On 22 March 2020, a Cessna 172 aircraft, registered VH-CBB, took off from a private airfield in Canyonleigh, New South Wales, on a local private flight with the pilot and one passenger on board. Shortly after take-off, due to turbulent weather, the pilot decided to terminate the flight and return to land at the airfield. During the approach, while the aircraft was lower than the pilot had intended, it encountered turbulence. This resulted in the aircraft pitching up steeply. After the pilot corrected the aircraft’s pitch attitude, the landing gear contacted the tree canopy of a steep forested escarpment on the approach path and below the level of the runway threshold. Uncertain if the aircraft could climb above the canopy, the pilot elected to reduce power immediately and land in the trees. The pilot and passenger sustained serious injuries as a result, and the aircraft was substantially damaged.
What the ATSB found
The ATSB determined that the aircraft was on a relatively shallow approach and was at a low height above the terrain when it encountered turbulence. After recovering from the turbulence, the pilot assessed that the aircraft could not reach the runway over the steep terrain, and decided to land in trees.
Safety message
This accident highlights the importance of adopting an approach profile that mitigates the effects of gusty/turbulent conditions and being prepared to go around if the approach becomes unstable. The Flight Safety Foundation Approach-and-landing Accident Reduction briefing note 6.1 emphasises the need to be ‘go-around-prepared’ or ‘go‑around-minded’ because it is not a manoeuvre that pilots execute regularly.
The investigation
The occurrence
On the afternoon of 22 March 2020, the pilot of a Cessna 172A aircraft, registered VH-CBB, planned to conduct a local private flight from a private airfield at Canyonleigh, New South Wales, with one passenger on board. The pilot noted that the wind speed and direction were as forecast, which were 20 kt and west‑south‑westerly, and therefore selected runway 27[1] for take-off.
Shortly after take-off, the aircraft experienced some turbulence. The pilot and passenger assessed it was ‘not going to be a relaxing time to go for a fly’, and decided to terminate the flight. The pilot confirmed via the windsock that the wind direction had not changed since take‑off, and elected to continue onto a downwind leg of the circuit for runway 27.
When the aircraft was 1 NM from the threshold, and approximately 400 ft above aerodrome level, the pilot completed the turn onto final approach. The pilot reported having selected one stage of flap for the approach and landing. The aircraft was on approach over steep forested terrain when the pilot noticed that the approach profile was shallower than intended and that the aircraft was ‘a bit low’. In response, the pilot increased the power.
The pilot reported that the turbulence then became ‘very severe’ and the aircraft pitched up steeply. The pilot initially decided to conduct a go-around manoeuvre, but after correcting the pitch attitude, realised that the aircraft was far lower than expected, and no longer aligned with the runway. The aircraft’s wheels reportedly brushed the tree canopy on the escarpment downhill from the runway threshold. Uncertain whether the aircraft would be able to climb over the canopy to the runway, the pilot elected to reduce power and land in the trees. The aircraft came to rest approximately 50 metres short of the threshold and to the left of the runway.
Both the pilot and passenger sustained serious injuries, but they were able to exit the aircraft and contact emergency services. The aircraft was substantially damaged.
Context
Recorded data and airfield geography
OzRunways[2] information for the flight was obtained, with the final approach shown in Figure 1. A review of the flight data identified that during the second half of the approach, the aircraft’s altitude remained relatively level (highlighted segment), but the terrain beneath falls away into a deep gully then climbs towards the airfield.
Figure 1: VH-CBB approach to Canyonleigh airfield, runway 27
The recorded data rounded the aircraft’s altitude down to 100 ft increments, giving a low approximation of VH-CBB’s actual approach. Due to sudden changes in attitude and altitude, the last few data points were considered unreliable and were therefore not included in the image. Source: Google Earth, annotated by the ATSB
Pilot’s experience at Canyonleigh
The pilot had landed at Canyonleigh airfield about 50 times prior to the occurrence, all in VH-CBB. During previous landings on runway 27, the pilot reported sometimes making high/steep approaches and extending full flaps to ‘increase the safety margin’ while flying over the steep, heavily forested terrain. On the day of the occurrence, the pilot believed a high approach would not be necessary.
The pilot assessed that the severe turbulence encountered prior to landing was caused by rotors—a specific type of turbulence produced by mountain waves.[3] This kind of turbulence had reportedly been encountered by both the accident pilot and, to a lesser degree, the airfield owner, during previous landings on runway 27.
Meteorological information
The Bureau of Meteorology provided the following assessment of the likely weather conditions at Canyonleigh on the day of the accident:
While winds gusting to 26 knots were observed at [the nearby weather station], it is possible that the winds higher in the atmosphere were a little stronger, possibly reaching 30 knots at times. With 20 to 30 knots of wind over elevated terrain, light to moderate mechanical turbulence is likely.
With regard to the possible formation of rotors beyond the threshold of runway 27, the Bureau of Meteorology stated:
While the atmospheric conditions did not strongly favour mountain wave and rotor turbulence and no evidence of waves could be seen on satellite imagery, the presence of a temperature inversion above the ridge top with moderate winds blowing perpendicular to the ridge means that small scale waves and rotors cannot be ruled out. The terrain downstream from the threshold, sloping sharply downwards towards the valley, could cause an acceleration of the winds close to the ground, thus increasing the possibility of downward air motion as well as rotor formation. There are, however, no observations to confirm that this occurred.
Safety analysis
While on approach to runway 27, the pilot noticed the glideslope was shallower than intended and that the aircraft was low, so increased power. The aircraft then encountered turbulence, resulting in it pitching upward. The exact nature of the turbulence could not be determined, but rotors or downward air motion over the escarpment may have been present at the time.
Once the aircraft’s attitude was corrected, the pilot assessed that the aircraft was too low and close to the terrain to climb out of the valley to the runway and decided to land immediately in the trees below.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the collision with terrain involving Cessna 172, VH-CBB, on 22 March 2020.
Contributing factors
During a shallow approach, the aircraft encountered significant turbulence that affected the aircraft’s pitch attitude and flight profile. As a result, the pilot assessed the aircraft was too low to reach the runway and elected to land in trees.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
pilot
passenger
airfield owner
New South Wales Police Force
Bureau of Meteorology
OzRunways.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the pilot
the airfield owner
the Bureau of Meteorology.
No submissions were received.
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the morning of 17 March 2020, a QantasLink Bombardier Dash-8-402, registered VH-LQJ (LQJ), was being taxied for a scheduled flight from Gladstone Airport, Queensland to Brisbane Airport, Queensland. There were two flight crew, two cabin crew and 34 passengers on board. At the same time, an ATEC Faeta 321, registered 24-8279 (Faeta 8279), with one instructor and student on board, was conducting circuit training at Gladstone Airport.
At about 0645, as Faeta 8279 was on approach to conduct a touch-and-go on runway 10, LQJ entered and taxied along the runway in front of Faeta 8279. The instructor on board Faeta 8279 conducted a go-around to avoid an incident on the occupied runway.
What the ATSB found
The ATSB found that the flight crew of LQJ set the incorrect common traffic advisory frequency and did not select the appropriate traffic collision avoidance system/transponder mode during the before start checks. These errors were likely influenced by increased workload and time pressures experienced during before start preparations.
The errors went undetected during the taxi phase of flight. As a result, the flight crew’s situational awareness was significantly degraded and caused the captain and first officer to form the shared belief that no other traffic was operating in the vicinity of Gladstone Airport. This shared incorrect mental model likely impacted the efficacy of the visual scan conducted prior to entering the runway, with neither flight crew member sighting the approaching aircraft.
What has been done as a result
Following this incident, QantasLink undertook a review of operating procedures at non-controlled airports. The procedural review included transponder activation and introduced a requirement to contact Air Traffic Control prior to entering the runway. QantasLink also provided internal communications to flight crew detailing the importance of standard operating procedures and threat management when dealing with distractions and workload.
Safety message
This incident illustrates the human factors implications associated with the combination of increased workload and time pressures. Flight crews can guard against similar outcomes by applying effective threat and error management strategies that recognise when such threats may arise and set in place suitable actions that minimise error potential. These actions include strict adherence to standard operating procedures and increased cross-checking of system inputs and mode changes.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
At about 0600 Eastern Standard Time,[1] on 17 March 2020, the crew of a QantasLink Bombardier Dash-8-402 aircraft, registered VH-LQJ (LQJ), commenced pre-flight preparations for a scheduled regular public transport flight from Gladstone Airport, Queensland to Brisbane Airport, Queensland. The crew comprised the captain, first officer (FO) and two cabin crew.
It was the first flight of the day for LQJ and the scheduled departure at 0645 meant that the crew had about 45 minutes to prepare the aircraft. Shortly after arriving at the aircraft, the captain started the auxiliary power unit (APU),[2]while the FO conducted the aircraft walk around. The captain then commenced the ‘originating’ and ‘before start’ checks, which included selecting APU bleed air ‘ON’ to provide air-conditioning to the cabin. At this point the APU failed, so the captain completed the automatic APU shutdown actions.
At about 0610 during the walk around, the FO noticed a small aircraft taxi behind LQJ. This aircraft was an ATEC Faeta 321, registered 24-8279 (Faeta 8279), that was being taxied for circuit training with one instructor and one student on board. The FO made a mental note of the taxiing aircraft, finalised the walk around, and returned to the flight deck to complete the remainder of the pre-flight preparations.
The captain and FO then restarted the APU, but it failed for a second time when APU bleed air was selected ‘ON’. At about the same time, a ground crew member attended the flight deck to inform the captain and FO that a ‘person in custody’[3]and their police escort would be travelling on the flight. The captain left the flight deck to review the person in custody paperwork and brief the cabin crew on the custody arrangements. The person in custody and their escort then boarded the aircraft, with the remainder of the flight’s 34 passengers boarding a short time later.
At about 0622, Faeta 8279 commenced circuit training using runway 28. The occupants of Faeta 8279 made regular positional broadcasts on the Gladstone Airport common traffic advisory frequency (CTAF) [4]throughout the training activity.
Meanwhile, on board LQJ, the captain returned to the flight deck and elected to apply the Minimum Equipment List (MEL)[5] to the APU system. The captain and FO then actioned the procedures required to apply the MEL with remote support provided by QantasLink maintenance engineers. Completing this task took the crew 5-10 minutes.
Once the MEL had been finalised, the captain and FO undertook the remainder of the before start checks, but omitted to set the traffic collision avoidance system (TCAS)[6]/transponder[7] to ‘ON ALT’ and to select the Gladstone CTAF in VHF COM 2.[8]The CTAF omission was identified by the FO during the departure briefing and subsequently addressed. However, the FO entered the incorrect frequency of 126.7 MHz instead of 118.8 MHz, which was the correct frequency for the Gladstone CTAF.
At 0643, a pilot in Faeta 8279 made a CTAF broadcast advising traffic that the aircraft would be changing runway direction for a touch-and-go on runway 10. The captain and FO of LQJ did not receive this broadcast as they were monitoring the incorrect frequency.
The weather at the time was reported as being a wind from 201 degrees magnetic at 6 knots, no cloud, and a visibility of 43 km. As the wind did not favour either runway, the flight crew of LQJ elected to use runway 28 to avoid departing towards the rising sun. This required a short taxi from bay 3 to the A5 intersection, and a right turn to enter and backtrack runway 28 (Figure 1 and Figure 2).
Figure 1: Overview of VH-LQJ taxi routing
Source: Google Earth, annotated by the ATSB
Figure 2: Gladstone aerodrome chart
Source: Airservices Australia, annotated by ATSB
At 0643:38, the FO made a broadcast on the incorrect CTAF using VHF COM 2 and LQJ was taxied from its parked position on bay 3.
At 0644:23, the FO made a second broadcast on the incorrect CTAF as the aircraft taxied towards the A5 intersection.
At 0644:29, a pilot in Faeta 8279 made a broadcast on the Gladstone CTAF advising traffic that the aircraft was on short final for a touch-and-go on runway 10. The flight crew of LQJ did not receive this broadcast either.
The captain and FO conducted a visual scan as LQJ neared the A5 intersection, but neither flight crew sighted Faeta 8279 on approach for runway 10. At about 0645, LQJ was taxied onto the runway in front of the approaching Faeta 8279. In response, the instructor on board Faeta 8279 commenced a go-around and attempted, unsuccessfully, to contact LQJ on the Gladstone CTAF.
At 0645:02, as LQJ backtracked along the runway, the FO made a taxi report to Brisbane Centre[9] using VHF COM 1. A secondary surveillance radar transponder code[10] was provided to LQJ and the captain entered it into the transponder. Shortly afterwards, the captain identified that the TCAS/transponder was not appropriately set and selected it to ‘ON ALT’.
At 0645:42, the TCAS presented the flight crew with a traffic advisory[11] indicating climbing traffic above LQJ. The traffic – Faeta 8279 – was subsequently sighted by the captain and FO climbing in an easterly direction overhead the airport.
The captain and FO checked the frequency set in VHF COM 2 and identified the incorrect frequency selection. The frequency was changed to the correct frequency of 118.8 MHz and the FO made a broadcast at 0646:29 advising that LQJ was ‘entering and backtracking’ runway 28.
At about 0646:36, a pilot in Faeta 8279 replied to LQJs broadcast, but the flight crew of LQJ did not respond to Faeta 8279’s transmission. A short time later, the instructor in Faeta 8279 broadcast the intention to manoeuvre for runway 28 to allow LQJ to depart. At about 0648, LQJ commenced its take-off from runway 28.
Context
Air Traffic Control communications
The captain and FO elected to delay the taxi report to Brisbane Centre until LQJ had entered the runway. This was due to the shared understanding that the Gladstone Airport terminal buildings shield VHF transmissions and prevent contact being made with Brisbane Centre when parked on bay 3. QantasLink procedures permit an aircraft to be moved to an alternate location when communications with air traffic services are not possible on the bay.
Human factors
The same crew had flown LQJ into Gladstone Airport the evening prior, arriving at about 1900 on 16 March 2020. The crew then stayed overnight in local hotel accommodation. Both the captain and FO reported no fatigue issues associated with the overnight stay, and an assessment of the flight crew’s previous 14-day roster did not identify any significant fatigue risk factors.
During pre-flight preparations, the captain and FO encountered a number of unanticipated events and distractions, including two APU failures, boarding of a person in custody, and application of a MEL to the APU system. The additional actions, due to these events, increased their workload.
On the morning of the incident, neither the captain nor the FO recalled listening for an aerodrome frequency response unit (AFRU)[12] reply to the two broadcasts made on the incorrect frequency. The first broadcast took place when both flight crew members recall increased workload associated with the turn off bay 3. The second CTAF broadcast was made mid-way through the short taxi to the runway intersection.
Prior to entering the runway, the captain recalled believing there was no other aircraft in the vicinity of Gladstone Airport as the crew had not heard any broadcasts on VHF COM 2 and there was no traffic indicating on the TCAS display. The FO recalls making reference to the small aircraft that had been sighted during the walk around checks. However, given the elapsed time since the sighting, combined with the lack of transmissions received on VHF COM 2, the FO concluded that the traffic was no longer in the vicinity of the airport.
Safety analysis
This was the first flight of the day for LQJ and the crew had about 45 minutes to complete all pre‑flight preparations prior to the scheduled departure time of 0645. During this period, the captain and FO encountered several unanticipated events and distractions, including the APU failure and person in custody paperwork, that required additional actions to be performed within the allocated timeframe. These interruptions and additional actions within a defined time period added workload and time pressures.
The combination of increased workload and time pressures is known to result in degraded information processing, increased errors, the tunnelling of attention, and an increased reliance on familiar strategies or actions (Staal, 2004). This response to workload and time pressures likely resulted in the flight crew’s omission of the two ‘before start’ checklist items and the selection of the incorrect frequency in VHF COM 2.
The frequency selection error was further compounded by the flight crew not recognising an absence of AFRU reply when making radio calls on the incorrect frequency. As a result, the captain and FO were not aware that they were monitoring and broadcasting on the incorrect CTAF.
The flight crew’s inadvertent omission of the TCAS/transponder selection resulted in the captain and FO incorrectly believing the TCAS would alert them to the presence of any transponder equipped aircraft that were operating in the vicinity of Gladstone Airport.
As a result of the frequency selection and TCAS/transponder errors, the flight crew’s situational awareness was significantly degraded resulting in the captain and FO forming the shared belief that no other traffic was operating in the vicinity of Gladstone Airport. This shared incorrect mental model likely impacted the efficacy of the visual scan conducted by the flight crew as they neared the A5 intersection. Consequently, neither flight crew member identified the approaching aircraft and LQJ was taxied onto the runway in front of Faeta 8279. The instructor on board Faeta 8279 conducted a go-around to avoid an incident on the occupied runway.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the runway incursion involving Bombardier Dash-8-402, registered VH-LQJ, at Gladstone Airport, Queensland, on 17 March 2020.
Contributing factors
The flight crew of VH-LQJ were not aware that light aircraft 24-8279 was on approach and taxied onto the runway in front of it. Consequently, the pilot of 24-8279 had to conduct a go‑around.
The visual scan by the flight crew of VH-LQJ before entering the runway did not identify the approaching 24-8279, probably because of their degraded situational awareness.
Increased workload and distractions while preparing VH-LQJ for departure led to the crew not setting the correct radio frequency and the appropriate mode on the traffic collision avoidance system/transponder. Without these essential aids to situational awareness, neither pilot developed an accurate mental model of the traffic.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Safety action by QantasLink
Following this incident, QantasLink undertook a review of operating procedures at non-controlled airports. The procedural review included transponder activation and introduced a requirement to contact Air Traffic Control prior to entering the runway. QantasLink also provided internal communications to flight crew detailing the importance of standard operating procedures and threat management when dealing with distractions and workload.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the flight crew of VH-LQJ
the pilot in command of 24-8279
QantasLink
Avdata
Civil Aviation Safety Authority
Airservices Australia.
References
Staal MA 2004, Stress, cognition, and human performance: A literature review and conceptual framework, National Aeronautics and Space Administration Technical Memorandum NASA/TM-2004-212824.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the crew of VH-LQJ, the pilot in command of 24-8279, QantasLink, and the Civil Aviation Safety Authority.
Submissions were received from QantasLink and the captain of VH-LQJ.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the afternoon of 5 March 2020, an Airbus A320, registered VH-VFL and operated by Jetstar Airways landed at Proserpine, Queensland, on a scheduled passenger service from Sydney, New South Wales. On the walk around after landing, damage was found to the nose gear landing light and the left main landing gear, including a pierced hydraulic brake line.
Fluid was subsequently found in the landing gear wheel well. No evidence of a strike or foreign object debris was found on the runway at Proserpine or Sydney. There was no indication that the aircraft had been struck by ground support equipment prior to departure from Sydney, and no recent maintenance had been performed on the left main landing gear.
What the ATSB found
The ATSB determined that the nose gear landing light was probably struck and damaged during departure from Sydney. However, the source of the damage could not be determined. The glass lens from the nose gear landing light most likely struck the main landing gear, resulting in the pierced hydraulic brake line.
Safety message
Visual inspections play an important role in maintaining the safety of an aircraft. In this case, a vigilant flight crew identified damage that could have otherwise impacted on the safety of future flights. Flight crew are encouraged to be attentive in their post-flight inspections, even when the flight has been completed without incident.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
At 1308 Eastern Standard Time[1]on 5 March 2020, a Jetstar Airways (Jetstar) Airbus A320‑232 registered VH-VFL, completed a scheduled passenger flight from Sydney, New South Wales to Proserpine, Queensland. During the subsequent walk around the flight crew noticed damage to the aircraft’s undercarriage, specifically:
the nose gear landing light was damaged
the left main landing gear (MLG) brake hydraulics were pierced, with fluid visible on the apron, tyres and gear assembly
a metal conduit carrying wiring for the left MLG was deformed.
After the damage was found, a member of the cabin crew recalled hearing a ‘deflation noise’ while on descent into Proserpine. There was no visible biological evidence that might indicate a wildlife strike. Therefore, given the extent and nature of the damage, Jetstar reported that a remotely piloted aircraft (RPA) may have collided with the aircraft.
Runway inspections were subsequently conducted at Sydney and Proserpine, however no debris or any evidence of an impact could be found at either location. Jetstar reviewed the flight data but could not identify anything that might indicate a strike had occurred. The flight data did not record the condition of the landing light or the level of hydraulic fluid in the MLG brake line.
Context
Aircraft damage description
Figure 1 shows the damage to the nose gear landing light at the time of the post‑flight walk around. Most of the lamp was missing, with a small fragment still attached to the socket. In the background of the image, the damaged left MLG can be seen. The broken nose gear landing light was inspected by the manufacturer, but there was no comment made regarding possible reasons for the damage.
Figure 1: Damaged nose gear landing light
Source: Jetstar Airways, annotated by the ATSB
Figure 2 shows the damage found on the left-hand MLG wiring conduit and the adjacent brake hydraulic line. Fluid can be seen on the apron as well as the tyres. A subsequent inspection of the aircraft found more fluid in the wheel well of the left main landing gear.
Figure 2: Main landing gear damage
Source: Jetstar Airways, modified by the ATSB
Ground handling and maintenance
The maintenance history of VH-VFL was reviewed to determine if some or all of the landing gear damage could have been due to some earlier maintenance activity, or if tooling might have been left in the wheel well, resulting in the damage to the MLG observed. However, prior to the occurrence, the aircraft had completed 35 scheduled flights since any maintenance was performed on the landing gear.
There were no reported incidents of damage from ground support equipment prior to departure from Sydney, but there was there was no CCTV footage available to confirm this.
Landing gear design and operation
The nose gear landing light used a halogen lamp. The lens was made of glass, but it included a polycarbonate lens cover described by the manufacturer as very resistant to thermal shocks and mechanical impacts. An undamaged halogen lamp, installed on an A320, is shown in Figure 3.
Figure 3: Undamaged nose gear landing light with polycarbonate cover
Source: Jetstar Airways
The damaged main landing gear hydraulic line was responsible for actuating the wheel brakes. The line would pressurise when the brakes were applied via pilot input or the automatic brake system. One function of the automatic brake system was to apply the brakes during landing gear retraction, to prevent wheel rotation.
Hydraulic line examination
The pierced hydraulic line was sent to the ATSB for examination. The line was confirmed to be a titanium-aluminium alloy, per the manufacturer’s specifications. The damage observed was consistent with a concentrated external force resulting in the puncture.
Scanning electron microscopy, including backscattered electron imagery[2] and energy-dispersive X-ray spectroscopy[3] was conducted on the damaged section of line. Figure 4 shows a foreign material identified around the damaged area.
Figure 4: Backscattered electron image of the hydraulic line damage
The darker regions indicate a foreign material is present, consisting of lighter elements than the titanium-aluminium line.
Source: ATSB
Energy dispersive X-ray spectroscopy identified the foreign material as a combination of silicon and oxygen. At higher magnifications, the foreign material appeared to have a granular, crystalline structure. The structure and composition of the foreign material indicated that it was most likely silica, otherwise known as silicon dioxide. Silica is the primary ingredient in most forms of glass.
Safety analysis
The polycarbonate cover on the nose gear landing light would likely have prevented it from disintegrating due to thermal stress, such as from a blown bulb. Therefore, the damage to the light indicated by the recovered bulb fragments was probably the result of an impact. The bulb fragmented despite the presence of the polycarbonate cover, indicating that the light was struck with considerable force. Given their proximity to each other and the nature of the damage, the punctured hydraulic line and deformed metal wiring conduit were also considered to be the result of an impact.
Examination of the damaged hydraulic line identified traces of what was most likely glass. The most probable source of the damage to the hydraulic line and wiring conduit was the glass lens of the nose gear landing light. Other potential sources of damage, such as ground support equipment or foreign object debris could not be ruled out, however there was no evidence found to support these.
Both impacts most likely occurred during the flight between Sydney and Proserpine, since no damage was reported following the previous flight, or during pre-flight inspections in Sydney. Fluid found in the main landing gear (MLG) wheel well likely came from the punctured hydraulic line. The fluid was probably discharged into the well when the crew raised the landing gear during departure from Sydney, as the line would have been pressurised, and the gear was not retracted.
again prior to the damage being found. It is therefore likely that the MLG damage occurred during departure from Sydney, rather than via a remotely piloted aircraft (RPA) while on descent into Proserpine, since damage on descent would not explain the fluid found in the wheel well. As such, the noise heard by the cabin crew member was probably unrelated to the occurrence.
The source of the impact to the nose gear landing light could not be determined. It is possible the aircraft struck a bird or an RPA during departure from Sydney, or foreign object debris during its take-off roll. It should be noted, however, that no debris was found during runway inspections at Sydney Airport and there was no visible biological evidence of a wildlife strike.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the landing gear damage involving Airbus A320 VH-VHL, on 5 March 2020.
Contributing factors
On departure from Sydney, the nose gear landing light was probably struck and damaged by an unknown object. Consequently, part of the nose gear landing light lens likely impacted and damaged the main landing gear.
Sources and submissions
Sources of information
The sources of information during the investigation included:
Jetstar Airways
the nose gear landing light manufacturer.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Jetstar Airways
Airbus
the nose gear landing light manufacturer
French Bureau of Enquiry and Analysis for Civil Aviation Safety (BEA).
A submission was received from:
Jetstar Airways.
The submission was reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
In the early morning of 7 March 2020, a maintenance work group was undertaking work between Thorneside Station and Birkdale Station on the Cleveland rail corridor in Brisbane, Queensland. Queensland Rail (QR) was the rail infrastructure manager of the rail corridor. The work involved replacing a defective section of track.
A planned closure was due to commence at 0218, during which the replacement of the rail track would be done under a track occupancy authority (TOA) with in-field protection. Prior to the planned closure, the work group conducted preparatory work under a TOA which did not require in-field protection.
Soon after 0100, an excavator operator was directed by a member of the work group (the recipient) to access the running tracks. However, at that time the rail corridor was open for normal rail traffic activity.
At about 0108, a suburban passenger train was involved in a near collision with the excavator near Thorneside. With the train speed greater than 90 km/h, the driver of the suburban train noticed the excavator on the running tracks and applied the emergency brake. At about the same time, the excavator operator identified the oncoming train and initiated emergency measures, removing the machine from the running tracks as the train passed at a speed of about 61 km/h.
The train stopped 75 m past the incident site. The network control officer (NCO) subsequently approved the driver to continue after being informed that the excavator was clear of the tracks. However, the excavator was still within the (3 m) danger zone, less than 1 m from the nearest rail.
The excavator operator was directed by the work group supervisor to remove the excavator. As the excavator operator was about to do so, at 0137, there was a second near collision when another suburban passenger train passed through the incident site at 60 km/h (after applying emergency braking). The excavator operator had to jump clear down an embankment to escape danger as the train passed.
What the ATSB found
The network pre-start briefing for the work group was conducted at the Cannon Hill depot before the workers departed for the worksite. However, the ATSB found that the lead protection officer (PO), assistant PO and the excavator operator were not included in the briefing, which denied them and the work group of essential safety information applicable to their roles and responsibilities.
There were also limitations with a number of subsequent communications processes after the work group arrived at the worksite. The lead PO was not informed of or aware that the excavator had arrived at the worksite. Consequently, when the NCO notified the PO of a track fault indication (associated with the on-tracking of the excavator) and asked if there was any equipment on-track, the PO had an incomplete mental model of the work group and advised the NCO that there was no equipment on-track at that time.
In addition, without gaining the necessary permission, the recipient had directed the operator of the excavator to on-track under the incorrect assumption the planned closure had commenced, and the worksite was protected by a TOA with in-field protection and train activity on the rail corridor had ceased. The recipient had misinterpreted the situation due to misinterpreting an instruction from the team leader and a combination of other situational factors.
Following the first near collision, communications between the emergency hotline contact (in the network control centre) and the lead PO, and between the lead PO and the work group supervisor, did not clarify that, although the excavator was off the track, it was still in the danger zone. The supervisor also directed the excavator operator to remove the excavator from the danger zone without gaining the necessary authority from the NCO or confirming that rail traffic had been stopped. This omission contributed to the second near collision.
Some of these communication problems were associated with personnel not using appropriate rail terminology when conducting safety-critical communications. The ATSB found that the Queensland Network Rules and Procedures did not provide sufficient guidance for rail safety workers to ensure they used standardised rail-specific terminology when communicating safety‑critical information.
Network pre-start briefings are a critical control in place to manage the risk of collisions between rail traffic and workers and machinery, and Queensland Rail had undertaken significant work in recent years to improve these processes. However, the ATSB found that the design of the first-line assurance activities and the limited conduct of second-line and third-line assurance activities provided only limited assurance that the worksite protection aspects of the briefings were being conducted effectively.
What has been done as a result
Soon after the incident, on 10 March 2020, Queensland Rail (QR) issued a critical safety alert (CSA) directed to protection officers (POs) and their supervisors and managers, and all infrastructure workers and their supervisors and managers. The alert outlined a number of key actions, including that all workers must attend a prestart briefing prior to entering the rail corridor (and the briefing must include the PO giving the rail safety component of the briefing). In addition, all workers could not access the danger zone without being given permission by their supervisor, and the supervisor could not allow workers to enter the danger zone until they had received advice from the PO that required protocols were in place.
As a result of the incident, QR subsequently entered an enforceable voluntary undertaking (EVU) with the Office of the National Rail Safety Regulator (ONRSR). As part of the EVU, QR committed to 13 initiatives to improving planning processes for track access, the safeworking control framework, capability of safety-critical workers and effectiveness of safety assurance and performance. As of 1 November 2023, 12 of the 13 initiatives had been externally verified as closed and QR advised that the final initiative was on track for completion by 31 December 2023.
In addition to the EVU initiatives, QR has proactively introduced safety actions in response to this incident by:
redeveloping the protection officer training package
delivering communication training for all rail corridor workers
implementing a first-line assurance activity focused on the effective use of rail-specific terminology and a range of other technical and non-technical skills when communicating safety-critical information
developing targeted first and second-line assurance activities to measure the effectiveness of the improved pre-start briefing process.
Safety message
Substandard network pre-start briefings and communication irregularities have been identified as contributors to railway accidents in Australia and abroad. However, with this knowledge, rail infrastructure managers and track workers are still experiencing problems with the application of effective safety-critical communication, and assurance that network pre-start briefings are conducted in accordance with procedures designed to manage safety risks. It is essential that all workers attend a network pre-start briefing prior to entering the rail corridor and fully understand the worksite protection that is in place for their activities. It is also vital that workers use standardised railway terminology when conducting safety-critical communications to minimise the potential for misunderstanding.
In a safety-critical work environment that fundamentally relies on procedural controls, it is vital that first-line assurance activities are appropriately designed to provide an accurate account of key work practices being assessed, and that sufficient higher level assurance activities are conducted to provide confidence in the results of the first-line assurance activities. The absence of accurate information limits the ability of an organisation to learn and continuously improve safety.
The occurrence
Overview
In the early morning of 7 March 2020, a maintenance work group was undertaking work between Thorneside Station and Birkdale Station on the Cleveland rail corridor in Brisbane, Queensland. Queensland Rail (QR) was the rail infrastructure manager of the rail corridor.
At about 0108 local time, a QR suburban passenger train, with passengers on board, almost collided with an excavator while it travelled along the rail tracks near Thorneside. While personnel were attempting to remove the excavator from the danger zone[1] of the rail corridor, a second near collision occurred involving another suburban passenger train.
Pre-work arrangements
The maintenance work group was tasked with replacing a defective section of railway track located between Thorneside and Birkdale stations. The following personnel were involved in the maintenance work:
a QR depot supervisor
a QR work group team leader (acting as the supervisor of the maintenance task under the guidance of the depot supervisor)
4 QR maintenance personnel, including the operator of a front-end loader and one worker performing the role of the recipient.[2]
In addition, the following contractors were involved in the track maintenance work:
a welder
a labourer
2 protection officers[3] (POs), (lead PO and an assistant PO)
an excavator operator.
The ‘planned closure’[4] was scheduled to start at 0218 on 7 March and involved the use of a track occupancy authority[5] (TOA) with in-field protection (sometimes known as a ‘protected TOA’).
At 2100 on 6 March 2020, the QR personnel, the labourer and the welder commenced their shift at the Cannon Hill depot in Brisbane. The supervisor and team leader discussed planning for the task and potential contingencies if there were delays. The team leader and members of the work group, who signed on at the depot, then prepared the work truck with the necessary tools for the worksite, while the supervisor planned the work schedule from their office.
At about 2130, the team leader gathered the work group members who were present for a network pre-start briefing[6] at the depot. The brief discussed the nature of the work task as well as the hazards and controls that would be applied. The work group was told that it was likely that preparation work at the worksite would occur prior to the planned closure using a TOA without in‑field protection (sometimes known as an ‘unprotected TOA’). The POs and the excavator operator were not involved in the pre-start briefing at the Cannon Hill depot.
After completing the network pre-start briefing, the team leader and members of the work group signed the relevant section of the Network Pre-Start Briefing form(MD-15-43), verifying they were present and that they understood the requirements of the briefing.
At about 2200, the work group members at the Cannon Hill depot travelled to the worksite at Thorneside, stopping briefly to purchase refreshments. At the same time, the POs arrived at the Cannon Hill depot to meet with the supervisor to discuss work arrangements, in particular the protection at the worksite. The supervisor communicated the potential for performing preparation work prior to the planned closure under the safeguard of a TOA without in-field protection,[7] which would require protection arrangements for the period of the preparation work in addition to those published in the train notice[8] for the planned track closure. Following the discussion between the supervisor and the POs, the team leader was provided with an overview of the proposed arrangements.
The lead PO contacted the network control officer (NCO) to discuss the proposed arrangements. The NCO checked their train diagram[9] and confirmed with the PO that there was availability to instate a TOA without in-field protection for the preparation work that allowed workers access to the track between trains for brief periods. As the NCO was nearing the end of their shift, they stated that they would inform the incoming NCO of the proposed work on track arrangement and the agreed protection for that work.
At about 2215, the team leader departed the Cannon Hill depot and travelled to the worksite at Thorneside. Shortly after, the POs and the supervisor also left the depot and travelled to the worksite in separate vehicles.
Preparation work
At about 2235, the team leader and members of the Cannon Hill work group arrived at the work group entrance gate to the rail corridor at Thorneside (located at the 23.645 km mark),[10] which was about 340 m east of the actual worksite (Figure 1). The team leader directed the recipient and the front-end loader operator to travel to Thorneside Station to collect the front-end loader that was required at the worksite.
At about 2245, the POs arrived at the work group entrance gate. The team leader and lead PO discussed the required protection arrangements for the preparation work, and the PO then briefed the work group members who were present about these arrangements.[11] The supervisor had not arrived at the worksite at this time. The PO explained that work in the danger zone would be for short periods, which would occur between train activity under the safeguard of a TOA without in‑field protection. The PO then contacted the NCO and the paperwork relevant to this TOA was completed. At about that time, the supervisor arrived at the entrance gate.
The TOA without in-field protection was issued to the lead PO at 2252 and it was suspended 10 minutes later at 2302. In that period, the PO, supervisor, and team leader entered the rail corridor through the entrance gate and walked to the worksite to evaluate the track defect and work requirements. While the TOA was suspended, they stood clear of the danger zone and 2 suburban passenger trains passed the site.
The TOA was reinstated at 2322 and suspended at 2333. In that period, at the request of the team leader, 4 members of the work group walked from the entrance gate to the worksite to perform preparation work, while the team leader returned to the entrance gate to measure a length of rail that had been placed in the rail corridor days earlier. The length of rail was to be cut to size in preparation for the replacement of the track defect at the worksite. The lead PO and supervisor remained at the worksite.
At 2325, the excavator operator, who was required for the planned closure (but not the preparation work) contacted the supervisor to obtain information about the location of the worksite. The supervisor directed the excavator operator to travel to the work group entrance gate and wait for instructions.
The excavator operator arrived at the entrance gate at about 2335, where they were met by the team leader and members of the work group. The excavator operator requested a worksite briefing but was told to wait until further notice as the excavator was not required until the planned closure and after the preparation work was finished. After completing several tasks, the team leader discussed the work arrangements with the excavator operator and requested the operator sign the network pre-start briefing form, which was signed. The excavator operator was not provided a formal network pre-start briefing and was not provided with any briefing about worksite protection arrangements by the lead PO. The PO was not informed or aware that an excavator had arrived at the worksite.
The team leader advised the excavator operator not to unload the excavator from the truck as passage through the work group entrance gate was not suitable for the excavator (as cement troughing was blocking its path). Consequently, the team leader directed the excavator operator to travel to another entrance gate further east, located at the 24.117 km mark (Figure 1), and wait for further instructions. In addition, the team leader advised the excavator operator to complete all documentation pertaining to the excavator accessing the rail corridor in readiness for the planned closure. The excavator operator then travelled to the next entrance gate, unloaded the excavator from the truck, and prepared the relevant paperwork.
Figure 1: Places of interest relevant to the worksite and the entrance gates
The image shows Thorneside Station, the worksite, entrance gates for the work group and the excavator and near collision location.
Source: Google earth, annotated by the ATSB
The TOA was reinstated at 0022 (on 7 March) and suspended at 0033. In that period, members of the work group walked from the worksite back to the work group entrance gate as preparation work at the worksite had been completed. The only remaining work activity prior to the planned closure was to load the bucket of the front-end loader with tools and equipment in readiness for transportation from the entrance gate to the worksite. At this time, the front-end loader was in the rail corridor near the entrance gate, but on the opposite side of the rail tracks to that of the entrance gate, work truck and work group.
While the TOA was suspended, the recipient, who had assisted in preparing the worksite, travelled by car to meet with the excavator operator at the other (excavator) entrance gate. The recipient and the excavator operator completed the necessary documentation in relation to the height limiter[12] on the excavator. The recipient advised the excavator operator that they required additional information on the state of the planned closure before they could grant access to the rail corridor. The recipient then travelled back to the work group entrance gate.
At 0051, as the recipient arrived back at the work group entrance gate, the TOA was reinstated. The team leader communicated an instruction to the work group ‘it’s on’, by which they meant the TOA had been reinstated and tools and equipment could be transferred from the work truck into the front-end loader.
On-tracking of the excavator
The recipient heard the team leader’s instruction and witnessed the work group loading the front‑end loader and assisted with the loading. Soon after, the operator of the front-end loader gave the recipient the height limiter key, which was a requirement before machinery could perform work on track under live overhead equipment. In interview, the recipient stated that the combination of these events gave them the impression that the planned closure was now in force.
In the belief that the planned closure was now active, the recipient contacted the electric control officer[13] (ECO), in accordance with procedures, to inform them about the location of the worksite and the number of machines (excavator and front-end loader) at the worksite.
Without seeking or receiving confirmation from the relevant personnel (team leader, supervisor, or PO) on the state of work and protection arrangements, the recipient travelled back to meet with the excavator operator at the (excavator) entrance gate. The recipient informed the excavator operator that the planned closure was active and that they could on-track the excavator, and the recipient unlocked the access gate.
Meanwhile, at the work group entrance gate, the team leader instructed all the workers there to stand down. At 0102, the lead PO, who was unaware that the recipient had directed the excavator operator to on-track the excavator, suspended the TOA and advised the NCO that preparation work was complete and there would be no further work until the planned closure at 0218. On receipt of the suspend code,[14] the NCO suspended the block,[15] and then set the signal path for a suburban passenger train (1898) to travel from Thorneside to Cleveland (eastward).
Shortly after the TOA for the preparation work was suspended, the excavator was driven into the rail corridor and, with the aid of its boom arm and bucket, the operator pulled the upper frame of the excavator onto the track and placed its guide wheels on the running tracks. The recipient advised the excavator operator to proceed towards Thorneside where they would be met. The recipient then returned to the work group entrance gate by car.
Track fault
At 0106:55, while train 1898 was stationary at Thorneside Station, the signalling system detected a track section between Thorneside and Birkdale was occupied. This detection momentarily generated a ‘failed track’ message on the monitor of the NCO’s workstation. At 0107:01 the track recovered, and at 0107:19[16] the passenger train departed the station.
As the indication of the failed track was in the vicinity of the work group, it prompted the NCO to contact the lead PO and question the whereabouts of the work group and machinery in relation to the running line. The NCO asked the PO if anyone in the work group had ‘gone on or near the track’, to which the PO replied ‘no’. The NCO further stated, ‘I’ve had a track fail and recover, which is most unusual, within the extremities of your TOA … which seems a bit odd’.
The lead PO ended the conversation by reassuring the NCO that everyone in the work group was off the track. At this time, the PO was unaware of the excavator’s movements and that it had on‑tracked as directed by the recipient.
First near collision
As train 1898 passed the work group entrance gate, it accelerated to above 90 km/h along the 100 km/h section of track (Figure 2). The recipient, who only minutes earlier directed the excavator operator to on-track the excavator, had just arrived back at the work group entrance gate as the train passed. On seeing the train, the recipient sounded the car horn in an attempt to warn the excavator operator of the approaching train, and they then proceeded in the car back towards the excavator.
Figure 2: View from train 1898 showing the work group, front-end loader, and headlights of the excavator in the distance
The image is from the front-of-train camera in train 1898. The time is 0108:22, about 19 seconds prior to the near collision. In the distance, the headlights of the excavator can be seen as it travelled towards the worksite.
Source: Queensland Rail, annotated by the ATSB
The excavator operator first noticed the train’s headlights in the distance and assumed that they belonged to other machinery at the worksite. They had not heard the car horn.[17] At about the same time, the train driver observed the lights of the excavator, which they thought belonged to a car travelling on the road adjacent to the rail corridor.
As train 1898 traversed the sweeping left curve between the 2 entrance gates (Figure 1), both the train driver and the excavator operator realised that there was an imminent risk of collision. The train driver immediately applied the emergency brake, while the excavator operator swung the boom arm about 90° to the right of the excavator’s direction of travel, gouged the bucket into the ground and dragged the excavator from the rail tracks just prior to the train passing at about 61 km/h (Figure 3).
The excavator came to a stop clear of the running tracks. However, it was still in the (3 m) danger zone, less than 1 m from the nearest rail.
Figure 3: View from train 1898 showing the near collision
The images, from 1898’s front-of-train camera, are in sequential order and show the near collision between 1898 and the excavator. The rear of the excavator moved clear of the running line less than 1 second before the train’s arrival, with the train travelling at about 61 km/h.
Source: Queensland Rail, annotated by the ATSB
After stopping (about 75 m past the excavator), the driver of 1898 contacted the NCO and reported that they had almost collided with a ‘tractor or backhoe’ that was on the track.
The NCO then called the lead PO and described what the train driver had reported and made further inquiries as to whether a backhoe or loader was at the worksite. The PO advised the NCO that there was a front-end loader at the worksite, but it was well clear of the track when the train passed. The NCO then asked the PO if there was any other machinery at the worksite, to which the PO replied, ‘we only have one machine that’s it … and I’m standing right next to it’. Further discussion between the PO and NCO considered the possibility that another machine had on tracked near the worksite.
After finishing the call, the lead PO informed the depot supervisor of the situation. The supervisor stated that they had just received a call from the recipient explaining how they had directed the excavator operator to on-track as they thought that the planned closure was active and train activity had ceased.
At 0116, the lead PO contacted the QR ‘emergency hotline contact’ (located at the network control centre) and reported the near collision. As the PO was not located at the incident site, they provided details to the hotline contact as received from the supervisor, who was in direct communication with the recipient at the incident site.
The emergency hotline contact asked the lead PO ‘… has he moved away from the track’, referring to the excavator. The PO then relayed this question to the supervisor. The supervisor, after consulting with the recipient, confirmed that the excavator was away from the track, and this information was relayed on to the hotline contact. The emergency hotline contact then told the PO to leave the excavator where it was as the incident was going to be investigated. That message was then relayed to the depot supervisor, who passed it on to the recipient. During these communications, it was not made clear to any party that although the excavator was no longer on the track, it was still within the danger zone.
At the network control centre, the NCO was informed (by the emergency hotline contact) that the excavator had been moved away from the running tracks. After checking the welfare of the train driver, the NCO authorised the train’s movement from the incident site.
The depot supervisor, who had been in contact with their off-site manager regarding the incident, advised the lead PO that work was cancelled and that they were required to travel to the Cannon Hill depot for drug and alcohol testing. The depot supervisor then had another conversation with the recipient, who confirmed that the excavator was off track but may still be in the danger zone. The depot supervisor then travelled to the incident site to assess the situation (Figure 1). The PO discussed the supervisor’s directive with another member of the work group and then decided to travel to the incident site rather than returning to the Cannon Hill depot, as it was their role to oversee the protection of workers within the rail corridor.
Second near collision
When the depot supervisor arrived at the incident site, they noticed the excavator was still in the danger zone although they believed it was not within the profile of a train. The supervisor, without gaining the necessary authority from the NCO (via the PO), instructed the excavator operator to move the excavator from the danger zone. The supervisor later reported that they assumed that after a near collision, the NCO would have stopped all trains, but they did not confirm that this had occurred.
At 0136:22, the next suburban passenger train en route to Cleveland (18A0) departed Thorneside Station.
As the excavator operator moved towards the excavator, in accordance with the supervisor’s instruction, they heard a member of the work group call out ‘train on’. The excavator operator stated that, after seeing the train, they jumped down the embankment and clung to the fence as they thought the train may collide with the excavator. The train passed by the incident site at about 60 km/h.
At 0137, the driver of 18A0 contacted the NCO and reported ‘… the excavator was only just clear of the track, I thought I was going to clip it’.
After 18A0 had cleared the area, and without requesting the necessary protection, the excavator operator was again directed to remove the excavator. On this occasion, members of the work group cut a gap in the fence and the excavator was removed from the rail corridor.
After receiving advice of the second near collision, the NCO contacted the lead PO regarding the location of the excavator and its proximity to the running track. The PO advised the NCO that the excavator had been removed from the rail corridor and the work group were returning to the Cannon Hill depot for drug and alcohol testing.[18]
Context
General information of planned closure
Track defect
A track inspection in 2019 identified a track defect just east of Thorneside Station. Work to rectify the defect involved the replacement of a 5 m section of track, which involved cutting and welding. As dry weather restrictions were in place at the time, the work was deferred until the restrictions were lifted.
Train notice
On 28 February 2020, a train notice (TN20-02366) was issued that detailed the planned closure and work required to correct the track defect. The train notice included information such as:
the date of the planned work – 7 March 2020
the depot of the work group performing work – Cannon Hill
the protection for the worksite – track occupancy authority (TOA) with in-field protection
the extent of protection – main Cleveland line between signal L294 and signal TS9 Thorneside and No.2 road from signal TS11 to 656 points Thorneside (in effect from Thorneside Station east towards Birkdale Station)
the name and contact details of the assigned protection officer (PO).
The train notice also specified the type of plant (machinery) that was permitted to work within the TOA, which consisted of a front-end loader and an excavator. In addition, it noted that rail traffic would be suspended on the main line from Birkdale to Thorneside for maintenance work between 0218 to 0440. No trains would normally be running on the line during this period.
The purpose of the train notice was to inform relevant rail personnel of the details associated with the planned work and the impact that it would have on operations and advise those who needed to plan for the proposed closure.
The train notice did not mention that preparation work would be conducted under the protection of a TOA without in-field protection, as this arrangement was initiated after the train notice was published and as a result of some staff reporting sick during the day of 6 March.
Planned closure protection
In the scheduling phase of the planned closure, a TOA with in-field protection[19] was the chosen ‘work on track authority’[20] to protect workers within the worksite. It was selected because repairing the track defect involved breaking and obstructing[21] the track. In addition, machinery and members of the work group were required to work within the danger zone. This option was determined as an efficient and safe means of protecting the work group when performing such work.
To implement the TOA with in-field protection, the PO needed to coordinate with the network control officer (NCO) so that the NCO applied blocking facilities to prevent unauthorised rail traffic entering the portion of track within the TOA limits. Additionally, the PO or their delegate was to organise in-field protection at the limits of the TOA or at a defined distance from the worksite after blocking facilities were in place.
Two POs had been allocated to the planned work, with a QR employee assigned the role of lead PO and a contractor the role of assistant PO (to organise the in-field protection).
The protection arrangements (TOA with in-field protection) for the planned closure on 7 March was appropriate for the type of work involved in removing and replacing the section of track at Thorneside.
Preparation work prior to planned closure
Reason for preparation work
On 6 March, the day prior to the planned closure, the assigned lead PO and one of the 2 assigned welders reported sick. To fill the role of the lead PO, the contractor PO who had already been assigned the role of erecting in-field protection was elevated to the role of lead PO, and another contracted worker was engaged to erect the in-field protection for the planned closure. During the afternoon, both POs were advised to meet the QR depot supervisor at the Cannon Hill depot at 2200 to discuss protection arrangements for the worksite.
A replacement welder, however, could not be found at short notice, which placed pressure on the work group completing the work within the available timeframe. To remedy this problem, there was a proposal to start preparation work earlier than the scheduled start time listed on the train notice. This involved gaining access to the rail corridor, under the safeguard of a TOA without in-field protection, to perform the preparation work prior to the planned closure. The proposal required approval from the NCO overseeing the area where the preparation work was planned.
Preparation work protection
The QR document MD-12-189 (Queensland Network Rules and Procedures or QNRP) stated the safety requirements for all persons required to access and perform activities on QR’s rail corridor.The QNRP allowed for work within the danger zone under the safeguard of a TOA without in-field protection provided there was no requirement to break or obstruct the track. The preparation work prior to the planned closure did not require the track to be broken or obstructed.
At the worksite, and prior to requesting the TOA without in-field protection, the lead PO completed a ‘corridor safety planner and assessment form,’ which determined the protection was adequate for the proposed work arrangements. The PO contacted the NCO, who issued the TOA without in‑field protection to perform the preparation work between train movements prior to the planned closure.
During the preparation work, the lead PO and the NCO were suspending and re-instating the TOA without in-field protection as required between train movements. When the TOA was active:
The NCO was applying blocking facilities to prevent unauthorised rail traffic entry into the portion of track within the limits of the worksite.
The lead PO’s role was to inform the work group that protection was in place and work could be performed within the danger zone. Immediately prior to suspending the TOA, the PO’s role was to ensure workers were clear of the danger zone and in a safe place.
Under the requirements for a TOA without in-field protection, a ‘lookout’[22] was required if the track speed approaching the worksite was 100 km/h and there was less than 560 m minimum sighting distance. The track speed approaching the worksite from the west was 100 km/h and the sighting distance was about 350 m. Therefore, a lookout was required as an additional safety measure at the worksite. The ATSB identified that there was no ‘lookout’ in place at the worksite while the preparation work was conducted. Although this omission did not comply with the procedure, it did not contribute to the first near collision.
Worksite and rail corridor information
The worksite was about 500 m east of Thorneside Station, on the Cleveland rail corridor branch line (Figure 1). The branch line, which commenced at Park Road Station, serviced the south‑eastern suburbs of Brisbane. Between Park Road and Manly stations there were 2 suburban unidirectional running lines with some bi-directional signalling to facilitate the passing of trains. The main line east of Manly (which included Thorneside and Birkdale stations) had a single bi-directional running line that continued through to Cleveland Station.
Steep slopes on either side of the rail corridor prevented direct access to the worksite. To reach the worksite it was necessary for the work group to enter the rail corridor through the entrance gate about 340 m further east.
The excavator could not access the rail corridor through the same entrance gate as the work group, as cement troughing blocked its entry. Therefore, it was necessary to transport the excavator to the entrance gate about 470 m further east of the entrance gate used by the work group (Figure 1).
Rail network safety
Responsibilities of track workers
The QNRP referred to track workers as ‘Competent rail safety workers whose primary duties are associated with work on or around infrastructure in the Rail Corridor.’ It stated:
Track workers’ responsibilities may include:
• performing track maintenance or construction work under supervision
• supervising track maintenance or construction work groups
• coordinating track maintenance or construction work groups and associated rail traffic in liaison with the Network Control Officer
• operating track machinery
• obtaining Authorities
• determining safety measures required for occupation of track
• managing worksite protection.
The QNRP also stated:
Work planned for the Rail Corridor must be assessed for safety and its potential to intrude on the Danger Zone.
No one can enter the rail corridor without:
• being accredited as a Protection Officer or being supervised by a Protection Officer
• contacting the relevant Network Control Officer or their delegate prior to entering the rail corridor and advising of their entry.
The deport supervisor, team leader, and recipient confirmed that prior to accessing the rail corridor under a TOA, the PO would obtain access authority and then inform the work group leader, who would then instruct other workers that they could access the rail corridor.
When dealing with a track vehicle needing to access or travel within a TOA, the QNRP stated:
Track vehicles associated with a… Track Occupancy Authority [TOA], entering or moving within the limits of the… Track Occupancy Authority must:
• be piloted, or
• receive written instructions from the Possession Protection Officer or Protection Officer.
Work group information
The QNRP defined a work group as:
One or more workers who function as a team to undertake a common task, within the Rail Corridor and/or Danger Zone under the authority of a Workgroup Supervisor and have their own prestart briefing.
Track workers must only perform work relevant to their competency qualifications. The work group assigned the task of repairing the track defect at Thorneside were appropriately qualified to perform relevant rail safety work applicable to their area of competence.
Supervisor information
The responsibility of a work group supervisor / team leader was to ensure there were sufficient qualified workers to complete the work within the time available. This included:
ensuring workers were appropriately qualified and competent to perform work
ensuring the necessary tools, equipment and machinery were available for workers to complete work tasks
having contingency plans in place if the work could not be completed in the scheduled time
ensuring that all work group members participated in the network pre-start briefing.
At a worksite, the supervisor / team leader was required to:
actively oversee and communicate with work group members to ensure the work was progressing as planned
communicate with the PO to ensure protection arrangements were adequate for the protection of the work group
assist as required at the worksite and comply with the rules and procedures relevant to QNRP.
The supervisor of the work group involved in the near collision at Thorneside gained employment with QR in July 2012 and held positions in several roles, all within track maintenance operations. At the time of the incident, their role was acting supervisor at the Cannon Hill depot. Their role at the worksite was to oversee the work and supervise the team leader and others as required.
The supervisor attended training courses and successfully gained numerous rail safety qualifications applicable to rail safety work. Training and critical safety alerts relevant to this incident included:
Communication protocols
Communications (QNRP)
Safely access the rail corridor (QNRP)
Protection officer 1 (QNRP)
Protection officer 2 TOA (QNRP)
Critical safety alert: Follow instructions respond to emergency
Critical safety alert: Entering the danger zone
Critical safety alert: Communication safety critical information
Emergency response
Safety critical communications
Delivering a pre-start briefing (network)
Rail safety awareness
Toolbox talk: Safeworking incidents
Plan and organise work
Operate under track protection
Process workplace documentation
Follow work health and safety
Perform lookout duties
Awareness safeworking rules.
Safety comes first always workshop.
On the day of the near collisions, the supervisor was overseeing the team leader, who was acting as the supervisor in charge of the work group.
The supervisor had been working day shifts until 5 March and had over 30 hours free of duty prior to signing on for the overtime shift at 2100 on 6 March. They reported that they had a nap on the afternoon of 6 March before going to work, and they did not feel fatigued at the time of the incident.
Team leader information
The team leader worked as a track maintainer with a rail contract company for about 3 years prior to gaining employment with QR in September 2016. Through internal training, the team leader acquired rail safety qualifications appropriate to their employment in network maintenance operations. They had recently undertaken the role of acting team leader. Training relevant to this incident included:
Safely access the rail corridor (QNRP)
Communications (QNRP)
Protection officer 2 TOA (QNRP)
Protection officer 1 (QNRP)
Network lockout workshop
Toolbox talk: First worker at emergency site
Delivering a pre-start briefing (network)
Toolbox talk: Post incident management guideline
Rail safety awareness
Follow occupational health and safety
Process workplace documentation
Lead a work team or group
Perform lookout duties
Safety comes first always workshop.
On the day of the incident, the team leader was acting as the supervisor under the guidance of the depot supervisor. The team leader delivered the network pre-start briefing at Cannon Hill depot and oversaw the work group and work activities associated with the replacement of the defective section of track.
The team leader had been working day shifts until 5 March and had over 30 hours free of duty prior to signing on for the overtime shift at 2100. They reported that they had a normal sleep on the night of 5 March and a nap on the afternoon of 6 March before going to work, and they did not feel fatigued at the time of the incident.
Protection officer information
The QNRP stated that the primary duty and responsibility of the PO was to manage the rail safety component of a worksite, and that the PO must be satisfied other work will not interfere with their primary duties. A worksite in the danger zone, or a worksite with potential to intrude into the danger zone, was required to have a PO for the duration of the work.
Specific planning duties of a PO included:
investigating the location of the worksite
having a detailed work plan
completing a safety assessment to determine the work on track authority, means of protection[23] or safety measures[24] needed to protect workers
meeting with the supervisor of the work group to discuss safety and protection arrangements
providing worksite protection details for the worksite safety briefing
participating in the network pre-start briefing
contacting the NCO if necessary.
Specific duties at the worksite included:
communicating with the NCO about the work
ensuring the appropriate protection had been selected to protect the work group at the worksite
identifying the safe place (for workers at the worksite)
advising the supervisor / work group when it is safe to enter the rail corridor / danger zone
immediately prior to suspending a TOA ensuring workers cease work and remain clear of the danger zone
keeping records about the work on track method and protection arrangements.
The lead PO involved with the track work near Thorneside held the appropriate competencies to administer TOA protection. The PO had worked for contract providers while performing the role as a PO for more than 3 years. They had worked on the QR network many times but had not previously worked at Thorneside. On the day prior to the planned closure, the PO was advised by a QR representative that they would be the lead PO and to meet the depot supervisor at Cannon Hill depot at 2200 to discuss protection arrangements for the planned work at Thorneside.
The assistant PO was not involved in any work activity related to the preparation work. Their role was to place in-field protection after the preparation work was completed and prior to the commencement of the planned closure.
Excavator operator information
The role of the excavator operator during the planned closure was to move the replacement piece of rail from within the rail corridor to the worksite. At the worksite, they were required to remove the defective rail and fit the replacement rail into place so it could be welded. In addition, they were required to comply with rules and procedures applicable to working safely within the rail corridor.
The excavator operator was employed by an external provider as a sub-contractor providing services to QR as required. They were advised to meet a QR representative at Thorneside Station at 2230 on 6 November, who would direct them to the worksite.
The excavator operator was qualified to operate the excavator and held the relevant competencies to work within the rail corridor and danger zone. They had worked in the earthmoving industry for many years and owned an earthmoving business for 11 years. The excavator operator stated that they had worked excavators at QR worksites on multiple occasions but had not previously worked at Thorneside.
Recipient information
The role of ‘recipient’ was previously known as ‘authorised person’ until a recent name change. Although the title of the role had changed, the responsibilities remained the same.
In accordance with QR’s authorised person [recipient] facilitator guide (FG-STD-141-01), the authorised person [recipient], working in QR’s 25,000 volts electrified area, was a qualified and competent worker who:
• needs to be aware of the inherent hazards (high voltage electric shock) and risks associated with undertaking work activities in and around the three (3) metre Electrical Exclusion Zone within the Electrified area.
• supervises (and may also perform) the electrical safety aspects of the work when the work could come closer than three (3) metres of the Overhead Line Equipment.
• accepts Forms [associated with the isolation of the Overhead Line Equipment].
• stays on site while work is being done.
• is appointed by line management to take charge of a specific worksite in the electrified area.
• holds an ‘Authorised Person’ Card, confirming competency.
On the day of the incident, the recipient’s role was to ensure the excavator and the front-end loader did not encroach into the electrical exclusion zone while working under the overhead line equipment at the worksite. This involved completing the relevant documentation with the machine operators and ensuring the height limiter on each machine was engaged prior to working under the overhead line equipment.
As required, the recipient was to interact with and discuss relevant information with the PO at the network pre-start briefing and at the worksite to ensure safety. The recipient could also perform other work tasks at the worksite, providing they were qualified to do so and that the work did not interfere with their primary duties and responsibilities. During the planned closure on 7 March, the recipient was also required to act as the mobile plant spotter,[25] which involved separating the excavator and front-end loader from workers at the worksite.
According to QR’s safe work method statement (SWMS) work activity MD-13-268 (Operation of height limited plant), the recipient was required to establish communication processes with machine operators and these processes had to be incorporated in the network pre-start briefing. The recipient was to observe and supervise the plant operations with full visibility and communication. To ensure this means of communication was operating as intended, they were required to confirm the radio channel and test the radios with each mobile plant operator.
On the day of the incident, the recipient (acting as the mobile plant spotter) was not in possession of a radio when they directed the excavator operator to on-track the excavator and therefore was not able to contact and alert the excavator operator of the approaching train. Channel 15 was recorded in documentation associated with the network pre-start briefing as the radio channel for machine operators to use. However, the recipient did not advise the excavator operator of which channel to use. The excavator operator had set their radio to channel 15 as this was the preferred channel when working on QR worksites (Excavator information).
The recipient had worked in rail maintenance operations as a QR employee for about 3 years. Prior to working for QR, they were employed by a railway construction contractor performing rail safety work. The recipient had gained numerous rail safety qualifications and attended operational training courses that enabled them to perform rail safety work. Training relevant to this incident included:
Safely access the rail corridor (QNRP)
Communications (QNRP)
Safety comes first always workshop
Delivering a pre-start network briefing
Rail safety awareness
Authorised person
Working in the electrified territory
Process workplace documentation
Operate under track protection
Follow work health and safety
Lead a work team or group
Perform lookout duties
Protection officer 1 (QNRP)
Safety comes first always workshop.
Two days prior to the incident, the recipient attended a training course that provided them with recipient qualifications. The recipient attended the course on 4 and 5 March (0800–1600), before having 31 hours free of duty and signing on for work at 2100 on 6 March. The maintenance work at Thorneside on 6–7 March was the first time they had acted in the role of recipient since gaining the qualification. They had previously performed the role of mobile plant spotter.
The recipient noted that normally they would seek confirmation from the team leader / supervisor before directing a vehicle to on-track but on this occasion, they did not do so because they thought they had understood the situation. The recipient also noted that normally all the workers accessed the rail corridor from the same location, whereas on this occasion the excavator being at a different location added some complexity. The recipient also noted that in their experience it was normal for all the workers (including the POs) to be at the same briefing whereas on this occasion the briefings were distributed.
Network pre-start briefing
The QR procedure Network Pre-Start Briefing (MD-12-87) defined a network pre-start briefing as:
A communication and on-site activity planning session undertaken prior to the commencement of work or an activity.
The Network Pre-Start Briefing should involve all workers, contractors, and / or visitors involved or exposed to, the work to be undertaken.
The purpose of a network pre-work briefing was to provide an opportunity for the work group to gain an understanding of the work, roles, and responsibilities of individuals, and provide an environment where questions relating to the work and worksite protection could be asked and answered. The briefing, and its associated form (MD-15-43), provided the framework to ensure hazards were identified, risks were managed, and relevant personnel at the worksite had the appropriate delegation to authorise safeworking decisions.
The QNRP and QR guidelines required the nominated person[26] (in this case the team leader) to deliver the network pre-start briefing before starting work (with a briefing to be conducted for each work activity). MD-12-87 stated the nominated person was to ‘gather all workers and contractors involved in the work to be undertaken’ and explain the activities that were to be completed and how it would be undertaken. Where safeworking requirements existed (for work in the rail corridor), these were to be discussed by the PO.
The nominated person was also required to compile and complete the appropriate network pre‑start briefing form. In addition, they were required to ensure that all identified workplace health and safety and rail safety hazards associated with the work and equipment had appropriate controls in place to manage and or eliminate risk. Each worker / contractor was to have the opportunity to identify any additional hazards or controls, and each worker and contractor was required to sign the briefing form.
The PO’s role at the network pre-start briefing was to inform all workers about the protection in place at the worksite and the limits of the protection. In addition, they were to answer any questions related to protection and worksite arrangements.
Although a planned network pre-start briefing occurred at the Cannon Hill depot on 6 March 2021, delivered by the team leader, the POs and the excavator operator were not invited to the briefing and therefore did not participate in the briefing.
In interview, the recipient stated that a second network pre-start briefing occurred at the worksite prior to entering the rail corridor at Thorneside. This however was not a network pre-start briefing, but rather a briefing to advise the work group that protection was in place for the preparation work and when they could enter the rail corridor and the danger zone. The team leader confirmed that a network pre-start brief did not take place at the worksite.
To assist the investigation, the ATSB interviewed a QR subject matter expert who designed and delivered training for track workers, including POs. In relation to the planned track maintenance work at Thorneside, it was their view that all members of the work group, including the lead PO, assistant PO, and excavator operator, should have attended the network pre-start briefing at the Cannon Hill depot.
Network pre-start briefing form
After a fatal accident in Brisbane in May 2017 (see Previous network occurrences), QR revised and developed a new network pre-start briefing form (MD-15-43) specifically for staff who delivered and participated in network pre-start briefings. The formcontained 6 sections that had to be completed by the nominated person before work commenced at a worksite.
The purpose of the revised network pre-start briefing form was to establish a consistent process for the delivery of a network pre-start briefing and provide a workplace focus on the identification, treatment and communication of both task and site-specific risks. QR developed a facilitator’s guide for trainers, and specific training was provided to rail safety workers who had a responsibility to deliver network pre-start briefings.
The network pre-start briefing form for the work at Thorneside on 6–7 March 2020 was completed by the team leader. Content in the form relevant to this incident included:
Section 1 – This section briefly required details for the work group, the person in charge (in this case the team leader), and the work task (requiring a clear description, SWMSs and permits used). The completed form listed 3 SMWSs but no description of the work task was provided.
Section 2 – This section listed several specific items and sought brief information regarding the process in place for each item.
In response to the question ‘Is the work occurring within the Rail Corridor?’, a box was ticked for the answer ‘Yes – Protection Officer to provide a brief on the track protection requirements’.
In response to the question ‘Is there potential for mobile plant or equipment (including vehicles) to contact people, infrastructure or other plant?’, a box was ticked for ‘Yes – detail the site plan for the separation of people and plant in your briefing…’.
Section 3 – With regards to a site sketch, a train signal diagram for Thorneside with annotations was appended to the form. The diagram showed (in broad terms) the area of the worksite and the travel path that machinery would be using. The travel path did not explicitly indicate that different machinery would be using different access gates (as that had not been determined prior to or during the briefing). The type of machinery using the travel path was not noted.
Section 4 – The form required a list of site-specific hazards and controls. The completed form included several hazards and controls, including:
With regard to the hazard ‘Trains’, it listed ‘Blocks, Lookout’ as the applicable controls. There was no record in the briefing form that there would be 2 phases of work (preparation work and the planned closure work), each with different protection arrangements.
With regard to the hazard ‘Machinery’, it listed ‘Separation, spotters’ as the applicable controls. There was no indication on the form of the types of machinery that would be used (and no mention that an excavator would be used).
Section 5 – This section contained details of what needed to be done if something changed. It included instructions for a ‘Pause and Re-start’ in the event of workers being unprotected, there was a change to the condition / task or a new hazard / risk was identified. Details of any debrief could be included on the form (and in this case it was blank). The instructions for a pause and re-start included:
Immediately pause the work we are doing;
Move to a safe place, and ensure any plant or equipment is moved clear of the Danger Zone and is protected;
Document the new hazard / risk and list the controls (using Section 4); and
Communicate the controls to everyone onsite by conducting a ‘Restart Briefing’.
Section 6 – This section (titled ‘Commitment to work safely’) asked workers to sign the form as acknowledgement that they had ‘taken the opportunity to ask questions and thoroughly discuss this briefing, so you can implement the controls agreed to protect you and your co-workers’. With regard to the completed form:
The work group members who attended the briefing at the depot signed the form at the depot.
The 2 POs and the excavator operator did not attend the briefing at the depot, however their signatures were recorded on the form. The excavator operator signed the form at the worksite at the request of the team leader. Both POs signed the form after returning to the Cannon Hill depot after work at the worksite had been cancelled as a result of the near collisions.
The supervisor’s signature on the network pre-start briefing form was listed after the excavator operator and the lead PO. The supervisor (and another worker) confirmed they were at the briefing at the depot, but the supervisor did not sign the form at that stage.
Network communication
QNRP rule 2007 (Network communications) and QNRP procedure 2008(Spoken and written communication) provided information for rail safety workers relevant to safeworking communication, general communication protocols and communication equipment.
Rule 2007 referred to effective communication as the ability to successfully send, receive and understand information. It stated that communication in the network must be:
clear, brief and unambiguous, and
relevant to the task at hand, and
agreed as to its meaning before being acted upon.
In general, the rule provided information on the principles, fundamentals, and protocols of network communication. It noted that emergency communications needed to commence with the phrase ‘emergency, emergency, emergency’. It also detailed specifics relevant to spoken and written communication in the context of electronic transmissions. However, it did not specify the requirement to use rail industry specific terminology when communicating safety-critical information, either electronically or face-to-face.
QNRP procedure 2008 provided standard terms to be used in radio communications, including using the term ‘out’ when the transition was complete and the term ‘roger’ meaning the information had been received and understood. Like the rule however, there was no guidance to rail safety workers on the use of rail-specific terminology when communicating safety-critical information, either via electronic devices or face-to-face.
In the context of the work and near collisions at Thorneside, rail-specific terminology used in communication should have included terms such as:
Conversely, the Rail Industry Safety and Standards Board’s (RISSB’s) Safety critical communications guideline (2018) stated in a section on fundamentals of communication:
• Where practicable, avoid the use of acronyms and words with alternate meanings… but do use common technical terms used in the industry…
The guideline noted such principles should be applied to all communications, safety critical or not.
The RISSB guideline also stated:
That communications, or the failure thereof, contribute to incidents is not doubted. The exact extent is not accurately established but studies put the rate at approximately 30% across all incident events, with something in the region of 50% in relation to all track work incidents.
Within Australia, one major rail network carried out their own studies and they found that, in an examination of their incidents, a significant number of all incidents had communication as a root cause.
The main factors contributing to these incidents comprised of:
• Lack of Communication;
• Poor Communication; and
• Incorrect Information being passed on.
Train and excavator information
Trains 1898 and 18A0 information
Both trains (1898 and 18A0) were scheduled suburban passenger services travelling between Shorncliffe and Cleveland via Central Station. Train 1898 consisted of suburban multiple units (SMUs) 227 and 229, and 18A0 consisted of an interurban multiple unit (IMU) 166 and SMU 285. Both trains were crewed by a driver and guard and had passengers on board.
Trains 1898 and 18A0 were fitted with event recorders and front-of-train cameras. Relevant information from these recordings has been included in other sections of this report.
Excavator information
The excavator involved in the near collisions was a Kubota CRV032 (Figure 4). It had an operating weight of 5 t and was fitted with small, retractable rail wheels enabling it to mount and operate on the running tracks.
The maximum speed of the excavator while on track was 4 km/h. It had an R3[32] detection rating, which meant the vehicle did not reliably operate track circuits; as a result, the vehicle was not detected by the signalling system and was not visible on the NCO’s workstation monitor. The boom arm was fitted with a height limiter allowing it to work under live overhead line equipment.
According to QR standard MD-14-575 (Road Rail Vehicles), the excavator was classified as a ‘road rail vehicle’ and was only allowed to operate within track closures. The QNRP categorised a road rail vehicle as a track vehicle. In accordance with the QNRP, permission had to be obtained from the PO before a track vehicle could enter a work on track authority (such as a TOA) or traverse a worksite within a work on track authority. On the day of the incident, the excavator was on-tracked at Thorneside without the permission of the PO.
Australian Standard (AS) 7502:2016 (Road Rail Vehicle) stated that a flashing beacon light shall be mounted on the top of the vehicle, or in a suitable location(s), so that the light is visible to a person standing 4 m in any direction from the vehicle on level ground. In addition, the flashing beacon light was required to be activated while the vehicle was operating on-track in rail mode. Although the excavator involved in the near collisions was fitted with a beacon capable of flashing, video footage showed that it was not active at the time of the near collisions.
In general, where people and mobile plant (machinery) share the same worksite, there should be radio communication between the plant operator and the mobile plant spotter / supervisor. The excavator was fitted with a UHF radio, which was set to channel 15 when it was placed on-track. The excavator operator said that channel 15 was QR’s preferred channel for maintenance work communication and they had been told to use this channel at other QR worksites.
In interview, the excavator operator stated that after the first near collision they transmitted a call over the radio but communication with the work group was unsuccessful. The team leader reported that they heard a radio call on channel 15 including the word ‘train’ but did not know who had made the call and the call did not make sense (as they were not aware that the excavator operator had on-tracked). They asked the person to repeat the message but heard no reply.
Figure 4: Excavator involved in the near collisions
Source: Queensland Rail
Related occurrences
Introduction
This section provides information about a selection of rail occurrences that involve problems with the briefing of rail workers prior to them undertaking work on track. The list is not exhaustive. Each of the occurrences involved a range of different factors, and the descriptions below focus only on aspects that have some relevance to the incident at Thorneside on 7 March 2020.
Mindi, Queensland, 2007
On 7 December 2007, 2 QR workers were fatally injured as a result of being struck by a track machine when carrying out their duties at Mindi, Queensland. The Queensland Transport Rail Safety Investigation (QT2140) stated that worksite safety briefings [network pre-start briefings] were not performed prior to starting work. It also noted that work group members did not challenge the absence of a worksite safety briefing.
One of the recommended safety actions from the investigation noted:
QR take the necessary steps to ensure that Worksite Safety Briefings are conducted in accordance with the Track and Trackside Safety Manual SAF/ STD/0038/SWK [currently MD-12-189, QNRP] and in particular the requirement that:
a. A TPO [PO] is nominated and present before workgroups commence work at a worksite on or near the track; and
b. Worksite protection methods are determined and communicated including when additional workers or workgroups join a worksite.
A coronial inquest into the Mindi accident noted that the absence of a worksite safety brief [network pre-start briefing] was most likely a contributing factor to the death of the 2 workers.
At about 1116 on 5 May 2010 a collision occurred between an XPT passenger train and a track‑mounted excavator near Newbridge, New South Wales. The operator of the track-mounted excavator was fatally injured.
The PO had conducted a pre-work brief involving the excavator operator and a hot-work labourer, during which a TOA was identified as the control in place for rail traffic. After obtaining a TOA from the NCO, the PO then advised the excavator operator and the hot-work labourer that the TOA had been obtained and that they could prepare for work while the PO put the site protection in place. A short time later both the hot-work labourer and excavator operator entered the danger zone before the worksite protection arrangements (detonators and flags) had been put in place.
An examination of the pre-work briefs found that the identified hazards were mostly related to general issues (for example, slips trips and falls and hazards associated with work equipment such as the excavator or oxyacetylene cutting). The only mention regarding the hazard of potential rail traffic identified the TOA as the relevant risk control. There was no mention of unexpected approaches of other rail vehicles and the use of additional site protection.
The excavator operator and hot-work labourer were relatively inexperienced. The ATSB found that, although the PO had told the excavator operator and hot-work labourer that the PO had received the TOA, they did not explicitly communicate to the workers that they should not occupy the danger zone until all site protection measures were put in place.
On 28 March 2011, a freight train 7SP3 collided with a track mounted excavator between Jaurdi and Darrine, Western Australia. The train driver sustained a minor injury. There was significant damage to the lead locomotive and the excavator, and minor damage to the track as a result of the accident.
The ATSB found that 2 track mounted excavators had been placed back on the track without permission of the authorised employee responsible for the coordination of track side safeworking activities between Jaurdi and Darrine. Another finding was that, although separate pre-work briefings were conducted, there was no discussion about train running information and site protection between the supervisor of the excavators and the authorised employee (who was the supervisor of the track machines at another location).
On 2 October 2015, a train departing Laverton Station approached a worksite where a supervisor was marking a track to identify dog spikes to be removed, with a lookout for their protection. The lookout observed the train, warned workers of its approach, and signalled to the driver that the track was clear. However, as the train took the crossover, the supervisor was foul of the track, and was struck by the train that was travelling at about 59 km/h. The supervisor suffered serious injuries.
The ATSB found that the pre-work briefing was not conducted. As a result, the supervisor and lookout (and others in the work group) did not receive the benefits of a safety briefing that would have informed them of the outcomes of the worksite hazard assessment, train running, and the designated position of safety.
On 18 June 2016, a signal maintenance team (SMT) worker was fatally injured by a train at Clyde, New South Wales, while working in the rail corridor. The ATSB investigation (conducted by the NSW Office of Transport Safety Investigations) identified a number of contributing factors and other factors that increased risk. Safety factors related to pre-start briefings included:
The PO had briefed the civil team, however they did not brief the signal team, and the signal team did not seek a pre-work briefing before commencing work on-track.
The signal team assumed their workplace was within the limits of the TOA and did not plan their own worksite protection…
The Sydney Trains worksite briefing process did not compel a new work group to seek a worksite protection pre-work briefing when accessing an existing worksite. The safety message from the ATSB report noted:
This accident highlights the importance of planning and integrating safety across the entire scope of work. It also highlights the importance of briefing all workers and all workers seeking a safety briefing about the worksite protection plans before work commences and when circumstances change.
The investigation report also included a finding relating to network communications between multiple parties not being ‘clear, brief and unambiguous.’
In May 2017, a QR protection officer (PO) was fatally injured after being struck by a suburban passenger train at Petrie, Queensland.
Four POs were assigned to the maintenance task, including 3 POs at Petrie Station. The lead PO participated in the briefing of the maintenance workers, and the 3 POs then undertook a pre-start brief for the implementation of the protection (stop signs and railway track signals), which the other 2 POs then started implementing. It was one of these POs who was fatally injured.
The ATSB found that the POs were not familiar with the new rail infrastructure and uncommon site layout at Petrie Station. The POs were not advised of an early work shift start requirement, which resulted in them having insufficient time to prepare for the task, and they experienced pressure to complete the task within the scheduled time. In addition, QR had no process for ensuring the provision of adequate time for the POs to familiarise themselves with new or changed worksites.
The train notice diagram had been incorrectly marked with the open and closed rail lines by a different PO, and the POs’ pre-start briefing was limited to about 90 seconds. In addition to this, the recorded pre-start briefing forms contained errors and inconsistent sign-off entries; it is possible that the recording of the pre-start brief had been rushed.
Following the accident, QR undertook a number of safety actions. The QR investigation had found that the ‘pre-start briefing process on the night was not effective in ensuring the risks of individual live tracks and site-specific hazards and risks were understood and controlled by the Protection Officers’. A subsequent review of the task distribution for POs noted that the pre-start safety briefings often lacked planning and were delivered spontaneously, and it recommended a review of the effectiveness and improve the delivery of the pre-start safety briefings. The network pre‑start briefing procedure and form were subsequently revised with briefings provided to relevant workers.
Training and qualification records showed that the supervisor, team leader and recipient involved in the occurrence at Thorneside, had attended training in delivering the revised network pre-start briefing procedure and form, and the revised form was used during the pre-start briefing on 6 March 2020. QR also re-enforced the message of ‘the right to stop work and getting safety right before commencing’ as part of its ongoing network pre-start brief project.
In addition, QR organised the development of a consistent process for marking up train notice diagrams.
On 3 July 2019, at Margam East Junction in South Wales, United Kingdom, 2 track workers were struck and fatally injured by a passenger train. A third track worker came close to being struck.
The group of 6 track workers were assigned a safe work pack (SWP) that included 3 tasks to be completed, and another task was added on the morning of the accident that was not included in the SWP. The SWP stated the work would be conducted between 1230 and 1530, with 2 types of protection included for this period (line blockages and lookout warning), although which tasks were to be protected by which method was not clearly articulated.
The workers commenced the tasks soon after 0800 using a lookout, but there were problems with its implementation when the workers spilt into 2 groups doing different tasks with only 1 designated lookout between them. The workers who were struck were performing a noisy task (maintaining a set of points) that should only have been undertaken with the line blocked. The controller of site safety (PO) and the lookout were with the other group when the accident occurred.
Overall, the system of work that was proposed was not adopted, and an alternative arrangement became progressively less safe as the work proceeded, which created conditions that made an accident much more likely. The SWP was developed without the involvement of any of the workers involved, and there was no challenge by the workers to the way the work was being conducted.
The investigation by the UK Rail Accident Investigation Branch (RAIB) found that local management/supervisors were not actively monitoring, and had not identified and managed, non‑compliant safety behaviors at the depot. The investigation also considered why Network Rail (the rail infrastructure manager) had not created the conditions that were needed to achieve a significant and sustained improvement in track worker safety. Relevant underlying factors were identified:
• Over a period of many years, Network Rail had not adequately addressed the protection of track workers from moving trains...
• Network Rail had focused on technological solutions and new planning processes, but had not taken account of the variety of human and organisational factors that can affect working practices on site…
• Network Rail’s safety management assurance system was not effective in identifying the full extent of procedural non-compliance and unsafe working practices, and did not trigger the management actions needed to address them…
• Although Network Rail had identified the need to take further actions to address track worker safety, these had not led to substantive change prior to the accident at Margam.
In terms of safety assurance, frontline management/supervisors were required to undertake planned ‘Level 1’ (first-line) assurance activities, which included worksite inspections to review the effectiveness of the planning process, competence of staff, and unsafe behaviours and activities/ conditions, including corrective actions as required. Regarding worksite inspections, the investigation identified that managers may have been relying on submitted paperwork rather than undertaking observations of work on site. In addition, there was a self-assurance process where front-line management was required to formally check compliance with procedures by responding to a series of subject-related questions. These questions were designed to monitor the managers’ own compliance and that of their staff.
The evidence obtained by RAIB suggested that the underlying weaknesses in the design of the level 1 assurance processes included:
• since managers in Network Rail are often judged on the level of compliance with process, there is an obvious disincentive to assess their part of the organisation as non-compliant
• once a manager has judged their part of the organisation to be non-compliant, there is an implied responsibility to take action; this may mean challenging well established work processes, or risk unwanted confrontation with those in the team
• route level audits tend to be focused on areas considered to be high risk or where self-assurance checks have revealed particular problems. If there are no reports of non-compliances and no significant issues are raised in self- assurance returns, it is easy for particular delivery units or depots to avoid route level audits
The investigation also found multiple problems with the design and execution of this process and noted that it was frequently referred to by managers and staff as a ‘tick box’ exercise. Overall, for a variety of reasons, the audits were not effective in detecting a range of problems with planning paperwork, procedural non-compliance, and unsafe working practices, and did not trigger the higher-level management actions needed to address them.
In contrast, level 2 audits (conducted by persons independent from those with the responsibility to implement the risk controls) detected numerous examples of non-compliance in work practices. Over a 3-year period (June 2016–July 2019), 30 level 2 audits were undertaken. These identified 36 non-compliance reports (NCRs) and 8 repeat NCRs. Most NCRs contained multiple instances of non-compliance of various types and 10 NCRs included non-compliances that were considered by the auditor to be ‘systemic’ in nature. The RAIB noted that the NCRs confirmed evidence that the management self-assurance (level 1) process was an unreliable mechanism. The RAIB also noted these level 2 audits, although reasonably thorough, were heavily based on reviews of paperwork.
Other incidents
Track worker safety has been a significant concern for the rail industry for many years, and at the time of the Thorneside incident track work safeworking was listed by the Office of the National Rail Safety Regulator (ONRSR) as one of its safety priorities. For the calendar year 2020 it reported that there were 458 track work safeworking rule and procedure breaches.
During the investigation, QR was requested to provide records and brief descriptions of notifiable safety incidents relevant to work on track safety breaches between 1 March 2018 and 29 February 2020. QR provided details of 24 incidents that occurred on its south-east Queensland network. Limited details were provided for some incidents. However, the available information indicated at least 3 notifications had some similarities with the incident at Thorneside:
One notification in which a PO advised that an excavator operator had on-tracked an excavator without permission.
One incident in which a welding crew had accessed a rail corridor and commenced work. The welding crew had not contacted the PO to sign on to the multiple workgroup register. A subsequent internal investigation identified a number of ‘absent or failed defences’, including the ineffective use of the pre-start briefing.
One incident involving a near collision between the tilt train[39] and a work group, where the PO suspended the TOA unaware that there was a work group working on-track.
Management oversight of network safety
Overview of risk management and assurance process
QR had documented standards and procedures for risk management and assurance. The standard MD-11-1338 (Risk management) stated:
Risk management embodies an organisational culture of prudent risk-taking within Queensland Rail. It is the process of identifying, assessing and responding to risks, and communicating the outcomes of these processes to the appropriate parties in a timely manner…
Managing risk effectively requires people at all levels in the organisation to have specific accountabilities, authorities, delegations, and appropriate competence to establish, apply and maintain the risk management framework as a basis for good decision making. It is important to have complete and current risk information available as this information assists in ensuring informed decisions around both strategic direction and operational objectives.
Risk management is not a stand-alone discipline and requires integration with existing business processes such as business planning, assurance and Internal Audit, in order to provide the greatest benefits…
In a section titled ‘Monitor and review, the standard stated:
Continuous monitoring and review are vital components of an effective risk management process. They may be undertaken as part of a formal periodic process [planned assurance activities], or performed on an adhoc [ad hoc] basis, (e.g. change in policy or change in requirement).
The primary purpose of monitoring and review is to determine whether risks still exist, whether new risks have arisen, whether the likelihood or impact of risks have changed, and to reassess the risk priorities within Queensland Rail’s internal and external context.
Monitoring and review provide important feedback with regard to assurance over the efficiency and effectiveness of controls implemented to treat risks. It enables QR to analyse and learn lessons from event successes, failures and near-misses.
The standard also stated:
For risk management to be effective, controls must be regularly monitored and reviewed. Controls must be monitored to ensure that they continue to perform as intended and continue to modify the risk in the manner and to the extent assumed in the risk assessment…
QR standard MD-16-24 (Assurance) expanded on the monitor and review concepts. It stated that in order for risk management to be effective, QR should comply with a set of assurance principles, which included:
Assurance is an integral part of all organisational processes. Assurance is not a stand-alone activity that is separate from the main activities and processes of the organisation.
Assurance is risk-based. Assurance should be weighted to risk and control effectiveness. The importance of this is highlighted by following an integrated risk and assurance approach. Ultimately assurance is part of risk management…
Assurance activities are aimed at obtaining reasonable assurance, rather than absolute assurance over Queensland Rail internal performance of controls.
