of flights is undertaken by the same pilot and refuelling is not carried out at intermediate stops, cross-checks may be made by checking the quantity gauge readings against computed fuel on board and/or fuel consumed indicator readings, provided the particular system is known to be reliable. 
Operator requirements regarding fuel quantity 

The operator’s fuel management requirements were documented in the Flight Operations Manual (FO1) and the Conquest Flight Operations Manual (FO6). The FO1 section on fuel quantity measurement included the following: 

On aircraft types with a MTOW less than 5700kgs, the PIC must use the acceptable cross check methods to ensure sufficient fuel is on board at take-off for the proposed flight. 

It must be understood that the degree of accuracy achieved when taking fuel quantity readings is highly dependent upon the scale provided on the gauge or measuring device and the slope of the tarmac surface. 

The following fuel quantity measurement methods are acceptable:- 

  • Indicated (electrical fuel quantity gauges) 
  • Stick Gauge (Magna or drip sticks) 
  • Calculated (by adding the refuel quantity to the residual fuel quantity) 

The following cross-check methods are acceptable:- 

  • Check of stick gauge readings against indicated readings, 
  • A check of stick gauge against calculated, 
  • A check of indicated against calculated, 

When a series of flights is undertaken by the same crew and refuelling is not carried out at intermediate stops, cross checks, other than the first flight of the day, may be made by checking the gauge readings against the calculated fuel on board. 

As the C441 did not have a stick gauge, only the cross-check of indicated versus calculated fuel quantity was applicable to that aircraft. 

FO1 defined ‘residual fuel quantity’ as the indicated quantity at engine shutdown and, as indicated above, it stated that calculated fuel was the residual fuel plus the amount added during refuelling. Given this definition, the last paragraph of the FO1 procedure provided very limited guidance to pilots. In effect it meant that, if no fuel was added between flights, the indicated fuel quantity at the end of the previous flight should be compared with the indicated fuel quantity prior to the current flight.  

By comparing the operator’s procedures with CAAP 234, the last paragraph of the FO1 procedure would have provided clearer guidance if it used the term ‘computed fuel’ rather than ‘calculated fuel’. FO1 defined ‘computed fuel’ as: 

For the purposes of acceptable fuel cross check methods, Computed fuel is defined as the anticipated destination fuel quantity that is derived during flight by use of fuel flow, ground speed and distance to the destination aerodrome. 

However, none of the cross-check methods stated in FO1 referred to computed fuel. 

In a section about fuel usage records, FO1 stated: 

Fuel on board gauge readings are to be checked prior to departure by adding the fuel quantity uplifted, as per the release note, to the fuel quantity remaining at the end of the previous flight which has been recorded on the Flight Log. 

In effect this statement was requiring pilots to conduct the cross-check of indicated fuel quantity (prior to a flight) with the calculated fuel quantity for those flights where fuel was added. 

FO6 provided further procedures and guidance for C441 pilots. It stated that ‘the acceptable method’ of cross-checking fuel quantity indications was as follows: 

  • Prior to flight, confirm the difference between the indicated fuel vs the residual figure noted in the flight log from the previous flight are within 5% 
  • After re-fuelling, compare the indicated fuel vs calculated and verify the difference is less than 5% of the higher amount. 
  • Should the indicated fuel vs residual figure noted or the indicated fuel vs calculated after refuelling difference exceed 5%, the aircraft shall not be flown and an appropriate entry into the Defect Endorsement Log shall be made. The crew should then seek Engineering assistance to rectify the defect. 
  • Prior to shutdown on the ground the L-R FUEL X-FER FAIL light will be used as a gross error check vs the indicated amount. The fuel boost pump switches will be position to OFF. If the L or R FUEL X-FER FAIL light illuminates, the associated fuel gauge should read below 580 Lbs or if the L or R FUEL X-FER does not illuminate the associated fuel gauge should read above 580 Lbs. 
  • When equipped with a Garmin 530 and the Shadin (fuel totaliser). Enter the total fuel at departure into the “FOB” on the Fuel Planning page in the Garmin 530. After shutdown open the Fuel 

Planning in the Garmin 530. “FOB” vs indicated amount will be used as a gross error check. 

If the crew believes a gross error check was not within an acceptable amount, the aircraft shall not be flown and an appropriate entry into the Defect Endorsement Log shall be made. The crew should then seek Engineering assistance to rectify the defect. 

The manual did not define an ‘acceptable amount’ for the two gross error checks (last two dot points).  

In addition, the C441 pre-flight checklist stated: 

Verify current fuel status and ensure balance [between both tanks] is within 300lbs. Enter indicated total fuel quantity on board into the Garmin 530 “Fuel Planning” page after re-fuelling. 

The C441 cruise checklist stated: 

Calculate and note destination fuel on current or average estimated ground speed and current fuel flow. Monitor throughout flight. Check balance [between both tanks] is within 300 pounds. 

None of the cross-check methods in FO6 referred to computed fuel. In addition, none of the methods stated in FO1 or FO6 referred to the use of estimated destination fuel or estimated fuel burn based on using flight-planned fuel burn figures. 

Senior pilots indicated that a pilot should also reference the flight-planned fuel figures as a crosscheck, and they described the operator’s flight planning software as accurate and reliable. One senior pilot stated that if the difference between the flight-planned fuel burn and the recorded fuel burn was more than 100 lb, they would be attempting to determine the reason for the discrepancy. Senior pilots reviewed the flight plan produced for the four sectors on the day of the occurrence and noted no errors or omissions in its preparation. 

Use of flight logs 

The operator’s pilots used a flight log form to record details of each of the flights conducted on a specific day. In terms of fuel, the form allowed a pilot to record the following in separate columns: 

  • total fuel quantity at departure 
  • fuel burn 
  • residual fuel 
  • added fuel (in L) 
  • added fuel (in lb). 

In the top row, the residual fuel from the previous flight log could be entered. 

FO1 stated: 

The figure placed in the ‘Total Fuel QTY at Dept’ column of the Flight Log Form shall be the fuel total as described in the aircraft type specific operations manual. 

FO6 did not provide any definition of what should be placed in the total fuel quantity column for a C441. 

A review of flight logs for VH-LBY from 1 February to 2 March 2018 indicated the following: 

  • The total fuel quantity was always the residual fuel from the previous flight log entry or, if the aircraft had been refuelled, the total fuel quantity was always the calculated fuel quantity. That is, the amount always matched the residual fuel plus the added fuel (in lb). If the indicated fuel quantity was being recorded, these figures would have at least occasionally varied slightly from the residual or calculated fuel quantity. 
  • The fuel burn was always the total fuel quantity at departure minus the residual fuel. 
  • No comments were included in the ‘Comments / Observations’ section on the flight logs to indicate any differences between the calculated fuel and indicated fuel prior to a flight, or the results of any other cross-checks. 
Sectors on 2 March 2018 

The pilot prepared a flight plan using the operator-provided flight planning software. Key flightplanned fuel figures for the 2 March are presented in Table 1. 

Table 1: Flight plan extract - planned fuel figures 2 March 2018 

Sector 

Estimated time interval (ETI) 

(minutes) 

Flight-planned fuel burn (lb) 

Estimated fuel at destination (lb) 

 

Start fuel 

 

2,350 

1 

47 

509 

1,841 

2 

30 

373 

1,467 

3 

28 

357 

1,110 

4 

43 

479 

632 

The pilot reported that, prior to the first sector on 2 March, they compared the indicated fuel quantity to the residual quantity recorded in the flight log from the last sector on the previous day (1,300 lb). The pilot stated that the fuel quantity gauges were as expected following this comparison and they carried forward the residual quantity to the new flight log. The actual indicated fuel quantity was not recorded (nor was it required to be). 

After the aircraft was refuelled, the pilot recorded the added fuel (1,050 lb) on the flight log. They also calculated the total fuel quantity at departure as 2,350 lb and recorded that figure on the flight log. The pilot recalled that, when checking the gauges after refuelling, the indicated fuel quantity was as expected. The actual indicated quantity was not recorded (nor was it required to be). 

At the end of each sector, the pilot recorded the indicated fuel quantities on the back of the flight plan. This included the raw indicated amounts in each tank, the total raw indicated quantity and the total indicated quantity after applying the appropriate calibration card corrections. These notes are reproduced below in Table 2. The pilot’s application of the calibration card corrections for the last two sectors contained minor errors. The recorded residual fuel at Halls Creek should have been 1,410 lb and the recorded residual fuel at Fitzroy Crossing should have been 1,310 lb. 

Table 2: Pilot’s fuel notes regarding indicated quantities on 2 March 

(Location)  

F (Fitzroy Crossing) H (Halls Creek) F (Fitzroy Crossing) 
(Left tank, right tank amounts) 

910 

740 

740 

550 

700 

490 

(Raw indicated quantity total) 

1650 

1290 

1190 

(Residual fuel, or indicated total after calibration corrections) 

1810 

1430* 

1300** 

       

The pilot’s notes contained the information not included in brackets. The information in brackets is provided to assist the reader with interpreting the pilot’s notes. *Figure should have been 1410. ** Figure should have been 1,310. 

At some point later, the pilot transferred the residual fuel figures to the flight log. The recorded flight log figures are reproduced in Table 3. The pilot also annotated the residual fuel amounts after each sector on the flight plan next to the estimated destination fuel quantities after each flight. 

Table 3: 2 March 2020 flight log extract – recorded fuel figures 

Sector 

Time (minutes) 

Total fuel quantity at 

departure 

(lb) 

 

Fuel 

 
Burn (lb) Residual (lb) Added litres Added lb 

Brought forward 

1,300 

600 

1,050 

1 

52 

2,350 

540 

1,810 

 

 

2 

34 

1,810 

380 

1,430 

 

 

3 

32 

1,430 

230* 

1,300 

 

 

4 

 

1,300 

 

 

 

 

* This figure should be 130, based on the indicated quantities recorded. 

 In terms of cross-checks of the fuel quantities: 

  • The fuel burn and residual quantity figures for the first two sectors were similar to the flightplanned figures (that is, 1,810 and 1,430 lb compared to 1,841 and 1,467 lb respectively). The pilot reported that the differences were minimal and not a concern. However, there was a large disparity between recorded and planned figures for the third sector (that is, 1,300 lb indicated compared to 1,110 lb estimated). 
  • The pilot stated that although the 1,300 lb indicated quantity after the third sector was higher than expected, it was greater than the planned minimum quantity required for the final sector (977 lb) so no further investigation was made. 
  • There was no evidence to suggest that any comparison of (recorded versus planned) fuel burn figures was made. The fuel burn for the third sector was recorded as 230 lb but should have been 130 lb based on the recorded residual fuel figures at the end of the second and third sectors, and 100 lb if the recorded residual fuel figures were correctly derived. This recorded fuel burn was substantially less than the flight-planned fuel burn (357 lb), and the actual flight time (32 minutes) was slightly longer than the planned flight time (28 minutes). 
  • There was no evidence to suggest that any computed fuel quantity calculations were made during the flight (that is, using fuel flow and time to run during flight or by using actual flight time with an average or block fuel consumption rate).   
  • Although the pilot was aware of the fuel totaliser capability in the Garmin 530, this was not used to do a gross error check of the fuel quantities as the pilot did not consider this to be mandatory. In other words, the pilot did not use the Garmin 530 to ascertain the fuel remaining after each flight and compare that figure with the recorded residual fuel based on fuel quantity indications. The pilot reported that they had seen other pilots use this gross-error check but 

that it was not used regularly.  A senior pilot based in Broome also advised that it was possible this cross-check was not routinely conducted by the other Broome-based pilots. 

  • On completion of each sector, the pilot did not conduct the gross error check that utilised the L/R FUEL X-FER FAIL annunciators to indicate if the tank quantity was above or below 580 lb. Although it was specified in the operator’s FO6 manual, the pilot stated being unaware of this gross error check method at the time of the occurrence. A senior pilot advised that it was routinely taught to pilots during line training. 
Sectors on 1 March 2018 (day prior to occurrence flight) 

The pilot of VH-LBY on the day of the occurrence operated the same aircraft on the previous day (1 March) for two sectors from Broome to Kununurra and return. Key flight-planned fuel figures are in Table 4 below. 

Table 4: Flight plan extract – planned fuel figures 1 March 2018 

Sector 

Estimated time interval 

(ETI) minutes 

Flight-planned fuel burn (lb) 

Estimated fuel at destination (lb) 

 

Start fuel  

 

2,700 

1 

95 

865 

1,834 

2 

91 

858 

976 

The recorded fuel figures on the flight log are shown in Table 5. 

Table 5: 1 March 2020 flight log extract – recorded fuel figures 

Sector 

Time (minutes) 

Total fuel quantity at departure (lb)  

Fuel 

 
Burn (lb) 

Residual 

(lb) 

Added litres 

Added lb 

Brought forward 

890 

1,031 

1,804 

1 

98 

2,694 

664 

2,030 

 

 

2 

90 

2,030 

730 

1,300 

 

 

 For both sectors, the recorded fuel burn derived from the total fuel quantity at departure and residual fuel quantity figures was significantly below the flight-planned estimates, even though the flight times were about the same. For the first sector the recorded fuel burn (664 lb) was 201 lb (23 per cent) less than planned, and for the second sector the recorded fuel burn (730 lb) was 122 lb (14 per cent) less than planned. 

Estimated fuel on board during recent sectors 

The operator estimated that the fuel burn during the fourth sector on 2 March (occurrence flight) was about 420 lb. Given that about little or no usable fuel was remaining when the aircraft landed on the highway, the aircraft therefore departed Fitzroy Crossing with about 420 lb on board. 

Using flight-planned fuel figures, the actual fuel on board for each of the sectors on 1 and 2 March was estimated and compared with the indicated fuel quantities, as shown in Table 6. The estimated fuel quantities would become less reliable as they progressed further back in time. Nevertheless, the comparisons showed that the fuel gauges were over reading throughout both days, and the amount of over reading substantially increased prior to the last sector and after the aircraft landed on the highway during the fourth sector. It also significantly increased after both of the sectors on 1 March. The amount of over reading did not increase on every flight. 

Table 6: Indicated and estimated fuel quantities during 1 and 2 March 2018 

Date 

Sector 

Indicated fuel quantity (lb) 

Estimated fuel quantity (lb) 

Estimated over reading 

1 March 

Start first sector 

  2,700* 

2,330 

370 

 End first sector 

2,030 

1,470 

560 

 

End second sector 

1,300 

610 

690 

2 March 

Start first sector 

 2,350* 

1,660 

690 

 End first sector 

1,810 

1,150 

660 

 

End second sector 

1,410 

780 

630 

 End third sector 

1,310 

420 

890 

 On highway  

   1,220** 

0 

1,070 

3 March 

After flown and usable fuel drained. 

     800** 

0 

800 

Indicated fuel quantities as recorded on the flight log except for minor corrections. Estimated fuel quantities based on using known quantity after last flight and using flight-planned fuel burns for previous flights. All figures rounded to the nearest 10 lb for readability. *The actual gauge readings prior to the first flight each day were not recorded. It is assumed that the calculated fuel quantity (recorded) was close to the indicated fuel quantity. **Calibration card corrections applied to gauge readings. 

Given the estimated fuel quantities, if the pilot had conducted gross error checks utilising the L/R 

FUEL X-FER FAIL annunciators, the annunciators would have illuminated at the end of sector 2 at Halls Creek and the end of sector 3 at Fitzroy Crossing on 2 March. They also would have illuminated at the end of the second sector on 1 March. 

Based on post-occurrence testing, the L/R FUEL LEVEL LOW annunciators would have illuminated when each tank quantity reduced to 160 lb. This amount equates to about 30 minutes of flying time, so the annunciators would have been activated during climb between 5 and 10 minutes after take-off from Fitzroy Crossing if the two tanks had the same quantity of fuel. If the tanks had different quantities, then one of the lights would have come on earlier. 

Given the likely quantity of fuel on board, it is possible that the fuel system annunciation observed during taxi was R FUEL LEVEL LOW rather than R X-FER PUMP FAIL. Given that the transfer pumps would have been on at that stage, the R X-FER PUMP FAIL should not have illuminated. 

As the pilot related, when the pilot observed the FUEL LEVEL LOW annunciators illuminated, the fuel quantity indications were sufficient for continuation of the flight to Broome. The pilot reported that they had developed a mistrust of the annunciators because of a faint glow during night flights and intermittent activation on various occasions. In contrast, the pilot had no experience of fuel quantity indication faults in the C441 and believed that the system was reliable. 

Once the fuel quantity in a tank reduced to below 80 lb, the FUEL X-FER FAIL annunciators would have illuminated. That amount provides for about 15 minutes flying time, so the annunciators would have been activated in the 5 minutes prior to top of descent. In that time period, the aircraft was between 55 and 25 NM to the south of Curtin. 

Review of other flight logs 

The ATSB reviewed the recorded fuel figures in the aircraft’s daily flight logs from 1 February 2018 to 2 March 2018. This included 10 flight logs from 1–13 February (prior to the wingtip damage event) and four flight logs from 27 February to 2 March (following the wingtip damage repair). A small number of maintenance and training/check flights were excluded, and the last sector (occurrence flight) on 2 March was excluded. 

Summary results are provided in Table 6. Based on the review, the following was noted: 

  • The average recorded fuel burn rate up to 13 February was 533 lb/hour and the average rate after 13 February was 465 lb/hour (Table 6). This difference of 68 lb/hour equated to a reduction in fuel burn rate of 13 per cent. If this rate was applied over the total flight time in the period after 13 February (13.0 hours), this equated to about 880 lb less fuel burned than expected. 
  • The recorded fuel burn rate on each sector varied significantly. As would be expected, the rate was generally shorter as the length of the flight increased. The average flight duration up to 13 February was 58 minutes and the average after 13 February was 68 minutes. 
  • To ensure the best comparison, a sample of flight logs was chosen from the period 1–13 February that matched the four flight logs from after 13 February (in terms of the destinations and/or the durations of the sectors). Where there were multiple logs that matched, the data was averaged. This resulted in a matched-sample average fuel burn rate during the period 1– 13 February of 509 lb/hour (Table 6). This difference of 44 lb/hour equated to a reduction in fuel burn rate of 9 per cent. If this rate was applied over the total flight time in the period after 13 February, this equated to about 570 lb less fuel burned than expected. 
  • For each of the four flight logs after 13 February, the matched sample had a higher fuel burn rate (ranging from 7 to 12 per cent). The rates were also lower than another matched sample from flights in October 2020. 