Assurance is systematic, structured and timely. A systematic, timely and structured approach to assurance contributes to efficiency and to consistent, comparable and reliable results…
Assurance is a continuous process that facilitates unceasing improvement. It consists of assurance providers and management incorporating consistent and systematic processes in their day-to-day activities to monitor and assess control effectiveness…
Assurance activities are interdependent and inter-related. All previous and planned assurance activities form an integrated whole and contribute to the application of the Three Lines of Defence Assurance Model.
QR’s 3 lines of defence assurance model was summarised in a diagram, as shown in Figure 5.
Figure 5: QR’s 3 lines of defence assurance model
Source: Queensland Rail
In line with QR’s procedure MD-12-27 (Assurance), QR was to develop an integrated assurance plan (IAP) focussing on second-line and third-line assurance activities through an assurance mapping exercise to provide a holistic view of all assurance activities in relation to the corporate risk hierarchy. The assurance procedure also stated that the planning of second-line and third-line assurance activities would be based on matters such as:
The relevant Key Operating Risks (KOR) and Event Risks (ER) of the Corporate Risk Hierarchy, their linked risks and key controls and the risk tolerance levels.
Findings, conclusions and status of actions from previous management reviews.
Findings, conclusions and status of actions from previous second line and third line assurance activities (including investigations) impacting the risks and controls.
Assurance activities performed by other managers with the Group, Function and other Functions.
QR’s corporate risk register regarded the safeguard of its workforce as one of its major priorities. One of the risks identified was:
The risk of a rail traffic collision with worker whilst in the danger zone, resulting in a serious injury or fatality.
As part of the investigation process, QR was asked to provide its integrated assurance plans[40] for financial years 2017–18, 2018–19, 2019–20 and 2020–21. In addition, the ATSB requested first‑line, second-line and third-line assurance activities over a predetermined period related to network pre-start briefings and related matters.
First-line assurance activities
One type of first-line assurance activity QR used to assess pre-start briefings and protection arrangements and compliance was conducted by use of form MD-17-27 (Worksite protection compliance inspection). The form was focussed on evaluating a specific worker’s compliance relevant to work activities and included 10 items, each with a comments section to record non‑compliances and required actions. One of the items referred specifically to ‘Pre-start safety briefings including additional Site-Specific hazards’. Five of the items referred to different types of safeworking protection. The compliance inspections and the forms were completed by the worker’s supervisor or manager.
There was no explicit guidance associated with the form to explain what aspects of the pre-start briefing were being evaluated (for example, whether it was simply evaluating whether a briefing was conducted, or whether it was also evaluating the content the worker provided during the briefing or whether all members of the work group were at the briefing).[41]
During the 12 months from January to December 2019, south east Queensland (SEQ) network conducted 495 compliance inspections using form MD-17-27. Of these, 9 inspections (about 1.8%) identified non-compliance where action was required with a small number also including reminders or minor issues. The non-compliances included:
incomplete or missing SW01 (corridor safety planner and assessment) form
incomplete or missing safe work method statements
inadequate worksite protection.
No instances of non-compliance in relation to the network pre-start briefing were identified. It was noted that a relatively high proportion of the non-compliance and feedback were identified by a relatively small proportion of those who conducted the inspections.
Another type of first-line assurance activity QR utilised to assess compliance with network pre‑start briefings, worksite protection, and multiple other tasks on the rail corridor was form MD‑12-66 (Construction / Maintenance HSE Inspection Record). The form related to all types of maintenance activities and worksites (not just those on track) and included 199 questions within 24 sections. The form’s instructions stated:
1. Review previous Planned Inspection to ensure all identified issues are addressed.
2. Identify any HSE [health safety and environment] issues that require rectification to ensure compliance…
3. Where a serious issue is identified which presents immediate risk to health, safety or the environment, interrupt the inspection to stop the operation/process and have workers relocated to a safe area (if required).
4. The relevant Manager / Supervisor is responsible for assigning resources to complete required corrective actions within the agreed time frame.
5. HSE issues that are unable to be rectified on the day of the inspection must be risk assessed / prioritised as either: Low, Medium, or High.
6. Ensure all fields are completed and not left blank. If not applicable, add N/A.
7. It is advisable that Supervisors and Managers schedule and attend a Pre-start brief to ensure quality of Safe Work Method Statement (SWMS) delivery.
In a section titled ‘Prestart Safety and Environment Briefing’, one of the questions asked if a ‘pre‑start safety and environment briefing was performed prior to accessing the site’ and another question asked, ‘During the Pre-start brief are the hazards and controls communicated to the workers and captured on the Pre-start brief’. None of the questions specifically asked whether all workers were at the pre-start brief or whether the PO specifically discussed worksite protection at the brief.
Another section was titled ‘Safe Working’ and included 35 items. These items primarily dealt with the technical implementation of different types of protection; none of the items referred to the conduct or content of the pre-start briefing.[42]
One of the questions regarding the pre-start briefing asked if radio channels / other communication was discussed. Another section on mobile plant included questions related to whether amber lights were fitted and operational, and whether the plant had a UHF radio and was it operational.
As part of the ATSB request, QR provided 118 (MD-12-66) forms that were conducted between 2019–2020. The ATSB examined the completed forms in accordance with the form’s instructions. The examination identified noteworthy similarities with each completed form, including:
Of the form’s 199 elements for inspection, they were either marked as compliant (Y) or if the element was not able to be inspected it was marked as not applicable (NA). There were very few cases where non-compliance (N) was recorded on an inspection form.
None of the forms recorded outstanding issues from previous inspections.
There were no recorded non-compliance issues noted with the network pre-start safety briefing component of the form.
There were no recorded issues relating to the separation of people and plant.
There were no recorded issues related to safeworking or worksite protection.
None of the inspections recorded any outstanding issues at the completion of the inspection.
All the inspection forms examined included minimal (if any) commentary or contextual evidence to support the results/findings of the inspections.
There were many cases of forms being completed by the same person with similar entries or phrasing in comments.
Second and third lines of assurance
During the financial years 2017–18, 2018–19 and 2019–20, QR’s integrated assurance plans recorded 3 scheduled second-line assurance activities that related to network pre-start briefings. One scheduled in Q3 of financial year 2017–18, another in Q4 of 2018–19 financial year and the other which took place in Q2 of the 2019–20 financial year.
On request, QR was able to provide a report for one of these 3 scheduled second-line assurance activities – a second-line assurance activity titled ‘Pre-Start Briefing Improvements Review’, which was conducted in September 2019. Its purpose was to determine whether changes made to the network pre-start briefing process (following the May 2017 Petrie accident (see Petrie, Queensland, 2017) had been effectively implemented across the network function and whether the changes met the intent of recommendations arising from QR’s investigation.
The assurance activity involved reviewing worksite activities at 21 locations throughout Queensland. Where the pre-start briefing had already been conducted and work had started, the auditor reviewed the completed briefing form and discussed with workers whether they were aware of the listed hazards and controls. For those worksites where the briefing had not commenced, the auditor discussed with the workers how the briefings were completed using the current version of the form. The audit report did not specifically note that any observations were conducted of briefings, and it also did not note whether all relevant workers (particularly POs) were present at the briefings.
The assurance activity noted that all work groups were using the required form, workers were aware of the risks and controls, and most work groups shared the task of conducting the briefings. Overall, the results of the second-line assurance activity recorded that the control effectiveness score was substantially effective. Some minor areas for improvement were noted. The auditor identified irregularities with documentation in relation to where the network pre-start briefing should be delivered (at the worksite or away from the worksite, such as at a depot) and recorded work groups receiving slightly different information in relation to completing the network pre-start briefing form.
Although not directly related to network pre-start briefings, another second-line assurance activity was undertaken in the second half of 2018 titled ‘Protection Officers’. The objective of the activity was to determine how QR (POs) interpreted safeworking rules in the field, how effective safeworking changes were communicated, and the effectiveness of first-line assurance activities.
According to the auditor, the risk control effectiveness of the assurance activity was rated at substantially effective. The auditor noted that none of the 42 POs interviewed were aware of the requirement to assure the worksite location on the detailed work plan (worksite diagram) matched the actual work location by comparing the plan to a labelled permanent structure and to have this validated by a member of the work group. The ATSB notes that, given this was a common understanding, it appeared to be related to the dissemination of information to POs rather than a compliance problem. The audit report did not provide any information regarding the network pre‑start briefing process.
Evidence provided by QR indicated there were no internal recorded third-line assurance activities directly relevant to changes made to the network pre-start briefing process following the May 2017 Petrie accident.
However, there were a number of compliance inspections undertaken by ONRSR in relation to track worker safety during 2019–20. Although the inspections did not identify any non‑conformance requiring action by QR, there were observations during the inspections that required consideration by the rail operator. Examples of those observations included:
• Queensland Rail staff undertaking the walking patrol were not in possession of a Pre-Start Brief form for the planned work, having left it at the depot at Sunshine. Changes to safety requirements for trackworkers were not able to be re-assessed as a result of changes to track conditions.
• The worksite protection plan completed by the Queensland Rail staff did not indicate safe places for the trackworkers to move to when required to clear the danger zone for rail traffic as required by the Queensland rail network Rules.
Safety analysis
Introduction
At about 0108 on 7 March 2020, a Queensland Rail (QR) suburban passenger train (1898) with passengers on board almost collided with an excavator while it travelled between Thorneside and Birkdale stations. The excavator operator was directed to on-track the excavator on the understanding that the section of track was closed and protected from rail traffic.
The near collision had the potential for serious consequences. In this case, it was very likely that the emergency actions of the train driver and the excavator operator prevented an imminent collision. Had this scenario resulted in a collision, it most certainly would have led to significant adverse consequences for the excavator operator and potentially the derailment of the train.
After the initial near collision, and while attempting to remove the excavator from the danger zone of the rail corridor, a second near collision occurred with another suburban passenger train. Although this occurrence was not as serious, it still had the potential for adverse consequences.
The safety analysis will consider the events and conditions which influenced the near collisions, particularly:
limitations associated with the network pre-start briefing
other limitations with communications at the worksite
the effectiveness of assurance activities related to these matters.
Pre-start briefing processes
All documentation associated with QR network pre-start briefings gained during the investigation stated that all work group members, including protection officers (POs), contractors and others associated with work within the rail corridor, were required to attend a network pre-start briefing. This understanding of the requirements was supported by a subject matter expert who developed and delivered training for QR’s POs and track workers.
In most cases, and as described by QR’s guidelines, a nominated person will deliver the network pre-start briefing with assistance from the PO and others as required. For example, the recipient or the mobile plant spotter should also provide information when required. The pre-start briefing should provide an environment where all work group members can participate and ask questions relevant to the work, including protection arrangements and the roles and responsibilities of individuals. One key aim of the briefing was to ensure everyone working on the site had a correct, shared understanding of the worksite protection arrangements that would be used and the limits of that protection.
On 6 March, the lead PO was advised to meet the depot supervisor at the Cannon Hill depot at 2200 to discuss protection arrangements for the planned work at Thorneside. By the time the PO arrived at the depot, the team leader had completed the network pre-start briefing, and shortly after the work group departed the depot for the worksite. Neither the lead PO or the assistant PO attended the briefing or provided any input to the briefing regarding worksite protection arrangements for the planned closure or the preparation work (for which the protection arrangements had not yet been assessed, planned, and confirmed). Most of the workers present at the briefing signed the network pre-start briefing form, even though they had not received a briefing from the PO. The supervisor did not sign the briefing form until after the near collisions.
The excavator operator was also not invited to the network pre-start briefing at the Cannon Hill depot. Instead, the arrangement was for a QR representative to meet the excavator operator at Thorneside Station at 2230, prior to the commencement of work. On arrival at the worksite, the excavator operator correctly requested a worksite briefing. The team leader explained the work requirements pertaining to the excavator. However, they were not provided with a network pre‑start briefing or any briefing from the PO explaining the protection arrangements relevant to the worksite, even though they were requested to sign the network pre-start briefing form.
Other than the network pre-start briefing delivered at the Cannon Hill depot, neither the supervisor nor the team leader, who was working under the guidance of the supervisor, provided an opportunity for the PO to deliver information about the worksite protection requirements to the work group for the planned work activities.
It was suggested by the recipient at interview that the PO delivered their component of a network pre-start briefing immediately prior to the work group entering the rail corridor at Thorneside. This however was not a formal network pre-start briefing, but a mandatory requirement of the Queensland Network Rules and Procedures (QNRP) before work could commence in the rail corridor. At the time the PO delivered the brief to access the rail corridor, the excavator operator and the supervisor of the work group were not present as they had not yet arrived at the worksite. There was no discussion of the work activities and protection arrangements for the planned closure.
It is understandable that in some situations, where maintenance work extends over several days, not all workers will be able to attend the same network pre-start briefing. Under those conditions multiple network pre-start briefings should be delivered to ensure that all workers are provided with safety information relevant to their working environment. However, the maintenance work at Thorneside was scheduled over one shift. Therefore, all members of the work group, including the POs and the excavator operator, should have attended the same pre-start briefing to enable them to develop a shared understanding of the worksite protection arrangements that would be in place for both the preparation work and the planned closure.
In this case, given the excavator operator was not present at the network pre-start briefing, the team leader (and supervisor) needed to ensure that the operator was provided with a full network pre-start briefing when they arrived at the worksite (or at least prior to the team leader directing them to an alternate entrance gate away from the worksite). This should have included briefings and involvement from relevant personnel such as the PO and the recipient / mobile plant spotter.
As well as the actual briefing, there were limitations with the level of detail included in the network pre-start briefing form about the type of machinery that would be used. The protection arrangements listed were also general in nature, and not clearly specified for both the preparation work and the planned closure. Given that the POs did not see the form prior to the near collisions, and the excavator operator was not involved in the preparation work, limitations within the form did not contribute to the near collisions.
In summary, there were a significant number of problems associated with the application of the network pre-start briefing process prior to work commencing at the Thorneside worksite. Of most importance, the POs and the excavator operator were not included in a network pre-start briefing, which denied them and the work group of essential safety information applicable to their roles and responsibilities. This limitation significantly increased risk and contributed to the initial near collision.
Other communication processes
Introduction
When working in a rail environment such as a worksite, communication for the purpose of developing a shared understanding is vitally important. The network pre-start briefing is an essential part of ensuring subsequent communications are based on a shared understanding and are effective.
In this case, there were a number of communication problems that occurred following the network pre-start briefing, many of which can be attributed in part to the absence of a thorough network pre-start briefing involving all of the personnel working at the site.
Protection officer awareness of the excavator
While at the worksite, the supervisor received a call from the excavator operator regarding the location of the worksite. The supervisor directed the operator to travel to the worksite and meet workers at the work group entrance gate. This information was passed on to others in the work group, including the recipient and the team leader, for future planning consideration. However, it was not communicated to the lead PO. The PO was not cognisant of the working arrangements involving the excavator and they were unaware an excavator had arrived at the site.
The need for that information became safety critical when the network control officer (NCO) contacted the PO regarding a track fault, which was very likely caused by the excavator when it was being on-tracked. When the NCO asked the PO if there was any equipment on-track, the PO had an incomplete mental model of the work group and advised the NCO that there was no equipment on-track.
Had the PO known that the excavator had arrived on site, it is likely they would have associated the track fault with the on-tracking of the excavator and communicated this information to the NCO. Given that the track fault occurred about 105 seconds prior to the first near collision, it is likely that such communications would have prevented the first near collision (or at least significantly reduced the risk associated with any such near collision).
Direction to on-track the excavator
The recipient directed the excavator operator to on-track the excavator before the planned track closure. This action appeared to result from a combination of situational factors. Firstly, the recipient misinterpreted the team leader’s instruction of ‘it’s on’ as meaning the planned closure was active, whereas the team leader was referring to the reinstatement of the protection for the preparation work, and that the work tools could be loaded into the bucket of the front-end loader. The recipient’s misinterpretation was reinforced by the work group loading the front-end loader with tools for the planned closure and then receiving the height limiter key from the operator of the front-end loader.
Although the chain of events had the potential to be misinterpreted by the recipient, there should have still been some level of doubt that the planned closure was in force. The time of the team leader’s instruction (0051) was well prior to the scheduled start time of the planned closure (at 0218), and there had been no discussion of changing the start time of the planned closure (and scheduled trains were still operating). In addition, the PO had not authorised the on-tracking of the excavator and the team leader (or supervisor) had not explicitly informed the recipient to direct the excavator operator to on-track at that time.
For any questions relevant to protection arrangements, the communication pathway should be through the PO. If a member of the work group required clarification on information or instructions, then they should gain this clarification from the person in charge at the worksite. In a work group there should be clearly defined communication protocols, and these protocols should be highlighted at every network pre-start briefing.
The recipient had been formally trained in network communication and should have been aware that, before acting upon a communication regarding access to the rail corridor and danger zone that is not explicit, further clarification is necessary. However, in this case the recipient acted on an assumption rather than clarifying the instruction and gaining the necessary authority from the PO and the person responsible at the worksite before they directed the operator to on-track the excavator.
It is conceivable that the recipient undertook the action with the view that it would help facilitate the work and provide more confidence that subsequent tasks would be completed within the planned closure period. However, there was no indication that the recipient was intentionally deviating from procedures when they directed the excavator operator to on-track. Rather they appeared to simply misunderstand the situation.
The work group member acting as the recipient was new to the role, having only received their qualification 2 days before. Therefore, consideration to provide supervision over the actions and performance of the recipient (also acting as the mobile plant spotter) should have been a priority for the supervisor and the team leader. However, there appeared to be limited supervision or support provided.
In summary, without gaining the necessary authority, the recipient directed the operator of the excavator to on-track under the incorrect assumption the planned closure was active, and the worksite was protected by a TOA with in-field protection and train activity on the rail corridor had ceased. However, there was no protection in place and the rail corridor was open for normal train traffic.
Use of standardised railway terminology
It is important that standardised industry-specific terminology is used when communicating safety‑critical information. When using general terms, it is possible for individuals to misinterpret the intent of a communication. In a work environment such terms can lead to a situation where something important can be taken out of context, which may lead to serious consequences. In the case of this investigation, there were 2 instances where workers used generic language to communicate safety-critical information that was misinterpreted and lead to serious consequences.
Firstly, the team leader communicated the generic term ‘it’s on’ to the work group to signify the TOA without in-field protection (or an ‘unprotected TOA’) had been reinstated and tools and equipment could be transferred from the work truck into the front-end loader. This term was misunderstood by the recipient and interpreted as the planned closure was now in force, prompting the recipient to direct the excavator operator to on-track the excavator.
A contributor to the second near collision was the conversation between the lead PO and the emergency hotline contact (located at the network control centre) by not incorporating standardised industry-specific terminology during their conversation. While gaining information relevant to the first near collision, the emergency hotline contact asked the PO had the excavator been moved away from ‘the track’, rather than using the rail-specific term ‘danger zone’.
The lead PO then gained confirmation from the supervisor (and indirectly from the recipient at the incident site) who verified the excavator was away from the track. On gaining this information, the emergency hotline contact advised the PO to leave the excavator where it was for investigation purposes. The emergency hotline contact then informed the NCO that the excavator was away from the track. Based on this information, the NCO believed that the excavator was clear of the danger zone and therefore allowed rail traffic to proceed past the incident site without imposing restrictions. However, the excavator was still in the danger zone and close to the running line, which meant it was a risk to operations. Had the conversations between the PO, emergency hotline contact and other parties identified the excavator was in the danger zone, it is highly likely that this information would have been forwarded to the NCO and the second near collision would have been avoided.
Guidelines for the use of standardised railway terminology
The Rail Industry Safety and Standards Board’s (RISSB’s) Safety critical communications guideline (2018) stated that one way to mitigate the risk of misunderstanding in communication was to avoid the use of acronyms and words with alternative meanings. Instead, the guideline advised the use of industry-specific terminology that cannot be misinterpreted. Although QR’s QNRP provided relevant information on spoken communication and the use of standard terms, such as the phonetic alphabet, when communicating information, there was no formal guidance for rail safety workers to incorporate standardised rail-specific terminology when communicating safety-critical information. Including this guidance, and reinforcing its use during safety-critical communications, would reduce the risk of these types of miscommunications, particularly during an emergency response.
Direction to remove the excavator from the danger zone
Following the first near collision, the supervisor travelled to the incident site to assess the situation, after being advised that the excavator was off the track but may still be in the danger zone. After arriving at the site, they confirmed that it was still in the danger zone, and they instructed the excavator operator to move the excavator further away from the tracks.
In interview the supervisor advised that they had assumed that rail traffic would have been suspended following the first near collision, but they had not confirmed that this was the case with the NCO. It is understandable that a natural reaction to such a situation would be to immediately remove a potential collision hazard. However, by instructing the excavator operator to enter the danger zone and move the excavator without first gaining permission from the NCO and confirming that rail traffic had been suspended, the supervisor was placing the excavator operator and others nearby (and potentially those on the train) at unnecessary risk.
After the second near collision, again the supervisor exposed the excavator operator to danger by directing them to remove the excavator from the danger zone without gaining the necessary protection from the NCO.
Assurance activities
Additional task performance aspects
At present in most rail networks in Australia, work on track fundamentally relies on administrative controls (rules and procedures), with there being limited use of technology to reduce the risk of workers being struck by rail traffic. However, human performance is inherently fallible. Accordingly, working within the rail corridor requires significant planning, communication and worker adherence to rules and procedures in order to provide a safe work environment.
As already outlined in previous sections of this analysis, there were limitations associated with the network pre-start brief that increased safety risk. There were also limitations with a number of subsequent communications that increased risk, as discussed in the previous section. In addition, the investigation identified a number of other actions at the worksite that increased risk, many of which were explicitly or implicitly inconsistent with the rail operator’s rules and procedures. These actions included:
The supervisor did not attend the briefing delivered by the lead PO at the worksite regarding the TOA without in-field protection prior to the preparation work and they then commenced work tasks in the rail corridor.
The supervisor provided limited supervision of the team leader and the recipient at the worksite, who were both new to their roles.
There was no designated ‘lookout’ in place for the preparation work, which was conducted with a TOA without in-field protection with less than the required sighting distance.
The recipient did not gain permission from the PO before directing the excavator to on-track the excavator.
The recipient did not advise the excavator operator of the radio channel to use at the worksite (although this was listed on the network pre-start briefing form).
The recipient did not have a radio and did not maintain full visibility and communication (radio contact) with the excavator operator.
After the first near collision there was no ‘pause and re-start’ in accordance with the network pre-start briefing form.
The supervisor directed the PO, who oversaw protection within the rail corridor, to return to the Cannon Hill depot while machinery and workers were still in the rail corridor without the required protection.
Although the team leader (acting as the person in charge of work) and the recipient were acting in roles for which they were inexperienced, they and the supervisor of the work group were experienced in track work safety. All 3 rail safety workers had been formally trained to act as a PO, deliver a network pre-start briefing, conduct communications (as per the QNRP), conduct lookout duties and rail safety awareness. Their training and experience should have provided them with the necessary competence and skills to work safely in the environment of the rail corridor.
The investigation did not identify any environmental conditions that necessitated the undertaking of deviations from procedures. The absence of one worker due to sickness resulted in the work group undertaking preparatory work prior to the planned closure to manage this contingency. However, there appeared to be no indication that there would be insufficient time to undertake the preparatory work and the preparatory work was completed well before the planned closure period.
The arrival of workers at different times and the need to use multiple access gates for different machinery complicated the situation for the work group. However, this situation should have indicated a need for more thorough briefings and communications as these problems developed. Although the activities were occurring overnight, the available evidence did not indicate that any of the involved work group was experiencing adverse levels of fatigue.
Given the number and variety of individual actions that increased risk associated with the near collisions, and no obvious explanation for this overall pattern of actions, the investigation considered the assurance processes the operator had in place to detect work practices being inconsistent with rules and procedures.
Assurance activities related to network pre-start safety briefings
It is essential that information gained from first-line assurance activities genuinely reflects what is actually happening when frontline workers are performing tasks in the rail corridor. Accurate data capture is critical in first-line assurance, as second and third-line assurance are linked and leverage off the results. If the information is not accurate, then the integrity of the 3 lines of defence assurance model will be flawed, which will likely have a significant impact on future safety.
As already outlined, the network pre-start safety briefing is an essential and safety-critical component of minimising safety risk while conducting work on track. Findings from investigations have shown that ineffective network pre-start briefings have either directly or indirectly contributed to the death of workers as a consequence of being struck by rail traffic, and this was also a key problem in the near collisions at Thorneside. Accordingly, the ATSB focussed its assessment on the application and results gained from assurance activities, relevant to pre-start briefings, to determine the effectiveness of the 3 lines of defence assurance model in identifying and managing risk.
The ATSB reviewed first-line assurance inspection forms that were completed between 2019–2020, which included (among other things) the inspection of compliance with network pre‑start briefings, worksite protection and safe work activities. These consisted of 495 worksite protection compliance assessment forms and 118 maintenance inspection records. Almost every form examined by the ATSB identified near full compliance with all aspects of the required processes with very few safety-related matters identified. This data could be interpreted as providing assurance to the organisation that workplace activities were routinely being conducted effectively. However, the results of this investigation and at least some other incidents indicate that workplace activities were not always effective.
The extent to which the first-line assurance activities provided a reliable assessment of the network pre-start briefings appeared to be limited due to multiple factors:
There was no explicit guidance associated with the worksite protection compliance assessment form that explained what aspects of the briefing were to be evaluated. More specifically, the extent which all relevant workers (including POs) were at the briefing and participated in the briefing was not explicitly requested or recorded.
The maintenance inspection form covered a wide range of topics and was detailed, consisting of 199 items. However, although some of these items referred to the network pre-start briefing, none of the questions asked if all relevant workers (including the PO) were at the briefing and participated in the briefing. It is acknowledged that not every specific aspect can be covered in such assessments, and increasing the length of such assessments will not always lead to more useful, accurate data.
The maintenance inspection forms were completed by a supervisor or team leader on their own work section (which is an inherent part of many first-line assurance activities). However, as noted in the UK Rail Accident Investigation Branch report into the Margam accident, such a process can be associated with a range of factors that may limit the objectivity, completeness, or accuracy of such assessments.
Accordingly, appropriate use of independent (or second-line / third-line) assessments is needed to provide confidence in the validity and reliability of first-line assessments. Evidence provided by QR showed that there had been limited second-line and no third-line assurance activities directed at network pre-start briefings, possibly due to the near faultless results of first-line assurance activities. One second-line assurance activity conducted after the May 2017 fatal accident at Petrie focussed on network pre-start briefings and involved interviewing workers associated with 21 tasks about a briefing or the briefing process. Given the identified criticality of effective pre-start briefings following the Petrie accident, this was a relatively small sample. The assessments also appeared to focus on the extent to which workers advised whether the briefings provided information about hazards and controls, which is obviously important. However, the extent to which all relevant personnel (including POs) attended briefings and actively participated in briefings was not documented.
The available evidence does not indicate that there was widespread non-compliance with network pre-start briefing procedures or related communication processes, and the ATSB has not concluded that widespread non-compliance was occurring. However, the assurance activities that were conducted did not provide sufficient assurance regarding the extent to which network pre‑start briefings were being conducted effectively. In other words, based on the nature of the assessments conducted, the extent to which the problems that occurred at Thorneside on 6–7 March 2020 had occurred at other locations or at other times could not be reliably evaluated.
In summary, QR’s 3 lines of defence assurance model is well equipped to manage safety. Nevertheless, if the process is not administered as intended and in line with risk management principles then track worker safety may be at risk. Network pre-start briefings are a critical control to manage the risk of collisions between rail traffic and workers. However, the design of the first‑line assurance activities and the limited conduct of second and third-line assurance activities provided only limited assurance that the worksite protection aspects of the briefings were being conducted effectively.
It is understood that assurance processes, regardless of how well or how often they are conducted, will not prevent all instances of procedures not being conducted as expected. In this case, given some of the situational factors involved, the extent to which improvements in the assurance processes would have prevented the near collisions at Thorneside was difficult to evaluate.
The ATSB notes that, following the Thorneside incident, QR has undertaken a significant program of work to improve track worker safety. Further details are provided in the Safety issues and actions section of the report.
Accident prevented
On recognising the imminent risk of collision, both the train driver and the excavator operator took immediate action which prevented the serious incident becoming an accident. The train driver applied the emergency brake on the train while the excavator operator used the excavator’s boom arm and bucket to drag it from the rail tracks as the train passed at about 61 km/h.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the near collision incidents involving an excavator and passenger trains 1898 and 18A0 near Thorneside, Queensland, on 7 March 2020.
Contributing factors
The lead protection officer (PO), assistant PO and the excavator operator were not included in a network pre-start briefing, which denied them and the work group of essential safety information applicable to their roles and responsibilities.
The lead protection officer (PO) was not informed of or aware that an excavator had arrived at the worksite. Consequently, when the network control officer (NCO) notified the PO of a track fault indication (associated with the on-tracking of the excavator) and asked if there was any equipment on-track, the PO had an incomplete mental model of the work group and advised the NCO that there was no equipment on-track.
Without gaining the necessary authority, the recipient directed the operator of the excavator to on-track under the incorrect assumption the worksite was protected by a track occupancy authority (TOA) with in-field protection and train activity on the rail corridor had ceased. However, there was no protection in place and the rail corridor was open for normal train traffic.
Following the first near collision, communications between the protection officer (PO), the emergency hotline contact and other parties about the location of the excavator did not clarify that, although the excavator was off the track, it was still in the danger zone.
The Queensland Network Rules and Procedures did not provide sufficient guidance for rail safety workers to ensure they used standardised rail-specific terminology when communicating safety-critical information. [Safety issue]
After the first near collision, the supervisor directed the excavator operator to remove the excavator from the danger zone without gaining the necessary authority from the network control officer or confirming that rail traffic had been stopped. This omission contributed to the second near collision between another suburban train and the excavator.
Other factors that increased risk
Network pre-start briefings are a critical control in place to manage the risk of collisions between rail traffic and workers and machinery, and Queensland Rail had undertaken significant work to improve these processes. However, the design of the first-line assurance activities and the limited conduct of second-line and third-line assurance activities provided only limited assurance that the worksite protection aspects of the briefings were being conducted effectively. [Safety issue]
Other findings
After detecting that the train and the excavator were on a collision course, the driver of train 1898 and the operator of the excavator both promptly undertook all available actions to reduce the collision risk.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: The Queensland Network Rules and Procedures did not provide sufficient guidance for rail safety workers to ensure they used standardised rail-specific terminology when communicating safety-critical information.
Assurance activities related to network pre-start safety briefings
Safety issue description: Network pre-start briefings are a critical control in place to manage the risk of collisions between rail traffic and workers and machinery, and Queensland Rail had undertaken significant work to improve these processes. However, the design of the first-line assurance activities and the limited conduct of second-line and third-line assurance activities provided only limited assurance that the worksite protection aspects of the briefings were being conducted effectively.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Additional safety action by Queensland Rail
Critical safety alert
Soon after the incident, on 10 March 2020, Queensland Rail issued a critical safety alert (CSA) directed to protection officers (POs) and their supervisors and managers, and all infrastructure workers and their supervisors and managers. The alert provided a brief overview of the incident and stated the following actions to be taken:
All workers must receive a prestart briefing prior to entering the Rail Corridor. The prestart briefing must include:
• the workgroup supervisor giving a briefing on the type of works that will take place and the risks and hazards associated with the worksite; and
• the Protection Officer giving the rail safety component of the briefing e.g. limits and types of track protection that will be used.
Workers may only enter the Danger Zone once they have been given permission from their workgroup supervisor.
Workgroup supervisors may only allow workers to enter the Danger Zone once they have confirmation from the Protection Officer that the required protection is in place.
If an incident occurs in the Danger Zone, workers must immediately notify their supervisor who must notify the Protection Officer. Where workers cannot contact their supervisor, they are to ensure the Protection Officer is advised. The Network Control Officer must also be notified.
Where necessary, the Protection Officer must arrange to have all rail traffic stopped.
Following an incident, the workgroup supervisors must confirm with the Protection Officer that adequate protection is in place prior to any workers re-entering the Danger Zone.
Subsequent improvement activities
Following the incident, Queensland Rail (QR) offered an enforceable voluntary undertaking (EVU) to the Office of the National Rail Safety Regulator in September 2021, with clarifications made in October 2021. This EVU summarised the following additional actions undertaken by QR:
• On 10 March 2020, the Executive General Manager SEQ Assets held a Safety Pause for applicable SEQ Assets employees to raise awareness of the incident and help focus employee mindsets on safe behaviours.
• On 12 March 2020, the Head of SEQ facilitated a Management Safety Workshop with key managers and supervisors to review details of several recent incidents (including reviewing interim findings of this Incident) to determine actions to help prevent future recurrence of similar incidents.
• On 30 April 2020, Queensland Rail commenced reporting on implemented lead indicators for key controls regarding trackside safety to the Executive Safety Committee on a monthly basis.
• On 18 May 2020, the Senior Manager SEQ Signalling & Telecommunications issued a CSA mandating that planned work in the Danger Zone must be advertised on Train Notice within SEQ Network Assets.
• On 18 May 2020, the Senior Manager Rail Safety and Accreditation clarified terminology to be used when communicating safety critical information when working in the Network within all Protection Officer training and the revised pre-start briefing training.
• On 1 June 2020, the Senior Manager SEQ Signalling & Telecommunications implemented a process for ensuring plans for work in the Danger Zone within SEQ are endorsed and approved including an escalation process for approving a change to an approved plan.
• On 14 July 2020 Queensland Rail updated its safety management system, including its pre-start briefing training to better outline the role of employees prior to entering the Rail Corridor. Part of these updates included further explaining the purpose of pre-start briefings, what makes a good pre-start and the importance of asking questions and developing good site sketches.
• On 29 July 2020, the Senior Manager Assurance & Capability implemented first-line and second-line assurance regimes for compliance with safety procedures and processes for working in the corridor throughout the SEQ network.
Subsequent proposed initiatives
Under the EVU, QR outlined 13 initiatives to improving planning processes for track access, the safeworking control framework, capability of safety-critical workers and effectiveness of safety assurance and performance. The EVU outlined safety initiative leads and accountabilities and a proposed schedule for implementation. The initiatives included the following:
improve planning and communication between track workers and network control officers (NCOs) in south-east Queensland
implement a track access system (a common interface between NCOs and POs)
conduct further work to review the Queensland Network Rules and Procedures (QNRP) and deliver refresher workshops
enhance network lookout processes (to reduce the likelihood of unintentional release of track protection while workers are still in the danger zone)
cease using lookout working[43] within south-east Queensland
review lookout working in regional areas
improve trackside pre-start briefings
introduce a non-technical skills program for POs
introduce a non-technical skills program for trackside worker supervisors
use external and internal incidents to review QR processes for any deficiencies
develop an approved tool for conducting first-line assurance of POs (and compliance with procedures for working in the rail corridor) and an associated assurance plan
develop an assurance tool for assessing communications between NCOs and POs and implement the assurance process.
QR advised the ATSB that, as of 1 November 2023, 12 of the 13 initiatives had been externally verified as closed and the final initiative was on track for completion by 31 December 2023.
Additional safety action by other parties
In January 2023, the Office of the National Rail Safety Regulator (ONRSR) and the Rail Industry Safety and Standards Board (RISSB) released the results of a global investigation into how world standard technology can protect track workers in the Australian rail industry. The introduction section of the Track Worker Safety Options Report stated:
This research project has been undertaken to establish a shared understanding of TWS [track worker safety] options and their use in the rail sector. The purpose of the project is to identify primarily current, and some emerging, TWS options for improving the safety of workers on Australian rail networks. It is anticipated that understanding the options available as well as their context for use in providing TWS will enable the rail sector to invest in these solutions and implement them successfully.
This report captures many aspects of this project, including a summary of the literature review, highlights from the survey findings, a snapshot of the stakeholder engagement workshop and an options table….
The options in the table were grouped in the following types:
vehicle installed devices that give warnings to train crew
worksite installed devices the give warnings to track workers
sensors and devices that give targeted alerts to both vehicle crew and track workers
infrastructure systems, methods and devices that remove the need for workers on tracks to undertake work
infrastructure systems and devices that automatically prevent vehicles from entering a worksite.
The sources of information during the investigation included:
relevant staff from Queensland Rail
the lead protection officer
the excavator operator
event recorder evidence from trains 1898 and 18A0
CCTV footage from the front-of-train camera of train 1898
universal traffic control replay system
Queensland Rail.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Queensland Rail
the depot supervisor
the work group team leader
the recipient
excavator operator
the Officer of the National Rail Safety Regulator (ONRSR).
Submissions were received from Queensland Rail and ONRSR. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Danger zone: all space within 3 m horizontally from the nearest rail and any distance above or below this 3 m, unless a safe place exists or can be created.
[2] Recipient: an authorised person who has the competence and responsibility to supervise the electrical safety aspects of the work and has been appointed in that function for a specific worksite in electrified areas.
[3] Protection officer: the competent worker responsible for managing the rail safety component of worksite protection.
[4] Planned closure: a pre-planned work arrangement on a railway which may exclude rail traffic from the rail corridor.
[5] Track occupancy authority (TOA): an authority for competent workers and their equipment to occupy a defined portion of track for a specified period.
[6] Network pre-start briefing: a communication and on-site activity planning session undertaken prior to the commencement of work or an activity. It should involve all workers, contractors and / or visitors involved, or exposed to, the work to be undertaken.
[7] Under this arrangement, signals are restored to STOP in the field by the NCO, restricting trains from entering the signalled section where work is being performed, and a lookout [competent person] positioned near the workers is used as a secondary safety measure. Work being performed cannot break or obstruct the track.
[8] Train notice: a notice issued by a rail infrastructure manager that contains safeworking and other relevant information for workers.
[9] Train diagram: a diagram that tracks the scheduled movement of trains, which is used by NCOs.
[11] The assistant PO was not required for the preparation work.
[12] A height limiter allows an operator to define the pre-set limit of machinery boom height.
[13] Electrical control officer: the worker who controls the power supply to the overhead line equipment and is responsible for all switching operations and isolations of electrical equipment.
[14] Suspend code: a code number communicated by the PO to the NCO.
[15] The NCO enters the suspend code into the system to enable the NCO to route train movements through the previous closed section.
[16] The failed track indication was most likely caused by the excavator’s bucket or boom arm contacting the rail(s) and short circuiting the track section as it on-tracked.
[17] Given the distance from the work group entrance gate and the noise of the excavator, it is extremely unlikely that the excavator operator could have heard the car horn at that time.
[18] The drug and alcohol tests of the involved workers produced a negative result (that is, no drugs or alcohol detected).
[19] In-field protection: 1 or more devices approved by access providers that provide warning to protect rail traffic crew and workers. Such devices include stop signs and railway track signals (that is, detonators placed on the track that explode on impact to attract the attention of rail safety workers). These devices may be used in conjunction with signalling or blocking facilities.
[20] Work on track authority: an authority to perform work on track (either a local possession authority, track occupancy authority or track work authority.
[21] Obstructing: any defect in the track or track formation or obstacle on or adjacent to the permanent way which will prevent the safe passage of trains.
[22] Lookout: a competent worker responsible for keeping watch for approaching rail traffic and for warning other workers to stand clear of the line before the rail traffic arrived.
[23] Means of protection: a method used to exclude rail traffic from a portion of track.
[24] Safety measure: a measure used to provide protection for workers when working or walking in the danger zone.
[25] Mobile plant spotter: a person responsible for the separation of plant and people at a worksite.
[26] Nominated person: a competent person trained and qualified to deliver a network pre-start briefing.
[27] Foul: in a position to obstruct rail traffic.
[28] Obstruction: any defect in the track or track formation or obstacle on or adjacent to the permanent way which will prevent the safe passage of trains.
[29] Safe place: a place where workers and equipment cannot be struck by rail traffic.
[30] Access: a designated safe way into, along, across or out of a rail corridor.
[31] Any defect in the track or track formation, or obstacle on, above or adjacent to the track which will prevent the safe passage of trains.
[32] R3: track/road vehicles that do not reliably operate track circuits and axle counters.
[33] ATSB rail occurrence investigation RO-2010-004, Collision between an XPT passenger train and a track-mounted excavator, near Maitland NSW, 5 May 2010
[34] ATSB rail occurrence investigation RO-2011-016, Collision between freight train 7SP3 and a track mounted excavator near Jaurdi, Western Australia, 28 March 2011
[35] ATSB rail occurrence investigation RO-2015-009, Track worker struck by train near Laverton station, Victoria on 2 October 2015
[36] ATSB rail occurrence investigation RO-2016-008, Track worker fatally injured when struck by train W510, Clyde, New South Wales, on 18 June 2016
[37] ATSB rail occurrence investigation RO-2017-003, Running line collision with worker involving passenger train T570, Petrie, Queensland on 29 May 2017
[38] RAIB Rail accident report 11/2020, Track workers struck by a train at Margam, Neath Port Talbot, 3 July 2019
[40] Integrated assurance plan: an assurance plan that puts together into an integrated whole all assurance activities of second and third-line assurance providers for a financial year.
[41] Sections: 2, 3 and 8 of the network pre-start briefing procedure referred to the delivery of the briefing, participation in the briefing and the debrief (following work).
[42] One item asked whether a specific type of qualified driver had been nominated in the briefing for an on-track vehicle authority.
[43] Lookout working: a safety measure used by competent workers to carry out work on track without a formally issued work on track authority. It involves positioning workers as lookouts to warn other workers of approaching rail vehicles.
On 11 March 2020, a Cessna 404 aircraft, registered VH-OZO, was being operated by Air Connect Australia to conduct a passenger charter flight from Cairns to Lockhart River, Queensland. On board were the pilot and 4 passengers, and the flight was being conducted under the instrument flight rules (IFR).
Consistent with the forecast, there were areas of cloud and rain that significantly reduced visibility at Lockhart River Airport. On descent, the pilot obtained the latest weather information from the airport’s automated weather information system (AWIS) and soon after commenced an area navigation (RNAV) global satellite system (GNSS) instrument approach to runway 30.
The pilot conducted the first approach consistent with the recommended (3°) constant descent profile, and the aircraft kept descending through the minimum descent altitude (MDA) of 730 ft and passed the missed approach point (MAPt). At about 400 ft, the pilot commenced a missed approach.
After conducting the missed approach, the pilot immediately commenced a second RNAV GNSS approach to runway 30.
During this approach, the pilot commenced descent from 3,500 ft about 2.7 NM prior to the intermediate fix (or 12.7 NM prior to the MAPt). The descent was flown at about a normal 3° flight path, although about 1,000 ft below the recommended descent profile. While continuing on this descent profile, the aircraft descended below the MDA. It then kept descending until it collided with terrain 6.4 km (3.5 NM) short of the runway. The pilot and 4 passengers were fatally injured, and the aircraft was destroyed.
What the ATSB found
The weather conditions when the aircraft reached the MAPt for the first approach could not be determined. It is possible that the conditions were better than the landing minima at that point but then deteriorated as the approach continued and when the aircraft was at a lower altitude.
The indicated airspeed during the latter part of the first approach was about 140 kt, which significantly exceeded the operator’s preferred speed after the final approach fix (FAF) (about 110 kt) and the operator’s stabilised approach criteria speed (about 110 kt at 300 ft above aerodrome elevation). Whether the pilot made the decision to conduct the missed approach based on the weather conditions, airspeed, descent rate or some combination of those factors could not be determined.
The aircraft probably entered areas of significantly reduced visibility during the second approach. In particular, there was a period of heavy rainfall at the airport after the first approach, and it is likely the aircraft entered the rain during the second approach.
There was no evidence of any conditions or circumstances likely to induce a medical problem or incapacitation for the pilot and the aircraft appeared to be in controlled flight up until the time of the impact. There was also no evidence of any aircraft system or mechanical anomalies that would have influenced the accident. Therefore, based on the available evidence, the accident was very likely the result of controlled flight into terrain (CFIT).
The most likely scenario to explain the descent 1,000 ft below the recommended descent profile on the second approach could not be determined. Regardless of the exact scenario, it is evident from the continued descent that the pilot did not effectively monitor the aircraft’s altitude and descent rate for an extended period.
In addition, when passing the FAF (5 NM prior to the MAPt), the aircraft significantly exceeded the operator’s required (lateral) navigational tolerance for the instrument approach for an extended period. This should have resulted in a second missed approach but, although the pilot was correcting the lateral deviation, a missed approach was not conducted. The aircraft’s speed after the FAF also increased to 140 kt, before increasing to 150 kt towards the end of the flight.
The ATSB found that the pilot was probably experiencing a very high workload during periods of the second approach. In addition to the normal high workload associated with a single pilot hand flying an approach in instrument meteorological conditions (IMC), the pilot’s workload was elevated due to conducting an immediate entry into the second approach, conducting the approach in a different manner to their normal method, the need to correct lateral tracking deviations throughout the approach, and higher than appropriate speeds in the final approach segment.
The pilot had the required qualifications and had been regularly logging RNAV GNSS approaches, although these approaches were almost all conducted in visual meteorological conditions. However, their workload was potentially further exacerbated by having limited recent experience in conducting RNAV GNSS approaches in IMC.
The aircraft had sufficient fuel to conduct the flight from Cairns to Lockhart River and return, with additional fuel for holding on both sectors if required. In addition, there was no evidence to indicate any organisational or commercial pressures on the pilot to complete the flight, but the extent to which self-imposed pressures or incomplete knowledge of procedural requirements influenced the pilot’s performance could not be reliably determined.
The aircraft was not fitted with a terrain avoidance and warning system (TAWS). Given the aircraft’s descent profile on the second approach, if a TAWS had been fitted and been operational, it would have provided the pilot with both visual and aural alerts of the approaching terrain for an extended period.
There was no requirement in Australia for piston-engine aeroplanes (such as VH-OZO) to be fitted with a TAWS. Although the Civil Aviation Safety Authority (CASA) had been considering changes to TAWS requirements since 2008, the Australian requirements at the time of the accident for some types of small aeroplanes being used for air transport operations were less than those of comparable countries and they were not consistent with International Civil Aviation Organization (ICAO) standards or recommended practices.
More specifically, although there was a TAWS requirement in Australia for turbine-engine aeroplanes carrying 10 or more passengers under the IFR, there was no requirement for piston-engine aeroplanes authorised to carry 10 or more passengers (an ICAO standard adopted as a requirement by many comparable countries) and no requirement for turbine-engine aeroplanes authorised to carry 6 to 9 passengers (an ICAO recommended practice adopted as a requirement by many comparable countries). However, even if these changes had been introduced in Australia prior to the accident, it is unlikely they would have resulted in an aeroplane such as VH-OZO being fitted with a TAWS.
The aircraft was fitted with 2 Garmin GNS 430W GPS units that provided navigation and radio communication capability. As part of the unit’s navigation capability, there was also a terrain awareness function capable of providing visual pop-up terrain alerts. However, that functionality was not to the same standard required for a TAWS installation. It could not be determined whether this function was selected on by the pilot during the accident flight.
Although the GNS 430W unit was suitable for an RNAV GNSS approach and other non-precision instrument approaches, it did not provide vertical guidance information, which would have explicitly indicated that the aircraft was well below the recommended descent profile.
CFIT accidents have been a significant problem over many years, although the rate of such accidents has been decreasing. However, risk factors still remain, particularly for smaller operators. Ideally, in order to minimise the risk of CFIT, operators conducting passenger transport operations under the IFR would use aircraft fitted with a TAWS and/or have a GPS/navigational system that provides vertical guidance during non-precision instrument approaches.
Nevertheless, even without these systems, there are other means available for such operators to minimise CFIT risk. In this case, the operator had specified a flight profile for straight-in instrument approaches and stabilised approach criteria in its operations manual, and encouraged the use of stabilised approaches, but there were limitations with the design of these procedures.
In particular, the operator’s stabilised approach criteria specified an applicable height of 300 ft above aerodrome elevation for operations in IMC. A similar problem has also been identified in multiple other operators conducting passenger transport operations under the IFR. Although an applicable height of 1,000 ft in IMC has been widely recommended by ICAO and many other organisations for over 20 years, CASA had not provided formal guidance information to operators in Australia regarding the content of stabilised approach criteria.
There were also limitations with the operator’s other risk controls for minimising the risk of CFIT, including no procedures or guidance for the use of the terrain awareness function on the aircraft’s GNS 430W units, and limited monitoring of the conduct of line operations.
What has been done as a result
On 2 December 2021, Civil Aviation Safety Regulation (CASR) Part 121 (Australian air transport operations – larger aeroplanes) and CASR Part 135 (Australian air transport operations – smaller aeroplanes) commenced. Associated with these regulations, piston-engine aircraft being used for air transport with a maximum operational passenger seat configuration (MOPSC) of 10 or more were required to have a TAWS and operate under Part 121, with the applicable dates dependent on the MOPSC and other factors.
In December 2021, CASA also published guidance material for CASR Part 121 and Part 135. This included guidance information about stabilised approach criteria, including advice regarding applicable heights for stabilised approach criteria in IMC, including an example height of 1,000 ft above aerodrome elevation in IMC.
Associated with the introduction of CASR Part 135 in December 2021, air transport operators of smaller aeroplanes were required to conduct a flight crew member proficiency check at intervals of 6 months (for IFR or night VFR operations) or 12 months (for day VFR operations).
Safety message
All operators conducting air transport operations under the IFR should evaluate the risk of CFIT in their operations. In addition, any such operators that do not currently have a TAWS fitted to their aircraft should recognise the substantial benefits of a TAWS, and be actively seeking to install a TAWS to maximise the safety of their operations.
In addition, there are many other lessons for operators of small aircraft to reduce their CFIT risk. These include:
If a TAWS is not currently viable but they have aircraft with a GNS 430 or similar system that provides a terrain awareness function, fully understand the nature and limitations of this function and develop procedures and guidance for pilots about its operation (particularly for instrument approaches or operations in IMC).
If not already fitted, actively seek to upgrade their GPS/navigational system to one that provides vertical guidance information on non-precision instrument approaches.
Develop (or review) flight profiles for instrument approaches that provide clear guidance regarding the expected configuration, speed and other requirements at key stages of the approach.
Develop (or review) stabilised approach criteria in line with best-practice industry guidance and ensure that the applicable heights or reference points are suitable for straight-in approaches and operations in IMC.
Review the frequency and content of flight crew member proficiency checks to ensure they provide sufficient opportunities to monitor the way instrument approaches are being conducted during line operations (noting that such checks for IFR operations conducted under CASR Part 135 are now required every 6 months). In addition, such operators should consider options for obtaining and reviewing recorded flight data of normal line operations for continuous learning purposes.
The occurrence
Overview
On 11 March 2020, a Cessna 404 aircraft, registered VH-OZO, was being operated by Air Connect Australia to conduct a passenger charter flight from Cairns to Lockhart River, Queensland. On board were the pilot and 4 passengers. The flight was being conducted under the instrument flight rules (IFR).[1]
Consistent with the forecast, there were areas of cloud and rain that significantly reduced visibility at Lockhart River Airport. After arriving at Lockhart River, the pilot commenced an area navigation (RNAV) global satellite system (GNSS) instrument approach to runway 30. The aircraft descended to an altitude of about 400 ft before the pilot conducted a missed approach. The pilot immediately commenced a second RNAV GNSS approach to runway 30, and during the descent the aircraft collided with terrain.
Planned flight
The passengers were contracted to carry out work at the local school at Lockhart River. The client arranged with the operator for the aircraft to depart Cairns at 0730 Eastern Standard Time[2] on 11 March 2020, wait on the ground at Lockhart River for about 5 hours, then depart at 1430 with the same passengers for the return flight. The operator assigned the pilot who regularly conducted the operator’s charter flights.
For the arrival at Lockhart River, the forecast weather was for light winds and rain and low cloud with periods of visibility reducing to 3 km in rain. There was also a 30% probability of thunderstorms. The pilot had submitted a flight notification, which specified IFR and capability for an RNAV instrument approach. The aircraft had sufficient fuel to conduct an approach at Lockhart River and return to Cairns and hold at Cairns for 1 hour if required.
Flight to Lockhart River
The aircraft departed Cairns at 0719 and tracked for the first planned waypoint on climb to its cruise level of 10,000 ft above mean sea level. Based on the forecast winds, the estimated time of arrival at Lockhart River was 0852. As the flight progressed, the pilot amended the estimated time of arrival to 0904. The aircraft’s track during the flight is shown in Figure 1.
Figure 1: VH-OZO recorded flight path from Cairns to Lockhart River, Queensland
Source: Google Earth overlaid with OzRunways data, annotated by the ATSB
At 0836, the pilot advised air traffic control that the aircraft was approaching top of descent, then tracking direct for the runway 30 RNAV GNSS instrument approach at Lockhart River, and the pilot requested traffic information. The controller responded there was no reported IFR traffic. At 0840, the pilot reported leaving 10,000 ft on descent and, at 0842, the controller advised the pilot of the very high frequency (VHF) and high frequency (HF) radio frequencies applicable to the rest of the flight. That was the controller’s last contact with the pilot and no further routine interactions with the controller were expected.[3]
During descent, the pilot transmitted on the common traffic advisory frequency (CTAF) for Lockhart River to activate the runway lighting for a period of 30 minutes. At 0852, the aerodrome frequency response unit (AFRU) broadcast ‘Lockhart River CTAF, runway lights are on’.
At about this time, the pilot very likely obtained weather information from the automated weather information service (AWIS) via VHF radio. Notes taken by the pilot indicated the wind was calm, visibility was at least 10 km, there was broken cloud[4] at 1,800 ft, broken cloud at 3,500 ft and overcast cloud at 5,300 ft, and the QNH was 1,008 hPa (see Automated weather information service).
At about 0857, the aircraft levelled off at 5,500 ft. At this time the aircraft was heading to waypoint LHREB, one of 3 initial approach fixes (IAFs) for the RNAV GNSS instrument approach to runway 30 (Figure 2). The weather information indicated that the conditions were better than the landing minima (which were a cloud ceiling of 730 ft and visibility 4,200 m).[5]
Figure 2: Lockhart River RNAV GNSS runway 30 approach chart
Source: Airservices Australia, annotated by the ATSB
First approach at Lockhart River
Figure 3 depicts the aircraft’s recorded flight track for the first approach and missed approach at Lockhart River. The altitudes described throughout the report are truncated to the nearest 100 ft.[6]
At 0859:38, the aircraft passed abeam LHREB, commenced descent from 5,400 ft and turned left to track to the runway in accordance with the RNAV GNSS procedure. At 0901:25, the pilot made a radio broadcast on the CTAF, advising the aircraft was 10 NM[7] to the south-east of the aerodrome, inbound to runway 30 and on descent passing 4,000 ft. Shortly afterwards, the aircraft passed the intermediate fix (IF) LHREI at 4,000 ft.
Figure 3: Flight track of VH-OZO during first RNAV GNSS approach at Lockhart River Airport with times, feature labels, and approach parameters superimposed
Source: Google Earth overlaid with OzRunways data, annotated by the ATSB
At about 0903, one of the passengers sent a text message that contained an image of conditions outside the aircraft (Figure 4). At that time, the aircraft was over halfway between LHREI and the final approach fix (FAF) LHREF, at an altitude between 3,100 and 2,500 ft. The photograph had been taken through a passenger window on the right side of the aircraft cabin and, although there was significant cloud in the vicinity, some terrain/coastline was visible near the intersection of the wing’s leading edge and the engine cowl.
Figure 4: Image recorded by a passenger looking forward over the right engine and sent via text message at 0903
Source: Supplied, lower section of image cropped by the ATSB
The aircraft continued the descent on the approach track and passed LHREF on descent through 2,300 ft. At 0904:27, the pilot broadcast on the CTAF that the aircraft was at 5 NM and on final (approach) to runway 30.
The minimum descent altitude (MDA) was 730 ft.[8] The aircraft arrived at the missed approach point (MAPt) LHREM at 0906:17 on descent through about 600 ft. The descent continued to about 400 ft then, about 1,000 m from the runway, the aircraft started to climb. The aircraft was passing 600 ft as it crossed the runway threshold in the early stages of a missed approach. In accordance with the missed approach procedure, the aircraft was turned slightly right to track towards the turning fly-over waypoint LHREH.
At 0907:22, the pilot broadcast on the CTAF that they were conducting a missed approach for runway 30, tracking to the west then turning back to the east and climbing towards 3,500 ft (as specified for the missed approach procedure). After passing LHREH at 0907:43 on climb through 1,200 ft, the aircraft turned right to track east as prescribed by the approach chart.
At 0909, the pilot contacted Flightwatch[9] on HF and advised:
[VH-OZO] conducting a missed approach runway three zero [30] at Lockhart River, and we’ll be joining the approach on runway three zero [30], ops normal time two three three zero [2330]
The middle part of this radio transmission, as recorded by Airservices Australia, was unclear, which is not uncommon for HF radio communication.
Second approach at Lockhart River
The aircraft continued the climb to 3,800 ft before descending to level out at 3,500 ft, heading towards the closest IAF, LHREA. At 0912:51, the AFRU recorded runway lights on, consistent with the pilot reactivating the runway lights for another 30-minute period. About 2.0 NM prior to reaching LHREA, at 0913:53, the aircraft commenced a right turn towards the IF, and initially was right of the inbound track to LHREI (Figure 5).
Figure 5: Flight track of VH-OZO during second RNAV GNSS approach at Lockhart River Airport with times, feature labels, and approach parameters superimposed
Source: Google Earth overlaid with OzRunways data, annotated by the ATSB
At about 0914, while the aircraft was tracking towards LHREI on a south-westerly heading at 3,500 ft, an image was uploaded to social media by one of the passengers (Figure 6). The camera was oriented to the west, which was in the general direction of Lockhart River. An associated message indicated very low visibility and that the pilot was circling while waiting for a break in the weather. Another passenger sent a text message at 0914 stating that the first attempt at landing was unsuccessful, the runway was not visible and there was heavy rain.
Figure 6: Image recorded by a passenger looking over the right wing and uploaded to social media at 0914
Source: Supplied
At about 0914:43, when about 2.7 NM from LHREI, the aircraft started descending from 3,500 ft. At this time, the aircraft was tracking towards the initial approach track between LHREA and LHREI (Figure 5).
At 0915:50, the pilot made another inbound broadcast on the CTAF advising:
ten miles [10 NM] to the south-east on descent passing three thousand eight hundred [3,800 ft] correction two thousand eight hundred [2,800 ft], straight-in approach runway three zero [30], circuit area two one [time 0921].
The recorded height was about 2,800 ft at this time.
The aircraft continued descending and passed over LHREI and turned right to fly parallel to the intermediate approach track at about 2,800 ft. According to the recommended flight profile for a 3° approach (Figure 2), the aircraft should have descended from 3,500 ft at about 4.2 NM from the FAF (9.2 NM from the MAPt). At this point, the aircraft was at about 2,500 ft.
The descent continued at a similar gradient to the first approach although at about 1,000 ft lower than that approach. About halfway between LHREI and LHREF, the aircraft descended below the intermediate segment minimum safe altitude of 1,800 ft and continued to descend on the same descent profile.
When the aircraft passed LHREF at 0918:23, it was on descent through about 1,100 ft (below the 3° approach profile height of 2,160 ft). The aircraft was right of the final approach track and, shortly after passing LHREF, the aircraft started turning back towards the final approach track.
From LHREF to LHREM, the altitude limitation was the MDA of 730 ft and, at 09:18:55, the aircraft was approaching 700 ft. The aircraft then descended below the MDA and, soon after, the aircraft’s flight path crossed the final approach track (on a ground track about 20° left of the final approach track).
Collision with terrain
The aircraft’s track and descent continued until it impacted a sand dune on the coastline at about 0919:41. The pilot and 4 passengers were fatally injured, and the aircraft was destroyed. Due to the impact forces, the accident was not survivable.
Context
Pilot information
Qualifications and experience
The pilot held a commercial pilot licence (aeroplane) with an instrument rating and multi-engine aeroplane endorsement. They had recorded a total of 3,220 hours before the accident flight.
The pilot obtained the multi-engine endorsement in June 2014 (on a Cessna 310 aircraft), and had accrued 1,177 hours on multi-engine aircraft, including 399 hours on the Cessna 404 aircraft type. In June 2014, the pilot also obtained their initial (multi-engine) instrument rating, and their total instrument time was recorded as 148 hours.
The pilot operated as a commercial pilot in remote locations for about 5 years. Up until March 2016, they operated single-engine aircraft. In March 2016 they received training and were found competent on the Piper PA31 aeroplane type. Between March 2016 and February 2018, the pilot conducted flights for a charter company that operated Cessna 310 and Piper PA-31 aircraft, usually under visual flight rules (VFR[10]) with occasional instrument flights. They were approved by the Civil Aviation Safety Authority (CASA) as chief pilot of this operator in December 2016.
From October 2018, the pilot was employed by Air Connect Australia on a casual basis. Prior to joining the operator, the pilot’s recorded total flying time was 2,800 hours. The pilot completed induction then conducted a flight for type-specific training in a Cessna 421 from an independent CASA-approved flight examiner that the operator frequently used for proficiency checks. This flight was about 1.6 hours and the examiner recalled that the pilot managed the transition to the 400-series Cessna without any problems. Other than the pressurisation system in the Cessna 421, the examiner considered it was operationally equivalent to the unpressurised Cessna 404.[11]
Following this type-specific training, the chief pilot of Air Connect Australia supervised the pilot on 4 flight sectors in VH-OZO and conducted an operator proficiency check (OPC) over 2 further sectors on 29 October 2018. The chief pilot noted that the pilot’s planning was satisfactory, and operation of the aircraft was above standard.
From November 2018 to the accident flight, the pilot was based in Cairns and conducted most of the operator’s charter flights, normally in VH-OZO. In December 2019, the chief pilot organised for the pilot to undertake some supervised flying at night with an instructor in a Piper PA-44 Seminole in order for the pilot to maintain night recency. The operator rarely conducted night flights.
In the 90 days prior to the accident (11 March 2020), the pilot had conducted 59 flights (60 flight hours), all in VH-OZO. This included 4.5 hours recorded instrument flying time. In the last 30 days, the pilot had conducted 12 flights (13.5 flight hours), including 1.0 hour recorded instrument flying time. The most recent flights were on 18 February 2020.
Since joining the operator in late 2018, the pilot had logged 69 RNAV GNSS approaches to various aerodromes. These included 21 RNAV GNSS approaches in the previous 6 months, 12 in the previous 90 days, and 2 in the previous 30 days (with the last on 18 February 2020). Only one of the approaches in the previous 6 months was conducted to some extent in instrument meteorological conditions (IMC),[12] and this approach resulted in a missed approach (see Prior missed approach during an RNAV GNSS approach (22 January 2020).
Lockhart River experience
Since the start of 2019, the pilot had flown into Lockhart River 8 times, 6 of which were logged as RNAV GNSS approaches, with the most recent being on 14 October 2019.
The recorded data for previous RNAV GNSS approaches into Lockhart River were reviewed by the ATSB, with the details provided in Table 1. A review of recorded weather information indicated that none of these previous approaches at Lockhart River were conducted in IMC. For the 17 January 2019 approach, there may have been reduced visibility in the early part of the approach.[13]
Table 1: Pilot’s prior flights to Lockhart River 2019–2020
Date
Departure location
Approach type recorded
ATSB comments
17 January 2019
Cairns
RNAV GNSS
Aircraft passed over MAPt for runway 30 at 1,500 ft and then conducted a circling approach to land on runway 12
21 March 2019
Cairns
RNAV GNSS
Missing flight data for the approach and landing though appeared to be heading for runway 30 IAF
23 March 2019
Cairns
RNAV GNSS
Flight data shows an RNAV approach to runway 30 from the FAF but missing flight data before that point
24 March 2019
Coen
RNAV GNSS
Flight data shows an RNAV approach to runway 30 from the FAF but missing flight data before that point
24 March 2019
Coen
VFR
Logged as VFR flight, so data was not reviewed
18 April 2019
Cairns
VFR
Logged as VFR flight, so data was not reviewed
9 October 2019
Cairns
RNAV GNSS
No flight data available
14 October 2019
Cairns
RNAV GNSS
No flight data available
Proficiency checks and flight reviews
The pilot conducted initial instrument flight training in 2014. During training it was noted that the pilot needed to scan faster, improve situation awareness and improve radio phraseology. On one simulator training exercise it was noted the pilot was too high on the RNAV GNSS MDA and minimum altitudes.
The pilot did not pass their first attempt at attaining an instrument flight rating (in a Cessna 310) on 2 June 2014 for not maintaining altitude within +100 ft and -0 ft at the MDA, not using accepted navigation procedures, not being within half-scale deflection of glideslope, and not demonstrating sound command judgement. On the next day, 3 June 2014, the pilot passed on their second attempt.
Under Civil Aviation Safety Regulation (CASR) 61.650, pilots need to have completed an instrument proficiency check (IPC) in the previous 12 months to fly a multi-engine aircraft under the instrument flight rules (IFR). The IPC must also be done in a multi-engine aircraft of the same category.
The pilot undertook 6 IPCs with 3 different independent CASA-approved flight examiners between 2016 and 2019. These are detailed in Table 2.
Table 2: Pilot instrument proficiency checks 2016–2019
Date
Outcome
17 March 2016
Competent
14 May 2017
Not competent on a ground component (underpinning knowledge) with no assessment of flying capability
27 July 2017
Competent
4 August 2018
Not competent due to misread of altimeter by 1,000 ft (under-read)
5 August 2018
Competent
7 August 2019
Competent
The pilot’s last 3 IPCs were conducted on 4 August 2018, 5 August 2018 and 7 August 2019, all with the same CASA-approved flight examiner (who also conducted the IPC in March 2016).
On 4 August 2018, the pilot did not pass the IPC due to misreading the altimeter. The flight examiner recalled that they were on descent to the minima on a circling approach and, when the aircraft was at 1,000 ft above the MDA, the pilot asked whether they were visual. It then became apparent that the pilot had misread the altimeter by 1,000 ft (that is, they thought the aircraft was 1,000 ft lower than it was). The pilot successfully passed the check the following day.
The pilot’s most recent IPC was conducted on 7 August 2019 and was valid until 7 August 2020. The flight examiner who conducted this check was selected by the pilot; it was not the flight examiner regularly used by the operator (and who was familiar with the Air Connect Australia operations manual and could also conduct OPCs).
For each of the IPCs in 2018 and 2019, the pilot conducted a training flight with an instructor prior to the test flight, using the same Cessna 310 aircraft as in the test flights. The instructor commented that the pilot flew significantly better in 2019. Between the 2 checks in 2018 and 2019, the Cessna 310 aircraft was fitted with a GPS/navigational system and electronic flight instruments comprising an attitude display indicator (ADI) and a horizontal situation indicator (HSI). The ADI displayed aircraft attitude information, together with a secondary display of air data information (airspeed, altitude and vertical speed). The ADI and HSI each provided course and advisory vertical guidance during RNAV GNSS approaches.[14]
As already noted, the pilot undertook an operator proficiency check (OPC) on 29 October 2018 before commencing line operations with Air Connect Australia. This was the last OPC carried out on the pilot (see also Operator proficiency checks).
Between February and June 2018, prior to joining the operator, the pilot undertook training with an airline in a multi-crew environment and high-performing (turboprop) aircraft. Although the pilot obtained high marks in theory and written tests, they did not obtain satisfactory ratings during 3 proficiency assessments in a simulator (with remedial training given after each of the first 2 assessments). A common identified problem was instrument approaches, with issues identified including inefficient instrument scan, fixation (on some parameters), speed control, workload management, insufficient situational awareness and ineffective profile management. The ATSB notes that the training and checking environment at the airline was different to the pilot’s previous experience and the operational environment at Air Connect Australia.
Observations of the pilot’s approach to safety
The chief pilot (and managing director) of Air Connect Australia described the pilot as being a good pilot who would not have gone into an approach if they thought the weather was going to be poor, and that there was never any pressure to fly in poor weather. The pilot was trusted to make safety decisions, which would be supported by the chief pilot. This was consistent with the recollection of a previous pilot who flew with the operator, who reported that there was never any operational pressure (from the operator’s key personnel).
Another pilot stated that the pilot of the accident flight had ‘good stick and rudder skills’ and that everything was done ‘by the book’. It was also reported that the pilot had not expressed any concerns about the operator, including its approach to safety.
Former colleagues from when the pilot was chief pilot at a previous operator described the pilot as smart, diligent, and methodical with good knowledge of the rules and regulations. They reported that the pilot did not take shortcuts or unnecessary risks and had good hand-flying skills.
With reference to instrument approaches, one pilot advised that they had many conversations with the pilot of the accident flight regarding aircraft accident reports and safety, and the pilot of the accident flight had stated that they would conduct instrument approaches using the published constant-descent profile and would not intentionally deviate below published segment minimum safe altitudes in order to get visual early in an approach.
During January 2020, the pilot spent a week conducting a series of charter flights between Aurukun and Weipa, Queensland, in VH-OZO with the same group of passengers (see also Prior missed approach during an RNAV GNSS approach (22 January 2020)). Their perception was that the pilot was a good, competent pilot who was diligent, professional, and responsible and that they never felt unsafe. They also advised that they observed the pilot reviewing forecast and actual weather conditions regularly and that the pilot would delay flights due to weather conditions if necessary. Some of the passengers reported observing the pilot make weather-based decisions and did not display any indications of external pressure to fly in poor weather. One of the passengers reported that the pilot had said they would only ever make 2 attempts at landing and, after that, would return to the departure aerodrome or divert to an alternate.
Recent history
The pilot had recently returned from annual leave, with their last flights before leave conducted on 18 February 2020. The 3 days prior to the accident flight were reported to be uneventful. It was described that the pilot ate and exercised regularly and had been sleeping well with a standard time to sleep about 2230 and wake time about 0700–0730. The night before the accident flight, the pilot went to bed at about 2230 and woke at about 0530. There was nothing of note from the pilot’s recent history to suggest they were experiencing a level of fatigue known to affect performance.
The pilot was notified about the 11 March 2020 flight a few days in advance. It was reported that the pilot had been in a good mood in the days prior to the flight and was looking forward to flying again. On the day before the flight, the pilot went to Cairns Airport and started the aircraft’s engines to re-familiarise themselves and ensure everything was ready for the next day’s flight.
Medical information
The pilot’s Class 1 Aviation Medical Certificate was renewed on 14 February 2020 and was valid until 14 February 2021. There were no indications of any significant medical problems in the pilot’s aviation medical records. There was no evidence to suggest the pilot had any current or ongoing medical issues at the time of the accident.
A post-mortem examination was conducted by a forensic pathologist on behalf of the Queensland Coroner. The pathologist found that there was ‘No obvious natural disease to contribute to the cause of death within limits of examination …’. Forensic toxicology screening returned negative results (that is, no alcohol or substances were detected). The sample was unsuitable for analysis for carbon monoxide.
Aircraft information
General information
The Cessna 404 Titan is an unpressurised, low-wing, twin piston-engine aircraft with retractable landing gear. The maximum take-off weight (MTOW) is 3,810 kg, and the aircraft was certified to be flown by a single pilot.
VH-OZO was manufactured by the Cessna Aircraft Company in 1980. It was reported that the aircraft was first operated in Australia before being transferred to Papua New Guinea and registered as P2-ALG. In December 2009, a CASA Certificate of Airworthiness was issued, and the aircraft was registered as VH-OZO. At that time, the aircraft’s total time in service was 28,193 hours.
Seating
The type certificate data sheet for the Cessna 404 stated the aircraft type had 11 total seats (2 pilot seats and 9 passenger seats). In 1980, VH-OZO was configured with a modified seating configuration with 13 seats (2 pilot seats and 11 passenger seats).[15]
During an audit of Air Connect Australia in June 2017, CASA identified that the Airplane Flight Manual stated a maximum of 9 passenger seats aft of the pilot seats but there was 11 on the aircraft. In its initial audit response, the operator stated that the seating change was approved many years ago and it was attempting to find supporting documentation. In a subsequent response, the operator stated that it had previously operated and would continue to operate with a maximum of 9 passengers. It noted that the extra seating would remain in the aircraft as it formed part of the aircraft’s current weight and balance data.
During the investigation, the chief pilot confirmed that the operator never operated the aircraft with more than 9 passengers and normally operated with significantly less than 9 passengers.
Photos taken during the accident flight indicated that no passengers were seated in the front right seat next to the pilot.
Aircraft instruments and systems
On arrival into Australia, the aircraft was fitted with aerial geophysical survey equipment and was operated in that configuration until the equipment was removed in March 2012. Concurrently, the aircraft were modified in accordance with an engineering order to install new types of avionics and integrate those with existing units. The post-modification avionics, including existing equipment, consisted of:
Bendix/King KR87 automatic direction finder (ADF) and Bendix/King KI-227 ADF indicator
Collins HF radio
Cessna 400B Navomatic autopilot
Bendix weather radar (monochrome display).
These units were still installed at the time of the accident except for the transponder, which had been replaced by an automatic dependent surveillance-broadcast (ADS-B) compliant unit in April 2017.
VH-OZO was not fitted with a terrain avoidance and warning system (TAWS), nor was it required to be under legislation in place in Australia at the time of the accident. Further information is provided in Terrain avoidance and warning systems.
An assigned altitude indicator was fitted to the aircraft, which was designed to be used as a reminder of the designated altitude. Altitudes could be manually set by means of individual thumb wheels and no aural or visual alerts were provided when reaching or leaving the set altitude. The aircraft did not have an altitude alerting system, nor was it required for the type of aircraft and operation.[16]
The 400B autopilot was one of the standard equipment options for the Cessna 404 type. It could provide pitch and roll control with heading and altitude hold (on command). A navigation function provided the autopilot with inputs from an associated CDI (the GI-106A), which in this case received data from the number‑1 GNS 430W.
For an RNAV GNSS approach, a pilot could ‘couple’ the autopilot for lateral navigation and manage vertical navigation by adjusting the autopilot pitch wheel to achieve the intended rate of descent. For a level segment, the pilot could select altitude hold on reaching the intended altitude. Several pilots who had flown VH-OZO advised that they routinely hand flew instrument approaches due to autopilot constraints.
The aircraft was fitted with the instrumentation required for operations under the IFR. These flight instruments were conventional analogue indicators and reflected the original specifications for the aircraft. The second artificial horizon/attitude indicator and altimeter were located on the right side of the co-pilot panel (far side of the instrument panel relative to the pilot) (Figure 7).
Figure 7: VH-OZO instrument panel
Source: Supplied, annotated by the ATSB
A closer view of the instrument panel is depicted in Figure 8. It had the standard 6 flight instruments directly in front of the pilot’s seat on the left. These include the attitude indicator, which depicts the aircraft’s basic roll and pitch attitude, and the primary performance instruments – altimeter, airspeed indicator and vertical speed indicator (VSI). Below those were 2 (GI-106A CDI) instruments[17] that provided course deviation indication provided either by the GNS 430’s digitally-tuned VOR/localiser and glideslope receiver or GPS input to conduct an RNAV GNSS approach. One CDI instrument was coupled to the aircraft’s number-1 GNS 430W GPS unit and the other to the number-2 GPS unit.
The basis of cockpit design is to have the primary instruments within a small arc of the pilot’s forward line of sight. Navigation systems such as the GPS units may be located next to the primary instruments, as was the case in VH-OZO. While conducting an RNAV GNSS approach, it is imperative that the pilot includes the GPS units in the scan.
Figure 8: Instrument panel of VH-OZO
Source: Supplied, annotated by the ATSB
Altimeters
VH-OZO was equipped with two 3-pointer altimeters (Figure 9), including one directly in front of the pilot. They had a 100-ft pointer (long and narrow), 1,000-ft pointer (short and wide) and 10,000-ft pointer (long and thin with a triangle at the end). The diagonal hashing indicated when below 10,000 ft and was gradually covered above that height.
These types of 3-pointer altimeters are very common in general aviation aircraft, including small aeroplanes used for passenger transport activities. Research has shown that such altimeters can be associated with misreading errors, including misreading the altitude by 1,000 ft, although accidents known to be associated with such errors seem relatively rare. Accordingly, such altimeters (and some other altimeter designs) are no longer allowed to be used on air transport certificated aircraft. Further information about requirements and guidance regarding altimeters is provided in Appendix A – Research and guidance regarding design of altimeters.
The aircraft was not fitted with a radio altimeter, nor was it required for the type of aircraft and operation.
Figure 9: Example of the 3-pointer type of altimeter fitted in VH-OZO
This altimeter shows an altitude of 1,210 ft (10,000 ft pointer indicating 0, 1,000 ft pointer indication 1,000 ft and 100 ft pointer indicating 210 ft.
Source: avioelectronica.com
GNS 430W overview
The Garmin GNS 430W is a panel-mounted unit that provides GPS navigation, instrument landing system or VHF omnidirectional radio range navigation, and VHF radio communication. It was approved for IFR operations, including RNAV GNSS approaches, and was used in conjunction with a CDI.
Although the ‘W’ designated wide area augmentation system capabilities[18] that facilitated GPS approaches with vertical guidance, Australia did not have the associated satellite-based augmentation system to enable this functionality at the time of the accident. As such, the GNS 430W was approved to provide distance and track information only for RNAV GNSS non-precision approaches.
Information was displayed to the pilot on an 8.4 cm by 4.6 cm (240 by 128 pixel) high-contrast colour LCD. A pilot could select the pages and menus to display relevant information during various flight stages. Those included the default navigation page and additional pages including:
a 2-dimensional representation of terrain relative to the aircraft position
information for vertical navigation of the aircraft
a moving map display
information about the status of the GPS satellite constellation
information relevant for the navigation and communication functions of the unit.
When used for an RNAV GNSS approach, the navigation page would display a graphic CDI together with the active leg of the approach and 6 user-selectable data fields.[19] After passing the waypoint it was tracking to, the unit would automatically sequence to the next waypoint.
When approaching a waypoint such as an initial approach fix (IAF), if a turn was required, the unit would display the recommended flight path (turn) to intercept the next track segment. The unit would also display a flashing message about 10 seconds prior to the start of the recommended turn, alerting the pilot that a turn was required and the track to intercept.
To use the unit for RNAV GNSS approaches, it was a requirement that the NavData card[20] was valid and the approach procedure was loaded from the database. The operator subscribed to the Jeppesen NavData service that provided monthly updates. It was reported that the pilot updated the NavData card using a laptop computer in the 24 hours prior to the flight. There were no changes in the update that would have been relevant to the accident flight.
The terrain, obstacle and airport terrain database was loaded on a terrain data card. The operator did not subscribe to an update service for terrain/obstacle data. Obstacle data was updated on a 56-day cycle and updates to the terrain database were released on an ‘as-needed’ basis. There was no requirement to have current obstacle or terrain databases to use the GNS 430W for flight under the IFR and/or during an RNAV GNSS approach. A June 2018 photograph of VH‑OZO’s GNS 430W receivers indicated the obstacle database installed at that time was dated October 2011.[21]
Fault detection and exclusion was incorporated into the GNS 430W software to detect satellite failure and exclude failed satellites from usage.
In addition to their experience with VH-OZO, the pilot of the accident flight had experience using GNS 430 units during their time flying Cessna 310 and PA-31 aircraft with a previous operator, which included units with a terrain awareness function.
Garmin TERRAIN function
Garmin TERRAIN was a non-certified[22] terrain awareness system, provided as a standard feature of 400W-series units, to increase pilot situation awareness and help reduce the risk of controlled flight into terrain (CFIT). The functions required a valid 3D GPS position and a valid terrain and obstacle database. Terrain and obstacle information was advisory only and was not equivalent to warnings provided by TAWS. The Garmin 400W SeriesPilot’s Guide & Reference manual stated:
CAUTION: The Terrain feature is for supplemental awareness only. The pilot/crew is responsible for all terrain and obstacle avoidance using information not provided by the 400W-series Terrain feature.
When the GNS 430’s terrain page was selected, it presented a 2-dimensional colour-coded display of terrain tiles and obstacles from its database, relative to the aircraft’s current position/altitude. Red (warning) indicated terrain/obstacles above and up to 100 ft below the aircraft’s current altitude, yellow (caution) between 100 ft and 1,000 ft below the current altitude, and black more than 1,000 ft below the current altitude. The terrain page would not normally be selected when conducting an RNAV GNSS approach.
Terrain advisory and alert messages were provided when flight conditions met specific parameters. The advisories/alerts comprised a visual annunciation in the lower left corner of the unit’s LCD display, accompanied by a larger pop-up advisory/alert on the current display page (except the page displaying terrain). To clear the pop-up advisory/alert, the pilot would either acknowledge the message to return to the selected page or acknowledge the advisory/alert and display the terrain page. The system did not provide auditory alerts.
A pilot could use an ’inhibit mode’ to deactivate the terrain advisory/alert message system and pop-up messages would not be generated. The terrain page was still selectable and would display colour-coded terrain and obstacle information relative to the aircraft’s position. Once inhibited, the terrain annunciator field displayed a ‘TER INHIB’ annunciation and the terrain alert system remained deactivated until reselected. The GNS 400W-Series manual stated that the terrain inhibit mode could be used when the advisories/alerts were deemed unnecessary by the pilot. The manual also stated:
Flying VFR into an area where unique terrain exists could cause the system to annunciate a nuisance alert. Pilots should use discretion when inhibiting the TERRAIN system and always remember to enable the system when appropriate.
According to the GNS 400W-Series manual, the terrain system issued a premature descent alert (PDA) when the aircraft was significantly below the normal approach path to a runway. The manual indicated that this alert would activate depending on the aircraft’s height above terrain and distance from the runway threshold (for example, it would be triggered if the aircraft was about 400 ft above terrain when 10 NM from the runway threshold, 350 ft at 5 NM, 320 ft at 4 NM, and 280 ft at 3 NM). PDA alerts were not provided when the aircraft was within 0.5 NM of the runway or less than 125 ft above terrain within 1.0 NM of the runway.
Based on this information and the recorded data for the accident flight (Recorded flight data), provided that the terrain advisory/alert function was enabled, a yellow and black ‘TERRAIN’ annunciation would be generated in the lower left corner of the LCD display, accompanied by a yellow and black ‘TOO LOW – TERRAIN’ PDA pop-up alert (Figure 10), about 15 seconds prior to the terrain collision.
Figure 10: Premature descent alert on the GNS 430W display
Source: Garmin GNS 400W Series Pilot’s Guide & Reference
The terrain system also provided forward-looking terrain avoidance (FLTA) alerts. Provided the terrain system was enabled, a FLTA terrain alert was generated when the predicted or present aircraft altitude above terrain or obstacles was below the minimum clearance value for that phase of flight. During an approach, the clearance value was 150 ft during level flight and 100 ft when descending.[23] The terrain/obstacle advisory alert comprised a yellow and black ‘TERRAIN’ annunciation in the lower left corner of the LCD display, accompanied by a yellow and black ‘TERRAIN ADVISORY’ or ‘CAUTION OBSTACLE’ pop-up message. The pop-up advisory alert would be displayed on all selectable pages (except the terrain page) and remained visible until the message was cleared/acknowledged by the pilot, or the minimum clearance value was no longer infringed.
If the minimum clearance value for terrain/obstacles remained, a terrain/obstacle ahead alert would be generated. The alert consisted of a flashing yellow and black ‘TERRAIN’ annunciation in the lower left of the LCD panel display and a flashing yellow and black ‘TERRAIN AHEAD’ or ‘OBSTACLE AHEAD’ pop-up alert. The pop-up alert would be displayed on all selectable pages, except the terrain page and remained visible until the message was cleared/acknowledged by the pilot, or the minimum clearance value was no longer infringed.
The GNS 400W-Series manual did not specify the warning period for FLTA alerts. However, an earlier version of the 430/430A-Series manual indicated the ‘TERRAIN ADVISORY’ or ‘OBSTACLE ADVISORY’ pop-up terrain alert would be displayed when approximately 60 seconds from potential impact and the ‘TERRAIN AHEAD’ or ‘OBSTACLE AHEAD’ flashing pop-up terrain alert when 30 seconds from potential impact.
On the accident flight, the descent rate when the aircraft reached 5 NM from the runway threshold (or 3.6 NM from the MAPt) is unclear (see Recorded flight data). However, soon after, the descent rate was about 1,200 ft/min and the predicted flight path would have resulted in an FLTA alert to be generated. Therefore, if the terrain awareness/alert system was enabled, an FLTA alert should have been generated about 30 seconds (or longer) prior to the collision.
Air Connect Australia did not have any operational guidance or procedures regarding the use of the terrain awareness function on the GNS 430W units. The chief pilot reported that, when they were the pilot flying VH-OZO, they would generally leave the function turned on, even though it could be annoying in some locations. However, they did not regularly fly the aircraft and had not conducted the most recent flights in the aircraft.
The ATSB spoke to several pilots who were familiar with GNS 430 units with a terrain awareness function. Some advised that the terrain awareness function would often be inhibited, whereas others would use the function on one 430 unit and inhibit it on the second 430 unit. None of the pilots were aware of operators having specific procedures and guidance for using the terrain function.
Pilots stated that the main reason for the terrain awareness function to be inhibited was the perception that it could issue nuisance alerts, with some of these pilots clarifying that this would only occur (or be a valid concern) when conducting visual approaches at non-licenced aerodromes. One pilot advised that they had heard of some pilots in one operator being concerned about using the terrain function if the terrain/obstacle database was not current. However, 2 experienced flight examiners advised that, in their experience, these databases were commonly not current on aircraft they encountered in their roles and that having a current database was not critical; the advantages of the terrain awareness function were more significant than any potential problem with a terrain/obstacle database not being current.
There was no information available regarding what the pilot of the accident flight normally did with the terrain awareness function when flying VH-OZO. Based on the available information, the ATSB could not establish if the terrain awareness function was enabled or inhibited during the accident sequence, or to what extent the pilot had previously encountered terrain alerts when conducting operations in the aircraft.
Configurations and speeds
The flap settings on the Cessna 404 included ‘UP’, ‘T.O. & APPR’ (take-off/approach) and ‘LAND’ (landing). The take-off/approach setting was often referred to as ‘approach flap’ and sometimes called ‘10° flap’.[24]
According to the Cessna 404 Pilot’s Operating Handbook (POH), which included the Airplane Flight Manual approved by the US Federal Aviation Administration, the maximum landing gear extension speed (and operating speed) was 182 kt, the maximum speed to select approach flap was 182 kt, and the maximum speed to select landing flap was 152 kt.
The POH specified a recommended minimum approach speed (or Vref[25]) at 50 ft of 91 kt (all engines operating, landing flaps, weight 8,100 lb or 3,6764 kg). For all aircraft weights of 7,500 lb (3,402 kg) and lower, the POH stated approach airspeeds (at 50 ft) of 88 kt. Consistent with the POH, the operator’s operations manual provided values for VAPP[26](approach speed) of 91 kt at 8,100 lb and 88 kt at 7,500 lb and lower weights.
The POH stated the minimum control speed (VMCA) with approach flap selected was 78 kt. In addition, the one-engine inoperative best rate-of-climb speed for the aircraft type was 102 kt (flap in the take-off/approach position and gear up) and 109 kt (flap and gear up).
Aircraft maintenance
The aircraft logbook statement specified that VH-OZO was to be maintained in accordance with the system of maintenance developed by the aircraft owner and approved by CASA. The key elements of the system were:
daily inspection in accordance with the Cessna 404 POH
engine and airframe inspections every 100 +/- 10 hours in accordance with the Cessna 404 progressive care program (Operations 1 and 2 plus 3 and 4 completed within 12-month period)
electrical and instrument inspections every 220 hours or 12 months in accordance with system of maintenance schedules
IFR avionics inspections every 220 hours or 12 months in accordance with system of maintenance schedules
special inspections, supplemental inspection documents, and corrosion prevention control program as required
altimeter and pitot-static system inspection and test every 24 months
maintenance release issue for a period of up to 220 hours or 12 months, whichever occurred first.
Scheduled engine and airframe maintenance was carried out by the CASA-approved maintenance organisation associated with the aircraft owner. While the aircraft was based in Cairns, electrical, instrument, and radio maintenance as well as unscheduled maintenance was contracted to licensed aircraft maintenance engineers.
The most recent maintenance was the scheduled 100-hour inspection based on Operations 3 and 4 of the Cessna 404 progressive care program. That was completed on 16 February 2020 at 31,066 hours total time. A maintenance release was issued with the next scheduled maintenance being the oil/filter change after 50 hours operation and compass swing in July 2020.
Other key maintenance was:
19 January 2020 at 31,050 hours: inspection of the electrical, instrument and IFR avionic systems certified as satisfactory
29 January 2019 at 30,750 hours: inspection and test of the pitot-static system and check of altimeters certified as satisfactory.
The current maintenance release was not found at the accident site. Operator records showed that the aircraft had been operated for 3.8 hours between maintenance release issue and the accident flight. The operator and aircraft owner both advised that no aircraft defects had been reported.
The ATSB identified that the vacuum pumps had been in service for a relatively long period and internal wear had not been inspected at the recent 100-hour inspection. Also, there was no record of testing or replacement of the vacuum manifold in the previous 10 years. Although these aspects increased the likelihood of a vacuum system failure, there was no evidence that the vacuum-powered instruments were adversely affected. Further information regarding the maintenance and serviceability of the vacuum system (associated with the attitude indicators and directional gyro) is provided in Appendix B – Vacuum system analysis.
Terrain avoidance and warning systems
General description
A terrain avoidance and warning system (TAWS) provides visual and aural alerting including a look-ahead terrain function. The aircraft’s height above terrain can be based on GPS or radio altitude information. TAWS is a generic term that also includes a ground proximity warning system (GPWS) with a forward-looking terrain avoidance function.
A TAWS is an important tool to help minimise the risk of controlled flight into terrain (CFIT). It provides an independent and unambiguous warning of proximity to the ground or obstacles, regardless of any navigational uncertainty or error such as mis-setting or misreading the altimeter.
Multiple levels or classes of TAWS are defined and internationally recognised. Class B TAWS (TAWS B) includes a minimum of the following alerts:
reduced required terrain clearance
imminent terrain impact
premature descent
excessive rates of descent
negative climb rate or altitude loss after take-off
descent of the aeroplane to 500 ft above the terrain or nearest runway elevation (voice callout ‘Five hundred’) during a non-precision approach.
Class B+ TAWS also has a terrain awareness display that shows surrounding terrain/obstacles relative to the aircraft. Class A TAWS (TAWS A) has all the requirements of Class B+ TAWS, plus 3 additional alerts. Both Class A and class B TAWS have a forward-looking terrain avoidance function.
To maximise its effectiveness, an aircraft operator should have standard operating procedures for the use of a TAWS and for actions to take in response to TAWS alerts.
Australian requirements
Civil Aviation Order (CAO) 20.18 (Aircraft equipment — basic operational requirements), which was in force at the time of the accident, stated that for Australian aircraft:
9.1C A turbine-engined aeroplane that:
(a) has a maximum take-off weight [MTOW] of more than 15 000 kg or is carrying 10 or more passengers; and
(b) is engaged in RPT [regular passenger transport], or charter, operations;
must not be operated under the I.F.R. unless it is fitted with
(c) an approved ground proximity warning system that has a predictive terrain hazard warning function…
(e) if the aeroplane has a maximum take-off weight of 5 700 kg or less, but is carrying 10 or more passengers – a TAWS-B+ system.
In effect, this meant that turbine-engine aeroplanes being used to conduct passenger transport operations under the IFR were required to have a TAWS if the aeroplane was carrying 10 or more passengers or it was a larger air transport aeroplane.[27] There was no requirement for a piston-engine aeroplane (such as VH-OZO) to be fitted with a TAWS.
International requirements for turbine-engine aeroplanes
The Australian TAWS requirements for turbine-engine aeroplanes were consistent with the standards included in International Civil Aviation Organization (ICAO) Annex 6 (Operation of Aircraft) Part I (International Commercial Air Transport – Aeroplanes), which included a standard[28] for all turbine-engine aeroplanes with a MTOW of more than 5,700 kg or authorised to carry 10 or more passengers to have a TAWS. In addition to Australia, this standard had been adopted by comparable countries, including the United States, Canada, New Zealand and Europe.
In 1996, the US National Transport Safety Board (NTSB) issued a recommendation to the US Federal Aviation Administration (FAA) to require that all turbojet-powered airplanes equipped with 6 or more passenger seats have an operating GPWS installed. In 1999 it also recommended that all turbine-powered aeroplanes of the same size be fitted with a TAWS.
In response, the FAA commissioned a report that examined 44 CFIT accidents that occurred between 1985 and 1994 in the US involving turbine-powered aeroplanes with 6 to 10 passenger seats. Of the 44 aeroplanes, 11 were powered by turbojets and 33 were powered by turboprops. None were fitted with a GPWS system. Computer modelling techniques used to analyse the data showed that, had GPWS been fitted, 33 accidents could have been prevented; had enhanced GPWS been fitted, 42 accidents could have been prevented.
Accordingly, the FAA introduced a requirement for all turbine-powered aeroplanes with 6 or more passenger seats to be fitted with a TAWS B (in Federal Aviation Regulations 91.223 and 135.154). The requirement commenced in March 2002 for new aircraft and March 2005 for older aircraft.
The FAA did not propose to introduce the same requirement for piston-engine (or reciprocating-engine) aeroplanes. In its final rule summary in 2000, the FAA stated:
The General Aviation Manufacturers Association (GAMA) is against requiring TAWS on reciprocating-powered [piston-engine] airplanes because the costs would be high (e.g., “TAWS equipment would cost more than the hull value of the aircraft”), and the panel space for installing TAWS with a situational display is not available in these airplanes.
The FAA did not receive any comments that would justify undertaking a new rulemaking project to mandate TAWS for reciprocating-powered airplanes.
However, regarding the issue of panel space, the FAA knows of at least one manufacturer who has developed a complete TAWS unit that was designed to replace an existing panel instrument.
Following the US introduction, from November 2006, ICAO Annex 6 Part I included a recommendation that turbine-engine aeroplanes with an MTOW of 5,700 kg or less and authorised to carry 6–9 passengers should be equipped with a TAWS. This recommended practice was introduced as a regulatory requirement in other countries, including New Zealand (from 2007 for air transport operations under the IFR), Canada (from 2014 for operations other than day VFR flights), and in Europe (for such aeroplanes with an individual certificate of airworthiness issued after 1 January 2019).[29]
International requirements for piston-engine aeroplanes
Applicable from January 2007, ICAO Annex 6 Part I included a standard for TAWS B to be fitted to piston-engine aeroplanes with a MTOW greater than 5,700 kg or authorised to carry 10 or more passengers.
Subsequently, TAWS requirements were introduced in Canada (from 2014 for air transport operations other than day VFR flights), New Zealand (from 2007 for air transport operations under the IFR) and Europe (from 2012 for air transport operations) for piston-engine aeroplanes. No such requirements for piston-engine aeroplanes were introduced in the United States.
Canada also introduced the same requirement for piston-engine aeroplanes with a passenger seating capacity of 6–9 conducting air transport operations other than day VFR flights from 2014. As far as could be determined, no other countries had introduced a TAWS requirement for piston-engine aeroplanes with a passenger seating capacity less than 10.
In its notice of amendments about TAWS requirements in 2012, Transport Canada indicated that the cost for installing a TAWS B on small aeroplanes conducting air taxi (charter) operations in aircraft with a passenger seating capacity of less than 10 was about Can$23,000. It also noted that the expected benefits of TAWS (in terms of reduced fatalities, serious injuries and accidents due to CFITs) were significantly higher than the costs.[30]
Considerations of changes in Australia
In March 2006, the ATSB issued safety recommendation R20060008:
The Australian Transport Safety Bureau recommends that the Civil Aviation Safety Authority review the requirements for Terrain Awareness Warning Systems for Australian registered turbine-powered aircraft below 5,700 kgs, against international standards such as ICAO Annex 6 and regulations such as FAR 91.223, with the aim of reducing the potential for CFIT accidents.
CASA accepted the recommendation and stated that it would examine the capital/installation costs and benefits. This work was initiated as part of CASA’s notice of proposed rule making (NPRM) 0808OS (Passenger transport services and international cargo operations – Small aeroplanes) published in February 2009. The proposed requirements included that small aeroplanes (regardless of engine type) conducting passenger transport operations carrying 6 or more passengers under the IFR to be fitted with a TAWS B. In terms of benefits and costs, the NPRM stated:
The costs and benefits of mandating TAWS B equipment for IFR aeroplanes carrying 6 to 9 passengers has been assessed by CASA. Equipment and fitment costs are forecast to be approximately $23,000 per aeroplane. Options to offset these additional costs are under consideration by the Government. Benefits are expected to flow to the industry from increased public confidence with this equipment fit to small aeroplanes in which passenger operations are conducted, as the overall accident rate is expected to reduce.
Accordingly, the ATSB recommendation was closed.
Subsequently, CASA released a consultation draft of Civil Aviation Safety Regulation (CASR) Part 135 (Australian air transport operations—smaller aeroplanes) in 2012. This contained a requirement for a TAWS for aeroplanes conducting passenger transport operations with a maximum operational passenger seat configuration (MOPSC)[31] of 6 or more. The proposed requirement’s applicability had expanded to include all flights (not just IFR flights) and was based on the passenger seat capacity rather the actual number of passengers carried on a flight.
Following further consultation, the 2012 proposal was amended to a MOPSC of 10 or more. In the summary of proposed change for CASR Part 135 (published in August 2018), CASA stated:
CASA had originally proposed the fitment of a minimum of TAWS-Class B for aeroplanes with a MOPSC greater than 5 which aligned with the Federal Aviation Administration of the USA (FAA) and Transport Canada rules however this was changed after discussion with the Aviation Safety Advisory Panel Technical Working Group.
In the 2018 explanatory statement in for the introduction of CASR Part 135, CASA outlined the options it considered (in its regulatory impact statement) regarding the implementation of TAWS. It noted that the estimated cost of installing a TAWS was about $21,000 (including about $12,000 for the system and additional costs for installation and training). One option (named option 2) was to only require a TAWS for all aeroplanes with a MOPSC of 10 or more or a MTOW greater than 5,700 kg. It was determined that this would affect 18 aeroplanes (in addition to those that already had or required a TAWS). Another option (option 3) was to require a TAWS for all aeroplanes with a MOPSC of 6–9 as well. In terms of option 3, the statement noted:
The types of aircraft that are within this category include, the piston powered AeroCommander 680, Beech 95 and Cessna 421 and the turbine powered aeroplanes that include the Cessna 208, Fairchild SA 226 and Pilatus PC 12. CASA estimates that there are approximately 323 of these types of aircraft. Based on 323 aircraft within the six to nine seat range and the 18 aircraft with MTOW>5700kg of option 2 this would result in an estimated cost impact of $7.2m for 341 aircraft... [as well as $0.72m annually]
The statement noted that initially CASA had proposed option 3 to industry but, following initial consultation, it did not pursue this option. Feedback associated with the initial consultation on TAWS (and other proposed regulatory changes) included that charter businesses were operating in a difficult marketplace with many not being profitable.
As a result of this regulatory reform process, the Australian requirements for TAWS changed from December 2021, such that piston-engine aeroplanes with a MOPSC of 10 or more conducting air transport operations were required to have a TAWS, with the applicable date being December 2021 or December 2022 dependent on various factors (see Safety issues and actions).
For VH-OZO and its seating configuration at the time of the accident, CASA advised the MOPSC was 12.[32]As such, if the operator had continued operating the aircraft for passenger transport flights with that seating configuration, the aeroplane would have been required to have a TAWS by December 2022 and, from December 2024, the operator would have had to operate the aeroplane under CASR Part 121 (and conduct all flights with 2 pilots under the IFR, as well as meet additional requirements compared to Part 135). Alternatively, the aeroplane would not have been required to have a TAWS or be operated under Part 121 if some seats were removed such that the MOPSC was 9 or less.[33]
Aerodrome information
Lockhart River Airport had one sealed runway (12/30), which was 1,500 m long and 30 m wide. It was not serviced by an air traffic control (ATC) tower and it was outside of ATC radar coverage. The airport had a common traffic advisory frequency (CTAF), which was used by pilots to advise intentions and arrange separation with other traffic.
The elevation of the runway was 76 ft at the threshold for runway 30 and 48 ft at the threshold for runway 12. The runway was equipped with low-intensity runway lights, and there was no visual approach slope guidance.
At the time of the accident there were 3 instrument approaches available at the airport:
NDB approach to runway 30
RNAV GNSS approach to runway 12
RNAV GNSS instrument approach to runway 30 (Figure 2).
The airport was located on a coastal plain 4.5 km west of the Lockhart River township. The Great Dividing Range was nearby with the terrain rising to over 800 ft to the south-west and west within about 8 km of the airport.
Lockhart River was known to experience low cloud and poor visibility conditions. The average (mean) rainfall at Lockhart River is 2,058 mm. In the month of March, the average rainfall is 446 mm and 19.5 days have rainfall of more than 1 mm.
The ATSB interviewed several pilots with experience conducting RNAV GNSS approaches, including some who had conducted multiple approaches at Lockhart River due to poor visibility conditions. The pilots had several suggestions for reducing workload for a second approach, including holding or diverting to Coen or Weipa to wait for weather to pass.
Meteorological information
Weather forecasts - overview
The Bureau of Meteorology produced aviation forecasts, observations, warnings and advisories. As the official provider of the Aeronautical Information Service, Airservices Australia delivered the bureau’s aviation meteorological products to pilots through National Aeronautical Information Processing System (NAIPS).
For the flight from Cairns to Lockhart River, the meteorological forecast information consisted of aerodrome forecasts (TAFs), graphical area forecasts (GAFs), grid point wind and temperature charts (GPWTs) and any warnings (such as SIGMETs[34]). These could be supplemented by aerodrome weather reports (METARs), ground-based weather radar imagery, and satellite imagery.
According to the weather forecasts, the pilot would have expected mostly visual meteorological conditions (VMC)[35] during the day at Cairns with some periods of rain showers and low cloud. For the arrival at Lockhart River, the forecast weather was predominantly VMC but there were overlapping periods of rain and low cloud with 30% probability of thunderstorms.
Aerodrome forecasts
A TAF for Lockhart River was issued at 0449 EST[36] and was valid from 0600 to 1800. The expected weather conditions were:
From 0600 to 1000: wind variable at 3 kt with visibility 10 km or greater. Light rain showers and cloud scattered at 1,000 ft.[37]
Between 0600 and 1000: TEMPO[38] - visibility reduced to 3,000 m with rain and broken cloud at 500 ft.
From 0600 to 0800: 30% probability of fog with visibility reduced to 500 ft and broken cloud at 100 ft.
From 1000 to 1800: wind from the north-east at 5 kt with visibility 10 km or greater. Light rain showers with scattered cloud at 1,000 ft.
Between 1000 and 1800: TEMPO - visibility reduced to 3,000 m with rain showers and broken cloud at 800 ft.
For the whole forecast period, 0600 to 1800: 30% probability TEMPO - winds gusting 25 to 35 kt and visibility reduced to 1,000 m due to thunderstorms and rain. This was associated with broken cloud at 500 ft and scattered cumulonimbus cloud with the base at 1,000 ft.
Based on this forecast a pilot arriving at Lockhart River was required to plan for 60 minutes holding or diversion to an alternate aerodrome. The aircraft had more than sufficient fuel for that purpose (see Fuel calculations).
An amended TAF for Lockhart River was issued at 0925 (5 minutes after the accident) and was valid from 0900 to 1800. The expected weather conditions were:
From 0900 to 1300: wind variable at 3 kt with visibility 10 km or greater. Light rain showers with cloud scattered at 1,000 ft and broken at 2,000 ft.
For whole forecast period, 0900 to 1800: TEMPO – winds gusting from 20 to 35 kt and visibility reduced to 1,000 m due to thunderstorms and rain. This was associated with broken cloud at 500 ft and scattered cumulonimbus cloud with the base at 1,500 ft.
Graphical area forecasts
A GAF was issued at 0835 and was valid from 0900 to 1500 and applicable from surface to 10,000 ft. This covered the Queensland-North region, which was divided into 6 areas for this forecast. Most of the flight including the arrival at Lockhart River was within one area that was forecast to have the following conditions:
Broken stratus 1,000 ft to 2,000 ft with broken cumulus/stratocumulus above that. Visibility reduced to 6,000 m in widespread rain.
Isolated towering cumulus from 2,000 ft, broken stratus from 800 to 2,000 ft, and broken cumulus/stratocumulus from 2,000 ft. Visibility reduced to 2,000 m in scattered rain showers.
Isolated cumulonimbus from 2,000 ft and broken status between 500 ft and 1,000 ft. Visibility reduced to 500 m in isolated thunderstorm rain showers.
A GPWT forecast was issued at 0538 and was valid to 1000. Lockhart River was located near the intersection of 4 data boxes and therefore roughly equidistant from 4 forecast locations. Taking 2,000 ft as a reference height for the approaches and coastal data as more relevant, the wind was forecast to be from the north-west at 9 kt increasing to 21 kt north of Lockhart River.
There were no significant weather warnings applicable to the flight.
Weather conditions - overview
The Bureau of Meteorology provided an overview to the ATSB of the actual weather conditions at Lockhart River on the day of the accident. It stated that a developing monsoon trough extended across Cape York Peninsula crossing the coast near Weipa and Lockhart River. A tropical low was embedded in the trough and was near Weipa at 1000, moving slowly eastward. The monsoon trough and low were causing scattered to widespread rain and isolated thunderstorms over much of Cape York Peninsula.
The surface winds at Lockhart River Airport were generally light and variable. Automatic weather sensors detected rain and heavy rain reducing visibility to 800 m and scattered to broken layers of cloud as low as 1,100 ft above ground level.
Aerodrome weather reports for Lockhart River
The METARs for Lockhart River were automatically generated every 30 minutes for routine reports and were issued as a special report (SPECI) at other times when one or more elements met specified criteria for degradation and improvement. For the period from 0830 to 0929 on 11 March 2020, the reports included:
0830: nil wind, visibility[39] 10 km or greater with rain and scattered cloud from 3,000 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm.
0900: nil wind, visibility 10 km or greater with rain and broken cloud at 2,000 ft, 3,500 ft, and 4,100 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0910: nil wind, visibility 10 km or greater with rain and broken cloud at 1,800 ft and 3,400 ft then overcast at 4,200 ft. Temperature and dewpoint were 26 and 25 °C respectively. Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0913: nil wind, visibility 3,800 m with rain and broken cloud at 1,800 ft and 3,400 ft, overcast at 4,200 ft. Temperature and dewpoint were 26 and 25 °C respectively. Rainfall in the previous 10 minutes was 2.2 mm.
SPECI 0929: wind westerly at 5 kt, visibility 8,000 m with heavy rain and scattered cloud at 1,200 ft, broken cloud at 1,900 ft, and broken cloud at 3,600 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm and rainfall since 0900 was 3.8 mm.
The QNH remained at 1,008 hPa during this period.
Automatic weather station
The Bureau of Meteorology (BoM) provided data from the Lockhart River Airport automatic weather station (AWS) recorded at 1-minute intervals. Table 3 details 1-minute rainfall, 30-minute cloud and 10-minute visibility data for the period encompassing the aircraft’s first approach prior to the final approach fix (FAF) at 0904 to the accident at 0920. The last column in the table indicates the 1-minute visibility associated with the telephone message for the aerodrome’s automated weather information service (see following section section). More detailed information from the Lockhart River AWS for the period 0850 to 0930 is provided in Appendix C – Detailed 1-minute weather data Lockhart River 0850–0930.
Table 3: Extract of 1-minute weather data from Lockhart River Airport AWS
The first shaded area indicates when the aircraft was at the MAPt on the first approach and the second shaded area indicates the time of the accident on the second approach. The 1-minute visibility data was that recorded to be broadcast by the AWIS by telephone. The times have been displaced by 1 minute (back) to align with the 1-minute rainfall data provided by BoM. The cloud data was averaged over the previous 30 minutes (see description in report text).
Source: Bureau of Meteorology
The cloud information was derived using a sky condition algorithm. This involved taking a sample (using a ceilometer at the aerodrome) at least every 30 seconds and averaging the data over a 30-minute period, with samples taken in the last 10 minutes provided double weighting.[40] Although this algorithm provided more stable estimates of cloud than each sample, the reported cloud for any given minute did not necessarily reflect the cloud level at that specific point in time.[41]
The visibility meter estimated atmospheric visibility based on the continuous sampling of a single point, providing a measurement of the prevailing visibility at the sensor. However, it sampled a relatively small volume of air in the immediate vicinity of the instrument and, unlike a human observer, was not capable of estimating visibility in different directions or over longer distances. One-minute data was based on the last 60 seconds of sensor output, as an average based on a processing algorithm. The 10-minute data recorded each minute was the average value over the previous 10 minutes.
A number of factors can affect the accuracy of the reported visibility, including:
discrete air masses, such as a shower of rain or a bank of fog, will not be identified unless the sensor is engulfed, and if the phenomenon is not of uniform density the visibility will be misreported
stationary localised patches of fog will remain undetected if the sensor is clear of fog, or if the sensor is within the patch of fog the reported visibility may be less than actual.
The temperature and dewpoint were about 25 °C for the duration with the relative humidity at 99% (increasing to 100% from 0917).
The reported wind speeds and directions were the mean values at 10 m above ground level, averaged over the last 1-minute period. The recorded wind was 0 kt until 0914, with speeds of 3–4 kt from the west, between 0916 and 0921.
Automated weather information service
Lockhart River was equipped with an automated weather information service (AWIS) that transmitted AWS data in text-to-speech format on a discrete VHF frequency. A new AWIS message was generated every minute in a similar format to the METAR reports. To produce the reports from the AWS 1-minute data, some averaging and rounding of the information occurred. The broadcasts were not recorded.
In addition, AWIS data at Lockhart River could also be accessed by telephone. A different phone message based on the AWS data was produced every minute and this was recorded. However, the AWIS information available by telephone was processed differently to the AWIS information available by VHF, and therefore there could be slight differences in the information produced at the same time.
During the flight, the pilot recorded the following data in the space allocated for arrival weather information in the flight plan/log:
calm (nil wind)
10 km (visibility)
B1800 (broken cloud at 1,800 ft)
B3500 (broken cloud at 3,500 ft)
OV 5300 (overcast cloud at 5,300 ft)
1008 (QNH 1,008 hPa)
25 (temperature 25 °C).
This information closely matched the recorded AWS 1-minute data at 0854, which stated (with expected transmitted message in brackets):
wind 0 kt at 023° (wind calm)
visibility 10 km (visibility one zero)
(present weather – rain)
cloud 4 oktas[42] at 1,800 ft (cloud broken one thousand eight hundred)
cloud 5 oktas at 3,500 ft (broken three thousand five hundred)
cloud 7 oktas at 5,300 ft (broken five thousand three hundred)
temperature 25.4 °C (temperature two five)
dewpoint 25.2 °C (dewpoint two five)
QNH 1,008.5 hPa (QNH one zero zero eight hectopascals)
rainfall last 10 minutes 0.4 mm (rainfall last ten minutes zero decimal four millimetres).
The pilot’s recorded weather information was also broadly consistent with the recorded AWIS messages available by phone for the period 0853–0855. It did not closely match any of the other recorded AWS 1-minute data or the recorded AWIS messages available by phone during 0840–0920. Accordingly, it is very likely that the pilot wrote down the AWIS data accessed by VHF radio at about 0854. It could not be determined whether the pilot additionally accessed the AWIS data prior to this time and/or after this time.
The AWIS broadcasted the most recent 1-minute visibility data measured by the AWS (see Table 3, last column). This data indicated visibility below the landing minima (4,200 m) at the AWS site between 0911 and 0915, and at 0917.
BoM operated a network of weather watch radars around Australia that detected water droplets in the atmosphere. Information from the weather radar was displayed on a map, with different colours depicting the approximate rainfall/precipitation intensity.
The nearest weather radar was at Weipa, approximately 150 km west of Lockhart River. Coverage in the vicinity of Lockhart River was affected by the distance from the radar and terrain, reducing the radar’s ability to detect low-level showers. However, precipitation at higher altitudes would still produce radar echoes.
Figure 11 provides an indication of the weather around Lockhart River at 0918 on the morning of the accident (during the second approach), with Figure 12 displaying an extract of radar images from the time of the first approach and the time of the accident. The weather radar depicted areas of moderate precipitation in the vicinity of Lockhart River. In addition, an analysis of a sequential series of images showed precipitation moving through the area at a speed of about 30 kt (55 km/h) from the north-west.
The minute-by-minute data from the AWS around the time of the accident (see Automatic weather station and Table 3) recorded no significant surface wind. However, there was a short period of rainfall between 0910 and 0916, including moderate to heavy rainfall between 0912 and 0914. If this rainfall persisted and continued moving in a direction/speed consistent with the observed radar returns, it would have been in the vicinity of the accident site about the time of the accident.
Figure 11: Weipa radar image at 0918 EST (about 2 minutes prior to the accident) showing weather in Lockhart River area (circled, approximate radius 25 NM/46 km)
Source: Bureau of Meteorology, annotated by the ATSB
Figure 12: Extract of Weipa radar images at 0906 (time of the first approach) and 0918 EST showing rain rate on the approach path to runway 30 at Lockhart River Airport
Source: Bureau of Meteorology, annotated by the ATSB
Local weather observations
Two pilots were operating aircraft in the Lockhart River area before and after the accident. The first pilot, operating before the accident, tracked to Lockhart River from the south and conducted the RNAV GNSS runway 30 approach, landing at 0810. There were intermittent rain showers in the area and the pilot advised that the end of the runway was visible while descending through 1,000 ft. The pilot remained on the ground at Lockhart River until later in the day and heard an aircraft (VH-OZO) fly over at high engine power. They recalled that, at that time, there was scattered low cloud at 500–1,000 ft with reduced visibility in rain showers.
The following pilot, operating after the accident, tracked to Lockhart River from the south-west and diverted 15 NM to the right of track due to weather. On arrival, the pilot conducted the Lockhart River RNAV GNSS runway 30 approach and landed at 0953. The pilot reported that there was rain in the area and, although the conditions allowed visual navigation after the final approach fix (FAF) while descending through 1,500 ft, the runway was not visible until later in the approach.
A person who was near the airport at the time of the accident described the conditions as an unusual morning with mist coming from the rainforest, and that there was about 5 to 10 minutes of heavy rain at about the time the aircraft would have been in the area. At that time, there was low-lying cloud (north-west of the airport) and no wind.
Fishermen who were in the area at the time reported that, at about the time of the second approach, there was a ‘wall’ of heavy rain that came across from the north-west.
Instrument approach
Overview
An instrument approach is a published procedure that allows for safe navigation of an aircraft operating in instrument meteorological conditions (IMC) to descend from the lowest safe altitude to a specified position (missed approach point - MAPt) near the aerodrome. If the conditions are suitable, the approach can be continued to land. If the conditions are not suitable, the pilot must conduct a missed approach in accordance with the procedure.
There are 2 general categories of instrument approach:
2-dimensional (2D) – lateral/tracking guidance only, also known as non-precision approaches or LNAV (lateral navigation)
3-dimensional (3D) – lateral/tracking and vertical guidance, including precision approaches such as an instrument landing system (ILS) approach and a (non-precision) approach with vertical guidance (APV).
Both categories of instrument approaches were only conducted utilising ground-based navigation aids until RNAV GNSS[43] approaches were available in Australia from 1998.
An RNAV GNSS approach is a 2D instrument approach that utilises an on-board GPS receiver (or flight management system - FMS) to generate lateral/tracking guidance and distance information. These approaches are pre-programmed in a GPS/navigation system’s database. Other types of non-precision approaches use ground-based aids such as a non-directional beacon (NDB) or a VHF omni directional radio range (VOR).
The transition in Australia from navigation reliant on ground-based navaids to performance-based navigation is continuing. As part of that process, Airservices Australia has been implementing barometric vertical navigation (Baro-VNAV) APV approaches since 2016. These 3D approaches are restricted to runways with a validated (LNAV/VNAV RNP APCH) procedure and aircraft with the applicable avionics, typically an FMS. Although these approaches were available at Lockhart River from 3 December 2020, VH-OZO was not Baro-VNAV capable.[44]
RNAV GNSS approach design
RNAV GNSS approaches in Australia have a Y-pattern, runway-aligned design. The Lockhart River runway 30 RNAV GNSS approach uses this typical layout, as shown in Figure 13.
Figure 13: Extract from Lockhart River RNAV GNSS runway 30 approach chart showing layout of waypoints
Source: Airservices Australia, annotated by the ATSB
The approaches have 3 initial approach fixes (IAFs, in this case, LHREA, LHREB and LHREC), followed by an intermediate fix (IF, LHREI), final approach fix (FAF, LHREF) and missed approach point (MAPt, LHREM).
The segment between an IAF and the IF is the initial approach segment, the segment between the IF and the FAF is the intermediate approach segment, and the segment between the FAF and the MAPt is the final approach segment. Each segment is typically 5 NM.
The intermediate approach track is normally aligned with the final approach track. One of the IAF waypoints is also aligned with the intermediate/final approach track (in this case, LHREB) and the other IAFs are located 70° off the intermediate/final approach track (LHREAS and LHREC). A pilot can commence an approach by flying to one of the 3 IAFs within the capture region for that waypoint. The capture region is a 140° arc for the IAF on the intermediate/final approach track and a 180° arc for the IAFs not on the intermediate/final approach track (with the extreme points parallel to the intermediate/final approach track).
Instrument approach waypoints can either be fly-by waypoints (which require turn anticipation to allow tangential interception of the next segment) or flyover waypoints (at which the turn is initiated). For RNAV GNSS approaches, the IAFs, IF and FAF are fly-by waypoints and the MAPt is a flyover waypoint.
The approaches are recommended to be flown using a continuous descent angle.
The recommended profile published on approach charts consists of an initial approach altitude which then joins a constant descent to 50 ft above the runway threshold. The approach path angle of the descent is normally (and ideally) 3°. Depending on the approach, the initial approach altitude joins the constant descent profile at about the FAF or earlier.
For example, the approach chart for the Lockhart River runway 30 approach (Figure 14) had an initial approach altitude of 3,500 ft leading to an approach path angle of 3°, which commenced 0.8 NM after the IF (4.2 NM prior to the FAF and 9.2 NM prior to the MAPt).
Figure 14: Excerpt from Lockhart River RNAV (GNSS) runway 30 approach chart showing recommended vertical profile and segment minima safe altitudes
The full approach chart is provided in Figure 2.
Source: Airservices Australia, annotated by the ATSB
Each segment of an RNAV GNSS approach has one or more specified segment minimum safe altitudes, depicted by shading on the chart’s profile diagram and the relevant altitude with a solid line underneath. For example, between the IF and the FAF on the runway 30 approach, the segment minimum safe altitude was 1,800 ft. The last segment minimum safe altitude, in the final approach segment, is the minimum descent altitude (MDA).
During an instrument approach, a pilot is able to descend below the recommended descent profile, but they are not allowed to descend below a segment minimum safe altitude, except for the MDA if certain conditions are met (as discussed below).[45] However, as stated in the Civil Aviation Advisory Publication (CAAP) 178-1(2) (Non-precision approaches (NPA) & approaches with vertical guidance (APV)):
While some pilots in the past have flown NPAs as a series of descending steps conforming to the minimum published altitudes, (a technique colloquially referred to as the ‘dive and drive’), CASA recommends a constant angle descent in a stabilised configuration. Many Controlled Flight into Terrain (CFIT) accidents have been attributed to the ‘dive and drive’ technique, due to human errors such as early descent before a step or failing to arrest descent. In addition, the aircraft’s descent is more difficult to manage due to changes in airspeed, rate of descent and configuration.
If the recommended descent profile starts prior to the FAF, the RNAV GNSS approach chart includes an advisory crossing altitude (or procedure height) at the FAF (and if required the IF) to assist pilots with maintaining the recommended descent profile (for example, 2,160 ft at the FAF in Figure 14). In addition, a pilot is provided with a distance/altitude scale on the approach chart that provides guidance for the recommended descent profile (see top of Figure 14). The distance specified is the distance to the next waypoint.
Approach waypoint naming convention
The waypoints documented on an RNAV GNSS approach chart are identified by a unique identifier comprising the airport identifier (in this case LHR), compass quadrant from which the approach is flown (E - east), and position on the approach (A, B, C, I, F, M or H).
During the investigation, some flight examiners stated that pilots occasionally misidentified waypoints (due to their similar names) and believed that they were on a different segment of the approach than they actually were. One flight examiner noted that this was more likely to occur when coming straight in via the IAF ‘B’ rather than when coming via one of the other 2 IAFs. This flight examiner also noted that one operator they worked with had introduced call-out requirement for pilots to annunciate that they were tracking from one waypoint to another in order to minimise this risk.
Conducting an approach
Before conducting the approach, the pilot must ensure they are qualified for RNAV GNSS approaches and satisfy the recent experience requirements. The aircraft must be equipped with an approved GPS receiver with a valid aeronautical database. It is also essential that the availability of receiver autonomous integrity monitoring (RAIM) is checked pre-flight and before entering the approach.[46]
To conduct the approach, the pilot selects the specific approach and IAF in the GPS unit (or FMS) and tracks towards the applicable IAF within the capture region. Prior to passing the IAF, a pilot must set the QNH to either the actual aerodrome QNH (from an approved source such as AWIS) or the aerodrome/area forecast QNH.
As the approach proceeds, the GPS (or FMS) will automatically sequence through the waypoints, displaying the next waypoint and distance to that waypoint. The pilot maintains the track with reference to the associated course deviation indicator (CDI).
To maintain the recommended descent profile (without electronic vertical guidance), pilots are required to:
establish a 3° descent by managing the descent rate proportional to the groundspeed (through engine power and pitch angle)
with reference to the altimeter, monitor the aircraft’s altitude - relative to the distance from the next waypoint with reference to the table on the approach chart and/or when passing waypoints with advisory altitudes
adjust the descent rate and/or groundspeed as required to correct the profile
level at the MDA and continue tracking to the MAPt unless the conditions are suitable for continuation of the approach.
The height of the MDA above the aerodrome elevation and the required visibility (in km) to complete the approach were included as bracketed figures after the MDA. If the minima label boxes on the approach chart were shaded, the MDA could be reduced by 100 ft when the actual aerodrome QNH was set. For example, for the accident flight, the pilot had noted the actual QNH so the 830 ft MDA could be reduced to 730 ft (Figure 15). At the lower MDA, the aircraft would be 653 ft above the aerodrome elevation and the minimum required visibility was 4.2 km. Practically, if the visibility was at the minima value, the pilot would see the runway threshold before the MAPt and, if the aircraft was on the recommended profile, by the MDA.
Figure 15: Excerpt from Lockhart River RNAV GNSS runway 30 approach chart showing minima table
The full approach chart is provided in Figure 2.
Source: Airservices Australia
The Aeronautical Information Publication (AIP) outlined several instructions or methods for pilots regarding the conduct of instrument approaches, in addition to those specified by an operator’s operations manual. CAO 20.91 (Instructions and directions for performance-based navigation, Instrument 2014) also applied to the operation of Australian aircraft using performance-based navigation (which included RNAV approaches during IFR flight), providing instructions/directions to operators and pilots conducting those operations. Relevant CAO and AIP requirements, instructions and methods are outlined in subsequent sections below.
Descent below the minimum descent altitude
After passing the FAF, a pilot is permitted to descend to the MDA (provided the aircraft is within navigational tolerances). Further descent below the MDA must not be made without the required visual reference. There may be different MDAs specified for a straight-in or circling approach. Descent below the straight-in approach MDA could only be conducted (AIP ENR 1.5, 1.8.2)[47] when:
visual reference can be maintained;
all elements of the meteorological minima are equal to or greater than those published for the aircraft performance category…; and
the aircraft is continuously in a position from which a descent to a landing on the intended runway can be made at a normal rate of descent using normal flight manoeuvres that will allow touchdown to occur within the touchdown zone of the runway of intended landing.
The AIP also stated that, if visual reference is not established at or before reaching the MAPt, a missed approach must be executed (ENR 1.5, 1.10.1).
The competencies and standards required for an initial instrument rating and IPCs were specified in the CASR Part 61 Manual of Standards (MOS). For a 2D approach, the required tolerance was within +100 ft at the MDA but not below it.
Lateral tolerances
The AIP stated that instrument approach procedures were based on specific navigation aids, ‘with the applicable navigation tolerances associated with the aids being used in the development of the procedure’s obstacle protection surfaces.’ For an RNAV GNSS approach, CAO 20.91 stated that the lateral tracking tolerances were 1.0 NM (1,852 m) for the initial, intermediate and missed approach segments (terminal area operations) and 0.3 NM (556 m) for the final approach segment.
Navigational equipment could be designed so that full-scale deflection on the CDI represented the required navigation performance (RNP) lateral tracking tolerance during that phase of flight. For an RNAV GNSS approach, this would typically be represented as a lateral 1 NM displacement being represented as a full-scale CDI deflection during the initial segment and most of the intermediate segment, then transitioning from about 2 NM (3,704 m) prior to the FAF to a 0.3 NM displacement being full-scale deflection about 1 NM after reaching the FAF (Figure 16).
The GNS 400W-series manual indicated that the CDI full-scale deflection varied during the final approach segment.[48] When conducting an RNAV GNSS approach using a GNS 400W-series unit, the full-scale deflection was 350 ft (0.06 NM or 107 m) at the MAPt, diverging back to the FAF at an angle of either 2° to the final approach track, or an angle such to achieve 0.3 NM full-scale deflection at the FAF, whichever was less (Figure 16).[49] For 5 NM final approach segments, the angular 2° would always be less than the lateral 0.3 NM CDI full-scale deflection at the FAF.
Figure 16: Conventional transition from RNP 1.0 to RNP 0.3 NM during final approach segment (represented by full-scale CDI deflection) compared to the full-scale CDI deflection provided by the GNS 400W-series GPS
Source: ATSB, derived from information contained in ICAO Doc 8168 Procedures for Air Navigation Services-Aircraft Operations, Vol II − Construction of Visual and Instrument Flight Procedures and the Garmin GNS 400W-Series Pilot’s Guide & Reference manual.
For the 5 NM final approach segment for the runway 30 approach at Lockhart River, an angular 2° to the final approach track displaced 350 ft (107 m) at the MAPt equated to 0.23 NM (430 m) at the FAF. The transition from 1.0 NM full-scale deflection during the intermediate segment to the 2° automatic rescaling full-scale deflection for the final approach segment commenced 2 NM prior to reaching the FAF and was completed by the FAF. In other words, during the final approach segment, GNS 400W series units presented CDI full-scale defection that was less than the lateral tracking limit specified in CAO 20.91 for the final approach segment. This difference was relatively minor at the FAF (0.3 NM versus 0.23 NM) but increased significantly as the aircraft got closer to the MAPt.
When using the GNS 400-series units, if the CDI exceeded a full-scale deflection, a green arrow and distance was displayed on the default navigation page’s CDI, indicating the direction (left or right) and distance the aircraft was displaced (in NM) from the required track.
For a straight-in, area navigation-based approach (such as the RNAV GNSS approach to runway 30 at Lockhart River), the AIP (ENR 1.5, 1.21) stated that an aircraft was required to:
…pass the waypoint, and when established on the specified track, descend to not below the specified altitude….
Note: “Established” means being within half full scale deflection for the ILS, VOR and GNSS... [50]
The AIP (ENR 1.5, 1.10.1) also stated that a missed approach had to be conducted if:
…during the final segment of an instrument approach, the aircraft is not maintained within the applicable navigation tolerance for the aid in use…
CAO 20.91, Appendix 6, contained operating standards for conducting an RNAV GNSS approach, which included the requirement to commence a missed approach if the cross-track error/deviation equalled or was reasonably likely to equal the RNP for that segment of the approach (that is, 1.0 NM for the initial and intermediate segments and 0.3 NM during the final approach segment).
In other words, to comply with the AIP, after passing the FAF, the aircraft needed to be established within half full-scale deflection before descending below the previous segment’s MSA. If the aircraft was established within half full-scale deflection, the descent could continue to an altitude not below the segment minimum safe altitude, which in this case was the MDA.[51] In addition, to comply with CAO 20.91, a pilot was required to conduct a missed approach if the aircraft was laterally displaced 0.3 NM or more from the final approach track.
CASA advised the ATSB that there was, in the aviation community, a commonly held misconception that half full-scale deflection was the required tracking tolerance limit. This was potentially related to a number of factors, such as:
CAO 20.91 included a note that stated ‘So far as practicable, the cross-track error/deviation for normal operations should be limited to 0.5 NM (½ x RNP) for the initial segment, the intermediate segment and a missed approach, and to 0.15 NM (½ x RNP) for the final approach segment. Brief deviations are acceptable during and immediately after turns where accurate cross-track information is not provided during the turn.’ This reference to half the RNP was providing a target level of safety rather than a minimum acceptable level of safety.
The CASR Part 61 MOS required tolerance when assessing a pilot’s competency for a 2D approach was within half full-scale deflection.
CAAP 179A-1(1) (Navigation using the Global Navigation Satellite Systems (GNSS)), issued in 2006, stated (erroneously) that for an RNAV GNSS approach that ‘The tracking tolerance is half of full-scale deflection regardless of the CDI scale’.[52]
CASA advised that operators could choose to specify a more restrictive lateral tracking requirement than that stated in CAO 20.91. If an operator specified a more restrictive limit (such as half RNP or half full-scale deflection), and included that in its operations manual, then that limit would be the applicable limit for that operator.
As discussed in Operator’s stabilised approach criteria, the operator of VH-OZO specified in its operations manual that a missed approach was required if an aircraft on an RNAV approach was not within ‘half scale deflection’ at the FAF. The ATSB is aware through its investigations that a number of other operators also specified a similar requirement for initiation of a missed approach.
Handling speeds
The AIP (ENR 1.5, 1.16) stipulated handling airspeeds for aircraft during instrument approaches based on the aircraft’s performance category. Aircraft performance categories were based on an indicated airspeed at the runway threshold (VAT).[53]
The Cessna 404 VAT was 91 kt. Therefore, the performance category for the Cessna 404 was category B, which applied to aircraft with a VAT of 91–120 kt.
The relevant handling speeds for instrument approaches for category B aircraft were:
120 to 180 kt for the initial and intermediate approach segments
85 to 130 kt for the final approach segments
maximum 150 kt for the missed approach.
A note in the AIP stated that a pilot was permitted to reduce the speed below the minimum in the initial/intermediate segments ‘to enable the final approach speed to be achieved prior to the commencement of the final segment’. In other words, for a category B aircraft, a pilot could operate below 120 kt prior to reaching the FAF but they could not operate above 180 kt.
The AIP handling speeds are broad speed bands used for purposes such as ensuring aircraft remain within the design tolerances for instrument approach procedures. Operators should provide more specific guidance regarding the appropriate speeds to use during instrument approaches for their aircraft types (see Flight profiles).
The AIP also stated that the descent rate after the FAF ‘should not normally exceed’ 1,000 ft/min.
Instrument flying and workload
Single pilot IFR operations are widely regarded to be among the most difficult and/or involve the highest workload. As stated by the US Aircraft Owners and Pilots Association (AOPA) in 2006:
No type of flying requires greater skill or longer periods of concentration than [single-pilot IFR] SPIFR…
Very simply, the problem is pilot workload, aggravated by the need for multi-tasking. A single IFR pilot also serves as navigator, radio operator, systems manager, onboard meteorologist, record keeper, and sometimes, flight attendant. En route flight in benign weather is usually not too stressful, but add high-density traffic in poor weather conditions or a significant equipment malfunction, and overload may not be far away.
In instrument flight, the pilot maintains an awareness of the aircraft’s spatial position by reference to instruments rather than outside visual references. The fundamental skills of instrument flight are instrument scanning and instrument interpretation. Instrument scanning is ‘the continuous and logical observation of instruments for attitude and performance information’ (FAA 2012).
In any phase of flight or manoeuvre, there are primary instruments that give the most pertinent information and supporting instruments that assist in their continued correct interpretation. For example, even when the aircraft is established in a constant-rate descent, and trimmed to remove control pressure on the yoke, it is necessary for the pilot to continuously check relevant instruments and make appropriate control adjustments to maintain aircraft performance and control.
With proficiency, a pilot scans at an appropriate rate and is able to interpret the instruments to maintain an accurate mental picture of what is happening. An ineffective scan, such as fixation on one instrument or the omission of another, or misinterpretation of the displayed information, can result in a pilot having an incorrect mental model of the aircraft’s position or flight path.
More generally, workload is described by Wickens and others (2013) as follows:
Mental workload characterizes the demands of tasks imposed on the limited information processing capacity of the brain in much the same way that physical workload characterises the energy demands upon the muscles. In any resource-limited system, the most relevant measure of demand is specified relative to the supply of available resources...
People experience workload differently, based on their individual capabilities and the local conditions at the time such as training and experience in the situation at hand and the operational demands during that phase of flight (Orlady and Orlady 1999). When workload gets too high for the available resources task shedding occurs (Wickens and others 2013).
Dismukes and others (2007) discussed task shedding in this context, explaining that a pilot may move from a proactive assessment of the situation, commonly referred to in aviation as ‘being ahead of the aircraft’, to a reactive situation, where the pilot is responding to events as they occur without an overall strategy to manage the situation (that is, being behind the aircraft). Wickens and others (2013) further explained that task shedding can result in some tasks being shed altogether, and others being shed in a non-optimal manner. In addition, tasks such as internal and external communication are often shed during periods of high workload.
Holmes and others (2003) stated that distractions and high workload can result in a pilot scanning fewer instruments and checking them less frequently. High workload can also lead to a reduction in the number of information sources that an individual will search, as well as the frequency or amount of time these sources are checked (Staal 2004). Additionally, vigilance tasks, such as monitoring flight instruments, require sustained attention with the associated eye movements being fatiguing (Wickens and others 2013).
The United Kingdom Civil Aviation publication, Monitoring Matters, provided information regarding monitoring and stated:
… whilst you are ahead of the game, concentrating on the next event, keeping an eye on all the flight parameters, system modes etc, everything runs fairly smoothly. But as soon as something draws your attention away and you become out of the loop it becomes difficult to play catch up.
Although it is possible to attend to more than one task using selective attention techniques, there is a limit to cognitive capacity. If tasks consume this capacity, that is when task shedding will occur. This publication further advised that under high workload, especially during approach and descent, attention capacity diminishes. This includes the ability to detect when the configuration of the aircraft is not correct, even when there is an aural or visual alert, particularly in the case of single-pilot operations as:
…the processes and procedures will be equivalent to multi crew operation except there will only be one person in the cockpit and the systems may be less automated. Hence the need to monitor the flight profile, flight instruments, fuel state, engines, radios, etc. diligently. The instrument scan must be carried out very frequently, especially during departure and approach in order to monitor the aircraft state and planned profile.
In addition to being a complex skill to acquire, instrument flying skills needs to be maintained by frequent practice (Newman 2007). As stated by CASA in 2016 (Changes to instrument proficiency checks):
Conducting IFR operations is a relatively high risk activity and so requires dedicated knowledge and practical flight training… Skill-based qualifications, like the instrument rating, require the qualification holder to maintain their skills and operational knowledge. Skills and knowledge degrade over time. In the interests of safety, rules are put in place to ensure pilots are sufficiently competent conducting IFR operations.
Accordingly, there are requirements in place for pilots conducting IFR operations to regularly undertake proficiency checks (Proficiency checks and flight reviews) and have recent experience (Monitoring of pilot recency). In general, skill decay or skill degradation increases as the retention interval (or time since learning) increases, and it also increases depending on the quantity and quality of the initial and recurrent training and the amount of task exposure (Arthur and others 1998, Sanli and others 2018, Vlasblom and others 2020). Skill decay has various effects, such as preventing the development of further expertise and decreasing spare mental capacity. As noted by the European Aviation Safety Agency (2021):
Proficiency decay in only a few skills may lead to time management issues, reduced situation awareness, and the ability to keep ahead of the situation. In non-normal situations or emergencies, appropriate actions may not be taken due to one’s inability to analyse the situation as a result of the cognitive overload.
RNAV GNSS approach workload
There has been limited research that has compared different types of instrument approaches, and specifically looked at RNAV GNSS approaches. Research was conducted by the ATSB following a CFIT accident on an RNAV GNSS approach at Lockhart River in 2005 (Godley, 2006). The study found that, for pilots of smaller single-engine and twin-engine aircraft, pilot workload was perceived as being higher, and reported losses of situational awareness were more common, for RNAV GNSS approaches compared to other approach types except for NDB non-precision approaches.
In contrast, pilots of larger aircraft found that RNAV GNSS approaches were not as problematic, with the workload only being higher than ILS (precision) approaches. The different aircraft category responses were likely to have been due to high capacity aircraft having advanced automation capabilities and operating mostly in controlled airspace. Such aircraft were also more likely to have an FMS rather than a GPS unit.
The concern most respondents had regarding the design of RNAV GNSS approaches was that they did not use references for distance to the missed approach point on the approach chart and cockpit displays (in contrast to previous types of approaches). Other problems raised were short and irregular segment distances and multiple minimum segment altitude steps, that the RNAV GNSS approach chart was the most difficult chart to interpret, and that five letter long waypoint names differing only by the last letter can easily be misread. The most common incident reported with RNAV GNSS approaches was commencing the descent too early due to a misinterpretation of position.
It should be noted that at the time of this research, many GPS units displays only provided numerical data rather than a map view of the aircraft’s lateral position (such as with the GNS 430W). In addition, RNAV GNSS approaches have become more common and pilots have become more familiar with them, and the design of RNAV GNSS approach charts has improved.
Recorded flight data
General information
The aircraft was not fitted with a flight data recorder or cockpit voice recorder, nor was it required for the type of aircraft and operation.
The ATSB obtained data broadcast by the automatic dependent surveillance broadcast (ADS-B)[54] equipment fitted to the aircraft and GPS data from the pilot’s iPad with the OzRunways[55] application installed. The data included:
timestamp
latitude and longitude
pressure altitude (from the ADS-B data) – rounded to the nearest 100 ft (for example, 498 ft would be rounded to 500 ft)
GPS altitude (from OzRunways) – truncated to 100 ft (for example, 498 ft would be presented as 400 ft)
groundspeed.
The lateral location (latitude and longitude) from OzRunways and ADS-B-based data were in close agreement. This indicated that the data from OzRunways was sufficiently reliable to show the aircraft’s lateral flight path.
The pressure altitude data from the ADS-B data was fairly consistently 100 ft higher than the OzRunways GPS height, which was partially due to the ADS-B data being rounded to the nearest 100 ft and the OzRunways data being truncated to the nearest 100 ft. In addition, the local QNH was 1,008.5 to 1,008.9 hPa during the period from 0900 to 0921, lower than the standard 1,013.25 hPa datum for pressure altitude. This would result in an altimeter set to the local QNH reading about 130–140 ft lower than the pressure altitude.[56] Thus, within the applicable errors, the altitudes from the 2 sources were consistent.
The OzRunways data points were provided at 5-second intervals, with some data points missing, and they covered the whole flight (including all of the 2 approaches), whereas the ADS-B data points were only available for parts of the approaches and/or were provided at less frequent intervals. As such, the OzRunways data is used in this report.
Figure 17 depicts the recorded data for the first and second approaches from the initial approach fix (IAF), through the intermediate fix (IF) and final approach fix (FAF) and to the missed approach point (MAPt). The top panel displays the aircraft’s altitude, the middle panel displays the lateral position, and the bottom panel displays the groundspeed. All distances on the horizontal axes are relative to the next waypoint, as would be displayed to the pilot on the GPS unit during the approach.
Figure 17: Recorded data for first and second approaches to Lockhart River
The upper panel shows altitude, the middle panel shows lateral deviation from the instrument approach path and the lower panel shows groundspeed. The purple bands on the groundspeed panel refer to the handling speeds (for indicated airspeed) specified in the Aeronautical Information Publication for a category B aircraft, such as the Cessna 404 (see Handling speeds).
Source: OzRunways data overlaid with Airservices approach information, annotated by the ATSB
Altitude during approaches
The top panel of Figure 17 shows the 3° approach path guidance (recommended descent profile) to the MAPt, which commenced from the initial approach altitude of 3,500 ft about 9.2 NM from the MAPt. As previously noted, the minimum descent altitude (MDA) was 730 ft unless the pilot had the required visibility. Key aspects regarding the recorded altitude data included:
The first approach (in blue) was flown at or slightly above a 3° approach to the MAPt from significantly prior to the IAF until reaching 700 ft just prior to the MAPt. The average descent rate during the first approach from the IAF to the MAPt was about 720 ft/min.
Although not indicated on the figure, the aircraft kept descending and reached a recorded altitude of 400 ft[57] at about 0.5 NM past the MAPt or 0.9 NM (1,700 m) before the runway threshold. It remained at that recorded altitude over 3 data points, or until it was 0.5 NM (900 m) from the runway threshold. The next 2 data points were not recorded, with the subsequent recorded data point indicating an altitude of 600 ft as the aircraft passed the runway threshold.
ADS-B data was available for the latter part of the first approach, and this data indicated that the aircraft had still been descending when it reached the second of the 400-ft data points (0.7 NM or 1,300 m from the runway threshold), and had started climbing just before the third of the 400-ft data points (1,000 m from the threshold). The ADS-B data also provided recorded values of geometric altitude rate of change. This data indicated that just before and just after the MAPt the descent rate was about 900 ft/min, and at about the second 400-ft data point the descent rate was about 960 ft/min.
The second approach (in red) was flown at about 3,500 ft prior to and after passing the IAF, with the aircraft starting to descend at about 0914:48 when about 2.7 NM from the IF. From about 1.6 NM prior the IF (at 0915:18 and an altitude of 3,300 ft), this descent was flown at about a 3° flight path, although about 1,000 ft below the recommended descent profile.
The radio call commencing at 0915:50, when the pilot stated the position (10 NM) and altitude of the aircraft (3,800 ft then corrected to 2,800 ft), started about 0.4 NM prior to the IF. At 0915:58, about 0.2 NM prior to the IF, the aircraft was at a recorded height of 2,800 ft.
For the second approach, the descent rate was about 700 ft/min during the descent from 3,300 ft to about 700 ft (at 0919:08 and 3.3 NM before the MAPt). From 700 ft until 100 ft, the descent rate was about 1,200 ft/min. Given this last part of the descent was over a 30-second period, it probably indicates an actual change rather than the effect of truncated data.
During both approaches, there were several instances during descent where 2 data points in succession were at the same recorded altitude. There were also 2 occasions during the second approach where 3 data points in succession were at the same recorded altitude (at 700 ft and at 2,200 ft). Although this could indicate that the descent rate decreased to some extent at those altitudes, such patterns could also occur (at least in part) due to the data being truncated to the nearest 100 ft and the small amount of error associated with each GPS data point. A descent rate of about 700 ft/min would equate to about 60-ft difference every 5 seconds, whereas a descent rate of 600 ft/min would equate to about a 50-ft difference every 5 seconds.
Lateral position during approaches
Figure 17 depicts the lateral paths flown on the 2 approaches relative to the lateral track prescribed for the approach (shown as a dash-dot line). Dotted lines depict the full-scale CDI deflection on the Garmin GNS 430W and show the scale transitioning from 1 NM full-scale deflection during the intermediate approach segment to 0.23 NM full-scale deflection at the FAF, narrowing to 0.06 NM full-scale deflection at the MAPt. The aircraft’s position is based on GPS data; the actual CDI values displayed to the pilot were not recorded.
Key aspects regarding the lateral position data include:
The flight paths for both approaches were consistent with the pilot hand-flying the aircraft, rather than the autopilot maintaining a programmed track.
The first approach passed the IAF LHREB in the middle of the capture region for that waypoint. The whole approach was contained within half full-scale deflection of the CDI.
For the second approach, the aircraft was just within the 180° capture region for the IAF LHREB when the pilot commenced the turn towards the IF LHREI (Figure 5). Prior to turning towards the initial approach track, the aircraft was on a track that was about 100° to the initial approach track.
On the second approach, the turn onto the track between the IAF and the IF resulted in the aircraft initially being displaced full-scale CDI deflection to the right, which was corrected soon after. The aircraft was also turned slightly late at the IF and overshot the waypoint, before being corrected back to the intermediate approach track.
About 3 NM before the FAF, the aircraft started deviating right of the intermediate approach track. About 2 NM before the FAF, the sensitivity of the CDI began increasing (as indicated by the dotted lines, see also Figure 17).
When passing the FAF on the second approach, the aircraft was at about full-scale CDI deflection (0.23 NM to the right), and it continued deviating further right of the final approach track for 25 seconds before starting to return closer to the final approach track. The aircraft remained outside full-scale deflection in the final approach segment for about 55 seconds and outside half-full scale deflection for an additional 5 seconds. From about 17 to 32 seconds after passing the FAF, the aircraft’s deviation equalled or slightly exceeded 0.3 NM to the right of the final approach track (the lateral tracking tolerance specified in CAO 20.91 for the final approach track).
The aircraft started to deviate left of the final approach track at about 2.5 NM prior to the MAPt and it continued left until the end of the recorded data.
Groundspeed during approaches
Deriving an estimate of indicated airspeed from groundspeed involves considering several factors. In this case:
The recorded wind at ground level indicated nil wind during the first approach and 3–4 kt from about 280° during the second approach. However, a review of wind and temperature forecast and analysis charts from multiple sources indicated that there would have been more wind at higher altitudes. Acknowledging that this was forecast and analysis data rather than recorded data, the ATSB estimated that there would have probably been about 10 kt headwind on the intermediate/final approach track at 2,300 ft and 5 kt at 1,000 ft. In addition, when the aircraft was heading towards the IAF on the second approach at 3,500 ft, and when the aircraft was heading from the IAF to the IF, there would have been a tailwind.
Air pressure and temperature differences from a standard atmosphere meant that calibrated airspeed would have been lower than the true airspeed, with this difference increasing as the altitude increased. The difference was about 10 kt at 3,500 ft and 5 kt at 1,100 ft.
The Cessna 404 Pilot’s Operating Handbook (POH) stated that the indicated airspeed at 140 kt was 1 kt higher than the calibrated airspeed with gear and flap up, 3 kt higher with gear down and flap selected to the take-off/approach position, and 5 kt higher with gear down and flap selected to the landing position. During the descent part of an approach, the operator’s flight profile stated the landing gear should be down and the flaps in the approach position (Flight profiles).[58]
Overall, the ATSB estimated that the indicated airspeed would have probably been close to (within 0 to +5 kt) of the recorded groundspeed during the 2 approaches while the aircraft was on or close to the intermediate/final approach track. For simplicity in this report, the groundspeed was considered to be equivalent to the indicated airspeed during these periods.
Key aspects of the recorded groundspeed (and estimated indicated airspeed) data for the 2 approaches include:
The groundspeed (and estimated indicated airspeed) for the first approach was about 130–140 kt for the whole approach between the IAF and the IF, and 130 kt at the FAF. It then increased to 140 kt before the aircraft reached 1,000 ft and then remained at about that speed as the aircraft passed through the MDA, passed the MAPt and passed the runway threshold.
For the second approach, the groundspeed when the aircraft was heading toward the IAF was about 185 kt, but the indicated airspeed was about 160 kt. After making the turn towards the IF, the groundspeed was about 160 kt and the indicated airspeed was about 145 kt.
Before commencing descent from 3,500 ft, at 0914:43, the groundspeed was about 150 kt and the indicated airspeed was about 135 kt. Soon after, there was a decrease in speed, which was probably associated with the pilot selecting approach flap and lowering the landing gear. The subsequent increase was probably associated with the aircraft’s descent.
Between the IF and the FAF, the groundspeed (and estimated indicated airspeed) was about 135 kt. It increased to 140 kt soon after passing the FAF and, when the aircraft was 3 NM from the MAPt, the groundspeed increased to about 150 kt (associated with the aircraft’s increased descent rate).
Wreckage and impact information
The accident site was located on a sand bank adjacent to the beach, about 6.4 km (3.5 NM) south-east of the runway 30 threshold at Lockhart River Airport and 500 m to the south-west of the specified final approach track. This location was about 2.1 NM (3.9 km) from the missed approach point (MAPt).
The accident site was in line with the aircraft’s recorded track over the previous 3 data points. It was about 200 m beyond the last recorded data point (which had a recorded height of 100 ft), and its location indicated that the impact occurred less than 3 seconds after the last recorded data point.
The wreckage trail was spread over a distance of about 20 m from the initial impact point and the trail indicated that the aircraft was on a heading of about 280° (magnetic), with the impact point about 30 ft above mean sea level (Figure 18).
Figure 18: Overview of accident site
Source: ATSB
The ATSB’s on-site examination of the wreckage, damage to surrounding vegetation and ground markings indicated that at initial impact the aircraft was:
upright and close to wings level
at a flight path angle of about 5° nose down
at relatively high speed.
An area of foliage around the aircraft displayed signs of chemical burn from avgas, indicating that the aircraft had a significant amount of fuel on board. There was no evidence of any structural or mechanical defects, but the examination was limited by the extensive damage.
The damage to the recovered propellor blades indicated significant rotational energy at impact consistent with both engines operating normally with substantial power.
The landing gear was extended at the time of impact. Other aircraft configuration information such as flap position, trim settings and switch selections could not be validated due to the impact damage.
The only components on the aircraft that may have recorded data were a digital fuel flow indicator/totaliser and a transponder, and the ATSB recovered these components. After consideration of the damage to these components and the potential value of any data, no further examination was undertaken.
Survivability aspects
Given the aircraft’s speed at impact (about 150 kt or 278 km/h) and the resultant impact forces (as evidenced by the nature of the wreckage), the accident was not considered survivable.
The aircraft was not fitted with a fixed emergency locator transmitter (ELT), nor was it required to be under the current regulations. A personal locator beacon (PLB) was in the pilot’s flight bag. Post-accident onsite examination noted it was within its expiry date and it passed a function test. PLBs do not have an inertial g-switch to automatically switch them on when an accident occurs, so the PLB did not activate during the accident sequence.
At 0934 and 0938, air traffic control (ATC) attempted to contact the pilot of VH-OZO after they had not cancelled or amended the SARTIME[59] of 0930. ATC also requested that the pilot of an inbound aircraft attempt to contact VH-OZO on the CTAF.
At 0939, an INCERFA was declared (which is a situation where uncertainty exists regarding the safety of an aircraft and its occupants) and soon after ATC transferred management of the situation to the Joint Rescue Coordination Centre (JRCC). At 1020, the JRCC advised ATC that it had declared a DETRESFA or distress phase (which is a situation where there is reasonable certainty that an aircraft and its occupants require immediate assistance). At 1251, the JRCC advised the ATSB that the wreckage at been located.
Organisational information
Air Connect Australia
Air Connect Australia was issued with an Air Operator’s Certificate (AOC) by the Civil Aviation Safety Authority (CASA) in March 2017 with an expiry date of 31 March 2020. It authorised the certificate holder to operate Cessna C310/340, C404, C402/421 and Raytheon Baron/Travelair twin piston-engine aeroplane types as well as single piston-engine aeroplane types with a MTOW not exceeding 5,700 kg on charter and aerial work operations.
At the time of the accident, CASA was assessing the operator’s application to renew the AOC, which was subsequently issued on 1 May 2020 with an expiry date of 30 September 2023.
From April 2017, the operator dry-leased VH-OZO from the aircraft owner, who was based in Western Australia. In this arrangement, the aircraft owner was responsible for the continuing airworthiness of the aircraft and the operator managed the operational aspects, such as fuel and flight crew.
Initially the operator’s personnel consisted of a chief pilot and the managing director, who was also the head of aircraft airworthiness and maintenance control. The chief pilot and managing director were the operator’s only line pilots. The chief pilot left in 2018, and the manager director became the chief pilot following an assessment by CASA.
In the 18 months prior to the accident, VH-OZO was the only aircraft operated and the operator employed one pilot (the pilot of the accident flight) additional to the chief pilot. As previously stated, the pilot of the accident flight conducted most of the operator’s flights.
Operator proficiency checks
To conduct IFR flights in a multi-engine aircraft, a pilot was required to complete an instrument proficiency check (IPC) every 12 months. The checks had to be conducted by a CASA-approved flight examiner. There were no additional requirements for proficiency checks for pilots conducting passenger charter operations under the IFR unless the operator had a check and training organisation as specified in Civil Aviation Regulation 217 (Training and checking organisation), which did not apply to operators such as Air Connect Australia.
CASR Part 135 (Australian air transport operations—smaller aeroplanes) was registered in December 2018 and commenced on 2 December 2021. It included a requirement for operators to conduct proficiency checks on pilots, with the requirements for such checks to be specified in the Manual of Standards (MOS). The draft Manual of Standards (MOS) for Part 135, publicly consulted in September 2018, included specific requirements for recurrent proficiency checks. For operators conducting IFR flights or flights at night, an operator proficiency check (OPCs) was required about 6 months after commencing unsupervised line operations for the operator and subsequently at intervals of 6 months. The MOS for Part 135 that came into effect in December 2021 had effectively the same requirements (with an OPC now called a ‘flight crew member proficiency check’).
Version 2 of the operator’s operations manual (February 2018) required an OPC to be conducted ‘every year’, with another section stating these needed to be completed ‘within the previous 12 months’. Version 3 of the manual (February 2020) required an OPC be conducted at the chief pilot’s discretion at periods not exceeding 24 months.[60] The manual stated that the OPC could be conducted by the chief pilot or a designated flight examiner.
The chief pilot noted that the flight examiner who regularly conducted IPCs for the operator (and was designated to conduct OPCs) would effectively conduct an OPC when they did an IPC. The change to every 24 months was done to provide more flexibility for scheduling checks.
In terms of the nature or content of the OPC, the operations manual stated that an OPC was required to be conducted
…on a flight encompassing all operations in which the pilot would normally be engaged. These flights will cover flight planning, refuelling, aircraft weight and balance, passenger briefing, forced landings and all emergency operations.
The manual also included an OPC form, which listed 23 items to be evaluated.
As previously discussed (Qualifications and experience), after the pilot of VH-OZO was cleared for line operations on 29 October 2018 (which included an OPC), the operator did not conduct any OPCs on the pilot. In addition, the chief pilot did not conduct any flights with the pilot after October 2018.
The pilot’s IPC in August 2019 was conducted with a flight examiner who was not familiar with the operator’s operations manual and therefore did not cover all aspects of an OPC, and the additional supervised training in December 2019 for night recency was done by an external provider and did not evaluate line operations.
Monitoring of pilot recency
CASR Part 61 outlined several different recency requirements. With relevance to the accident flight, these included a pilot not being able to:
conduct a flight with passengers by day in a particular category of aircraft unless had conducted 3 take-offs and landings within the previous 90 days in that category of aircraft (CASR 61.395 (1))
conduct a flight under the IFR unless had conducted at least 3 instrument approaches within the previous 90 days (CASR 61.870 (2))
conduct a flight under the IFR in a particular category of aircraft unless had conducted at least 1 instrument approach in the previous 90 days in that category of aircraft (CASR 61.870 (3))
conduct a 2D instrument approach unless had conducted at least one such approach in the previous 90 days (CASR 61.870 (4))
conduct a flight under the IFR in a single-pilot operation unless had conducted at least one single-pilot flight under the IFR in the previous 6 months that had a duration of at least 1 hour and involved one instrument approach (CASR 61.875).
The CASA website stated:
We use recent experience requirements to maintain a pilots knowledge and skills when conducting instrument approach operations.
When conducting an approach to satisfy a recent experience, pilots should recognise the purpose of the approach is to maintain their competency to conduct such operations.
Simulating IMC, when safe to do so, will enhance the purpose of the approach. Conducting the approach provides some effective practice…
As previously noted, the pilot had been regularly logging the conduct of RNAV GNSS approaches (Qualifications and experience) as well as other types of instrument approaches. The pilot met all required recency requirements listed above.
The operator used the Aerotrack aviation management tool. The tool could be used to manage flight scheduling, fleet operations, and crew recency and rostering to meet regulatory requirements. It also created an online pilot logbook, as it tracked all flights conducted for the operator, and totalled recency requirements such as IFR flight time and instrument approaches.
The Aerotrack system correctly tracked all of the recency requirements except for CASR 61.875. The system tracked the total number of single-pilot IFR flight hours over a rolling 6-month period, calculated as a sum of all hours logged including partial hours (such as 0.5 hours).[61] However, it was not programmed to track if a single-pilot flight under the IFR (of at least 1 hour duration) was conducted.
Regulatory oversight
In June 2017, CASA conducted a level-1 surveillance event on Air Connect Australia. CASA concluded that the operator was:
an overall compliant organisation with sufficiently equipped facilities and suitable qualified personnel conducting operations in accordance with its legislative authorisations and responsibilities.
The audit identified 5 non-compliance notices, including 3 relating to operations manual content regarding transponders, daily inspections and oil consumption records, and 2 relating to incomplete staff induction records for one pilot and the emergency proficiency checks for one pilot carried out by a person who was not the chief pilot. Other findings included 2 observations relating to job descriptions and one aircraft survey report finding. These findings were addressed by the operator.
In June 2018, CASA conducted a level-2 airworthiness and maintenance system surveillance activity relating to VH-OZO, prior to a flying operations inspector flying on the aircraft for the purpose of a chief pilot assessment. The surveillance report found there were no anomalies identified in either the technical documentation assessment or the physical inspection of the aircraft and the chief pilot assessment was then conducted.
In February 2020, CASA conducted a desk-top surveillance activity to determine if the AOC could be subsequently re-issued. The surveillance considered the organisation’s surveillance and compliance history, the management structure and operational oversight effectiveness. The review did not indicate any matter that would preclude a subsequent issue of the organisation’s AOC.
In May 2020, CASA conducted a post-accident regulatory and safety review. This review concluded that VH-OZO was correctly registered, certified for flight, maintained by qualified people, flown by a qualified person to a qualified aerodrome using a correctly validated approach. The review stated that past and current surveillance events had not detailed safety concerns with the operation of VH-OZO.
Operational information
Pre-flight planning and in-flight monitoring
Civil Aviation Regulation 239 (Planning of flight by pilot in command) stated:
Before beginning a flight, the pilot in command shall study all available information appropriate to the intended operation, and, in the cases of flights away from the vicinity of an aerodrome and all I.F.R. flights, shall make a careful study of:
a. current weather reports and forecasts for the route to be followed and at aerodromes to be used;
b. the airways facilities available on the route to be followed and the condition of those facilities;
c. the condition of aerodromes to be used and their suitability for the aircraft to be used; and
d. the air traffic control rules and procedure appertaining to the particular flight;
and the pilot shall plan the flight in relation to the information obtained.
AIP ENR 1.10 (Flight Planning) also stated these requirements. In addition, it stated a pilot was required to review NOTAMs[62] applicable to the flight.
At 1326 on the day before the accident flight, the pilot accessed a location briefing for Lockhart River from the National Aeronautical Information Processing System (NAIPS) via an electronic flight bag (EFB) application. This type of briefing typically displayed current forecasts, reports, and ‘notice to airmen’ (NOTAM) applicable to the nominated location.
Later that day, at 1830, the pilot requested grid point wind and temperature charts (GPWT) and a specific pre-flight information bulletin (SPFIB) from NAIPS via flight planning software. The SPFIB request was for Cairns to Lockhart River and return with the estimated time of departure nominated as 1930 the same day. This bulletin was valid until 1830 on the day of the accident.
A printout of the SPFIB found at the accident site showed aerodrome forecast (TAF) and weather reports (METAR) for Cairns. The weather for the next day (day of accident flight) at Cairns Airport was expected to be a visibility of 10 km or greater and showers of light rain with scattered cloud at 1,800 ft in the morning lifting to 2,500 ft. In addition, the forecast imposed a TEMPO for the next day to specify periods of visibility reduced to 2,000 m with showers of moderate rain and broken cloud at 1,000 ft.
On the printout of the SPFIB, a METAR for Lockhart River for 1800 (10 March 2020) showed light winds, visibility 10 km or greater and nil cloud detected. Since 0900 that morning, recorded rainfall was 1.8 mm.
No TAF was provided on the SPFIB for Lockhart River as the time of the request was outside the issue and validity period. There were no predicted outages of global positioning system/global navigation satellite system (GPS/GNSS) capability for Cairns or Lockhart River. NOTAM information included a change to Lockhart River runway distance and gradient data and no other notices with significance for the planned flight.
After the SPFIB was received, at 1942, the pilot submitted a flight notification for the planned departure from Cairns at 0730 the next morning to Lockhart River followed by a departure at 1430 for the return sector. Both sectors were planned under IFR with nominated capability for instrument approaches using GPS/GNSS equipment.
After the pilot requested the SPFIB and submitted the flight notification on the evening before the accident flight, there was no record of further requests for meteorological information from NAIPS. Such information was also available from the Bureau of Meteorology website and other sources without any user registration requirements. The ATSB was advised that the pilot was aware of the current weather forecasts for Lockhart River and Cairns on the morning before the flight.
A damaged and partly illegible copy of the pilot’s flight plan/log was found at the accident site. This was a printout from flight planning software showing key navigational data and pilot notes on progress of the flight. There was no indication of any operational abnormalities.
Fuel calculations
On the morning of the flight, the pilot refuelled the aircraft with 650 L of avgas. A tabulated fuel plan showed 1,040 L on board at engine start at Cairns and expected fuel consumption of 285 L for the planned 94-minute flight to Lockhart River. The pilot had included provision for 45 minutes fixed reserve (124 L), 40 L variable reserve and 60 minutes holding (110 L) if required (consistent with the forecast TEMPO conditions in the TAF, see Aerodrome forecasts). If the variable reserve and holding allowance was consumed on the outbound sector (in addition to the calculated flight fuel), the remaining 605 L was sufficient to return to Cairns with allowance for 60-minutes holding on arrival.
In summary, the aircraft had sufficient fuel to conduct the flight from Cairns to Lockhart River and return, with additional fuel for holding on both sectors if required. The pilot was probably not intending to refuel at Lockhart River, although avgas was available if required.
Weight and balance
The pilot completed the operator’s passenger/cargo manifest form and calculated the aircraft’s weight and balance with reference to individual passenger weights and baggage. The take-off weight was recorded as 3,678 kg and nominal landing weight as 3,366 kg (7,421 lb). The aircraft’s maximum take-off weight was 3,810 kg and maximum landing weight was 3,674 kg. The graphical trimsheet showed the centre of gravity was within limits throughout the flight.
A copy of the operator’s in-flight monitoring form was found at the accident site. When the pilot completed the form in cruise at 10,000 ft, all of the recorded engine parameters for each engine were comparatively similar with no indication of any aircraft-related problems.
Communications during approaches
The AIP (ENR 1.1, 10.1) recommended radio calls at an uncontrolled aerodrome. These included:
the pilot being inbound to an aerodrome (10 NM or earlier, commensurate with aeroplane performance and pilot workload, with an estimated time of arrival)
during an instrument approach:
departing the FAF or established on the final approach segment (including details of position and intentions)
terminating the approach or commencing the missed approach (including details of position and intentions).
The Air Connect Australia operations manual stated the following for communications at non-towered aerodromes:
When operating within the vicinity of a non-controlled aerodrome, a known training area or authorised low flying area, Company pilots are to broadcast their intentions, listening out and communicate with any possible conflicting aircraft in accordance with the requirements of the AIP.
Additionally, for straight-in approaches at non-towered aerodromes, the manual stated:
Monitor / broadcast on CTAF shall be made by 10 NM and include aircraft type, position, callsign and include the intention to make a straight-in approach.
Monitor / broadcast at 3 NM that the aircraft is established on the final approach.
During both of the approaches at Lockhart River, the pilot of VH-OZO made broadcasts when at 10 NM (that is, at about the IF). During the first approach, the pilot also made a broadcast at 5 NM (at the FAF) and during the missed approach. There was no call recorded when the aircraft was at 5 NM on the second approach.
Electronic flight bag and approach charts
During the flight, the pilot was using an iPad with an electronic flight bag (EFB) application (OzRunways) and was carrying a second iPad as a backup. The operator’s operations manual (section 2A1.3.2.2) stipulated that all EFB devices permitted for use were class 1 (portable electronic device) and functionality level 1, which meant that it could be one or more of the following:
held in the hand
mounted on an approved mount
attached to a stand-alone kneeboard secured to a flight crew member
connected to the aircraft power for battery re-charging
connected to an installed antenna intended for use with the EFB for situational awareness but not navigation.
Furthermore, unless secured in accordance with b or c above, the EFB was required to be stowed during take-off, landing, instrument approach and when flying less than 1,000 ft above terrain. It was also only to be used:
…as a source of navigational data e.g. Departure and Approach plates and airport information.
The operator did not have an approved mount for the iPad. Accordingly, the operator required paper approach charts to be used when conducting an instrument approach. The chief pilot stated that the pilot subscribed to the departure and arrival procedure charts published by Airservices Australia. There was a clamp on the control column where a paper approach chart could be placed (Figure 8). There were no paper approach charts identified at the accident site, although the flight plan/log was found. Due to the disruption of the wreckage, it could not be determined whether the pilot carried the paper charts on board.
A friend of the pilot stated that they had provided the pilot with a mounting device that could be used to mount an iPad on a control column. The pilot’s iPad EFB was on[63] during the approach, however there were differing reports about how the pilot used the iPad during previous flights and whether it was mounted on the control column, placed on their knee or placed on the vacant seat next to the pilot. Due to disruption of the aircraft in the accident, only the second (backup) iPad was found at the accident site.
Flight profiles
The operator’s operations manual included flight profiles to be used for various situations for the Cessna 404, and stated that the profiles were required to be used for all operations. The prescribed flight profile for an RNAV GNSS approach (and other straight-in instrument approaches) is shown in Figure 19.
The indicated airspeed was required to be below 180 kt at the IAF and at 130 kt (+ or - 5 kt) at the start of the descent after passing the IAF (with the landing gear down and approach flap selected). The airspeed was also required to be Vref to Vref +10 kt at the FAF. As noted in Configurations and speeds, the Vref at maximum landing weight (8,100 lb) for the Cessna 404 was 91 kt and at weights 7,500 lb and below was 88 kt. In effect, the operator’s flight profile requirement to be at Vref to Vref + 10 kt at the FAF equated to an indicated airspeed of about 90–100 kt.
Figure 19: Flight profile for Cessna 404 RNAV GNSS approach
In another section titled ‘Final approach & threshold speeds’, the operations manual stated:
The [pilot] shall conduct the final approach in accordance with the stabilised approach criteria… [see next section]
These were the ‘handling speeds’ referred to the AIP for instrument approaches for a category B aircraft, such as the Cessna 404 (see Handling speeds). In effect, these speeds meant that the maximum allowed indicated airspeed after passing the IAF for the Cessna 404 was 180 kt and the maximum airspeed after passing the FAF was 130 kt.
The chief pilot recalled that the flight profiles were included in the operations manual by the previous chief pilot, who had based them on profiles used by another operator. The chief pilot stated that they advised the pilot of the accident flight to be at about 5,000 ft at the start of an approach (at the IAF) and then use a continuous descent to the runway from the IAF, and they demonstrated this to the pilot during their supervised flying in October 2018.
The chief pilot recalled that, when they flew the aircraft, they would select approach flap and landing gear early in the descent and be stabilised at a speed of 120 kt and a descent rate of 600 ft/min[64] well before the FAF. The chief pilot stated that the speed at the FAF should be about Vref + 20 kt (which equates to about 110 kt) but that the 100 kt specified in the flight profile would be acceptable. They stated that 130 kt at the FAF was too fast.
The previous chief pilot also recalled that the operator’s flight profile was most likely obtained from another operator. They noted their recollection of speeds was limited given the time since they flew the aircraft, but they recalled that they would be at least at Vref + 10 kt (that is, 100 kt) but not faster than 120 kt at the FAF, then slowing the aircraft down by 1,000 ft.
The flight examiner regularly used by the operator also worked with another operator of Cessna 404 aircraft (which was a different operator to that referred to by the previous chief pilot). The examiner stated that at the IF they would normally be at 130 kt with gear down and approach flap selected. The normal speed they used at the FAF was 110 kt (Vref + 20 kt), and 100 kt would be a little slow at that point on the approach. The examiner advised that these speeds were also used by the other Cessna 404 operator.
In summary, the ATSB concluded that the operator’s published flight profile speed of 90–100 kt at the FAF was probably not the operator’s preferred speed during flight operations. Rather, it appeared that the preferred speed at the FAF was probably about 110 kt. However, the extent to which this was clearly communicated to the pilot of the accident flight could not be determined.
Stabilised approach criteria
Guidance regarding stabilised approach criteria
A stabilised approach is one in which all criteria specified in the operations manual are met, at or before the applicable height or reference point. The Flight Safety Foundation (FSF) has for many years recommended that operators have stabilised approach criteria. Detailed guidance was provided by the FSF in its approach and landing accident reduction (ALAR) briefing note 7.1 (Stabilized approach, 2000a). The recommended criteria were summarised in a list, as reproduced in Figure 20.
Figure 20: FSF recommended elements of a stabilised approach
Source: ALAR briefing note 7.1 (Flight Safety Foundation 2000a)
The FSF briefing note also stated:
The flight crew must “stay ahead of the aircraft” throughout the flight. This includes achieving desired flight parameters … during the descent, approach and landing. Any indication that a desired flight parameter will not be achieved should prompt immediate corrective action or the decision to go around.
The minimum stabilization height constitutes an approach gate on the final approach; a go-around must be initiated if:
The required configuration and airspeed are not established, or the flight path is not stabilized when reaching the minimum stabilization height;
The aircraft becomes unstabilized below the minimum stabilization height.
ICAO Annex 6 Part I applied to international commercial air transport operations in aeroplanes. Since 1998, it included a standard stating an operator’s operations manual had to include stabilised approach procedures.
ICAO document 8168 (Procedures for Air Navigation Services, Aircraft Operations, known as PANS-OPS) provided recommendations on procedures for flight crew. Since 2001, PANS-OPS included content on stabilised approaches and stabilised approach criteria. It stated:
Studies have shown that the risk of controlled flight into terrain (CFIT) is high on non-precision approaches. While the procedures themselves are not inherently unsafe, the use of the traditional step down descent technique for flying non-precision approaches is prone to error, and is therefore discouraged. Operators should reduce this risk by emphasizing training and standardization in vertical path control on non-precision approach procedures…
Operators should use the CDFA (continuous descent final approach) technique whenever possible as it adds to the safety of the approach operation by reducing pilot workload and by lessening the possibility of error in flying the approach…
This technique requires a continuous descent, flown either with vertical navigation (VNAV) guidance calculated by on-board equipment or based on manual calculation of the required rate of descent, without level-offs. The rate of descent is selected and adjusted to achieve a continuous descent to a point approximately 15 m (50 ft) above the landing runway threshold or the point where the flare manoeuvre should begin for the type of aircraft flown...
The guidance document also stated:
The primary safety consideration in the development of the stabilized approach procedure shall be maintenance of the intended flight path as depicted in the published approach procedure, without excessive manoeuvring.
PANS-OPS stated the types of information that should be included in stabilised approach criteria (such as speeds, minimum power settings, attitudes, crossing altitude deviation tolerances, aircraft configuration, maximum sink rate and competition of checklists and briefings). In addition, the document stated that an operator’s procedures should include, as a minimum:
a) that in instrument meteorological conditions (IMC), all flights shall be stabilized by no lower than 300 m (1 000 ft) height above threshold; and
b) that all flights of any nature shall be stabilized by no lower than 150 m (500 ft) height above threshold.
Although the FSF and ICAO guidance may be considered most applicable to larger air transport aircraft with multi-crew operations and turbine engines, similar guidance (with the same applicable heights of 1,000 ft for operations in IMC and 500 ft for operations in VMC) has also been widely recommended for operations in smaller aircraft (Appendix D – Guidance to industry regarding stabilised approaches). This guidance has emphasised the benefits of using a CDFA technique with stabilised approach criteria in terms of reducing workload and increasing the time to monitor, detect and react to problems.
In Australia, since 2014, the Civil Aviation Advisory Publication (CAAP) 215-1 (Guide to the preparation of operations manuals) stated that an operator’s manual should include stabilised approach criteria in its section on approach and landing procedures. Guidance regarding applicable heights or reference points for such criteria were not specified in the CAAP or other CASA guidance documents.[65]
CASA advised the ATSB that specific Australian guidance was not provided prior to 2021 since there was no direct legislative requirement for operators to use such criteria, and it was considered that there was readily available and significant global guidance on this topic available from a wide range of authoritative sources.
Operator’s stabilised approach criteria
The Air Connect Australia operations manual stated:
Stabilised Approach Criteria are as follows:
(a) All flights, other than training flights, must be stabilised by 300 feet above aerodrome elevation in both IMC and VMC.