Table 7: Flight times and fuel burn rates for periods before and after 13 February 2018 

Sample 

Sectors 

Flight time 

(minutes) 

Flight time per sector 

(minutes/sector) 

Fuel burn 

rate 

(lb/hour) 

1–13 Feb: all normal flights 

32 

1,844 

57.6 

533 

1–13 Feb: matched sample 

11 

754 

68.5 

509 

27 Feb to 2 Mar: all normal flights 

11 

753 

68.5 

465 

With regards to specific flights: 

  • For flights of the same duration, there was a notable variance in recorded fuel burns (both before and after 13 February), which increased the difficulty of identifying patterns in recorded fuel burns for specific sectors. However, the most notable outlier was the third sector on 2 March, when the fuel burn was substantially lower than the average for similar flights both before and after 13 February. 
  • Estimated fuel burns for all the flights were derived from using the fuel planning figures from 1 and 2 March and the recorded flight times for each sector. Based on this approach, a small number of flights during 1–13 February had recorded fuel burns significantly lower than expected fuel burns, and there was no obvious pattern in these flights. For flights after 13 February, the last 3 of the 4 sectors on 27 February, the last of the 2 sectors on 28 February, and the first of the 2 sectors on 1 March had recorded fuel burns significantly lower than the expected fuel burns (ranging from 21 to 29 per cent lower). 
  • As already noted, the fuel burn was substantially higher that the flight-planned burn for the third sector on 2 March and a similar result would have occurred for the fourth sector had the flight been completed successfully. 
Operator fuel usage monitoring 

A requirement to monitor fuel usage existed within FO1, which stated: 

The FOM monitors the actual fuel burn data and makes adjustment to the Champagne Flight Planning Software where necessary. 

Although FO1 did not state how this was to be achieved, nor at what frequency, the chief pilot explained that they undertook this duty on a monthly basis. The chief pilot explained that this was a broad review of fuel usage but on a few occasions the review required follow up maintenance to confirm usage data. 

There were no fuel usage anomalies recorded or reported from the flights after 13 February until the occurrence flight. The exact date on which the last fuel usage monitoring was conducted for VH-LBY could not be determined. 

Other fuel management occurrences 

AO-2007-017

On 26 June 2007 at 0639 Western Standard Time, an Empresa Brasileira de Aeronáutica S.A. EMB-120ER aircraft, registered VH-XUE and operated by Skippers Aviation, departed Perth on a contracted passenger charter flight to Jundee Airstrip (Western Australia). On final approach to Jundee Airstrip, the aircraft drifted left of the runway centreline. As the flight crew initiated a goaround, the aircraft aggressively rolled and yawed left, causing the crew control difficulties. 

The left engine had sustained a total power loss following fuel starvation, because the left fuel tank was empty. The left fuel quantity gauge was indicating 300 kg at the time. A fuel probe in the left fuel tank had failed, which resulted in the left fuel quantity indicator over reading. The aircraft was not fitted with a fuel low level warning system (nor was it required to be). 

The investigation concluded that the practices used by the operator’s EMB-120 pilots for measuring and logging of fuel quantity were inconsistent. The aircraft was fitted with dripless measuring sticks and a fuel totaliser, but these devices were not being effectively used for crosschecking the fuel quantity gauge indications and aircraft were rarely refuelled to a known quantity. Fuel quantity cross-checks largely relied on checking the indicated quantity after refuelling with the calculated quantity (residual plus refuel quantity), with significant discrepancies in this amount not always being adequately explained. 

Following the occurrence, the operator revised its procedures, which included using a dripless measuring stick each day and improving its recording practices and the checking of flight logs. 

AO-2007-049

On 18 October 2007, the pilot of a Cessna C404 Titan aircraft, registered VH-TMP, was conducting a charter flight from Adelaide Airport to Parafield Airport, Beverley Airstrip, and return to Adelaide (South Australia). The pilot had commenced descent into Adelaide on the final sector of the flight when the right engine lost power. There were no apparent anomalies and the fuel quantity gauges were showing adequate fuel in each tank. After securing the right engine, the pilot continued to Adelaide Airport and landed without further incident. 

Aircraft maintenance engineers who inspected the aircraft reported that 3 L of fuel was drained from the right tank, and the associated fuel quantity gauge was indicating 150 lb (95 L). An engineer found that one of the electrical circuits in the right fuel quantity indication system had a high resistance. After wiring in the circuit was repaired, the fuel quantity gauge correctly indicated zero fuel in the right tank. Calibration of the fuel quantity indication system (FQIS) was carried out 

and, during that process, the left and right signal conditioners were found to be unreliable and were replaced or repaired. 

The investigation concluded that the operator’s pre-flight fuel quantity measurement procedures were predicated solely on FQIS readings, with no provision for regular independent checks of fuel quantity. Problems with the accuracy of recording details on the flight logs was also identified. The operator amended its fuel documentation and fuel planning procedures to include a secondary means of verification of fuel on board to cross-check the electric fuel indication system. 

Safety issues identified 

During the AO-2007-017 investigation, the ATSB issued safety advisory notice (SAN) AO-2007017-SAN-013, which stated: 

The ATSB suggests that all turboprop operators take note of the following safety issue and review their processes accordingly: 

The processes used by some turboprop operators for checking the fuel quantity on board prior to flight have not used two methods of sufficient independence. In particular, the practice of using a comparison of a gauge indication after refuelling with the gauge indication prior to refuelling plus the fuel added is not adequate to detect gradually developing errors in gauge indications. 

Investigations AO-2007-017 and AO-2007-049 also identified safety issues concerning regulatory guidance for fuel quantity measurement as follows: 

  • Regulatory guidance regarding the measurement of fuel quantity before flight lacked clarity and appropriate emphasis and did not ensure that the fuel quantity measurement procedures used by operators included two totally independent methods. (AO-2007-017) 
  • Guidance promulgated by the Civil Aviation Safety Authority (CASA) in Civil Aviation Advisory Publication 234-1 regarding aircraft fuel requirements allowed for a fuel quantity cross check to be conducted after refuelling and without reference to an independent source of onboard fuel quantity information. (AO-2007-049) 

In 2016, the ATSB started an investigation into the fuel exhaustion and subsequent collision with terrain of a McDonnell Douglas Corporation 369 helicopter. The final report stated: 

A search of the ATSB database for the period from 2003 to 2017 found 76 reports of ‘fuel exhaustion’, which included four accidents with fatalities, three accidents with serious injuries and two accidents with minor injuries, with some accident reports including more than one injury classification. The operations represented in the occurrences included sport aviation, private, aerial work, training, charter and air transport–low capacity. From the 76 occurrences, 26 were for commercial operations, and all reports were for aircraft not greater than 5,700 kg MTOW… 

The presence of commercial operators indicated that the applicable fuel regulations may be less than adequate, and shows that commercial operators may not implement effective fuel policies and training to prevent fuel exhaustion events. 

The final report also included the following safety issue: 

The current legislation does not require commercial operators of aircraft not greater than 5,700 kg maximum take-off weight to provide instructions and procedures for crosschecking the quantity of fuel on board before and/or during flight. This increases the risk that operators in this category will not implement effective fuel policies and training to prevent fuel exhaustion events… 

It was noted that CASA had commenced a review of regulatory requirements and guidance in 2016 in response to the safety issues: 

The Civil Aviation Safety Authority (CASA) has started project CD 1508OS, which was published on their website 20 January 2016. The project contains the proposed changes to Civil Aviation 

Regulation (CAR) 234, the issuance of a CAR 234 Legislative Instrument, and revised Civil Aviation 

Advisory Publication (CAAP) 234-1(2): Guidelines for aircraft fuel requirements, CAAP 215-1(2): 

Guide to the preparation of Operations Manuals, Volume 2, appendix B9: Fuel management, and the Air Operator’s Certificate (AOC) handbook Volume 2 – Flying Operations – Section 6: Fuel policy and related requirements. Once made into law, the amendments to the existing CAR 234 will commence on 8 November 2018. 

A key outcome of the amendment is providing clarity about the regulatory requirements that apply to fuel by having those requirements set out in a legislative instrument. This overcomes difficulties with the previous arrangement, where requirements were set out in guidance material ‘called up’ by regulation, in that the requirements were often not readily recognised as having the force of law. CASA 29/18 – Civil Aviation (Fuel Requirements) Instrument 2018 sets out the legislative requirements that: 

  • specify the matters that must be referenced by the operator and the pilot in command in determining the quantity of usable fuel required for a flight 
  • specify the quantities required to commence a flight and also to continue a flight 
  • require that inflight fuel management be conducted, and 
  • specify the contingencies to which additional fuel calculation must be applied. 

To assist industry and CASA understanding of the changes to the fuel requirements in legislation, the amendment to guidance material CAAP 234-1(2) will be published. It will contain enhanced guidance on the generally applicable fuel related areas of the legislative instrument. CAAP 234-1(2) will differentiate between requirements and guidance.

The updated regulatory material was published November 2018 (8 months after this occurrence). 

Emergency procedures 

The emergency landing area was a single carriageway road with two-way traffic. The road was only just sufficiently wide for the aircraft to land on (Figure 5). For comparison, the runway at Broome Airport is 45 m wide and other aerodromes the operator used C441 aircraft normally had runways of 30–45 m wide (and occasionally a narrow runway of 23 m wide). The wingspan of a C441 is about 15 m. 

Figure 5: The emergency landing area

Figure 5.jpeg

 

Source: Broome Advertiser 

The operator’s aircrew emergency procedures manual highlighted the risks to an individual during an emergency landing and included the following detail on the brace for impact position: 

Passengers must be encouraged to correctly fasten their seat belts and practice the brace for impact position in a prepared emergency landing. 

If a seat belt is not worn in an impact, the body continues moving forward at the same speed as the aircraft was moving before the impact. 

Even with a seat belt fastened, the deceleration causes the head and limbs to fly forward until they make contact with something stopping their movement, (that is, the seat or bulkhead in front). In most cases, this leads to traumatic injury preventing movement away from the aircraft and/or death. The brace for impact position is a compact position allowing the body to move very little during the impact and post impact deceleration. This position should increase the chance for survival... 

The brace for impact position must be held until the aircraft completely stops. 

In the case of the 2 March 2018 forced landing on the highway, the pilot did not instruct the passengers to adopt the brace-for-impact position.

__________

  1. For demonstrative purposes, the ATSB utilised a figure of 600 lb per hour as a block fuel consumption rate. This was based on the average planned fuel consumptions from the occurrence flight plan, taking into account climb and cruise segments.
  2. The fuel burn during start and taxi can be similar regardless of flight duration, and there is a higher fuel burn rate during climb than during cruise. Actual fuel burns prior to and after each flight were not known and not able to be subtracted.
  3. ATSB Investigation AO-2007-017, Fuel starvation Jundee Airstrip, WA – 26 June 2007 VH-XUE Empresa Brasileira de Aeronáutica S.A., EMB-120ER
  4. ATSB Investigation AO-2007-049, Engine power loss (fuel tank exhaustion) 102 km north Adelaide, SA 18 October 2007 VH-TMP Cessna Aircraft Company C404
  5. ATSB investigation AO-2016-078, Fuel exhaustion and collision with terrain involving McDonnell Douglas Corporation 369, VH-PLY, 36 km NW Hawker, South Australia, on 17 July 2016

Safety analysis

Introduction

The Cessna 441 (C441) aircraft departed on a scheduled passenger flight from Fitzroy Crossing to Broome without sufficient fuel to reach the destination. This was not identified by the pilot and subsequently the fuel tanks were exhausted and both engines lost power.

Although the weather was suitable for visual flight rules and the aircraft was within range of a highway, the pilot was faced with a dual engine failure, a situation that is not usually addressed in multi-engine training and checking. The pilot successfully landed the aircraft on the nearby highway and there were no passenger injuries or aircraft damage.

A fuel exhaustion event on scheduled passenger transport flight is a serious incident. Accordingly, this analysis will discuss the accuracy of the fuel quantity indication system (FQIS), the procedures and practices used to check the fuel quality, the procedures and practices used to check the fuel quantity, and the effectiveness of the fuel low level warning system.

Fuel quantity indication system error

Post-occurrence inspection of the fuel system identified water contamination of the fuel tanks. The presence of water on the probes had a significant effect on probe functionality, resulting in over reading of the fuel quantity in the tanks. The FQIS functioned appropriately after the water was removed.

More specifically, following the engine power losses and forced landing, the fuel quantity gauges indicated 1,120 lb. On return to Broome, having drained all usable fuel on board, the gauges indicated 740 lb. In addition, prior to the occurrence flight, the gauges indicated about 1,310 lb (after applying fuel calibration card corrections) when there was only about 420 lb of usable fuel on board.

The source of the water contamination could not be definitively determined. It is likely to have occurred at some point during the period 13–26 February, when wingtip damage was being repaired. A review of the aircraft’s flight logs identified that recorded fuel burns after this period were consistently lower than fuel burns prior to this period.

Based on the available information, the water was unlikely to have been introducing during refuelling. It is possible that it was associated with the aircraft sitting in a humid environment for a period of time and, because the tanks were close to empty (about 590 lb total fuel on board), condensation forming in the tank.

It is reasonable to presume that the influence of the water on the fuel quantity gauge indications increased over time. If there had been a substantial step change in the gauge indications (more than the fuel added), then it is likely that this would have been detected when the aircraft undertook a test flight following the repair. However, there was no indication in the flight logs of a substantial discrepancy.

Nevertheless, it is also unlikely that the amount of over reading increased in a linear manner over time. The limited information available suggested that there may have been larger increases in over reading when the fuel levels were lower, which would be consistent with less water on the probes when the fuel tanks were at higher levels. 

Fuel quality management

Considering the level of water contamination found after the occurrence, and the length of time the water had been in the aircraft, it is unclear why this problem had not been detected through fuel quality testing. Fuel drains were required to be conducted by the operator’s pilots prior to the first sector each day and following each refuel. This should have resulted in at least nine inspections prior to the occurrence flight. However, none of these checks appeared to identify an unusual amount of water.

The pilot reported conducting a fuel drain during prior to the first sector on the day of the occurrence but did not report observing water in the fuel and did not test the sample using the water detection capsule. A final opportunity to detect contamination was available following aircraft refuelling. However, the pilot did not conduct a fuel drain and chemical test following the refuel, which reduced the opportunity to detect contamination.

At the time of the occurrence, fuel in the hopper area of each fuel tank of VH-LBY could not be sampled because the standard fuel drains were located elsewhere (including the low points of the fuel system). Although fuel was able to circulate throughout the tank, the hopper was designed to limit the outflow of fuel. As such, it is possible that some fuel samples were not representative of the fuel in the hopper. Nonetheless, not all of the water contamination was found to be in the hopper tanks.

Fuel quantity management

Overview

The operator had several processes in place to check the functionality of the FQIS on its C441 fleet, including several methods that pilots could use to cross-check the fuel quantity gauge indications with other sources.

One reliable and independent method of cross-checking fuel quantity gauge indications is to use some form of direct reading of the fuel quantity; however, no direct reading mechanisms were available for the C441.

Another reliable and independent method of cross-checking fuel quantity gauge indications is to fill the tanks to capacity or to empty the tanks of usable fuel and add a known quantity of fuel. Due to the nature of the operator’s flights, its C441 aircraft were rarely refuelled to capacity during normal operations. However, the operator required each of its C441’s fuel tanks to be refuelled to a known quantity (500 lb per side) every 150 flight hours. Unfortunately, the last check on VH-LBY was done 66 hours prior to the occurrence (and 53 hours prior to the likely start of the FQIS error).

The operator’s fuel management procedures were also supported by regular maintenance inspections to confirm FQIS accuracy. However, in this instance the error had developed in between maintenance inspections.

Ultimately, detecting the FQIS error in this case relied on the operator’s procedures for cross-checking fuel quantity gauge indications, and its pilots use of those procedures.

Check of indicated versus calculated fuel quantities prior to a flight

The primary cross-check method for the C441 fleet specified in the operator’s manuals was a check of the indicated fuel quantity against the calculated fuel quantity (or residual fuel, indicated at the end of the previous flight, plus the refuel amount). This is a relatively simple and commonly used cross-check method in the aviation industry, which can only be used when fuel is added.

However, this cross-check method is not an independent check of the FQIS. It is simply checking the difference in the fuel quantity gauges after fuel has been added. In other words, the check is self-referencing the same source of information. Although it may detect some types of FQIS error, it is generally not adequate to detect gradually developing errors in gauge indications.

The extent to which the method could have been effective on this occasion was difficult to determine because of limitations in the way the C441 pilots were recording information on the flight logs. The operator required pilots to confirm that the difference between the residual quantity recorded on previous flight log and the indicated quantity prior to flight was within 5 per cent of higher amount. After refuelling, pilots were to confirm the difference between the indicated quantity and calculated quantity (sum of residual/indicated plus added fuel) was within 5 per cent. These comparison checks were not recorded, nor required to be recorded. Consequently, pilots were not able to identify any differences or trends in indicated readings over time, or in the indicated versus calculated readings over time.

On the day of the occurrence, the pilot refuelled the aircraft prior to the first sector. The pilot reported that the fuel quantity gauge indications were verified as required before and after refuelling. The residual fuel figure from the previous day was within comparison check limits and therefore carried forward on the flight log, facilitating the continuity of the FQIS error.

Check of indicated versus computed or planned fuel quantities

The operator’s Flight Operations Manual required pilots to compare the indicated fuel with the computed fuel on board (although the manual mistakenly used the word ‘calculated’ instead of ‘computed’). This meant comparing the indicated fuel quantity at the end of a flight with a value based on the indicated quantity at the beginning of the flight and the computed fuel burn during the flight.

In addition, during cruise, C441 pilots were required to compute the destination fuel using current or average groundspeed and current fuel flow, but there was no requirement for this to be recorded. The pilot of the occurrence flight did not appear to use this method, and the extent to which other pilots were using it was unclear.