(b) An approach is stabilised when the following criteria are met:
The aircraft is on the correct flight path;
Only small changes in heading and pitch are required to maintain the correct flight path;
The aircraft is not more than Vref + 20 kts and not less than Vref indicated airspeed
The aircraft is in the correct landing configuration;
Sink rate is no greater than 1000 fpm [ft/min];[66] if an approach requires a sink rate greater than 1000 fpm, a special briefing should be conducted;
Power setting is appropriate for the aircraft configuration and is not below the minimum power for approach as defined by the aircraft operating manual;
All briefings and checklists have been conducted;
Instrument approaches are stabilised by the final approach fix, if they also fulfil the tracking requirements – established within ‘half scale deflection’ for the ILS, VOR and GNSS, within + or – 5 degrees for the NBD; during a circling approach, wings should be level on final by 300 feet above aerodrome elevation;
Unique approach procedures or abnormal conditions requiring a deviation from the above elements of a stabilized approach require a special briefing.
Missed Approach Procedure is as follows:
(a) Other than on training flights, an approach that is not stable below 300 feet aerodrome elevation in both IMC and VMC requires an immediate GO-AROUND. The procedure for a go around / missed approach is as follows:
Should be flown as per the approach chart missed approach procedure, or as advised by ATC;
The aircraft handling technique will be as per the relevant AFM for the appropriate aircraft…
The manual further stated:
If an approach does not meet the criteria for a stabilised approach…, the Pilot-in-Command shall conduct a missed approach.
To meet these stabilised approach criteria, the maximum indicated airspeed in a Cessna 404 needed to be Vref + 20 kt or about 110 kt at 300 ft above aerodrome elevation.
The chief pilot advised the ATSB that the published applicable height of 300 ft was too low to be effective, as it was normally below the MDA. They believed approaches should be stabilised much earlier, ideally at height of about 1,000 ft or even earlier. The chief pilot also stated that all configuration changes should be done early in the approach, with only the selection of landing flap to be completed late in the approach at the pilot’s discretion. The flight examiner used by the operator noted that stabilised approach criteria for most piston twin-engine and single-engine aeroplanes needed to acknowledge that the last stage of flap (or landing flap) should generally not be selected until about 300 ft due to aircraft performance considerations.
The chief pilot also recalled that they had discussed the importance of being stabilised early in the approach to the pilot of the accident flight on multiple occasions, and they had stated the importance of conducting constant angle descents down to the MDA at 600 ft/min. The chief pilot also noted that they had emphasised to the pilot the importance of gradual reductions in power and therefore speed during approaches in order to minimise undesirable cylinder head temperatures, and use slow descent rates for passenger comfort.
Additional information
During its investigation into the 2005 CFIT accident of a Metro aircraft at Lockhart River involving an operator that conducted passenger transport operations in Metro turboprop aircraft, the ATSB identified that that operator did not have stabilised approach criteria.[67] Of 5 other operators conducting operations in Metro aircraft, all had stabilised approach criteria, with 1 having an applicable height of 200 ft, 2 having an applicable height of 300 ft and 2 having an applicable height of 1,000 ft.
The ATSB also identified that an operator conducting passenger transport operations in a DHC-8 aircraft in 2012 had stabilised approach criteria based on an applicable height of 300 ft.[68] In addition, during another investigation commenced in 2021, the ATSB recently identified another operator of turboprop aircraft conducting passenger transport operations (charter) that had stabilised approach criteria with an applicable height of 300 ft. The ATSB has also identified that major airlines and some operators of single-pilot IFR operations in Australia have criteria based on 1,000 ft above ground level in IMC.
Prior missed approach during an RNAV GNSS approach (22 January 2020)
A review of the pilot’s logbook identified one other flight since the pilot joined the operator that involved 2 instrument approaches (and therefore a missed approach following an instrument approach). This occurred on a flight from Weipa to Aurukun, Queensland, on 22 January 2020, after which the pilot logged 2 RNAV GNSS approaches. Recorded data confirmed that the pilot conducted 2 approaches to runway 34 at Aurukun.
Analysis of the weather conditions and interviews with the passengers identified that there was a storm in the vicinity at the time, and interviews and recorded flight data indicated that the pilot was trying to avoid the weather. The passengers recalled observing the pilot using the onboard weather radar as well as an iPad with the weather on it to track the movement of the storm.
Passenger recollections regarding the weather during the first approach were varied; some recalled that they could not see the runway at times whereas others recalled the runway was still visible though restricted. The ground appeared to be visible most of the time. Images taken by a passenger during the first approach confirmed that there was significant cloud in the area though the ground could be seen to the left of the aircraft.
Review of the recorded flight data indicated that, on the first approach, the aircraft commenced descent on the recommended descent profile from about 1,600 ft, slightly below the initial approach altitude of 1,800 ft. The aircraft passed the FAF at an indicated airspeed of about 140 kt, and it was about 200–300 ft below the recommended descent profile when it passed the MDA at an indicated airspeed of about 145 kt. The aircraft descended to a recorded altitude of about 200–300 ft (at about 140 kt) before starting to climb.
The missed approach did not conform to the published missed approach procedure, with the aircraft flying to the right of the MAPt rather than maintaining the runway heading. However, the conditions may have been visual at this time. After the missed approach, the pilot circled for some time, remaining in VMC and waiting for the storm to pass, before conducting a second approach (about 31 minutes after the first approach). Images taken by a passenger during the second approach confirmed that the weather conditions were significantly better than on the first approach.
The exact reasons for the missed approach could not be determined (that is, whether it was due to reduced visibility of the runway or also due to the aircraft’s speed not meeting the operator’s stabilised approach criteria at 300 ft above aerodrome elevation).
Further details of these 2 approaches are provided in Appendix E – Aurukun incident flight – 22 January 2020.
Review of the pilot’s recent RNAV GNSS approaches
General aspects
The ATSB reviewed the available recorded data for the pilot’s flights in the previous 6 months for which the pilot had logged an RNAV GNSS approach (that is, 21 approaches). Recorded data was available for 16 of these approaches. Of these 16 approaches:
10 involved straight-in approaches to the runway
5 were flown to past the FAF and then a circling approach was flown from above the specified circling minima to the opposite (reciprocal) runway
1 was not an RNAV GNSS approach as it did not fly near the designated waypoints (and it was therefore not considered for further analysis).
Based on a review of available weather information, all 21 approaches were very likely conducted in VMC except for the first approach conducted at Aurukun on 22 January 2020 (which was potentially in IMC for a brief period). For those approaches conducted in VMC, the pilot was not specifically required to conduct an RNAV GNSS approach, except for the purpose of meeting recency requirements.
The published approach charts for all the approaches had 5 NM segments between the IAF and IF, IF and FAF, and FAF and MAPt. Most of the approaches were conducted at locations where the recommended descent profile commenced at about the FAF, except for one approach to runway 11 at Cooktown (where the recommended descent profile commenced at the IAF).
Vertical profiles
For most of the 15 RNAV GNSS approaches with recorded data available, the data showed the pilot typically descended to about 5,000–5,300 ft and then levelled out for a short period prior to the IAF. When passing the IAF, the pilot commenced a continuous descent to join the approach’s recommended descent profile on about a 3° approach.
The only exceptions to this method were the 2 approaches conducted at Aurukun on 22 January 2020 (when the pilot commenced descent on the approaches from close to the published initial approach altitude of 1,800 ft). As noted in Recorded flight data, the second approach at Lockhart River during the accident flight was also commenced at a lower altitude (that is, the published initial approach altitude of 3,500 ft) when the aircraft was between the IAF and the IF).
In general, the approaches were conducted close to the recommended descent profile. The only exception was the first approach at Aurukun on 22 January 2020, which reached the MDA about 200–300 ft below the recommended profile.
Lateral positions
The pilot generally entered each approach via the nearest of the 3 IAFs. In most cases, the aircraft passed the IAF from close to the middle of the capture region for that waypoint, or at least on a track that was less than 45° difference to the initial approach track. On one approach (at Cooktown), they entered from a similar position as the second approach at Lockhart River, although from about 65° right of the extended initial approach track to the IAF labelled ‘A’ (as opposed to about 100° at Lockhart River).
For all the straight-in runway approaches (except the second approach at Lockhart River), the aircraft remained close to the intermediate approach track and final approach track. In most cases, the aircraft also remained close to the initial approach track. The only exceptions were:
the Cooktown approach (when the aircraft flew over the IAF then, while descending, deviated left of the initial approach track by 0.9 NM and remained left until close to the IF)
the first approach at Aurukun on 22 January 2020 (when the pilot commenced the approach from slightly more than 1 NM west of the IAF and flew direct to the IF from that position, while remaining close to the initial approach altitude).
Indicated airspeeds
The ATSB reviewed the indicated airspeeds during the pilot’s 8 previous straight-in RNAV GNSS approaches to evaluate their consistency with the operator’s speed requirements and preferences, and these were compared with the 2 approaches at Lockhart River on the day of the accident (Figure 17). The 8 other approaches included the 2 approaches conducted at Aurukun on 22 January 2020 (Figure 25), and 6 other approaches that the pilot conducted from December 2019 to February 2020 and logged as RNAV GNSS approaches.
For the 10 approaches, the ATSB estimated the indicated airspeeds based on the recorded groundspeed, forecast and analysis wind charts and other relevant information. The actual wind speeds above the aerodrome on each occasion were not known, and as a result there could have been some differences between the estimated indicated speeds and the actual indicated airspeeds.
The results for key points on the approaches are shown in Table 4. In general terms:
In all 10 cases, the approaches did not exceed (and were well below) the maximum AIP handling speed of 180 kt in the initial and intermediate approach segments.
In all 10 cases, the approaches exceeded the operator’s preferred speed of 110 kt at the FAF. Most of the approaches were about 130–140 kt at the FAF, and 7 of the approaches appeared to exceed the maximum AIP handling speed of 130 kt at or after passing the FAF by 10 kt or more.
In most cases, the approaches appeared to be close to the operator’s maximum stabilised approach speed of 110 kt at or approaching 300 ft. However, in 3 cases there was a significant exceedance. These included the first approach at Aurukun on 22 January 2020 (which was followed by a missed approach), and the 2 approaches at Lockhart River (with the first followed by a missed approach).
Table 4: Summary of estimated indicated airspeeds during the pilot’s recent RNAV GNSS approaches (in kt)[69]
IF
FAF
FAF
1,000 ft
300 ft
Operator requirement or preference
(180 max)
110 preferred
(130 max)
(130 max)
110 max
Mornington Island, 2 Dec 2020 (VMC)
145
140
140
140
120
Normanton, 9 Dec 2020 (VMC)
145
145
145
145
125
Cooktown, 4 Jan 2020 (VMC)
140
140
140
140
115
Aurukun, 22 Jan 2020 (potential IMC, missed approach)
140
140
140
140
140
Aurukun, 22 Jan 2020 (VMC, second approach)
135
135
135
125
105
Aurukun, 3 Feb 2020 (VMC)
150
145
145
145
115
Kowanyama, 13 Feb 2020 (VMC)
140
120
120
120
115
Pormpuraaw, 18 Feb 2020 (VMC)
150
130
130
120
115
Lockhart River, 11 Mar 2020 (IMC, missed approach)
135
130
130
140
1401
Lockhart River, 11Mar 2020 (IMC, second approach, accident)
135
135
135
140
150
The requirement at 300 ft above aerodrome elevation is from the operator’s stabilised approach criteria. The maximum requirements for the IF, FAF and 1,000 ft above aerodrome elevation are from the AIP handling speeds for a category B aircraft (also referred to in the operations manual). The operator preferred speed at the FAF is based on interviews. All speeds rounded to nearest 5 kt. Green shading indicates the speed was consistent with the requirement or preference (within 5 kt), orange shading indicates a small exceedance (within 10 kt), and red shading indicates a significant exceedance (15 kt or more).
1Descent to just above 300 ft above aerodrome elevation (or just below that height) on this approach occurred after passing the MAPt.
In summary, the pilot was not conducting RNAV instrument approaches in the Cessna 404 in accordance with the operator’s preferred speed of 110 kt at the FAF. In some cases, the pilot appeared to be complying or was close to the AIP handling speed requirement to be at a maximum speed of 130 kt in the final approach segment, but in some cases they exceeded this requirement. The chief pilot advised that they were unaware that the pilot was conducting RNAV approaches with a speed that was significantly above 110 kt at the FAF.
Controlled flight into terrain
CFIT accident data
The ATSB research report CFIT: Australia in context 1996 to 2005 (ATSB, 2007), defined a controlled flight into terrain (CFIT) as an in-flight collision with terrain, water, or obstacles, in which:
the aircraft is under the control of the pilot(s)
there is no defect or unserviceability that would prevent normal operation of the aircraft
the pilot(s) had little or no awareness of the impending collision.
In the 10-year reporting period for that research (1996–2005), there were 27 CFIT occurrences in Australia. Of these 27 occurrences:
25 were accidents, including 15 fatal accidents, resulting in a total of 47 fatalities.
19 involved aeroplanes (including 18 accidents and 12 fatal accidents) and 8 involved helicopters (including 7 accidents and 3 fatal accidents)
17 (63%) occurred during the approach phase, with 8 during a visual approach and 9 during an instrument approach
1 occurred during a low-capacity regular public transport flight (RPT), 8 during charter flights, 4 during aerial work flights and 14 during private/business flights.
only one aircraft of the 27 occurrences was fitted with a TAWS – the Fairchild SA227-DC (Metro) aircraft involved in the low-capacity RPT CFIT accident at Lockhart River in May 2005.[70] This GPWS was not a predictive or enhanced TAWS, which became required for turbine aircraft like the Metro by the end of June 2005.
Of the 9 CFIT occurrences that occurred during an instrument approach:[71]
all 9 were accidents, including 7 fatal accidents, resulting in a total of 31 fatalities
all 9 involved aeroplanes
4 occurred during an RNAV GNSS approach, 2 during a GPS arrival and 3 during an NDB approach.
1 occurred during a low-capacity RPT flight, 3 during charter flights, 2 during aerial work flights and 3 during private/business flights.
Further details of some of these accidents are provided in Appendix F – Related occurrences.
A review of the ATSB database for the 15-year period 2006–2020 identified only 1 CFIT involving an aeroplane on an instrument approach (that is, VH-OZO at Lockhart River, resulting in 5 fatalities). There were also 5 other CFITs involving aeroplanes on visual approaches, which resulted in 2 accidents, including 1 fatal accident with 4 fatalities.
The International Air Transport Association (IATA) (2018) published a report on worldwide CFIT accidents from 2008 to 2017 involving aircraft with a MTOW of at least 5,700 kg (12,540 lb). During that period, there were 47 CFIT accidents, which accounted for 6% of total accidents. Most (42 or 89%) of the CFIT accidents involved fatalities, and CFIT was the second highest fatal accident category (after loss of control in-flight), accounting for 28% of all fatal accidents.
Of the 47 CFIT accidents, 24 (51%) occurred during the approach phase of flight, 7 (15%) during landing, and 4 (9%) during a go-around. Turbo-prop aircraft had a much higher CFIT rate (per million flights) than jet aircraft. Older generation aircraft were also involved in more CFIT accidents.
The IATA report found that the rate of CFIT accidents was significantly lower in the last 5 years (2013–17) compared to the first 5 years (2008–12). The report stated:
It is generally accepted that the reduction in CFIT accidents can be traced back to the introduction of Ground Proximity Warning System (GPWS), and Terrain Awareness Warning System (TAWS). Other improvements, may have also contributed directly or indirectly to the reduction of the likelihood of CFIT accidents, including aircraft design, replacing non-precision with precision approach procedures, pilot training, improved flight standards, Continuous Descent Final Approach (CDFA) technique, approach lightning, visual approach guidance and procedures, ground-based Minimum Safe Altitude Warning (MSAW) system, visual and instrument approach guidance and procedures.
In addition, the IATA report noted common contributing factors to CFIT accidents, including poor visibility or IMC (49%) and lack of visual reference (33%). Unstable approaches were cited in 10% of accidents. The report stated:
Unstable approaches increase the possibility of diverting a flight crew’s attention away from the approach procedure to regain better control of the airplane. Stabilized approach policies broadly concur in stating that a safe approach requires the flight path angle, configuration, and airspeed to be stabilized. Once one or more of these parameters are violated, the approach becomes unstable and the margin for a safe landing is decreased to a level requiring flight crew action; a go-around should be initiated.
Since the CDFA techniques contribute to a stabilized approach, the industry should also as soon as, and wherever, possible to develop procedures and train pilots to fly a stabilized CDFA…
The report also stated:
It is evident that most of the CFIT accidents result from a pilot’s breakdown in situational awareness (SA) instead of aircraft malfunction or a fire. In other words, these accidents are, for the most part, entirely preventable by the pilot. SA refers to the accurate perception by flight crew of the factors and conditions currently affecting the safe operation of the aircraft, and their vertical and/or horizontal position awareness in relation to the ground, water, or obstacles. The data shows that 49 percent of CFIT accidents had vertical, lateral or speed deviations as a contributing factor to CFIT accidents. One method to provide pilots with a greater level of safety through enhanced situational awareness and, more reliable warnings of possible terrain conflicts such as EGPWS that is equipped with accurate navigation systems like global positioning system (GPS) for both navigation and terrain surveillance.
Research conducted for the Netherlands Directorate-General of Civil Aviation, under the auspices of the Flight Safety Foundation, identified a fivefold increase in accident risk in commercial aircraft flying a non-precision approach compared with a precision approach (Enders and others, 1996).
Other research conducted into the human factors associated with CFIT accidents between 2007 and 2017 found that 24 out of 50 accidents reviewed (48%) occurred during the approach phase of flight (Kelly and Efthymiou, 2019). This research also found that ‘Breakdown of the Visual Scan’ occurred in 84% of accidents and that, in 42 of the analysed accident reports, a critical parameter such as altitude was ignored, and an unsafe situation occurred through ‘distraction’, ‘complacency’ or ‘lack of skill’.
Efforts to reduce CFIT accidents
In 1995 an international CFIT task force, whose major goal was to prevent CFIT accidents, completed its work after creating several unique products for the Flight Safety Foundation (FSF) including a CFIT Education and Training Aid. The training aid described GPWS (now known as TAWS) as ‘one of the major weapons in the growing arsenal of CFIT prevention methods.’ It further recommended every aircraft be fitted with such a system, as a GPWS warning ‘is normally the flight crew’s last opportunity to avoid CFIT’.
The training aid recommended standard operating procedures and/or guidance from the aircraft manufacturer that specified flight crew actions in the event of a terrain warning. In the absence of these, the aid provided a standard escape manoeuvre for flight crew to follow in the event of a terrain warning.
The CFIT task force identified 2 ‘basic causes’ of CFIT accidents – a lack of flight crew’s vertical position awareness and their lack of horizontal position awareness in relation to the ground, water, or obstacles. More than two-thirds of all CFIT accidents were the result of altitude error or lack of vertical situational awareness. To mitigate against this, the training aid emphasised the importance of flight crew training and discipline.
CFIT mitigation strategies
In 1994, the international CFIT task force also designed a CFIT checklist for the FSF, aimed at reducing CFIT accidents (Appendix G – Flight Safety Foundation CFIT Checklist). The checklist had 3 parts:
Part I enabled a calculation of the CFIT risk factors for the planned destinations (including air traffic control capabilities and the types of approaches available) and risk multipliers (such as the type of operation and weather conditions). Some of the risk factors relevant to this accident included no ATC at the airport and a non-precision approach type. Risk multipliers included passenger-carrying charter operation, IMC, and a single-pilot flight crew.
Part II of the checklist listed CFIT risk-reduction factors in 4 areas: company culture, flight standards, hazard awareness and training, and aircraft equipment.
Part III calculated the CFIT risk score by adding the destination CFIT risk factors (which are negative values) multiplied by the calculated risk multiplier to the risk-reduction factors.
The ATSB included copies of the FSF checklist in several of its accident reports, and also referred to the checklist in the research report CFIT: Australia in context 1996 to 2005 (ATSB, 2007).
In addition to the checklist, the FSF developed a CFIT Education and Training Aid in the 1990s, which included an example CFIT training program (albeit focussed on larger aircraft operations). It also developed a video training aid (for regional and business aircraft operators) and the ALAR Tool Kit, which included a number of briefing notes, such as the briefing note on stabilised approaches (see Guidance regarding stabilised approach criteria).
More recently, the FSF also developed a basic aviation risk standard (BARS) program that was designed to provide organisations that engaged contracted aircraft operators with a standard to assist in the risk-based management of aviation activities. It advised that the standard was suited to any organisation that used aircraft operators to provide contracted aviation support for its operations, particularly within remote and challenging environments. The program was used by several large mining/resource companies and other organisations. Participating aircraft operators could be audited against the standard.
The standard document stated:
All national and international regulations pertaining to aviation operations must be followed. This Standard is designed to supplement those requirements.
With regards to CFIT, the following risk controls were specified:
2 pilots for flights to be flown at night or ‘in IFR’
multi-engine aircraft to be used for flights flown at night or ‘in IFR’
aircraft operators to include type-specific stabilised approach requirements in their operations manual
aircraft that fly under IFR or at night and on long-term contract to be fitted with an approved and serviceable Class A TAWS when an approved modification exists for the aircraft type (and the operator must have related procedures to be followed by the flight crew in the event of an alert).
The BARS implementation guide outlined guidance for stabilised approach criteria, based on the ALAR briefing note 7.1.
Operator’s CFIT risk mitigation
General aspects
At the time of the accident, Air Connect Australia was not required to have a safety management system (SMS). At the core of an SMS is a formal risk safety management process, which is used specifically to:
identify hazards associated with an organisation’s operations
analyse and assess the risks associated with those hazards
implement control, to prevent future accidents, incidents or occurrences (CASA, 2018).
The operator advised it had an SMS incorporated into its operations manual, which included a requirement for 6-monthly safety meetings as well as a hazard, incident and accident report form. However, this did not include a detailed hazard identification and mitigation process. Without a documented hazard identification process, Air Connect Australia had not explicitly identified CFIT as a hazard nor detailed how it would mitigate the risk.
Based on the FSF CFIT checklist, the ATSB assessed that a single-pilot passenger transport operation involving non-precision approaches to airports without ATC and radar coverage (such as Lockhart River) in IMC carried a significant CFIT risk. Many of the risk-reduction factors listed in the checklist were specific to multi-crew operations and would not be appropriate or viable for a small operator conducting single-pilot operations such as Air Connect Australia. However, the checklist highlighted the CFIT risk for such an operation and provided some ways to mitigate the risk.
The ATSB further assessed Air Connect Australia and the aircraft (VH-OZO) against the suggested risk-reduction factors, as outlined in the following sections.
Section 1 – Company culture
The checklist items included aspects such as the operator placing safety before schedule and placing no negative conations on diversions or missed approaches. The chief pilot advised the ATSB that they often cancelled or postponed flights due to adverse weather. They also stated that they had frequent discussions with the pilot, and they were approachable and open to discussions with the pilot about any safety issues or concerns. Friends of the pilot were not aware of the pilot having any concerns about the chief pilot or the operator and confirmed that the pilot and chief pilot had frequent discussions about operational matters before flights.
Section 2 – Flight standards
The CFIT checklist did not specifically refer to stabilised approach criteria (which were introduced in later FSF guidance material). However, it listed a number of other items. Those potentially applicable to single-pilot operations included:
Reviewing approach or departure plates
Reviewing significant terrain along intended approach or departure course…
Briefing and observing MSA circles on approach charts as part of plate review
Checking crossing altitudes at IAF positions
Checking crossing altitudes at FAF and glideslope centering…
Use of 500-foot altitude call and other enhanced procedures for NPAs…
The operator’s operations manual stated, for all arrivals:
Before descending to an ALA [aircraft landing area], the Pilot-in-Command shall study available charts of the proposed ALA and surrounding area and make a note of hazards indicated on the charts.
The manual also required pilots to check the existing conditions in flight to determine their suitability for the approach and landing (including in terms of the MDA and required visibility on the approach charts). In addition, the manual included a requirement for crew to self-brief prior to the approach and also before landing:
Instrument Approaches – A self-briefing is to be carried out before every landing regarding the intentions of the Pilot-in-Command before / after the commitment point.
…
An emergency self-briefing is to be carried out before the landing regarding:
(a) the intentions of the Pilot-in-Command before / after the commitment point; and
(b) identifying missed approach track or heading.
As previously noted, the flight profile for a straight-in instrument approach also required a pilot to check the altimeter at the FAF. No other checks or altitude calls were explicitly stated.
Section 3 – Hazard awareness and training
The FSF checklist outlined various requirements for CFIT hazard awareness, including:
Your company’s pilots are reviewed annually about the following:
Flight standards operating procedures
Reasons for and examples of how the procedures can detect a CFIT “trap”
Recent and past CFIT incidents/accidents
Audiovisual aids to illustrate CFIT traps
Minimum altitude definitions…
The operator did not conduct formal hazard awareness training and there were no records of any training relating specifically to CFIT. There was no specific regulatory requirement for the operator to conduct such training.[72]
The checklist also included items regarding incident reporting and investigation:
You have an incident/exceedance review and reporting program
Your organization investigates every instance in which minimum terrain clearance has been compromised
The company culture items also referred to fostering a culture where CFIT incidents could be reported. The chief pilot advised they had frequent discussions with the pilot and believed there was a high level of mutual trust, such that that if the pilot had a concern they would feel comfortable coming to talk to the chief pilot about it. However, the chief pilot was not aware of the circumstances associated with the missed approach at Aurukun in January 2020.
The chief pilot advised that the pilot used their own tablet device (iPad) and OzRunways subscription. As a result, the chief pilot did not have access to the recorded data.
Section 4 – Aircraft equipment
The CFIT checklist referred to GPWS, radio altimeter, various types of displays and autopilot functions. The checklist was not up-to-date and not targeted to the needs and potential current opportunities for small aircraft.
As previously noted, VH-OZO was not fitted with a TAWS or radio altimeter, nor were these mandated by the regulatory requirements at the time. The aircraft’s GPS units did not provide vertical guidance for RNAV GNSS approaches and the autopilot was not capable of maintaining a vertical profile without pilot input.
CFIT risk score
Based on the total CFIT risk factors for the destination and risk multipliers, then consideration of the available risk-reduction factors, the total CFIT risk score calculated for the operator was less than zero and indicated a significant CFIT risk. However, as already noted, other operators conducting single-pilot charter flights involving non-precision approaches in IMC to airports without ATC and radar coverage (such as Lockhart River) would also be exposed to a significant CFIT risk as assessed by this checklist.
Safety analysis
Introduction
After conducting an area navigation (RNAV) global navigation satellite system (GNSS) approach to runway 30 at Lockhart River and then a missed approach, the pilot of the Cessna 404 aircraft (VH-OZO) immediately commenced a second RNAV GNSS approach to runway 30. The aircraft’s descent gradient was similar to the first approach but significantly lower than the recommended profile in the approach chart. This descent continued until the aircraft collided with terrain 6.4 km short of the runway.
There was no evidence of any conditions or circumstances likely to induce a medical problem or incapacitation for the pilot, who had been in good health and was well rested. Also, based on the recorded flight data and impact information, the aircraft appeared to be in controlled flight up until the time of the impact. Accordingly, it is very unlikely that the pilot was incapacitated or impaired during the flight.
There was no evidence of any aircraft system or mechanical anomalies that would have influenced the accident. However, as a consequence of extensive aircraft damage, it was not possible to be conclusive about the aircraft’s serviceability.
Therefore, based on the available evidence, the accident was very likely the result of controlled flight into terrain (CFIT). That is, an airworthy aircraft under the control of the pilot was flown unintentionally into terrain, probably with no (or very limited) prior awareness by the pilot of the aircraft’s proximity to terrain.
As evidenced in this case, a CFIT accident generally results in significantly adverse consequences for the occupants of an aircraft, and thus operators conducting operations in instrument meteorological conditions (IMC) or degraded visual conditions need to have robust risk controls to minimise the risk of such accidents.
This analysis considers the weather and sequence of events, followed by the factors that likely influenced the pilot’s performance. It also discusses risk controls for CFIT relevant to this accident.
Weather conditions
The weather conditions at Lockhart River at the time of the 2 approaches were consistent with the forecast, with periods of reduced visibility due to rain and cloud. The conditions had been suitable for the pilot of one aircraft to land about 1 hour prior to the accident and allowed another to land about 30 minutes afterwards.
Although the pilot of VH-OZO had not obtained the latest weather forecast for Lockhart River on the morning prior to the flight using their National Aeronautical Information Processing System (NAIPS) account, they could have obtained the forecast from other sources and they were reportedly aware of the current weather information. In any case, the pilot had ensured the aircraft had sufficient fuel to hold, divert or return to Cairns if necessary.
The landing minima for the runway 30 approach at Lockhart River included a cloud ceiling (for broken cloud or worse) of 730 ft and a visibility of 4,200 m. On arrival at Lockhart River, the pilot listened to the automated weather information service (AWIS) via VHF radio, and received information that the reported conditions were above the landing minima (with 10 km visibility and broken cloud at 1,800 ft).
The conditions recorded by the airport’s automatic weather station (AWS) at the time of the first approach’s final segment (0904–0907) included a visibility of 10 km, some rainfall (0.2 mm at 0904) and nil wind. The visibility was measured in the immediate vicinity of the sensor and may not have reflected the conditions experienced by the pilot during the approach. The recorded cloud base was 1,800 ft, however the recorded values for cloud were averaged over the preceding 30-minute period, and the cloud conditions at any specific time may have been worse than recorded.
Based on a witness report, it appeared as though the conditions at times were probably worse than recorded, with periods of reduced visibility due to cloud and rain. Messages sent by 2 of the passengers at 0914 indicated there was low visibility and one stated there was heavy rain, however it was not clear whether these comments were related to the conditions during the first approach or were observations of the conditions closer to 0914, which was about 7 minutes after the aircraft passed the missed approach point (MAPt).
Therefore, although the AWS observations indicated the weather was above the landing minima, there were areas of reduced visibility in the vicinity of the airport and it was not possible to conclusively determine the actual conditions experienced by the pilot when they reached the MAPt during the first approach.
The recorded visibility deteriorated to 800 m at 0912 and was below the landing minima for most of the period 0911–0917. This aligned with recorded rainfall between 0910–0916, including moderate to heavy rain during 0912–0914. Weather radar images from the Bureau of Meteorology (BoM) also showed rain passing through the Lockhart River area during both approaches, with heavier rain during the second approach. The radar images were consistent with the weather observations by people in the area, including that a ‘wall’ of heavy rain passed through at about the time of the accident. Given the direction the radar returns were moving, it is likely the aircraft entered the rain during the second approach.
In summary, while the pilot was operating in the vicinity of Lockhart River Airport, there were areas of cloud and rain that significantly reduced visibility and increased the risk of CFIT. In particular, the aircraft probably entered areas of significantly reduced visibility during the second approach. As a result of the reduced visibility, the pilot would have been reliant on the aircraft’s flight instruments and GPS units during both approaches.
Conduct of the approaches
First approach and missed approach
On the first approach, the pilot levelled at about 5,000 ft prior to the initial approach fix (IAF), which in this case was LHREB, then established the aircraft on a 3° descent from the IAF. This was consistent with the pilot’s normal method and conformed to the operator’s recommendations and the guidance shown on the approach chart. The pilot conducted the approach consistent with the recommended (3°) constant descent profile, and the aircraft kept descending through the minimum descent altitude (MDA) of 730 ft and passed the missed approach point (MAPt).
There were no significant lateral deviations from the published track, and the indicated airspeed when passing the final approach fix (FAF) was about 130 kt. However, after the FAF, the airspeed increased to about 140 kt, which was sustained throughout the remaining descent. This was significantly in excess of the operator’s preferred airspeed for such approaches (about 110 kt at the FAF), and it also exceeded the applicable handling speed limit specified in the Aeronautical Information Publication (AIP) of 130 kt in the final approach segment.
After passing the MAPt, the aircraft’s recorded descent rate was 900 to 960 ft/min. When the aircraft reached about 400 ft, the pilot initiated a missed approach. The airspeed at that time significantly exceeded the operator’s stabilised approach criteria speed (that is, about 110 kt at 300 ft above aerodrome elevation).
The reason for the non-conforming airspeed on this approach could not be determined. It is possible that this was intentional, and the pilot was expediting the arrival in response to the visible weather. Alternatively, it could have been inadvertent and associated with a focus on other flying tasks in this phase, such as maintaining track (with reduced tolerances) and/or searching for visual cues such as the runway threshold in reduced visibility (see also Awareness of procedural requirements). Whatever the reason, the high airspeed would have made it difficult to configure the aircraft for a stabilised final approach and landing.
Although the descent rate was just within the operator’s limit for a stabilised approach (that is, 1,000 ft/min), it was higher than the 600 ft/min that would be typical for this stage of a final approach. It was also higher than the 750 ft/min that would be commensurate with a 3° profile at 140 kt. Similar to the high airspeed, the reason for the relatively high descent rate could not be determined. It is possible that the pilot was attempting to maintain visual reference.
As previously noted, the weather conditions when the aircraft reached the MAPt could not be determined. It is possible that the conditions were better than the landing minima at that point but then deteriorated as the approach continued and when the aircraft was at a lower altitude.
Irrespective of the conditions, this was not a stable approach due to the relatively high airspeed and a missed approach was necessary. Ultimately, the pilot commenced the missed approach when the aircraft reached about 400 ft. Whether the decision to conduct the missed approach at that time was based on the weather conditions, airspeed, descent rate or some combination of those factors could not be determined.
After initiating the missed approach, the pilot was required to select one of 4 options:
immediately conduct another instrument approach
hold in the area, monitor the weather at Lockhart River and, if suitable, conduct another instrument approach
divert to a nearby airport, monitor the weather at Lockhart River and, if suitable, return for another approach
return to Cairns.
Having descended to 400 ft then overflown the airport during the missed approach, it is expected that the pilot had an appreciation of the low-level weather conditions. Then, during the missed approach, the aircraft tracked initially to the north-west, which was in the direction of weather that was moving towards Lockhart River. Given heavy rain was recorded at the airport about 5–7 minutes after the aircraft had been overhead, the boundary of this rain area may have been visible to the pilot. The rain should also have been displayed on the aircraft’s weather radar display and potentially also the iPad the pilot was using during the flight, although exactly what information was displayed to (or observed by) the pilot could not be determined.
As reported by a passenger in a text message at 0914, at some point during the missed approach or transition to the second approach, the aircraft was in or near heavy rain. Although the AWS between 0911 and 0917 was indicating below-minima weather at the airport, it is unlikely that the pilot had spare capacity to access the AWIS in that period.
Given this context, the pilot may have considered there was a window of opportunity to conduct a second approach before there was heavy rain at the airport and, accordingly, they expedited the second approach.
Second approach – vertical profile
The pilot tracked directly towards the IAF LHREA at 3,500 ft to commence the second approach. After passing the IAF, the aircraft remained at that altitude while heading to the IF. The pilot then commenced descent from 3,500 ft about 2.7 NM prior to the IF. From about 1.6 NM before the IF, the descent was flown at about a normal 3° flight path, although about 1,000 ft below the recommended descent profile. The aircraft descended through the intermediate segment minimum safe altitude of 1,800 ft and passed the FAF at about 1,100 ft. When the aircraft reached a recorded altitude of 700 ft, the descent rate increased from about 700 ft/min to about 1,200 ft/min until the collision with terrain.
The investigation considered 3 main scenarios to explain the vertical profile of the second approach. The first scenario is the pilot misunderstood their position along the approach (or misidentified the waypoints) and believed they were one segment (5 NM) further along the approach than they actually were. Figure 21 shows the vertical profile of the second approach (in red) and it also shows the vertical profile moved 5 NM to the left (in green), as if the pilot thought they were one segment further along the approach. With regard to this scenario:
The scenario does not provide a good explanation of the recorded data as the aircraft remained about 600 ft above the recommended profile for an extended period and there was no indication of any attempt to correct such a perceived problem prior to reaching the perceived MAPt.
The waypoint names on RNAV approaches are similar and there is some potential for confusion. However, in this case the pilot had significant cues to indicate their position along the approach, given they were turning at the IF (10 NM from the MAPt), and they had broadcasted they were at this position just prior to the turn. Although the absence of a subsequent broadcast by the pilot at the FAF (5 NM) could indicate a loss of awareness of the aircraft’s position at that time, it could also have been omitted because the pilot assessed it was unnecessary due to the lack of other aircraft in the vicinity, and/or the pilot was experiencing high workload.
Figure 21: Second approach to runway 30 (red), second approach displaced 5 NM (green) and second approached raised 1,000 ft (yellow)
The second scenario is the pilot believed they were 1,000 ft higher than they actually were during most of the descent. This scenario is shown on Figure 21 (in yellow). With regard to this scenario:
The scenario closely matches the recommended descent profile in terms of commencing the 3° descent at about the right point for a constant descent and then continuing the descent past the IF and FAF.
When the pilot commenced the descent from 3,500 ft, they were correcting the aircraft’s lateral position (right of the initial approach track) and would therefore have been experiencing a high workload. The potential to mis-read instruments (such as an altimeter) is significantly increased under high workload, and the ability to subsequently detect and correct such an error would also be reduced, given that high workload can lead to scanning information sources less frequently and also scanning them for shorter durations.
Just prior to passing the IF, the pilot broadcasted that they were at ‘3,800 correction 2,800 ft’, and this correction was an accurate broadcast of the aircraft’s altitude at the time. This indicated an initial mis-reading of the altimeter, but it also indicated that the pilot had correctly read the altimeter at that time. However, this correction occurred at one point in time for the purpose of making the radio broadcast, and the pilot may not have fully assimilated the information for the purpose of monitoring their descent profile.
The pilot should have been regularly checking the altimeter during the descent as part of their instrument scan, so for this scenario to be viable the pilot would need to mis-read the altimeter multiple times, or at least not detect a problem when scanning the altimeter after an initial error. This would seem unlikely over an extended period. However, as noted before, the pilot may have been scanning instruments less frequently and for shorter durations due to workload. They may also have been focussing more on the vertical speed indicator than the altimeter after commencing the descent.
The aircraft was fitted with a 3-pointer altimeter, which are widely used in small aircraft. Research has shown that pilots can mis-read this type of altimeter, including mis-reading by 1,000 ft, although accidents known to be associated with such errors seem relatively rare.
The scenario does not specifically explain why the descent rate increased in the last 30 seconds of the approach. However, the pilot was probably experiencing a very high workload at that time associated with correcting the aircraft’s lateral position (see Second approach - lateral position). The pilot may also have started increasing the amount of time they were looking outside the aircraft for visual cues, and/or their attention was diverted when entering heavy rain. In addition, heavy rain on a windshield is known to create refraction effects that can lead a pilot to perceive that the aircraft is too high, which can result in an unwarranted nose-down correction and flight below the desired flight path (Flight Safety Foundation 2000).[73]
The third scenario is the pilot intentionally descended below the recommended descent profile and segment minimum safe altitude in order to maximise the chances of becoming visual before reaching the MAPt. For this type of scenario, it is unlikely a pilot would intentionally descend below the MDA before the MAPt unless there were some visual references. With regard to this scenario:
There were no indications in the pilot’s recent RNAV GNSS approaches of descending this early on an approach or descending below segment minimum safe altitudes, although it is acknowledged that the pilot had limited experience with having to conduct a second approach in IMC. There was also no indication that the pilot took unnecessary risks in interviews with other pilots who had flown with the pilot.
Lockhart River is a location widely known to be problematic in terms of the weather conditions and terrain. Although the pilot had flown to Lockhart River on several occasions, as far as could be determined they had not previously encountered IMC at this location before. Nevertheless, given the location’s reputation, it would be reasonable to expect that the pilot would be conducting approaches cautiously and therefore less likely to descend below altitude limits.
If the pilot was intentionally descending early, it is not exactly clear why they would choose to conduct a 3° descent that was about 1,000 ft below the recommended descent profile. However, it is possible the pilot wanted to reach the MDA over water (to ensure more clearance from terrain) and had calculated that such a profile would enable the aircraft to be over water just after reaching the FAF.
There was some indication in the recorded data that the aircraft’s descent rate may have briefly reduced near the MDA, with 3 successive data points recorded at 700 ft. This might be associated with an attempt to level out at about the MDA. Alternatively, the descent rate may have only briefly reduced from 700 ft/min to 500–600 ft/min due to the pilot’s workload and attention been focussed on the aircraft’s lateral position at that time, or due to the pilot’s attention being diverted when they entered heavy rain. It is also possible that the 3 data points at the same level were an artefact of the recorded data and there was no significant change in descent rate.
If the pilot was attempting to level out at about 700 ft, it is unclear why the aircraft kept descending for over 30 seconds after reaching this altitude at a descent rate of 1,200 ft/min. It is possible the pilot did not retrim the aircraft after levelling out and then did not effectively monitor the altimeter due to other tasks, including looking outside to gain visual references.
In summary, following the missed approach, the pilot immediately conducted another approach to the same runway that was on a similar gradient to the recommended descent profile but displaced about 1,000 ft below that profile. While continuing on this descent profile, the aircraft descended below a segment minimum safe altitude and the minimum descent altitude, then kept descending until the collision with terrain about 6 km before the runway threshold.
Based on the available evidence, it is unlikely that the pilot thought they were one segment out on the approach and there was no specific evidence to indicate that the pilot had or would intentionally descend below the recommended descent profile and below a segment minimum safe altitude. Overall, mis-reading the altimeter by 1,000 ft appears to be the most likely scenario, although there was insufficient evidence to provide a definitive conclusion. Regardless of the exact scenario, it is evident from the continued descent that the pilot did not effectively monitor the aircraft’s altitude and descent rate for an extended period.
Second approach - lateral position
The aircraft was just within the capture region for the IAF LHREA when the pilot commenced the turn towards the IF, and it was then initially significantly to the right of the initial approach track. The pilot corrected the aircraft’s heading, but the aircraft was still more than half full-scale deflection on the course deviation indicator (CDI) at the time it started descending from 3,500 ft. The descent was paused soon after and then recommenced, before the IF, with the aircraft within the required half full-scale deflection in order to descend.
Before reaching the IF, the aircraft was close to the initial approach track. The pilot then turned slightly late at the IF and the aircraft was left of the intermediate approach track, reaching about half full-scale deflection on the CDI. The pilot promptly took corrective action, though the aircraft then started deviating to the right of the approach track about 3 NM prior to the FAF. However, the lateral deviation at that stage was less than half full-scale deflection.
Nearing the FAF, the sensitivity of the CDI increased, and when the aircraft passed the FAF it was at about full-scale deflection on the CDI (as presented by the Garmin GNS 430W), and then it exceeded full-scale deflection for about 55 seconds (and was outside half-scale deflection for about 60 seconds). The aircraft’s change of track to the left during the final 30 seconds of the approach suggests the pilot had observed the CDI and attempted to correct the situation, but had then flown through the final approach track and, before a further correction back to the right could be conducted, the aircraft impacted terrain.
Given the aircraft was more than half full-scale deflection on the CDI when it reached the FAF, the pilot was required to conduct a missed approach in accordance with the operator’s stabilised approach procedures. It is acknowledged that the GNS 430W presented full-scale CDI deflection more restrictively than the required navigation performance (RNP) requirements specified in Civil Aviation Order (CAO) 20.91 (that is, 0.23 NM compared to the RNP of 0.3 NM at the FAF). Nevertheless, given that the aircraft’s position was at full-scale deflection (rather than half-scale deflection), this difference should not have affected the pilot’s decision.
In addition, the aircraft was at 0.3 NM lateral displacement shortly after passing the FAF (for about 10 seconds). This would have been displayed to the pilot as more than full-scale CDI deflection, and the lateral displacement distance would also have been displayed on the graphical CDI on the default NAV page of the GNS 430W. Accordingly, the pilot was also required to conduct a missed approach in accordance with the CAO 20.91 requirements at that time.
Finally, with reference to the AIP, the pilot was also required to be within half full-scale deflection on the CDI after passing the FAF before continuing the descent below the previous segment minimum safe altitude (1,800 ft). This should have precluded further descent when passing the FAF (actual altitude 1,100 ft) or soon after (when the actual height was 800 ft and the perceived height may have been 1,800 ft).
It is possible the pilot may not have promptly detected the lateral deviation due to other workload, or they may not have fully realised the extent of the change in the sensitivity of the CDI near the FAF. Alternatively, it is possible that the lateral deviation was due, in part, to the pilot attempting to avoid the most adverse weather.
In summary, the pilot experienced some difficulty controlling the aircraft’s lateral position throughout the second approach. In particular, when passing the FAF and after passing the FAF, the aircraft reached or exceeded the required limits to conduct a missed approach, and a missed approach was not conducted. Regardless of the reason for the lateral deviations, by continuing the approach the pilot significantly increased their workload and the risk of collision with terrain/obstacles.
Second approach - indicated airspeed
The aircraft was at about 135 kt when it passed the FAF, before increasing to 140 kt soon after the FAF. It then increased to 150 kt towards the end of the flight, which was associated with the increased descent rate.
By exceeding the operator’s preferred speed of 110 kt at the FAF, the pilot significantly increased their workload and reduced the time available in the final approach segment to detect and identify other problems with the conduct of the approach (in terms of altitude, descent rate or lateral deviation). More specifically, if the airspeed had been about 110 kt at the FAF, and remained at or below that speed, the pilot would have had over 20 seconds more time prior to the collision to identify problems with the aircraft’s flight path (as well as additional time prior to reaching the FAF). A lower speed would also have made it easier to effectively correct the aircraft’s lateral position.
Unstable approach
Overall, at times during the conduct of the second approach, the pilot appeared to experience difficulty controlling the aircraft’s lateral position, and after passing the FAF they did not effectively control the aircraft’s altitude, descent rate, lateral position and airspeed. As already noted, the approach did not meet the operator’s stabilised approach criteria for lateral deviation at the FAF, and the pilot was required to conduct a missed approach at that point.
In addition, the second approach did not meet the stabilised approach criteria for airspeed (110 kt maximum) or descent rate (1,000 ft/min) at the operator’s applicable height of 300 ft above aerodrome elevation. At this point, the aircraft was travelling at about 150 kt and descending at 1,200 ft/min. However, given that the pilot may have believed the aircraft was 1,000 ft higher than it actually was during the approach, or may have thought they were in level flight near the MDA, they may have not yet considered these stabilised approach criteria.
Factors influencing pilot performance
Introduction
As previously noted, there was no evidence to indicate that the pilot was incapacitated during the accident flight. There was also no evidence to indicate the pilot was experiencing fatigue. The investigation considered a range of other factors that could have influenced the pilot’s performance, including workload, instrument flying proficiency, awareness of procedural requirements, and operational, social or organisational pressures.
Workload and monitoring
Single-pilot operations under the instrument flight rules (IFR), conducting instrument approaches in poor visibility and hand flying an aircraft are all demanding tasks. A pilot needs to be regularly scanning and interpreting the flight instruments, GPS unit (or navigational display) and approach chart, and assimilating the information from multiple sources. As they near the MAPt, they also need to be looking outside to evaluate the visual conditions.
It could not be determined with certainty whether the pilot was using a paper approach chart clamped to the control column and/or was referring to an iPad with the approach chart displayed. Based on the evidence available, it was more likely the pilot was using an iPad, but it was not clear whether it was secured to the control column or if it was on the pilot’s knee. If they were routinely scanning an iPad that was not fixed to the control column, this would have increased the difficulty of the pilot’s scanning and exacerbated the inherent workload associated with the tasks.
Overall, the pilot’s workload on the second approach was elevated throughout the approach compared to the first approach (and other recent instrument approaches conducted by the pilot). Initially the workload was elevated because they joined the approach directly after conducting the missed approach and from just within the capture region of the IAF LHREA. This limited their time to prepare for the approach, and also required more manoeuvring than normal at the IAF.
After turning at the IAF, the pilot’s workload was further elevated by the need to correct the aircraft’s track while also reducing airspeed. As previously noted, it was during this period that the pilot decided to commence the descent from 3,500 ft, which also involved selecting the approach flap and lowering the landing gear soon after.
The pilot’s workload after turning at the IF was also elevated due to the turn being slightly late and then needing to correct the aircraft’s track. This workload would have been significantly elevated after passing the FAF, with the deviation from the final approach track needing more significant correction, as well as due to potentially starting to look more outside the aircraft to assess the visual conditions.
At some point the aircraft probably entered rain, and this would also have increased the pilot’s workload and the difficulty of their task. The presence of rain decreases contrast in the visual environment, making it more difficult to detect terrain features. This effect is exacerbated when approaching or flying over water. In addition, as already discussed, heavy rain on a windshield can lead to a perception of being too high. Light rain can also result in a pilot misperceiving their aircraft to be higher than it is, resulting in a tendency to pitch down (Gibb and others 2010, Flight Safety Foundation 2000b, Previc 2004).
A further factor potentially increasing the difficulty of the pilot’s task after passing the FAF was the increasing sensitivity of the Garmin GNS 430W’s CDI. At and just past the FAF, where a decision to conduct a missed approach should have been made, full-scale deflection on the 430W was not significantly different to the RNP. Towards the MAPt, the 430W was significantly more restrictive than the RNP. The pilot should have been familiar with the system, although the extent to which they fully appreciated the effect of the increasing sensitivity could not be determined.
As previously noted, the omission of the broadcast at 5 NM could be an indication of the pilot’s high workload at that time. In addition, the aircraft’s increased descent rate and speed in the final 30 seconds as the pilot was correcting the lateral deviation is also consistent with the effects of high workload, reducing the ability to monitor and effectively control multiple flight parameters at the same time.
As previously discussed, the pilot’s workload could have been reduced by conducting the approach at a lower airspeed prior to and after the FAF. In addition, there were other available options after conducting the missed approach, including taking more time prior to conducting the second approach and commencing it from another position (for example, tracking further away from the IAF and then approaching it from closer to the centre of its capture region). Alternatively, the pilot could have conducted a holding pattern and waited for the weather to pass before attempting the second approach.
Such options would have provided more time to prepare for the approach and minimise the potential for altitude, descent rate or lateral deviations or other workload problems. These options may also have provided the pilot more opportunity to use the autopilot to reduce their sustained workload prior to initiating the second approach.
Instrument flying proficiency
Many pilots experience some difficulty with developing instrument flying skills and then consistently maintaining those skills. The pilot of the accident flight experienced some difficulties obtaining their initial instrument rating in 2014, and also experienced some difficulties in subsequent instrument proficiency checks (IPCs) in 2016 (underpinning knowledge) and 2017 (mis-reading the altimeter), before passing subsequent assessments. The pilot also experienced significant difficulties in conducting instrument approaches, including the management of multiple flight parameters at the same time, when being assessed in an airline simulator in early 2018, albeit in a much different environment to their previous operations.
The pilot’s last IPC was conducted in August 2019, 7 months prior to the accident, and no problems were noted. However, on that occasion, the Cessna 310 aircraft used for the check was fitted with a navigational system capable of providing vertical guidance for an RNAV GNSS approach. As far as could be determined, the pilot’s instrument flying skills using VH-OZO (a Cessna 404 with GNS 430 GPS units) or similar aircraft had not been observed by the chief pilot or a flight examiner pilot since they were cleared for line operations in October 2018.
Since their last IPC, the pilot had regularly logged RNAV GNSS approaches in VH-OZO and these approaches were generally flown accurately. However, these approaches were almost all conducted in VMC, which would have provided the pilot with cues to identify and correct problems with the aircraft’s position.
The pilot had only conducted one previous approach since the last IPC that potentially encountered IMC for a brief period, at Aurukun on 22 January 2020. This approach was not initiated in the pilot’s normal manner (with a descent from about 5,000 ft at the IAF). In addition, the aircraft reached the MDA 200–300 ft below the recommended descent profile and there were problems with speed control, with the speed after the FAF reaching 145 kt.
Overall, it was difficult to assess the pilot’s instrument flying skills at the time of the accident. Given the limited number of recent RNAV GNSS approaches in IMC or simulated IMC, it is conceivable that the pilot would have experienced significant workload in conducting an approach in IMC, particularly in circumstances where the approach required them to use a different method to normal. They would probably also have had limited ability to manage any additional problems or tasks that occurred during the conduct of an approach in IMC.
Awareness of procedural requirements
The operator’s published flight profile for an RNAV GNSS approach required a Cessna 404 to be at an indicated airspeed of about 90–100 kt at the FAF. However, interviews with the operator’s relevant personnel suggested that the operator’s preferred speed was probably about 110 kt. Given that the one-engine inoperative best rate of climb speed for the aircraft type was 102 kt (flap in the take-off/approach position and gear up), 110 kt was a more appropriate speed at the FAF. The pilot’s approaches routinely exceeded the operator’s preferred speed by a significant margin, with speeds of 130–140 kt being common.
Although the pilot should have been familiar with the contents of the operations manual, it is unclear to what extent they were aware of the flight profile speed or the operator’s preferred speed, and, if they were aware, the extent to which they thought these were reasonable expectations. In other regards, the pilot appeared to be conducting RNAV GNSS approaches in a manner consistent with the chief pilot’s expectations, using a constant descent from about 5,000 ft at the IAF in order to maximise the potential for a stabilised approach.
Having held an instrument rating since 2014, and been subject to many IPCs since then, the pilot should have been aware of the requirement to be to be no faster than 130 kt after the FAF while conducting an RNAV GNSS approach. They should also have been aware of the operator’s requirement to be within half-scale deflection of CDI in the final approach segment.
There were no indications from interviews with various people who flew with the pilot to suggest that the pilot routinely or intentionally deviated from procedural requirements. Given many of the pilot’s previous instrument approaches were conducted in VMC, it is possible the pilot did not consider that some procedural requirements, such as keeping the speed below 130 kt, were essential during such approaches. The pilot may have then become familiar with using such speeds and, when actually conducting approaches in IMC, did not fully recognise the problem. Alternatively, as already discussed, these speed deviations on the approaches in IMC may have been unintentional and were symptoms of high workload and/or limited proficiency.
Operational, social and organisational pressures
Pilots conducting passenger charter flights can experience or perceive a range of social and organisational pressures that can influence the potential to conduct or continue flights in unsuitable conditions (Paletz and others 2009, Michalski and Bearman 2014). These can include not wanting to disappoint customers, reluctance to admit defeat or time-related pressures.
Although such pressures can exist in operational environments, the ATSB identified no evidence to indicate the pilot was subject to any pressure to conduct this flight, complete the flight as quickly as possible, or to deviate from procedural requirements. The chief pilot had previously cancelled flights due to poor weather, but the forecast conditions in this case did not necessitate that the flight be cancelled.
As previously noted, the pilot had ensured the aircraft had sufficient fuel to conduct holding after arrival at Lockhart River, and divert or return to Cairns. They had also conducted holding for an extended period after a missed approach on a previous flight to Aurukun while waiting for a storm to pass, without any apparent negative social or organisational consequences.
As noted above, it is possible that, following the missed approach during the accident flight, the pilot assessed that the weather conditions were worsening and they had limited time to conduct a second approach before a more extensive delay. It is also possible that the pilot was worried about some aspect of the aircraft’s serviceability and did not want to delay the flight further. However, as previously noted, there was no evidence available to indicate a problem with the aircraft’s serviceability.
The pilot had previously commented to a passenger that they would only ever attempt 2 approaches prior to diverting. To what extent this may have placed self-imposed pressure on the pilot on this occasion to continue the approach could not to be determined.
Summary
In summary, the pilot was probably experiencing a very high workload during periods of the second approach. In addition to the normal high workload associated with a single pilot hand flying an approach in IMC, the pilot’s workload was elevated due to conducting an immediate entry into the second approach, conducting the approach in a different manner to their normal method, the need to correct lateral tracking deviations throughout the approach, and higher than appropriate speeds in the final approach segment. The workload was potentially further exacerbated by the pilot having limited recent experience in conducting RNAV GNSS approaches in IMC.
There was no evidence to indicate any organisational or commercial pressures on the pilot to complete the flight, but the extent to which self-imposed pressures or incomplete knowledge of procedural requirements influenced the pilot’s performance could not be reliably determined.
Risk controls for minimising the likelihood of controlled flight into terrain
Introduction
CFIT accidents have been a significant problem over the years, although the rate of such accidents has been decreasing. In Australia, the number of CFIT accidents during instrument approaches decreased from 9 in the 10-year period 1996–2005 and only 1 in the subsequent 15 years (that is, the accident involving VH-OZO at Lockhart River).
This decrease can be attributed, at least in part, to improved instrument approach designs, the increased use of better equipment to display relevant lateral and vertical navigational information, the increased fitment of a terrain warning system (TAWS), and greater use of constant descent angle approaches. However, risk factors still remain, particularly for smaller operators.
Air Connect Australia was a very small operator, with effectively only 2 pilots and one conducting almost all of the operator’s flights. Nevertheless, it conducted passenger transport operations in an aircraft with up to 9 passengers, and multiple factors existed that indicated a significant CFIT risk. These factors included:
single-pilot operations under the IFR
many of the operator’s destination aerodromes were in uncontrolled airspace and outside radar coverage
most of the destination aerodromes offered only non-precision approaches with limited runway lighting systems and without visual approach slope indicating systems
some of the destination aerodromes (such as Lockhart River) were associated with frequent rainfall or adverse weather conditions.
Although the operator had started introducing a safety management system (SMS), it had not developed a formal hazard register and a formalised approach to addressing the risk of hazards such as CFIT. The operator had introduced various measures to manage CFIT risk, such as a flight profile and stabilised approach criteria. However, there were limitations with these and some of the operator’s other risk controls.
Design of the flight profile
The operator’s operations manual included a flight profile for RNAV GNSS and other straight-in runway approaches. Such a flight profile can be an effective way of summarising an operator’s requirements and expectations for pilots regarding how an approach should be conducted.
However, as previously noted, the stated speed on the profile at the FAF (Vref to Vref + 10 kt) was very conservative and unrealistic in most situations. In addition, it did not appear to reflect the expectations of the operator’s key personnel (which equated to Vref + 20 kt or about 110 kt). The flight profile also did not include any requirements or expectations at the IF, which increased the potential for ambiguity.
Design of stabilised approach criteria
An essential and effective means of minimising the risk of CFIT accidents is for an operator to publish clear and relevant stabilised approach criteria, and then ensure that flight crew are aware of and comply with these criteria. Air Connect Australia’s stabilised approach criteria covered relevant parameters and factors, such as airspeed, configuration, descent rate, lateral tracking and briefings/checklists. The chief pilot also reportedly promoted the use of stabilised approaches to the pilot.
However, other than for lateral flight path deviations, the operator’s published criteria had an applicable height of 300 ft above aerodrome elevation for operations in both IMC and VMC. Such a height will have limited effectiveness for non-precision (or 2D) instrument approaches conducted in IMC, particularly given that the MDA for such approaches will often be above 300 ft. An applicable height of 1,000 ft above aerodrome elevation in IMC is widely recommended, including for operations in small aeroplanes. This will enable pilots to ensure that an approach is stable well before reaching the MAPt, reducing workload and maximising the time available to monitor the approach and identify and correct any problems.
The pilot of the accident flight generally appeared to be close to the stabilised approach speed of 110 kt at 300 ft in most of the instrument approaches examined by the ATSB, with 2 main exceptions being the first approach at Aurukun on 22 January and the first approach at Lockhart River, both of which resulted in missed approaches. Based on this information, the pilot appeared to be generally complying with the stabilised approach criteria. Therefore, had the operator specified an applicable height of 1,000 ft in IMC, it seems likely that the pilot would generally have been conducting approaches with a lower speed at this height.
However, it is not clear whether an applicable height of 1,000 ft would have influenced the pilot’s performance and changed the outcome of the second approach on the accident flight. As previously discussed, the exact reasons why the aircraft was descending below the recommended descent profile could not be determined. The pilot may have believed the aircraft was 1,000 ft higher than it was, and therefore thought the aircraft was still above 1,000 ft in the period immediately prior to the collision. Nevertheless, if they were effectively monitoring the flight instruments and complying with the criteria, they should have been slowing down well before reaching an altitude of 1,100 ft (the applicable height at Lockhart River given the aerodrome elevation).
An applicable stabilised approach height of 1,000 ft has been widely recommended by organisations such as the International Civil Aviation Organization (ICAO), the Flight Safety Foundation (FSF) and overseas regulators. However, as of the time of the accident, no formal guidance regarding the content of stabilised approach criteria had been published for Australian operators by the Civil Aviation Safety Authority (CASA). The ATSB has identified a number of Australian operators over the years conducting passenger transport operations under the IFR with applicable heights for all approaches of 300 ft. Accordingly, providing more specific formal guidance in Australia should reduce the likelihood that other operators will use such heights as the reference point for their criteria for all approaches.
It is acknowledged that operators need to tailor stabilised approach criteria to their specific aircraft and operations, and the use of 300 ft may be appropriate for some criteria on some types of approaches. In particular, circling approaches could involve a turn onto final approach at about 500 ft, and therefore cannot meet all stabilised approach criteria until about 300 ft (which is acknowledged in the FSF’s recommended criteria). In addition, it may not be appropriate to select full flap on many smaller aeroplanes until much lower than 1,000 ft on an approach (although other criteria could be met at a different height).
Nevertheless, with greater use of straight-in approaches, all operators should ensure the applicable heights for their stabilised approach criteria are consistent with contemporary guidance where possible for such approaches, particularly for operations in IMC.
Fitment of a terrain avoidance and warning systems
The use of a terrain avoidance and warning system (TAWS) has been shown to significantly reduce the risk of a CFIT. However, VH-OZO was not fitted with a TAWS, nor was one required to be fitted.
Given the aircraft’s descent profile on the second approach, if a TAWS had been fitted and been operational, it would have provided the pilot with both visual and aural alerts of the approaching terrain for an extended period. Accordingly, it is very likely that the accident would not have occurred.
The requirements for a TAWS have been increasing over time. However, the requirements in Australian have lagged behind those in comparable countries, and they were also not consistent with ICAO standards and recommended practices. In Australia there was a requirement for turbine-engine aeroplanes carrying 10 or more passengers on air transport flights under the IFR to be fitted with a TAWS, whereas the ICAO standard required aeroplanes authorised to carry 10 or more passengers to be fitted with a TAWS, regardless of the number of passengers carried on a flight. More importantly:
There was no requirement for piston-engine aeroplanes conducting air transport operations to be fitted with a TAWS, even though this had been an ICAO standard since 2007 for such aeroplanes authorised to carry 10 or more passengers, and this standard had been adopted as a requirement in many comparable countries.
There was no requirement for turbine-engine aeroplanes conducting air transport operations that were authorised to carry 6–9 passengers to be fitted with a TAWS, even though this had been an ICAO recommended practice since 2007, and this recommended practice had been adopted as a requirement in many comparable countries.
CASA had been consulting on applying TAWS requirements to more aircraft since 2008, and had proposed introducing a TAWS requirement for aeroplanes conducting air transport operations (turbine- and piston-engine) with a maximum operational passenger seat configuration (MOPSC) of 6 or more in 2012. However, following consultation with industry, this proposal was amended in 2018 to only require aeroplanes with a MOPSC of 10 or more to be fitted with a TAWS, with the application date being December 2021 or December 2022 depending on various factors.
VH-OZO had 12 seats that could be used by passengers and therefore it had a MOPSC of 12 when used for single-pilot operations. If it remained in that configuration, the operator would have had to have fitted a TAWS to the aircraft by December 2022 and, by December 2024, operated the aircraft under CASR Part 121 (which imposed additional requirements, including 2 pilots for all flights). Given that context, it is likely that an operator in this situation would have chosen to modify such an aircraft so that its MOPSC was 9 or less. Consequently, even if the changes to the TAWS requirements had been introduced in Australia earlier, they probably would not have resulted in an aircraft such as VH-OZO being fitted with a TAWS.
In terms of other comparable countries, only Canada has introduced a requirement for piston-engine aeroplanes with a passenger seating capacity of 6–9 seats to be fitted with a TAWS. However, it is noted that Canada generally experiences more adverse weather conditions than most areas of Australia.
In summary, there was no requirement for VH-OZO to be fitted with a TAWS, and piston-engine aeroplanes with a passenger seating capacity of 6–9 seats were not required to have a TAWS in most comparable countries. Accordingly, it would probably have been difficult to justify mandating that such aeroplanes be fitted with a TAWS in Australia.
Nevertheless, the lessons from the VH-OZO accident (and many previous accidents) are clear: all operators conducting passenger transport operations under the IFR in aircraft that do not currently have a TAWS should recognise the substantial benefits of a TAWS, and be actively seeking to install a TAWS in their aircraft to maximise the safety of their operations.
Use of the GNS 430W terrain awareness function
Although not developed to the same standard and with the same functionality as a TAWS, the Garmin GNS 430W units fitted to VH-OZO had a terrain awareness function that was capable of providing visual pop-up terrain alerts. If the function was selected on, then the system should have displayed a terrain alert to the pilot within the last 30 seconds of the flight (and potentially longer).
However, the terrain awareness function could be inhibited by a pilot, in which case no terrain alerts would be displayed. It could not be determined whether the function was selected or inhibited during the approaches at Lockhart River.
Given the pilot had significant experience using GPS units with a terrain awareness function, it would be expected that they were aware of the function and had seen terrain alerts in the past. However, the investigation could not determine how the pilot normally used the function (that is, whether they normally had it selected on or inhibited).
The Garmin 400W SeriesPilot’s Guide & Reference manual explicitly stated that the system’s terrain awareness function was to be used for supplemental awareness only and was not to be relied upon for terrain avoidance. Nevertheless, although not as effective as a TAWS, the terrain awareness function could still be a valuable tool during instrument approaches in IMC if an operator (and its pilots) had clearly-defined procedures, training and guidance on how to effectively and safely use the function.
For example, an operator could require its pilots to confirm that the function was selected on as part of the descent checklist (particularly when conducting an instrument approach). However, the operator of VH-OZO did not have any explicit procedures or guidance, and this was similar to other operators who used the same type of equipment.
Vertical guidance information
At the time of the accident, the approaches available to the pilot at Lockhart River were RNAV GNSS approaches available for runways 12 and 30, and an NDB approach for runway 30. These were non-precision approaches that did not provide vertical guidance to pilots.
More advanced GPS/navigational systems than the GNS 430W, such as that fitted to the aircraft in which the pilot conducted their most recent IPC, can provide vertical guidance to aid in maintaining the correct vertical profile for a non-precision RNAV GNSS approach.
Vertical guidance information (showing the aircraft’s vertical position during the approach) would have significantly assisted the pilot in maintaining awareness of the aircraft’s vertical position and would have provided a salient indication that the aircraft was dangerously low for an extended period. Having vertical guidance available would also have reduced the pilot’s workload, such as reducing the extent of the mental calculations required to ascertain the aircraft’s position versus altitude and any necessary corrections to the descent rate.
There was no requirement for VH-OZO to be fitted a GPS/navigational system that provided vertical guidance information. However, in the absence of a TAWS, such a system could have significantly reduced the risk of CFIT during instrument approaches.
Monitoring of line operations
The pilot generally conducted instrument approaches in a manner that was consistent with the chief pilot’s preferred method. However, the approaches were also conducted at speeds significantly higher than the operator’s preferred speed. Although they were having regular discussions with the pilot about their flights, the chief pilot had no awareness that this was occurring.
One means of identifying potential problems with the conduct of line operations is through regular proficiency checks. The pilot had not received an operator proficiency check (OPC) since being checked to line in October 2018, and the chief pilot (or the designated flight examiner who could conduct OPCs) had also not flown with the pilot since that time. The pilot had completed an IPC in August 2019, although with a flight examiner who was not familiar with the operator’s procedures and in a different aircraft, with different navigational equipment, than the operator used.
At the time of the accident, there was no specific regulatory requirement for most charter operators to conduct OPCs on their pilots (though pilots conducting IFR operations still needed to undertake an IPC every 12 months). However, as of December 2021, such operators needed to conduct OPCs (or flight crew member proficiency checks) every 6 months.
It is acknowledged that OPCs will not necessarily identify all problems, and pilots may sometimes perform differently when being observed compared to when they are not being observed. However, such checks provide a valuable opportunity for identifying potential misunderstandings regarding the operator’s expectations about how key aspects of flight operations should be conducted.
Another option now readily available to small operators is the use of GPS-based flight data, either through an electronic flight bag application (EFB) or via other sources. Such data may only include some basic flight parameters, which is not as useful as a flight data recorder or other device specifically designed for monitoring flight operations. However, it could still assist with evaluating some aspects of flight operations, including the way instrument approaches are conducted.
Reviewing recorded GPS-based flight data would require a chief pilot or other designated person to be aware of the limitations of the data, and the process would be best done cooperatively with pilots. Nevertheless, the process would not require significant resources and, if done on a regular basis, could help identify potential misunderstandings regarding the operator’s expectations and also provide useful feedback and learning opportunities for pilots.
Hazard awareness training
As stated by the FSF, another useful mitigator for reducing the risk of CFITs is hazard awareness training. The operator had not developed any hazard awareness training material relating to CFIT, and it would be difficult for a small operator to develop a detailed and tailored training program. Nevertheless, various resources from the FSF could be selected and used to provide some guidance information to pilots, together with focussed discussions regarding flight profiles and stabilised approach criteria.
Summary
Ideally, in order to minimise the risk of CFIT, operators conducting passenger transport operations under the IFR would use aircraft fitted with a TAWS and/or have a GPS/navigational system that provides vertical guidance during a non-precision instrument approach. However, without such equipment being a regulatory requirement, it would be difficult for some operators to justify the cost, including in cases where they are leasing the aircraft from another organisation (as was the case with Air Connect Australia).
Nevertheless, there are other means available for such operators to minimise CFIT risk. In this case, the operator had included stabilised approach criteria and flight profiles in its operations manual, and it encouraged the use of stabilised approaches. However, there were problems with the applicable height for the criteria (that is, not 1,000 in IMC) and the flight profile for straight-in approaches did not fully reflect the operator’s requirements or preferences. The operator had also not developed clear procedures and guidance for the use of the terrain awareness function in the aircraft’s 430W GPS/navigational units, and had not conducted regular OPCs or other checks of line operations. Overall, improving these procedural controls would have reduced the operator’s CFIT risk and probably reduced the likelihood of this particular accident.
It is likely that many of these limitations will also exist in other small operators conducting passenger transport operations in small aircraft. Accordingly, this accident has provided many important lessons to such operators regarding ways they can minimise their CFIT risk during IFR operations. These are summarised in the Executive summary.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the controlled flight into terrain involving a Cessna 404 aircraft, registered VH-OZO, which occurred near Lockhart River Airport, Queensland, on 11 March 2020.
Contributing factors
While the pilot was operating in the vicinity of Lockhart River Airport, there were areas of cloud and rain that significantly reduced visibility and increased the risk of controlled flight into terrain. In particular, the aircraft probably entered areas of significantly reduced visibility during the second approach.
After an area navigation (RNAV) global satellite system (GNSS) approach to runway 30 and missed approach, the pilot immediately conducted another approach to the same runway that was on a similar gradient to the recommended descent profile but displaced about 1,000 ft below that profile. While continuing on this descent profile, the aircraft descended below a segment minimum safe altitude and the minimum descent altitude, then kept descending until the collision with terrain about 6 km before the runway threshold.
Although the exact reasons for the aircraft being significantly below the recommended descent profile and the continued descent below the minimum descent altitude could not be determined, it was evident that the pilot did not effectively monitor the aircraft’s altitude and descent rate for an extended period.
When passing the final approach fix (FAF), the aircraft’s lateral position was at about full-scale deflection on the course deviation indicator (CDI), and it then exceeded full-scale deflection for an extended period. In accordance with the operator’s stabilised approach procedures, a missed approach should have been conducted if the aircraft exceeded half full-scale deflection at the FAF, however a missed approach was not conducted.
The pilot was probably experiencing a very high workload during periods of the second approach. In addition to the normal high workload associated with a single pilot hand flying an approach in instrument meteorological conditions, the pilot’s workload was elevated due to conducting an immediate entry into the second approach, conducting the approach in a different manner to their normal method, the need to correct lateral tracking deviations throughout the approach, and higher than appropriate speeds in the final approach segment.
The aircraft was not fitted with a terrain avoidance and warning system (TAWS). Such a system would have provided visual and aural alerts to the pilot of the approaching terrain for an extended period, reducing the risk of controlled flight into terrain.
Although the aircraft was fitted with a GPS/navigational system suitable for an area navigation (RNAV) global satellite system (GNSS) approach and other non-precision approaches, it was not fitted with a system that provided vertical guidance information, which would have explicitly indicated that the aircraft was well below the recommended descent profile.
Although the operator had specified a flight profile for a straight-in approaches and stabilised approach criteria in its operations manual, and encouraged the use of stabilised approaches, there were limitations with the design of these procedures. In addition, there were limitations with other risk controls for minimising the risk of controlled flight into terrain (CFIT), including no procedures or guidance for the use of the terrain awareness function on the aircraft’s GNS 430W GPS/navigational units and limited monitoring of the conduct of line operations. (Safety Issue)
Other factors that increased risk
Although an applicable height of 1,000 ft for stabilised approach criteria in instrument meteorological conditions has been widely recommended by organisations such as the International Civil Aviation Organization for over 20 years, the Civil Aviation Safety Authority had not provided formal guidance information to Australian operators regarding the content of stabilised approach criteria. (Safety issue)
The Australian requirements for installing a terrain avoidance and warning system (TAWS) were less than those of other comparable countries for some types of small aeroplanes conducting air transport operations, and the requirements were not consistent with International Civil Aviation Organization (ICAO) standards and recommended practices. More specifically, although there was a TAWS requirement in Australia for turbine-engine aeroplanes carrying 10 or more passengers under the instrument flight rules:
There was no requirement for piston-engine aeroplanes to be fitted with a TAWS, even though this was an ICAO standard for such aeroplanes authorised to carry 10 or more passengers, and this standard had been adopted as a requirement in many comparable countries.
There was no requirement for turbine-engine aeroplanes authorised to carry 6–9 passengers to be fitted with a TAWS, even though this had been an ICAO recommended practice since 2007, and this recommended practice had been adopted as a requirement in many comparable countries. (Safety Issue)
Other findings
The forecast weather at Lockhart River for the time of the aircraft’s arrival required the pilot to plan for 60 minutes holding or diversion to an alternate aerodrome. The aircraft had sufficient fuel for that purpose; and the aircraft had sufficient fuel to conduct the flight from Cairns to Lockhart River and return, with additional fuel for holding on both sectors if required.
There was no evidence of any organisational or commercial pressure to conduct the flight to Lockhart River or to complete the flight once to commenced.
Based on the available evidence, it is very unlikely that the pilot was incapacitated or impaired during the flight.
There was no evidence of any aircraft system or mechanical anomalies that would have directly influenced the accident. However, as a consequence of extensive aircraft damage, it was not possible to be conclusive about the aircraft’s serviceability.
The aircraft was fitted with Garmin GNS 430W GPS/navigational units that could be configured to provide visual (but not aural) terrain alerts. However, it could not be determined whether the terrain awareness function was selected on during the accident flight.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: Although the operator had specified a flight profile for a straight-in approaches and stabilised approach criteria in its operations manual, and encouraged the use of stabilised approaches, there were limitations with the design of these procedures. In addition, there were limitations with other risk controls for minimising the risk of controlled flight into terrain (CFIT), including no procedures or guidance for the use of the terrain awareness function on the aircraft’s GNS 430W GPS/navigational units, and limited monitoring of the conduct of line operations.
Safety issue description: The Australian requirements for installing a terrain avoidance and warning system (TAWS) were less than those of other comparable countries for some types of small aeroplanes conducting air transport operations, and the requirements were not consistent with International Civil Aviation Organization (ICAO) standards and recommended practices. More specifically, although there was a TAWS requirement in Australia for turbine-engine aeroplanes carrying 10 or more passengers under the instrument flight rules:
There was no requirement for piston-engine aeroplanes to be fitted with a TAWS, even though this was an ICAO standard for such aeroplanes authorised to carry 10 or more passengers, and this standard had been adopted as a requirement in many comparable countries.
There was no requirement for turbine-engine aeroplanes authorised to carry 6–9 passengers to be fitted with a TAWS, even though this had been an ICAO recommended practice since 2007, and this recommended practice had been adopted as a requirement in many comparable countries.
Regulatory guidance for stabilised approach criteria
Safety issue description: Although an applicable height of 1,000 ft for stabilised approach criteria in instrument meteorological conditions has been widely recommended by organisations such as the International Civil Aviation Organization for over 20 years, the Civil Aviation Safety Authority had not provided formal guidance information to Australian operators regarding the content of stabilised approach criteria.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Additional safety action by Aerotrack
The owner of Aerotrack has made a change to the tool to ensure compliance with Civil Aviation Safety Regulation 61.875. As a result, only instrument flight rules (IFR) flights with over 1 hour IFR flight time were included in the calculation of recency, and decimals were not included in the calculation.
A barometric vertical navigation (Baro-VNAV) approach with vertical guidance (APVs) enables a suitably-equipped aircraft’s systems to compute and display a vertical guidance path. Accordingly, they are a 3D instrument approach. Airservices Australia has been implementing Baro-VNAV APV approaches since 2016. After the accident (in December 2020), a Baro-VNAV approach was implemented at Lockhart River (and several other airports in Australia). However, this type of approach requires the aircraft to have a flight management system and VH-OZO was not equipped to conduct a Baro-VNAV approach.
On 2 December 2021, CASR Part 135 (Australian air transport operations – smaller aeroplanes) commenced. Air transport operations included passenger transport operations, regardless of whether they were scheduled or charter operations.
It included a requirement for operators to conduct proficiency checks on pilots, with the requirements for such checks to be specified in the Manual of Standards (MOS). The MOS for Part 135 defined a flight crew member proficiency check as:
… an assessment, conducted by an aeroplane’s operator in accordance with the operator’s exposition, of whether a person is competent to safely carry out the person’s duties as a flight crew member in the aeroplane, which relates to the matters mentioned in subsection 12.05(2).
Standard 12.08 stated:
(3) The flight crew member must successfully undertake the operator’s flight crew member proficiency check, for the relevant type or class of aeroplane, as follows:
(a) for a flight crew member only conducting a flight under the VFR by day — subject to subsections (4) and (5), initially 6 months after first commencing unsupervised line operations for the operator, and then at intervals of 1 year after the previous proficiency check;
(b) otherwise — subject to subsections (4) and (5), initially 6 months after first commencing unsupervised line operations for the operator, and then at intervals of 6 months after the previous proficiency check.
For the 1-year requirement, the check could be done within 90 days of the required date and for the 6-months requirement the check could be done within 30 days of the required date.
The matters specified in 12.05(2) were:
(a) training in the duties and responsibilities for the flight crew member’s position;
(b) training in the standard operating procedures for the type or class of aeroplane used for the flight;
(c) training in the normal, non-normal and emergency procedures for an aeroplane of that type or class;
(d) training in any flight procedures or manoeuvres, conducted in an aeroplane of that type or class, for which the operator holds an approval under regulation 91.045, or 135.020, of CASR;
Note: Examples of approvals issued under regulation 91.045, or 135.020, of CASR include approvals to conduct low visibility operations and flights using certain PBN navigation specifications.
(e) training in the procedures for any other operations conducted by the operator in an aeroplane of that type or class that the flight crew member has not previously experienced, for example, precision runway monitor operations or land and hold short operations.
Glossary
ADS-B Automatic dependent surveillance-broadcast
AFRU Aerodrome frequency response unit
AGL Above ground level
AIP Aviation information publication
AOC Air operator’s certificate
APV Approach with vertical guidance
ATC Air traffic control
AWIS Automated weather information service
AWS Automatic weather station
BARS Basic aviation risk standard (a Flight Safety Foundation program)
BoM Bureau of Meteorology
CASA Civil Aviation Safety Authority
CASR Civil Aviation Safety Regulations
CDI Course deviation indicator
CFIT Controlled flight into terrain
CTAF Common traffic advisory frequency
DETRESFA Distress phase
EFB Electronic flight bag
EST Eastern Standard Time
ETA Estimated time of arrival
FAF Final approach fix
FLTA Forward looking terrain avoidance (a function of the Garmin GNS 430W unit)
FMS Flight management system
FSF Flight Safety Foundation
GAF Graphical area forecast
GNSS Global navigation satellite system
GPS Global positioning system
GPWS Ground proximity warning system
GPWT Grid point wind and temperature chart
HF High frequency
IAF Initial approach fix
ICAO International Civil Aviation Organization
IF Intermediate fix
IFR Instrument flight rules
ILS Instrument landing system
IMC Instrument meteorological conditions
INCERFA Uncertainty phase
IPC Instrument proficiency check
JRCC Joint Rescue Coordination Centre
LCD Liquid crystal display
LNAV Lateral navigation
MAPt Missed approach point
MDA Minimum descent altitude
METAR Meteorological aerodrome report
MOPSC Maximum operational passenger seat configuration
NAIPS National Aeronautical information Processing System
NM Nautical miles
NOTAM Notice to airmen
NPRM Notice of proposed rule making
OPC Operator proficiency check
PDA Premature descent alert (a function of the Garmin GNS 430W unit)
PLB Personal locator beacon
POH Pilot’s operating handbook
QNH That pressure setting which, when placed on the pressure setting sub‑scale of a sensitive altimeter of an aircraft located at the reference point of an aerodrome, will cause the altimeter to indicate the vertical displacement of the reference point above mean sea level.
RAIM Receiver autonomous integrity monitoring
RNAV Area navigation
RNP Required navigation performance
SIGMET Significant meteorological information
SMS Safety management system
SPFIB Specific pre-flight information bulletin
TAF Aerodrome forecast
TAWS Terrain avoidance and warning system
VFR Visual flight rules
VHF Very high frequency
VMC Visual meteorological conditions
VNAV Vertical navigation
Vref Reference landing speed
VSI Vertical speed indicator
Sources and submissions
Sources of information
The sources of information during the investigation included the:
operator/chief pilot of Air Connect Australia
aircraft owner and maintainer for VH-OZO
GPS unit manufacturer (Garmin)
Civil Aviation Safety Authority
Queensland Police Service
Airservices Australia
Bureau of Meteorology
OzRunways flight data.
References
Arthur W, Bennett W, Stanush PL and McNelly TL (1998) ‘Factors that influence skill decay and retention: A quantitative review and analysis’, Human Performance, 11:57-101.
Civil Aviation Authority (2013) Monitoring matters: guidance on the development of pilot monitoring skills, CAA Paper 2013/02.
Dismukes RK, Berman BA & Loukopoulos LD (2007) The limits of expertise: Rethinking pilot error and the causes of airline accidents, Ashgate, Aldershot UK.
Enders JH, Dodd R, Tarrel R, Khatwa R, Roelen ALC & Karwal AK (1996) Airport safety: a study of accident and available approach-and-landing aids, Flight Safety Foundation, Flight Safety Digest, 15(3).
European Union Agency Safety Agency (2021), Safety issue report – Skills and knowledge degradation due to lack of recent practice, downloaded from www.easa.europa.eu.
Federal Aviation Administration (2012) Instrument flying handbook, FAA-H-8083-15B
Gibbs R, Gray R & Scharff L (2010) Aviation visual perception: Research, misperception and mishaps, Ashgate, Aldershot UK.
Godley ST (2006) Perceived pilot workload and perceived safety of RNAV (GNSS) approaches, Australian Transport Safety Bureau.
Hoekstra HD, Perry EB & Huang S (1972) Altimetry display study Part 2 – Analysis of altitude accidents, Report No. FAA-RD-72-46 II, prepared by the Flight Safety Foundation for the US Department of Transportation, Federal Aviation Administration.
Holmes S, Bunting A, Brown D, Hiatt K, Braithwaite M & Harrigan M (2003) ‘Survey of spatial disorientation in military pilots and navigators’, Aviation, Space, and Environmental Medicine, 74:957-965.
International Air Transport Association (IATA) (2018) Controlled flight into terrain accident analysis report 2008–2017 data, Montreal, Canada
Kelly D & Efthymiou M (2019) ‘An analysis of human factors in fifty controlled flight into terrain aviation accidents from 2007 to 2017’, Journal of Safety Research, 69:155-165.
Michalski DJ & Bearman C (2014) ‘Factors affecting the decision making of pilots who fly in Outback Australia’, Safety Science, 68:288-293.
Mitchell TR (1972) Altimetry display study Part 1 – Summary report, Report No. FAA-RD-72-46 I, prepared by The Mitre Corporation for the US Department of Transportation, Federal Aviation Administration.
Orlady HW & Orlady LM (1999) Human factors in multi crew operations, Ashgate, Aldershot, UK.
Paletz SBF, Bearman C, Orasanau J & Holbrook J (2009) ‘Socializing the human factors analysis and classification system: Incorporating social psychological phenomena into a human factors error classification system’, Human Factors, 51:435-445.
Previc FH (2004) ‘Visual illusions in flight’, in FH Previc & R Ercoline (Eds) Spatial disorientation in aviation, American Institute of Aeronautics and Astronautics, Reston VA.
Sanli EA and Carnahan H (2018) ‘Long-term retention of skills in multi-day training contexts: A review of the literature’, Industrial Journal of Ergonomics, 66:10–17.
Shrager JJ (1972) Altimetry display study Part 3 – Review of R&D on display readability, Report No. FAA-RD-72-46 III, prepared by the Navigational Aviation Facilities Experimental Center for the US Department of Transportation, Federal Aviation Administration.
Staal MA (2004) Stress, cognition, and human performance: A literature review and conceptual framework, National Aeronautics and Space Administration Technical Memorandum NASA/TM-2004-212824.
Vlasblom JID, Pennings HJM, Van der Pal J and Oprins EAPB (2020) ‘Competence retention in safety-critical professions: A systematic literature review’, Educational Research Review, 30:10.1016.
Wickens CD, Hollands JG, Banbury S & Parasuraman R (2013) Engineering psychology and human performance, 4th edition, Pearson Boston, MA.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the aircraft operator
the aircraft owner/maintainer
the Civil Aviation Safety Authority
Airservices Australia
Bureau of Meteorology
Aerotrack
United States National Transportation Safety Board
the aircraft manufacturer
Garmin.
Submissions were received from:
the aircraft operator
the Civil Aviation Safety Authority
Bureau of Meteorology
Garmin.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Appendices
Appendix A – Research and guidance regarding design of altimeters
Civil Aviation Order (CAO) 20.18 (Aircraft equipment — basic operational requirements) required that aeroplanes engaged in passenger charter operations under the instrument flight rules (IFR) be equipped with 2 sensitive pressure altimeters. As already noted in Aircraft instruments, VH‑OZO was fitted with two 3-pointer altimeters that met this requirement.