The operator’s pilots did report that they regularly compared flight-planned fuel burns with recorded fuel burns (based on fuel quantity gauge indications) after each sector. The pilot of the occurrence flight reported that, following each of the first two sectors that day, there was no notable discrepancy between the recorded fuel burns and the flight-planned fuel burns. However, the recorded fuel burn for the third sector based on fuel quantity gauge indications was substantially lower than the expected fuel burn based on the flight plan. Even so, in the absence of relevant information from other sources, the pilot rationalised that this discrepancy was not significant, given that the indicated fuel quantity was significantly more than the minimum required for the flight.

The ATSB noted that there appeared to be significant variability in recorded fuel burns and the associated fuel burn rates, both before and after the FQIS error started. The exact reasons for the size of this variability are not clear, but its effect would be to make it difficult for a pilot to detect when a discrepancy was meaningful. The fuel quantity indications on the aircraft also needed significant corrections from the fuel calibration card, which complicated any calculations. Nevertheless, in the case of the sector prior to the occurrence flight, the discrepancy was substantial and should have prompted further inquiries by the pilot about the fuel quantity indications.

At that stage, the pilot had limited other options available to verify the amount of fuel on board. However, they could have discussed options with a senior pilot or elected to add more fuel.

Check of indicated quantity versus fuel totaliser reading at end of a flight

The operator’s procedures required that C441 pilots enter the indicated fuel on board into the Garmin GNS 530 system at the beginning of each sector, and then compare the fuel quantity gauge indications with the fuel totaliser indication (of fuel on board) at the end of a sector. In effect, this cross-check method, using an independent source, provided a means of detecting whether there was a change in the reliability of the fuel quantity gauges during a flight (or a longer period).

The operator had not specified a threshold level or ‘acceptable amount’ for this check. Accordingly, if a pilot followed the procedure, it was unclear what level of difference between the gauge indications and the totaliser indications warranted action.

More problematically, the procedure was not always being used. The pilot of the occurrence flight reported that they did not think it was mandatory, based on observing other pilots, and did not use it themselves. A senior pilot also agreed it may not have been used regularly by other pilots.

If the pilot of the occurrence flight had used the procedure, then it would have identified a significant discrepancy after the third sector on the day of the occurrence. It is also likely to have detected discrepancies on the two sectors they conducted the previous day. In addition, if the method was being regularly used, it is likely that it would have identified discrepancies on some sectors conducted by the operator’s pilots on previous days.

Check using the X-FER PUMP FAIL annunciators

The operator’s procedures also required that C441 pilots, prior to engine shutdown after a flight, switch the fuel boost pumps off to check whether either of the X-FER PUMP FAIL annunciators would illuminate. If they did, then this meant there was less than 580 lb in that tank. This check was coarse in nature, and would only detect a problem in some cases, depending on the indicated fuel quantity.

Although the procedure was clearly stated in the operator’s operations manual, the pilot of the occurrence flight reported not being aware of this requirement and so was not conducting these checks. Post-occurrence fuel quantity calculations suggests that this gross error check would likely have identified the indication error on arrival at Fitzroy Crossing after third sector and possibly at Halls Creek after the second sector on the day of the occurrence. It is likely it would also have detected a problem after the last sector the previous day.

Summary

In summary, the operator had specified multiple methods for its C441 pilots to use to cross-check fuel quantity indications. However, there were limitations with the design, definition and/or application of these methods. In particular, the primary method used (indicated versus calculated) was self-referencing in nature, and not able to detect gradual changes in the reliability of fuel quantity gauge indications. In addition, the operator’s pilots did not record sufficient information on flight logs to enable trends or patterns in fuel quantity gauge indications to be effectively identified, and the pilots did not routinely cross-check fuel gauge indications with the information from the independent fuel totaliser.

In the case of the occurrence flight, the pilot had not been applying two of the operator’s cross-check methods (that is, the use of the fuel totaliser and the use of the X-FER PUMP FAIL annunciators). Using either or both of these methods would have identified discrepancies, which should have resulted in the pilot concluding that the FQIS was not functioning correctly.

Low fuel level warning

Illumination of the L/R FUEL LEVEL LOW annunciators on the C441 indicated that 150 to 250 lb remained in the associated tank. This would be approximately 30 to 50 minutes flight time for each engine. The annunciators on VH-LBY were found to be serviceable during post-occurrence inspections and were illuminating at approximately 160 lb remaining in each tank, or roughly 30 minutes flight time.

The fuel level low annunciators are independent of the FQIS and of each other (left and right). Landing as soon as possible would be the most conservative response to a fuel level low annunciation.

Although the pilot reported that the annunciators illuminated in the 10 to 15 minutes prior to the first engine failure, analysis suggests it likely that the annunciators had been illuminated well prior, sometime during the climb. In that timeframe, the aircraft was within range of suitable airports to which a diversion could have been effected.

The pilot considered the FQIS to be reliable but based on experience did not trust the annunciators. As such, the pilot believed there was sufficient fuel on board and continued to Broome and disregarded the fuel level low annunciations. Overall, the pilot’s response to the various fuel system annunciations was consistent with confirmation bias, or a tendency for a person to seek information that confirms or supports their hypotheses or beliefs, and discounting or not seeking information that contradicts those hypotheses or beliefs (Wickens and others 2013). This was likely influenced by not completing all the required fuel quantity cross-checks during previous sectors, resulting in the pilot having little information available (other than the annunciators) to doubt the fuel quantity indications.

Briefing prior to an emergency landing

During the emergency landing, the pilot did not instruct the passengers to adopt the brace-for-impact position.

In a recent cabin safety bulletin, the Civil Aviation Safety Authority (2020) advised:

Passenger survival rates are improved when they are informed about the correct use of equipment and the actions they should take in the event of an emergency, such as how to assume an appropriate brace for impact position.

The brace position has been determined to be the most effective protective position for passengers and crew to adopt to mitigate the potential for injury during impact.

The “brace for impact” position is an action where a person pre-positions his/her body against whatever he/she is most likely to be thrown against, and which may significantly reduce injuries sustained.

The brace position serves two purposes:

1. it reduces flailing by having the forward-facing occupant flex, bend, or lean forward over his/her legs in some manner

2. it reduces secondary-impact injuries by pre-positioning the body, predominantly the head, against the surface that it would otherwise strike during that secondary impact, thus reducing the momentum of the head and other parts of the body.

In summary, because the passengers did not adopt the brace-for-impact position, this increased the risk of injury during the emergency landing. It is likely that the pilot was experiencing a high workload during the approach and emergency landing, but pilots in such situations should ensure, when time is available, that passengers are appropriately briefed for any emergency landing and instructed to brace for impact.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the fuel exhaustion and forced landing involving Cessna 441, VH-LBY, 39 km east‑south‑east of Broome Airport, Western Australia on 2 March 2018.

Contributing factors

  • Due to water contamination in the fuel tanks, the aircraft’s fuel quantity gauges were significantly over reading on the day of the occurrence and on previous days. This ultimately resulted in the aircraft departing for a flight without sufficient fuel to reach its destination.
  • Although the operator had specified multiple methods of cross-checking fuel quantity gauge indications for its C441 fleet, there were limitations in the design, definition and/or application of these methods. These included:
    • The primary method used (indicated versus calculated fuel) was self-referencing in nature, and not able to detect gradual changes in the reliability of fuel quantity gauge indications.
    • Pilots did not record (and were not required to record) sufficient information on flight logs to enable trends or patterns in fuel quantity gauge indications to be effectively identified.
    • Pilots did not routinely cross-check information from fuel quantity gauge indications with information from the independent fuel totaliser. (Safety issue)
  • Although the pilot routinely compared indicated versus calculated fuel quantities, and indicated versus flight-planned fuel quantities, the pilot did not routinely conduct two other methods stated in the operator’s procedures for cross-checking fuel quantity gauge indications.
  • The recorded fuel burn for the previous (third) sector based on fuel quantity gauge indications was substantially lower than the expected fuel burn based on the flight plan. However, in the absence of relevant information from other sources, the pilot did not regard this as being an indication of a fuel quantity indicating system problem.
  • The pilot disregarded the L/R FUEL LEVEL LOW annunciators, which likely illuminated approximately 30 minutes before the fuel was exhausted in each tank, and when the aircraft was still within range of suitable alternative airports. The pilot relied on the (erroneous) fuel quantity indications and continued to Broome until the engines lost power, at which point a forced landing on a highway was the only remaining option.

Other factors that increased risk

  • Although the pilot stated that they conducted a fuel quality check prior to the first flight of the day, they did not conduct another check after refuelling (as required by the operator’s procedures), increasing the risk of undetected fuel contamination.
  • The pilot did not instruct the passengers to brace for impact prior to the emergency landing.

Other findings

  • Following the complete engine power loss, the pilot assessed the aircraft would not reach Broome Airport, identified a suitable landing area, and conducted a forced landing without injury to the passengers or damage to the aircraft.

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

The initial public version of these safety issues and actions are provided separately on the ATSB website, to facilitate monitoring by interested parties. Where relevant, the safety issues and actions will be updated on the ATSB website as further information about safety action comes to hand.