A series of research studies have compared the effectiveness different types of altimeter display. In summarising the research from 1960 to 1972 for the United States Federal Aviation Administration (FAA), Shrager (1972) concluded:
3. Comparative laboratory, simulator, and flight tests of 3P [3-pointer], DP [drum-pointer], CP counter-pointer], and CDP [counter drum pointer] altimeter displays[76] indicate that the least preferred was the 3P and the most desirable was the CDP by subject opinion. This order of ranking is most pronounced when the subjects used were pilots as opposed to nonpilots. The subjective display preference was further accentuated when random dynamic changes in altitude and secondary tasks were introduced into the experiment.
4. The 3P display required the longest time to interpret and produced the largest number of errors among all the production-type displays evaluated. The misreading errors included both those of l,000- and 10,000-foot altitudes. The experimental test results have been supported by significant actual flight experiences on the part of both the military and commercial aviation.[77]
5. A majority of the air carriers and the military have or are converting to displays other than the 3P. The principal display selected has been the CDP.
6. The most prevalent type of altimeter display in general aviation is the 3P. The 10,000-foot error of the 3P display has not been supported by significant actual flight experience by general aviation. However, the 1,000-foot error is a problem in the 3P display.
As part of a related research program, Hoekstra and others (1972) reviewed civil and military accidents during 1964–1970. They noted that problems with misreading an altimeter were cited in a small number of accident investigation reports. For the examples provided, where the type of altimeter was stated or otherwise known, the majority involved 3-pointer altimeters. This study also conducted a survey of various organisations. Its conclusions included:
1. Official investigations have cited altimetry as a causal factor in approximately 1% of all accidents; considering accidents of unknown causes and those where altimetry could possibly have been a factor, it is estimated that altimetry contributes to a maximum of 3% of all accidents. This estimate includes mechanical malfunctions and human errors.
2. Ten to twenty percent of all accidents are "altitude-related" as they involve altitude displacement for some reason.
3. "Altitude-related" accidents occur more frequently in conditions where it is difficult to see the terrain, i.e., at night and in restricted visibility.
4. The majority of "altitude-related" accidents occur during the landing approach. Most are without benefit of vertical guidance from any source other than the altimeter and pilot visual contact with the terrain.
5. Although a few accidents occurred in landing approaches where precision aids were used, they were characterized by a deviation from the glide path after the pilot gained visual contact.
6. Survey comments indicated that the three-pointer altimeter is susceptible to frequent misreading by 1,000 or 10,000 feet, but the number of accidents known to have been caused or possibly could have been caused, by this type of misreading was small. However, several incidents of misreading were reported.
7. Small improvements in the accident rate could be achieved by improving altimetry display, static/pitot systems and setting procedures, but greater improvement would result from the provision of more precision aids and visual warning systems in the ground environment.
A report summarising the FAA research program (Mitchell 1972) concluded that retrofitting of aircraft was not justified. However, it recommended that an advisory circular should be distributed, suggesting that all 3-pointer and drum-pointer altimeters be replaced with counter-drum pointer altimeters where feasible, and that counter-drum pointer altimeters should be required for all yet-to-be-constructed transport category aircraft and more expensive general aviation aircraft.
In 1991, the Flight Safety Foundation launched a campaign to reduce the number of controlled flight into terrain (CFIT) accidents and, together with other organisations, it formed a task force. As part of its work, the FSF CFIT task force made 8 recommendations to the International Civil Aviation Organization (ICAO), including a warning against the use of 3-pointer and drum-pointer altimeters.
ICAO Annex 6 (Operation of Aircraft) Part I (International Commercial Air Transport – Aeroplanes) paragraph 6.9.1 required that aeroplanes operated in accordance with IFR (for commercial air transport) be equipped with 2 sensitive pressure altimeters. Since 1998, it also required that these altimeters have ‘counter drum-pointer or equivalent presentation’. A note under this requirement stated that 3-pointer or drum-pointer altimeters did not satisfy this requirement.[78]
All modern transport aircraft are equipped with vertical altimeter displays or, for some older transport aircraft, counter-drum pointer altimeters. However, 3-pointer altimeters are still very common in general aviation aircraft, including small aeroplanes used for passenger transport activities.
Several experienced pilots interviewed by the ATSB during the investigation reported that misreading a 3-pointer altimeter is more commonly seen in pilots undergoing initial instrument training.
Appendix B – Vacuum system analysis
System overview
VH-OZO had 2 artificial horizon (attitude indicator) instruments and one directional gyro instrument that were powered through hoses connected to a common manifold with 2 sources of power from a vacuum pump on each engine, controlled by in-line regulators. An analogue suction indicator (vacuum gauge) located on the lower left pilot-side instrument panel showed the pilot the net amount of suction at the manifold and ‘dolls eye’ indicators showed if each vacuum pump was operating or not.
Maintenance history
Both artificial horizon instruments and directional gyro instrument as well as vacuum regulators were not subject to service life or maintenance requirements, other than regulator garter filter changes that were being carried out. According to a service bulletin issued by the manufacturer of the vacuum pumps, the vanes could be inspected through a wear indicator port and it recommended the pump be replaced at the wear limit.
The left vacuum pump had been in service for about 1,076 hours and the right for about 911 hours, which exceeded the life of the previous pumps (711 hours and 880 hours respectively). The previous pumps were replaced due to failing in service rather than due to wear. Inspection of pump wear through a port was not carried out consistently by the aircraft maintainer and it is unlikely it was conducted at the previous periodic inspection.
The ATSB identified that the vacuum system manifold had not been tested in the previous 5 years or replaced in the previous 10 years, as specified by the component manufacturer. This was due to an oversight in the maintenance tracking system that was subsequently rectified. A search of the aircraft logbooks did not identify any recorded replacement of the manifold and markings that might indicate component life were indistinct.
Pilots and engineers can carry out an informal test of the manifold by alternating the engine that is started (and/or shut down) first and verifying that either vacuum pump by itself can maintain adequate supply. This was not noted at the recent 100-hour inspection and it is not known if the pilot routinely monitored the operation of each vacuum pump at engine start or shutdown. Damage sustained in the accident prevented functional testing and examination of the internal condition of the manifold.
Although the vacuum manifold was outside its specified service life and its condition could not be verified, if there was an age-related defect there was no effect on aircraft operation unless one of the vacuum pumps failed.
Post-accident inspection
Both vacuum pumps were recovered from the aircraft after the accident and examined.
The right vacuum pump showed evidence of casing deformation and damage consistent with a heavy impact sustained during the accident sequence. When the right vacuum pump was removed from the engine the drive shaft was observed to have sheared. An accurate wear measurement could not be ascertained due to internal damage within the unit. Inspection of the internal components indicated that the pump vanes were intact, and the carbon block had fractured. The support pin had also failed in overload. Inspection of the frangible drive shaft showed damage indicative of overload. Further examination of the frangible shaft fracture surface under a microscope did not identify any features indicative of surface-to-surface rotation contact that may be possible when the engine is running and the pump is seized. Post-accident examination concluded that it was highly likely the pump failed due to the impact with terrain.
The left vacuum pump showed no sign of external damage and the drive shaft was intact. The pump did not show any signs of accident damage. An accurate wear measurement could not be conducted because the pump did not have an inspection port. Inspection of the internal components indicated that the pump vanes and carbon block were intact. The pump internal components were rotated and observed to work as designed. There were no pre- or post-impact defects identified within the left vacuum pump that would make it incapable of supplying pressure as required.
The left artificial horizon instrument and directional guidance instrument were recovered from the aircraft after the accident, disassembled and examined. The left artificial horizon instrument was significantly damaged, however detailed examination of the components did not identify any pre-impact defects. Rotational scoring was noted between the rotor, the casing and the end cap with metal transfer evident (Figure 22). This indicates that the rotor was rotating with significant speed, highly likely produced by suction from the vacuum pump(s), when the aircraft impacted with terrain.
The directional gyro instrument was significantly damaged, with detailed examination producing no identified pre-impact defects with the components that were available for inspection. There was evidence of rotational scoring on the rotor case end and the rotor end. There was no scoring evidence in the rotor case. The rotational scoring indicates that the directional gyro was rotating at significant speed, highly likely produced by suction from the vacuum pump(s), when the aircraft impacted with terrain.
Appendix C – Detailed 1-minute weather data Lockhart River 0850–0930
Appendix D – Guidance to industry regarding stabilised approaches
Overview
This appendix provides examples of guidance provided regarding stabilised approach criteria for flight operations in addition to that provided by the Flight Safety Foundation.
Transport Canada guidance
Transport Canada’s Advisory Circular AC700-028 (Vertical path control on non-precision approaches, issued 2013) was applicable to all flight crew and types of operations. It was issued in 2013, at the same time that NAV CANADA introduced non-precision approach (NPA) charts with constant descent angles. In terms of stabilised approaches, the AC stated:
Many air operators require their crews to use a stabilized approach technique which is entirely different from that envisaged in the original NPA procedure design. A stabilized approach is calculated to achieve a constant rate of descent at an approximate 3° flight path angle; with stable airspeed, power setting, and attitude; and with the aircraft configured for landing. The safety benefits derived from a stabilized final approach have been recognized by many organizations including ICAO, the Federal Aviation Administration, and Transport Canada Civil Aviation (TCCA). Those air operators not already doing so are encouraged to incorporate stabilized approach criteria into their Standard Operating Procedures (SOPs) and training syllabi.
With regard to reference points for stabilised approach criteria, the AC stated:
Stabilized approach criteria should be defined for all approaches and may include:
that flights shall be stabilized by no lower than 1,000 feet (ft.) above the threshold when in instrument meteorological conditions (IMC);
that all flights shall be stabilized by no lower than 500 ft. above the threshold;
that the flight remain stabilized until landing
that if an approach is not stabilized in accordance with these requirements, or has become destabilized afterwards, a go-around is required.[79]
The AC also provided detailed comments regarding step-down versus constant descent angle approach techniques. It noted that step-down techniques were inherently unstable and resulted in higher workload. They also resulted in inconsistent rates of descent and at times high rates of descent, and also extended periods with the aircraft flown at minimum safe altitudes. In contrast, constant descent angle approaches were inherently stable and associated with lighter workload.
In 2015, Transport Canada also issued a Civil Aviation Safety Alert 2015-04 (Stabilized approach) for all commercial air operators (including airline, commuter, air taxi and aerial work). It reiterated the key points of the AC, and noted that:
Rushed and unstabilized approaches remain a significant factor in Controlled Flight Into Terrain (CFIT) and other Approach-and-Landing Accidents (ALA). The safety benefits derived from a stabilized final approach have been recognized by many organizations including ICAO, the FAA, EASA and TCCA. These benefits include:
Increased flight crew situational awareness;
More time and attention for monitoring ATC communications, weather conditions and systems operation;
More time and attention for flight path and energy monitoring;
Defined flight parameter deviation limits and minimum stabilization heights to support the decision to land or to go-around; and,
Landing performance consistent with expected performance values.
It also stated:
Stabilized approach criteria should be defined for all approaches and should include that:
Approaches be stabilized by no lower than 1,000 feet (ft) above aerodrome elevation (AAE) when in instrument meteorological conditions (IMC);
All approaches be stabilized by no lower than 500 ft AAE in visual meteorological conditions (VMC);
A call be made upon reaching 1000 ft AAE in IMC or 500 ft AAE in VMC as to whether the approach is stabilized or not;
The approach remain stabilized until landing;
If an approach is not stabilized in accordance with these requirements, or has become destabilized afterwards, a go-around is required.
Federal Aviation Administration guidance
The United States Federal Aviation Administration issued guidance for general aviation pilots regarding CFIT in Advisory Circular AC 61-134 (General aviation controlled flight into terrain awareness), issued in 2003. The background section stated:
According to FAA information, general aviation CFIT accidents account for 17 percent of all general aviation fatalities. More than half of these CFIT accidents occurred during IMC…
Because a single-piloted, small GA aircraft is vulnerable to the same CFIT risks as a crewed aircraft but with only one pilot to perform all of the flight and decision-making duties, that pilot must be better prepared to avoid a CFIT type accident…
Under a section regarding GA operations in IMC on an IFR flight, the AC stated:
These operations also pose special risks. Whether it is failure to follow safe takeoff and departure techniques, recommended en route procedures ― which includes loss of situational awareness ― or failure to maneuver safely to a landing, IFR operations can be dangerous for those not prepared to operate or not current and proficient in the IMC and IFR environments. Many of these accidents result in fatalities. Techniques or suggestions for avoiding some of these IFR risk factors include…
s. The importance of flying a stabilized approach. A common definition of a stabilized approach is maintaining a stable speed, descent rate, vertical flightpath, and configuration throughout the final segment of the approach. Although originally designed for turbojet aircraft, a stabilized approach is also recommended for propeller-driven aircraft. The idea is to reduce pilot workload and aircraft configuration changes during the critical final approach segment of an approach. The goal is to have the aircraft in the proper landing configuration, at the proper approach speed, and on the proper flightpath before descending below the minimum stabilized approach height. The following are recommended minimum stabilized approach heights.
(1) 500 feet above the airport elevation during VFR weather conditions.
(2) MDA or 500 feet above airport elevation, whichever is lower, for a circling approach.
(3) 1,000 feet above the airport or touch down zone elevation during IMC.
In 2011, the United States Federal Aviation Administration (FAA) issued AC 120-108 (Continuous descent final approach), providing guidance for operators on the continuous descent final approach technique for NPAs. The AC was intended for airline and air taxi operators, though it noted the guidance was beneficial to all operators. The background section stated:
Controlled flight into terrain (CFIT) is a primary cause of worldwide commercial aviation fatal accidents. Unstabilized approaches are a key contributor to CFIT events. Present NPAs are designed with and without stepdown fixes in the final approach segment. Stepdowns flown without a constant descent will require multiple thrust, pitch, and altitude adjustments inside the final approach fix (FAF). These adjustments increase pilot workload and potential errors during a critical phase of flight. NPAs designed without stepdown fixes in the final segment allow pilots to immediately descend to the MDA after crossing the FAF. In both cases, the aircraft remains at the MDA until descending for the runway or reaching the missed approach point (MAP). This practice, commonly referred to as “dive and drive,” can result in extended level flight as low as 250 feet above the ground in instrument meteorological conditions (IMC) and shallow or steep final approaches.
In terms of stabilised approaches, the AC 120-08 stated:
A stabilized approach is a key feature to a safe approach and landing. Operators are encouraged by the FAA and the International Civil Aviation Organization (ICAO) to use the stabilized approach concept to help eliminate CFIT. The stabilized approach concept is characterized by maintaining a stable approach speed, descent rate, vertical flightpath, and configuration to the landing touchdown point. Depart the FAF configured for landing and on the proper approach speed, power setting, and flightpath before descending below the minimum stabilized approach height; e.g., 1,000 feet above the airport elevation and at a rate of descent no greater than 1,000 feet per minute (fpm), unless specifically briefed. (Refer to AC120-71.)
The FAA also issued guidance regarding stabilised approaches in AC 91-79A (Mitigating the risks of a runway overrun upon landing), issued in 2014 and last updated in 2018. The intended audience was all pilots, flight crew and operators. The AC stated in part:
Stabilized on Profile. The airplane should be stabilized on profile before descending through the 1,000-ft window or through the 500 ft above touchdown zone elevation (TDZE) window in visual meteorological conditions (VMC). Configuration, trim, speed, and glidepath should be at or near the optimum parameters early in the approach to avoid distractions and conflicts as the airplane nears the threshold window. The electronic or visual glidepath or an optimum glidepath angle of 3 degrees should be established and maintained…
Indicated Airspeed. Indicated airspeed should be not more than VREF + 5 or the POH published approach airspeed, with appropriate adjustments for wind or other factors, and never less than VREF or the appropriate airspeed in order to avoid the loss of aircraft control.
United States Aircraft Owners and Pilots Association
The United States Aircraft Owners and Pilots Association (AOPA) stated in a 2000 article (The stabilized approach):
Most of us don’t have to worry about the vagaries of turbine aircraft and their response to power and speed changes on approach. But there are plenty of good reasons to fly stabilized approaches regardless of whether you fly a Cessna Skyhawk or Golden Eagle, Beech King Air or Piper Super Cub. Here are a few:
It reduces workload…
It gives us more opportunity to see the big picture…
It slows the aircraft down earlier, allowing more time to think…
It allows more time to react...
It makes it easier to fly the VOR, ILS, or ADF needles...
It allows the pilot more opportunity to detect changes in the wind on approach…
It reduces the variables and thus reduces our required reactions to these changes. When you have the airspeed nailed early, you have one less variable to worry about, freeing you to focus on other things. If we can set the power and mostly forget it, we don't have to constantly change power in response to our configuration and speed changes.
It creates the time to finish your before-landing checklist and to really look around the airplane for other things you might have missed or neglected when rushed...
It makes the approach—and thus the landing spot—predictable because you do it the same every time.
Notice that time is the major benefit when we fly a stabilized approach. Time allows us to more easily perceive changes and then make corrections to course, altitude, or airplane management.
Most airlines set the stabilized approach point at 500 feet in visual conditions and 1,000 feet when the weather is IMC. These 500- and 1,000-foot target points might be a good starting place when establishing your own stabilized approach minimums. You might also want to use 1,000 feet for night approaches and landings because the fewer visual cues at night reduce your ability to perceive differences and changes.
Appendix E – Aurukun incident flight – 22 January 2020
Introduction
On 22 January 2020, on a flight from Weipa to Aurukun, the pilot conducted 2 RNAV (GNSS) approaches to runway 34 at Aurukun in VH-OZO, with the first approach followed by a missed approach.
An extract of the relevant Airservices Australia approach chart is depicted in Figure 23. As indicated in the chart, the recommended initial approach altitude was 1,800 ft, with the recommended 3° approach profile to the runway threshold commencing just prior to the final approach fix (FAF). The minimum descent altitude (MDA) for a pilot with an actual QNH was 450 ft.
The ATSB analysed OzRunways GPS data from the 2 approaches and the missed approach (Figure 24). The data was recorded at 5-second intervals. Recorded altitude, lateral position and groundspeed data for the 2 approaches from the initial approach fix (IAF) to the missed approach point (MAPt) is shown in Figure 25.
The recorded altitudes were slightly below the recommended approach profile during the 2 approaches. Aurukun Airport has an elevation of about 30 ft above sea level, and one of the passengers recalled observing the altimeter reading 50–100 ft when the aircraft was on the ground after landing. This indicated the QNH set on the altimeter may not have accurately reflected the actual QNH when the aircraft landed,[80] and the altimeter may have been slightly overreading during the approaches. In addition, the recorded altitude data was truncated to the nearest 100 ft.
Figure 23: Extract of the Aurukun RNAV (GNSS) RWY 34 approach
Source: Airservices Australia, annotated by the ATSB
Figure 24: VH-OZO recorded data 22 January 2020 at Aurukun, Queensland
Source: Google Earth overlaid with OzRunways data, annotated by the ATSB
First approach
The data showed that the aircraft approached from the north and about 1,100 ft and overflew the runway 34 threshold before continuing to track south. After passing about 3 NM west of the initial approach fix (IAF) AURSB at 1,500 ft, the aircraft turned 180° then passed 1 NM to the west of the IAF and then tracked direct towards the intermediate fix (IF) AURSI at 1,500 ft. About 1 NM prior to AURSI, the aircraft climbed to 1,700 ft and passed over the IF.
The aircraft was at 1,600 ft when it reached the FAF AURSF, and it then commenced the descent on about a 3° profile (Figure 25). The aircraft was about 200–300 ft below the recommended 3° descent profile when it reached the MDA, about 1.8 NM prior to the MAPt AURSM. The minimum recorded altitude the aircraft descended to (1 data point) was 200 ft when 1.2 NM prior to the MAPt, and it was at a recorded altitude of 200–300 ft over 4 data points (15–20 seconds) prior to reaching the MAPt.
Figure 25: Recorded data for 2 RNAV approaches to Aurukun 22 January 2020
Source: ATSB
The descent rate from the FAF (recorded height 1,600 ft) until the aircraft reached 900 ft was about 650 ft/min, and the descent rate for the remainder of the descent was about 1,050 ft/min.
A review of wind and temperature forecast and analysis charts from multiple sources and other information indicated that the indicated airspeeds would have been about 5 kt higher than the recorded groundspeeds during the 2 approaches while the aircraft was on or near the intermediate/final approach track. Therefore, on the first approach the indicated airspeed was about 140 kt when the aircraft passed the FAF, about 145 kt when the aircraft passed through the MDA and about 140 kt when the aircraft reached a height of 300 ft above aerodrome elevation.
Missed approach
A missed approach was commenced prior to the MAPt, with the aircraft climbing and passing 0.2 NM to the right of the MAPt. The aircraft passed over the Aurukun township at an altitude of about 800 ft, then turned left and heading south, climbing to 1,900 ft.
The published missed approach commenced at AURSM and required the aircraft to maintain runway direction for 3 NM before turning left to heading 170° and climbing to 1,700 ft. Based on witness reports, it is possible that the pilot was avoiding a nearby thunderstorm during the missed approach and/or was in visual conditions at the time.
The exact reasons for the missed approach could not be determined (that is, whether it was due only to reduced visibility of the runway at the time or also due to the aircraft’s speed not meeting the operator’s stabilised approach criteria at 300 ft above aerodrome elevation).
Second approach
The aircraft then headed south to about 8 NM south-south west of AURSB, before turning back to the IAF and then doing a holding pattern before again approaching the IAF. The pilot then commenced a second RNAV approach about 31 minutes after the first approach from an altitude of about 1,900 ft. The aircraft was close to the published descent profile throughout the approach and also within the required lateral tolerances.
Given the indicated airspeeds were about 5 kt higher than the recorded groundspeeds, the indicated airspeeds were 135 kt at the FAF and 105 kt at 300 ft above aerodrome elevation. Overall, the approach appeared to comply with the operator’s stabilised approach criteria.
Appendix F – Related occurrences
Collision with Terrain involving Fairchild Metro 23 aircraft, VH-TFU, 11 km north-west of Lockhart River Airport, Queensland, on 7 May 2005
On 7 May 2005, a Fairchild Aircraft Inc. SA227-DC Metro 23 turbo-prop aircraft, registered VH-TFU, with 2 pilots and 13 passengers, was being operated on an instrument flight rules (IFR) regular public transport service from Bamaga to Cairns, with an intermediate stop at Lockhart River, Queensland. At 1143:39 local time, the aircraft impacted terrain 11 km north-west of the Lockhart River Airport. At the time of the accident, the crew was conducting an area navigation global navigation satellite system (RNAV GNSS) non-precision approach to runway 12. The occupants were fatally injured and the aircraft was destroyed.
The accident was almost certainly the result of a controlled flight into terrain. Weather conditions in the Lockhart River area were poor and necessitated the conduct of an instrument approach procedure for an intended landing at the aerodrome. The cloud base was probably between 500 ft and 1,000 ft above mean sea level and the terrain to the west of the aerodrome, beneath the runway 12 RNAV GNSS approach, was probably obscured by cloud.
The investigated identified a significant number of contributing factors and other safety factors associated with the crew’s performance, local conditions, the operator’s procedures and regulatory oversight. With relevance to the findings of the 2020 accident involving VH-OZO, these included the aircraft descending below the segment minimum safe altitude for the aircraft’s position on the approach (after passing the final approach fix) and the speeds and descent rate exceeding those appropriate for a stabilised approach. The operator’s procedures did not provide clear guidance on approach speeds, when to select aircraft configuration changes during an approach and clear criteria for a stabilised approach. There were also problems with the operator’s processes for supervising the standard of flight operations, and the operator did not have a structured process for managing safety-related risks.
The aircraft was fitted with a ground proximity warning system (GPWS), but there would have been insufficient time for the crew to effectively respond to the GPWS alert and warnings that were probably annunciated during the final 5 seconds prior to impact with terrain. The aircraft was not fitted with a terrain avoidance and warning system (TAWS).
The GPS unit fitted to the aircraft (Garmin GPS 155XL) also had several limitations compared with more recent models available at the time. These included the limited usefulness of the moving map display because of the vertical size of the screen size, the lack of an option to display a distance to the missed approach point (MAPt) throughout the approach, and the lack of any form of vertical advisory guidance.
Additional CFIT investigations in Australia
The ATSB has investigated a number of other CFIT accidents in Australia, all involving aircraft that were not fitted with a TAWS. These included the following occurrences.
On 10 December 2001, a Raytheon Beech 200C Super King Air was being operated under the IFR to Mt Gambier, South Australia, on an aeromedical flight with the pilot and a medical crew member on board. At approximately 2333 local time, the pilot reported to air traffic control that they were in the circuit at Mt Gambier and would report after landing. At approximately 2336, the aircraft impacted the ground at a position 3.1 NM from the threshold of the runway. The pilot was fatally injured and the medical crew member sustained serious injuries.
Dark night conditions existed in the area. The available evidence indicated that the pilot was conducting a GPS arrival procedure.
On 15 May 2003, a Raytheon Beech 200C Super King Air was being operated under the IFR to Coffs Harbour, New South Wales, on an aeromedical flight with a pilot, 2 medical crew and a patient on board. The pilot conducted a missed approach from a low height and the aircraft impacted the sea, or a reef, approximately 3.2 NM north of the airport at about 0833 local time. During the missed approach, the aircraft narrowly avoided a breakwater and an adjacent restaurant. During the subsequent landing the aircraft was substantially damaged.
The pilot was conducting a GPS non-precision approach. Instrument meteorological conditions (IMC) existed at the time, including heavy rain and restricted visibility.
On 28 July 2004, a Piper PA-31T Cheyenne, with one pilot and 5 passengers, was being operated on a private IFR flight from Bankstown, New South Wales, to Benalla, Victoria. The aircraft collided with terrain 18 NM south-east of Benalla. All occupants were fatally injured and the aircraft was destroyed.
IMC existed at the time and the pilot had reported commencing a GPS non-precision approach to Benalla.
On 28 July 2004, a Piper PA31-350 Navajo Chieftain was being operated under the IFR to Mount Hotham, Victoria on a passenger charter flight with the pilot and 2 passengers on board. The aircraft collided with terrain 5 km south-east of the aerodrome and to the left of the extended centreline of runway. All occupants were fatally injured and the aircraft was destroyed.
IMC existed at the time and the pilot had reported commencing an RNAV GNSS approach.
Appendix G – Flight Safety Foundation CFIT Checklist
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] Instrument flight rules (IFR): a set of regulations that permit the pilot to operate an aircraft in instrument meteorological conditions (IMC), which have much lower weather minimums than visual flight rules (VFR). Procedures and training are significantly more complex as a pilot must demonstrate competency in IMC conditions while controlling the aircraft solely by reference to instruments. IFR-capable aircraft have greater equipment and maintenance requirements.
[2] Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10.0 hours.
[3] In the Lockhart River area, VHF contact with air traffic services was not generally available below 4,500 ft. Outside of VHF coverage, pilots communicated with Flightwatch using HF radio.
[4] Cloud cover: in aviation, cloud cover of the sky is reported using words/abbreviations that denote the extent of the cover. ‘Sky clear’ (SKC) indicates no cloud, ‘few’ (FEW) indicates 1–2 oktas (or eighths) is covered, ‘scattered’ (SCT) indicates 3–4 oktas is covered, ‘broken’ (BKN) indicates 5–7 oktas is covered, and ‘overcast’ (OVC) indicates that 8 oktas is covered.
[5] Landing minima: specified meteorological conditions of cloud ceiling and visibility. In order for an aircraft to land at an aerodrome, the actual weather conditions need to be at or above the landing minima.
[6] The ATSB obtained data broadcast by the automatic dependent surveillance broadcast (ADS-B) equipment fitted to the aircraft and GPS data transmitted from the pilot’s iPad with the OzRunways application installed. Further information on the aircraft’s recorded flight path during the 2 approaches is provided in Recorded flight data.
[8] The MDA published on the instrument approach chart was 830 ft and was based on the aerodrome forecast (TAF) QNH being set on the subscale of the aircraft’s pressure-sensitive altimeter. For this chart, the MDA could be reduced by 100 ft (to 730 ft) when using the actual QNH from an approved source. With the aircraft above the aerodrome and the actual QNH set, the altimeter indicates the approximate height above mean sea level. The aerodrome’s AWIS was an approved source for actual QNH and valid for a 15-minute period from the time of receipt.
[9] Flightwatch: on-request flight information service used to provide operational information including weather, aerodromes and navigational aids.
[10] VFR: a set of regulations that permit a pilot to operate an aircraft only in weather conditions generally clear enough to allow the pilot to see where the aircraft is going.
[11] The operator’s operations manual stated: ‘Due to the possibility of engine damage, asymmetric training in Company Cessna 404 aircraft is to be undertaken only where strictly necessary. Abrupt or large power changes are to be avoided where possible.’
[12] Instrument meteorological conditions (IMC): weather conditions that require pilots to fly primarily by reference to instruments, and therefore under instrument flight rules (IFR), rather than by outside visual reference. Typically, this means flying in cloud or limited visibility.
[13] The aerodrome forecast for that flight included periods of reduced visibility (3,000 m) in rain showers and cloud at 1,200 ft. Data from the aerodrome’s automatic weather station indicated the 1-minute visibility was 2,500 m at the airport when the aircraft passed the initial approach fix (IAF). However, the visibility had improved to 4,200 m by the time the aircraft reached the final approach fix (FAF) and continued to improve, to more than 10 km by the missed approach point (MAPt). There was no recorded rainfall during this period. The forecast and observed wind favoured a landing on runway 12.
[14] This aircraft retained the conventional airspeed indicator, altimeter and vertical speed indicator flight instruments, which were mounted in their usual positions relative to the ADI display. Those instruments were similar to the instruments fitted to VH-OZO.
[15] A number of other Cessna 404 aircraft introduced to Australia at about the same time also had modified seating arrangements with 11 passenger seats.
[16] An altitude alerting system provides an aural alert (tone) and/or a visual alert when an aircraft on climb/descent approaches the designated altitude and when deviating from that altitude during cruise. They are generally used to assist pilots monitor adherence to the ATC assigned level in controlled airspace, rather than mitigate the risk of controlled flight into terrain. Civil Aviation Order (CAO) 20.18 required aircraft conducting IFR operations in controlled airspace to have either an assigned altitude indicator or an altitude alerting system. For piston-engine aircraft, an altitude alerting system was only required for IFR operations above flight level 150 (which is 15,000 ft measured according to a standard atmosphere).
[17] Second CDI is partially hidden behind control column and clamp in Figure 8.
[18] The wide area augmentation system (WAAS) was developed by the US Federal Aviation Administration. The system provided augmentation information to GPS receivers, which improved the position accuracy and enabled localiser performance with vertical guidance (LPV) approaches to the runway. Those approaches took advantage of the increased position accuracy and were flown to a decision altitude, similar to a Category I instrument landing system procedure. The WAAS system covered most of the US, parts of Canada and Mexico.
[19] The default settings for the user-selectable fields were distance to the next waypoint, desired track, bearing to waypoint, groundspeed, ground track and estimated time en route.
[20] The navigation and terrain data were contained on 2 removable data cards, which slotted into the front face of each unit.
[21] One of the GNS 430W units was swapped with that from another aircraft in July 2018. The last terrain/obstacle database update of that unit was not determined.
[22] The series of Technical Standard Orders (TSO) C151 stipulated the minimum operational performance standards that a terrain awareness and warning system (TAWS) must meet to comply with regulatory requirements for the fitment and use of those systems.
[23] FLTA alerts were automatically inhibited when the aircraft was less than 200 ft above terrain while within 0.5 NM of the runway, or less than 125 ft above terrain within 1.0 NM of the runway.
[24] With approach flap selected, the inboard flap surface extended 10° and the outboard flap surface extended 8°.
[25] Vref: reference landing speed. It is normally defined as the speed required when crossing the runway threshold at 50 ft given the landing weight and configuration of the aircraft. It is usually calculated as 1.3 times the stalling speed in the landing configuration and at the prevailing aircraft weight.
[26] The operations manual used the term VAPP and Vref interchangeably. Often VAPP is used to refer to Vref plus additions for wind and other factors.
[27] Turbo-prop aeroplanes such as the SAAB 340 (maximum 37 passengers) and the Embraer EMB 120 (maximum 30 passengers) had a MTOW less than 15,000 kg.
[28] ICAO annexes specified standards and recommended practices (SARPS).
[29] In its notice of proposed amendment, the European Aviation Safety Agency (EASA) noted that the absence of a TAWS had been noted as a factor in 2 accidents in Europe for these types of aircraft in the previous 10 years. It also noted that new aeroplanes were already fitted with a TAWS and that a significant number of older aeroplanes had already been retrofitted with a TAWS or equivalent system. EASA also noted that the cost of fitting a TAWS in Europe was between €20,000 to €50,000.
[30] Transport Canada also noted that it had considered only introducing this requirement for turbine-engine aeroplanes (as per the US FAA) but that some stakeholders noted that some operators may discontinue using turbine-engine aeroplanes in favour of (less reliable) piston-engine aeroplanes to eliminate the cost of installing TAWS.
[31] MOPSC was defined at that time as the maximum passenger seat capacity of the aircraft, excluding pilot seats, flight deck seats and cabin crew seats.
[32] When the aeroplane was operated by a single pilot, this included the 11 passenger seats in the cabin and the front right seat, as that could also be used by a passenger. CASA further advised that an aeroplane with 2 seats at the front and 9 seats in the cabin (such as a Cessna 404 with the seating configuration specified in its type certificate data sheet) would be considered to have a MOPSC of 9 and the front right seat would not have to be removed.
[33] CASA advised that the definition of MOPSC referred to the number of passenger seats fitted to an aircraft available to be used by a passenger. An operator could not elect to limit the number of seats of an aircraft with a MOPSC of 10 or more through administrative or operational controls in order to have a MOPSC of 9 or less. Rather, seats would have to be physically removed from the aircraft.
[34] A SIGMET provides a concise description concerning the occurrence or expected occurrence, in areas over which meteorological watch is being maintained, of en-route weather phenomena that are potentially hazardous to aircraft.
[35] Visual meteorological conditions (VMC): an aviation flight category in which visual flight rules (VFR) flight is permitted – that is, conditions in which pilots have sufficient visibility to fly the aircraft while maintaining visual separation from terrain and other aircraft.
[36] In aviation meteorological products, time is expressed as coordinated universal time (UTC) and the data is generally expressed in coded terms. For ease of reference, the time has been converted to EST and the data has been decoded.
[37] In aerodrome forecasts and reports, the height datum for cloud is aerodrome elevation.
[38] TEMPO: a significant temporary variation from the prevailing conditions previously given in the TAF, expected to last for periods of between 30 and 60 minutes.
[39] Visibility reported in METARs/SPECIs was a 10-minute average.
[40] This improved the ceilometer’s response time to report changing conditions.
[41] In May 2012, BoM published a pamphlet Ceilometers and Visibility Meters as part of their aviation reference material series (available from www.bom.gov.au). The pamphlet provided information about the measurements made by these instruments and the associated advantages and limitations of the equipment.
[42] The term okta is used to refer to one eighth of cloud cover.
[43] From 9 September 2021, the naming of RNAV (GNSS) charts in Australia was progressively changed to RNP (required navigation performance) in alignment with an international convention.
[44] APV Baro-VNAV procedures required a navigation system capable of continuously computing a barometric VNAV path and displaying the relevant information on the instrument display.
[45] Civil Aviation Regulation 178 (Minimum height for flight under I.F.R.) stated that a pilot could not fly below a published lowest safe altitude except under certain conditions, such as during arrival if the aircraft was being flown in accordance with any instructions in the AIP, during an authorised instrument approach procedure, or if the aircraft was being flown by day in VMC.
[46] Availability of RAIM during the conduct of an RNAV GNSS approach provides an assurance of the integrity of the navigation system and that the calculated position is within the required tolerance for the procedure being flown.
[47] This paragraph and other AIP references were correct for the edition current at the time of the accident. That paragraph numbering may have changed during subsequent revisions of the publication.
[48] As discussed in the section GNS 430W overview, these receivers used satellite or ground-based augmentation (in regions where augmentation was available) to improve the position accuracy, enabling approaches providing localiser performance with vertical guidance (LPV) that could be flown to a decision altitude, similar to a Category I instrument landing system procedure.
[49] GPS units in the manufacturer’s 400 series without the ‘W’ designation (for example GPS 400, GNS 430/430A) used 0.3 NM CDI full-scale during the final approach segment. Those units could not be used to conduct LPV procedures.
[50] The approach procedure instructions published in the AIP to be established on the specified track before commencing descent were different to the navigation tolerances specified for the approach.
[51] For an aircraft conducting the Lockhart River RNAV (GNSS) runway 30 approach, descending on the recommended constant angle 3° profile, the aircraft crosses the FAF about 360 ft above the intermediate segment MSA.
[52] The CASA CNS/ATM resource kit (Chapter 9: Instrument flight rules operations, Flying the approaches), on the CASA website, also stated that ‘The tracking tolerance is half of full-scale deflection regardless of the CDI scale’. This resource kit content was based on the pre-December 2021 legislation but remained on the CASA website after December 2021.
[53] VAT is the indicated airspeed at the runway threshold (50 ft), which is equal to the stalling speed with landing gear extended and flaps in the landing position multiplied by 1.3. It is calculated at the aircraft’s maximum landing weight. At the maximum landing weight, VAT and Vref are the same.
[54] The aircraft was fitted with on-board Automatic Dependent Surveillance Broadcast (ADS-B) equipment, transmitting real-time operational data that enabled air traffic service providers to track aircraft. Airservices Australia recorded the transmissions received by its network of ADS-B receivers. That data could also be received by privately-operated equipment used to feed information to flight tracking websites.
[55] OzRunways is an electronic flight bag application that helps flight crew perform flight management tasks without the need for paper-based information. The OzRunways application also recorded flight data via a built-in GPS receiver. The data used in this investigation was transmitted from an iPad during the flight.
[56] 1 hPa difference equates to an altitude difference of about 30 ft.
[57] As previously noted, due to recorded altitude being truncated, this data have meant an altitude of 400–499 ft. The elevation of the terrain in the area was about 100 ft.
[58] According to the POH, the maximum gear extension speed was 182 kt, the maximum speed to select take-off and approach flap was 182 kt, and the maximum speed to select landing flap was 152 kt.
[59] Search and rescue time (SARTIME): the time nominated by a pilot for the initiation of search and rescue (SAR) action. If the pilot does not contact the SARTIME holder by the allotted time the search and rescue response will begin.
[60] The chief pilot advised the ATSB that, at some point prior to 29 October 2019, a Notice to Aircrew (number 13) was issued which outlined the operator’s change of requirements for OPCs to a period not exceeding 24 months.
[61] In this case, the pilot had conducted multiple flights under the IFR of over 1-hour duration in the last 6 months. On such flights, they had recorded a maximum of 30 minutes IFR flight time on these flights in their logbook.
[62] NOTAM: a notice distributed by means of telecommunication containing information concerning the establishment, condition or change in any aeronautical facility, service procedure or hazard, the timely knowledge of which is essential to personnel concerned with flight operations.
[63] The flight data used in this investigation was transmitted from the iPad during the approach.
[64] A descent rate of 600 ft/min requires a groundspeed of 113 kt to achieve a 3° approach path angle.
[65] CASA’s Air Operator’s Certificate Handbook: Volume 2 – Flying Operations stated in version 3.0 (November 2018) that ‘The use of the stabilised approach concept is mandatory for all approach operations.’ No further guidance regarding the contents of this guidance was included.
[66] The AIP also stated that, after passing the FAF, the descent rate ‘should not normally’ exceed 1,000 ft/min.
[67] ATSB Aviation Occurrence Report 200501977, Collision with Terrain, 11 km NW Lockhart River Aerodrome, 7 May 2005, VH-TFU, SA227-DC.
[69] The ATSB also reviewed the recorded data for 2 other straight-in approaches that the pilot logged as RNAV GNSS approaches in September to October 2019. The recorded groundspeeds were 145–150 kt at the FAF, 140–155 kt at 1,000 ft and 115–135 kt at 300 ft. A full review of winds and indicated airspeeds was not conducted.
[70] ATSB Occurrence Report 200501977, Collision with Terrain, 11 km NW Lockhart River Aerodrome, 7 May 2005, VH-TFU, SA227-DC (Metro 23).
[71] In addition to these accidents, notable CFIT accidents during non-precision instrument approaches resulting in multiple fatalities also occurred on 11 June 1993 (Piper PA-31 piston-engine aircraft on scheduled passenger transport flight to Young, New South Wales, on an NDB/circling approach, 7 fatalities) and 27 April 1995 (Israel Aircraft Industries Westwind 1124 turbojet aircraft on scheduled freight flight to Alice Springs, Northern Territory, on a twin locator NDB approach, 3 fatalities).
[72] Between October 1999 and December 2000, there was a requirement for passenger transport operators under the IFR in turbine-engine aeroplanes with a MTOW more than 15,000 kg or carrying more than 9 passengers to conduct CFIT hazard awareness if the aircraft was not fitted with a GPWS or TAWS. After that time, all such aircraft were required to have a GPWS or TAWS. Some operators continued to include CFIT hazard awareness training as a requirement in their operations manual. Further details are provided in ATSB Occurrence Report 200501977.
[73] The operator’s operations manual also stated: ‘Extreme caution should be exercised in low visibility operations. Note that when encountering low visibility conditions due to rain, it is important to be aware that an illusion of being too high can occur, with a resulting undershoot being a possibility.’
[74] The MOPSC for an Australian operator was defined as the maximum passenger seat capacity of the aircraft approved by CASA as part of the approval of the operator’s exposition under CASR Part 119 and specified in the operator’s operations manual.
[75] That is, aeroplanes certified to be operated by a single pilot in accordance with the type certificate data sheet and whose flight manual provided that the flight crew could consist of a single pilot.
[76] A drum pointer altimeter has a single pointer that indicates tens and hundreds of feet, while a single drum indicates thousands and tens-of-thousands of feet (and fractions thereof) in numerals. A counter-drum pointer altimeter includes a single pointer that indicates tends and hundreds of feet while one or more coupled drums (or counters) indicated hundreds, thousands and tens-of-thousands of feet.
[77] Previous research conducted by Fitts and Jones (1947) also identified similar problems with misreading of 3-pointer altimeters, particularly in terms of misreading by 1,000 ft and misreading by 10,000 ft. They found that misreading of altimeters was the most common error in interpreting aircraft instruments at that time.
[78] The same exclusion for 3-pointer and drum-pointer altimeters was not stated in ICAO Annex 6 Part II International General Aviation – Aeroplanes.
[80] 1 hPa difference equates to an altitude difference of about 30 ft.
Preliminary report
Report release date: 11/06/2020
This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
The occurrence
First phase of the flight
On 11 March 2020, Air Connect Australia was operating a Cessna 404, registered VH-OZO, on a passenger charter flight from Cairns to Lockhart River and return (Figure 1). The client arranged for the aircraft to depart Cairns at 0730 Eastern Standard Time[1] with four passengers, wait on the ground at Lockhart River for about 5 hours, then depart at 1430 with the same passengers for the return flight. The operator assigned the pilot who regularly conducted the client’s charter flights.
Figure 1: Location of Cairns and Lockhart River in north Queensland, Australia
Source: Google Earth, annotated by the ATSB
According to the weather forecasts, the pilot could expect mostly visual meteorological conditions (VMC)[2] during the day at Cairns with some periods of rain showers and low cloud. For the arrival at Lockhart River, the forecast weather was predominately VMC but there were overlapping periods of rain and low cloud with 30 per cent probability of thunderstorms.
The pilot had submitted a flight notification, which specified instrument flight rules (IFR)[3] and capability for an area navigation (RNAV) instrument approach. On the morning of the flight, the pilot refuelled the aircraft with 650 L of avgas.
The aircraft departed Cairns at 0719 and the pilot tracked for the first planned waypoint on climb to 10,000 ft above mean sea level. Based on the forecast winds, the estimated time of arrival (ETA) at Lockhart River was 0852. As the flight progressed, the pilot amended the ETA to 0904.
At 0840, the pilot advised air traffic control that he was leaving 10,000 ft on descent to Lockhart River. A couple of minutes later, the controller advised the pilot of the very high frequency (VHF) and high frequency (HF) radio frequencies applicable to the rest of the flight. That was the controller’s last contact with the pilot and no further routine interactions with the controller were expected.[4]
During descent, the pilot transmitted on the common traffic advisory frequency (CTAF) for Lockhart River to enable the pilot activated lighting (PAL) for a period of 30 minutes. At 0852, the aerodrome frequency response unit (AFRU) broadcast ‘Lockhart River CTAF, runway lights are on.’
As the aircraft was descending, the pilot tracked to waypoint LHREB, one of three initial approach fixes for the RNAV (GNSS) runway 30 instrument approach at Lockhart River.
First approach at Lockhart River
Note: Figure 2 and Figure 4 provide information on the pilot’s first approach and Figure 3 and Figure 4 provide information on the second approach. Figure 11shows the applicable approach chart, and key parameters for the approachesare incorporated into Figures 2, 3 and 4.
The aircraft flightpath parameters referenced in the following text and shown in Figures 2, 3, and 4 are taken from transmitted GPS data recorded at 5-second intervals by an electronic flight bag application. The quoted heights are geometric altitudes rather than barometric altitudes indicated by an altimeter, which is the primary altitude reference for this approach. The ATSB notes that GPS altitude was transmitted as a rounded value so the recorded altitude could vary up to 100 ft from the actual GPS-computed geometric altitude. Preliminary validation of the flight data indicates that the recorded geometric altitudes correlate with barometric altitude data that is available for part of the flight.
The pilot passed abeam LHREB at 0859:38 on descent through 5,400 ft and turned left to track to the runway in accordance with the RNAV procedure.
At 0901:25, the pilot made a radio broadcast on the CTAF, advising the aircraft was 10 NM to the south-east of the aerodrome, inbound to runway 30 and on descent passing 4,000 ft. Shortly afterwards, the aircraft passed intermediate approach fix LHREI at 4,000 ft.
The pilot continued the descent and inbound track to pass the final approach fix LHREF on descent through 2,300 ft. At 0904:27, the pilot broadcast on the CTAF that he was 5 NM out and on final (approach) to runway 30.
The aircraft arrived at the missed approach point LHREM at 0906:17 and 570 ft. The specified minimum descent altitude (MDA) was 830 ft, which could be lowered by 100 ft if the pilot set the current aerodrome QNH[5] from the automated weather information service (AWIS). The pilot continued the descent to 500 ft then climbed to 600 ft and maintained the approach track for a further 2 NM. Coincident with passing over the aerodrome facilities, the pilot initiated a missed approach and, while climbing, turned slightly right to track to the missed approach turning fix LHREH.
At 0907:22, the pilot broadcast on the CTAF that he was conducting a missed approach for runway 30, tracking to the west then turning back to the east and climbing to 3,500 ft.
After passing LHREH at 0907:43 on climb through 1,200 ft, the pilot made a right turn to track to the east as prescribed by the approach chart. At 0908, the pilot contacted Flightwatch on HF to advise of the missed approach and his intention to provide an update of ‘operations normal’ by 0930. The middle part of this radio transmission, as recorded by Airservices Australia, was unclear, which is not uncommon for HF radio communication. Based on the fragments and context, the pilot was probably advising his intention to conduct another approach.
The pilot continued the climb to 3,500 ft as specified for the missed approach procedure.
Figure 2: Flight track of VH-OZO during first RNAV (GNSS) approach at Lockhart River Aerodrome with time stamps, feature labels, and approach parameters superimposed
Source: Google Earth, annotated by the ATSB
Second approach at Lockhart River
Following the missed approach, the pilot levelled the aircraft at 3,500 ft and turned from the easterly heading towards the closest initial approach fix LHREA. At 0912:51, the AFRU recorded runway lights on, consistent with the pilot reactivating the runway lights for another 30-minute period.
About 2 NM from LHREA, the pilot turned right toward the general direction of intermediate approach fix LHREI and tracked to the south-west for about 2 NM then turned left to intercept the defined inbound track to LHREI. The pilot started descent from 3,300 ft at 0915:18.
At 0915:50, the pilot made another inbound broadcast on the CTAF advising:
10 miles [NM] to the south-east on descent passing three thousand eight hundred [3,800 ft] [unclear phrase, possibly ‘correction’] two thousand eight hundred [2,800 ft], straight-in approach runway three zero [30], circuit area two one [time 0921].
At the start of the transmission, the aircraft was on descent through 2,900 ft. The ATSB notes that the recorded transmission sounded routine; no further transmissions from VH-OZO were recorded.
After passing over LHREI, the pilot flew parallel to the defined RNAV approach track and continued the descent at a similar gradient to the first approach. About halfway between LHREI and final approach fix LHREF, the aircraft descended through the segment minimum safe altitude of 1,800 ft.
When the aircraft passed LHREF at 0918:23, the aircraft was on descent through 1,100 ft. From LHREF to LHREM, the altitude limitation was the MDA of 730 ft (assuming the pilot had set the current QNH). About 30 seconds later, the aircraft was approaching 700 ft with an apparent decrease in the descent rate for a short period. The aircraft then descended below the MDA and the aircraft track diverged to the left, crossing the inbound track at an angle of about 20°.
The divergent aircraft track and descent continued until the aircraft impacted a sand dune on the coastline at 0919:40. The pilot and four passengers were fatally injured and the aircraft was destroyed.
Figure 3: Flight track of VH-OZO during second RNAV (GNSS) approach at Lockhart River Aerodrome with time stamps, feature labels, and approach parameters superimposed
Source: Google Earth, annotated by the ATSB
Profile and speed information
The descent profile of the aircraft on the first approach was slightly higher than the nominal 3° approach gradient specified on the approach chart. The descent profile of the aircraft on the second approach had a similar gradient but was generally displaced 1,200 ft lower.
The ATSB calculated the average groundspeed of the aircraft from the distance travelled between data points in the specified time. This is provisional data that requires further adjustment for the effects of wind, altitude, and temperature to derive estimates of aircraft airspeed.
On the first approach, the groundspeed was between 130 and 140 kt until the missed approach was initiated. On the second approach, the groundspeed was also between 130 and 140 kt until it increased to 150 kt as the aircraft descended below the MDA up to the collision with terrain.
Figure 4: Profile of VH-OZO during the two RNAV (GNSS) approaches to Lockhart River Aerodrome with approach parameters and features incorporated.
Note: Short periods of constant altitude represented in the diagram do not necessarily indicate a constant altitude because the transmitted/recorded data is rounded.
Source: ATSB
Site and wreckage
The accident site was located on a sand bank adjacent to the beach, about 6 km south-east of Lockhart River Aerodrome and 300 m to the south-west of the specified RNAV track. The wreckage trail was about 20 m from the initial impact point (Figure 5), and indicated that the aircraft was on a heading of about 280° (magnetic), with the impact point about 30 ft above mean sea level.
Figure 5: Overview of accident site
Source: ATSB
The ATSB’s on-site examination of the wreckage, damage to surrounding vegetation and ground markings indicated that at initial impact the aircraft was:
upright and close to wings level
about 5° nose down
at relatively high speed.
An area of foliage around the aircraft displayed signs of chemical burn from avgas, indicating that the aircraft had a significant amount of fuel on board.
There was no evidence of any structural or mechanical defects, but the examination was limited by the extensive damage (Figure 6). All but one of the propeller blades were located at the site; damage to the recovered blades indicated significant rotational energy at impact consistent with both engines operating normally with substantial power.
The landing gear was extended at the time of impact. Other aircraft configuration information such as flap position, trim settings and switch selections could not be validated due to the impact damage. The serviceability of the flight instruments and associated systems could also not be verified.
Figure 6: Impact points of VH-OZO and main wreckage
Source: ATSB
The only components on the aircraft that may have recorded data were a digital fuel flow indicator/totaliser and a transponder, and the ATSB recovered these components. After consideration of the damage to these components and the potential value of any data, no further examination was undertaken.
Context
Pre-flight planning and in-flight monitoring
At 1326 on the day before the accident flight, the pilot accessed a location briefing for Lockhart River from the National Aeronautical Information Processing System (NAIPS) via an electronic flight bag (EFB) application. This type of briefing typically displayed current forecasts, reports, and ‘notice to airmen’ (NOTAM) applicable to the nominated location.
Later that day, at 1830, the pilot requested grid point wind and temperature charts (GPWT) and a specific pre-flight information bulletin (SPFIB) from NAIPS via flight planning software. The SPFIB request was for Cairns to Lockhart River and return with the estimated time of departure nominated as 1930 the same day. This bulletin was valid until 1830 on the day of the accident.
A printout of the SPFIB found at the accident site showed aerodrome forecast (TAF) and weather reports (METAR) for Cairns. The weather for the next day (day of accident flight) at Cairns Airport was expected to be visibility of 10 km or greater and showers of light rain with scattered[6] cloud at 1,800 ft[7] in the morning lifting to 2,500 ft. In addition, the forecast imposed a TEMPO[8] for the next day to specify periods of visibility reduced to 2,000 m with showers of moderate rain and broken[9] cloud at 1,000 ft.
On the printout of the SPFIB, a METAR for Lockhart River for 1800 (10 March) showed light winds, visibility 10 km or greater and nil cloud detected. Since 0900 that morning, recorded rainfall was 1.8 mm.
No TAF was provided on the SPFIB for Lockhart River as the time of the request was outside the issue and validity period. There were no predicted outages of global positioning system/global navigation satellite system (GPS/GNSS) capability for Cairns or Lockhart River. ‘Notice to airmen’ (NOTAM) information included a change to Lockhart River runway distance and gradient data and no other notices with significance for the planned flight.
After the SPFIB was received, at 1942, the pilot submitted a flight notification for the planned departure from Cairns at 0730 the next morning to Lockhart River followed by a departure at 1430 for the return sector. Both sectors were planned under instrument flight rules (IFR) with nominated capability for instrument approaches using GPS/GNSS equipment.
A damaged and partly illegible copy of the pilot’s flight plan/log was found at the accident site. This was a printout from flight planning software showing key navigational data and pilot notes on progress of the flight. There was no indication of any operational abnormalities.
A tabulated fuel plan showed 1,040 L on board at engine start at Cairns and expected fuel consumption of 285 L for the planned 94-minute flight to Lockhart River. The pilot had included provision for 45 minutes fixed reserve (124 L), 40 L variable reserve and 60 minutes holding (110 L) if required (consistent with TEMPO conditions). If the variable reserve and holding allowance was consumed on the outbound sector (in addition to the calculated flight fuel), the remaining 605 L was sufficient to return to Cairns with allowance for 60-minutes holding on arrival.
In summary, the pilot was not intending to refuel at Lockhart River, and the aircraft had sufficient fuel to conduct the flight from Cairns to Lockhart River and return, with additional fuel for holding on both sectors if required. Avgas was available at Lockhart River.
The pilot completed the operator’s passenger/cargo manifest form and calculated the aircraft’s weight and balance with reference to individual passenger weights and baggage. The take-off weight was recorded as 3,678 kg and nominal landing weight as 3,366 kg. The aircraft’s maximum take-off weight was 3,810 kg and maximum landing weight was 3,674 kg. The graphical trimsheet showed the centre of gravity was within limits throughout the flight.
A copy of the operator’s in-flight monitoring form was found at the accident site. When the pilot completed the form in cruise at 10,000 ft, all of the recorded engine parameters for each engine were comparatively similar with no indication of any aircraft-related problems.
After the pilot requested the SPFIB and submitted the flight notification on the evening before the accident flight, there was no record of further requests for meteorological information from NAIPS. Such information is also available from the Bureau of Meteorology website and other sources without any user registration requirements. It was reported that the pilot was aware of the current weather forecasts on the morning before the flight.
During the flight, the pilot was using an iPad with an electronic flight bag (EFB) application and was carrying a second iPad as a backup.
Meteorological information
Introduction
The Bureau of Meteorology produced aviation forecasts, observations, warnings and advisories. As the official provider of the Aeronautical Information Service, Airservices Australia delivered the bureau’s aviation meteorological products to pilots through NAIPS.
For the flight from Cairns to Lockhart River, the essential meteorological data was aerodrome forecast (TAF), graphical area forecast (GAF), grid point wind and temperature chart (GPWT) and any warnings (such as SIGMET). This could be supplemented by aerodrome weather reports (METAR), ground-based weather radar imagery, and satellite imagery.
Forecasts for Lockhart River
On 11 March 2020 (day of accident), the initial TAF for Lockhart River was issued at 0449 EST[10] and was valid from 0600 to 1800. The expected weather conditions were:
From 0600 to 1000: wind variable at 3 kt with visibility 10 km or greater. Light rain showers and cloud scattered at 1,000 ft (all heights are above the aerodrome elevation).
Between 0600 and 1000: TEMPO - visibility reduced to 3,000 m with rain and broken cloud at 500 ft.
From 0600 to 0800: 30 per cent probability of fog with visibility reduced to 500 ft and broken cloud at 100 ft.
From 1000 to 1800: wind from the north-east at 5 kt with visibility 10 km or greater. Light rain showers with scattered cloud at 1,000 ft.
Between 1000 and 1800: TEMPO - visibility reduced to 3,000 m with rain showers and broken cloud at 800 ft.
For the whole forecast period, 0600 to 1800: 30 per cent probability TEMPO - winds gusting 25 to 35 kt and visibility reduced to 1,000 m due to thunderstorms and rain. This was associated with broken cloud at 500 ft and scattered cumulonimbus cloud with the base at 1,000 ft.
Based on this forecast, for a flight expected to arrive at between 0900–1000, the pilot was required to plan for 60 minutes or diversion to an alternate. The aircraft had more than sufficient fuel for that purpose.
An amended TAF for Lockhart River was issued at 0925 and was valid from 0900 to 1800. The expected weather conditions were:
From 0900 to 1300: wind variable at 3 kt with visibility 10 km or greater. Light rain showers with cloud scattered at 1,000 ft and broken at 2,000 ft
For whole forecast period, 0900 to 1800: TEMPO – winds gusting from 20 to 35 kt and visibility reduced to 1,000 m due to thunderstorms and rain. This was associated with broken cloud at 500 ft and scattered cumulonimbus cloud with the base at 1,500 ft.
Other forecasts
A GAF was issued at 0853 and was valid from 0900 to 1500 and applicable from surface to 10,000 ft. This covered the Queensland-North region, which was divided into six areas for this forecast. Most of the flight including the arrival at Lockhart River was within one area that was forecast to have the following conditions:
Broken stratus 1,000 ft to 2,000 ft with broken cumulus/stratocumulus above that. Visibility reduced to 6,000 m in widespread rain.
Isolated towering cumulus from 2,000 ft, broken stratus from 800 to 2,000 ft, and broken cumulus/stratocumulus from 2,000 ft. Visibility reduced to 2,000 ft in scattered rain showers.
Isolated cumulonimbus from 2,000 ft and broken status between 500 ft and 1,000 ft. Visibility reduced to 500 m in isolated thunderstorm rain showers.
A GPWT forecast was issued at 0538 and was valid to 1000. Lockhart River was located near the intersection of four data boxes and therefore roughly equidistant from four forecast locations. Taking 2,000 ft as a reference height for the approaches and coastal data as more relevant, the wind was forecast to be from the north-west at 9 kt increasing to 21 kt north of Lockhart River.
There were no significant weather warnings applicable to the flight.
Aerodrome weather reports for Lockhart River
The METARs for Lockhart River were automatically generated every 30 minutes for routine reports and were issued as a special report (SPECI) at other times when one or more elements met specified criteria for degradation and improvement. For the period from 0830 to 0930 on 11 March 2020:
0830: nil wind, visibility 10 km or greater with rain and scattered cloud from 3,000 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm.
0900: nil wind, visibility 10 km or greater with rain and broken cloud at 2,000 ft, 3,500 ft, and 4,100 ft. Temperature and dewpoint were both 25 °C. Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0910: nil wind, visibility 10 km or greater with rain and broken cloud at 1,800 ft and 3,400 ft then overcast at 4,200 ft. Temperature and dewpoint were 26 and 25 °C respectively. Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0913: nil wind, visibility 3,800 m with rain and broken cloud at 1,800 ft and 3,400 ft, overcast at 4,200 ft. Temperature and dewpoint were 26 and 25 °C respectively. Rainfall in the previous 10 minutes was 0.2 mm.
SPECI 0929: westerly at 5 kt, visibility 8,000 m with heavy rain and scattered cloud at 1,200 ft, broken cloud at 1,900 ft, and broken cloud at 3,600 ft. Temperature and dewpoint were both 25 °C . Rainfall in the previous 10 minutes was 0.4 mm.
SPECI 0930: westerly at 5 kt, visibility 9,000 m with heavy rain and scattered cloud at 1,200 ft, broken cloud at 1,900 ft and broken cloud at 3,600 ft. Temperature and dewpoint were both 25 °C . Rainfall in the previous 10 minutes was 0.4 mm.
The QNH remained at 1,008 hPa during this period, except at 0929 when it was reported as 1,009.
During the next 30 minutes, there were four SPECI issued with variations to visibility between 5,000 m and 10 km or greater. The wind varied in direction and strength no greater than 7 kt. The temperature and dewpoint both remained at 25°. There was persistent rain, and scattered to broken low cloud.
Automated weather information service
Lockhart River was equipped with an automated weather information service (AWIS) that transmitted text-to-speech on a discrete VHF frequency. A new AWIS message was generated every minute in a similar format to the METAR reports. This data was also available from a telephone service.
The pilot recorded the following data in the space allocated for arrival weather information in the flight plan/log:
calm (nil wind)
10 km (visibility)
B1800 (broken cloud at 1,800 ft)
B3500 (broken cloud at 3,500 ft)
OV 5300 (overcast cloud at 5,300 ft)
1008 (QNH)
25 (temperature 25 °C).
Radar information
Figure 7 provides an indication of the weather around Lockhart River at 0930 on the morning of the accident.
Figure 7: Weipa radar image at 0930 WST (shortly after the accident) showing weather in Lockhart River area (circled, approximate radius 25 NM/46 km)
Source: Bureau of Meteorology, annotated by the ATSB
Local weather observations
Two pilots were operating aircraft in the Lockhart River area before and after the accident. The first pilot, operating before the accident, tracked to Lockhart River from the south and conducted the RNAV (GNSS) RWY 30 approach, landing at 0810. There were intermittent rain showers in the area and the pilot advised that the end of the runway was visible while descending through 1,000 ft. The pilot remained on the ground at Lockhart River until later in the day and heard an aircraft (VH-OZO) fly over at high engine power. At that time, there was scattered low cloud at 500–1,000 ft with reduced visibility in rain showers.
The following pilot, operating after the accident, tracked to Lockhart River from the south-west and diverted 15 NM to the right of track due to weather. On arrival the pilot conducted the Lockhart River RNAV (GNSS) RWY 30 approach and landed at 0953. There was rain in the area and, although the conditions allowed visual navigation after the final approach fix while descending through 1,500 ft, the runway was not visible until later in the approach.
A person who was near the aerodrome at the time of the accident described the conditions as an unusual morning with a bit of mist coming from the rainforest, and that there was about 5 to 10 minutes of heavy rain around the time the aircraft would have been in the area. At that time, there was low-lying cloud and no wind.
Two of the passengers recorded and shared images during the flight, including one image from each passenger while the aircraft was in the Lockhart River area. The first image (Figure 8) was sent by text messaging at 0903, which was during the first approach while the aircraft was over halfway between intermediate approach fix LHREI and final approach fix LHREF at an altitude between 3,100 and 2,500 ft. The camera is orientated to the north so the foreground, if visible, would be the ocean to the east of Lockhart River.
In a subsequent text message sent at 0914, the passenger advised that the first attempt at landing was unsuccessful and the runway was not visible due to heavy rain. This was followed a couple of minutes later by a text to advise of another attempt. No further communication was received.
Figure 8: Image recorded by a passenger looking forward over the right engine and sent via text message at 0903
Source: Provided to the ATSB, lower section of image cropped by the ATSB
The second image (Figure 9) was uploaded at 0914 during the early stages of the second approach, while the pilot was tracking towards LHREI on a south-westerly heading at 3,500 ft. The camera is oriented to the west, which is in the general direction of Lockhart River. An associated message indicated very low visibility and the pilot was circling while waiting for a break in the weather. No further communication was recorded.
Figure 9: Image recorded by a passenger looking over the right wing and uploaded to social media at 0914
Source: Provided to the ATSB
Operator information
The Civil Aviation Safety Authority (CASA) issued Air Connect Australia with an Air Operator’s Certificate (AOC) in March 2017 with an expiry date of 31 March 2020. It authorised the certificate holder to operate Cessna C310/340, C404, C402/421 and Raytheon Baron/Travelair aircraft types on charter and aerial work operations. At the time of the accident, CASA was assessing the operator’s application to renew the AOC.
From April 2017, the operator dry-leased VH-OZO from the aircraft owner based at Jandakot Airport, Western Australia. In this arrangement, the aircraft owner was responsible for the continuing airworthiness of the aircraft and the operator managed the operational aspects, such as fuel and flight crew.
The managing director carried out the key roles in the operator’s organisational structure, such as chief pilot and head of aircraft airworthiness and maintenance control. In the 18 months prior to the accident, Air Connect Australia operated one aircraft (VH-OZO) with one pilot additional to the chief pilot (that is, the pilot of the accident flight).
Pilot information
The pilot held a Commercial Pilot Licence (Aeroplane) with an instrument rating and multi-engine aeroplane endorsement. On 7 August 2019, the pilot completed an instrument proficiency check for multi-engine aeroplanes conducted by an independent CASA-approved flight examiner. This was valid until 7 August 2020 and deferred the requirement for a flight review up to August 2021.
Prior to joining the operator in October 2018, the pilot’s recorded total flying time was 2,800 hours. He had been operating as a commercial pilot in remote locations for 5 years, including a total of 3 years based in Arnhem Land, Northern Territory. Between March 2016 and February 2018, he was chief pilot for a charter company that operated Cessna 310 and Piper PA-31 aircraft.
The pilot completed operator induction in October 2018 and received type-specific training in a Cessna 421 from an independent CASA-approved flight examiner. The examiner recalled that the pilot managed the transition to the 400-series Cessna without any problems. Other than the pressurisation system in the C421, the examiner considered it was operationally equivalent to the unpressurised Cessna 404.
Following this, the chief pilot supervised the pilot in command on four flight sectors in VH-OZO and conducted an operator proficiency check (OPC) over two further sectors. The chief pilot noted that the pilot’s planning was satisfactory and operation of the aircraft was above standard. No further OPC was recorded, which was consistent with the operator requirement for an OPC within a 2-year period.
From November 2018 to the accident flight, the pilot was based in Cairns and conducted most of the operator’s charter flights in VH-OZO. During this period, the pilot recorded 70 RNAV (GNSS) approaches to various aerodromes including six at Lockhart River, most recently in October 2019. On one flight, the pilot recorded two RNAV (GNSS) approaches (to Aurukun), which indicates that the pilot conducted a missed approach after the first attempt and landed after a second approach.
In the 2 months prior to the accident flight, the pilot conducted a number of flights (56 sectors). Prior to the day of the accident, his most recent flights were on 18 February 2020. These flights included a RNAV (GNSS) approach and an instrument landing system (ILS) approach.
The pilot had recorded a total of 3,220 hours before the accident flight, including a total of 1,177 hours on multi-engine aircraft with 399 hours on the Cessna 404 aircraft type. Total instrument time was recorded as 148 hours, including 4.5 hours in the 90 days prior to the accident flight.
The pilot’s Class 1 (Commercial Pilot) Medical Certificate was renewed on 14 February 2020 and was valid until 14 February 2021. There were no indications of any significant medical problems in the pilot’s aviation medical records. It was reported that the pilot had been sleeping well in the nights preceding the accident and exercising regularly. He had been on a holiday in the weeks before the accident and was described to be in good health and looking forward to flying again.
Aircraft history and avionics
The aircraft was manufactured by the Cessna Aircraft Company in 1980. It was reported that the aircraft was first operated in Australia before being transferred to Papua New Guinea and registered as P2-ALG. In December 2009, after the aircraft was flown to Australia, a CASA certificate of airworthiness was issued and the aircraft was registered VH-OZO. At that time, the aircraft total time was 28,193 hours.
On arrival into Australia, the aircraft was fitted with aerial geophysical survey equipment and was operated in that configuration until that equipment was removed in March 2012. Concurrently, the avionics were modified in accordance with an engineering order to install new types of avionics and integrate those with existing units. The post-modification avionics, including existing equipment, consisted of:
Garmin GMA340 audio panel
Dual Garmin GNS430W GPS/Nav/Com
Dual Garmin GI-106A CDI Indicator
Garmin GTX327 Transponder
Bendix/King KR87 ADF and
Bendix/King KI-227 Indicator
Collins HF
Cessna 400B Navomatic Autopilot
Bendix non-colour weather radar.
These units were installed at the time of the occurrence except for the transponder, which was replaced by an automatic dependent surveillance-broadcast (ADS-B) compliant unit in April 2017.
The 400B autopilot was one of the standard equipment options for the C404 type. It can provide pitch and roll control with heading and altitude hold (on command). A navigation function provided the autopilot with inputs from an associated CDI instrument, which in this case received data from the number‑1 GNS430W. For a RNAV (GNSS) approach, the pilot could ‘couple’ the autopilot for lateral navigation and manage vertical navigation by adjusting the pitch control or selecting altitude hold.
The aircraft was fitted with the instrumentation required for operations under IFR. These instruments were conventional analogue indicators and reflected the original specifications for the aircraft. It was noted that the second artificial horizon/attitude indicator and altimeter were located on the right side of the co-pilot panel (far side of the instrument panel relative to the pilot).
Figure 10: VH-OZO instrument panel
Source: Provided to the ATSB
Aircraft maintenance
The aircraft logbook statement specified that VH-OZO was to be maintained in accordance with the system of maintenance (SOM) developed by the aircraft owner and approved by CASA. The key elements of the SOM were:
daily inspection in accordance with the Cessna 404 Pilot’s Operating Handbook
engine and airframe inspections every 100 +/- 10 hours in accordance with the Cessna 404 Progressive Care Program (Operations 1 and 2 plus 3 and 4 completed within 12-month period)
electrical and instrument inspections every 220 hours or 12 months in accordance with SOM schedules
IFR avionics inspections every 220 hours or 12 months in accordance with SOM schedules
Special inspections, Supplemental Inspection Documents, and Corrosion Prevention Control Program as required
altimeter and pitot-static system inspection and test every 24 months
maintenance release issue for a period of up to 220 hours or 12 months, whichever occurred first.
Scheduled engine and airframe maintenance was carried out by the CASA-approved maintenance organisation associated with the aircraft owner. While the aircraft was based in Cairns, electrical, instrument, and radio maintenance as well as unscheduled maintenance was contracted to licensed aircraft maintenance engineers.
The most recent maintenance was the scheduled 100-hour inspection based on Operations 3 and 4 of the Cessna 404 Progressive Care Program. This was completed on 16 February 2020 at 31,066 hours total time. A maintenance release was issued with the next scheduled maintenance being the oil/filter change after 50 hours operation and compass swing in July 2020.
Other key maintenance was:
19 January 2020 at 31,050 hours: inspection of the electrical, instrument and IFR avionic systems certified as satisfactory
29 January 2019 at 30,750 hours: inspection and test of the pitot-static system and check of altimeters certified as satisfactory.
The current maintenance release was not found at the accident site. Operator records showed that the aircraft had been operated for 3.8 hours between maintenance release issue and the accident flight. The operator and aircraft owner both advised that no aircraft defects had been reported.
Garmin GNS 430W
The Garmin GNS 430W is a panel-mounted unit that provided for GPS navigation, instrument landing system (ILS) or VHF omnidirectional radio range (VOR) navigation, and VHF radio communication. It was approved for IFR operations including RNAV (GNSS) approaches and was used in conjunction with a course deviation indicator (CDI) instrument.
Although the ‘W’ designates wide area augmentation system (WAAS) capabilities that allow for GPS approaches with vertical guidance, Australia does not have the associated infrastructure. As such, the GNS 430W was approved to provide distance and track information only for RNAV (GNSS) non-precision approaches.
To use the unit for RNAV (GNSS) approaches, it was a requirement that the NavData card was valid and the approach was loaded from the database. The operator subscribed to the Jeppesen NavData service that provided updates on a monthly basis. It was reported that the pilot updated the NavData card using a laptop computer in the 24 hours prior to the flight, although this is yet to be confirmed by the ATSB.
The GNS 430W has a terrain function that requires a valid 3D GPS position solution and a valid terrain and obstacle database to operate properly. Terrain information is advisory only and can include:
display of altitudes of terrain and obstructions relative to the aircraft’s altitude
pop-up terrain alert messages issued when flight conditions meet parameters set within the terrain system software algorithms
forward looking terrain avoidance alerts in all phases of flight
premature descent alerting on approach to land (including RNAV approaches).
The ATSB has not yet established if the terrain function was operable and the status of any user and system inhibitions.
Fault detection and exclusion was incorporated into the GNS 430W software to detect satellite failure and exclude failed satellites from usage.
Lockhart River RNAV (GNSS) RWY 30 approach
It was reported that the pilot subscribed to the departure and arrival procedures published by Airservices Australia. A copy of the Lockhart River RNAV (GNSS) RWY 30 approach chart as published by Airservices Australia is shown in Figure 10.
To enable the approach, the pilot loads the approach waypoints and approach tracks from the GPS database. All altitudes specified for the Lockhart River RNAV (GNSS) RWY 30 approach are barometric and are managed by the pilot with reference to the altimeter. In addition to the various minimum safe altitudes for different segments of the approach, the pilot is provided with a distance/altitude scale that provides guidance for the optimum descent angle of 3°.
After the final approach fix LHREF, the pilot is permitted to descend to the MDA provided the aircraft is within tracking tolerances. Further descent is only allowed if the pilot has at least 4,200 m visibility and is able to continue the approach and land on the runway. If the pilot arrives at the missed approach point and is unable to continue the approach to land by visual reference, the pilot is required to conduct a missed approach by initiating a climb to the specified altitude and tracking in accordance with the procedure.
Figure 11: Lockhart River RNAV (GNSS) Runway 30 approach chart
Source: Airservices Australia
Further investigation
The investigation is continuing and will include further review and examination of:
recorded flight data for the accident flight
meteorological data at the time of the accident
recorded flight data as available for selected RNAV (GNSS) approaches conducted by the pilot at Lockhart River and other aerodromes
regulatory oversight processes for Air Connect Australia
software version and operation of Garmin GNS 430W units fitted to VH-OZO
training and checking practices related to RNAV (GNSS) approaches, including missed approaches and subsequent approaches
occurrences involving RNAV (GNSS) approaches, including at Lockhart River
existing and potential risk controls for controlled flight into terrain
human factors considerations
potential pilot incapacitation risk factors.
Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Acknowledgements
The ATSB acknowledges the significant assistance provided by the Queensland Police Service during the on-site phase of this investigation.
The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this preliminary report. As such, no analysis or findings are included in this report.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 9 February 2020, a Qantas Boeing 787-9 was conducting a flight from London Heathrow Airport, Greater London, United Kingdom to Perth Airport, Australia. During rotation, the pilots received a tail strike caution message and returned for landing at London Heathrow Airport.
The United Kingdom Air Accident Investigation Branch (AAIB) is conducting an investigation into this occurrence. As Australia is the State of Registration of the aircraft, the AAIB has requested an Accredited Representative from the Australian Transport Safety Bureau (ATSB) be appointed.
To facilitate this request, the ATSB initiated an external investigation under the provisions of the Transport Safety Investigation Act 2003.
The UK AAIB is responsible for and will administer the release of the final investigation report into this incident.
Any enquiries relating to the investigation should be directed to the AAIB at: www.aaib.gov.uk
Final report
The occurrence
On 9 February 2020, a Qantas Airways Boeing 787-900, registered VH-ZND, departed on a flight from London Heathrow Airport, United Kingdom to Perth Airport, Australia. Shortly after initiation of aircraft rotation,[1] the flight crew received a caution message indicating that the tail strike prevention system had been triggered. After performing the relevant checks the flight crew returned the aircraft for an overweight landing at Heathrow Airport.
Investigation
The United Kingdom Air Accident Investigation Branch (AAIB) was responsible for the investigation into this occurrence. As Australia is the State of Registration of the aircraft, the AAIB requested appointment of an Accredited Representative from the ATSB.
To facilitate this request, the ATSB initiated an external investigation under the provisions of the Transport Safety Investigation Act2003.
Conclusion
The AAIB investigation concluded that, during conditions of strong and gusty winds, a high pitch rate near lift-off caused the trail strike sensor to contact the runway surface. This resulted in activation of the aircraft’s tail strike prevention system and generation of an Engine Indication and Crew Alerting System TAIL STRIKE message. While the tip of the sensor was abraded due to contact with the runway, no further damage was found.
Any further information regarding this investigation should be directed to the AAIB via: enquiries@aaib.gov.uk
_____________
The information contained in this update is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the AAIB investigation of the occurrence.
At about 0438 local time on 29 February 2020, in darkness and clear visibility, the inbound fishing vessel Sandgroper collided with the outbound self-discharging bulk carrier Accolade II, off the entrance to Port Adelaide, South Australia. The collision occurred within port limits shortly after Accolade II had exited the Port Adelaide channel and resulted in significant structural damage to Sandgroper and minor damage to Accolade II. There were no injuries reported on either vessel.
What the ATSB found
The ATSB found that a proper lookout using all available means was not being maintained on board either vessel in the time leading up to the collision. Consequently, neither vessel was aware of the risk of the collision posed by the other until shortly before the collision when it was too late to take effective avoiding action.
Accolade II’s bridge team did not have a complete appreciation of the traffic situation and of the risk of collision outside the port channel before the ship exited the channel. In particular, effective use was not made of radar and a dedicated look-out was not posted in darkness.
Sandgroper’s skipper initially sighted Accolade II while the ship was still in the channel. However, a proper look-out was not subsequently maintained using all available means, including radar and radio. As a result, Sandgroper's skipper was not aware that Accolade II had exited the port channel and a close quarters situation with the ship was developing. While Sandgroper was not equipped with, nor required to be equipped with, an automatic identification system (AIS) transceiver, had one been fitted, it would have improved the vessel's detectability. That in turn would have increased the chances that the vessel was detected by Accolade II’s bridge team in sufficient time to avoid collision.
What has been done as a result
Following this incident Sandgroper was fitted with an AIS transceiver.
Accolade II’s managers (Inco Ships) advised that a navigational audit of the ship’s operations was conducted, which resulted in several recommendations to improve the ship’s bridge resource management practices.
Safety message
The safety of fishers and people in small boats continues to be of concern to the ATSB as collisions between trading ships and small vessels on the Australian coast continue to occur. Safety investigations into such collisions have consistently shown that the keeping of a proper lookout by all available means, including radar, radio and AIS, in accordance with the collision regulations could have prevented most of these collisions.
The occurrence
At about 1100 Central Daylight-saving Time[1] on 28 February, Sandgroper (Figure 1) departed its fishing grounds off Kangaroo Island, South Australia and began making its way back to North Arm Marina in Port Adelaide. The vessel was crewed by a skipper and two uncertificated crew (deckhands). The crew had been fishing at sea for the previous week when a hydraulic equipment malfunction resulted in the decision to return to port.
Figure 1: Sandgroper
Source: Ashworth Maritime Services
At 0226 on the morning of 29 February, Sandgroper was about 13 nautical miles (miles)[2] south‑west of Port Adelaide’s southern breakwater (Figure 2), on a heading[3] of about 020°, with steering in autopilot mode and a speed of about 5-6 knots. The skipper was on watch in the wheelhouse with the deckhands resting. At about 0300, the skipper handed over the watch to one of the deckhands in order to get some rest. The skipper instructed the deckhand to follow the course plotted on the chart plotter and to wake them if there were any concerns or when arriving at a nominated point marked on the chart plotter near Port Adelaide’s port limits. The skipper then lay down to rest on the wheelhouse bunk, aft of the conning position. Both the vessel’s very high frequency (VHF) radio units were set to maintain a listening watch on VHF channel 16.[4]
Meanwhile, Accolade II was alongside at Adelaide Brighton Cement’s K-Berth in Port Adelaide Inner Harbour. The ship was engaged in discharging a cargo of limestone loaded earlier that day at Klein Point, South Australia.
Figure 2: Section of chart Aus 781 showing key locations and vessel tracks
Source: Australian Hydrographic Office, annotated by the ATSB using electronically recorded data
At about 0230, Accolade II’s first engineer woke the chief mate and provided 1-hours’ notice for the ship’s planned departure at 0330 for Klein Point. The chief mate went up to the ship’s navigation bridge (bridge) to complete the bridge pre-departure checklist. The checklist included checking that the ship’s radar[5] was on, testing that the ship’s whistle was operational and testing engine and steering gear controls. The checks also included confirming that one VHF radio was set to the port’s working channel (VHF channel 12), and that the ship’s planned departure time of 0330 was reported to the Flinders Ports Communications Tower (communications tower).[6]
At 0255, the chief mate woke the chief integrated rating (IR)[7] and shortly after, the master. By about 0310, the master had made his way to the bridge where he met the chief mate who was on his way down to deal with cargo paperwork and read the ship’s draughts. At 0320, cargo discharge was completed, and the ship’s departure draught recorded as 3.77 m forward and 4.97 m aft.
At 0327, the master contacted the communications tower on VHF radio and reported that the ship was departing its berth. The ship’s forward mooring station were manned by the chief mate and an IR while the aft mooring station was manned by the chief IR and another IR. By 0329, all mooring lines were cast off and, by 0339, the ship had completed its swing to the north and commenced its outbound passage to Klein Point through the Port Adelaide Inner and Outer Harbours. The crew at the mooring stations were stood down and the chief IR went up to the bridge to assume helmsman duties. The chief mate went back to the accommodation to finalise cargo-related paperwork while the other IRs attended to routine post-departure tasks on deck.
At about the time Accolade II was casting off, Sandgroper was about 6.8 miles south-west of Port Adelaide’s southern breakwater. The fishing vessel was on autopilot, still on a heading of about 020° and a speed of about 5-6 knots, with a deckhand on watch and the skipper resting.
By 0356, Accolade II was passing the reporting point at beacon number 39 in the Port Adelaide River at a speed of about 8.9 knots. The master reported passing beacon number 39 to the communications tower on VHF channel 12 and continued the ship’s passage with the helmsman steering.
At about 0415, Sandgroper’s deckhand sighted a red light off the port bow and, shortly after, woke the skipper. The deckhand handed over the watch including reporting the sighting of the red light on the vessel’s port bow. The deckhand then left the wheelhouse to rest while the skipper made a coffee.
At about 0420, Sandgroper entered Port Adelaide’s port limits. The weather at the time was fine, with light winds, calm seas, good visibility and no moon. The skipper checked the reported red light and assessed it to be the port sidelight of an outbound ship in the channel. He then identified the ship on the radar display, which was set on a range scale of 3 miles. The skipper assumed the ship would stay in the channel, and at about 0426 or very shortly after, altered Sandgroper’s course to starboard to stay out of the channel and avoid giving the impression of heading for the channel and thereby impeding the ship’s progress. The skipper then reduced the radar display range scale from 3 miles to 0.125 miles as the vessel progressed towards the port’s breakwater.
At about 0428, as Accolade II was approaching Port Adelaide’s southern breakwater, the chief mate arrived on the ship’s bridge. At about 0433, the ship’s course was altered to port and it exited the channel between beacons number 13 and 15 at a speed of about 9.1 knots. The master contacted the communications tower and reported that the ship was ‘…departing at beacon 13.’ The master then instructed the helmsman to change the ship’s steering from manual to autopilot. The helmsman changed the steering to autopilot and turned off two of the ship’s four steering motors, which was the usual practice for the sea passage.
Meanwhile, the chief mate increased the range scale of Accolade II’s radar display from 0.75 miles to 3 miles and selected the ‘Off Center’ function to provide for the maximum view on the display ahead of the ship. Accolade II’s radar immediately detected Sandgroper. The fishing vessel’s radar echo immediately began to paint on the ship’s radar display about 1.2 miles off Accolade II’s starboard bow, but the chief mate did not notice it.
At about 0434, the chief mate used the radar to select and display the automatic identification system (AIS)[8] target data of two vessels off the ship’s port bow. At about the same time, the master dismissed the helmsman who then left the bridge with a radio. At about 0435, the chief mate answered a call on the bridge telephone. The call lasted about a minute before the chief mate went back to familiarising himself with the navigational situation and adjusting bridge equipment, such as dimming lights, in preparation for taking over the watch from the master.
The collision
Just after 0436, the chief mate, who was standing by the steering console on the ship’s centreline, sighted a red light fine off the ship’s starboard bow. The chief mate crossed to the starboard side of the bridge, got a pair of binoculars to better observe the sighted light and moved to the port side of the bridge to avoid a visual blind sector created by the ship’s bucket elevator on deck. Meanwhile, the master, who was also alerted to the red light, crossed to the port side of the bridge to get another pair of binoculars and returned to the centreline. Both officers then recalled seeing both red and green sidelights of the vessel. By this time, Sandgroper was about 0.5 miles from the ship.
Just over a minute later, at 0437, Accolade II’s radar range scale was reduced from 3 to 1.5 miles. By this time, Sandgroper had closed to about 0.25 miles and the master instructed the chief mate to ‘…go more south…’. The chief mate switched over to manual steering and applied 15° of port rudder helm as the master repeated his instructions to go further south. The master went out on to the starboard bridge wing and their instructions to ‘...go more south…’ became increasingly urgent. The chief mate then applied full port rudder as the ship slowly began turning to port at a speed of about 9.4 knots. The chief mate also attempted to sound the ship’s whistle without success.
Meanwhile, on board Sandgroper, the skipper unexpectedly saw Accolade II’s green sidelight at very close range. The skipper quickly put the vessel’s propulsion full astern, but this had little effect. Shortly after 0438, Sandgroper collided with Accolade II’s starboard side, just forward of midships (Figure 3).
Figure 3: Sections of charts Aus 130 and Aus 138 showing sequence of the collision
Source: Australian Hydrographic Office, annotated by the ATSB using electronically recorded data
At about 0439, the master tried unsuccessfully to call Sandgroper on VHF channel 12. Meanwhile, the chief mate recalled the IR to the ship’s bridge and handed over the helm. The chief mate then issued helm orders to steady the ship’s heading to avoid close quarters situations with the two vessels on the ship’s port side. At about 0440, the master reported the collision to the port’s communications tower.
Shortly after, Sandgroper’s skipper called Accolade II on VHF channel 16. The masters of the two vessels then switched over to VHF channel 13 and exchanged details, confirmed that there were no injuries to anyone on either vessel and that neither vessel required assistance. Accolade II’s master then reported the collision to the ship manager by phone and, having assessed there was no significant damage, resumed the ship’s passage to Klein Point.
Sandgroper’s skipper telephoned the vessel’s manager to report the collision and was advised to resume its passage. By about 0830 that morning, Sandgroper was safely alongside at North Arm Marina.
Sandgroper sustained significant structural damage to the starboard bow (Figure 4) with some minor damage to the vessel’s port side as well. Additionally, Sandgroper’s anchor was lost from the vessel’s bow and was found lodged in Accolade II’s deck railings.
Figure 4: Damage to Sandgroper
Source: Australian Maritime Safety Authority and Inco Ships
Accolade II sustained relatively minor damage to deck structures and railings on the ship’s starboard side as a result of the collision (Figure 5).
Accolade II is a 108 m, self-unloading bulk carrier of 6,310 gross tonnage, built in 1982 by Carrington Slipways, Newcastle, New South Wales. The ship was owned by Adelaide Brighton Cement and, at the time of the collision, was managed and operated by Inco Ships. Accolade II was designed and built for the carriage of limestone from quarries at Klein Point, South Australia, across the Gulf St. Vincent, to Adelaide Brighton Cement’s facilities at Birkenhead, situated within Port Adelaide’s inner harbour.
Equipment and machinery
Accolade II was a Regulated Australian Vessel (RAV). RAVs are commercial vessels which operate (or can be operated) outside the Australian exclusive economic zone. RAVs are subject to the Navigation Act 2012 and are generally required to comply with the requirements of international conventions as given effect by the Australian Maritime Safety Authority’s (AMSA) marine orders.[9]Accolade II was equipped with the navigational and safety equipment required by the International Convention for the Safety of Life at Sea (SOLAS)[10] for a ship of its size and age.
The ship’s navigation equipment included a single radar, automatic identification system (AIS), gyrocompass, differential GPS and a bridge navigational watch alarm system.[11]Accolade II was also fitted with a Japan Radio Company (JRC) JCY 1850 simplified voyage data recorder (VDR).[12] The ship’s primary means of navigation was paper charts although it was also fitted with a chart plotter.[13]
The ship’s propulsion was provided by twin Fuji Diesel 6LG32X dual-fuel propulsion engines that used compressed natural gas as their main fuel, although they could also be operated with marine gas oil.
Radar
Accolade II was equipped with a single JRC JMA-5312-6 X‑Band[14] radar with automatic radar plotting aid (ARPA) and automatic target acquisition capability as well as data input from the AIS and GPS units.
SOLAS regulations prescribed radar carriage requirements for ships based on their gross tonnage. Most modern merchant ships of Accolade II’s size were required to be equipped with two radars. However, Accolade II was subject to the provisions of SOLAS regulations that were in force at that time of its construction, which only required that ships of 1,600 gross tonnage and upwards be fitted with a single, type-approved radar. The regulations allowed for ships constructed before 1 July 2002 to be fitted with equipment which fulfilled the requirements prescribed in the relevant regulations in force prior to 2002.
Crew
Accolade II was manned and operated by a crew of nine in compliance with the ship’s AMSA‑issued minimum safe manning document. The ship’s complement included two deck watchkeeping officers—a master and a chief mate—as well as three integrated ratings, a chief engineer, two first engineers and a cook. The ship’s crews operated on a 3-week roster and most personnel had been assigned to the ship for several years. Crew changes were staggered so that different crew began their 3-week duty periods at different stages of the 3-week roster period.
The master had about 32 years of seagoing experience and held an Australian master’s (unlimited) certificate of competency. The master had worked exclusively on Accolade II for the previous 6.5 years and had joined the ship 16 days before the collision. The master’s usual rank on board was as chief mate (with over 10 years’ experience in the rank) but he had acted in the role of master several times in the past, usually for about a week at a time. In this instance, he was acting in the role of master for the last week of his 3-week roster period. The master also held a marine pilotage exemption certificate (PEC) for Port Adelaide. The PEC was endorsed for night navigation and allowed the master to navigate Accolade II in the waters of Port Adelaide’s Inner and Outer harbours at any time without the need to take on a pilot.
The chief mate had about 15 years of seagoing experience, held a Philippines master’s (unlimited) certificate of competency and the equivalent Australian certificate of recognition. The chief mate had about 8 years’ experience in the rank, had worked exclusively on Accolade II for the previous 5 years and had joined the ship 2 days before the collision. The chief mate did not hold a PEC for Port Adelaide.
Operations
Accolade II generally conducted a daily return voyage between Port Adelaide and Klein Point.
The ship’s operations routinely involved a departure from Port Adelaide in the early hours of the morning with the exact time of departure varying depending on when cargo discharge was completed. The chief mate was usually woken about an hour before completion of cargo discharge/departure with the master usually woken about half-an-hour before departure. The chief mate assisted with unmooring operations, following which the master piloted the ship out of the harbour.
On exiting the channel, the chief mate usually took over the watch for the 4-hour sea voyage to Klein Point. The master returned to the bridge when the ship was approaching Klein Point and berthed the ship with the chief mate’s assistance. Once alongside, the chief mate was stood down while the master managed cargo loading operations, which usually took about 4 hours.
The chief mate was recalled for departure and then kept the sea watch for the passage back to Port Adelaide. The master returned to the bridge and took over the watch just before the ship entered the Port Adelaide channel (near beacon number 13). The chief mate then assisted with bringing the ship alongside and with mooring operations. Once alongside, both the master and chief mate stood down while the ship’s cargo was discharged, which usually took about 8 hours.
Sandgroper
Sandgroper is a steel-hulled trawler built in 1978 in Johnsonville, Victoria. The vessel was owned by Pescatore Di Mare and, at the time of the collision, managed and operated by Southern Fisheries Group. The vessel operated out of the Government-owned North Arm Marina, a commercial fishing harbour located in a narrow channel off the Port Adelaide river, south of Torrens Island.
At the time of the collision, Sandgroper was a class 3B domestic commercial vessel (DCV) and was equipped with navigational and safety equipment required for an ‘existing’ class 3B DCV.[15]
The trawler’s wheelhouse was equipped with a Furuno 1942 Mark-2 radar, GPS, echo sounder and two VHF radios, both with dual watch capability. Sandgroper was not equipped with AIS or VDR, nor was it required to be (see the section titled Automatic identification system). Additionally, the trawler was equipped with a vessel monitoring system (VMS)[16] required by the Australian Fisheries Management Authority (AFMA).
Sandgroper was crewed and operated by a crew of three – a skipper and two uncertificated crew – in compliance with the applicable conditions in the vessel’s AMSA-issued Certificate of Operation. The skipper had over 28 years’ seagoing experience and held an Australian master’s (<24 m, near coastal) certificate of competency as well as a marine engine driver’s (Grade 3, near coastal) certificate of competency. The skipper had operated out of Port Adelaide for more than 20 years.
International regulations for preventing collisions at sea
The look-out
The International Regulations for Preventing Collisions at Sea, 1972, as amended (COLREGs) provide internationally‑agreed rules and measures to prevent collisions. The COLREGs generally apply to all vessels at sea, including fishing vessels. The COLREGs include requirements for keeping a look-out, assessing risk of collision with other vessels as well as the conduct and responsibilities of vessels in preventing collisions.
With respect to keeping a lookout, Rule 5 of the COLREGs (Look-out), states:
Every vessel shall at all times maintain a proper look-out by sight and hearing as well as by all available means appropriate in the prevailing circumstances and conditions so as to make a full appraisal of the situation and of the risk of collision.
The rules required that a lookout be kept not only by sight and hearing, but by all available means including radar, AIS, and information from other sources such as port radio broadcasts and ship‑to‑ship or ship‑to‑shore calls.
The ‘prevailing circumstances and conditions’ include various factors that should be considered when keeping an effective lookout. While not explicitly identified in the rule on the look-out, many of these factors were identifiable elsewhere within the COLREGS. For example, Rule 6 (Safe speed) listed several factors that were also relevant to the keeping of a lookout. Factors relevant to keeping an effective lookout include the:
state of visibility and time of day (day, night or twilight)
background lights (shore lights or back scatter from own lights)
expected traffic in the area (open sea, coastal passage, port or harbour)
traffic density, including concentrations of fishing and other vessels
characteristics, efficiency and limitations of radar (including its range and any interference)
constraints imposed by the radar range scale in use.
Other relevant factors include the availability, type, capability, and limitations of the AIS units of the vessels involved, available local knowledge and information, and the availability of traffic information via radio (ship‑to‑ship calls, all ship broadcasts and schedules). A number of the factors listed above are interrelated. For example, the use of radar significantly enhances keeping a lookout, particularly during darkness or when visibility is restricted by fog, rain or other conditions.
The COLREGs made specific mention of the proper use of radar equipment to obtain early warning of the risk of collision. The regulations also warned against making assumptions based on scanty information. The keeping of a proper lookout enables the risk of collision to be assessed in sufficient time for early and appropriate action to be taken.
Navigation lights
The COLREGs also described the requirements for vessels to exhibit specific lights (navigation lights) from sunset to sunrise. These lights were generally dependent on vessel length with some additional lights required depending on the type/purpose of the vessel or under certain circumstances and conditions.
Accolade II was required to display a white masthead light forward, a second masthead light abaft of, and higher than the forward one (mandatory for vessels 50 m or more in length), sidelights, and a stern light.
Sandgroper was not engaged in fishing at the time of the collision and therefore was required to display a single masthead light, sidelights and a sternlight.
At the time of the incident, both Accolade II and Sandgroper were probably displaying the required navigation lights for power-driven vessels of their size while underway. Additionally, neither vessel was displaying other lights, such as working lights or deck lights, that could obscure or be mistaken for regulation navigation lights or otherwise be an impediment to sighting and identifying navigation lights.
Signals to attract attention
The COLREGs required that vessels carry equipment to make sound signals for manoeuvring and warning purposes as well as to attract attention. Depending on size, a vessel may be required to carry a whistle, a bell and/or a gong.[17]
Accolade II was equipped with a pneumatic whistle fitted on the main mast. The whistle could be operated from six different locations, including from buttons on the bridge and bridge wings. Accolade II’s chief mate reported that when he attempted to sound the ship’s whistle to attract Sandgroper’s attention before the collision, he probably did not hold the button down long enough for it to sound. Accolade II was also equipped with an Aldis lamp[18] that was not used to attract attention because of the lack of available time.
Sandgroper was equipped with a manually operated horn. However, no attempt was made to use it, probably due to the rapid sequence and unexpected nature of the collision.
Accolade II’s look-out
Accolade II’s safety management system (SMS) included procedures for the navigation and operation of the ship. The procedures stated that the collision regulations as well as other international and local regulations relating to safe navigation were to be strictly complied with. They also noted that the primary reference documents for the operation of the ship at sea included:
the COLREGs
Standards of Training, Certification and Watchkeeping for Seafarers (STCW) Code[19]
AMSA’s Marine Order 28 (Operations standards and procedures)[20]
Together, these documents and publications, referenced in Accolade II’s procedures, comprehensively dealt with the subject of watchkeeping and the look-out.
The STCW Code provided mandatory watchkeeping standards applicable to ‘seagoing ships’ and required that a proper lookout be maintained at all times in compliance with the COLREGs. The Code required that the lookout be able to give full attention to lookout duties and not be assigned or undertake any duties which could interfere with that task. It also clarified that the duties of a lookout and helmsperson on a ship are separate. While the Code permitted the watchkeeping officer to be the sole lookout in daylight (in good conditions), it implied that a separate, dedicated lookout was to be posted in darkness.
Accolade II’s master’s standing orders made it clear that during the hours of darkness, the minimum manning requirement for the bridge was a qualified watchkeeping officer and one integrated rating (IR) as a lookout. The orders also clarified that the lookout should not be assigned any other tasks, although they could be absent from the bridge for brief periods to perform tasks such as a fire and safety round.
The Bridge Procedures Guide is a publication that aims to reflect best practice on subjects such as passage planning and watchkeeping, including on the subject of the look-out, and is widely used internationally to support shipboard safety management systems. The guide and its content are consistent with the requirements of COLREGs and the STCW Code.
On the morning of the collision, when Accolade II departed the berth at about 0339, the ship’s bridge was manned by a watchkeeping officer (the master) and a helmsman (an IR). The pilot‑exempt master (with the helmsman steering) navigated the ship in darkness within the confines of the Port Adelaide River for about 50 minutes before the chief mate joined them on the bridge at about 0428. As such, for the duration of the ship’s passage within the harbour in darkness, there was no separate, dedicated look-out posted as required.
Once on the bridge, the chief mate performed a number of tasks to become familiar with the navigational situation in preparation for taking over the watch. While the chief mate was pre‑occupied with these tasks, the IR (helmsman) was dismissed from the bridge instead of being retained as a dedicated look-out.
Events and conditions on board Accolade II
On departure from the berth, Accolade II’s radar display was centred, north-up and in relative motion mode on a 0.75 nautical mile (mile) range scale. A variable range marker (VRM) was turned on and set to a range of 1.005 miles, but no electronic bearing line (EBL) was turned on. The radar’s heading input was sourced from the gyrocompass while speed input was from the GPS. The radar’s functionality allowed the ship’s passage plan waypoints to be input to display the ship’s planned track, but this was not used. Target vectors were set to ‘True’ for a duration of 3 minutes.[22] The ‘Trails’ function was off. This function displays the recent history (or past track) of a target as an echo trail or afterglow, making it conspicuous while distinguishing it from inconsistent echoes, such as from sea clutter or from stationary targets such as beacons (depending on whether true motion trails or relative motion trails have been selected).[23].
During the bridge pre-departure checks, the cursor was moved to the right of the display, over the AIS information menu item (Figure 6). The cursor’s position and other radar settings remained unchanged for Accolade II’s passage through Port Adelaide River and channel.
Figure 6: Set-up of Accolade II's radar as it exited the channel at 0433
The radar display was centred on a 0.75 mile range scale and that Sandgroper’s radar echo was not visible with these settings.
Source: Accolade II’s VDR, annotated by the ATSB
Table 1 and Figure 7 below provide a brief sequence of the events leading up to the collision referenced against relevant radar and audio data from the ship’s VDR.[24]
Table 1: Sequence of events referenced against Accolade II's VDR radar and audio data
Time
Event/action
0357
· Accolade II’s master reported passing beacon number 39 to tower
0428
· Chief mate arrived on bridge and engaged in general conversation with master and helmsman
0433:42
· Accolade II’s master reported exiting channel between beacons number 13 and 15 (Figure 6)
0433:47
· Radar display range scale increased from 0.75 miles to 3 miles
0434:02
· ‘Off Center’ view selected
· Sandgroper’s radar echo appeared at a range of about 1.2 miles (Figure 8)
· Chief mate selected AIS target data of a vessel on Accolade II’s port side
0434:26
· Helmsman dismissed from bridge
0434:47
· Chief mate selected AIS target data of a second vessel on Accolade II’s port side
· Sandgroper’s radar echo was now at a range of 1 mile from Accolade II
0434:55
· Chief mate answered bridge phone
0435:56
· Chief mate completed phone call
0436:45
· Chief mate reported sighting a ‘small fishing vessel’ to master
· Sandgroper’s radar echo indicated that the vessel was now at a range of 0.5 miles
0437:32
· Radar display range scale decreased to 1.5 miles
· Sandgroper’s radar echo indicated that the vessel was now at a range of 0.25 miles
0437:46
· Master ordered the chief mate to ‘go more south…’
0438:02
· Ship’s heading began to alter to port (Figure 9)
0438:32
· Sandgroper collided with Accolade II.
Figure 7: Section of chart Aus 138 showing events leading up to collision
Note that Sandgroper’s actual track between 0426 and 0434:02 is an approximate track as there was no positional data available for the vessel between these times
Source: Australian Hydrographic Office, annotated by the ATSB using electronically recorded data
Sandgroper first appeared on Accolade II’s radar display at about 0433 (Figure 8). However, no one on the bridge detected the fishing vessel until about 3 minutes later when the chief mate sighted its port sidelight. In those 3 minutes, the chief mate was pre-occupied with tasks such as adjusting radar settings, acquiring AIS icons of vessels on the radar, dimming lights and getting accustomed to the darkness in preparation to take over the watch.
About 1 minute of the chief mate’s time was taken up attending to a phone call. Meanwhile, the master recalled concentrating on navigating the ship clear of the channel and beacons (rather than checking outside the channel for traffic, either visually or using the radar). The master may have been experiencing a degree of cognitive tunnelling, which is an inattentional blindness where one becomes overly focused on some variable other than the present environment (Mack and Rock, 1998; Most, 2010).
Figure 8: Sandgroper's first appearance on Accolade II's radar at 0434:02
The radar image at 0434:02 shows that as soon as the range scale was increased from 0.75 miles to 3 miles and the ‘Off Center’ view was selected, Sandgroper’s radar echo immediately became visible on the radar display.
Source: Accolade II’s VDR, annotated by the ATSB
Additionally, the repetitive nature of the ship’s voyage may have induced a sense of complacency in the ship’s officers. One behavioural definition of complacency is trending behavioural variation that eventually exceeds safety boundaries (Hyten and Ludwig, 2017). This variation can be influenced by habituation. The master and chief officer had both worked on Accolade II for several years, executing the same voyage almost daily, to the point where it became a highly practiced activity.
Highly practised activities become automatic and require less attention than new or slightly practiced activities. Automatic processes occur without intention, taking place without effort. When a person is using automated processing (sometimes referred to as being on autopilot), they are sometimes ‘out of the loop’. It is recognised that to have good situational awareness, a monitoring operator needs to be ‘in the loop’, in order to notice anomalies.
Figure 9: Accolade II's radar display immediately before collision at 0438:02
Source: Accolade II’s VDR, annotated by the ATSB
Bucket elevator
The cargo system on board Accolade II comprised a single hold, two longitudinal scraper conveyors, a transverse scraper conveyor, a shuttle belt conveyor and a bucket elevator. The bucket elevator was located on the starboard side, just forward of midships. The 2 m wide elevator extended about 8.5 m above the ship’s main deck. This created a visual blind sector across the view of the sea surface as seen from the ship’s bridge (Figure 10).
SOLAS regulations required that any blind sector caused by cargo gear outside of the wheelhouse forward of the beam that obstructs the view of the sea surface as seen from the conning position, should not exceed 10°. Additionally, SOLAS stated that each individual blind sector obstructing the view of the sea surface from the conning position, forward of the bow to 10° on either side, should not exceed 5°.
Figure 10: Views from different positions on Accolade II's bridge
Source: Inco Ships, annotated by the ATSB
Figure 11: Bucket elevator visual blind sectors
Source: Inco Ships, annotated by the ATSB
The bucket elevator had been documented in several of the ship’s annual navigational audits as a known visual obstruction. As such, the blind sector created by the elevator was a known factor that the ship’s crew were aware of and one they routinely allowed for.
While Sandgroper might have been temporarily visually obscured by the bucket elevator, it did not pose a significant impediment to detecting the vessel if an effective visual lookout had been kept. The blind sector would only have affected observers near the starboard extremities of the ship’s bridge with visibility for observers elsewhere on the bridge unaffected. In any case, the bucket elevator had no effect on the performance of the ship’s radar.[25]
Sandgroper’s look-out
Sandgroper’s SMS included procedures on passage planning and watchkeeping which stated that the COLREGs were to be complied with at all times.
Sandgroper’s skipper was alerted to the presence of Accolade II by the deckhand’s sighting of the ship’s red sidelight. The skipper assessed that the ship was in, and would remain within, the channel. Due to that expectation, the potential for collision with the ship was probably not anticipated. Sandgroper’s skipper may have been experiencing an expectation bias in expecting Accolade II to continue down the channel. Expectation bias can occur when an individual's expectations about an outcome influence the perception of one's own or others’ behaviour (Williams and others 2012).
The skipper reported that following the course alteration and reduction of the radar range scale (from 3 miles to 0.125 miles), no vessels were sighted either visually or on radar until the collision. At the reduced radar range scale, the skipper would only have been able to see radar echoes within about 230 m around the vessel. The skipper also reported that the presence of lights on the shoreline made it difficult to visually distinguish Accolade II’s navigation lights.
Sandgroper was within port limits when Accolade II’s master broadcast the message to the communications tower that the ship was exiting the channel at beacon number 13. Sandgroper’s skipper did not hear this VHF broadcast as a listening watch on channel 12 was not being maintained. Although the vessel was equipped with two VHF radio units, a listening watch was being maintained only on VHF channel 16 as was the skipper’s usual practice. The port rules did not require fishing vessels to report to the communications tower and the skipper could not recall any past communications or interaction with the tower.
Automatic identification system
The automatic identification system (AIS) is a maritime communications device that uses the VHF radio frequency band to transfer data, including a vessel’s course, speed and other dynamic and static data. The system enables AIS-equipped vessels and shore-based AIS stations to send and/or receive identification information that, in addition to the AIS unit, can be displayed on an electronic chart and compatible radar. The information received can be used to assist the watchkeeper in making a full appraisal of the situation and of the risk of collision.
The Australian Maritime Safety Authority (AMSA) is responsible for the safety of domestic commercial vessels (DCVs). Under the National Law,[26] the National Standard for Commercial Vessels (NSCV) set out the standards for vessel survey, construction, equipment, design, operation, and crew competencies for DCVs.
The NSCV required that class 3B vessels carry an AIS Class B receiver/transmitter unit. However, ‘grandfathering’ arrangements allowed older DCVs (built before July 2013) to continue to operate under the requirements that existed before the introduction of the National Law and NSCV. As an ‘existing vessel’ built in 1978, Sandgroper was not required to have an AIS unit fitted to comply with survey requirements, and an AIS unit was not fitted on the vessel at the time of the collision.
Use of AIS for collision avoidance
The use of AIS can enhance situational awareness and can assist in target tracking. AMSA considers the use of AIS to transmit accurate data and to locate targets as a way to keep a proper lookout. AMSA also encouraged operators to help improve the detectability of their vessels by transmitting AIS data.[27] However, it is also important to note the use of AIS cannot replace the need for a visual lookout. Additionally, AIS target tracking data should be treated with caution for collision avoidance for which radar plotting data and compass bearings of targets remain the primary assessment tools.[28]
Fatigue
Fatigue has been defined as decreased capability to perform mental or physical work, produced as a function of inadequate sleep, circadian disruption, or time on task (Brown, 1994). Factors that contribute to fatigue-impaired work performance include:
the duration of a duty period
inadequate sleep
circadian effects
the type or nature of the task being undertaken (workload)
the work environment.
Fatigue can have a range of effects on human performance, such as decreased short-term memory, slowed reaction time, decreased work efficiency, reduced motivational drive, increased variability in work performance, and increased errors of omission (Battelle Memorial Institute, 1998).
An AMSA safety awareness bulletin[29] summarised fatigue among seafarers as follows:
The nature of vessel operations means seafarers are exposed to conditions which lead to fatigue. Insufficient sleep, night work, irregular and long working hours, monotonous tasks, high work demands are all frequently present in seafaring jobs. These are the primary factors that lead to fatigue. The need to manage the risk of fatigue - both at the individual and management level - is critical.
The ATSB has also highlighted the issue of fatigue through previous investigation findings and specific publications, including for the fishing vessel sector.[30]
Accolade II
The crew on board Accolade II were required to comply with the rest hour requirements of the STCW Code (as given effect by AMSA’s Marine Order 28). The ship’s SMS included a procedure that defined fatigue, provided guidance on recognising the signs of fatigue and reflected the rest hour requirements of the STCW Code.
The SMS also required crew to record their daily hours of work and rest on board. The rest hour records for Accolade II’s master and chief mate showed that their rest hours complied with the minimum rest hour requirements of the STCW Code. While self-assessment of fatigue is not a reliable indicator of alertness, both reported feeling very alert and well rested.
The sleep environment on the ship was reportedly comfortable and hence suitable for achieving restorative rest. A review of the ship’s voyage reports for January and February 2020 showed at least two instances in each month when the ship’s sailing was delayed to ensure compliance with rest hour requirements. The reports also showed no voyage on 27 February 2020 (2 days before the collision), with the day marked as a ‘Reset day’.
FAST analysis
A roster analysis of the master and chief mate’s work and rest times was conducted using the Fatigue Avoidance Scheduling Tool (FAST) bio-mathematical model to assess fatigue/alertness, and the effect on performance.
The FAST analysis showed that while there may have been a slightly higher fatigue risk for the chief mate, overall, the analysis did not appear to show that levels of fatigue likely to influence performance were present for either the chief mate or the master. The accuracy of the analysis was influenced by the nature of the ship’s fatigue management system. The recorded hours of rest indicated rest opportunity and not the exact hours of sleep, which had to be estimated.
Sandgroper
As a DCV, Sandgroper and its crew were not subject to the minimum rest hour requirements of the STCW Code. There were no prescribed minimum hours of rest and no requirement to record hours of rest. However, AMSA’s Marine Order 504[31] required that ‘the risk of fatigue of the master and crew’ be considered, among other factors, when determining the number of crew required to safely carry out a vessel’s operations. The AMSA website also provided guidance on managing crew fatigue on DCVs including practical information on the causes, effects and management of fatigue and its risks. Owners and masters were advised to take all practicable steps to ensure the safety of the vessel and crew, and that the crew were to be involved in the management of fatigue and the risks to safety.
Sandgroper’s SMS included some basic information on managing crew fatigue and required the skipper to manage crew fatigue. Guidance for crew stated they were to try and achieve 7–9 hours of sleep in every 24 hours.
Sandgroper’s AFMA fishing logs showed that the crew usually shot their fishing gear from about 0230-0430 and hauled the gear between 0930-1330 with rest opportunity obtained in between these times. This meant there was a total of about 18 hours of rest opportunity in every 24-hour period.
On the night before the collision, the skipper reported resting from about 1700–2300 followed by taking the watch until about 0300. The skipper then handed the watch to the deckhand and slept for about an hour until woken shortly after 0415.
Sandgroper’s skipper self-reported feeling ‘…well rested as far as a fisherman gets rest’ and alert. The skipper reported consuming at least one cup of coffee after waking that morning.
FAST analysis
The accuracy of the FAST analysis for Sandgroper’s skipper was influenced by the absence of recorded hours of work and rest, and no reliable record of sleep obtained in the days preceding the collision. The analysis was conducted based on estimates of sleep obtained and the AFMA fishing logs. Overall, the analysis did not appear to show that levels of fatigue likely to influence performance were present for the skipper.
Summary
Based on the available evidence, it was considered unlikely that levels of fatigue likely to influence performance were experienced by either vessel’s crew. However, there were several relevant risk factors present that were conducive to an environment in which fatigue could develop or that could have increased the chances of crew being fatigued.
Port Adelaide
Port Adelaide is the main port of South Australia handling a range of cargo including grains and seeds, limestone, containers, dry and wet bulk, vehicles, and general cargo. The port was owned and operated by Flinders Ports which was formed in 2001 when the Flinders Ports consortium successfully acquired seven ports that were privatised by the South Australian Government.
Port Adelaide port rules
Flinders Ports’ published rules for Port Adelaide that were intended to inform commercial users of the port of their responsibilities for the safe navigation of vessels within the port. The rules did not specifically define a ‘commercial user’ but, according to Flinders Ports, it did not include fishing and recreational vessels.
The rules documented three entry and exit points for the channel—at the entrance beacon, beacon number 5 and beacon number 9—depending on the vessel’s draught. Fishing vessels and recreational vessels could enter/exit the channel at any point. While Accolade II’s entry/exit point between beacons 13 and 15 was not among those listed, the ship was allowed the liberty of entering/exiting the channel at this location owing to its long history of operating in the port and its generally shallow draught.
At the time of the collision, Port Adelaide was not authorised as a Vessel Traffic Service (VTS) Authority. A VTS is established to improve the safety and efficiency of vessel traffic and to protect the environment. Ports may apply to establish a VTS when the volume of traffic or degree of risk justifies the service. Port Adelaide operated a communications tower (Flinders Ports Communications Tower) that kept a 24/7 listening watch on VHF channels 16 and 12. Channel 12 was used for ship/shore operations, information, transit advice and ship-to-ship traffic.
Flinders Ports rules required all pilots, masters and exempt masters to communicate with the tower at designated reporting points on channel 12. The rules also stated that vessels should monitor VHF channel 12 at all times in port limits for information.
Flinders Ports clarified to the ATSB that the port’s reporting requirements and the requirement to monitor the port’s working channel (channel 12) within port limits only applied to commercial vessels. As such, fishing vessels and recreational vessels were not required to report nor were the rules regarding a listening watch on channel 12 applicable to them.
Port Adelaide VTS
On 4 December 2020, about 8 months after the collision, Port Adelaide was authorised as a VTS authority with a new call sign of ‘Adelaide VTS’. Adelaide VTS was authorised to provide services, including a traffic organisation service (TOS). The TOS is a service to prevent the development of dangerous marine traffic situations and to provide for the safe and efficient movement of vessel traffic within the declared VTS area.
Adelaide VTS required all vessels over 150 gross tonnage (or where there was no gross tonnage, vessels 35 m or greater in length) to participate in the VTS. The rules required all commercial vessels to comply with VTS reporting requirements and Adelaide VTS can request any other vessel in the coverage area to participate. However, fishing and recreational vessels were generally not required to report.
While VTS rules stated that all vessels were to maintain a listening watch on VHF channels 12 when within or approaching Port Adelaide port limits, Flinders Ports advised that the rule only applies to commercial vessels. However, all vessels, including fishing and recreational vessels were encouraged to monitor the channel through the port’s safety outreach programs to educate and inform the public. The South Australian Department of Planning, Transport and Infrastructure (DPTI) also published a recreational boating safety handbook and boating safety advice, which included material on radio communication and listed channel 12 as among the channels usually used for port communications.
Rules in other ports
Local rules covering operations within port waters vary depending primarily on the port’s specific risk profile and resources. The applicability of the various rules also varies from port to port but are usually applied on the basis of factors such as vessel type, length or tonnage. Consequently, in each port, certain rules apply to vessels meeting certain defined criteria and not to others as the following examples show.
The Port of Fremantle, Western Australia, required all vessels 35 m or greater in length and all commercial vessels, regardless of length, to participate in the VTS when operating in the coverage area. It required all vessels navigating within port limits or at an anchorage within the port to maintain a continuous listening watch on the port’s working channel.
The Port of Melbourne, Victoria, required all vessels 50 m or greater in length to report at designated points/times and maintaining a continuous listening watch on the VTS working frequency. Non-recreational vessels less than 50 m in length (including fishing vessels) were required to watch the VTS working frequency and to report to VTS if 35 m or greater in length. Recreational vessels less than 50 m in length and equipped with VHF radio were required to watch the VTS working frequency when operating in port waters.
The ports of Weipa and Cairns in Queensland required all vessels, whether commercial or recreational, to maintain a listening watch on channel 16 and, if equipped, channel 12 while within the ports’ pilotage areas. Additionally, all ships greater than 24 m in length had to obtain approval from VTS before entering, leaving or manoeuvring within the pilotage area and all ships between 10 and 24 m in length were required to advise VTS before entering, leaving or manoeuvring within the port’s pilotage area.
The Port of Darwin, Northern Territory, although not serviced by a VTS, required all vessels of 20 m or greater in length, vessels carrying more than 12 passengers and certain other vessels to participate in the port’s traffic organisation service. Other vessels were encouraged to participate voluntarily.
As evident from the examples above, port rules and their applicability vary depending on various factors and there was nothing unusual in the content or applicability of Port Adelaide’s rules.
Similar occurrences
Over the last 30 years, at least 68 collisions between trading ships and small vessels have been reported to the ATSB or its predecessor. Of these, at least 40 have been investigated. The failure to keep a proper and effective lookout and/or take early and effective avoiding action in accordance with the COLREGs were recurrent contributing factors that could have prevented most of these collisions.
Collisions between large trading ships and small vessels, particularly fishing vessels, continue to occur off the Australian coast. In these collisions, a fishing vessel, being significantly smaller than a ship, almost always comes off worse and sometimes with severe consequences. For example, the 2000 collision between Star Sea Bridge and the fishing vessel Sue M, off Evans Head, New South Wales, and the 2003 collision between Asian Nova and the fishing vessel Sassenach off Townsville, Queensland, both resulted in the loss of life and of the vessels themselves.
While the measures in place to prevent such collisions might appear straightforward, the recurrence of similar contributing factors indicates that further effort is required from operators and crews to implement these measures. In addition to its safety investigation reports into collisions, the ATSB has published a number of safety bulletins to highlight collision risks and educate all seafarers. These documents and other safety information about marine safety issues are available on the ATSB website.
At about 0438 local time on 29 February 2020, in darkness and clear visibility, the inbound fishing vessel Sandgroper collided with the outbound self-discharging bulk carrier Accolade II, within port limits, about 1.5 NM south-west of the entrance to Port Adelaide, South Australia. The collision resulted in significant structural damage to Sandgroper and minor damage to Accolade II. Neither vessel identified that a risk of collision existed with the other until it was too late for effective avoiding action to be taken.
Look-out
Accolade II
In the time leading up to the collision, both the master and chief mate were occupied with tasks demanding much of their attention. The master was focused on navigating clear of the shipping channel while the chief mate was busy with various activities, including preparation to take over from the master. There was no dedicated look-out who could devote their full attention to sighting and reporting targets, including Sandgroper. As a consequence, the master and chief mate only sighted the fishing vessel moments before the collision.
Accolade II’s radar offered an additional means of detecting Sandgroper at an early stage. However, the radar’s initially small display range scale setting did not allow for an appreciation of the situation outside the channel before the ship exited it. Further, when the scale was eventually adjusted to one more conducive to detecting Sandgroper’s presence, the chief mate focussed on the automatic identification system (AIS) icons of two other vessels displayed on the radar display at the expense of Sandgroper’s radar echo. In addition, useful radar tools such as the trails function, which could have made Sandgroper’s radar echo more conspicuous and increased the chances of the vessel being detected were not used.
In summary, Sandgroper was not detected by anyone on board Accolade II until it was too late for effective avoiding action to be taken. Had better use been made of the radar or a dedicated lookout been posted as required, it would have increased the chances of detecting Sandgroper early and allowed more time to take action to avoid collision.
Sandgroper
Sandgroper’s skipper sighted Accolade II early when it was in the channel and assumed, not unreasonably, that it would remain in the channel. On that basis, the skipper altered Sandgroper’s course to keep clear of the ship. However, the skipper then paid little attention to the ship and its movement probably due to expectation bias that the ship would follow the channel. Further, the radar range scale was reduced to the minimum and an effective visual lookout by sight was also not maintained.
While there was no explicit requirement for fishing vessels to monitor Port Adelaide’s VHF radio working channel, Sandgroper was equipped to do so. Had the skipper monitored the working channel, it might have provided forewarning that Accolade II was exiting the channel at beacon number 13 (contrary to the skipper’s assumption), and to the developing close-quarters situation.
Sandgroper’s radar and VHF radio were both available means that could have enhanced the skipper’s look-out and allowed for an improved appreciation of the situation. However, neither was used effectively to maintain a proper look-out. Consequently, Sandgroper’s skipper was not aware of the risk of collision until collision was imminent and it was too late for effective avoiding action.
Automatic identification system
Sandgroper was not fitted with an automatic identification system (AIS) transceiver unit, nor was it required to be. Had an AIS unit been fitted, it would almost certainly have improved the detectability of the fishing vessel and made it more conspicuous on Accolade II’s radar and chart plotter. The evidence in this case shows that Accolade II’s chief mate readily acquired and monitored the AIS icons of two other vessels on the radar display but not Sandgroper’s radar echo, which should have been of immediate concern.
In addition, the fitting of an AIS unit with a display on board Sandgroper would have given its skipper the means to detect Accolade II’s AIS-transmitted data thereby enhancing situational awareness and augmented the keeping of a proper look-out.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the collision between Accolade II and Sandgroper, off Port Adelaide, South Australia, on 29 February 2020.
Contributing factors
A proper lookout by all available means was not maintained on board Accolade II. In particular, radar was not used effectively, and the dedicated lookout required in darkness was not posted. Consequently, Accolade II's watchkeepers were not aware of Sandgroper's presence or of the risk of collision until shortly before the collision when it was too late to take effective action.
After initially sighting Accolade II, Sandgroper’s skipper did not maintain a proper lookout or assess the risk of collision using all available means, in particular the radar and radio. As a result, the skipper only saw the ship when collision was imminent and unavoidable.
Other factors that increased risk
Sandgroper did not have an automatic identification system (AIS) transceiver fitted, nor was one required to be fitted. An AIS transceiver would have improved the vessel's detectability and enhanced the ability of its crew to keep a proper look-out.
Other findings
Accolade II’s bucket elevator did not pose a significant impediment to the ability of the ship’s watchkeepers to detect Sandgroper.
Safety actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the marine industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out or are planning to carry out in relation to each safety issue relevant to their organisation.
The initial public version of these safety issues and actions will be provided separately on the ATSB website on release of the final investigation report, to facilitate monitoring by interested parties. Where relevant, the safety issues and actions will be updated on the ATSB website after the release of the final report as further information about safety action comes to hand.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future.
Additional safety action by Southern Fisheries Group
Southern Fisheries Group advised the ATSB of the following safety action taken in response to the collision:
Sandgroper was fitted with an automatic identification system
Skippers and crews were provided with education on Port Adelaide River traffic
All crew are now required to be on watch when approaching port.
Additional safety action by Inco Ships
Accolade II’s managers (Inco Ships) advised the ATSB that, following the collision, a navigational audit was undertaken to assess the performance and effectiveness of the ship’s bridge team and bridge resource management. Inco Ships advised that the audit resulted in several recommendations to improve Accolade II’s bridge resource management practices.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the master and chief mate of Accolade II
the skipper and deckhand of Sandgroper
Inco Ships
Adelaide Brighton Cement
Southern Fisheries Group
Australian Maritime Safety Authority
Australian Fisheries Management Authority
Flinders Ports
Ashworth Maritime Services
Lloyd’s Register.
References
Australian Maritime Safety Authority, 2017, Maritime Safety Awareness Bulletin, Issue 5, March 2017, Canberra, Australia.
Australian Maritime Safety Authority, 2018, Marine Order 504 (Certificates of operation and operation requirements — national law) 2018, Canberra.
Australian Maritime Safety Authority, 2020, Marine Notice 06/2020 Reducing the risk of collisions at sea, Canberra, Australia.
Australian Transport Safety Bureau, 2004, Safety Bulletin 04 – Fatigue and fishing crews, Canberra, Australia.
Battelle Memorial Institute. An Overview of the Scientific Literature Concerning Fatigue, Sleep, and the Circadian Cycle, 1998. (Report prepared for the Office of the Chief Scientific and Technical Advisor for Human Factors, Federal Aviation Administration, USA.).
Brown, I. D. (1994). Driver fatigue. Human Factors, 36(2), 298-314.
Hyten, C., & Ludwig, T. D. (2017). Complacency in process safety: A behavior analysis toward prevention strategies. Journal of Organizational Behavior Management, 37(3-4), 240–260.
International Maritime Organisation, Standards of Training, Certification and Watchkeeping for Seafarers (STCW) Code, 1995, as amended, IMO, London.
International Maritime Organization, 2020, The International Convention for the Safety of Life at Sea (SOLAS) 1974 as amended, IMO, London.
Mack A & Rock I 1998, Inattentional blindness, MIT Press Cambridge MA.
Maritime and Coastguard Agency, 2016, Marine Guidance Note (MGN) 324 (M+F), Navigation: Watchkeeping Safety – Use of VHF Radio and AIS, Southampton, United Kingdom.
Most SB 2010, What's "inattentional" about inattentional blindness?, Consciousness and Cognition, vol. 19, pp.1102-1104.
Williams JB, Popp, D, Kobak KA & Detke MJ 2012, The power of expectation bias, European Psychiatry, vol. 27, pp.1
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the master, chief mate, owner and manager of Accolade II
the master, deckhand and manager of Sandgroper
Australian Maritime Safety Authority (AMSA)
Flinders Ports.
Submissions were received from AMSA and Accolade II’s managers (Inco Ships). The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Glossary
JRC
Japan Radio Company
MO
Marine Order
NSCV
National Standard for Commercial Vessels
PEC
Pilotage Exemption Certificate
RAV
Regulated Australian Vessel
SA
South Australia
SMS
Safety Management System
SOLAS
The International Convention for the safety of Life at Sea, 1974, as amended
STCW
Standards of Training, Certification and Watchkeeping for Seafarers
VDR
Voyage Data Recorder
TOS
Traffic Organisation Service
VHF
Very High Frequency
VMS
Vessel Monitoring System
VRM
Variable Range Marker
VTS
Vessel Traffic Service
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 4 February 2020, an Airbus Helicopters AS 350 B3 was being operated in support of New South Wales National Parks and Wildlife Service activities. Winching of personnel and equipment was being conducted when the operating crewman detected a technical issue with the load cable of the hoist system fitted to the helicopter. The outer strands of the cable toward its termination into the hook assembly had loosened in respect of the inner core.
During a subsequent hoist operation to restore the cable integrity, the cable fractured at the hook assembly while under load, releasing the weight bag and hook assembly to the ground. There was no damage to the helicopter or injuries to personnel.
What the ATSB found
The ATSB found that variations in the operator’s stowage practices over an extended period of winching operations led to inadequate compression of the hook assembly and subsequent wear to the load cable. The wear damage was due to vibration and movement of the hook assembly during periods of helicopter operation. This led to a significant reduction in the cross-sectional area of the cable, fatigue and fracture of the strands and an associated reduction in cable strength.
It is likely that specific post-flight inspection requirements for the Breeze Eastern rescue hoist required in the Civil Aviation Safety Authority (CASA) Airworthiness Directive AD/SUPP/10 were not being adequately completed by the operator. The inspections were targeted at minimising wear damage to the load cable by ensuring correct stowage of the hook assembly at the end of each flight.
Finally, the operator’s method of cycle counting during operation of the rescue hoist led to an accumulation of cycles that significantly exceeded the helicopter manufacturer’s recommended life-limit. That exceedance probably compounded the level of wear damage sustained to the load cable.
What has been done as a result
The New South Wales National Parks and Wildlife Service (ParkAir) implemented a range of pro‑active safety actions since the occurrence, including:
In July 2020, ParkAir provided Breeze-Eastern Flight Line maintenance training for all staff including pilots, maintainers and rescue hoist crewman.
A measurement gauge is now used by crewman to determine whether the hoist has adequate compression in accordance with the pre- and post-flight requirements listed within CASA Airworthiness Directive AD/SUPP/10.
In January 2021, a revision of the ParkAir Flight Manual Supplement was accomplished to ensure cable inspection procedures requirements are now completed in accordance with CASA Airworthiness Directive AD/SUPP/10.
ParkAir have adopted the more conservative Airbus Helicopters method for hoist cycle counting and all hoist cables now have a 500 cycle life-limit.
Additionally, as a direct result of this occurrence and the release of ATSB’s Safety Advisory Notice SAN-2020-013-001, the following pro-active safety advice was released by organisations responsible for the design, manufacture, and regulation of helicopter rescue hoist systems:
Breeze-Eastern Service Information Letter (SIL 14 Maintenance) Breeze-Eastern Rescue Hoist Maintenance & Flight Line Inspections for BL-29700 Series, release date 6 April 2020
CASA Airworthiness Bulletin (AWB) 25-034 Helicopter Rescue Hoist Wire Rope – Wear, Fatigue and Failure, release date 22 April 2020
Airbus Helicopters Safety Information Notice (SIN) 3507-S-25 Fatigue failure of a BREEZE 450 Lbs hoist cable, release date 4 June 2020
European Aviation Safety Agency (EASA) Safety Information Bulletin (SIB) 2020-11 Helicopter Rescue Hoist Cable Failure, release date 11 June 2020.
Safety message
The ATSB advises all helicopter operators and flight crew involved in rescue hoist operations to review their current operational practices to ensure hoist operation and hook stowage are in accordance with the manufacturers’ published procedures.
In addition, it is recommended that the pre- and post-flight inspection requirements of the hook and cable assembly, along with any recurring scheduled maintenance of the hoist system are closely reviewed, to ensure that they are completed in accordance with the manufacturers’ instructions. Improper stowage of the hoist hook assembly can lead to excessive movement and accelerated wear of the cable, which if undetected, could have a fatal outcome.
Should any load cable exhibit an increased frequency of outer strand loosening requiring a condition operation, operators should be particularly mindful to check for narrowing or ‘necking’ of the cable at the ball end within the swivel hook assembly. This can signify that the cable has become damaged due to extreme wear and may no longer be safe to use.
Summary video
The occurrence
An Airbus Helicopters AS 350 B3, registered VH-UAH, was being operated by the New South Wales (NSW) National Parks and Wildlife Service (NPWS) Flight Operations Unit (ParkAir) in support of bushfire operations during the 2019/20 summer period. The helicopter had been repositioned from the ParkAir aviation base at Bankstown Airport to a NPWS depot at Bulga, NSW to provide aerial support to fire crews at the Springvalley fire-grounds, within the Blue Mountains National Park. During that period, the helicopter was operated by a single pilot and a crewman operated the rescue hoist.
On 2 February 2020, the crewman assigned to VH-UAH was exchanged with another ParkAir crewman who had mobilised to Bulga. At duty handover, the departing crewman identified that the rescue hoist was operating without issue, however the load cable was starting to exhibit loose wires and would need monitoring. Over the next two days of operation about 30 winches of personnel and equipment was conducted. During that period the replacement crewman identified that the condition of the load cable from the hoist was continuing to deteriorate.
The outer wire strands of the load cable toward its termination into the swivel hook had loosened in relation to the inner core. Such loosening can develop during repeated short-length cable deployment and retrieval cycles. The crewman reported that, in an attempt to rectify the looseness, the outer wires of the cable were massaged and manipulated as it was reeled in and wound onto the hoist drum during operation. Despite that, the looseness was unable to be rectified.
On 4 February 2020, at the conclusion of the daily operations and on return to the Bulga depot, the crewman recommended to the ParkAir senior pilot that a conditioning operation be accomplished. Cable conditioning was a specific procedure intended to tension the cable and realign the wires to restore the cable integrity. It was agreed that it would be completed the following day prior to the conduct of any further winching sorties.
On the morning of 5 February 2020, following a pre-flight inspection of the rescue hoist, the crewman and senior pilot commenced the conditioning operation. A 160 kg weighted bag was attached to the swivel hook and the helicopter was lifted into a low hover and flown to an open field adjacent the NPWS Bulga depot. The bag was suspended about 5 m above the ground and the helicopter lifted into a vertical climb at an equivalent rate as the cable was reeled out from the rescue hoist. This continued until the maximum reel out extension limits of the hoist system were reached, after which the cable was reeled in. At the conclusion of that first conditioning run the crewman identified that the cable had further degraded.
The conduct of an additional conditioning operation was agreed and during that operation while under tension and close to maximum reel out, the cable failed, releasing the weighted bag and swivel hook to the ground.
The crewman advised the pilot that the cable had failed and that the hook and bag had fallen. The pilot’s only reported perception of an anomaly was a slight tilt of the helicopter from the centre‑of‑gravity redistribution when the bag fell. Both crew members returned to the depot and recovered the bag and swivel hook for subsequent examination. There were no injuries to personnel or additional damage to the helicopter. A portion of the fractured cable and the general fitment of the rescue hoist to the AS350 helicopter is shown at Figure 1.
ParkAir immediate actions
Following the cable failure, the Chief Pilot and Senior Pilot distributed an internal notification to ParkAir staff advising of the occurrence. As an immediate measure, ParkAir contacted the hoist manufacturer and arranged for it to be examined. All further ParkAir winching operations were suspended until each system was inspected and had their cables replaced (with the exception of a single hoist that remained in service due to the recent fitment of a new load cable).
Figure 1: A NPWS ParkAir AS350 helicopter (left) displaying general fitment of the rescue hoist, and a close-up of the fractured cable (right)
The fractured cable was found protruding from the swivel hook assembly. Source: National Parks and Wildlife Service
Context
Operational overview
The New South Wales (NSW) National Parks and Wildlife Service (NPWS) Flight Operations Unit (ParkAir) utilised a fleet of four AS350 B3 helicopters to support field operations that included fire management, personnel insertion duties, feral animal and pest species control. Each ParkAir helicopter could be equipped with an electric-powered recue hoist. A fifth hoist, also operated by ParkAir, was used as back-up in case of an unserviceability. The hoists were used for aerial winching of personnel and equipment into confined areas.
Aircraft information
VH-UAH was an Airbus Helicopters AS350-B3 light utility helicopter manufactured in 2014. It was powered by a single turbine engine and depending on its internal cabin configuration, could transport up to six people. The helicopter had been fitted with a hoist that was attached to an externally mounted mechanical arm on the left side of the helicopter, adjacent to the rear cabin (Figure 1). The arm pivoted outward during use and also allowed the hoist to be stowed against the fuselage during forward flight.
Hoist information
Manufactured by Breeze-Eastern, the rescue hoist was a model HS-29700 and provided a means for the lowering and raising of a single person or equipment to and from the helicopter (Figure 2). The hoist was remotely operated by the crewmember using a controller and the pilot was also able to control the system if necessary.
The hoist was an approved modification for the helicopter. The instructions for continued airworthiness for the hoist were contained in the:
Breeze-Eastern Flight Line and Operations Manual[1]
Airbus Helicopters AS350B3 Master Servicing Manual.[2]
The HS-29700 hoist has an allowable lifting limit of 204 kg and contains a rotating drum onto which is spooled 50 m of useable wire cable that terminates with a swivel hook and bumper assembly. The cable speed can be varied[3] during operation and limit switches within the system automatically trigger to slow the hoist speed as the cable approaches the full-out, or full-in position. The bumper assembly near the swivel hook consists of a crushable rubber block and conical spring that is intended to compress as the cable is reeled in and the full-in limit switch is activated, stopping the hoist. Compression of the spring and bumper assembly is a design feature by the hoist manufacturer to ensure that the swivel hook is adequately homed after being reeled in.
The Breeze-Eastern maintenance manual contained the hoist operating instructions and guidance for continued airworthiness. The manual advised that when reeling in, the cable should be guided by hand, at full pendant thumbwheel deflection to the full in position. The manual provided the following cautionary statement:
WARNING: WHEN NOT IN USE, THE HOOK MUST BE HOMED COMPLETELY IN THE FULL IN POSITION TO AVOID FATIGUE OF THE CABLE NEAR THE BALL END DUE TO VIBRATION.
Hoist cable
The load cable was specified to be manufactured from 0.156-inch diameter corrosion‑resistant stainless steel into a 19-strand by 7-wire configured arrangement comprising an inner core and outer layer (Figure 2). To resist rotation during use, the outer strands were woven in the opposite direction to the inner core. A stainless-steel fitting with a spherical ball-end was swaged onto the termination of the cable to enable secure fitment of the swivel hook and bump stop assembly.
Cycle counting
The Breeze-Eastern hoist was designed with a mechanical counter that recorded each revolution of the drum. The number on the counter was required to be recorded in the hoist logbooks and a calculation provided the total number of hoist cycles accrued during each recurring maintenance period.
Breeze-Eastern used a method whereby the difference on the cycle counter between successive maintenance periods was divided by 264. One complete hoist cycle was equivalent to a full reel-out and then a full reel-in of the cable. This was equivalent to 264 revolutions of the drum being logged by the counter. The method was specific to Breeze-Eastern and did not consider the actual number of winch operations that had been completed. Breeze-Eastern recommended a 1,500‑cycle life-limit for their hoist cables. The following cautionary note was contained within the Breeze-Eastern hoist manual:
1500 hoist cycle recommended replacement criteria is under ideal laboratory conditions, and may not be representative of actual operating conditions, or usage.
Figure 2: Breeze-Eastern HS-29700 rescue hoist and cross-section of the load cable showing its 19 strand x 7 wire configuration
Source: Breeze-Eastern, annotated by ATSB
Recent maintenance
All significant inspections, including recurring maintenance, were conducted by ParkAir’s maintenance provider for the hoist. Records showed that the occurrence rescue hoist (serial number 203) was bought and first introduced into service by ParkAir in December 2011. Over the subsequent 9 years of operation, the hoist was installed onto various AS350 helicopters within the ParkAir fleet until being rotated onto VH-UAH in July 2019 where it remained in service. The hoist logbook contained cycle counter entries confirming that ParkAir had been using the Breeze‑Eastern method for recording usage of their rescue hoists.
The last recorded maintenance activity contained in the hoist logbooks was on 3 December 2019 at approximately 600 hoist cycles and indicated the accomplishment of a 3-month and 6-month repetitive inspection in accordance with the Breeze-Eastern HS-29700 maintenance manual. Along with various checks of the system for functionality, an inspection of the swivel hook assembly was indicated as complete with no recorded defects. The load cable had accrued 617 hoist cycles at the time of the cable failure.
Technical examination
Hoist cable from ParkAir AS350 B3 helicopter, VH-UAH
The rescue hoist and the fractured load cable were sent to the ATSB technical facilities in Canberra for further analysis, with senior personnel from ParkAir in attendance during the preliminary examination.
The construction of the cable confirmed it to be of the configuration and type specified by Breeze‑Eastern for the BL-29700 hoist. Measurements confirmed the cable to be of the correct diameter with a 19-strand by 7-wire arrangement. The specifications[4] required the load cable to be manufactured from an austenitic stainless steel with a minimum breaking strength of 980 kg.
The load cable fractured approximately 10 mm from the swaged ball end fitting that terminated into the swivel hook assembly (Figure 3). The diameter of the remnant cable stub had drawn down with ‘necking’ of the cable cross-section evident. Measurements also identified that the inner core had retracted between 50 to 60 mm from the outer layer. Those outer strands had splayed which was typical of an overload cable failure, while the inner core remained tightly gathered. A faint serial number was etched on the shank of the swaged fitting that was confirmed by Breeze-Eastern to match their own records for the hoist and that the cable had been an original fitment from 2011.
Close visual examination of the cable at the point of fracture in the ‘necked’ region identified that many of the wires were grooved and scalloped (Figure 4). There was no evidence of foreign debris, external abrasion, corrosion, kinking or nicks that might otherwise explain the failure. Remnant lubricant was identified between the wires and on the swaged ball end fitting.
A scanning electron microscope (SEM) was utilised to further analyse the failed cable at much higher magnifications. The SEM examination confirmed that the severe scalloping was due to a wear mechanism of the cable near the point of fracture. The wear had progressed to an extreme level with many of the wires having lost almost the entirety of their cross-section.
A mixed fracture mode was also identified with evidence that some wires had sustained fatigue cracking prior to failure (Figure 5). The general shape of the fatigue cracking was indicative that the cable had been exposed to cyclic bending loads. A portion of the wires had also failed in ductile overstress and these were likely what provided the remnant cable strength during the final conditioning operation.
Hoist cable from ParkAir AS350 B3 helicopter, VH-ZHG
An additional hoist cable was also supplied by ParkAir for comparative examination. That cable had been removed from another Breeze-Eastern BL-29700 rescue hoist as an immediate organisational response to the failure. The secondary hoist cable had accrued 535 hoist cycles. External inspection before destructive sectioning of that cable showed local ‘necking’ had also occurred in the same area as the failed cable approximately 10 mm from the swaged ball end fitting.
The ‘necking’ provided an indicator of the onset toward a serious defect, such as worn or broken internal wires and strands. The subtle changes in diameter associated with the ‘necking’ could also be felt when handling the cable during physical inspection. Magnified examination of the ‘necked’ region identified that wear grooves and scallops had occurred to the wires comprising the cable. The damage was similar in appearance to that from the failed cable off VH-UAH, though all strands remained intact. Figures 6 and 7 provide further detail on the severity of wear damage associated with ‘necking’ of the intact hoist cable.
Figure 3: Swivel hook and bumper assembly
The wire strands comprising the inner core of the cable had retracted approximately 50 mm to 60 mm from the outer strands. Source: ATSB
Figure 4: Close-up of the remnant cable portion near the swaged ball end fitting showed narrowing or ‘necking’ and grooves in many of the wires from severe wear damage
Source: ATSB
Figure 5: SEM images of the fractured cable identified severely worn wires (left) and fatigue crack progression bands from bending fatigue (right)
Source: ATSB
Figure 6: Another ParkAir rescue hoist removed from service after the occurrence displayed narrowing of the cable at the ball end fitting.
The narrowing, or ‘necking’, could be detected during physical handling and close visual examination. The cable had accrued 535 hoist cycles throughout its service life.
Source: ATSB
Figure 7: Severe wear to the wires was evident from the intact cable at the point of narrowing near the swaged fitting
The cable strands in the ‘necked’ region were spread apart in order to identify the extent of wear damage.
Australian operators of Breeze-Eastern hoists were required to comply with Civil Aviation Safety Authority (CASA) Airworthiness Directive AD/SUPP/10.[5] The AD noted that damage can occur to a particular area of the load cable that may evade detection during normal inspection, resulting in a serious compromise of cable integrity. The AD referenced Breeze-Eastern document CAB-100-30[6] that introduced inspections intended to significantly improve the operational safety of the rescue hoist system. Specifically, operators of Breeze-Eastern hoists were required to conduct:
1. A one-time and recurring inspection of the of the hoist’s load cable in a specific area.
2. A pre-flight and post-flight inspection of the hook and bumper assembly during stowage.
During the one-time and recurring inspections, CAB-100-30 required maintenance personnel to partially disassemble the hook assembly to allow a close visual inspection of the cable at the ball end for evidence of necking down, loose or broken wires, and other damage. The hoist logbook indicated no defects were identified from that specific cable inspection, which had last been completed in December 2019 (at approximately 600 hoist cycles).
Pre- and post-flight inspections required from CAB-100-30 were intended to ensure proper stowage of the hook assembly ‑ firmly seated against the bump stop at the conclusion of the homing procedure. CAB-100-30 noted that assurance of adequate hook homing could be achieved by grasping it and rocking it fore and aft. Importantly, the advice from Breeze-Eastern within CAB-100-30 also indicated that during the post-flight inspection of the swivel hook, the degree of spring compression was required to be measured to verify proper homing of the hook, as identified in Figure 8.
Figure 8: Extract from Breeze-Eastern CAB 100-30 describing the inspection requirements 1) the load cable and 2) the hook and bumper spring compression measurement
Source: Breeze-Eastern
Organisation
ParkAir rescue hoist operation
While the rescue hoists within their operator’s fleet were primarily used for winching of personnel and equipment in response to operational requirements, another significant aspect of hoist usage involved hoist training/familiarisation exercises. The familiarisation training was mostly conducted at low heights with about 5 m of cable reeled out, leading to the accrual of hundreds of short-haul winches per year.
Hook homing
The Breeze-Eastern procedures for reeling up the load cable and homing of the hook assembly were defined in the hoist operations manual.[7] At the conclusion of a winching operation, and while positioning the hook to the upper limit stop, Breeze-Eastern indicated that it was important to ensure that completion of that action was uninterrupted and provided the following advice:
Always guide the hook by hand as the cable is reeled in, at full pendant thumbwheel deflection, to the full in position. Ensure the spring in the bumper is compressed sufficiently to prevent the hook from moving when the helicopter is in flight.
ParkAir advised the ATSB that minor variations to the prescribed Breeze-Eastern hook homing procedure had probably developed over the years without correction. It was indicated that in certain instances intermittent control of the cable speed and gentle homing had been conducted to avoid damaging the rubber bumper attached to the hook assembly.
The operator advised that it was uncertain how this deviation in practise arose, however it may have been influenced by a lack of recent Breeze-Eastern Flight Line maintenance training on the hoist system. Such training had last been conducted by ParkAir staff approximately 7 years prior. ParkAir had expanded in that time and staff turnover may have led to the factory‑instructed lessons being diluted.
AD/SUPP/10 hoist inspections pre- and post-flight
The ATSB identified that there was no reference within the operator’s supplementary documentation to ensure the pre- and post-flight verification that the hook assembly was correctly homed. The safety concerns and corresponding checks raised by CASA within AD/SUPP/10 regarding adequate compression of the hook assembly were not mentioned within the documentation. The operator indicated that, although homing of the hook assembly was physically checked by the crewman at the end of each winching operation, a verification measurement for hook assembly compression, as per AD/SUPP/10 was not accomplished.
Airbus Helicopters hoist specific maintenance
Airbus Helicopters provided technical guidance in their Master Servicing Manual[8]that specified the maintenance operations to be performed by the helicopter operator. Within section 25-63Equipment and Furnishings of the manual, Airbus Helicopters defined a hard life-limit of 500 hoist cycles on the load cable for the Breeze-Eastern BL-29700 hoist. Airbus Helicopters defined a hoist cycle as:
Hoisting cycles: HC (Hoist Cycle)
1 HC =
- In flight, one downward movement + one upward movement, whatever the length of cable and load involved.
- On the ground, one downward movement of 5 meters or more and one equivalent upward movement, whatever the load involved.
Both the Airbus Helicopters definition of a hoist cycle, and their definition of load cable life-limit were notably different to the definition and limits specified by Breeze-Eastern. Airbus Helicopters indicated that the reason for the discrepancy was to align the hoist cycle definition to other hoists within the Airbus Helicopters fleet. It was also indicated that although the Airbus Helicopters life‑limit is significantly more restrictive than that defined by Breeze-Eastern, their limits were intended to provide a greater safety margin during operation.
Regulatory guidance on maintenance
During the course of the investigation, CASA advised the ATSB that regulatory information was available to operators regarding which publication should be consulted if there are two sources of conflicting information for maintaining continued airworthiness, such as that issued by Breeze‑Eastern and that issued by Airbus Helicopters. Civil Aviation Regulation (CAR) 50E Inconsistent requirements – resolution of inconsistencies, stated the order of priorities under these circumstances:
(4) The order of priority of requirements is as follows (starting with those of highest priority):
(a) requirements in these Regulations (except those requirements mentioned in the remaining provisions of this subregulation);
(b) requirements in instruments made under these Regulations;
(c) requirements in documents (including designs) approved by CASA or authorised persons under these Regulations;
(d) requirements in instructions issued by designers of modifications of aircraft;
(e) requirements in instructions issued by designers of modifications of aircraft components;
(f) requirements in instructions issued by aircraft manufacturers;
(g) requirements in instructions issued by aircraft component manufacturers;
(h) requirements in instructions issued by aircraft material manufacturers;
(j) requirements in documents that are approved maintenance data because of paragraph 2A(2)(e).
Using the above list of priority requirements, the hoist had been fitted to the helicopter under a separate engineering instruction 4(d), however that instruction advised that the Airbus Helicopters 4(f) and Breeze-Eastern 4(g) maintenance instructions should be followed. CASA indicated that in this instance, the life-limits listed in the Airbus Helicopters master servicing manual would take precedence and were therefore to be followed.
Other occurrences
A search of the Australian defect reporting system, managed by CASA, identified no specific examples of cable failure similar to the occurrence involving VH-UAH.
However, a similar report of cable ‘necking’ was identified on a rescue hoist fitted to an Agusta Westland AW139 helicopter. The necking was identified at the swaged terminal within the hook assembly of a Breeze-Eastern hoist by that operator in May 2020. The defect report indicated that the necking had been found after release of CASA AWB 25-034 Helicopter Rescue Hoist Wire Rope – Wear, Fatigue and Failure (released in response to the occurrence involving VH‑UAH). The cable had accrued 114 cycles and after identifying the necking it was replaced. Also mentioned in the defect report was an indication that the ‘necking’ was associated with many short hoist cycles accrued in training.
The following analysis discusses the factors surrounding the cable failure from a Breeze-Eastern rescue hoist fitted to an Airbus Helicopters AS 350 B3 helicopter, registered VH-UAH, which occurred near Bulga, New South Wales. The failure occurred while the helicopter crew were conducting a conditioning maintenance operation of the rescue hoist system to restore the integrity of the cable. Although no personnel were injured in this occurrence, the helicopter had previously been conducting live winching.
Wear damage and cable failure
The ATSB’s technical examination identified that severe wear damage had developed within the wire strands of the load cable. Additionally, the cable internal core had retracted from the externally wound strands indicating that the inner portion had probably fractured prior to the commencement of the conditioning operation. The failure occurred when the cable was loaded with a 160 kg weighted bag which was significantly less than the ultimate tensile load limit of the cable. In normal circumstances the cable should have withstood the imposed load. There was no evidence of corrosion, kinking, shock loading or any other such damage on the cable that might have otherwise contributed to the failure. Remnant lubricant was identified between the wire strands.
The identified wear led to a significant reduction in cross-sectional area and eventual overstress of the load cable. Some of the worn wires also showed indicators of progressive fracture consistent with the development of fatigue cracking, with the remainder displaying ductile overstress fracture.
Stowage practices and Airworthiness Directive AD/SUPP/10
Breeze-Eastern provided clear advice in the operating instructions for the rescue hoist that when homing the hook, it was important to ensure that the homing action was not interrupted, using full deflection of the controller. This ensured adequate compression of the bump spring and prevented the hook from moving during flight.
The operator commented to the ATSB that in certain instances, intermittent control of the cable speed and gentle homing of the hook had been conducted to avoid damaging the rubber bumper attached to the hook assembly. Although that stowage practice was intended to prevent component damage, it probably led to inadequate compression of the hook assembly that resulted in winch cable damage as the hook assembly vibrated and moved during helicopter operation. The observed wear in the failed cable and the cable off another ParkAir rescue hoist, found to be the result of vibratory movement, supported that conclusion.
In addition to variations in the homing practices, it is likely that specific post-flight inspection requirements for the Breeze Eastern rescue hoist listed in Airworthiness Directive AD/SUPP/10 were not being adequately completed by the operator. The inspections were targeted at verifying correct stowage of the hook assembly at the beginning and end of each flight.
Although the hook assemblies were physically checked for security at the end of each winching sortie, a specific instruction contained within AD/SUPP/10 identified the requirement to measure the degree of spring compression that in turn verified proper hook stowage. The operator’s inspection requirements for the rescue hoist did not contain any reference for a compression measurement to be accomplished.
Cycle counting
A significant difference was identified between the method that Breeze-Eastern and Airbus Helicopters used to define hoist cycles and life-limits for load cables. Breeze-Eastern recommended a 1,500-cycle life-limit while Airbus recommended a 500-cycle life-limit. Breeze‑Eastern utilised a mechanical counter within the mechanism of the winch to determine a full winch cycle, while Airbus identified a hoist cycle as a downward and upward movement of the cable in flight.
The winch had been installed onto the helicopter using an engineering instruction that deferred to both the Breeze-Eastern and Airbus Helicopters technical documentation for maintaining continuing airworthiness. In the event of conflicting sources of information, Civil Aviation Regulation (CAR) 50E Inconsistent requirements – resolution of inconsistencies provided the means to prioritise the relevant instruction. Under these circumstances, given the hierarchy of inspection orders contained within the regulations, the Airbus Helicopters maintenance instructions should have been followed. ParkAir’s use of the Breeze-Eastern method for cycle counting during operation led to an accumulation of load cycles that significantly exceeded the 500-cycle life-limit recommended by Airbus Helicopters.
The wear that occurred to the wires probably occurred over an extended period of in-service movement of the hook assembly, further compounded by the overall extended age and accumulated load cycles of the cable. The hoist cable had accrued 617 hoist cycles and was 9 years old. Based on the number of short-haul winches accrued each year, it is very likely the cable had been exposed to thousands of load cycles. Had the Airbus Helicopters cycle life‑limit been followed, the cable would have been removed from service prior to failure.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the rescue hoist cable failure from an AS350 B3 helicopter that occurred on 5 February 2020.
Contributing factors
While the helicopter crew were conducting a conditioning maintenance operation of the hoist system, the hoist cable fractured, which allowed the suspended load to fall to the ground.
Wear damage from in-service movement of the hook assembly led to a significant reduction in cross-sectional area, fatigue and overstress fracture of the strands and an associated reduction in cable strength. The wear was probably compounded by the extended age of the cable and accumulated load cycles.
Variations in hook stowage practices following winching operations led to inadequate compression of the hook assembly. This probably led to the winch cable becoming damaged due to wear as the hook assembly vibrated and moved during helicopter operation.
It is likely that specific post-flight inspection requirements for the Breeze‑Eastern rescue hoist listed in Airworthiness Directive AD/SUPP/10 were not adequately completed by the operator. The inspections were targeted at ensuring correct stowage of the hook assembly at the end of each flight. (Safety issue)
The operator’s method for cycle counting during operation of the rescue hoist led to an accumulation of cable load cycles that exceeded the 500-cycle life-limit recommended by Airbus Helicopters.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation, industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety action not associated with an identified safety issue
Industry awareness of the rescue hoist cable failure
After being notified of the cable failure and on completing the technical examination of the hoist components, the ATSB advised the Civil Aviation Safety (CASA), Breeze-Eastern, the European Aviation Safety Agency (EASA), and Airbus Helicopters. Those organisations, along with the ATSB, released the following advisories to provide an alert to the broader helicopter industry.
Breeze-Eastern released Service Information Letter (SIL 14 Maintenance) Breeze-Eastern Rescue Hoist Maintenance & Flight Line Inspections for BL-29700 Series, on 6 April 2020. The SIL reminded operators, hoist maintainers and personnel of the critical importance of all listed inspections, including pre-and post-flight, contained in the BL-29700 hoist maintenance manual. The SIL reiterated the requirement to ensure proper compression of the spring from the bumper assembly, and the need for careful inspection of the cable in the immediate area of the swaged ball end fitting.
Proper hook homing inspections post flight must be done according to the flight line maintenance manual and other appropriate technical documents. Failure to complete these checks and verify that the hook is homed correctly post flight could cause a loosely stowed hook to vibrate during flight, creating stress on the wire rope cable.
The continual vibration of a helicopter and a loosely “homed” hook can result in a fatigue failure of the cable immediately above the ball end fitting.
CASA released Airworthiness Bulletin (AWB) 25-034 Helicopter Rescue Hoist Wire Rope – Wear, Fatigue and Failure, on 22 April 2020 to emphasise the care, attention and proficiency required to safely operate and maintain winch systems that lifted and lowered personnel and loads. Within the AWB CASA discussed the cable failure and recommended operators to:
Ensure inspections are completed methodically and thoroughly.
Always ensure the hook has been homed securely, as per approved data. This will prevent the hook causing premature cable fatigue.
Hoist system cycle counters cannot be used to replace physical and visual system inspections. These cycles are based on fatigue life determined in laboratories. Many hoist operations consist of much shorter deploy and retrieve cycles, than a counter may show. Additional inspections may be warranted.
ATSB released a Safety Advisory Notice (SAN) AO-2020-013-SAN-001 on 23 April 2020 that provided a preliminary summary of the cable failure. The SAN was distributed to all Australian operators permitted to conduct aerial work and conduct helicopter winching operations. The SAN advised:
For all helicopter operators and flight crew involved in rescue hoist operations to review their current operational practices to ensure hoist operation and hook stowage are in accordance with the hoist manufacturers’ published procedures.
For operators, flight crew and maintainers to closely review the pre- and post-flight inspection requirements of the hook and cable assembly, along with any recurring scheduled maintenance of the hoist system, to ensure that they are completed in accordance with the manufacturers’ instructions.
Airbus Helicopters released a Safety Information Notice (SIN) 3507-S-25 Fatigue failure of a BREEZE 450 Lbs hoist cable, on 4 June 2020 to all operators of AS350 and AS355 civilian helicopters fitted with the Breeze-Eastern BL-29700 winch. The notice provided a reminder that:
… after a hoisting mission, the hoist operator must position the hoist hook to the upper stop, while holding the control handle in the upward direction without interrupting the automatic stop of the hoist so that the compression phase of the hook assembly is not interrupted.
The notice also advised operators that maintenance of the hoist was to be completed using the Airbus Helicopters definition of a hoist cycle, whereby:
1 Hoist cycle (HC) =
In flight, one downward movement + one upward movement, whatever the length of the cable and load involved
On the ground, one downward movement of 5 meters or more and one equivalent upward movement, whatever the load involved.
EASA released Safety Information Bulletin (SIB) 2020-11 Helicopter Rescue Hoist Cable Failure on 11 June 2020 that informed European operators of the Breeze-Eastern 450 lb BL‑29700 series rescue hoist of the Australian occurrence. EASA recommended the following to all AS350 and AS355 helicopter operators:
…maintenance personnel should use the applicable Airbus Helicopters definition of a hoist cycle
…maintenance personnel and pilot(s), as applicable, should perform the pre-flight and post-flight inspection(s) as per applicable B-E CMM instructions
…pilots and on-board hoist operators should ensure a proper hoist stowing at the end of each hoist operation, by fully reeling it in to compress the hook bumper. Failure to follow this procedure could result in damage (due to wear and fatigue through vibration and aerodynamic loading) to the cable.
Safety issue description: It is likely that specific post-flight inspection requirements for the Breeze Eastern rescue hoist listed in Airworthiness Directive AD/SUPP/10 were not adequately completed by the operator. The inspections were targeted at ensuring correct stowage of the hook assembly at the end of each flight.
Glossary
AD Airworthiness Directive
ATSB Australian Transport Safety Bureau
AWB Airworthiness Bulletin
CAR Civil Aviation Regulation
CASA Civil Aviation Safety Authority
CMM Component maintenance manual
EASA European Aviation Safety Agency
HC Hoist cycle
NPWS National Parks and Wildlife Service
NSW New South Wales
SAN Safety Advisory Notice
SEM Scanning electron microscope
SIB Safety Information Bulletin
SIL Service Information Letter
SIN Safety Information Notice
Sources and submissions
Sources of information
The sources of information during the investigation included:
New South Wales National Parks and Wildlife Service Flight Operations Unit (ParkAir)
Civil Aviation Safety Authority
Breeze-Eastern
Airbus Helicopters
Additional references
Breeze-Eastern Customer Advisory Bulletin CAB 100-51, Use and Maintenance of Wire Rope on Airborne Personnel Hoists, October 1994
Helicopter Rescue Techniques, Civilian Public Safety and Military Helicopter Rescue Operations, United States Department of the Interior National Park Service, National SAR Academy (NSARA), First edition October 2013
Information on Helicopter Hoist Wire Rope, Failure Modes, and Rejection Criteria, Zephyr International IIc 2013
James Paul WALLIS, The importance of cable care, AirMed & Rescue Magazine, 4 June 2019
Kasim TURGAT et. al. Falls from height: a retrospective analysis, World Journal of Emergency Medicine, 2018 pp46-50
US Department of Defence, Wire Rope – Steel - Nonrotating for Aircraft Rescue Hoist, Military Specification MIL-W-83140 April 1969. Washington, DC
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
New South Wales National Parks and Wildlife Service Flight Operations Unit (ParkAir)
Civil Aviation Safety Authority
European Aviation Safety Association
United States National Transportation Safety Board
Breeze-Eastern
Airbus Helicopters
Bureau d'Enquêtes et d'Analyses of France
the helicopter owner
the rescue hoist maintainer
Submissions were received from:
Breeze-Eastern
Civil Aviation Safety Authority
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
Around midday on 19 February 2020 a Beech D95A Travel Air, registered VH-AEM, and a Piper PA44-180 Seminole, VH-JQF, collided mid-air approximately 8 km south of Mangalore Airport, Victoria. The Travel Air was approaching Mangalore Airport from the south, on descent to conduct a practice instrument approach, while the Seminole was southbound on climb from Mangalore to Essendon Airport.
Both aircraft were operating under the instrument flight rules (IFR) in non-controlled airspace. The pilots of each aircraft had been provided with traffic information about the other aircraft prior to the collision, in accordance with procedures. Both aircraft were fitted with dual radios. Other pilots monitoring the common traffic advisory frequency (CTAF) associated with Mangalore Airport reported hearing pilots from both aircraft broadcast but had no recollection of hearing them speaking directly to each other.
The two aircraft collided with no evasive manoeuvring identified in recorded flight data. All four pilots were fatally injured and both aircraft were destroyed.
What the ATSB found
This was the first mid‑air collision between two civil aircraft operating under the instrument flight rules and procedures that have been in place in Australia for decades.
The ATSB identified that, following receipt of verbal traffic information from the controller, the pilots did not successfully manoeuvre or establish direct communications on the CTAF to maintain separation, probably due to the collision risk not being recognised.
While it is probable that the aircraft were in instrument meteorological conditions at the time of the collision due to the presence of extensive cloud, the known limitations of the ‘see-and-avoid’ principle meant that the pilots were unlikely to have seen each other in sufficient time to prevent the collision even in clear weather conditions.
Additionally, following receipt of an alert indicating the developing proximity of the aircraft, the controller assessed it in accordance with the required procedure. However, after considering that the pilots were aware of each other’s presence and were required to ensure their own separation in non‑controlled airspace, the controller did not intervene further.
While the pilots were responsible for self-separation within the Mangalore CTAF area, they did not have access to radar or automatic dependent surveillance broadcast (ADS-B) information. As a result, the pilots were required to make timely decisions to avoid a collision without the best available information.
Finally, although not contributory to the accident, the ATSB identified that the wording of procedures relating to the conduct of practice instrument approaches at Mangalore Airport resulted in varied application and an increased risk of traffic conflicts.
What has been done as a result
Airservices Australia (Airservices) have proposed a change to the Civil Aviation Safety Authority (CASA) to introduce a surveillance flight information service (SFIS) around Mangalore Airport, designed to provide enhanced traffic information services to all aircraft operating in a 20 NM radius of the airport. The proposed service would require all aircraft to broadcast on the CTAF within the broadcast area, while providing a dedicated air traffic controller operating on the CTAF to provide a flight information service utilising surveillance.
By listening on the CTAF, the controller would be able to determine whether aircraft have arranged their own separation following receipt of traffic information and provide updated traffic information if required. A similar service was introduced around Ballina Airport in August 2021.
In September 2021, the CASA Office of Airspace Regulation (OAR) announced an aeronautical study into the airspace within a 25 NM area of Mangalore Airport, up to an altitude of 8,500 ft. The scope of this study involves:
a review of traffic type and density over the previous 5 years
an evaluation of the suitability and efficiency of the airspace
a review of the equitability of access to the airspace, the appropriateness of the airspace classification and the suitability of the existing services and facilities provided by Airservices Australia.
As of February 2022, this aeronautical study has not been published.
The proposal for the introduction of an SFIS on the Mangalore CTAF is currently on hold pending completion of the OAR review. However, a dedicated controller is providing safety alerting on the Mangalore CTAF in the interim period. Communications on the CTAF are recorded by Airservices when the safety alerting service is operational. A further consultation has been raised by Airservices to lower the base of Class E airspace around Mangalore Airport. As of February 2022, that proposal was in review by Airservices following an industry consultation period.
In December 2021, the Department of Infrastructure announced a $30 million fund to provide rebates to general aviation aircraft operators to fund up to $5,000 or 50% of the cost of installing ADS-B transponder technology into their aircraft.
Safety message
While this accident involved aircraft operating under the IFR, irrespective of whether operating under the instrument or visual flight rules, pilots are responsible for separation from other aircraft in non‑controlled airspace.
As such, if made aware of traffic, either via advice from air traffic control (ATC), a received broadcast or any other means it is vitally important that the traffic is risk assessed and, if necessary, a plan established to assure separation. The following separation methods can be useful in maintaining a safe operating distance between aircraft:
different operating altitudes
ground feature reference (e.g. townships, lakes or linear features – rivers, roads)
navigation or avionics reference (e.g. radial or GPS distance)
‘clock code’ reference – useful to assist aircraft sighting.
The ATSB also strongly encourages the fitment of ADS‑B transmitting, receiving and display devices as they significantly assist the identification and avoidance of conflicting traffic. The continuous positional information that ADS‑B provides can highlight a developing situation many minutes before it becomes hazardous – a significant improvement on both point‑in‑time radio traffic advice and ‘see‑and‑avoid’. The ATSB also notes that ADS‑B receivers, suitable for use on aircraft operating under both the instrument or visual flight rules, are currently available within Australia at low cost and can be used in aircraft without any additional regulatory approval or expense.
It is also important to recognise however that ADS‑B cannot be relied upon to display all nearby traffic so effective use of radio remains a primary defence in avoiding mid‑air collisions. In that context pilots need to make all required broadcasts detailed in the Aeronautical Information Publication, even if there is no known traffic, and respond to broadcasts if a potential traffic conflict is identified.
Finally, in line with the key objective of ATC being the prevention of collisions, controllers should advise pilots if they become aware of a developing traffic conflict rather than assume that the pilots are already aware of it.
The occurrence
On 19 February 2020, at about 1055 Eastern Daylight-saving Time[1], a Beech Travel Air D95A aircraft registered VH-AEM (AEM), departed Tyabb Airport, Victoria for an Instrument Flight Rules (IFR)[2] training flight to Shepparton via Mangalore, and return to Tyabb. A student pilot (the student) and an instructor (the instructor) were on board. The pilots were planning to conduct a practice VOR[3] approach to Mangalore Airport as part of the student’s training towards the issue of an instrument rating. AEM was estimated to arrive overhead Mangalore Airport at 1126.
At around the same time, a pilot (the pilot under examination) and flight examiner (the examiner) were at Mangalore Airport, Victoria, preparing for an instrument rating flight test in a Piper PA44‑180 Seminole, registered VH-JQF (JQF).
At 1111, the pilot under examination, seated in the left seat of JQF, contacted the Melbourne Centre air traffic controller responsible for the surrounding Class G non‑controlled airspace, to advise that the aircraft was taxiing for a departure from Mangalore Airport. The pilot had submitted a flight plan for a round-trip IFR flight via Essendon and Shepparton. At this time, the Mangalore automatic weather station recorded cloud as broken[4], with a base of about 3,200 ft above mean sea level (AMSL).
After departing Tyabb, the crew of AEM climbed the aircraft to 6,000 ft and tracked north through the Melbourne Class C controlled airspace, before being instructed to contact Melbourne Centre. The student pilot first made contact with the Melbourne Centre controller at 1117:42 (Figure 1). They were informed there was no IFR traffic for the descent to Mangalore Airport. At the time the student pilot in AEM acknowledged this information, JQF had not appeared on the controller’s surveillance display. At 1120:07 the controller passed traffic information to the pilots of AEM that JQF was shortly to depart Mangalore airport heading to the south.
Surveillance data for JQF first appeared on the controller’s display at 1120:31, indicating JQF was airborne. At 1122:19, the pilot under examination in JQF made a departure call to the Melbourne Centre controller and provided information that the aircraft was passing 2,700 ft on climb to 7,000 ft and tracking to waypoint LACEY. The controller identified the aircraft on their display and replied with the area QNH[5]. At 1122:44 the controller provided the pilots in JQF with the following traffic information:
6 [nautical] miles in your 12 o’clock is alpha echo mike, a King Air. They are inbound to Mangalore for airwork. Passing 5,000 [ft] on descent to not above 4,000 [ft].
At 1122:49, five seconds after the controller passed this traffic information to the pilots of JQF, an aural and visual short-term conflict alert (STCA)[6] was provided to the controller. The alert indicated that the two aircraft were to come within 4.8 NM lateral and 600 ft vertical proximity in the next 60‑90 seconds. Based on the predicted velocity vectors[7] presented on the radar display for the two aircraft, the controller assessed that the aircraft would pass each other, with JQF passing behind AEM, then acknowledged the STCA. At 1123:00 JQF acknowledged the traffic information. By this time, JQF was climbing through 3,250 ft, had a ground speed of 81 kt and had commenced a turn to intercept their planned outbound track from Mangalore Airport to LACEY (Figure 2). At the same time AEM had a ground speed of 187 kt and was descending through 4,918 ft on a track of 354⁰. At this point, there was 5.4 NM horizontally and about 1,675 ft vertically between the aircraft.
Under IFR operational requirements, the pilots in JQF were required to intercept their outbound track (in this case the direct track between Mangalore Airport and LACEY) within 5 NM of the airfield, and manoeuvre to ensure terrain clearance until above the minimum sector altitude of 3,400 ft within 10 NM of the airfield. Terrain clearance was also assured above 3,900 ft within 25 NM of the airfield.
Figure 1: Flight paths for AEM and JQF, and airspace around Mangalore, including Melbourne Class C airspace and waypoint LACEY
Source: Google Earth and Airservices, annotated by the ATSB
In addition to AEM and JQF, there were six other aircraft either taxiing on the ground at Mangalore Airport, operating in the circuit area, or in the local area monitoring the Mangalore common traffic advisory frequency (CTAF).[8] Multiple pilots recalled each of the aircraft communicating separately on the CTAF, with one of the crew of JQF making a, rolling and circuit departure broadcast and a pilot from AEM making an inbound broadcast. However, none of the pilots in the CTAF area recalled any radio communications to arrange separation between AEM and JQF.
At 1123:51, another STCA appeared on the controller’s screen for the two aircraft. The controller acknowledged the STCA at 1124:09, whilst providing traffic information to another aircraft. At the time of the STCA activation, the velocity vector of JQF crossed the velocity vector of AEM, with JQF predicted to pass closely behind AEM. However, the controller’s display showed there was 500 ft vertical separation between the aircraft.
At 1124:20 the aircraft collided. Following the collision, the ATC radar display reverted from a presentation of the track of each aircraft based on surveillance data to the flight planned tracks. The controller attempted to contact each aircraft numerous times, before declaring a distress phase for both aircraft.
The collision occurred about 4 NM (7.5 km) south of Mangalore Airport[9] at around 4,100 ft. There were no witnesses to the collision. However, the pilot of a helicopter operating to the south of the collision point reported seeing one aircraft (AEM) descending rapidly, with the other aircraft (JQF) descending more slowly while spinning. Two other witnesses, one, a pilot located on the airfield, and a second closer witness, similarly reported seeing JQF spinning toward the ground.
The two aircraft impacted the ground about 1.3 km apart (Figure 2). Some lighter debris from each aircraft was located at a third location downwind from the collision point. All four pilots were fatally injured in the accident, and both aircraft were destroyed.