Fuel quantity assessment methods

Safety issue number: AO-2018-019-SI-01

Safety issue description: Although the operator had specified multiple methods of cross-checking fuel quantity gauge indications for its C441 fleet, there were limitations in the design, definition and/or application of these methods. These included:

  • The primary method used (indicated versus calculated fuel) was self-referencing in nature, and not able to detect gradual changes in the reliability of fuel quantity gauge indications.
  • Pilots did not record (and were not required to record) sufficient information on flight logs to enable trends or patterns in fuel quantity gauge indications to be effectively identified.
  • Pilots did not routinely cross-check information from fuel quantity gauge indications with information from the independent fuel totaliser.

Safety action not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Safety action by Skippers Aviation

In April 2021, during the directly involved party process, Skippers Aviation advised that:

  • There was a strong focus on Broome as an operating base, with the chief pilot now visiting multiple times per year, and regular audits being carried out.
  • Communication between Broome and Perth had been enhanced.
  • Emergency procedure training now emphasised brace commands.
Safety action by the Civil Aviation Safety Authority

In the 18 months following the occurrence, the Civil Aviation Safety Authority (CASA) conducted additional surveillance of Skippers Aviation through a series of visits, interviews and observation flights. Surveillance encompassed Airworthiness, Flight Operations, Cabin Safety, Ground Operations and Safety Systems. CASA noted that the operator had demonstrated improvements in the operations of its Broome base and recommended returning to a normal oversight level. No findings were issued on completion of the surveillance.

Sources and submissions

The sources of information during the investigation included:

  • the pilot of the occurrence flight
  • the operator (Skippers Aviation Pty Ltd)
  • the Civil Aviation Safety Authority
  • Airservices Australia.

References

Civil Aviation Safety Authority 2020, Cabin Safety Bulletin No.6 – Brace positions, available from www.casa.gov.au.

Wickens CD, Hollands JG, Banbury S & Parasuraman R 2013, Engineering psychology and human performance, 4th edition, Pearson Boston, MA.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • the pilot of the occurrence flight
  • the operator (Skippers Aviation Pty Ltd)
  • the Civil Aviation Safety Authority
  • Textron Aviation (Cessna).

Submissions were received from:

  • the pilot of the occurrence flight
  • the operator (Skippers Aviation Pty Ltd)
  • the Civil Aviation Safety Authority
  • Textron Aviation (Cessna).

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Appendices

Appendix A – Fuel system schematics

Fuel system schematics

Source: C441 Pilot’s Operating Handbook

 

Fuel system schematics

Source: C441 Pilot’s Operating Handbook

 

Appendix B – Fuel system testing procedures

 

Fuel system testing procedures

Source: Skippers Aviation Flight Operations Manual

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2021

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2018-019
Occurrence date 02/03/2018
Location 39 km east-south-east of Broome Aerodrome
State Western Australia
Report release date 27/05/2021
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Fuel exhaustion
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model 441
Registration VH-LBY
Serial number 4410023
Aircraft operator Skippers Aviation
Sector Turboprop
Operation type Air Transport Low Capacity
Departure point Fitzroy Crossing, Western Australia
Destination Broome, Western Australia
Damage Nil

Technical assistance to Recreational Aviation Australia in the examination of a rudder control cable from an Aeroprakt A22LS Foxbat aircraft

Final Report

Report release date: 04/10/2018

On 1 November 2017, an Aeroprakt A22LS Foxbat was involved in a landing accident that resulted in the aircraft coming to rest inverted adjacent to the airstrip. Examination of the aircraft following the occurrence, identified that the right rudder control cable had failed in flight. Significant damage to the left rudder control cable was also identified at a similar location to where the right cable had failed.

Recreational Aviation Australia requested that the ATSB perform a detailed technical examination of the aircraft’s rudder control cables and associated rigging. The scope of this examination was limited to the identification of factors that contributed to the damage and subsequent failure of the cable. To facilitate this work, the ATSB initiated an external investigation under the Transport Safety Investigation Act 2003.

The ATSB analysis found that the right cable failed as a result of fatigue failure associated with significant wear of the individual wires (see Figure 1). Although the left hand cable did not fail, it was found to be unserviceable based on the standards set in the aircraft maintenance manual, due to fatigue fracturing of the wire strands. Both cables were found to be within material specifications.

Figure 1: Wear and associated fatigue fracture of wires on the right rudder control cable

Figure 1: Wear and associated fatigue fracture of wires on the right rudder control cable. Source: ATSB


Source: ATSB

Any further enquiries in relation to the accident investigation should be directed to Recreational Aviation Australia.

___________
The information contained in this update is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

Occurrence summary

Investigation number AE-2018-018
Occurrence date 01/11/2017
Location Mt Jack Station
State New South Wales
Report release date 04/10/2018
Report status Final
Investigation level Defined
Investigation type External Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Control - Other
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Aeroprakt Ltd
Model A22LS Foxbat
Registration 24-7930
Serial number 088
Sector Sport and recreational
Operation type Private
Departure point Mt Jack Station, New South Wales
Destination Mt Jack Station, New South Wales
Damage Substantial

Technical Assistance to The Gliding Federation of Australia - Collision with terrain involving Jonker Sailplanes JS1C 18/21, VH-IBS, near Boggabilla, New South Wales, on 9 October 2017

Final Report

On 9 October 2017, a Jonker Sailplanes CC JSIC 18/21 sailplane, registered VH-IBS, collided with terrain near Boggabilla, NSW. The pilot sustained fatal injuries.

The Gliding Federation of Australia (GFA) requested assistance from the ATSB to download information from an avionics unit on-board the sailplane, on the accident flight.

The GFA sent the avionics unit (the unit) to the ATSB facilities in Canberra. The unit was a LXNAV LX900. The device was badly damaged, with damage to the internal electronic circuit board. A micro-SD card, which was attached to the main circuit board, was also cracked (Figure 1). This micro-SD card contained the flight data.

Figure 1: Micro-SD card recovered from the avionics unit with the crack highlighted inside the red box

Figure 1: Micro-SD card recovered from the avionics unit with the crack highlighted inside the red box

Source: ATSB

The micro-SD card was x-rayed, which confirmed damage to the internal electrical connections (Figure 2).

Figure 2: X-ray of micro-SD card with the crack highlighted inside the red box

 

 

 

Figure 2: X-ray of micro-SD card with the crack highlighted inside the red box

Source: ATSB

 

The ATSB was unable to recover any data from the micro-SD card. A report documenting the ATSB’s work was provided to the GFA.

Any enquiries in relation to the investigation should be directed to the GFA.

 

______________
The information contained in this web update is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this web update. As such, no analysis or findings are included in this update.

 

Occurrence summary

Investigation number AE-2017-107
Occurrence date 09/10/2017
Location near Boggabilla
State New South Wales
Report release date 28/02/2018
Report status Final
Investigation level Defined
Investigation type External Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Highest injury level Fatal

Aircraft details

Model Jonker Sailplanes, JS1C 18/21
Registration VH-IBS
Sector Sport and recreational
Operation type Sports Aviation
Damage Substantial

Collision between Pacific National train 9221 and Aurizon train 9T66, Oonoomurra, Queensland, on 27 February 2018

Final report

Report release date: 21/11/2018

Safety summary

What happened

On the night of 27 February 2018, the Queensland Rail Network Control Officer (NCO) at Townsville planned to cross two freight trains at Oonoomurra on the Mount Isa line, Queensland. Train 9221 had departed Cloncurry at about 2310, travelling in an easterly direction toward its limit of authority at Oonoomurra. Shortly after train 9221 stopped at Oonoomurra, its rail traffic crew advised the NCO that the rear of the train was clear of the track section between Cloncurry and Oonoomurra.

The NCO then issued an authority to the crew of train 9T66, travelling in a westerly direction, to continue through Oonoomurra toward Cloncurry, as train 9221 had reported clear of that track section. The crew of train 9T66 entered Oonoomurra travelling at about 25 km/h. As the train rounded a sweeping left curve at the western end, the crew sighted three empty container wagons at the rear of train 9221, with the last wagon fouling the track. The driver made an emergency brake application but was unable to avoid a collision. The collision caused minor damage to the lead locomotive of train 9T66 and the last wagon of train 9221, derailing its trailing bogie. There was no injury to the rail traffic crew of either train.

What the ATSB found

The on-board information system in the lead locomotive of train 9221 was operating in a degraded state, displaying erroneous speed and distance information to the driver. The driver, unaware of the error, relied on the displayed indication of distance travelled to determine the last wagon of train 9221 was clear of the track section to its rear. The rail traffic crew of train 9221 did not make sure the train was in clear before releasing the track section to the NCO.

Towards the western end of the crossing, the track alignment resulted in the headlight of the lead locomotive on the opposing train projecting light predominately to the right of the track, away from train 9221. The rail traffic crew were observing the top sections of the adjacent bulk wagons but it was not until the track alignment transitioned to straight that the crew then sighted the last of three empty container wagons at the rear of train 9221. By this time, with the train travelling at 25 km/h and despite making an emergency brake application, a collision was unavoidable.