Figure 2: Flight path of AEM and JQF, and location of the ground impact of both aircraft
Source: Google Earth and Airservices, annotated by the ATSB
All four pilots and the air traffic controller held the required licences and medical approvals. It was considered unlikely that fatigue affected the performance of any of the involved pilots, due to the time of the accident, and their previous work and rest times. Workload and fatigue assessments for the controller are detailed in a separate section below.
VH‑AEM instructor
Qualifications and experience
The instructor onboard VH-AEM (AEM) held an Air Transport Pilot Licence (Aeroplane) (ATPL(A)) issued on 29 January 2004, and a Commercial Pilot Licence (Aeroplane) (CPL(A)) issued on 13 October 1993. The instructor also held a Grade 1 flight instructor rating with endorsements for multi-engine class rating[10] training and instrument rating training. The instructor had an English language proficiency of level 6[11].
The instructor’s instrument rating and multi-engine aircraft rating were valid until 29 February 2020, and their flight instructor rating was valid until 30 June 2020. The instructor had previously held an examiner rating covering private pilot licence and night visual flight rules testing endorsements, and English language proficiency assessments.
The instructor’s logbook showed a total flying experience of 5,907.2 hours to the last recorded flight on 14 February 2020. In the previous 90 days, the instructor had flown 29.3 hours of which 7.6 hours were in the Beech D95A Travel Air (Travel Air) aircraft type. In the previous 30 days the instructor had flown 25.1 hours total, 5.4 of which were on type.
The instructor had been the operator’s Chief Pilot since March 2019, and the Head of Operations since April 2019.
Medical information
The instructor held a class 1 aviation medical certificate valid until May 2020, with a restriction that it could not be used for ATPL operations. The instructor had a mild colour vision deficiency which had been assessed by specialists as ‘extremely mild’ and had been declared to the Civil Aviation Safety Authority (CASA).
There were no restrictions preventing the instructor from undertaking commercial operations including flight instruction. Additionally, the instructor was not required to wear any vision correction in flight.
VH‑AEM student
Qualifications and experience
The instrument rating student in AEM held a CPL(A) issued on 30 April 2013. The student had also previously held a Grade 3 flight instructor rating permitting single engine aircraft, night VFR and design feature training. The student also held activity endorsements for formation flight, aerobatics and spinning. The student held a level 6 English language proficiency assessment.
The student’s logbook showed a total flying experience of 1,103.1 hours to the last recorded flight on 17 February 2020. The student’s total flying experience on the Travel Air was 6.6 hours. In the previous 90 days, the student had flown a total of 60.4 hours, including the 6.6 hours on the Travel Air; and in the last 30 days had flown 30.3 hours with 2.2 of those in the Travel Air.
Medical information
The student held a Class 1 aviation medical certificate valid until 2 September 2020. There were no restrictions on their medical certificate.
Instrument rating training
An instrument rating is an operational rating permitting a pilot to fly under the IFR.
The student passed their instrument rating theory examination on 2 October 2019. Logbook records indicate that the pilot first completed 1.1 hours in the simulator for ’NDB and instrument flying’ in June 2019. This was completed with another instructor.
Records indicate that the Travel Air instructor and the student began flying together in October 2019 for the purposes of completing the instrument rating. Table 1 identifies the flights logged in the student’s logbook, conducted as flight training toward the instrument rating with multi-engine aeroplane instrument endorsement. The first three flights were conducted as day VFR flights in the Travel Air, conducting elements of handling required for the multi-engine endorsement (see the section titled Pilot Licencing).
Table 1: Flights completed in preparation for instrument rating
Date
Aircraft
Duration (Hours)
Details
14 October 2019
VH-AEM
0.9 (VFR)
General handling, stalls and circuits
16 October 2019
VH-AEM
1.1 (VFR)
Circuits, go arounds
21 October 2019
VH-AEM
2.4 (VFR)
Tyabb – LaTrobe Valley – Asymmetric engine operation and engine failure after take-off - Tyabb
28 October 2019
Simulator
1.7 (IFR)
Sector entry and holding / basic instrument flying
28 October 2019
Simulator
1.0 (IFR)
Holding with winds
18 November 2019
Simulator
1.0 (IFR)
ILS at Essendon, RNAV and hold at Moorabbin
20 January 2020
Simulator
2.1 (IFR)
Holding, cross wind, RNAV Mangalore and Yarram, VOR Approach
23 January 2020
Simulator
2.0 (IFR)
Moorabbin, Yarram – Holding and RNAV, Essendon ILS
28 January 2020
VH-AEM
2.2 (IFR)
Tyabb – Yarram – LaTrobe Valley – MOZZA[2] – MONTY – Essendon ILS
1 February 2020
Simulator
1.2 (IFR)
Moorabbin – Mangalore – VOR approach
[1] ILS, RNAV and VOR are types of instrument approaches. [2] MOZZA and MONTY are IFR waypoints. See the section titled Operational information.
VH‑JQF examiner
Qualifications and experience
The examiner on board VH-JQF (JQF) held an ATPL(A) that was issued on 17 July 1978. They held a flight examiner rating permitting examination of a variety of operational ratings, including an instrument rating and multi-engine aeroplane class rating. The examiner had a level 6 English language proficiency.
The operator’s records indicate the examiner received a briefing on relevant operational policies in August 2018. However, as per the regulations, the examination flight was conducted as a private flight rather than a commercial operation.
The examiner successfully completed an instrument rating proficiency check in a Seminole on 17 February 2020, two days before the accident flight. The examiner’s instrument rating and multi‑engine class rating were valid until 28 February 2021. The examiner’s grade 1 flight instructor rating was valid until 31 December 2021.
The examiner’s flight examiner rating had exceeded the renewal date, however, operation as an examiner was still permitted under CASA EX70/18, an exemption issued by CASA to extend the requirement to conduct a proficiency check until March 2020. This exemption was issued to assist with the transition of examiners from the Authorised Testing Officer delegations to the Civil Aviation Safety Regulations Part 61[12] Flight Examiner ratings.
A review of the examiner’s logbook showed a total flying experience of about 21,600 hours. CASA records indicate that the examiner conducted 194 flight tests in the 2 years prior to the accident, of which 34 were for the initial issue of an instrument rating.
Medical information
The examiner held a class 2 aviation medical certificate that was valid until 15 October 2020. There were two restrictions placed on the examiners medical certificate:
Distance correction was to be worn while exercising the privileges of this licence.
Reading correction was to be available while exercising the privileges of this licence.
The available evidence indicates that these restrictions were being complied with at the time of the accident.
VH‑JQF pilot under examination
Qualifications and experience
The pilot under examination had been enrolled in a diploma course with the operator since February 2017, and although having completed most of the flying program from Moorabbin Airport they were also familiar with operating to and from Mangalore Airport. The pilot under examination held a CPL that was issued on 24 June 2019. The final component of their training was the instrument rating and multi-engine class rating, being tested during the accident flight. The pilot had a level 6 English language proficiency.
The pilot’s logbook showed a total flying experience of 244.9 hours to the last recorded flight on 17 February 2020. The pilot’s total flying experience in the Seminole was 22.2 hours. In the previous 90 days, the pilot had completed 20.4 hours total flying (all in the Seminole), and in the last 30 days had completed 4.8 hours flying.
Medical information
The pilot’s Class 1 aviation medical certificate was renewed 3 days prior to the accident and was valid until 12 March 2021. There were no restrictions placed on their medical certificate.
Instrument rating training
The purpose of the accident flight was examination for an instrument rating, a multi-engine aeroplane instrument endorsement and a multi-engine aeroplane class rating. The pilot under examination had passed the theory component for the instrument rating on 11 November 2019.
Records indicate that the pilot began training for the multi-engine class rating and the instrument rating in August 2019. During this training, the pilot logged:
Day multi-engine aircraft flight: 32.0 hours
Night multi-engine aircraft flight: 7.2 hours
In-flight instrument flight time: 17.2 hours (logged during the 39.2 day and night multi-engine aircraft flight hours)
Simulator time: 20.4 hours
All training was completed with one instructor, and all flying was conducted in a Seminole. Documentation recommending the pilot for the flight examination was completed by this instructor after a final practice flight on 17 February 2020, which included flying to Mangalore Airport.
Air traffic controller
Qualifications and experience
The controller had worked for Airservices Australia (Airservices) since 1989. The controller was issued with ratings for area procedural control and area radar control in 1996; and was issued with an endorsement for the sector being controlled on the day (see the section titled Airspace) in January 2012. The controller held a level 6 English language proficiency.
The controller held a Class 3 medical, appropriate for air traffic controllers, which was valid until 6 October 2021, and required the controller to have reading correction available.
The most recent training completed by the controller prior to the accident was compromised separation refresher training on 2 October 2019, and effective scanning training on 26 February 2019.
Roster and workload
The controller reported that they did not feel fatigued prior to, or at the time of the accident. The controller noted that although some of the roster patterns worked could be fatiguing, controllers found ways to manage this. A review completed by Airservices did not identify any fatigue related‑ issues with the controller’s roster.
While the roster had a mix of morning, afternoon and night shifts during February, in the 3 days prior to the accident the controller had completed the following roster:
Sunday 16 February: day off
Monday 17 February: 1400 - 2200
Tuesday 18 February: 1400 - 2200
Wednesday 19 February: 1100 start
The controller recalled being asleep by midnight after the shift on Tuesday 18 February and waking to an alarm at 0800 on Wednesday morning. The controller arrived at work about 15 minutes early, to prepare for the day.
The controller described the workload on the day as having ‘a bit going on’, but not busy. It was further stated that there were no particular pressures on the day of the accident.
Medical and pathological information
Given the nature of the mid‑air and ground collisions, the accident was not survivable for any of the four pilots.
The autopsy of the examiner in JQF identified a level of ischaemic heart disease capable of causing death in isolation from other factors, but there was no evidence of an acute cardiac event having occurred at the time of the incident.
No other significant medical issues were identified in any of the remaining pilots. Further, the toxicology results did not identify any substance that could have impaired the pilots’ performance or that were not noted in their aviation medical records.
Aircraft information
Both aircraft met the equipment requirements for flight under the IFR, detailed in Civil Aviation Order 20.18 including the carriage of Automatic Dependent Surveillance – Broadcast (ADS-B)[13] equipment (see the section titled Automatic dependent surveillance broadcast).
VH‑AEM
The Beech D95A Travel Air is a four to six seat, low‑wing, retractable-tricycle-undercarriage aircraft fitted with two 180 horsepower Textron Lycoming IO-360-B1B reciprocating engines driving constant‑speed, two-bladed propellers.
AEM (Figure 3) was manufactured in the United States in 1966 with serial number TD 682. It was first registered in Australia in 1967, and prior to the departure from Tyabb, the aircraft had accumulated 7,400.3 hours in service.
Figure 3: Beech Travel Air VH-AEM
Source: Aircraft operator, annotated by the ATSB.
AEM had a current Certificate of Registration, Certificate of Airworthiness and maintenance release. The last maintenance conducted on the aircraft was a calibration of the aircraft’s altimeters, air speed indicators, compass, pitot-static system and fuel quantity system, conducted on 17 January 2020.
The aircraft was certified for IFR and charter operations and was equipped with dual controls for the student and instructor. The aircraft was also equipped with a Garmin GNS530 radio communication and GNSS navigation system, together with a second communication radio. The aircraft was also fitted with a Garmin GTX335 ADS-B OUT transponder. AEM did not have any ADS-B receiving equipment.
One notable modification to the aircraft was the replacement of the original two frame windscreen with a single pane ‘speed-slope’ windscreen. The exact date of replacement was unknown, however this was a common modification to Travel Air aircraft. The speed-slope screen is a component of later-model Travel Air aircraft and Beech Baron aircraft.
The modification involved removal of the centre spine of the original screen, with no further modifications to the fuselage roof area or side frames. The lower section of the speed-slope screen protruded approximately 75-100 mm further towards the aircraft nose than the original windscreen. A larger glareshield was also fitted to the aircraft to fill the space between the instrument panel and the new windscreen.
A review of the previous two aircraft maintenance logbooks for AEM showed that the speed‑slope screen was last replaced on 5 August 2011, and that the pilot’s side window had been replaced on 25 December 2014.
VH‑JQF
The Piper PA-44 Seminole is a four-seat, low-wing, twin-engine light aircraft. It is powered by two 180 horsepower Textron Lycoming O-360-E1A6D reciprocating piston engines. JQF was fitted with three-blade, constant‑speed and full-feathering aluminium propellers. The Seminole is equipped with hydraulically‑operated, retractable, tricycle landing gear. JQF (Figure 4) was manufactured in the United States in 1979 with serial number 44-7995291. It was first registered in Australia in 1990. The aircraft was owned by the operator. Prior to the accident flight, the aircraft had accumulated a total flight time of 11,190.6 hours.
Figure 4: Piper Seminole VH-JQF
Source: Aircraft operator, annotated by the ATSB.
JQF had a current Certificate of Registration, Certificate of Airworthiness and maintenance release. The maintenance release was issued on 12 February 2020, and the aircraft had completed 18.0 hours flying since that time.
The aircraft was certified for IFR and private/airwork operations. It was equipped with dual controls for the student and instructor. The aircraft was also equipped with a Garmin GNS430 radio communication and GNSS navigation system and a second communication radio. The aircraft was fitted with an Appaero Stratus Mode-S transponder unit, which had ADS-B OUT transmit capability only.
Operational information
Airspace
Overview
Airspace in Australia is separated into different classes that may be either controlled (Class A, Class C, Class D, Class E) or non-controlled (Class G) (Figure 5). Different services are offered to aircraft that operate in these airspace classes, based on the flight rules the aircraft is operating under (see the section titled Air traffic services).
Figure 5: Australian airspace structure
Source: Airservices
Common traffic advisory frequency
Mangalore Airport is a non-controlled airport that operates on a common traffic advisory frequency (CTAF). This frequency is shared with four other airfields in the local area – Locksley Field, Nagambie-Wirrate, Wahring Field and Puckapunyal (Figure 6).
The precise boundaries of a CTAF are not defined, however, the Aeronautical Information Publication (AIP[14]) stated that:
An aircraft is in the vicinity of a non-controlled aerodrome if it is within a horizontal distance of 10 [nautical] miles; and within a height above the aerodrome reference point that could result in conflict with the operations at the aerodrome.
Mangalore Airport is located 4 NM north of an 8,500 ft Class C control step. The accident took place almost directly underneath the 8,500 ft step boundary (Figure 6). Class G non-controlled airspace surrounds Mangalore Airport up to 8,500 ft; with Class E controlled airspace from 8,500 ft to flight level[15] 125 (FL125) and Class C controlled airspace from FL125 to FL180. Class A controlled airspace was in place above FL180.
Figure 6: Airspace surrounding Mangalore Airport
Source: Airservices, annotated by the ATSB.
Class G airspace
Class G airspace has been operational in Australia since 1995. In Class G airspace, air traffic controllers provide a traffic information service to IFR aircraft about conflicting IFR and observed VFR flights (see the section titled Flight Information Service). Controllers have offered a similar ‘flight service’ to IFR aircraft operating in non-controlled airspace since 1963.
AEM was transferred from one Melbourne Centre controller to another Melbourne Centre controller, just prior to the 30 DME[16] control boundary (Figure 7), where the lower level of Class C airspace increased from 4,500 ft to 8,500 ft.
The pilots of AEM first made contact with the Melbourne Centre controller at 1117:42, and they entered the airspace around 1118:22. They were not on the Melbourne Centre frequency at 1111 when the pilot of JQF made their taxi call to the Melbourne Centre controller.
Figure 7: Airspace around Mangalore Airport and the outbound IFR track to LACEY
Source: Airservices, annotated by the ATSB
Rules of the air
While both aircraft were operating in the same airspace under the IFR and were in contact with the Melbourne Centre controller, due to the airspace being class G non-controlled airspace, the controller was providing a flight information service only to these aircraft, rather than a traffic control service with positive separation (see the section titled Flight information service). This meant that, as with VFR operations in non-controlled airspace, the pilots were responsible for ensuring they maintained sufficient separation.
The Civil Aviation Regulations 1988161 through 166 sets out a number of associated regulations detailing pilot responsibilities in relation to rules for the prevention of a collision, operating near other aircraft, right of way and operating in non-controlled airspace.
With regard to the responsibility of pilots to communicate on VHF radio, Civil Aviation Regulation 166C – Responsibility for broadcasting on VHF radio states
(1) If:
a. An aircraft is operating on the manoeuvring area of, or in the vicinity of, a non-controlled aerodrome; and
b. The aircraft is carrying a serviceable aircraft VHF radio; and
c. The pilot in command of the aircraft holds a radiotelephone qualification;
The pilot is responsible for making a broadcast on the VHF frequency in use for the aerodrome in accordance with subregulation (2)
(2) The pilot must make a broadcast that includes the following information whenever it is reasonably necessary to do so to avoid a collision, or the risk of a collision, with another aircraft:
a. The name of the aerodrome;
b. The aircraft’s type and call sign;
c. The position of the aircraft and the pilot’s intentions.
The AIP defines a broadcast as: A transmission of information relating to air navigation for which an acknowledgement is not expected.
The AIP further clarified statements about broadcasts and collision avoidance in GEN 3.3 paragraph 7.5.1 Acknowledgement of broadcasts:
Broadcasts should not be acknowledged unless a potential collision risk exists
Flight plans
AEM
The student pilot of AEM submitted a flight plan to Airservices at 1041 on the morning of the flight. The flight plan details were to
depart Tyabb Airport at 1055
fly direct to Mangalore Airport and conduct the VOR hold and approach
depart to Shepparton Airport for the Area Navigation (RNAV) Global Navigation Satellite System (GNSS)[17] approach
return via Mangalore and LACEY to Moorabbin for the RNAV GNSS approach before returning to Tyabb.
A witness from Tyabb reported that the instructor and instrument rating student had tried to book slots to conduct instrument approaches at airports in the Melbourne control zone but were unable to secure any on the morning of the flight[18]. They were also unable to operate at East Sale due to military training. Therefore, it was decided to fly to Mangalore and Shepparton.
The aircraft proceeded as per the flight plan. The pilots were transferred to the Melbourne Centre controller just prior to the airspace boundary and entered the Class G airspace while maintaining 6,000 ft about 24 NM south of Mangalore Airport. About 90 seconds later, when the aircraft was about 18 NM from Mangalore Airport, the student pilot contacted Melbourne Centre to report their departure from 6,000 ft for airwork at Mangalore not above 4,000 ft (operations between ground level and 4,000 ft).
The planned instrument approach was the VOR approach to runway 23 (see the section titled Mangalore VOR). The approach required them to pass overhead the VOR not below 3,900 ft before beginning the outbound leg of the approach, and descending to no lower than 1,800 ft. There were no reported issues with the serviceability of the VOR at the time of the occurrence.
JQF
The pilot under examination submitted a flight plan at 0949. The flight plan detailed:
an 1100 departure from Mangalore Airport and climb to 7,000 ft while tracking to LACEY
conduct of an NDB[20] approach at Shepparton Airport before returning to Mangalore for an RNAV approach.
The flight plan submitted to Airservices did not specify the route planned to LACEY, other than Mangalore Airport direct to LACEY. However, a copy of a handwritten flight plan indicated the intention to track from Mangalore to LACEY along the published IFR route W481 (Figure 7).
JQF commenced the take-off roll from runway 23 at Mangalore just prior to 1120. The aircraft initially departed in an extended upwind direction, before commencing a series of left turns that resulted in the aircraft tracking towards the planned route to LACEY (Figure 8).
The pilot under examination made a departure call to the Melbourne Centre controller with the first communication commencing at 1122:19. At the time of this call, during which the pilots were provided traffic information about AEM, the track maintained by JQF was direct to LACEY. This may have been intentional, or co-incidental due to the increased workload of the student during the take-off phase and climb phase and managing the radio during the Melbourne Centre call. It was at this time the controller reviewed the velocity vectors that were based on the track of the aircraft not the flight planned track, and assessed that JQF would pass behind AEM (see the section titled Short term conflict alert). However, at the end of the radio communication, JQF resumed the turn towards the planned route to LACEY via route W481.
Figure 8: Track of JQF after take-off from Mangalore Airport
Source: Google Earth and Airservices, annotated by the ATSB
Mangalore VOR
The Mangalore VOR is one of four such navigation aids in Victoria. As part of the 2016 Navigation Rationalisation project, in a move towards using a Global Navigation Satellite System (GNSS), 179 ground-based navigation aids were decommissioned across Australia. Twenty eight of the decommissioned instrument approaches were in Victoria, including five VORs. The Mangalore VOR was maintained as part of the back-up network, along with VORs at Melbourne, Avalon and Mildura airports. Despite fewer available local VORs since the decommission of navaids, IFR traffic numbers using Mangalore Airport have decreased (see the section titled Aerodrome information).
Figure 9 details the published VOR instrument approach to Mangalore Airport.
Figure 9: Mangalore Runway 23 VOR approach
Source: Airservices, annotated by the ATSB
Pilot Licencing
Licencing of pilots with operational ratings and endorsements, such as the multi-engine aeroplane class rating and the instrument rating, requires the pilot to demonstrate relevant competencies to a flight examiner. These competencies are set by CASA and mandated under Part 61 of the Civil Aviation Safety Regulations (CASR).
The CASR Part 61 Manual of Standards (MOS) details these competencies both for initial testing and recurrent examination. At all stages of pilot licencing, competence in non-technical skills must be demonstrated by pilots under examination, including
- Maintain effective lookout
- Maintain traffic separation using a systemic visual scan technique at a rate determined by traffic density, visibility and terrain;
- Maintain radio listening watch and interpret transmissions to determine traffic location and intentions;
- Recognise and manage threats
Of the Part 61 MOS competencies outlined for the instrument rating, there were two competencies that were relevant to the departure path flown by the pilot of JQF:
- 2.2 (e) conduct instrument departure to comply with obstacle clearance requirements.
- 4 (w) pilot's responsibility in an IFR visual departure.
If either of these competencies were not demonstrated, then it would be marked as a failure item for the test.
In complying with 2.2(e), the AIP ENR 1.5 stated:
4.4 Take-off minima for other IFR aeroplanes
4.4.3 – It is a condition of the use of the minima in Section 4.4 that the pilot in command of the aeroplane must ensure that:
a. terrain clearance is assured until reaching either an en-route LSALT[21] or departure aerodrome MSA[22]
As identified on the VOR chart (Figure 9), the minimum sector altitude within 10 NM of Mangalore Airport was 3,400 ft, and the minimum sector altitude within 25 NM to the south and south‑east of the airport was 3,900 ft. Therefore, the pilot of JQF had to ensure terrain clearance was maintained until the aircraft climbed to 3,400 ft.
In complying with 4(w), AIP ENR 1.1 paragraph 10.6.2 stated:
The pilot of a departing aircraft is required to establish the aircraft on the outbound track as soon as possible after take-off, and in any case, within 5 nm of the departure aerodrome.
JQF departed from runway 23, and was flight planned on a published IFR route southbound via waypoint LACEY. Figure 10 identifies the latest position at which JQF could have intercepted this outbound track and complied with the requirement to be ‘established’.
Figure 10: JQF track flown and planned track to LACEY
Source: Google Earth and Airservices Australia, annotated by the ATSB
Another competency for a multi-engine aircraft class rating is the requirement to demonstrate how to safely manage a simulated engine failure. The ATSB considered the possibility that the examiner of JQF had simulated an engine failure for the pilot under examination take-off from Mangalore. However evidence provided by the operator suggested that this would not have been the standard practice of the examiner and the recorded climb performance was indicative of the aircraft climbing at a normal two‑engine climb rate.
Neither the student in AEM or the pilot under examination in JQF were likely to have been wearing an IFR ‘hood’, used to simulate instrument conditions, at the time of the accident. AEM had been in cloud for most of the descent from 6,000 ft and the hood for JQF was found in a basket behind the pilot seats, having not been used for the flight.
Self-separation by radio
As previously detailed, while operating in non-controlled airspace, even under the IFR, pilots remain responsible for ensuring their own separation from other aircraft. While the occupants of the two aircraft were provided with traffic information, where the possibility for traffic conflict occurs, communication between pilots over the radio remains the primary means for ensuring separation.
Interpreting location information heard over the radio into a useful mental model is a practical skill taught to pilots during initial training, and developed with experience. Once a pilot hears where another aircraft is through a radio call, they must:
process the audio information
identify where that aircraft is in relation to their own aircraft
determine where both aircraft are heading
assess whether there is a potential conflict and, if so, communicate this risk with the other aircraft.
Despite the importance of this skill, there is limited written guidance to pilots on how to communicate and arrange this separation. CASA CAAP 166-2 (2013) is one document that provided the following written guidance to pilots on suggested methods for traffic separation by radio:
Accurate provision and interpretation of traffic information for the purposes of separation to or from another aircraft is an essential pilot skill. Four commonly used ways of providing and interpreting traffic information by radio communication for the purpose of airborne separation are practised at non‑controlled aerodromes. All methods have their advantages depending upon circumstances.
- Separation by ‘clock code’ – Pilots maintain traffic separation by reference to the central axis and numbers of an analogue clock face. Particular care must be given to identifying which aircraft is the central axis of the clock. You are at my 2 o’clock and low has the opposite meaning to I am at your 2 o’clock and low. The weakness of this method of separation is that is requires at least one pilot to have seen, identified and made contact with the other aircraft.
- Separation by ground reference – Pilots maintain separation by radio by either identifying that each is in different places relative to a ground feature(s), or by agreeing to remain on different sides of a readily identifiable ground feature such as a runway extended centreline, road, town or railway line. The advantage of this method of separation is that it does not required either aircraft to have actually seen each other (although this is desirable). The weakness of this method of separation is that ground features could be misidentified. The uncertainty or confusion can distract from the effort of retaining separation through see-and-avoid.
- Separation by altitude reference – Pilots maintain separation by radio by identifying that each is at a different altitude or by one aircraft descending/climbing to another level. Provided that both aircraft altimeters are set to the correct subscale reference (QNH) this method should provide separation for both aircraft regardless of visual contact.
- Separation by navigational or avionic reference – Pilots maintain separation by identifying that each is in a different place relative to a known navigational point or line (radial), or separated by distance from a fixed point (e.g. Global positioning system (GPS) or a radio navigation aid). This method of separation does not require either aircraft to have actually seen each other (although this is desirable). The weakness of this method of separation is that differing avionic equipment or pilot navigational skill can lead to incorrect assumptions being made about the usability of the separation information offered.
Air traffic services
Overview
Airservices is the national air traffic services (ATS) provider for other than military‑related airspace within Australia. A number of different services are provided by Airservices based on the airspace classification (Table 2), broadly described as either an air traffic control service, or a flight information service.
Table 2: Services provided to IFR aircraft in Australian Airspace
Source: CASA
The AIP defines an air traffic control service as:
A service provided for the purpose of:
a. preventing collisions:
(1) between aircraft; and
(2) on the manoeuvring area between aircraft and obstructions; and
b. expediting and maintaining an orderly flow of air traffic.
An air traffic control service is provided in controlled airspace, such as in Class A, C, D and E airspace in Australia. These classes of airspace have a separation standard for aircraft operating in these control areas. In controlled en route[23] airspace with surveillance services, the minimum separation requirements between IFR aircraft are 5 NM lateral separation and 1,000 ft vertical separation.
A flight information service (FIS), such as that provided in Class G airspace, is defined in the AIP as:
A service provided for the purpose of giving advice and information for the safe and efficient conduct of flights.
A flight information service differs from an air traffic control service in that pilots are not provided with positive separation between aircraft, and there are no separation standards for aircraft. Instead, pilots of IFR flights are provided with traffic information, and are required to comply with the rules of the air to maintain their own separation (see the sections titled Rules of the air and Flight information service).
Air traffic control surveillance
Both AEM and JQF were broadcasting ADS-B and SSR and were identified by the controller, therefore the pilots were receiving traffic information through a surveillance service rather than a procedural information service. All aircraft information on the controller’s display is filtered to update once every 5 seconds (see the section titled Recorded data)
The Manual of Standards (MOS) Part 172 (paragraph 10.2.3) required controllers to verify level information being broadcast by aircraft as being within ±200 ft, and that:
ATC must verify displayed pressure altitude-derived level information:
a. On initial contact with the aircraft or, if this is not feasible, as soon as possible after initial contact; and
b. By simultaneous comparison with:
i. Altimeter-derived level information received from the same aircraft by radiotelephony.
On first airborne contact with each aircraft, the controller validated the altitude information provided by the pilots in the radio transmissions against the altitude displayed on the controller’s console. At this check AEM was indicating 100 ft higher than the pilot reported (6,100 ft rather than the reported 6,000 ft), as it was again when the pilot reported the start of descent for airwork at Mangalore. The altitude displayed on the controller display matched the altitude reported by the pilot of JQF. This was within tolerance for both aircraft.
Flight information service
At the time of the accident, AIP GEN 3.3 paragraph 2.16 outlined the traffic information provided in Class G airspace. This information was available to both pilots and controllers. Key information in this section of the AIP included:
2.16.1 In Class G airspace, a traffic information service is provided to IFR flights about other conflicting IFR and observed VFR flights.
2.16.1.1 An IFR flight reporting taxiing or airborne at a non-controlled aerodrome will be advised of conflicting IFR traffic which is not on that CTAF.
2.16.1.2 An IFR flight inbound to a non-controlled aerodrome will be advised of conflicting IFR traffic. The ATS obligation to provide the pilot with traffic information ceases when the pilot reports changing to the CTAF.
2.16.1.3 Traffic information will continue to be provided about an IFR flight following cancellation of its SARWATCH[24], until expiry of the flights ETA. Traffic information may be provided to an IFR pilot who has cancelled SARWATCH where workload and communications permit.
2.16.2 In accordance with the preceding paragraphs, traffic information will be provided to IFR flights when:
a. requested;
b. notifying intention to change level;
c. reporting either taxiing or airborne or departure, whichever is first; or
d. the ATS officer becomes aware of conflicting traffic.
2.16.3 Pilots of IFR aircraft should advise ATS of the callsign(s) of relevant IFR traffic, previously intercepted, to avoid receiving the same traffic information from ATS.
2.16.4 Traffic information will be provided in accordance with the preceding paragraphs whenever there is a possibility of confliction between aircraft in the following situations:
a. aircraft that climb, descent or operate with less than 1,000 ft vertical spacing and less than 15 NM lateral or longitudinal spacing;
b. overtaking or opposite direction aircraft on the same or reciprocal tracks with less than 1,000 ft vertical spacing and less than 10 minutes longitudinal spacing based on pilot estimates;
c. more than one aircraft arriving at, or departing from, the same aerodrome with less than 10 minutes between arrival and/or departure and falling within these guidelines.
2.16.5 When the traffic assessment is based entirely on the use of an ATS surveillance system, traffic information will be provided when, in the opinion of the controller, it is warranted by the proximity of the aircraft to each other.
2.16.7 Traffic information will include relevant factors from the following:
a. the identification of the conflicting aircraft;
b. the aircraft type;
c. the route of the aircraft;
d. the last position report received from the aircraft;
e. intentions of the pilot (if known), and, as required;
f. the aircraft’s initial departure track and intended cruising level;
g. inbound track or direction, level and next estimate; and
h. any other data which may enhance the value of the information.
An ATS surveillance service is defined in the AIP as a:
Term used to indicate an air traffic service provided directly by means of an ATS surveillance system.
An ATS surveillance system is defined in the AIP as:
A generic term meaning variously, ADS-B, primary surveillance radar, secondary surveillance radar or any comparable ground-based system that enables the identification of aircraft.
AEM and JQF were under a surveillance service, once they were identified by the controller following their first airborne radio calls. Therefore, AIP paragraph 2.16.5 was applicable, with the controller providing traffic information when warranted by controller opinion rather than through the requirements of 2.16.4. There was no requirement for the controller to pass updated traffic information to aircraft that had already received traffic information, even when the information passed no longer accurately reflected the current position the aircraft were in.
An air traffic controller overseeing Class G airspace has the responsibility to provide traffic information to IFR aircraft until they report changing to CTAF. This is a historical procedure that was in place when aircraft commonly only had one radio and remains despite many aircraft being fitted with dual radio systems. However, this procedure remains in the latest edition of the AIP, current 2 December 2021 (AIP GEN 3.3, paragraph 3.3.7.2).
Guidance in the Airservices and Department of Defence Manual of Air Traffic Services (MATS) supports the AIP information, and provides controllers with further advice about how to provide traffic position information to pilots:
9.1.6.5 Position information
Provide position information by:
a. Clock reference;
b. Bearing and distance;
c. Related to a geographical point;
d. Reported position and estimate; or
e. Position in the circuit
Airspace
The Melbourne Centre controller was responsible for monitoring a section of airspace known as ‘Alpine’ that spanned an area from the Melbourne control zone to Canberra (Figure 11). This airspace included Class C and E controlled airspace, as well as Class G non-controlled airspace.
Where workload required, the ‘Alpine’ airspace can be sub‑divided into three sectors – Hume (HUM), Ovens (OVN) and Dookie (DOK). At the time of the accident, the controller was operating the three sectors combined.
Figure 11: Alpine airspace, including Dookie, Ovens and Hume sectors and key aerodromes
Source: Airservices, annotated by the ATSB.
Controller display
Air traffic controllers have multiple screens on their console, displaying information such as a map view of the aircraft in their sector; flight plans of active and future aircraft; weather and NOTAM[25] information. Co-ordination of aircraft passing into their sector may occur either through verbal communication with another controller or through data messages sent between controllers.
The position of AEM and JQF as they operated under a surveillance service were identified through a combination of secondary surveillance radar (SSR) and ADS-B. Airservices advised that, when SSR information was available, this was the primary source of traffic information displayed to the controller. Additionally, data presented to the controller was only updated every 5 seconds (see the section titled Recorded data).
The controller had the ability to zoom into sections of the airspace on the display. This gave the controller the ability to further inspect information available about each aircraft, including callsign, altitude and flight plan information. The controller used this function to inspect alerts that were generated (see the section titled Short term conflict alert).
Following the accident, Airservices recreated the controller’s display for the period that AEM and JQF were operating in Class G airspace. While this did not replicate where the controller had the information labels[26] placed for each aircraft, it did display the same information as the controller would have seen.
The controller operated with the default display setting, with 2 minute velocity vectors projected ahead of each aircraft in their sector. The vectors were based on the current track of the aircraft, and not on any information included in the flight plan. Therefore, following the departure call from the pilot under examination in JQF, when traffic information about AEM was passed to the occupants of JQF (see the section titled Communication, Melbourne Centre), the vectors indicated that JQF would pass behind AEM (Figure 13). However, this projected information did not consider the flight planned track and the intent of the pilot in JQF to turn and intercept the Mangalore to LACEY track within 5 NM of Mangalore Airport (see the sections titled Flight plans and Pilot Licencing). Unlike the velocity vectors that projected where in space an aircraft would be if they continued on the same track and with the same groundspeed, there was no numerical predictive information provided to the controller relating to the projected altitude of a climbing or descending aircraft in that 2 minute timeframe. If needed, this information had to be determined by the controller through processing a combination of climb or descent arrows, known aircraft performance, flight plan information or speed information.
Short term conflict alert
A short term conflict alert (STCA) is an aural and visual alert received on a controller’s console when two aircraft come within a defined proximity of each other. In describing the intent of the STCA, the International Civil Aviation Organization (ICAO, 2016) noted:
The objective of the STCA function is to assist the controller in preventing collision between aircraft by generating, in a timely manner, an alert of a potential or actual infringement of separation minima.
In the Australian ATC system STCAs occur in both controlled and non-controlled airspace, with alerts inhibited in some areas. Specifically, Airservices advised that STCAs in Class G airspace are inhibited below 4,500 ft in the Brisbane flight information region[27], but occur to the ground in areas of the Melbourne flight information region.
When two aircraft are assessed by the system as likely to pass within prescribed vertical and lateral parameters in a particular time window, the controller will receive a pop-up window on their display with aircraft details. The parameters for an alert on aircraft in Class G airspace are the same as the parameters for aircraft in an en-route controlled environment. Aircraft operating below FL285, under a surveillance service will generate a STCA if they are projected to pass within 4.8 NM and 600 ft in the next 60-90 seconds.
The STCA only alerts for aircraft operating under a surveillance service. Both AEM and JQF were included in this, as they were both operating under a flight plan, broadcasting ADS-B and SSR data, and had both been positively identified by the controller. Some aircraft, such as 2 VFR aircraft in non‑controlled airspace operating without a submitted flight plan, will not generate a STCA even if a conflict situation develops.
The procedures documented for the response to a STCA did not differentiate between controlled airspace, where a STCA indicates an infringement of separation minima, and non-controlled airspace where there is no published separation minima.
In terms of prioritisation of alerts, the National ATS procedures manual (NAPM) identified the STCA as one of the highest priority alerts, indicating a system detected safety net critical event, requiring immediate attention.
The response procedure for a controller receiving a STCA was:
14.1.3.1 Alert integrity
On receipt of a STCA:
1. Assess its integrity; and
2. Issue a ‘Safety Alert’ or ‘Avoiding Action’ advice when appropriate.
The process for ‘assessing integrity’ of a STCA was undefined. Airservices advised the ATSB that it was an assessment based on controller judgement and experience, and there was no documented checklist or criteria that controllers used to complete this assessment. A STCA may be assessed as not having integrity if the procedure of passing mutual traffic information to two aircraft had been completed, and the aircraft were expected to be self-separating on the CTAF.
It was reported by the controller that it was not unusual to receive a STCA in the airspace being controlled after traffic information was passed. This statement was supported by the Airservices accident investigation report, which noted that other controllers operating the same Alpine sector received a high number of nuisance[28] STCAs. These STCAs activated between aircraft in the circuit or between aircraft on diverging tracks or who had already passed each other. It was reported that IFR aircraft in the vicinity of non-controlled aerodromes often pass within the STCA parameters when self‑separating and did not normally need further intervention after traffic information was passed.
After a controller assessed the integrity of a STCA, and determined that escalation was required, the information for controllers in the MATS regarding safety alerts stated:
9.1.4.1 Vigilance
Remain vigilant for the development of safety alert or traffic avoidance advice situations
9.1.4.2 Responsibility
Do not assume that because another controller has responsibility for an aircraft that an unsafe situation has been observed and a safety alert or traffic avoidance advice has been issued.
9.1.4.3 Issuing a safety alert
Unless the pilot has advised that action is being taken to resolve the situation or that the other aircraft is in sight, issue a safety alert prefixed by the phrase ‘SAFETY ALERT’ when you become aware that an aircraft is in a situation that places it in unsafe proximity to:
a. Terrain;
b. Obstruction;
c. Active restricted or prohibited areas; or
d. Other aircraft
9.1.4.3.1 Airspace classes – safety alerts
You may issue safety alerts, including those based on visual observation, in all classes of airspace both within and outside ATS surveillance system coverage.
Advice to pilots in AIP GEN 3.3 current at the time of the accident stated:
5.1 ATC will issue a Safety Alert to aircraft, in all classes of airspace, when they become aware that an aircraft is in a situation that is considered to place it in unsafe proximity to:
a. terrain;
b. obstruction;
c. active restricted or prohibited areas; or
d. other aircraft.
5.1.1 When providing an ATS surveillance service, ATC will issue advice to pilots regarding avoiding action as a priority, when they become aware than an aircraft is in a situation that is considered to place it at risk of collision with another aircraft.
5.1.2 ATC will prefix advice to turn or change level with “suggest” unless the alerts are for controlled flights with reference to other controlled flights.
5.1.3 ATC may discontinue issuing Safety Alerts or advice regarding avoiding action when the pilot has advised action is being taken to resolve the situation or has reported the other aircraft in sight.
The AIP guidance for safety alerts stated that pilots would receive a safety alert whenever two aircraft were deemed by a controller to come within an unsafe proximity of each other, whether in controller or non-controlled airspace. When the combination of the MATS and NAPM guidance was followed after receipt of a STCA, a safety alert may not be issued if the controller deemed other risk controls were in place such that the proximity was safe. However, the guidance did not preclude a safety alert being issued when a controller deemed it necessary after a STCA, or at any other time.
There was no definition for what ‘unsafe proximity’ between aircraft was when operating in non‑controlled airspace under pilot separation as there was no separation standard in non‑controlled airspace. Further, when pilots were in the vicinity of a CTAF and had been provided traffic information, there was an expectation from controllers that the pilots were in radio contact with each other and self-separating.
The information in MATS regarding traffic avoidance advice was:
9.1.4.4 Traffic avoidance advice
Issue traffic avoidance advice, prefixed by the phrase ‘AVOIDING ACTION’, to an aircraft that:
a. Is receiving an ATS surveillance service; and
b. In your judgement, is in a situation that places it at risk of a collision with another aircraft under surveillance.
In the time between JQF taking off and the collision, there were three STCA alerts generated (Figure 12).
Figure 12: STCA activation and vertical profiles of AEM and JQF
Source: Airservices
Notes:
Callsigns of other aircraft redacted. Controller was actively communicating with either pilots or other controllers at these times.
ASD is an abbreviation for ‘Air Situation Display’, meaning the controller display.
Times on the graph are displayed in UTC (local time – 11 hours at the time of the accident).
Data is displayed in graph in 3 second intervals and is not representative of the 5 second intervals that the controller display was updated with.
On the basis of analysis conducted by an ATC subject matter expert and technical detail provided by Airservices, it was assessed that:
The first STCA, at 1122:42, was a nuisance alert generated by JQF conflicting with VFR traffic in the Mangalore circuit area.
A second STCA, at 1122:49, occurred as the controller passed traffic information to JQF (Figure 13). At that stage, indications were that the aircraft would pass abeam each other. The STCA was assessed by the controller but not cleared from the screen at this point.
The controller re-inspected the two aircraft at 1123:30 after JQF had turned towards the planned outbound track. The velocity vectors indicated that lateral displacement would be maintained, with JQF passing behind AEM in about one minute. At that time, the controller’s display showed AEM at 4,800 ft while JQF was at 3,400ft.
A final STCA alert occurred at 1123:51. The controller zoomed in to inspect the aircraft flight paths and altitudes again and acknowledged the STCA at 1124:09. The controller identified that JQF was going to pass across the track of AEM, but at that time, 11 seconds prior to the collision, indications on the controller’s display showed AEM at 4,500 ft and JQF at 4,000 ft, with 0.9 NM lateral separation between the aircraft.
Figure 13: Recreation of STCA display at 1122:49
Source: Airservices data, annotated by the ATSB
Note: Not to scale or necessarily representative of how the controller had the labels configured.
When each of the STCAs displayed, the controller assessed the integrity of the alert in accordance with the NAPM procedure. The controller reported checking the path of each aircraft using the set velocity vectors, the vertical separation of the aircraft, and confirming that traffic information about each aircraft had been passed to the other aircraft. Having assessed that the aircraft would pass each other and:
the STCA was designed as an alert for a breakdown in separation standards
there was no set separation standard in non-controlled airspace
the pilots were responsible for their own separation
they decided that a safety alert or traffic avoidance advice was not required, and cleared the aural alert.
Radio communication
Common traffic advisory frequency
Table 3 shows the guidance provided by CASA (2019) to pilots on the recommended CTAF broadcasts in the vicinity of a non‑controlled aerodrome.
Table 3: Recommended positional broadcasts in the vicinity of a non-controlled aerodrome
In addition to this guidance, the En-Route Supplement Australia (ERSA)[30] identified a local procedure for pilots to make a report about intentions when conducting practice instrument approaches at Mangalore (see the section titled Practice instrument approaches). The ERSA also noted the following minimum number of radio calls for aircraft operating at Mangalore:
Taxiing, entering (a runway), departing: Inbound, Joining, Base and Final with position, altitude and intentions.
Note: Pilots must respond to radio requests from other traffic for their intentions, position or altitude.
Based on evidence provided by other students trained by the instructor, due to the higher performance of the Travel Air, the instructor encouraged students to make their inbound CTAF call around 15 NM from the airport. The operator of JQF advised that they had a similar procedure to make CTAF broadcasts around 15 NM from Mangalore Airport.
Radio transmissions on the Mangalore Airport common traffic advisory frequency (CTAF) were not recorded, nor were they required to be. Several witnesses stated the CTAF was often congested, but due to the weather at the time of the accident, there was limited flight training and so the CTAF was not as busy.
The ATSB interviewed the pilots operating in the Mangalore area at the time of the accident regarding calls made from the pilots of AEM and JQF. None recalled the pilots of AEM and JQF talking to each other to arrange separation. Various pilots recalled a pilot in JQF making a rolling call, and a departure from the circuit call, and one pilot remembered details of an inbound call made by a pilot of AEM, including mention of an altitude of 3,900 ft.
The CTAF frequency at Mangalore was not equipped with an aerodrome frequency response unit (AFRU)[31]. There was no evidence to suggest either aircraft had selected the incorrect radio frequency or that an AFRU would have changed the sequence of events. The radios installed in AEM were too damaged to be analysed, but notes found in the aircraft, and details provided by another pilot about an inbound call from AEM, indicated it was likely that AEM broadcast on the correct CTAF frequency.
The two radios from JQF were recovered and analysed by the ATSB. One was set to the Melbourne Centre frequency and the other to the Mangalore CTAF. The audio panel configuration was found in a position consistent with the pilots of JQF either broadcasting or intending to broadcast on the CTAF.
Melbourne Centre
The required radio reports for IFR pilots operating in Class G airspace are listed in the AIP (Table 4). Transmissions between each aircraft and the controller were made on the ATS Melbourne Centre 122.4 MHz frequency and were recorded.
Table 4: Required reports for IFR pilots operating in Class G airspace
Source: AIP
Table 5 outlines the communications that occurred between each of the aircraft and the controller providing traffic information (see the section titled The occurrence). A review of the radio recordings confirmed that the pilot of JQF made taxi and departure calls to Melbourne Centre. The student in AEM also made the appropriate calls when changing to the Melbourne Centre frequency and before changing level, when they started the descent from 6,000 ft into Mangalore.
Table 5: Key traffic information on Melbourne Centre frequency
Time start
(* indicates approximate time)
Time end
(* indicates approximate time)
Aircraft
Comment
1111:21
1111:32
JQF
Taxi call
1117:42
1117:55
AEM
Initial contact with controller on entry to airspace. Area QNH provided and advice of no reported IFR traffic.
1119:35
1119:54
AEM
Controller contacted with information about commencing descent from 6,000 ft and establishing a SAR time for airwork in the Mangalore area. Advice of no reported IFR traffic provided by the controller.
1120:07
11:20:08
AEM
Controller called the pilots of AEM to pass traffic. No response received.
1120:15
1120:28
AEM
Controller again called the pilots of AEM. Pilot responded and traffic information about JQF shortly to depart Mangalore was passed and acknowledged.
11:22:19
1123:00
JQF
Departure report to controller. Information was provided that the aircraft was passing 2,700 ft on climb to 7,000 ft and tracking to LACEY. Controller advised the pilots that AEM was inbound to Mangalore in JQF’s 12 o’clock position, for airwork, passing 5,000 ft on descent to not above 4,000 ft.
During this conversation a STCA for proximity between AEM and JQF activated and was acknowledged by the controller.
1123:51
1124:09
STCA for AEM and JQF. Controller zoomed in on screen and acknowledged the STCA at 1124:09.
1124:20
Approximate time of collision
Source: Airservices, annotated by the ATSB
A review conducted by Airservices following the accident concluded that both aircraft were provided with, and acknowledged receipt of, mutual traffic that contained all relevant information. They also assessed that pilot communications with the controller were generally consistent with the AIP phraseology and the required content was included in the transmissions. A subject matter expert was independently asked by the ATSB to review the recordings and confirmed that the controller provided traffic in accordance with the procedures in the AIP and MATS.
Figure 14 details analysis conducted by the ATSB of ADS-B data and Melbourne Centre recordings provided by Airservices.
Figure 14: Approximate timeline of transmissions and key actions from 1117 to the collision
Source: ATSB, based on data provided by Airservices
Note: Radio transmissions on the Melbourne Centre frequency were recorded so correspond to exact times (see Table 5). The ATSB calculated data is based on ADS-B data. Due to a lack of available information, the following assumptions were made:
The start of the JQF take off, at 1120:00 corresponds to the first recorded ADS-B point, which occurred when the aircraft was approximately one third down the runway and around 50ft above the runway. It is likely that the pilot’s rolling call, and the start of the take-off roll occurred some seconds before this time. The time from application of power to attaining a height of 50ft has been estimated to be 20-25 seconds.
The pilots of AEM had a number of opportunities to listen to the Automated Weather Information Service (AWIS)[1] – before and after the descent call to the Melbourne Centre controller at 1119:35. As the aircraft was fitted with two radios, the pilots would likely have selected the AWIS frequency instead of the CTAF for the period of time required. This means they were unable to monitor the CTAF for this time period. A previous student of the instructor described setting up the AWIS frequency in the cruise so that it could be listened to as soon as it came into range, and before top of descent.
When the pilot under examination in JQF made a taxi report at 1111, AEM was not yet in the controller’s airspace. Therefore, at that point AEM was not assessed as conflicting traffic and so no information was provided to the pilots of JQF. Additionally, the expected arrival time of AEM at Mangalore was outside the 10-minute window to be considered arriving ‘traffic’ for JQF in accordance with the guidance provided in AIP GEN 3.3 paragraph 2.16.4c for non-surveillance traffic. The controller indicated awareness of this in interview with the ATSB.
AEM was not given traffic information about JQF when they first called the Melbourne Centre controller at 1117, or initially at 1119 when calling to notify their descent. While JQF had made the taxi call to Melbourne Centre by that time, JQF had not appeared on the controller’s screen as a prompt at that point.
However, the controller did identify JQF as potential traffic for AEM by 1120:07 and called the pilot of AEM. The pilot did not initially respond to this call, however, they did respond to a second call from the controller a short time later at 1120:15. It could not be determined why the pilot did not respond to the initial call, but consideration was given to whether the pilots were listening to the automated weather information services (AWIS) (see the section titled Meteorological information) or making an inbound call on the CTAF as at this point they were about 18 NM from Mangalore. The information given to the pilots of AEM was that JQF was shortly to depart Mangalore southbound via LACEY on climb to 7,000 ft.
Analysis of high-resolution ADS-B information identified that JQF’s take‑off coincided with the pilots of AEM’s call to Melbourne Centre to inform of their descent into Mangalore for airwork. This timing suggests that the pilots of JQF were unlikely to have been actively monitoring transmissions on the Melbourne Centre frequency at this time, including advice of AEM’s descent, due to their focus on the take-off.
AEM reached 15 NM from Mangalore at around 1120:30, just as they finished receiving traffic information from the Melbourne Centre controller. This is the position that previous students of the instructor identified that the instructor encouraged students to make their inbound call. The aircraft reached 10 NM around 1122:30 (Figure 14), which is the latest point the student should have made an inbound call-in accordance with expected CTAF procedures. It is therefore likely that an inbound CTAF broadcast was made during this 2-minute time period. Significantly, that time interval coincided with the time that JQF was in the initial climb, and making a departure call to Melbourne Centre. Therefore, it is possible that the pilots of JQF did not hear this inbound call, nor the pilots of AEM hear the CTAF circuit departure call or the Melbourne Centre departure call from JQF.
AIP GEN 3.4 paragraph 6.16.8 contained information about the standard phraseology expected from pilots making reports after take‑off in particular operating environments. The standard phraseology for a departure report made from a non-controlled aerodrome in a non‑surveillance environment was:
DEPARTED (location)(time in minutes) TRACKING [TO INTERCEPT] (track) CLIMBING TO (intended level) ESTIMATING (first reporting point) AT (time)
The standard departure report phraseology from non-controlled aerodromes under surveillance when notifying departure and identification was expected with the departure report was:
(location reference departure aerodrome) PASSING (current level) CLIMBING TO (intended level) ESTIMATING (first reporting point) AT (time)
AIP ENR 1.1 paragraph 10.6.4 also includes the information
If the pilot transmits the departure report before intercepting the departure track the report must include advice that the aircraft is manoeuvring to intercept departure track.
Radio communication between the Melbourne Centre controller and the pilot under examination in JQF after take‑off was as follows:
1122:19
JQF to ML Centre
Melbourne Centre, juliet quebec foxtrot departure
1122:22
ML Centre to JQF
juliet quebec foxtrot’s identified, verify level with departure
1122:27
JQF to ML Centre
juliet quebec foxtrot departure at Mangalore two three passing two thousand seven hundred on climb to seven thousand tracking to LACEY, Mangalore.
1122:37
ML Centre to JQF
juliet quebec foxtrot area QNH one zero one zero
(Note this call was interrupted internally by another Melbourne controller)
1122:41
JQF to ML Centre
One zero one zero, juliet quebec foxtrot
1122:44
ML Centre to JQF
And juliet quebec foxtrot, traffic six [nautical] miles in your 12 o’clock is alpha echo mike a king air, they’re inbound to Mangalore for airwork, passing five thousand on descent to not above four thousand.
While the controller positively identified JQF, the statement made was by the pilots of JQF that they were tracking to LACEY, without the specific information that they were tracking to intercept the IFR airway from Mangalore to LACEY (Figure 10). Additionally, it did not include detail of the position of JQF with reference to Mangalore, which at the time of the departure report was about 2.2 NM south-south‑west of the airport. While it could not be determined whether the pilots of AEM heard this departure report, the information had the potential to provide them with an incorrect mental model of the aircraft’s relative position. The Airservices investigation report identified that at this time the two aircraft had 8.6 NM lateral separation, and 2,600 ft vertical separation.
There was also a discrepancy with the traffic information, in referencing AEM as a King Air rather than a Travel Air. However, that was unlikely to have had a significant impact on the understanding of the presence of traffic, or its performance, as the groundspeed of AEM was similar to the approach speed of the type of King Air that frequented Mangalore Airport.
Based on the information presented by the velocity vectors, when giving this traffic information the controller judged that JQF would pass behind AEM.
While it would not be expected, as traffic self-separation broadcasts would generally be made on the CTAF, a review of the recording confirmed that neither aircraft attempted to contact the other using the Melbourne Centre frequency.
A review of the air traffic control recordings and transcripts indicated that between 1123:12 and 1124:08, the controller was actively engaged with other aircraft, or co-ordinating aircraft with another controller. It was during this time that the final STCA for the two aircraft occurred.
Automatic Dependent Surveillance Broadcast
Overview
ICAO (2018) defined Automatic Dependent Surveillance Broadcast (ADS-B) as:
A means by which aircraft, aerodrome vehicles and other objects can automatically transmit and/or receive data such as identification, position and additional data, as appropriate, in a broadcast mode via a data link.
ADS-B uses the GNSS for positioning. ADS-B data can be both broadcast (ADS-B OUT) and received (ADS-B IN).
Under Civil Aviation Orders 20.18, both AEM and JQF were required to be fitted with ADS-B OUT equipment to operate under the IFR. Both aircraft were fitted with transponders that complied with this requirement.
To provide an ADS-B based surveillance service, Airservices has a range of ground-based ADS-B receivers. The resulting ADS-B coverage at an altitude of 5,000 ft across Australia is shown in Figure 15. Mangalore Airport was within the coverage area at this altitude. ADS-B coverage improves as altitude increases, and at 30,000 ft almost all flights within Australia can be conducted under an ADS-B surveillance service.
Figure 15: ADS-B coverage at 5,000 ft across Australia
Source: Google Earth and Airservices, annotated by the ATSB.
Cockpit traffic display
Neither aircraft was fitted with a system to receive ADS-B information directly from other aircraft, nor were they required to be. As such, all the positional guidance the pilots had about other traffic was received from the controller and via any received radio broadcasts.
It is possible to receive ADS-B information from other aircraft directly into an aircraft. Aircraft that are fitted with such a receiver (ADS-B IN) can be configured with a cockpit display of traffic information (CDTI) to identify where other aircraft are relative to their position.
CDTI may give an image of the traffic over a moving map or directional guidance about the location of other aircraft. Some of these systems are also able to provide audible and visual alerts to pilots about identified traffic risks.
The CASA CNS/ATM guide (2017) identified some limitations with cockpit displays:
CDTIs will help you spot other ADS-B traffic more easily by showing you where to look. However:
- Depending on the unit’s filtering capability, your CDTI might not show all ADS-B traffic
- CDTIs will not display non-ADS-B traffic
- Don’t try to second-guess ATC instructions with CDTI information
- Do not attempt to take evasive action, or to separate your aircraft from other traffic, using a CDTI. It is there to enhance situational awareness, not to replace separation procedures.
Cockpit display of traffic information does not replace see-and-avoid. You still have to look out the window for other traffic.
Electronic flight bag
The student pilot in AEM was using ‘AvPlan’ electronic flight bag (EFB)[33] software installed on an iPad. In addition to the EFB, this pilot was also carrying a paper flight plan and set of relevant approach charts.
AvPlan has an option to display traffic information overlayed on the map display.
Traffic information can be obtained either by:
having an external ADS-B receiver attached
using the ‘AvPlan live’ feature.
Use of the AvPlan live traffic information system required the live tracking feature to be turned on, a data connection and a connection to a GPS position. The iPad in AEM was fitted with a SIM card capable of providing the required data connection to AvPlan live, but was not fitted with an external ADS-B receiver. The AvPlan user manual identified that traffic displayed using the AvPlan live function was from:
…other connected airborne AvPlan EFB users, a network of ADS-B ground receivers, and FLARM[34] ground receivers.
Data displayed using AvPlan live was updated every 5 seconds, rather than every second when an ADS-B receiver was attached. The software had no capability to identify aircraft using other EFB software, or non-ADS-B equipped aircraft. The AvPlan user manual noted:
Note that this traffic is a great start for situational awareness, however it does not include all traffic. Always be on the lookout/maintaining a listening watch for traffic.
Due to the damage to the tablet sustained in the impact, it was not possible to recover data from the iPad to determine whether the traffic information overlay display was selected at the time of the collision.
The ADS-B ground receiver network used by AvPlan for traffic information was not the same as the network used by Airservices for receiving ADS-B data, and there was limited coverage for the AvPlan network in the Mangalore area. Information provided by AvPlan after the accident identified that aircraft in the approximate location of the collision, 5 NM south of Mangalore airport, were not visible as traffic on AvPlan below approximately 4,900 ft. Therefore, as the pilots in JQF were not carrying an AvPlan‑connected iPad and it was unlikely that the AvPlan ADS-B ground network received broadcasts from JQF it is probable that JQF would not have appeared as traffic on the iPad used in AEM, even if the traffic information overlay had been selected.
The use of an external ADS-B receiver significantly increases the frequency of updated traffic information and receives ADS-B broadcasts directly from ADS-B OUT equipped aircraft within range of the receiver. Information from the AvPlan user manual stated:
When AvPlan EFB is connected to an ADS-B receiver, traffic as far as the receiver can observe will be displayed. Traffic sources from the receiver will be coloured green to allow quick identification of a traffic target’s source. No height or distance limitations are placed on traffic delivered by an attached device. Traffic received via this method is updated once every second”.
At the time of the accident, neither AvPlan nor OzRunways, another Australian EFB provider, provided audible alerts about proximal traffic, although at the time of writing AvPlan offered this feature.
Collision avoidance systems
ADS-B also has the ability to feed into an aircraft collision avoidance system (ACAS). Neither aircraft were required to have ACAS fitted.
In describing ACAS, the ICAO (2021) stated:
The objective of airborne collision avoidance systems (ACAS) is to provide advice to pilots for the purpose of avoiding potential collisions….
ACAS has been designed to provide a back-up collision avoidance service for the existing conventional air traffic control (ATC) system while minimizing unwanted alarms in encounters for which the collision risk does not warrant escape manoeuvres. The operation of ACAS is not dependent upon any ground-based system.
By providing pilots with visual information about where other aircraft are operating in their proximity, pilots are able to make more timely decisions based on displayed information and take avoiding action, thereby reducing the risk of collision.
At present in Australia, there are no regulatory requirements for aircraft of the size and operational category involved in this accident to have any form of ACAS fitted to the aircraft.
In 1991 the Bureau of Air Safety Investigation (the predecessor to ATSB) issued the Civil Aviation Authority (the predecessor to CASA) with a recommendation that:
In light of the serious limitations of the see-and-avoid concept, the CAA should closely monitor the implementation of TCAS[35] in the US and should consider the system for Australia.
In 1998, CASA accepted this recommendation and stated the system would be introduced when cost effective.
Under the current regulations in Australia, an approved ACAS must be fitted any turbine-engine aeroplanes operating under Part 121 (Australian Air Transport Operations – Larger Aeroplanes) that:
Paragraph 11.21
a. Either:
i. has a maximum take-off weight of more than 15,000kg; or
ii. has a maximum certificated passenger seating capacity of more than 30; or
b. Is first registered, in Australia or elsewhere, on or after 1 January 2014, and:
i. has a maximum take-off weight of more than 5,700 kg but not more than 15,000kg; or
ii. has a maximum certificated passenger seating capacity of more than 19 but not more than 30.
Aircraft operating under Part 135 (Australian Air Transport Operations – Smaller Aeroplanes) must be fitted with an approved ACAS if they are turbine-engined, have a maximum take-off weight of more than 5,700kg and was first issued with a certificate of airworthiness on, or after, 1 January 2014. There are no regulations requiring fitment of an ACAS to aircraft equivalent to AEM and JQF.
Meteorological information
Forecast weather
The Bureau of Meteorology (BoM) produced a terminal area forecast (TAF)[36] for Mangalore Airport and the surrounding area, and a graphical area forecast (GAF)[37] for Victoria. The forecast conditions at the time of the accident included scattered cloud at 2,500 ft AMSL[38] and between 3,500 ft and 6,000 ft AMSL. Visibility was forecast to be greater than 10 km, and the wind from the south‑west (230°) at 15 knots at ground level, with gusts up to 25 knots. The grid-point wind and temperature forecast listed the wind at 5,000 ft as from 210° at 32 kt.
Actual weather
The Aerodrome weather report (METAR/SPECI) issued at 1130, 6 minutes after the collision, identified the presence of three cloud layers - broken layers at 3,000 ft and 3,700 ft AMSL[38] and an overcast layer at 4,500 ft.
At the time of the accident, the automatic weather service (AWS) at Mangalore Airport recorded two cloud layers: one scattered at about 3,500 ft AMSL[38] and a second broken layer at 4,200 ft (about the collision altitude).
Three photographic sources were also reviewed to assess the likely cloud conditions at the time of the accident. Figure 16 identifies the locations where these images were recorded.
Figure 16: Location of photographic sources used in the cloud assessment
Source: Google Earth, annotated by the ATSB
Figure 17 shows an image recorded by a BoM weather camera at Kilmore Gap (elevation 1,731 ft), looking north towards Mangalore Airport at the time of the collision.
Figure 17: Weather camera image from Kilmore Gap facing towards Mangalore Airport
Source: BoM
A similar image was recorded at Wahring Field (elevation 410 ft) looking in a south-east direction at 1120 (Figure 18)
Figure 18: Weather camera at Wahring Field
Source: BoM
Video imagery recorded by the Victoria Police Air Wing (Figure 19) near the accident site at 1240, 1 hour and 16 minutes after the accident showed a broken layer of cloud at approximately 4,050 ft AMSL with some lower patches of cloud also present. This is just below the approximate height of the collision (4,100 ft)
Figure 19: View of cloud from the Victoria Police Air Wing helicopter
Source: Victoria Police
The observed cloud conditions were marginally poorer than forecast, but still suitable for the flights. The observations show scattered, broken and overcast cloud layers with bases below, at, and above the collision altitude.
Information from the automatic weather service was available to pilots on an aerodrome weather information service (AWIS) radio frequency. It is likely that the pilots of AEM checked this information before making their inbound CTAF call.
Recognising that both the aircraft were operating under the IFR, AIP ENR 1.2 defined the criteria required for pilots to maintain visual meteorological conditions (VMC) (Table 6).
Table 6: Criteria to maintain VMC in Class G airspace
At the time of the collision a scattered cloud layer was observed at Mangalore Airport at 3,500 ft and a broken layer at 4,200 ft, encompassing the collision altitude. However, just 6 minutes after the accident the lower cloud layer was observed to be broken. The later Police video showed that the broken cloud base was about 4,000 ft with some lower patches. The observations recorded over the time between the accident and the Police helicopter arriving indicated the weather remained similar, with only a slight increase in cloud base of about 100 ft.
Therefore, at the time of the collision, the aircraft were probably near a layer of scattered to broken cloud, and just below a further broken to overcast cloud layer. Consequently, as AEM descended it is probable that the aircraft was surrounded by cloud until passing through about 4,500 ft. While the aircraft may not have been in cloud at the time of the collision, the extensive surrounding cloud would have reduced conditions to significantly below VMC, reducing the opportunity for visual acquisition by any of the pilots.
Aerodrome information
Overview
Mangalore Airport has an elevation of 467 ft. The airport has four paved runways – 05/23 and 18/36[39]. At the time of the accident, runway 23 was in use. The airport is used for a variety of general aviation purposes, including a high volume of ab-initio pilot training. There are no scheduled regular public transport operations to the airport.
There was no specific data collected by the airport about the number of aircraft using Mangalore Airport however, the CASA Office of Airspace Regulation (OAR) provided the ATSB with the traffic information used for monitoring risk at Mangalore airport, which was provided to them by Airservices. This traffic information is summarised in Table 7 (see the section titled Airspace oversight).
Table 7: Mangalore Airport movement data
Source: CASA
Local flight procedures
The ERSA current at the time of the accident included a number of notes that identified several local flight procedures for the airport. Three of these were applicable to the operations of AEM and JQF. The procedure requiring additional radio calls above the standard requirements at non-controlled aerodromes has been previously discussed (see the section titled Common traffic advisory frequency)
Practice instrument approaches
Note 2 stated:
Except as required during instrument rating tests, pilots making practice instrument approaches should add 1,000 ft to the altitude prescribed in the approach to reduce interference with Mangalore AD circuit traffic. Such flights must broadcast their intentions, including altitude limits of OPS. Similarly, pilots making instrument approaches in IMC on encountering VMC are required to remain as high as practicable and join the circuit in the standard manner.
Records from CASA indicated that this local procedure first appeared in the Mangalore ERSA in July 1997. The airport manager provided information to the ATSB that this procedure was requested by a flying school to assist with the separation of instrument approach traffic from circuit traffic. Airservices and CASA were unable to provide any further background about this procedure.
This procedure is not unique to Mangalore Airport, the ERSA also described similar local procedures at Ballarat, Busselton, and Latrobe Valley airports. In a review of Ballarat Airspace published in August 2017, OAR received stakeholder feedback that IFR training aircraft were incorrectly approaching Ballarat without the required additional 1,000 ft of height stated in the ERSA. In response, OAR made a recommendation that:
CASA should provide specific information to IFR pilots that frequent Ballarat about the additional 1,000 ft procedure.
Interviews conducted by the ATSB established that the two operators involved in this accident interpreted and applied this ERSA local procedure differently. Specifically:
Previous students of the instructor in AEM applied 1,000 ft to the minimum decision altitude only, flying the approach as published and discontinuing early.
The operator of JQF stated that they required pilots to add 1,000 ft to all heights identified on the chart. However, they stated that while they were aware that the two largest flying schools using Mangalore Airport applied it this way, there were other operators that applied the procedure the same way as the operator of AEM.
When the ATSB requested clarification about the intention of the wording of the procedure, CASA advised that:
This procedure is to be applied by adding the 1,000 ft to all waypoints and the MDA.
Landing lights
Note 3 stated:
It is recommended that all ACFT shall illuminated LDG and taxi lights WI a 10 NM radius of the airport and when established in the circuit.
Due to the extent of damage, investigators were unable to determine whether AEM had landing lights switched on. Examination of JQF identified the landing lights were switched on at the time of impact however, it is also noted that landing lights have a relatively narrow beam and therefore are only visible from the frontal aspect of an aircraft.
Recorded data
Neither aircraft was equipped with a flight data recorder or a cockpit voice recorder, nor were they required to be, due to their size and type of operation. In January 2021, the ATSB issued a safety recommendation to CASA (Safety issue number AO-2017-118-SI-03) recommending the consideration of mandating the fitting of onboard recording devices for passenger-carrying aircraft with a maximum take-off weight less than 5,700 kg. A second recommendation (Safety issue number AO-2017-118-SI-04) was also made to the International Civil Aviation Organization (ICAO):
The Australian Transport Safety Bureau recognises that the International Civil Aviation Organization has developed technical standards for lightweight recorders and airborne image recorders. However, despite the known benefits for the identification of safety issues, the fitment of such devices for passenger-carrying aircraft with a maximum take-off weight less than 5,700 kg is not mandated. The Australian Transport Safety Bureau recommends that the International Civil Aviation Organization takes safety action to consider the safety enhancement of these devices to passenger-carrying operations.
Airservices provided the ATSB with two sources of data relating to the accident flight:
Filtered ADS-B and radar data showing the aircraft as they appeared on the controller’s display. This data was filtered to approximately 5 second intervals.
Raw ADS-B data captured from the ADS-B receivers. This information captured the ADS-B out data from each aircraft at intervals of less than 1 second. This data was not available to the controller at the time, but has been used for the aircraft performance and visibility study (see the section titled Aircraft performance and cockpit visibility study)
Flight data received from the EFB used by the student in AEM was also provided by AvPlan. This ADS-B data matched the data provided by Airservices.
No data was recoverable from any of the instruments on board either aircraft.
Flight path data
The raw ADS-B data was analysed to determine how the two aircraft came together. The data indicated that approximately 0.55 seconds before the collision AEM was on a true heading of 352° and JQF on a true heading of 132°, giving a relative heading angle of 140° (Figure 20). At this time JQF and AEM were estimated to be at the same level, 4,125ft, with JQF maintaining altitude and AEM descending on approach to Mangalore (Figure 21, Figure 22). The groundspeeds of JQF and AEM, considering all available wind information and limitations in the ADS-B data, were around 94 kt and 192 kt respectively with a closing speed just prior to the collision of approximately 245 kt.
The data for AEM showed very little variation in track and the data for JQF showed a slow turn towards the flight planned track to LACEY. Based on the lack of rapid or pronounced change in the aircrafts’ flight paths it is unlikely that an evasive manoeuvre was initiated by the pilots in either aircraft. Figure 22 shows the total separation, including both lateral and vertical components, of AEM and JQF after the time of JQF’s take-off from Mangalore. This illustrates that the two aircraft remained on a collision course for most of the flight.
It should be noted that this data was not available to the controller at the time of collision. However, this information would have been available to the pilots of AEM and JQF had both aircraft been fitted with additional ADS-B IN technology.
Figure 20: Aircraft position for AEM and JQF
Source: ATSB, based on data provided by Airservices.
Note: Due to wind, the angle of approach (track angle) will appear smaller than the angle of collision (heading angle).
Figure 21: Vertical profile and timeline for AEM and JQF
Source: ATSB, based on data provided by Airservices.
Figure 22: Total separation between AEM and JQF in nautical miles
Source: ATSB, based on data provided by Airservices.
Wreckage and impact information
Overview
Following the mid-air collision, JQF continued for about 0.5 km before impacting an open field, while AEM continued in a northerly direction and impacted a lightly wooded area about 1.4 km from the collision point (Figure 23).
Airborne debris liberated in the collision formed a further wreckage field about 1.6 km to the north-north-east of the collision point and about 200 m to the west of the Hume Highway. The debris field contained parts of both aircraft, including the front section of JQF’s right wing, and the instrument panel coaming from AEM.
Inspection of both aircraft identified paint transfer from the other aircraft. A blue paint transfer was noted on the instrument coaming of AEM, indicating that the right wing of JQF had passed through the cabin area of AEM. After contact between the two aircraft, JQF likely lost a section of the right wing outboard of the engine nacelle, which was the piece found separate from the two aircraft.
Figure 23: Locations of collision, AEM, JQF and debris field
Source: Google Earth and Airservices, annotated by the ATSB.
VH-AEM site
The Travel Air was found in a significantly disrupted state, and it was not possible to conduct an extensive examination of the engines and aircraft control systems.
From observations of the wreckage and damage to nearby trees and ground scars, it was established that the aircraft collided with the ground in a wings-level but steep, inverted attitude. The aircraft passed through the tree canopy and collided with flat ground, the right wing impacted the base of a large tree, a post, and a fence. The wreckage trail was on a heading of 355⁰, just right of the aircraft’s track prior to the collision, with the wreckage spread along a 30‑metre path, from the initial impact point to the resting position of the aircraft.
The examination of the airframe and engine systems did not identify any pre-existing defects likely to have contributed to the accident. Flight data showed the aircraft was descending in a stable attitude, until the mid-air collision. Site inspection indicated that the landing gear and flaps were retracted at impact with the ground.
VH-JQF site
Witnesses reported seeing JQF in a spinning descent prior to the collision with terrain, which is supported by the wreckage examination. The aircraft impacted terrain in a relatively flat attitude.
The examination of the airframe and engine systems did not identify any pre-existing defects likely to have contributed to the accident. Flight data showed the aircraft was level immediately prior to the mid-air collision.
All components of JQF were accounted for at the accident site with the exception of some of the right-wing sections, which were located in the debris field to the north of JQF’s location, and the right aileron mass balance weight, which was located inside the wreckage of AEM.
The collision
Analysis of the wreckage from each aircraft indicated that the two aircraft came together at an obtuse relative angle with JQF crossing over the top of the AEM (Figure 24).
Figure 24: Estimated collision aspect based on ADS-B data and wreckage assessment
Source: ATSB.
Airspace oversight
Under the Airspace Act 2007, CASA, through their OAR was responsible for regulation of all Australian airspace. This included the classification of airspace.
Section 13 of the Airspace Act 2007 specified that:
(1) CASA has the function of conducting regular reviews of the existing classifications of volumes of Australian-administered airspace in order to determine whether those classifications are appropriate.
(2) CASA has the function of conducting regular reviews of the existing services and facilities provided by the providers of air navigation services in relation to particular volumes of Australian-administered airspace in order to determine whether those services and facilities are appropriate.
(3) CASA has the function of conducting regular reviews of Australian-administered airspace generally in order to identify risk factors and to determine whether there is safe and efficient use of that airspace and equitable access to that airspace for all users of that airspace.
The Australian Airspace Policy Statement 2018 outlined the process for reviewing the classification of a volume of airspace at an aerodrome. The thresholds set for conducting an airspace review were based on a set number of either total annual:
aircraft movements;
public transport operation movements; or
public transport operation passengers.
If an airport met or exceeded any of the thresholds for a classification (Table 8), in line with the policy CASA should complete an airspace review of the particular volume of airspace. The purpose of a review was to determine whether the airspace classification was appropriate and whether additional air traffic services was required, considering public, industry and agency comments, forecast future traffic levels, and any other significant risk mitigators.
Table 8: Airspace review criteria thresholds
Source: Australian Government (2018)
There were no requirements for the review of airspace where aircraft movements or passenger numbers did not meet the thresholds identified, however there was a provision in the Australian Airspace Policy Statement 2018, which stated that:
These criteria do not preclude CASA examining the requirement for airspace changes at other aerodrome locations should CASA consider such examinations is required, for example, on risk of safety grounds.
The available information on recorded aircraft movements and passenger numbers at Mangalore Airport (see the section titled Aerodrome information) did not reach the thresholds for the conduct of an airspace review.
Outside the formal review system, the OAR conducted risk assessments on numerous aerodromes and their surrounding airspace. Records provided by CASA indicated that, prior to this accident, these assessments for Mangalore were last conducted in May 2018 and July 2019. Comments associated with these reviews indicated an awareness that the data quality about the known movements was poor, and that there were fluctuations associated with a low number of aircraft movements, and that there has been an increase in Seminole and King Air operations which CASA attributed to training flights.
At the time of the accident, the OAR had not conducted a formal review of the airspace around Mangalore. A 2011 study of the Melbourne airspace noted that Mangalore had a high level of aviation activity, but was outside the scope of the study. CASA launched an aeronautical study of the Mangalore airspace in September 2021. The results of this review had not been released at the time of publication of this report.
The Australian Airspace Policy Statement was updated in November 2021. This update removed the prescriptive thresholds for a review, and instead moved towards risk-based assessments.
Mid-air collisions
See and avoid
In non-controlled airspace, pilots rely on the use of the rules of the air and see-and-avoid to maintain separation from other aircraft sharing the airspace. The limitations of see-and-avoid principle are well published.
The 1991 ATSB report ‘Limitations of the See-and-Avoid Principle’ is cited extensively in pilot guidance by CASA and foreign regulators and investigators. The paper identified a number of factors that influence the ability for a pilot to see-and-avoid other aircraft. It includes the statement that:
See-and-avoid can be considered to involve a number of steps. First, and most obviously, the pilot must look outside the aircraft.
Second, the pilot must search the available visual field and detect objects of interest, most likely in peripheral vision.
Next, the object must be looked at directly to be identified as an aircraft. If the aircraft is identified as a collision threat, the pilot must decide what evasive action to take. Finally, the pilot must make the necessary control movements and allow the aircraft to respond.
Not only does the whole process take valuable time, but human factors at various stages in the process can reduce the chance that a threat aircraft will be seen and successfully evaded. These human factors are not ‘errors’ nor are they signs of ‘poor airmanship’. They are limitations of the human visual and information processing system which are present to various degrees in all pilots’.
It is likely that the cloud present on the day affected the ability of the pilots to see the approaching aircraft. However, even without this cloud, the ATSB paper identified additional limitations of see-and-avoid:
Workload – The pilots in JQF were in the climb phase of a test flight and establishing the aircraft on the outbound track. The crew of AEM were conducting the first in-aircraft VOR approach with this student.
Visual search – A human’s field of vision begins to narrow after 35, and significantly after age 55. Additionally, in daylight, a pilot must look almost directly at an object to see it. Therefore it is possible for a pilot to look past an object in their screen if they do not see it directly.
Cockpit visibility – Items such as engines, window pillars, sunshades, and dirt may impact on the pilot’s ability to see an aircraft.
Time to conduct a traffic scan – Pilots require a long time to effectively conduct a traffic scan, during which time the picture out the window changes due to the motion of the aircraft.
Limitations of vision – Factors such as the eye’s physiological blind spot and the threshold of an individual’s vision and the acuity of their vision. Some individuals may perceive another aircraft much further away than others.
Alerted traffic search – It is estimated that pilots who are told where an aircraft is are around eight times more likely to see the aircraft than pilots who are not alerted to the direction of an aircraft.
Characteristics of the aircraft – Aircraft are more easily spotted if they have a high contrast with their background
Relative movement between aircraft – It is difficult to see another aircraft when there is little relative motion between one aircraft and the other, such as when they are moving towards the same location in space. Furthermore, when aircraft have a high closing speed, the small visual angle presented by an aircraft may not grow rapidly until collision is imminent.
In addition to the issues presented with pilots seeing other aircraft, there is evidence that pilots need around 12.5 seconds after they see an aircraft to perceive what it is and respond with an evasive manoeuvre to avoid the collision. The research shows that older or less‑experienced pilots need even longer.
Excluding the likely influence cloud had on the opportunity for the pilots of each aircraft to sight the other aircraft; at 12.5 seconds prior to the collision, the angular size that each aircraft would have appeared was only around 0.4°; increasing to around 1° 5-6 seconds pilot to the collision.
Studies have assessed the size an object needs to be for it to be sighted, with estimations varying from 0.2° degrees (NTSB, 1988) to 0.4-0.6° (Morris, 2005). However, these observations may be made under certain conditions, and not reflective of the particular conditions experienced by these pilots.
Collision prevention
The United Kingdom (UK) Airprox[40] board commissioned a research paper (Helios 2014a, 2014b) to review the risk of mid-air collision in Class G airspace. While the particular operation and regulation of Class G airspace in the UK is slightly different from that in Australia, it remains non‑controlled airspace, with an available traffic information service.
The research identified seven barriers to mitigate the risk of mid-air collisions (Figure 25). Four of these were preventative, to avoid the occurrence of both conflicting traffic and incidents:
- strategic conflict management, - pre-tactical events, - pilot tactical control, and - ATC tactical intervention,
The other three barriers were attempts to stop an incident becoming an accident:
- ATC recovery, - pilot recovery (ACAS) and - pilot recovery (see and avoid).
Analysis of all the received UK airprox reports identified that pilot see-and-avoid was the most effective at preventing mid-air collision, but was also the last available defence. The study also found that an alert provided by ATC following a STCA effectively prevented 1.5 per cent of events escalating to collisions.
Figure 25: Barriers of defence in preventing a mid-air collision
Source: Helios, 2014b
Aircraft performance and cockpit visibility study
As previously discussed, the evidence indicates that the collision occurred either in, or very close to, the bottom of a cloud layer (see the section titled Meteorological information), with minimal opportunity for the occupants of the two aircraft to see-and-avoid each other.
However, in order to more fully understand the situation presented to the pilots, the ATSB conducted an aircraft performance and cockpit visibility study for this investigation, based on similar work carried out by the United States National Transportation Safety Board[41] and refined for a number of investigations over recent years, most recently for the 2019 mid-air collision near Ketchikan, Alaska (NTSB, 2021).
The study estimated the time windows during which the respective aircraft would have been visible to the pilots in the other aircraft if the accident had occurred in visual conditions. It also assesses the value of the installation and availability of traffic display and alerting systems based on the ADS-B data that both aircraft were transmitting.
This study was conducted as ATSB Safety Study report AS-2022-001. Results of this study indicated that the pilots would have faced significant difficulties in using the see‑and‑avoid principle to avoid the collision and that ADS‑B‑based alerting would likely have prevented the accident.
Related occurrences
This is the first recorded mid-air collision between two civil IFR aircraft operating in Australia.
A review of the ATSB’s national aviation occurrence database identified that a total of 29 civil mid‑air collisions (including this occurrence) were reported in the 20 years between 2001 and 2020. Of these 29 collisions, 21 were classified as accidents, with 12 resulting in fatal outcomes. The remaining 8 collisions did not result in a sufficient level of damage or injury to meet the definition of an accident in the Transport Safety Investigation Act, 2003 and were instead categorised as incidents or serious incidents.
Of the 28 mid-air collisions, other than this accident:
One incident was a collision between an aircraft and a parachutist as they exited the aircraft;
Eight collisions occurred between two gliders (6 accidents with 2 being fatal; 2 serious incidents);
One serious incident was a collision between a paraglider and a hang glider;
One fatal accident was a collision between two ultra-light aircraft that reportedly also hit a powerline;
Three collisions involved two aircraft operating together in either aerial mustering or fire control activities (one fatal accident between two helicopters, one serious incident between two helicopters, and one fatal accident involving a helicopter and an aircraft);
Three collisions occurred between aircraft conducting formation flying (1 accident, 1 serious incident, 1 incident);
Four accidents occurred between aircraft on late final approach to land, 2 of which were fatal;
Five collisions occurred between aircraft operating elsewhere in the circuit – 2 of these were fatal accidents, 2 were accidents with no injuries and one was a serious incident;
One fatal accident occurred between an aircraft departing from an airport and one conducting aerial agriculture work in the vicinity of the aerodrome; and
One fatal accident occurred between two aircraft converging at the approach point to an airport.
All of the aircraft involved in these 28 mid-air collisions were operating under visual flight rules. Twenty six of the 28 mid-air collisions occurred in non-controlled airspace. Nineteen of these occurred within 10 NM of an airport, aerodrome or authorised landing area.
Apart from this accident, in the same 20-year period there have been 25 other airspace‑related occurrences reported to the ATSB in the vicinity of Mangalore Airport.
Eleven of the 25 occurrences were categorised as a near collision[42]; four of which involved one aircraft operating under the IFR, and one that involved both aircraft operating under the IFR. All eleven occurrences were categorised as serious incidents.
Two of these serious incidents were investigated by the ATSB and are summarised below:
AO-2011-119: Airprox - VH-CIX/VH-KHG, Piper PA-28-151/PA-44-180, Mangalore Airport, Victoria on 27 September 2011
While conducting circuits, the Piper PA-28 came within close proximity of a Piper PA-44 rejoining the circuit following an instrument approach, resulting in the crew of the PA-28 taking evasive action. Both aircraft were operated by the same company.
As a result of the incident the operator introduced a procedure whereby, when the wind conditions favoured a take-off towards the north or north-east, aircraft joining the circuit from a practice instrument approach were to descend to an overfly height of 2,000 ft AMSL and join the circuit from the non-active side of the circuit.
AO-2014-006: Near collision involving a Cessna 404, VH-VEC and a Piper PA-28, VH‑UNW near Mangalore Airport, Victoria on 10 January 2014
The pilot of a Cessna 404 aircraft registered VH-VEC (VEC) was conducting an aerial survey flight north-east of Mangalore Airport, Victoria. The flight was being conducted under the instrument flight rules (IFR) and flown at about 1,500 ft above ground level. The survey pattern required the aircraft to fly across the extended centreline of runway 36. The pilot made all required CTAF broadcasts while operating in the area.
At the same time as VEC was conducting the survey, several aircraft were departing Mangalore for a series of different navigational exercises. The pilot of VEC continually attempted to call the pilots in the departing aircraft, to establish their position and intentions. However, as per their training, the pilot’s did not respond until their respective aircraft were at least 500 feet above the ground. Also, due to misunderstanding the pilot of VEC’s intentions, they did not respond to his radio calls, unless the request was directed at their particular aircraft. When the solo student pilot of VH-UNW (UNW) departed runway 36, they focussed on flying the aircraft rather than communicating, until reaching 500 feet above ground level. The pilot of UNW then lowered the aircraft nose to check for traffic and saw VEC in close proximity. In response, they turned UNW to the right at the same time that the pilot of VEC initiated a climbing turn to the right.
Both of these near collisions involved a conflict between a VFR and IFR aircraft in the CTAF area. In the near collision in 2014, separation between the two aircraft was reduced to 100 m horizontally and 200 ft vertically. In the earlier occurrence the separation was 30‑45 m horizontally, and at the same level.
One of the other near collisions in the CTAF area at Mangalore involved two aircraft operating under the IFR. One of those aircraft was VH-JQF, the same aircraft involved in this collision. A summary is below:
ATSB Occurrence 201200571: The Piper PA-44 was tracking outbound in the VOR holding pattern when another PA-44 crossed its path in close proximity, tracking inbound to the NDB at the same level.