What's been done as a result

Pacific National (PN) verified the accuracy of the Functionally Integrated Railroad Electronics (FIRE) system on each 83-class locomotive in its fleet and the process for advising rail traffic crew to use alternative methods to validate accuracy of displayed information, should a ground radar fault occur. Additionally PN introduced procedures for the maintainer to identify restrictions to a locomotives operation as lead, and reinforced the implementation of procedures associated with the active identification of a stopping location with PN staff.

In the longer term, PN undertook to investigate procedural or locomotive-based system changes to alert rail traffic crew of an inconsistent speed fault, based on deviations greater than 7 per cent and to advise rail traffic crews of this faulty meter counter occurrence and the follow-up action taken. Additionally PN undertook to review the Townsville Bulk and the Coal Depot’s risk registers to ensure the identification of hazards associated with faulty FIRE system indications, and the implementation of appropriate control measures

Safety message

Rail traffic crews on both trains undertaking a cross at a directional travel station under the Direct Traffic Control safeworking system must validate rail traffic is complete and in clear prior to releasing the block to the rear of the rail traffic and prior to entering a block following receipt of a proceed authority.

 

The occurrence

What happened

At about 2310[1] on 27 February 2018, the Queensland Rail (QR) Network Control Officer (NCO) at Townsville issued a direct traffic control (DTC) authority[2] for the rail traffic crew of Pacific National freight train 9221 to depart Cloncurry, Queensland and proceed to Oonoomurra, located about 14.5 km by rail to the east. About the same time, the rail traffic crew of an opposing empty Aurizon fertiliser train 9T66 were departing Undina, Queensland, travelling west toward Oonoomurra (about 39 km by rail). The NCO planned to cross the two trains at Oonoomurra. The rail comprised of a single track with crossing loops.

Later that night at about 2334, the driver of 9221 advised the NCO that the train was approaching Oonoomurra, which was the limit of their authority. The driver reduced the train speed to around 18 km/h, crossed the Landsborough Highway level crossing before entering the western end of the Oonoomurra crossing location. The Oonoomurra crossing location is a directional travel station that is 1,033m long and equipped at each end with a trailable point[3] set to divert an approaching train to the right side track. Directional travel stations between Townsville and Mount Isa are typically of similar length, equipped with trackside location boards that mark the limits of the respective Station and Section blocks and configured to divert an approaching train to the right (Figure 1).

Figure 1: DTC Blocks and position of Block Limit Boards

Figure 1: DTC Blocks and position of Block Limit Boards. Source: Queensland Rail annotated by ATSB

Source: Queensland Rail annotated by ATSB

As the locomotive cab passed the departure side[4] of trackside location board BLB OA16, the driver selected the length counter feature of the on-board information system[5] to measure the distance the locomotive had travelled after passing the board. The driver had previously set the length counter feature to a distance of 2,500 m, to assist in managing the train’s approach to any temporary speed restrictions.[6] The driver controlled train speed and referred to the distance travelled on the length counter to reduce the potential of overshooting the limit of authority at the eastern end of Oonoomurra and ensure the rear vehicle was clear of BLB OA16.

The driver stopped the train when the length counter readout reduced to 1,431 m. Having travelled 1,069m (according to the counter) and considering train length (rounded to 1,000 m), the driver calculated that the rear wagon should be in clear of the adjacent track by around 70 m. The rail traffic crew crosschecked their location and limit of authority before contacting the NCO to confirm the rear of train 9221 had vacated the Cloncurry to Oonoomurra block[7] behind them.

Shortly after, the rail traffic crew of train 9T66 contacted the NCO advising they were approaching Oonoomurra, the limit of their authority and the cross with train 9221. Having received confirmation from 9221 that they were clear, the NCO subsequently extended the authority of 9T66 from Oonoomurra through to Cloncurry.

Prior to 9T66 entering Oonoomurra, the rail traffic crew of 9221 contacted the crew of 9T66 on the train-to-train radio channel to confirm the trailable points were set for their arrival. Train 9T66 entered Oonoomurra, at speed of 25 km/h; the driver turned the locomotive headlight off as they approached the lead locomotive of 9221 to avoid shining light in the eyes of the opposing train crew.

After turning the headlight back on, the crew of 9T66 continued through Oonoomurra observing the wagons on 9221. As 9T66 transitioned into a sweeping left curve at the western end of Oonoomurra, with the headlight orientation ahead, the rail traffic crew could distinguish only the upper profile of the adjacent bulk wagons. The rail traffic crew sighted the end of the last bulk wagon, which appeared clear of their track.

As they continued through the curve, the rail traffic crew sighted three empty container wagons at the rear of train 9221, with the last wagon (RNDY 20927-S) fouling the track.

The driver made an emergency brake application shortly before locomotive 2838 collided with the middle of the last wagon of train 9221 (Figure 2). Locomotive 2838 was travelling at 25 km/h at the time of the collision and travelled about 104 m after the brake application.

Figure 2: Damage to locomotive 2838 and wagon RNDY 20927-S

Figure 2: Damage to locomotive 2838 and wagon RNDY 20927-S. Source: Queensland Rail annotated by ATSB


Source: Queensland Rail annotated by ATSB

The collision caused minor damage to the headstock of the locomotive and side frame of the wagon and the derailment of the wagon’s trailing bogie. There was no injury to the rail traffic crew of either train.

Train information

Train 9221

Train 9221 was 984 m long with a gross mass of 6,422 t comprising locomotives 8316, 8315 and 8317, a crew accommodation van and 79 freight wagons (the last three were empty). Train 9221 provided a freight service, conveying mineral products between Mount Isa and Townsville.

Post occurrence inspection identified two end-of-train marker devices mounted on train 9221 (Figure 3). One marker, installed at the rear of the last wagon, was in use and connected to the brake pipe and the electronically controlled pneumatic braking system of the train. The other marker was not in use, but mounted at the rear of the fourth wagon from the end of the train. The operator had placed the additional (unused) end-of-train marker device to facilitate its operational requirements for that train service.

Figure 3: End-of train marker devices located on train 9221

Figure 3: End-of train marker devices located on train 9221. Source: Queensland Rail annotated by ATSB

Source: Queensland Rail annotated by ATSB

The QR interface standard[8] specified the requirement for operators to install at least one red tail light, or an approved end-of-train marker device to indicate the rear of the last vehicle of each train. However, the standard did not clearly preclude an operator placing additional (unused) markers in train. Post occurrence QR commenced a review into the phrasing of the interface standard to ensure their end-of-train marker device requirements are clear and operators do not place end-of-train marker devices on any part of the train apart from the last wagon.

Train 9T66

Train 9T66 was 887.96 m long with a gross mass of 1,154 t comprising locomotives 2838 and 4028 with 57 empty freight wagons. Train 9T66 provided a bulk fertiliser service between Phosphate Hill and Townsville.

Procedures for Directional Travel Stations

The safeworking system of Direct Traffic Control (DTC) used on the Mount Isa railway operates on the principle of absolute block working which provides that only one rail traffic movement will be authorised on any one block, at any one time. The DTC Standard[9] identifies limitations in that while the system design validates and creates authorities for issue by the NCO, it cannot:

  • detect if blocks that are currently occupied, or to be occupied are released:
    • by the rail traffic crew
    • or by the NCO
  • detect if a block which is available to the NCO is physically unavailable for traffic for any reason such as a track defect.

For trains to cross/pass at a directional travel station, the NCO is therefore reliant on the rail traffic crew stopped at the location to confirm their train is complete and in clear of the block to the rear (in this instance, train 9221). Following receipt of confirmation and the release code from the rail traffic crew, the NCO then issues an electronic authority for the opposing/following train (in this instance, 9T66) to proceed and occupy the vacated block.

The General Operational Safety Manual also requires the rail traffic crew of each train undertaking a cross/pass at a station to:

  • ensure that the other train is in clear and complete by checking:
    • the other rail traffic is in clear
    • last vehicle (wagon) has the rear of train signal fitted and working
  • tell other rail traffic crew, if possible, the rail traffic is complete.

If the opposing rail traffic is not clear, the rail traffic crew are required to

  • stop clear of other traffic
  • tell rail traffic crew of other rail traffic their train is not in clear

Additionally if the opposing rail traffic is not complete, the rail traffic crew are required to:

  • tell rail traffic crew of opposing train
  • tell the NCO
  • not proceed into the block until authorised by the NCO.

__________

  1. All times referred to in this report are local time, Eastern Standard Time (EST).
  2. An instruction displayed on a computer screen, or on a prescribed form issued for rail traffic movement
  3. Point designed to permit a trailing movement through points closed against the intended move. The wheelset opens the points, which spring back to the normal position after the wheelset is through.
  4. When on the departure side, the worker can see the back of the board (blacked out) and not the block limit board (BLB) number.
  5. Functionally Integrated Railroad Electronics (FIRE) system forming the interface between the operating crew and locomotive computer systems.
  6. A Caution board is placed 2,500 m in advance of any temporary speed restriction Slow board.
  7. A portion of line with defined limits between two adjoining Block Limit Boards, which only one rail traffic movement is permitted at any one time.
  8. Queensland Rail Standard MD-10-194, Interface standard, Version 4.1, s 2.3.4.
  9. Queensland Rail MD-10-113, Direct Traffic Control Manual, Version 2.5, Module DT-1 General, s 1.6 Computer Operations

Safety analysis

Train 9221 lead locomotive serviceability

The lead locomotive 8316 on-board information system used a Doppler speed sensor (ground radar) and Global Positioning System to calibrate the speed and distance measurement. The ground radar on locomotive 8316 had malfunctioned about a week earlier (23 February 2018) and the locomotive returned to the maintainer’s Townsville facility on the 25 February 2018. The locomotive re-entered service, on the 26 February 2018, with the ground radar equipment disconnected.

There was no record of the initial ground radar fault documented in the operator’s locomotive logbook, the daily-automated report, or other maintenance records issued by the maintenance provider to Pacific National.

The disconnection of the ground radar meant that the on-board information system would not automatically calibrate speed and distance measurements. Although a calibration error existed, the maintainer considered it was within the allowable tolerance of 1 to 10 per cent. Testing by the operator found the error resulted in a lower than actual speed indication and a longer than actual length measurement. In this case, the displayed length measurement was around 120 m further than actually travelled.

There was no information displayed on the on-board information system or conveyed during the pre-start briefing or available in the locomotive to alert the rail traffic crew of the disconnection of the ground radar or the implications to the accuracy of the speed and distance information displayed on the systems monitor.

The practice of rolling stock operators operating longer trains on the Mount Isa railway has required drivers to bring their lead locomotive closer to the limit of authority to ensure the rear wagon of the train is in clear.

It is likely that the rail traffic crew in undertaking this action, and complying with the operators signal passed at danger (SPAD) mitigation procedures, place an increasing dependence on the on-board information system to identify the location of the rear of the train. Errors in the distances displayed on the on-board functions therefore have the potential to increase operational risk to that train and other trains required to cross/pass at directional travel stations operated under the Direct Traffic Control safe working system.

Crossing of trains 9221 and 9T66

Train 9221

To facilitate the cross with train 9T66, the driver of 9221 was required to stop the 984 m long train within the 1,033 m track section between block limit boards OA16 and OA25. Pacific National procedures for signal passed at danger SPAD mitigation[10] applicable to Direct Traffic Control (DTC) safeworking areas also required the driver to stop the train no closer than 50 m from the block limit board marking the limit of authority (BLB OA25), before moving forward to ensure the rear of the train was in clear. To determine the stopping point for train 9221 to be in clear, the rail traffic crew relied on the length counter function to identify the location of the last vehicle with respect to BLB OA16.

Based on the displayed distance information, the driver stopped about 82 m from the limit of authority BLB OA25 (Figure 4) believing locomotive 8316 travelled around 1,070 m into the loop and the rear of the train was therefore in clear of BLB OA16.

Figure 4: Stopping location of train 9221 relative to limit of authority

Figure 4: Stopping location of train 9221 relative to limit of authority. Source: Pacific National annotated by ATSB

Source: Pacific National annotated by ATSB

After stopping, the rail traffic crew prepared to release their authority for the Cloncurry-Oonoomurra block to the rear. The Standard General Operational Safety Manual[11] required the rail traffic crew to undertake a number of actions, including ensuring rail traffic is in clear and complete[12] from the adjacent track. To make sure the rail traffic is in clear required the rail traffic crew to compare the length of the rail traffic to the capacity of the main line or loop and, although not expressly stated, should include consideration of the distance between the lead locomotive and the BLB ahead. The rail traffic crew, in this instance, relied solely on the displayed indication of distance travelled to determine their train was in clear before releasing the block to the Queensland Rail Network Control Officer (NCO).

A validation check comparing the indicated distance travelled against the available loop length, train length, and distance between the stopping point of locomotive 8316 and BLB OA25 may have alerted the rail traffic crew to the error in the displayed information and that the rear wagon of train 9221 was fouling the adjacent track. Information on the loop lengths, including Oonoomurra was available to rail traffic crew through the operator’s route competency training and in a ‘run sheet’ carried on board that identified the length of the loop against the location name.

Train 9T66

After receiving an authority to proceed, the rail traffic crew of 9T66 entered Oonoomurra to cross train 9221. As the trains passed, the crews checked the other train to identify the end-of-train maker to determine if the opposing train was complete and in clear. The rail traffic crew of 9221 identified the end-of-train marker on 9T66 and advised its crew.

The rail traffic crew of 9T66 were traversing a left curve at the western end of Oonoomurra. The track alignment resulted in the headlight of the lead locomotive projecting light predominately to the right of the track, away from train 9221. The rail traffic crew were observing the top sections of the adjacent bulk wagons (ROAF class) from train 9221 and were looking for the end-of-train marker on train 9221 and BLB OA16 on the adjacent track, but could not see it.

It was not until the track alignment transitioned to straight, approaching the Landsborough Highway level crossing, that the crew then sighted the last of three empty container wagons (RNDY class) at the rear of train 9221; the last was foul of their track (Figure 5). By this time, with the train travelling at 25 km/h and despite the making an emergency brake application, a collision was unavoidable.

Figure 5: Stopping location of wagon RNDY 20927-S relative to the adjacent track

Figure 5: Stopping location of wagon RNDY 20927-S relative to the adjacent track. Image taken post collision of  the re-railing of wagon RNDY 20927 illustrating the location of the wagon relative to the adjacent track and trailable point at the Western end of the Oonoomurra crossing location. Source: Queensland Rail annotated by ATSB

Image taken post collision of  the re-railing of wagon RNDY 20927 illustrating the location of the wagon relative to the adjacent track and trailable point at the Western end of the Oonoomurra crossing location.

Source: Queensland Rail annotated by ATSB

__________

  1. Pacific National, Active Identification of a Stopping Location, PN-SPL-SAF, Single Point Lesson, Version 1
  2. Queensland Rail, MD-10-107, Module GS 2, Version 2.4, Rail Traffic Movements, s 2.9 - Rail Traffic in Clear and Complete
  3. Clear and Complete - Rail traffic where the last vehicle of a consist has passed beyond a location.

Findings

From the evidence available, the following findings are made with respect to the collision of train 9T66 with the rear wagon of train 9221 at the Oonoomurra directional travel station, Queensland, on 27 February 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • The on-board information system in locomotive 8316 was operating in a degraded state, displaying erroneous speed and distance information to the driver.
  • The Pacific National procedures to determine and communicate the serviceability of a locomotive to operate as a lead were inadequate.
  • Train 9221 stopped with the rear fouling the track section between Cloncurry and Oonoomurra. The rail traffic crew relied solely on the displayed indication of distance travelled to determine the train was in clear and did not validate the distance travelled against the length of their rail traffic and the distance available in the loop before releasing the block to the Network Control Officer.
  • Rail traffic crew of train 9T66, having received authority to proceed through Oonoomurra, did not identify the fouled track ahead with sufficient time to avoid a collision.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Pacific National

As a result of this occurrence, Pacific National has advised the ATSB that they are taking the following safety actions:

Short term measures
  • Verification of the Functionally Integrated Railroad Electronics (FIRE) systems on 83 class locomotives in the Pacific National fleet.
  • Verify the message displayed to rail traffic crew when a ground radar fault occurs and determine arrangements to advise the rail traffic crew to use alternate methods to verify the accuracy of displayed information.
  • Procedures for the maintainer to identify and qualify restrictions to locomotive operation to enable Pacific National to respond.
  • Disseminate information to relevant staff reinforcing the procedures associated with the active identification of a stopping location.
Long-term measures
  • Investigate the requirement to implement a procedural or locomotive-based system change for the identification to rail traffic crew of an inconsistent speed fault based on deviations greater than 7 per cent.
  • Publish a Rollingstock Notice advising rail traffic crews of this faulty meter counter occurrence and follow-up action taken.
  • Review the Townsville Bulk and the Coal Depot’s risk registers to ensure the identification of hazards associated with faulty FIRE system indications and the implementation of control measures.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • Aurizon
  • Pacific National
  • Queensland Rail
  • Rail Traffic Crew.

References

Pacific National, Active Identification of a Stopping Location, PN-SPL-SAF, Single Point Lesson, version 1.

Queensland Rail Standard, MD-10-113, Direct Traffic Control Manual, Module DT-1 General, s 1.6 Computer Operations, version 2.5, 26 October 2016, pp. 7-8

Queensland Rail Standard, MD-10-194, Interface standard, s 2.3.4, version 4.1, 4 September 2018.

Queensland Rail, MD-10-107, Rail Traffic Movements, Module GS 2, s 2.9 - Rail Traffic in Clear and Complete, version 2.4, 10 March 2014, pp. 24-25

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to Aurizon, Office of the National Rail Safety Regulator, Pacific National, Queensland Rail and the Rail Traffic Crew.

Submissions were received from Aurizon, Office of the National Rail Safety Regulator, Queensland Rail and the Rail Traffic Crew. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2018-006
Occurrence date 27/02/2018
Location Oonoomurra, located 16.5 km by rail east of Cloncurry
State Queensland
Report release date 21/11/2018
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Collision
Occurrence class Incident
Highest injury level None

Train details

Train operator Pacific National
Train number 9221
Type of operation Containerised freight
Departure point Mt Isa, Queensland
Destination Townsville, Queensland
Train damage Minor

Train details

Train operator Aurizon
Train number 9T66
Type of operation Fertilizer freight
Departure point Townsville, Queensland
Destination Phosphate Hill, Queensland
Train damage Minor