At the time of writing, the ATSB is investigating another separation occurrence between two aircraft near Mangalore Airport on 6 June 2021 (AO-2021-023). In this incident, an Augusta Westland 139 helicopter was flying southbound toward Mangalore at an altitude of 3,100 ft. At the same time, a PA-44 was conducting an instrument approach to Mangalore.
Due to cloud conditions, the PA-44 commenced a missed approach from below 2,000 ft in a northerly direction toward Mangalore. Shortly after the PA-44 began climbing, and prior to the pilot broadcasting that the missed approach had been commenced, the pilot of the AW139 received a traffic collision and avoidance (TCAS) alert and manoeuvred the aircraft to increase separation. Both flights continued without further incident. A final report for this investigation is due to be published in the second quarter of 2022.
The two aircraft, VH-AEM and VH-JQF, collided in mid-air south of Mangalore Airport. This was the first recorded mid-air collision of two civil, instrument flight rules (IFR) flights in Australia, although not the first event where two IFR aircraft have come into close proximity with each other.
Site and wreckage examination did not identify any aircraft defects or anomalies that might have contributed to the accident. Additionally, no evidence was found to suggest any medical or fatigue‑related issues that would have likely affected pilot performance on the day of the flight.
Both aircraft involved in the accident were fitted with Automatic Dependent Surveillance Broadcast (ADS-B) OUT equipment which broadcast positional information. However, neither aircraft had the capability to directly receive this information. Flight path data did not support an evasive manoeuvre being initiated by either aircraft, suggesting that the pilots of both aircraft did not see each other in sufficient time prior to the collision to initiate avoiding action.
This analysis will examine how the two aircraft flight paths conflicted without the risk of a collision being identified and the accident prevented. Further, it will review the controls that could be used to prevent similar accidents from occurring in the future.
Operational environment
In non-controlled airspace, pilots hold responsibility for maintaining separation from other aircraft. The rules of the air require pilots to maintain a lookout for other aircraft when conditions permit, to not operate in a way that creates a hazard for other aircraft, and to monitor and broadcast on the appropriate frequency whenever it is reasonably necessary, to avoid the risk of collision.
Both aircraft had experienced pilots on board. The examiner in JQF and instructor in AEM were both highly experienced and had conducted similar operations many times before. The student in AEM had a high level of experience as a VFR pilot operating in controlled and non-controlled airspace. The exam candidate in JQF had completed an intense period of training and been assessed as competent to undertake the final assessment for their training course. All the pilots were familiar with the operational environment and how to separate from other traffic.
Both aircraft had operational requirements that needed to be achieved. According to the published approach chart, and the pilots interpretation of the ERSA requirements, AEM had to be at an altitude of not below 3,900 ft passing overhead Mangalore Airport to conduct the planned approach. Vertically, JQF had to avoid terrain until above 3,400 ft within 10 NM of the airport, and laterally, JQF had to be established on the outbound track to waypoint LACEY within 5 NM of the departure airport. If the intercept of the outbound track exceeded this distance, the candidate would not have demonstrated the required competencies for the departure sequence of the flight test. In controlled airspace these flight tracking requirements would be assessed and managed by an air traffic controller. In non-controlled airspace the pilots’ were required to assess and manage the operational requirements and collision risk.
AEM and JQF were both fitted with dual radios. Examination of the radios fitted to JQF identified that the radios were tuned to the expected CTAF and Melbourne Centre frequencies. As the pilots of AEM had not indicated to the controller that they were switching to the CTAF, it can also be reasonably assumed that they also had the radios tuned to the appropriate CTAF and Melbourne Centre frequencies.
Air traffic control recordings confirmed that pilots from both aircraft communicated with Melbourne Centre, and interviews with other pilots in the area identified calls occurring from pilots of both aircraft on the CTAF. Significantly, a review of events leading up to the collision identified that pilots from AEM and JQF may have been communicating on different frequencies at the same time and therefore missed important alerting information from, and about, the other aircraft.
The human ability to monitor two frequencies simultaneously is limited, particularly in periods of high workload or stress, such as during a flight test or early instrument flight, and when there are other non-pertinent broadcasts on the frequencies. While the instructor in AEM and the examiner in JQF had more capacity to monitor both frequencies than the students by virtue of their relative experience, they both had other responsibilities in their training and checking roles that may have affected their ability to identify and assess all broadcasts. The initially missed call made from the Melbourne Centre controller to the pilots of AEM, where the pilots were likely either listening to the AWIS or setting up the aircraft for the descent to the approach is consistent with the known effect of workload on other tasks.
While other pilots flying in the area recalled broadcasts from both aircraft on the CTAF prior to the accident, no‑one recalled coordinating transmissions between the pilots of the two aircraft. While it is possible that this may have occurred and not been recalled by other pilots in the area, this was considered unlikely.
Having both been advised of the presence of the other by the Melbourne Centre controller, it is also highly unlikely that the pilots intentionally continued into a situation where they assessed the other aircraft to be a threat without taking action, including communicating, to protect themselves. As such, the ATSB concluded that the pilots either failed to identify that a collision risk existed or identified the potential risk but incorrectly assessed that the aircraft were sufficiently separated. In either case, the primary defence of established self‑separation required in non‑controlled airspace was absent.
Limitations of see-and-avoid
While it is not certain that the accident took place in cloud, it is clear the accident took place in instrument meteorological conditions due to the presence of extensive cloud. It is likely that AEM was in cloud for most of its descent from 6,000ft. JQF may have manoeuvred around cloud during the climb, explaining the variation in track, or passed through cloud on its climb, and had cloud between it and AEM for most of the time from when traffic information was passed until the collision.
This would have significantly reduced the likelihood that the aircraft were visible to one another prior to the collision. If either aircraft were operating in cloud, see-and-avoid would have been unachievable to both. However, if visual meteorological conditions had existed, under IFR, they would have been expected to use see-and-avoid, along with radio broadcasts, to avoid each other.
The limitations of see-and-avoid have been widely discussed in previous accident investigations, and in CASA guidance to pilots.
After JQF entered a turn towards the outbound track, the two aircraft maintained a reasonably constant relative position. This means that, had they been visible to each other, their position in the windscreen would have had limited movement, making perception difficult. The closure rate between the two aircraft was also very high, meaning that even 20 seconds prior to the collision, the angular size of each aircraft would have made them barely perceivable. Other factors that may have affected the ability of the pilots to see and avoid conflicting traffic included:
The crew of AEM were not directly alerted to the direction and height of JQF once airborne and may have either believed JQF was right of their track from the information in the associated departure call. Equally, they may have not heard JQF’s departure call through making their own report to Melbourne centre or inbound CTAF broadcast at the same time, and therefore not realised JQF was airborne.
The aircraft were both white with a background of textured ground or cloud.
The lack of variation in the flight tracks prior to the mid-air collision strongly suggests that the pilots did not see the other aircraft in time to commence avoiding action.
Local procedures
The evidence supports the pilots in the two aircraft probably having different interpretations of the wording of the local altitude requirements for practice instrument approaches at Mangalore detailed in the En-Route Supplement Australia (ERSA). It is also known that these different interpretations were held and applied by pilots other than those involved in this accident.
The different interpretations affected the altitude that AEM was required to be at when overhead the VOR. According to the reported understanding of the pilots in AEM, the approach would be flown as published, passing overhead the VOR at 3,900 ft and terminating the approach 1,000 ft higher than the minima. However, using the reported understanding of the pilots in JQF, aircraft conducting a practice VOR approach at Mangalore would start the approach at 4,900 ft. While it is not possible to determine why the pilots of JQF levelled off briefly at 4,100 ft prior to the collision, one possible consideration is that they may have believed they were passing a safe distance below AEM on its inbound descent to the VOR.
While the controller provided traffic information to the pilots of JQF that AEM was descending for airwork to ‘not above 4,000 ft’, the information that AEM was at 5,000 ft when the traffic information was passed, combined with possibly not hearing any inbound call from AEM, may have supported the pilots of JQF’s mental model of the higher practice approach height being used.
The safety benefit of clearly worded standard operating procedures, applied in the same way by all, is clearly understood in aviation. The procedure was originally written to separate IFR traffic from circuit traffic, which both interpretations would achieve. The risk of misunderstanding this procedure was identified by the CASA Office of Airspace Regulation at Ballarat in 2017. Despite that, the written procedure remained unchanged at Ballarat, Mangalore and two other airports. Information in the ERSA is published by Airservices, based on information provided by the airport operator. CASA advised that the procedure was intended to be applied by adding 1,000 ft to all heights in the approach.
Traffic information
From the Melbourne Centre records, ADS-B data, and the estimated times of broadcasts on the CTAF, it appears that there was some overlap between the pilots of the two aircraft making key transmissions or actions on different radio frequencies at the same time. In particular, around 1119 – 1121 the crew of AEM were likely checking the AWIS and communicating with the Melbourne Centre controller at the top of their descent and receiving traffic information. During the same time period, the pilot under examination in JQF was probably broadcasting on the CTAF prior to take-off.
This may have affected pilot awareness of the position of the other aircraft, and the associated collision risk.
The controller provided traffic information to each aircraft in accordance with the required procedures. The content of the traffic information gave the pilot of each aircraft the position of the other aircraft at the time, and the intended flight path. However, the timing of the traffic information did not give the pilots in AEM in particular, a clear understanding of where JQF would be as their flight paths neared.
AEM was outside the Melbourne Centre controller’s airspace and on a different frequency when the pilot of JQF made their taxi call. When AEM was given traffic about JQF, it was reported that JQF was still on the ground, shortly to depart. Analysis of ADS-B data available after the accident, which was not available to the controller at the time, indicated it was likely that JQF was somewhere in the take-off sequence at this time, but had not yet appeared on the controller’s display.
It is possible that JQF made a rolling broadcast, reportedly heard by other pilots in the CTAF, at the time that the pilots of AEM were providing information to the Melbourne Centre controller about their descent and airwork, or listening to the AWIS. If this were the case, the pilots of AEM may have been waiting to hear a broadcast from JQF on the CTAF indicating their take-off, and not expecting that they were airborne already. This, combined with the absence of JQF on the electronic flight bag display of the student in AEM, and the higher workload environment that would be expected in training a first VOR approach, made it unlikely that they had updated their mental model that JQF had departed and were a potential threat.
At the time the pilots of JQF were passed traffic about AEM, AEM was 10-11 NM from Mangalore. Previous students of the instructor have advised they were taught to provide traffic information early, at about 15 NM rather than the minimum required 10 NM. This was a recommended procedure due to the high performance of the Travel Air, but also meant that it was likely that AEM made a CTAF broadcast sometime in the window that the pilots of JQF were in the initial climb, changing radio frequencies to Melbourne Centre, or actively making the departure report to the Melbourne Centre controller.
If the pilots of AEM had made their CTAF broadcast later in the window, closer to 10 NM, which is possible considering the workload for the student setting up and conducting their first VOR approach, it is possible that the CTAF broadcast from AEM and the Melbourne Centre report from the crew of JQF were made at the same time, with neither aircraft occupants hearing the other.
Alternatively, the pilots of AEM may have heard the Melbourne Centre departure report made by the pilot of JQF, but, due to the missing ‘tracking to’ information in the call, expected that JQF was to the right of their track and not a threat to their inbound descent.
In summary, while there were a number of factors that may have impeded radio communication between the pilots of the two aircraft, it could not be determined why there was no apparent coordination on the CTAF.
There were opportunities for the traffic information to have been passed by the controller to each aircraft earlier, although the pilots of AEM would still have been told JQF was on the ground and the crew of JQF would have been told that AEM was inbound, but over 15 minutes away at the time of the JQF taxi call. As such, the earlier provision of traffic information would probably not have changed the alerting it provided. There is potential however, that traffic information provided to the pilots of JQF while they were still on the ground after their initial taxi call, but prior to departure, could have led to the aircraft remaining on the ground until AEM was overhead the airport.
Air traffic control procedures have no requirement for a controller responsible for Class G airspace to provide updated traffic information to IFR aircraft. Analysis conducted for the ATSB by an air traffic services subject matter expert identified a number of potential reasons why updated traffic information would not have been provided. Specifically, the controller:
could reasonably expect the occupants of the aircraft were talking to each other and taking action to avoid each other
may over-transmit the pilots while they are trying to talk to each other
not being fully aware of any coordination between the occupants of the two aircraft, could give advice that created a hazardous situation.
Automatic Dependent Surveillance Broadcast
When automatic dependent surveillance broadcast (ADS-B) equipment became mandatory for IFR aircraft, there was no requirement to be fitted with ADS-B receiving equipment. Had each aircraft been fitted with ADS-B IN, and a suitable cockpit display, the occupants would have received the same quality of surveillance information received by the controller.
This technology could have prevented this accident from occurring and, more generally, it provides a valuable enhancement to the long‑established procedures for maintaining separation in non‑controlled airspace.
Instead of receiving one snapshot of traffic information from a controller in non-controlled airspace, an ADS‑B display in the aircraft constantly updates a pilot about the position of other ADS‑B‑equipped aircraft and is capable of providing alerts when the traffic come within an unsafe proximity. If the pilots had more information about their proximity, either through updated traffic information or ADS-B IN display and alerts, they would probably have acted differently to separate, and avoided the collision.
Surveillance service technology has aided the work of air traffic controllers, enabling them to provide a traffic position service with known accuracy of aircraft altitude and position rather than simply applying procedural separation.
This accident occurred in a location where both SSR and ADS-B data was captured and a surveillance service was offered. In areas where an existing SSR service exists, the mandatory fitment of ADS-B broadcasting equipment, without the fitment of ADS-B receiving equipment and an in-cockpit display of traffic information has provided little advantage to operators of IFR aircraft in non-controlled airspace.
Arguably, if these two aircraft were operating outside a surveillance service, the traffic information provided to them based on AIP GEN 3.3 paragraph 2.16.4, in the AIP version dated 7 November 2019, current at the time of the accident standards, would have kept them further apart than when their positions were accurately known. So, while the controller had better traffic information and a more accurate picture of where the two aircraft were coming together, the pilots did not share this information.
The advantage of ADS-B broadcast equipment comes from extending the area in which a surveillance service can be offered to an operating aircraft, as well as providing direct information to aircraft fitted with receiving equipment both within and outside of a surveillance environment.
ADS‑B IN and OUT also provide valuable alerting to VFR aircraft. CASA Advisory Circular 91-23 (2020) stated, in relation to ADS-B options for VFR aircraft, that:
All instrument flight rules aircraft have ADS-B transmitting equipment (ADS-B OUT). Logically, ADS-B OUT is the ideal way for VFR aircraft to signal their presence directly to other aircraft. In effect, ADS-B turns the ‘see and avoid’ concept into ‘see, BE SEEN, and avoid’.
In the lead up to the collision, all four pilots had to make decisions about the location of the other aircraft, based on information supplied to them by the controller. It is difficult for pilots to keep an updated mental model of where other aircraft are, particularly if they are not familiar with the performance capability of that particular aircraft, as they manoeuvre their own aircraft in the airspace.
By contrast, ADS-B IN equipment has the benefit of identifying accurate positions of other aircraft broadcasting ADS-B OUT information, although it still has the limitation that it cannot display other aircraft not broadcasting ADS-B OUT. Consequently, even with ADS-B IN display equipment, pilots need to be aware of positional information about potentially conflicting not broadcasting ADS-B aircraft, and not just rely on alerts generated by the ADS-B IN equipment. The NTSB report into the 2019 Ketchikan, Alaska mid-air collision, in which both aircraft were carrying ADS-B IN display equipment, showed there were limitations in alerting functions due to software differences. As such, even when ADS-B receiving equipment is fitted, radio communications should remain the primary method for pilots operating in non-controlled airspace to arrange separation with other pilots in the vicinity.
The student pilot in AEM made a proactive choice to carry an electronic flight bag (EFB), connected to a mobile network. While this EFB had the ability to display conflicting traffic, there were limitations in the type of traffic that would be displayed, and in this case it was unlikely to have displayed JQF. Tablets can however be fitted with an external ADS-B receiving unit that will provide this additional information, and in some cases aural alerting, from ADS-B broadcasting aircraft.
Short term conflict alert
Once a controller passes traffic information to two IFR aircraft, they do not receive any feedback on whether the two aircraft have established communications or a separation plan. There is no requirement for a pilot to respond that they have traffic sighted or contacted. Once traffic is passed, the controller operates on the expectation that, if required, the pilots will coordinate to ensure separation.
Because aircraft operate in non-controlled airspace, without published separation standards, it is not unusual for controllers to receive a short term conflict alerts (STCAs). Nuisance alerts, or alerts which need to be checked but very rarely responded to are of little benefit. Controllers responsible for the same airspace reported regularly receiving STCAs, with this accident being the first collision involving IFR aircraft.
These were not the only two aircraft the controller was managing at the time. While it was not reported to be a high workload period, the controller was constantly communicating with other aircraft in the time between providing traffic to the pilots of JQF and the accident. There is guidance that a STCA alert should be responded to over all other communications, and records show that the controller did prioritise an assessment of the alert while talking to another aircraft.
In the documented procedures for a STCA, there was no written difference for response to a STCA in controlled airspace and non-controlled airspace. Controllers are taught to use their judgement in assessing the integrity of a STCA and to respond appropriately. Therefore, in non‑controlled airspace, when the controller is displayed a STCA, they assess the risk in the context of whether traffic information has been passed from the controller to each of the pilots of the involved aircraft. Additionally, Airservices do not consider the STCA as a defence in non-controlled airspace.
In the 3 minutes before the collision, the controller received three separate STCAs involving these two aircraft. One was spurious and the velocity vectors at the time of the others projected the aircraft would pass each other, albeit narrowly for the third alert. The recordings indicated that the controller responded to these as per procedures.
With hindsight, the velocity vectors during the third STCA, which occurred less than 30 seconds prior to the collision, accurately indicated the conflict. When the STCA was assessed and acknowledged by the controller about 10 seconds prior to the collision, the display indicated that 500 ft displacement existed between the two aircraft, which the controller considered to be a reasonable pilot‑managed vertical separation. However, taking into account the filtering of data, and the permitted 200 ft tolerances, the risk of collision was higher that indicated on the display.
Additionally, this information was presented in the context that:
alerts regularly occurred as nuisance or no-risk alerts
alerts were based on separation standards not appropriate to the airspace
traffic had been provided to the aircraft in accordance with procedures
the aircraft still appeared vertically separated
self‑separation permitted the two aircraft to pass relatively closely.
It is acknowledged that the final STCA activation provided limited time for the controller to react and broadcast a safety alert or suggested avoiding action.
However, given typical reaction times, the ATSB determined that 30 seconds was sufficient time to assess the final STCA, provide a safety broadcast and probably prevent the collision. Equally, given the same reaction time considerations, it is questionable whether a controller radio broadcast, 10 seconds prior to the collision could have been processed and reacted to by the pilots sufficiently to have manoeuvred the aircraft to prevent the accident.
Airspace
When operating in non-controlled airspace (such as the current Class G airspace around Mangalore), whether under the instrument or visual flight rules, pilots hold responsibility for separation from other aircraft. An ATSB review of historical occurrences identified that this was the first ever collision between aircraft operating under the instrument flight rules in Australia under a procedure that has been in place for some decades.
This record indicates that self-separation using broadcast traffic advice has been a largely reliable procedure.
The ATSB does however note that the effectiveness of the current pilot-separation method relies on individual pilots:
recognising a potentially unsafe situation
formulating an effective separation plan that often requires coordination with the occupants of the other involved aircraft.
This process is almost exclusively reliant on individual human actions without other mechanisms potentially acting as a safeguard and/or safety redundancy, and as such subject to human error, even when it involves experienced pilots. Furthermore, such errors often increase under high workload associated with, for example, instrument flying procedures, low experience or a busy airspace environment. Of note, the airspace surrounding Mangalore Airport is commonly utilised for training and by pilots gaining experience, especially in instrument flying.
In that context, while the available evidence in this investigation does not support a conclusion that the present self‑separation system is unsafe, there is an opportunity to potentially reduce safety risk further.
The ATSB therefore supports systemic enhancements to the overall air traffic system that have been assessed by regulatory and air traffic specialists, in keeping with their obligations as providing a net overall safety increase. Key examples of such enhancements include:
the increased use of controlled airspace and ADS‑B aircraft surveillance data (both by air traffic services and in‑cockpit)
improved monitoring of air traffic movements (both quantity and complexity) to assist the identification of increasing risk areas.
With respect to the accident involving VH‑JQF and VH‑AEM, had the aircraft been operating in controlled airspace (an example being Class E airspace) they would have been positively separated and therefore the collision would have been unlikely to have occurred.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the mid-air collision and subsequent collision with terrain involving Piper PA44-180 Seminole, VH-JQF and Beech D95A Travel Air, VH-AEM, near Mangalore Airport, Victoria, on 19 February 2020.
Contributing factors
Following receipt of verbal traffic information, the pilots did not successfully manoeuvre or establish direct communications on the common traffic advisory frequency to maintain separation, probably due to the collision risk not being recognised.
While it is probable that the aircraft were in instrument meteorological conditions and could not visually separate to avoid the collision; the known limitations of the see-and-avoid principle meant that the pilots were unlikely to have seen each other in sufficient time to prevent the collision even in visual conditions.
Following receipt of a short-term conflict alert, the controller assessed it in accordance with the required procedure. After considering that the pilots had been passed mutual traffic information and were required to ensure their own separation in non‑controlled airspace, the controller did not intervene further.
While the pilots were responsible for self-separation within the Mangalore common traffic advisory frequency area, they did not have access to the same surveillance data, including automatic dependant surveillance broadcast information available to air traffic control. As a result, the pilots were required to make timely decisions to avoid a collision without the best available information.
Other factors that increased risk
The En-Route Supplement Australia included a requirement to add 1,000 ft to the prescribed practice instrument approach ‘altitude’ at Mangalore Airport. The procedure did not detail whether this height was to be applied to the minimum descent altitude or to all approach altitudes, resulting in varied application and an increased risk of traffic conflicts. (Safety issue)
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: The En-Route Supplement Australia included a requirement to add 1,000 ft to the prescribed practice instrument approach ‘altitude’ at Mangalore Airport. The procedure did not detail whether this height was to be applied to the minimum descent altitude or to all approach altitudes, resulting in varied application and an increased risk of traffic conflicts. (Safety issue)
Safety recommendation description: The Australian Transport Safety Bureau recommends that the Civil Aviation Safety Authority addresses the ambiguity in the En‑Route Supplement Australia requirement relating to practice instrument approach altitudes at Mangalore Airport to reduce the variation in application and risk of traffic conflicts.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Safety action by the Civil Aviation Safety Authority
The Civil Aviation Safety Authority is conducting a study of the airspace within a 25 NM area of Mangalore Airport from the ground to 8,500 ft AMSL. The study will evaluate the suitability of the airspace, including efficient use, equitable access for all users, appropriateness of the airspace classification and the existing services and facilities provided by the air navigation service provider. At the time of publication this study has not been published.
Safety action by Airservices Australia
Airservices Australia has submitted a proposal to the Civil Aviation Safety Authority for the implementation of a surveillance flight information service (SFIS) at Mangalore Airport, however the review process for the SFIS is pending the completion of the Office of Airspace Regulation study of the airspace surrounding Mangalore Airport. In the interim period a Melbourne Centre controller is monitoring the CTAF frequency during prescribed hours to provide a safety alerting service if required.
Airservices Australia has also raised a consultation to lower the base of Class E airspace around Mangalore Airport. At the time of writing that proposal was in review by Airservices following an industry consultation period.
Glossary
ACAS Airborne collision avoidance system
ADS-B Automatic Dependent Surveillance Broadcast
AIP Aeronautical Information Publication
AMSL Above mean sea level
AFRU Aerodrome frequency response unit
ASD Air Situation Display
ATC Air traffic control
ATS Air traffic services
ATSB Australian Transport Safety Bureau
AWIS Automated weather information system
AWS Automatic weather service
BoM Bureau of Meteorology
CASA Civil Aviation Safety Authority
CASR Civil Aviation Safety Regulations
CDTI Cockpit display of traffic information
CTAF Common traffic advisory frequency
DOK Dookie (sector of airspace)
EFB Electronic flight bag
ERSA En-Route Supplement Australia
FIS Flight information service
GAF Graphical Area Forecast
GNSS Global navigation satellite system
HUM Hume (sector of airspace)
ICAO International Civil Aviation Organization
IFR Instrument flight rules
ILS Instrument landing system
MATS Manual of Air Traffic Services
MOS Manual of Standards
NDB Non-directional beacon
NAPM National ATS procedures manual
NM Nautical mile
OVN Ovens (sector of airspace)
QNH That pressure setting, which, when placed on the pressure setting sub‑scale of a sensitive altimeter of an aircraft located at the reference point of an aerodrome, will cause the altimeter to indicate the vertical displacement of the reference point above mean sea level
SAR Search and rescue
SFIS Surveillance flight information service
SME Subject matter expert
STCA Short term conflict alert
TAF Terminal area forecast
TCAS Traffic collision avoidance system
VOR VHF Omni-directional range
Sources and submissions
Sources of information
The sources of information during the investigation included the:
Helios (2014a) Review of existing Class G airspace risk studies: what do we know? Helios Document reference P1838D002, produced for United Kingdom Civil Aviation Authority.
Helios (2014b) Class G airprox reports analysis: results and conclusions. Helios document reference P1838 D003, produced for United Kingdom Civil Aviation Authority.
International Civil Aviation Organization (2018)) Annex 11: Air Traffic Services. Fifteenth edition. International Civil Aviation Organization, Canada.
Morris, C (2005) Midair collisions: Limitations of the see-and-avoid concept in civil aviation. Aviation, Space, and Environmental Medicine. Vol 76, No. 4 April 2005.
National Transport Safety Board (1988) AIRCRAFT ACCIDENT REPORT - Midair Collision of Skywest airlines Swearingen Metro II, N163SW, and Mooney M20, N6485U, Kearns, Utah, January 15, 1987
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the operators of VH-AEM and VH‑JQF
the owner of VH-AEM
the air traffic controller
Airservices Australia
air traffic control subject matter expert
Bureau of Meteorology
Civil Aviation Safety Authority
AvPlan
United States National Transportation Safety Board
Office of the Aircraft Accident and Incident Investigation Commission, Thailand
Submissions were received from:
the operators of VH-AEM and VH-JQF
the air traffic controller
Airservices Australia
Bureau of Meteorology
Civil Aviation Safety Authority
Office of the Aircraft Accident and Incident Investigation Commission, Thailand
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
Appendices
Appendix A - Sequence of events
The sequence of events shows the key events identified in the report, including a transcript of the radio calls recorded between the Melbourne Centre controller and the pilots of AEM and JQF (in italics). The transcript does not include all calls made between the Melbourne Centre controller and other pilots or controllers.
Time start
(* indicates approximate time)
Time end
(* indicates approximate time)
Aircraft
Comment
1055*
Departure of AEM from Tyabb
1111:21
1111:32
JQF
Melbourne Centre, JQF is two POB IFR Mangalore taxying for runway two three for Mangalore
Melbourne Centre
JQF, Melbourne Centre, G’day. Squawk three six two four, there’s no reported IFR traffic.
JQF
Three six two four, JQF
Coordination to Melbourne Centre controller of AEM. Aircraft had previously reported estimating Mangalore at 1126.
1117:42
1117:55
AEM
Melbourne Centre, AEM, maintaining six thousand.
Melbourne Centre
AEM, G’day Melbourne Centre. Area QNH one zero one zero, and there’s no reported IFR traffic for your descent for your airwork at Mangalore.
AEM
One zero one zero, not traffic for airwork at Mangalore, thank you, AEM.
1118:22
AEM entered ML Centre airspace (30 DME boundary)
1119:35
1119:54
AEM
AEM, leaving six thousand for airwork four thousand down to ground, will call again time five zero or on departure.
Melbourne Centre
AEM thanks, I’ll talk to you again by time five zero and no reported IFR traffic for not above four thousand.
AEM
AEM
1120:07
11:20:08
Melbourne Centre
AEM, actually I will pass you some traffic when you’re ready.
1120:15
1120:28
Melbourne Centre
AEM, Centre?
AEM
AEM go ahead
Melbourne Centre
AEM shortly to depart Mangalore southbound, or via LACEY is JQF, a Seminole, they’ll be on climb to seven thousand
AEM
JQF copied, AEM.
1120:31
JQF first appeared on controller’s display
1122:19
1123:00
JQF
Melbourne Centre, JQF departure
Melbourne Centre
JQF’s identified, verify level with departure
JQF
JQF departure at Mangalore two three passing two thousand seven hundred on climb to seven thousand tracking to LACEY, Mangalore
Melbourne Centre
JQF area QNH one zero one zero
JQF
One zero one zero, JQF
Melbourne Centre
And JQF, traffic six miles in your twelve o’clock is AEM, a kingair, they’re inbound to Mangalore for airwork, passing five thousand, on descent to not above four thousand
JQF
Copy traffic JQF
1122:42
First STCA - between JQF and other traffic (during calls listed above)
1122:49
Second STCA – between JQF and AEM. Occurred as Melbourne Centre controller was providing traffic to the pilots of JQF (above)
1123:51
11:24:09
Third STCA appeared on controller display. Was assessed and acknowledged.
1124:16
Last updated data point displayed to controller prior to collision.
1124:20
Approximate time of collision
Preliminary report
Report release date: 23/04/2020
This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.
The occurrence
On 19 February 2020, at about 1055 Eastern Daylight-saving Time[1], a Beech Travel Air D95A aircraft, registered VH-AEM (AEM), departed Tyabb Airport, Victoria for an Instrument Flight Rules (IFR)[2] training flight to Shepparton via Mangalore, and return to Tyabb. On board were an instructor and student.
At 1111, the pilot of a Piper PA44-180 Seminole, registered VH-JQF (JQF) contacted air traffic control (ATC) to advise that the aircraft was taxiing for departure from Mangalore Airport. The pilot had submitted a flight plan for a round-trip IFR flight for Mangalore via Essendon and Shepparton. Also on board was an authorised testing officer, who was testing the pilot for an instrument flight rating.
AEM tracked as per the flight plan and, at 1117, began a descent from 6,000 ft above mean sea level (AMSL) for airwork at Mangalore. Radio communication with ATC indicated the airwork was to occur between 4,000 ft and ground level.
At 1119, the air traffic controller passed traffic information to AEM about JQF departing from Mangalore. At 1122, JQF made a departure call from Mangalore, advising ATC of a planned climb to 7,000 ft. ATC passed traffic information about AEM to the Seminole crew.
At 1124, Automatic Dependent Surveillance Broadcast (ADS-B)[3] data indicated the two aircraft collided approximately 8 km south of Mangalore Airport at approximately 4,100 ft (Figure 1). There were no witnesses to the collision, however another pilot in the area witnessed both aircraft descending immediately after the collision. All four pilots were fatally injured in the accident, and both aircraft were destroyed.
Figure 1: Flight path of AEM and JQF, and location of ground impact of both aircraft
Source: Google, modified by the ATSB
Context
Pilot information
All four pilots involved in the accident held the licences and medical approvals required to undertake the operations they were conducting.
The instructor on board AEM held an air transport pilot licence (aeroplane) and was a grade 1 flight instructor, with approvals to conduct instrument rating instruction and multi-engine aircraft class rating instruction. The instructor’s logbook indicated he had about 5,800 hours total flying experience. The student on this aircraft held a commercial pilot licence (aeroplane), and had passed the instrument rating theory exam. The student’s logbook indicated he had approximately 1,100 flight hours. This lesson was his second instrument training flight.
The examiner on board JQF held an air transport pilot licence (aeroplane), was a grade 1 flight instructor, and held a flight examiner rating to conduct a range of examinations, including for instrument ratings and multi-engine class ratings. He had about 21,000 hours flying experience. The pilot on this aircraft held a commercial licence (aeroplane), and had passed the instrument rating theory exam. This pilot’s logbook indicated she had approximately 220 hours of total flight experience. The test being conducted was for the purpose of issuing the pilot with both an instrument rating, and a multi-engine class rating.
Aircraft information
VH-AEM (Figure 2) was a Beech D95A Travel Air, twin-engine aircraft. It was manufactured in the United States of America in 1966 with serial number TD-682. It was first registered in Australia in 1967.
Figure 2: Beech Travel Air, registered VH-AEM
Source: Aircraft operator
VH-JQF (Figure 3) was a Piper PA44-180 Seminole, twin-engine aircraft. It was manufactured in the United States of America in 1979 with serial number 44-7995291. It was first registered in Australia in 1990.
Figure 3: Piper Seminole, registered VH-JQF
Source: Aircraft operator
Wreckage and impact information
Following the mid-air collision, JQF travelled for about 0.5 km before impacting an open field, while AEM continued in a northerly direction and impacted a lightly wooded area about 1.4 km from the collision point. Airborne debris liberated in the collision formed a further wreckage field that was located about 1.6 km to the north-north-east of the collision point and about 200m to the west of the Hume Highway.
Meteorological information
The forecast meteorological conditions for the Mangalore area indicated scattered[4] cloud at 2,000 ft above ground level (approximately 2,500 ft above mean sea level), with scattered stratocumulus cloud between 3,000 and 6,000 ft. Visibility was forecast to be greater than 10 km, and the wind from the south‑west at 25 knots.
At the time of the accident, the automatic weather station at Mangalore Airport, 8 km north of the collision location, recorded two cloud layers: one scattered at 3,467 ft AMSL and a second broken layer at 4,174 ft AMSL, (about the collision altitude).
Video taken by the Victoria Police Air wing (Figure 4) near the accident site at 1240, 1 hour and 16 minutes after the accident showed the base of a broken layer of cloud to be at approximately 4,050 ft AMSL with some lower patches of cloud also present.
Figure 4: View of cloud from the Victoria Police Air Wing helicopter
Source: Victoria Police
Aerodrome and airspace information
Mangalore Airport has an elevation of 467 ft. The airport was non‑controlled, and utilised a ‘Common Traffic Advisory Frequency’ (CTAF)[5]. The CTAF frequency was shared with three other aerodromes in the local area.
Surrounding the Mangalore CTAF was class G non‑controlled airspace. In class G airspace, air traffic controllers provide traffic information to IFR aircraft about other conflicting IFR and observed VFR flights.
Recorded data
Neither aircraft was equipped with a flight data recorder or cockpit voice recorder, nor were they required to be. One aircraft was carrying an iPad, which had AvPlan[6] software installed and operating at the time of the accident. This data was provided to the ATSB.
Both aircraft were fitted with transponders that broadcast ADS-B data. This information included the position and altitude of the aircraft and was received by Airservices Australia, as well as other third-party ADS-B receivers (FlightRadar24) and provided to the ATSB.
Radio transmissions on the CTAF were not recorded.
Further investigation
The investigation is continuing and will include further examination and analysis of:
weather conditions at the time of the accident
recovered radios from the aircraft
recorded radar data, as well as recorded area frequency calls and recollections of CTAF radio broadcasts.
pilot qualifications, experience and medical histories
aircraft maintenance and operational records
air traffic services actions, procedures and practices
traffic density in and around Mangalore Airport
classification of the airspace around Mangalore Airport
Class G and CTAF operational and communication processes and procedures around Mangalore Airport
visibility from both aircraft.
Should a critical safety issue be identified during the course of the investigation, the ATSB will immediately notify relevant parties so appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Acknowledgements
The ATSB acknowledges the assistance of Victoria Police, and the Victorian Coronial Support Unit in supporting the ATSB’s on-site investigation team and providing information and support through the evidence collection phase of the investigation.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 3 February 2020, a fire in a signalling equipment hut at Wallan in Victoria resulted in damage to the signalling system on the standard gauge rail network operated by the Australian Rail Track Corporation (ARTC). Repair of the signalling system would take several weeks and ARTC commenced managing rail traffic over a 24 km section between Kilmore East and Donnybrook using administrative systems. The section was predominantly a single bi-directional track which included a crossing loop at Wallan.
Trains were initially being managed through this 24 km section under the existing train working protocols that limited train speeds to no more than 25 km/h. This speed limit led to significant delays and ARTC developed train working arrangements that would permit trains to operate at normal track speeds. For passenger trains, this was up to 130 km/h. The arrangements that were established used (paper-based) train authorities to give drivers permission to travel through the section without signals operational, and also required an accompanying qualified worker (AQW) to ride in the cab with the driver. The first train authority under these new arrangements was issued on the evening of 6 February.
After the initial loss of signalling, the crossing loop at Wallan was not used and the points at either end of the loop were then locked in their normal (straight) position. Then, on 20 February, trains were to be routed through the loop to clean contamination from the rail head in preparation for signalling system testing. Around mid-afternoon, the points at each end of Wallan Loop were changed to their reverse position to route trains through the turnout to the loop track.
That evening, NSW Trains (TrainLink) was operating XPT train ST23 from Sydney to Melbourne. Train ST23 entered the affected section at Kilmore East and after travelling about 15 km derailed in the turnout at the northern end of Wallan Loop. The derailment occurred at about 1943. As a result of the derailment, the leading power car of train ST23 overturned and slid on its side for some distance. The driver and the AQW in the driver’s cab of the power car did not survive the accident. Eight passengers were seriously injured,[1] and a reported 53 passengers and the 5 passenger services crew members sustained minor injuries.
What the ATSB found
The investigation found that train ST23 derailed due to its speed exceeding the infrastructure design speed by a significant margin. The train entered the turnout to Wallan Loop travelling at a speed of between 114 and 127 km/h following an emergency brake application a short distance before the turnout. The maximum permitted operational speed for the turnout was 15 km/h and the train could not negotiate the turnout at its higher speed.
There was no evidence identified to suggest that the driver was incapacitated leading up to the derailment, and no evidence to suggest a rolling stock or a track defect had contributed to the derailment.
Several scenarios that may have led to ST23 not slowing for the loop turnout were considered. The leading power car was not fitted with in-cab voice or video recording devices and the absence of information on the interactions within the driver’s cab reduced the certainty of this finding. On the balance of evidence, it was concluded that the driver of ST23 probably expected to remain on the straight track through Wallan and was operating the train with that expectation.
The driver had likely developed a strong expectation that ST23 would be travelling on the straight track through Wallan. The driver of ST23 had operated the XPT service through the location 8 times in the 12 days prior, and on all occasions the loop track at Wallan was locked out of service consistent with the arrangements not to use the crossing loop at Wallan while signalling was non-operational.
Information on the routing of ST23 through Wallan Loop on the evening of 20 February was provided to the driver in a modified train authority document given to them at Kilmore East. However, the train working arrangements that were established by ARTC on 6 February did not include protocols that would confirm the driver’s understanding of the authority and excluded the requirement for the driver to read back the train authority to the network control officer. Expectations based on past experience influence the perception of information and it is probable that the driver did not recognise the text changes made to the train authority from those issued to them on their 8 previous trips.
The train working arrangements that were established to manage traffic while the signalling system was not functioning deviated from ARTC network rules and there was ineffective management of the risks introduced by this deviation. There were several safety factors that increased safety risk including weaknesses in ARTC risk management, the train working arrangements, risk controls (including a reliance on manual processes), and stakeholder engagement. For the routing of trains through Wallan Loop on 20 February, it was concluded that there were several available and practical risk controls that were not used by ARTC.
Weaknesses were also identified in the distribution and collection of safety information. It was found that NSW Trains did not have a functioning process for obtaining safety critical information for its Victorian operations from the ARTC web portal (WebRAMS).
It was also found that the configuration of the driver’s cab contributed to the adverse outcome for the driver and AQW. The side door of the power car detached when the car overturned. This resulted in track ballast and earth entering the cab and trapping the driver and the AQW. Efforts by members of the train crew and emergency services to assist those trapped was thwarted by a lack of ground-level access to the cab. It was found that contemporary industry standards did not address the loading of the side-doors of driver cabs during overturn, and ground-level access to train crew trapped in an overturned vehicle.
Soon after the derailment, some passengers self-evacuated the train. It was found that the methods of providing safety information to passengers through briefings, onboard guides and signage did not provide reasonable opportunity for all passengers to have knowledge of what to do in an emergency. Systemic weaknesses in the training of passenger services crew by NSW Trains was also identified.
Other findings are made with respect to potential barriers to safety improvements on the ARTC rail network. These address shared risks between the rail infrastructure manager (RIM) and rolling stock operators (RSO) and the slow, and uncoordinated, adoption of technologies. There continues to be a high reliance on administrative controls and a slow take up of technological solutions by ARTC to improve safety.
What has been done as a result
ATSB identified 15 safety issues against which organisations were requested to advise on their proactive safety actions. The details of these actions, and ATSB comment on these actions, are described in the Safety issues and actions section of this report.
Six safety issues were allocated to ARTC. ARTC advised that it has introduced an updated management process for deviations from ARTC Network Rules (for planned or unplanned works). ARTC advised that this process required a risk assessment involving stakeholders, the development of appropriate controls for implementation by each stakeholder, and ARTC Executive approval of the risk assessment and plan. Three safety issues pertaining to network user engagement and distribution of safety information remained open, and updates will be provided on the ATSB website.
Six safety issues were allocated to NSW Trains. NSW Trains advised that it has developed new procedures for the daily access of the ARTC WebRAMS system for safety information and has also amended procedures to include confirmation of receipt of safety critical information by train crew prior to them starting their day of operations. NSW Trains also advised of changes to crew emergency response training, although 2 related safety issues remain open. The ATSB has made one recommendation to NSW Trains that it undertake further work to improve the methods used to provide safety information to passengers.
One safety issue was allocated to ActivateRail, a contractor to ARTC. Relevant to this safety issue, ActivateRail advised that it has introduced additional control processes pertaining to its participation in projects. ActivateRail also committed to ongoing and future risk management awareness training of its consulting and professional services staff.
The Rail Industry Safety and Standards Board (RISSB) has committed to consider the outcomes of this investigation in a review of the Australian Standards for body structural requirements (locomotive) and access and egress. The outcomes of the RISSB review of these standards will be reported on the ATSB website.
Safety message
Central to this occurrence was the breakdown of risk management processes following deviation from established network rules. Critical to successful risk management in degraded network conditions is the involvement of network users in the identification and assessment of emergent risks, and user participation in the development of appropriate risk controls.
This occurrence also highlighted an over reliance on administrative controls and the missed opportunities to use existing and emerging technologies to manage risk associated with human error. To improve safety outcomes, the rail sector must move faster and together in embracing technology to improve its management of safety risks.
The occurrence
Overview
On 20 February 2020, NSW Trains (TrainLink) was operating the express passenger train (XPT) designated ST23 from Sydney, New South Wales (NSW), to Melbourne, Victoria. Train ST23 was operating on the rail network managed by the Australian Rail Track Corporation (ARTC). For a 24 km section between Kilmore East and Donnybrook in Victoria, ARTC was managing rail traffic using temporary train working arrangements while it undertook repairs to the signalling system that had been damaged in early February.
Train ST23 entered the affected section at Kilmore East at about 1935 local time. At about 1943, and after travelling about 15 km into the affected section, ST23 derailed at the northern end of Wallan Loop. As a result of the derailment, the leading power car of ST23 overturned. The driver and an accompanying rail worker in the driver’s cab of the power car did not survive the accident. Several passengers were seriously injured, and a large number of passengers and the passenger services crew sustained minor injuries.
Prior to the occurrence
At about 2343 on 3 February 2020, ARTC identified that the centralised traffic control (CTC) signalling system had been disrupted around Wallan in Victoria. A subsequent investigation by ARTC determined that a road vehicle had struck overhead electrical wires in Wallan, resulting in a ‘power surge’ to the nearby signalling equipment hut. A subsequent fire in the hut resulted in extensive damage to equipment and cabling.
As a result of the damage to the signalling system at Wallan, ARTC commenced managing rail traffic through the affected section using caution orders and other safeworking rules. Under these arrangements, trains were required to proceed cautiously at a speed not exceeding 25 km/h, and as a result there were significant delays to rail services.
To reduce delays through this affected section, ARTC established train working arrangements that used train authorities[2] and permitted higher train speeds. The new arrangements commenced at 1900 on 6 February and the first train authority issued was at 2042 that day. This arrangement was used for the 24 km section between Donnybrook and Kilmore East (Figure 1).
Figure 1: Location of train working between Donnybrook and Kilmore East
The affected section was between signals within the passing lanes at Donnybrook and Kilmore East. Rail-km shown from Melbourne.
Source: Google Maps, annotated by CITS
Notification to network users of the change in train working was by a train notice[3] issued by ARTC. Train notice 266 (TN 266) describing the change was issued on 6 February, updated on 7 February, and further amended on 13 February. In the arrangements established, the turnouts at either end of Wallan Loop were set to their normal position for the No.1 track (the through route) and clipped in that position.[4]
For the train working arrangements established, ARTC did not impose any additional speed restrictions through the section. The maximum permitted speed for passenger trains travelling on the No.1 track through Wallan was 130 km/h.
On 19 February, TN 266 was supplemented with train notice 367 (TN 367) advising of a change at Wallan Loop. Trains were to be diverted through the loop (No.2 track) for a short period on 20 February. The purpose of routing trains through the loop was to remove any contamination that may have developed on the rail head of the No.2 track while it was not being used.[5] This was in preparation for signal system testing and re-establishment of the CTC signalling system.
Between 1453 and 1536 on 20 February, and with track protection in place,[6] the points at either end of Wallan Loop were manually reconfigured from their normal position to their reverse position.[7] This change meant that rail traffic travelling in either direction after this time would be diverted into the crossing loop (No.2 track). TN 367 reflected this change and also specified a speed limit of 15 km/h for entry into the loop, and a limit of 35 km/h when exiting the loop. On that same day between 1600 and 1837, track force protection was utilised about 1 km south (towards Donnybrook) of Wallan Loop for the laying of conduit.[8]
The first train to pass through Wallan Loop in this altered configuration was southbound V/Line train 8620. Immediately prior to 8620 departing Kilmore East, the network control officer (NCO) advised the driver that they were going to be the first train through Wallan Loop in the past 72 hours. This notification by the NCO was consistent with the NSW practice of advising drivers of the potential unreliability of track circuits if trains have not run on a track in the previous 72 hours, although in this instance the signalling system was not operating at Wallan Loop.[9] Train 8620 departed Kilmore East at about 1623 and its train authority was cancelled for its arrival at Donnybrook at 1647.
The second train through the loop was northbound V/Line train 8625. When stopped at Donnybrook, and during exchanges between the driver and the NCO, there was no mention by either party of transiting through Wallan Loop. The train departed Donnybrook at about 1857 and was in the affected section when ST23 arrived at Kilmore East.
Train ST23 journey from Sydney to Albury
Passenger train ST23, operated by NSW Trains, was to be the third train through Wallan Loop under the modified train working arrangements. The train was comprised of leading power car XP2018, 5 passenger cars of varying configuration, and a trailing power car. It was a single-driver operation.
ST23 departed Central Station in Sydney at 0741 on 20 February 2020, just after the scheduled departure time of 0740. The train service was to travel through NSW, into Victoria, and to arrive at its final destination at Southern Cross Station (Melbourne) at 1830 that evening (Figure 2).
Figure 2: Train route from Sydney to Melbourne
Source: Google Maps, annotated by CITS
The train proceeded south and arrived at Junee in southern NSW at 1452,[10] about 85 minutes behind schedule. There was a change of driver at Junee. The train departed Junee at 1456 and continued south, arriving in Albury on the NSW–Victorian border at 1637. There was a change in passenger services crew at Albury. The new passenger services crew comprised a passenger services supervisor (PSS), a crew member training for the supervisory role, and 3 passenger attendants.
Train ST23 journey from Albury
Train ST23 departed Albury at 1644, about 89 minutes behind schedule, and entered the Victorian section of its journey. After departing Albury, there was an announcement to passengers, tickets were checked, and the passenger services crew walked through the passenger cars checking door locks and equipment. Later, the driver was provided with a snack while the train was stopped at Wangaratta and the train departed that station at 1722, 87 minutes behind schedule.
Beyond Benalla, the focus of several of the passenger services crew was on meal activities in the buffet car. The crew described the journey as normal, although passengers were reported to be frustrated with the delays. ST23’s delay had originated prior to Junee.
At about 1840, the NCO at ARTC Network Control[11] contacted the driver of ST23 regarding a network alarm that had been received.[12] Later in the communication, the NCO advised the driver that ST23 would come into Kilmore East and wait until a V/Line train had passed.[13] As part of this communication, the controller mentioned that ‘you’re going via the loop there at Wallan’. The response from the driver did not reference the train’s route via Wallan Loop.
Train ST23 at Kilmore East
Train ST23 continued south before coming to a stand at about 1856 at intermediate home[14] signal KME28, which was displaying a stop indication. There was a standard-gauge passing lane at Kilmore East, with designated East and West Lines, and ST23 had been routed via the East Line (Figure 3).[15]
Figure 3: Kilmore East standard-gauge passing lane shown in black (not to scale)
The schematic shows the track at Kilmore East including the passing lane. Only the signalling for the standard-gauge track is shown. NSW Trains’ services did not use the broad-gauge track. Source: ARTC, modified and annotated by CITS
The driver of ST23 contacted the NCO at about 1904 and inquired when they might receive permission to proceed. ST23 was required to wait until the northbound V/Line train 8625 had cleared the single-line section.
At around this time, several rail workers were preparing for the arrival of ST23 at signal KME16 (at Kilmore East). These rail workers were to assist ST23 with the train working arrangements between Kilmore East and Donnybrook. Among these rail workers were an (in-field) signaller (referred to in this report as the signaller) and an accompanying qualified worker (AQW).[16] The AQW would accompany the driver from Kilmore East to Donnybrook and arrange the activation of level crossing protection at Wallan–Whittlesea Road just south of Wallan Loop.
ST23 was the first train that the signaller and AQW were to assist after commencing their shifts. The signaller had first arrived at Donnybrook at about 1830, and then travelled to Kilmore East to start their shift. The AQW had also first attended Donnybrook before travelling to Kilmore East. At the start of their shift, the AQW was provided with a copy of TN 367 and then briefed on the transit through the loop and the requirement to advise the driver.[17]
At about 1915, while ST23 was stopped at signal KME28, the signaller positioned near signal KME16 contacted the NCO to advise that they had come on shift and taken over from the previous signaller. During this call, train authority 17 (TA 17) for ST23 to proceed between Kilmore East and Donnybrook was issued to the signaller by the NCO. The NCO read TA 17 to the signaller, describing that the authority was issued in accordance with train notices 266 and 367, that the points at Wallan Loop were set and secured for No.2 track, and that there was a maximum speed entering the loop of 15 km/h and a maximum speed exiting the loop of 35 km/h. From this NCO dictation, the signaller completed their copy of the train authority form and then read the completed TA 17 back to the NCO. The NCO noted the time of the readback as 1920.
A condition affecting the network (CAN)[18] notice was then completed by the signaller under the instruction of the NCO. This notice was to warn train crew of the condition of the Wallan–Whittlesea Road level crossing protection, and that the protection was being manually operated. The CAN was designated number 7, and the readback of CAN 7 to the NCO by the signaller was noted by the NCO as being completed at 1921.
ST23 was held at signal KME28 on the East Line until the northbound V/line passenger train 8625 had transited the Donnybrook to Kilmore East single-line section, passed signal KME2, and was travelling along the West Line through Kilmore East. The V/Line train was clear of the single-line section by about 1925 and, soon after, the driver of ST23 was given permission by the NCO to proceed to home departure signal KME16,[19] still on the East Line within the Kilmore East location.
ST23 arrived at signal KME16 at about 1931. The train was met by several rail workers, including the signaller and the AQW. Shortly prior to the train’s arrival, the signaller gave documents TA 17 and CAN 7 to the AQW and briefed the AQW on their content. The AQW boarded the leading power car and joined the driver at the head of the train, and gave TA 17 and CAN 7 to the driver. It was intended that the AQW would accompany the driver for the 24 km section to Donnybrook. The XPT cab was not fitted with a cab voice recording facility (and was not required to be), and there was no record of the conversation between the AQW and driver.[20]
At about 1932, while the train was stopped at signal KME16, the driver and the on-duty NCO communicated via the train radio. This exchange included the NCO asking whether the driver had received all the paperwork, and the driver responding ‘yeah, authority 17 and CAN number 7 filled out ahh the same way it has been for the … rest of the time’.
During this communication between the NCO and driver, the NCO did not read the content of TA 17 to the driver, and the driver did not read back the content of TA 17 to the NCO.[21] The NCO commented ‘points all set for the loop’. The driver’s response to the controller did not reference transiting via the crossing loop (No.2 track) at Wallan. There was no communication between the controller and driver regarding the maximum speed of 15 km/h for entering Wallan Loop.
Derailment of train ST23
The train departed signal KME16 at about 1934 and entered the single-line section towards Wallan and Donnybrook. The line speed for the XPT between Kilmore East and Donnybrook was 130 km/h.[22] After departing from signal KME16, the speed of the train was increased and initially maintained between 100 km/h and 120 km/h.[23]
The AQW was to ensure that the active level crossing protection at Wallan–Whittlesea Road in Wallan was in place for the passage of the train.[24] A level crossing keeper (LCK)[25] was located at the crossing to activate the crossing protection. The AQW contacted the LCK by phone at approximately 1941, when the train was at about the 52 km mark. The LCK reported activating the crossing protection at Wallan–Whittlesea Road and confirmed its activation to the AQW. This phone call lasted about 53 seconds and the LCK did not recall anything unusual about the communications with the AQW. The call was completed when the train was about 4.5 km from the level crossing and 2.7 km from the entry to Wallan Loop.
The speed of ST23 then increased towards the line speed of 130 km/h as the train approached Wallan. At about 1943, ST23 was approaching the northern end of Wallan Loop when an emergency brake application was made. Brake cylinder pressure was recorded as commencing to rise when ST23 was between 153 and 50 m from the turnout.[26] This slowed the train a small amount before it entered the turnout travelling at a speed estimated to be between 114 and 127 km/h. The train was not able to negotiate the turnout to the No.2 track (loop) at this speed and derailed (Figure 4). The leading power car rolled onto its left side. The trailing 5 passenger cars remained upright although tilted by varying amounts, and the rear power car remained upright on the track.
Figure 4: Aerial photograph of derailment site
Source: ATSB
Emergency response
At the time of the derailment, there were 155 passengers,[27] the driver, 5 passenger services crew members and the AQW on board the train. The driver and AQW were in the driver’s cab, a passenger services crew member was in the second passenger car and the other 4 passenger services crew members were in the buffet car (the third passenger car).
After the train came to a stop, the passenger services supervisor (PSS) called the train crew on a hand-held radio and received responses from the other members of the passenger services crew. However, the driver did not respond and the AQW was not in possession of a NSW Trains issued radio.
Two members of the passenger services crew then commenced raising the emergency using their hand-held radios.[28] The crew members made several emergency calls seeking assistance, advising that the XPT had derailed and requesting that all trains stop.
A V/Line signaller based at Wallan heard the emergency calls and responded within about 25 seconds of the first recorded ‘emergency emergency emergency’ radio broadcast by the passenger services crew. On confirming the nature of the emergency, the Wallan signaller contacted V/Line network control at Centrol.[29] Centrol then contacted ARTC Network Control at Junee at about 1945, relaying the information that the XPT may have derailed. During this communication, Centrol also advised ARTC Network Control that V/Line would stop trains on the broad-gauge tracks that ran parallel to the standard gauge. In response to the Centrol call, ARTC sought confirmation of what had happened and initiated its response.
Emergency services recorded the first ‘000’ call for assistance from a train passenger, time-stamped 1945:06.[30] This was followed by a series of calls from other passengers, members of the passenger services crew, and members of V/Line and ARTC.
Around this time or soon after, some passengers started to self-evacuate from the train prior to the passenger services crew receiving confirmation that rail traffic in the area had been stopped. Although passengers were told to vacate adjacent tracks and leave their belongings behind, video footage and photographs showed that there were mixed levels of compliance with these instructions.
In response to the emergency, passenger services crew undertook a range of tasks including managing passengers that had evacuated onto the track and attending to passengers on the train. At different times, three passenger services crew members also went to the leading power car to check on the driver and AQW. Two crew members separately entered the power car through its right-side cab door, accessible from the ‘top’ of the car laying on its left side. Finding it difficult from within the cab to assist the driver and AQW, who had both been trapped by track ballast and earth that had entered the cab, the crew attempted to break the cab’s windscreen to gain access from outside.[31] However, attempts by the passenger services crew to gain this ground-level access from outside the cab were unsuccessful.
The first emergency service to arrive on site was Victoria Police at about 2003, followed by further emergency, medical and fire services. However, both the driver and the AQW did not survive.
As a result of the movement of the passenger cars during the derailment sequence, 8 passengers were seriously injured and a reported 53 received minor injuries.[32] The 5 passenger services crew members also received minor injuries.
Context
Train operator
Train ST23 was operated by NSW Trains trading as NSW TrainLink.[33] NSW Trains was established in 2013 as part of a restructure of rail arrangements in New South Wales (NSW). NSW Trains operated regional rail and coach services in NSW and interstate rail passenger services between Sydney (NSW) and the east coast capital cities of Melbourne (Victoria) and Brisbane (Queensland).
In accordance with the Rail Safety National Law (RSNL), NSW Trains was an accredited rolling stock operator (RSO), that was defined (in part) as having ‘… effective control and management of the operation or movement of rolling stock on rail infrastructure for a railway…’.[34] As an RSO, NSW Trains was also defined in the RSNL as a rail transport operator and had defined safety duties.[35]
Train information
The XPT (Express Passenger Train) ST23 operating on 20 February 2020 was comprised of 7 vehicles (Figure 5). The leading 3 vehicles were manufactured by ABB Transportation in Dandenong, Victoria, and were commissioned in 1993. The trailing 4 vehicles were manufactured by Comeng in Granville, NSW, and were commissioned between 1981 and 1984. The fleet of XPT vehicles was maintained by Sydney Trains.[36]
Figure 5: Train configuration
Source: Vehicle images supplied by Sydney Trains, annotated by CITS
The XPT was first introduced into service in 1982 and was based on the InterCity 125/Class 43 design used in the United Kingdom. The power car included a forward driver’s cab that was located ahead of a compartment housing propulsive machinery. Cab features included side doors for primary access (fitted on the left and right sides of the driver’s cab), a rear door to the machinery space, the driver’s seat that was positioned slightly left of the car centreline, and a second seat that was located to its right (Figure 6).
Figure 6: Power car layout and cab seat arrangement
Source: RailCorp (NSW Transport), annotated by CITS
A post-derailment review of the condition of the ST23 rolling stock did not identify any adverse rolling stock condition or defect that was likely to have contributed to the derailment. The review involved inspections, testing and an examination of maintenance records (Appendix A).
Inspections were conducted at several locations and included observations at the derailment site, inspection of vehicles XP2000 and XFH2108 at the Sydenham Maintenance Centre, and inspection of vehicles XP2018, XAM2179, XL2229, XBR2155 and XF2201 at the Auburn UGL facility. Post-occurrence testing conducted by Sydney Trains and witnessed by the Office of Transport Safety Investigations (OTSI) included testing of braking, vigilance and communication systems.
Personnel information
Driver
The driver of train ST23 had been associated with the rail industry for about 40 years, employed in a range of roles including driving, training, and management. They returned to driving in mid-2016 as a regional driver with NSW Trains and were assessed as competent on the route between Junee and Melbourne in July 2019. The driver was qualified to operate the XPT train and had completed continuation training (safeworking).
Typically when driving the XPT services between Junee and Melbourne, they would drive the Junee to Melbourne leg of the Sydney to Melbourne service and, following a period of rest in Melbourne, drive the return journey to Junee. After the commencement of train authority working through Wallan on 6 February 2020, they drove the Junee–Melbourne–Junee round trip (including a rostered rest period in Melbourne) 4 times between 8 and 19 February, including several trips after all signals within the section had been extinguished.
On 20 February, the driver’s shift commenced in Junee at 1315 and their scheduled sign-off in Melbourne was at 1845.[37] As a result of the delayed arrival of ST23 into Junee (85 minutes), the commencement of driving duties were delayed (to 1456) and would have led to a late arrival in Melbourne. A review of the driver’s roster and recent history found there was insufficient evidence to conclude that the driver was experiencing a level of fatigue that would adversely affect their performance (Appendix B).
The driver was medically assessed as fit for duty (unconditional) in accordance with the requirements for a Category 1 Safety Critical Worker[38] and no pre-existing health issues were identified that were likely to have contributed to the occurrence. Further, toxicology results did not identify any substance that may have impaired performance.
There was no evidence of any phone calls to or from the driver or messages sent from the driver’s phone in the period immediately prior to the occurrence.
Passenger services crew
There were 5 passenger services crew members on board ST23, one more than the normal complement. Their years of service ranged between 1 and 13 years. The passenger services crew consisted of:
a passenger services supervisor (PSS) responsible for overall supervision of the passenger operations and the management of passengers in an emergency[39]
a senior passenger attendant (SPA) responsible for the buffet operations and ticket sales
a passenger attendant 4 (PA4) responsible for assisting the SPA in the buffet, and assisting with general passenger duties along the train
a passenger attendant 2 (PA2) responsible for general passenger duties along the train
an additional crew member who was shadowing the PSS as part of on-the-job training.
The accompanying qualified worker
The accompanying qualified worker (AQW) on board ST23 was employed by Programmed, a labour-hire organisation that provided skilled workers across a range of industries including transport. Programmed supplied several personnel to ARTC from 4 February 2020 to assist with the management of rail traffic between Donnybrook and Kilmore East.
The AQW was certified to Track Protection Coordination level 3.2, most recently renewed in March 2019. They had completed several safeworking related training modules including (in 2017) the units TLIC2081 (Pilot rail traffic within work on track authority limits)[40] and TLIL3083 (Implement a track work authority and manage rail traffic through worksites).
The AQW had been with Programmed since 2006. Records[41] indicated that the worker had been engaged by several rail operators in Victoria in various roles, and in recent years primarily as a track force protection coordinator or hand signaller. There were no records identified of previous experience in performing the role of an AQW, or in train pilotage.
The AQW had been engaged at Wallan from 4 February, primarily in the role of level crossing keeper (LCK) at the Wallan–Whittlesea Road level crossing. All shifts from February were night shifts that mostly commenced at about 1900. On 20 February, the AQW had just commenced the night shift. A review of the AQW's roster and recent history found there was insufficient evidence to conclude that the AQW was experiencing a level of fatigue that would adversely affect their performance. The AQW was rostered off duty from 16 to 18 February and conducted a night shift commencing 19 February from 1900 to 0500.
The evening of 20 February was the first time this rail worker performed the role of an AQW, and ST23 was to be their first train that evening. Reporting in at Donnybrook for the start of their shift, the AQW received a briefing from a more senior AQW on the tasks to be performed, and the conditions of transiting through the loop described in TN 367. They then travelled to Kilmore East for the start of the shift.
The AQW was medically assessed as fit for duty (unconditional) in accordance with requirements for a Category 1 Safety Critical Worker and no pre-existing health issues were identified that were likely to have contributed to the occurrence. Further, toxicology results did not identify any substance that may have impaired performance.
The network control officer
The network control officer (NCO) on duty at the time of the derailment had worked as a network controller since 2004 and was qualified on all the control boards at ARTC Junee network control. This was the first shift that this NCO had experienced the train authority process being used between Donnybrook and Kilmore East.
The NCO came on shift at about 1445. The NCO advised that they received instruction on how the train authority forms were to be used from the NCO that was previously on shift. A conversation also took place between an ActivateRail representative[42] and the NCO at 1530, during which the NCO was advised of the correct train authority forms that reflected train notice 367 (TN 367). At 1554 a further conversation took place between the NCO and the ActivateRail representative for the issuing of train authority 15 to train 8620, during which the NCO stated that they were ‘still trying to get my head round all of this’.
The NCO had been issued with the new train authority form for use under TN 367 and completed that form with the correct information in train authority 17 (TA 17) for the passage of train ST23. At interview, the NCO referred to the AQW as a ‘pilot’ and advised that they had not spoken to the ‘pilot’ that was issuing TA 17 for service ST23.
The signaller
The (in field) signaller involved in the receipt of TA 17 was employed by labour-hire firm Australian Recruiting Group (ARG Rail) and had been contracted by ActivateRail to perform the duties of a signaller on this project. They were certified to perform signalling duties and were rostered on night shifts from 1900 to 0700. Their first shift on this project was on 16 February and 20 February was their fifth consecutive night shift. At interview, the signaller also referred to the AQW as a pilot.
On the evening of 20 February 2020, the signaller, positioned at Kilmore East, was issued TA 17 and the condition affecting network (CAN) notice 7 from the NCO commencing at 1917. The signaller read back TA 17 to the NCO at 1920, and the train authority and CAN notice were then passed from the signaller to the AQW. The signaller remained at Kilmore East until the AQW had boarded train ST23. The signaller did not board the train or speak to the driver (consistent with the normal process implemented by other signallers involved in the train working arrangements). The signaller then left Kilmore East, by car, for Donnybrook with the intention of receiving the next train authority for a northbound freight train travelling between Donnybrook and Kilmore East.
Infrastructure
Network manager
ST23 was operating on the rail network managed by the Australia Rail Track Corporation (ARTC). This management included track and signalling infrastructure and rail traffic control. ARTC was created following a Commonwealth and mainland State Governments’ Intergovernmental Agreement in 1997 for the establishment of a ‘one-stop shop’ for rail operators seeking access to the standard gauge rail network between Brisbane and Perth.[43] Established in 1998, ARTC was a Government Business Enterprise fully owned by the Commonwealth of Australia.
In Victoria, the standard gauge infrastructure was leased by ARTC from VicTrack.[44] Under the agreement, ARTC was required to maintain, replace and repair the leased infrastructure to a level where its condition was no worse than it was at the commencement of the lease. There was also provision in the lease agreement that, in addition to maintenance, repair and renewal works, ARTC could undertake capital works at its own cost and risk.
In accordance with the RSNL, ARTC was an accredited rail infrastructure manager (RIM), that was defined (in part) as having ‘…effective control and management of the rail infrastructure…’.[45] As a RIM, ARTC was also defined as a rail transport operator in the RSNL and had defined safety duties.[46] ARTC was also accredited as a rolling stock operator.
Track
The XPT service was running on the standard-gauge interstate track that connected Sydney and Melbourne. The standard-gauge track between Donnybrook and Kilmore East was a single, bi‑directional line used by the XPT, V/Line passenger services and rail freight.
On this single-line section, there was a 1,550 m crossing loop located at Wallan (Figure 7). The northern entry to this loop was located about 1.8 km north of Wallan–Whittlesea Road. Towards the southern end of Wallan Loop was Wallan Railway Station, which serviced broad-gauge passenger trains operated by V/Line.[47]
Figure 7: Standard-gauge track and signals at Wallan Loop (not to scale)
The schematic shows the standard-gauge track at Wallan including the crossing loop. The standard-gauge tracks are shown in black, and the adjacent broad-gauge tracks in red. Only the signalling for the standard-gauge track is shown in this figure. Source: ARTC, modified and annotated by CITS
Wallan Loop northern turnout
The turnout at the northern end of the Wallan Loop was located at the 49.058 km mark (Figure 8). The turnout design was reported by ARTC as being rated for a train speed of 25 km/h (for entry into the loop) and the maximum operational speed was 15 km/h in accordance with the ARTC operating code of practice.[48] It consisted of 60 kg/m rail on timber bearers, with a cast V-crossing. Following the left turnout, the right curve (in the direction of travel) along the No.2 track had a radius of about 420 m.
Figure 8: Elevated view of northern turnout to No. 2 track at Wallan Loop
The photograph shows the turnout and signal WLN8 on 21 February 2020 after the passage of train ST23 and its derailment. The points are set for the No.2 track as they were at the time of the derailment.
Source: ATSB
For southbound trains approaching the northern end of Wallan Loop, there was a downhill gradient of approximately 1:150 and the track was tangent (straight) for about the final 800 m of the approach to the turnout with trees lining the rail corridor. The approach track was comprised of 60 kg/m rail, fastened to concrete sleepers.
Wallan–Whittlesea Road level crossing
The Wallan–Whittlesea Road level crossing was located just south of Wallan Loop (Figure 9).
Figure 9: Aerial view of Wallan–Whittlesea Road level crossing and surrounds
Source: Pass Assets, annotated by CITS
The Wallan–Whittlesea Road level crossing was fitted with active protection that included boom barriers, flashing lights and bells. While the signalling system at Wallan was being repaired, the crossing protection was manually activated by a level crossing keeper (LCK) located at the crossing. The operation of the crossing protection for each train was initiated by a call from the AQW travelling on the approaching train.
Signalling
Approach from Kilmore East towards Wallan Loop
Approaching from Kilmore East, the first signal to advise of the state of the turnout at Wallan Loop was signal ES1712 located about 2.7 km prior to the northern turnout to Wallan Loop.[49] At the time of the derailment, signal ES1712 was extinguished and was fitted with a black cross near its base to indicate that it was not functioning (Figure 10).
Figure 10: Signal ES1712 following derailment, non-operational and with cross affixed
Source: CITS
Signal ES1712 was a 3-position automatic signal. When operational, the signal would provide an indication of any speed reduction required approaching the next signal (WLN8) at Wallan Loop. A normal speed warning indication (yellow over red) at ES1712 would require a driver to be prepared to stop at the next fixed signal (WLN8) at the entry to Wallan Loop. If the train was signalled for the straight (No.1 track) at Wallan Loop, ES1712 would show a clear normal speed indication (green over red).
Wallan Loop Up home signal
Entry to the northern end of Wallan Loop was normally controlled by signal WLN8. At the time of the derailment, signal WLN8 was extinguished and was fitted with a black cross near its base to indicate that it was not functioning (Figure 11).
Signal WLN8 authorised train movements in the Up (towards Melbourne) direction. When operational, signal WLN8 could provide several indications (Figure 11). For train movements routed on the straight track at line speed, signal WLN8 would show a clear normal speed indication. For movements into the crossing loop, the low speed caution indication was used, which meant that trains must not exceed 15 km/h. Trains could also be signalled to stop at signal WLN8.
Figure 11: Signal WLN8 possible indications (left) and on day of occurrence (right)
The figure shows the possible indication for signal WLN8 (when operational), and a photograph of the signal extinguished. The photograph of signal WLN8 also shows the black cross that was attached to the signal post. Source: CITS
Broad-gauge signal near Wallan Loop entry
A broad-gauge distant signal was located about 45 m to the north of WLN8 and was probably indicating a proceed (green) aspect at the time ST23 passed (Figure 12).[50] This broad-gauge signal did not apply to the operation of ST23, which was running on the standard-gauge line.
Figure 12: Probable aspect of broad-gauge signal at the northern end of Wallan Loop
The figure shows the approach to the Wallan Loop turnout. The image has been modified to show the extinguished state of standard gauge signal WLN8 and the probable proceed (green) indication of broad-gauge distant signal at the time of the derailment. In this image, the points are set for the straight and the black cross is not fitted to the base of signal WLN8 as the image was taken prior to the signalling failure. Source: V/Line training video, with signal aspects modified and annotated by CITS
Environmental conditions
The conditions at the derailment location were dry. At 1930 at the nearest weather station, located at Kilmore Gap,[51] the temperature was recorded as 13°C, and the wind was from the south at 32 km/h. These weather conditions were unlikely to have been a factor in this occurrence.
The derailment occurred about 30 minutes before sunset. At 1943 at Wallan, the sun was at an azimuth[52] of 259°48'28" and altitude[53] of 5°02'59".[54] The direction of travel was 223° from true north, meaning the sun was about 36° to the right of the driver’s direct view ahead and low in the sky.
Photographs taken soon after the derailment showed a mostly cloud-covered sky with a break in the clouds on the southern horizon towards which ST23 was travelling. The sky near the horizon was therefore probably bright (with possible sun glare) when train ST23 approached Wallan. However, the circumstances of this occurrence do not suggest that visibility approaching Wallan Loop was a factor in the overspeed of ST23.
Management of rail traffic between Donnybrook and Kilmore East
Background
Late on 3 February 2020, ARTC identified that signalling had been disrupted around Wallan due to a fire in the signalling equipment hut. As a result of the damage to the signalling system, ARTC commenced managing rail traffic through the section using caution orders and other safeworking rules, consistent with the ARTC Code of Practice for the Victorian Main Line Operations (TA20). The rules associated with caution orders meant that trains were restricted to speeds not exceeding 25 km/h, which contributed to service delays of probably at least 45 minutes.[55]
To reduce delays, ARTC sought an alternative method of managing trains in the 24 km section between the passing lanes at Donnybrook and Kilmore East. The use of caution orders under the CTC safeworking system was then replaced with a method using train authorities that permitted train speeds up to normal line speed. Train authorities had previously been used by ARTC during infrastructure commissioning activities.
In early February, ActivateRail[56] had been engaged by ARTC to assist with a safeworking solution to improve the passage of rail traffic between Donnybrook and Kilmore East. The scope of its services included the development and management of the safeworking solution and the provision of qualified signalling personnel for its implementation. ActivateRail in turn engaged ARG Rail for the provision of an additional 3 qualified signallers.
ARTC also sourced personnel from labour-hire firm Programmed to assist with the implementation of the train working arrangements. Contracted workers included accompanying qualified workers (AQWs), car drivers (to transport personnel), level crossing keepers (LCKs), and track force protection staff.
Train notice 266 description of train working arrangements
Initial issue of Train Notice 266
The use of train authorities between Donnybrook and Kilmore East in February 2020 was notified by train notice 266 (TN 266), issued on 6 February 2020 and effective from 1900 on that day (Appendix C). The train notice was a typed document of 6 pages and provided the following introduction to the change of conditions:
TRAIN AUTHORITY WORKING DONNYBROOK PASSING LANE TO KILMORE EAST PASSING LANE:
Owing to signalling disarranged at Wallan Loop, commencing 1900hrs on Thursday 06/02/2020, rail traffic will operate by means of Train Authority issued by the ARTC Network Controller between signal DBK6 and DBK18 Donnybrook Passing Lane, and signals KME4 and KME16 at Kilmore East Passing Lane.
All signalling between Donnybrook Passing Lane and Kilmore East Passing Lane will be disarranged and the Train Authority single line section will be Donnybrook Passing Lane to Kilmore East Passing Lane.
TN 266 advised the details of the signals that were disarranged, and that black crosses were affixed to the posts of disarranged signals. TN 266 advised that within the affected section:
It should be noted that the signal may be lit and any aspect displayed may be ignored provided the driver of the rail movement is in possession of a Train Authority as detailed in this Train Notice.[57]
TN 266 also advised that the points at either end of Wallan Loop would be placed in the hand‑operating position and clipped in the normal (straight) position, and that signage would be installed at each end of the section advising of the transition between CTC and train authority working.
TN 266 discussed the roles of the various parties and advised:
ARTC NETWORK CONTROLLER
-----------------------------------------------
The ARTC Network Controller is responsible for ensuring the track is safe for traffic prior to each rail movement and issuing a Train Authority for a rail movement to proceed between Donnybrook Passing Lane to Kilmore East Passing Lane.
SIGNALLER
-----------------
A signaller will attend Donnybrook Passing Lane, or Kilmore East Passing Lane to receive a Train Authority and CAN from the ARTC Network Controller and issue it to the driver of each rail movement.
The signaller will deliver the Train Authority and CAN to the driver of the rail movement as required.
All rail movements operating between Donnybrook Passing Lane to Kilmore East Passing Lane during the period of the Train Authority Working will be provided with an Accompanying Qualified Worker who will advise the driver of the rail movement the activities occurring and the affected infrastructure.
TN 266 further specified the processes to be used for the issuing of the train authority to the driver. It described a requirement for the (in-field) signaller to read back the contents of the train authority to the NCO, and for delivery to the driver TN 266 stated:
The signaller may then hand the Train Authority to the driver and the driver must sign for the Train Authority on the butt of the form. The signaller will deliver the Train Authority to the driver of the rail movement as required.
TN 266 also described the processes for the issuing of a condition affecting the network (CAN) notice, which was required because the Wallan–Whittlesea Road level crossing protection was not operating normally.[58] The described process included the signaller delivering the CAN to the driver.
For the passage through the section under the train working arrangements, TN 266 stated:
Prior to entering the section, the driver must verify the Train Authority with the ARTC Network Controller.
The Accompanying Qualified Worker must also board the locomotive and once the Train Authority has been verified, the Accompanying Qualified Worker must advise the train crew of the work activities and that details of the non-operational level crossings.
The rail movement may proceed through the section in the normal manner.
As the movement approaches the Wallan - Whittlesea Rd level crossing at Wallan Loop. The Accompanying Qualified Worker must contact the level crossing keeper and advise of the rail movements approach, and when advised, the level crossing keeper operate the test switch to activate the level crossing and provide the driver the ‘all clear’ hand signal.
Changes to train notice 266
TN 266 was updated and reissued on 7 February. This amended notice introduced reference to the arrangements being in exception of a rule within TA20 and stated:[59]
SIGNALLING DISARRANGED
--------------------------------------------
Rule 5, clause b Section 5 of TA20 will not apply for the disarranged signals and the signals will have a black cross affixed to the signal post and the signal may be lit.
The following signals are disarranged and have a black cross affixed to the post of the signal…
TN 266 was further amended and re-issued by ARTC on 13 February 2020 (Appendix D). Amendments included:
removal of the advice that signals in the section may remain lit[60]
addition of text advising that ‘Repeat Back of the Train Authority is not required to be undertaken by the driver of the rail movement’
replacement of ‘The rail movement may proceed through the section in the normal manner’ with ‘The rail movement may proceed through the section up to track speed as advised by the Accompanying Qualified Worker’
addition of the instruction that ‘The driver must approach the level crossing with caution, prepared to stop short of the crossing unless the ‘all clear’ hand signal has been provided’
that Rule 1, Section 3, did not apply during Train Authority Working.[61]
Train authority form
A train authority form was prepared for use as part of the process described in TN 266 (Appendix E). This form was then to be completed by the NCO and the (in-field) signaller.
Application of train notice 266
In-practice application of TN 266
The method applied for issuing a train authority to a driver travelling in the section between Donnybrook and Kilmore East involved the on-duty ARTC NCO at Junee, an in-field signaller (the signaller) and an AQW. Key steps used by these parties in practice were:
The NCO and signaller were both provided with train authority forms to be used under TN 266 (Appendix E).
The signaller positioned themselves at whichever end of the Donnybrook–Kilmore East section that was to receive the next train.
Prior to the arrival of the next train, the signaller contacted the NCO to obtain details specific to the next train movement and was issued with a train authority.[62] The issuing process involved the NCO dictating the details of the train authority to the signaller and the signaller completing the form accordingly.
The signaller then read back the completed train authority to the NCO to verify its contents.
A CAN notice was also completed by the signaller under the instruction of the NCO.[63]
The signaller gave the completed train authority and CAN notice to the AQW and, on the train’s arrival, the AQW boarded the driver’s cab of the train. There was no contact between the signaller and the driver of the train.
Once on board, the AQW gave the train authority and CAN notice to the driver. The driver then contacted the NCO to verify the train authority. ARTC network control required the driver to verify the train authority to the NCO by its number only. There was no expectation that the driver would read the content of the train authority to the NCO, and no provision made on the train authority form for the driver to sign the form.
Train authority statistics
Between 6 and 20 February, 255 train authorities were issued for the section between Donnybrook and Kilmore East; 126 were issued at Donnybrook and 129 at Kilmore East.[64] Two of these authorities were cancelled owing to errors, one at each location.
Of the 255 train authorities issued, 55 were issued to XPT drivers, with 8 being issued to the driver of train ST23 prior to the day of the derailment. TA 17 was the ninth train authority that the driver had received. Drivers of other (non-XPT) passenger trains received 59 train authorities.
There were several instances during the two weeks where the signaller was issued a train authority for the single line section between Donnybrook and Kilmore East prior to the previous train authority for the single line section being cancelled. This was contrary to the instructions of TN 266.
Between 6 and 20 February, there were 21 NCOs and 5 signallers involved in the issuing of the authorities.
Driver readback statistics
Even though the train working arrangements did not specify a requirement for drivers to read back the train authority to the NCO, over a quarter of V/Line drivers and some others read the train authority back to the controller. The proportion was about the same before and after the (13 February) amendment of TN 266 that stated explicitly that readback was not required.
The driver of ST23 read back the train authority on their first journey under the altered train working arrangements. On subsequent trips, this driver did not read back the train authority and verified the authority by stating its number.
The reaction of NCOs to driver readback varied; on some occasions they allowed it to continue, and on other occasions they indicated to the driver that the readback was not necessary. At 1322 on 20 February 2020, when a V/Line driver was repeating back the train authority, the NCO on duty on the shift prior to the derailment, advised the driver that they did not need to repeat back. When the driver continued to repeat back the message, the NCO attempted to talk over the driver’s repeat back and instructed the driver to ‘standby’.[65] The driver continued to repeat back and advised the NCO that they were of the understanding that a repeat back to the controller was required.
Other operator queries and feedback
On establishment and the subsequent use of the alternative train working arrangements, there was disquiet within some sectors, and concern that the arrangements introduced were outside the established operating rules of TA20. The expressed concerns were mostly amongst V/Line drivers. The following is a selection of relevant actions and concerns on the train working arrangements in place:
On 7 February, a northbound NSW Trains driver queried the wording in TN 266 that indicated that drivers should disregard signals between signals DBK8 and KME2. The driver advised the on-duty NCO that DBK8 would be facing trains travelling in the other direction.[66] The NCO advised they would raise the matter, although there was no subsequent change to this part of TN 266.
On 10 February, a V/Line driver advised ARTC train control that that they would not pass signal WLN8 at stop (that was still lit), as they believed they could not treat it as a signal that could be disregarded. The driver requested separate authority to proceed, or for the lights in the signal to be extinguished, leading to a long delay in train operations through the section. The NCO advised that the instructions in the train notice covered the workings and they would not issue an additional authority as they believed this would be a second authority for the same section. All signals within the section were subsequently extinguished, and TN 266 was revised on 13 February with the text ‘the signal may be lit’ removed.
On 11 February, a V/Line driver made an inquiry to their management as to why ARTC had implemented train authority working when TA20 section 25.1d did not allow for such use of train authorities.
On 12 February, a V/Line driver advised the on-duty NCO that they had been instructed by their superiors to travel through the section at 25 km/h ‘due to the rule book’. TN 266 was reissued on 13 February with the text ‘Rule 1, Section 3, did not apply during Train Authority Working’ added and the text ‘The rail movement may proceed through the section in the normal manner’ in the original notice replaced with ‘The rail movement may proceed through the section up to track speed as advised by the Accompanying Qualified Worker.’
On 14 February, a V/Line driver requested that the signaller give them the train authority directly (as stated in TN 266) rather than via the AQW. This required the signaller (who had by that time departed the handover position) to return to Kilmore East to hand the train authority directly to the driver.
Train notice 367 description of changed conditions
Details of notice
Train Notice 367 (TN 367) (Appendix F) was issued on the evening of 19 February 2020 and contained additional instruction to TN 266. In relation to the changed conditions at Wallan Loop, the notice advised:
In addition to instructions contained in Train Notice 266 / 2020 issued on 13/02/2020 the following temporary alteration to working will apply.
On Thursday 20 February 2020 between 1430 hrs and 2130 hours, all trains will operate via No. 2 track at Wallan Loop, in the Donnybrook to Kilmore East, Train Authority Single Line Section.
At approx. 1400hrs the TFPC[67] will obtain a Track Warrant between Signal DBK8 at Donnybrook and KME4 at Kilmore East and upon Stop Boards being erected at Wallan Loop, the Safeworking Manager will set points 3 at the Melbourne end of Wallan Loop, and Points 7 at the Kilmore East end of Wallan Loop to the reverse position and then reapply the point clips and secure the point clips with special padlocks.
TN 367 also provided information on what would be in the train authority with the note:
NOTE: POINTS AT WALLAN LOOP SET AND SECURED FOR NO. 2 TRACK
MAXIMUM SPEED ENTERING WALLAN LOOP 15KPH
MAXIMUM SPEED EXITING WALLAN LOOP 35KPH UNTIL TRAIN HAS CLEARED POINTS
At the conclusion of TN 367 was the following special note:
SPECIAL NOTE:
# The maximum speed for trains entering Wallan No. 2 track and is 15Kph until the whole of the train has cleared the points, and
# The maximum speed for trains exiting Wallan No. 2 track is 35Kph until the whole of the train has cleared the points.
The Accompanying Qualified Worker must remind train crews of trains that the train will operate via No. 2 track at Wallan Loop and the speed limits required.[68]
A separate train notice details testing of signalling at Wallan after which normal main line running will resume.
The instruction in TN 367 on the maximum speed for entering Wallan Loop was not documented as a temporary speed restriction.[69] Therefore, a CAN warning for the 15 km/h speed limit at entry to Wallan Loop was not issued.
Train authority form for transit through Wallan Loop
A new train authority form was prepared for use by NCOs and (in-field) signallers during train transit through the loop (Appendix G). The form included the additional note that:
NOTE: POINTS AT WALLAN LOOP SET AND SECURED FOR NO. 2 TRACK
MAXIMUM SPEED ENTERING WALLAN LOOP 15KPH
MAXIMUM SPEED EXITING WALLAN LOOP 35KPH UNTIL TRAIN HAS CLEARED POINTS
Distribution and receipt of TN 367
ARTC distribution
ARTC procedures defined the processes to be followed for preparing, reviewing, approving and issuing operational notices (including train notices) on the ARTC network.[70] Different processes applied to different parts of the ARTC rail network. For its NSW and Queensland network, the ARTC procedures for distribution of operational notices specified direct transmission to selected internal and external stakeholders.
For Victoria, South Australia and Western Australia, approved operational notices were published on the ARTC WebRAMS (Rail Access Management System) portal.[71] Standing train notices were specified as being uploaded to this portal at approximately 1800[72] each evening. There was no specified timeframe in which a notice was to be issued prior to it coming into effect.[73] Access to WebRAMS was available to ARTC customers and stakeholders via an allocated User ID system. For rail operators operating in Victoria, the onus was therefore on them to access ARTC safety notices through this portal.
Formal distribution of TN 367 by ARTC to rail operators was via the WebRAMS portal. ARTC reported that TN 367 was uploaded to WebRAMS as part of an automated system update at 1845[74] on 19 February 2020.
In addition to the formal release (on WebRAMS), a draft of TN 367 was forwarded to V/line for comment at about 1330 on 19 February. There was no reported similar active engagement by ARTC with, or direct release of TN 367 to, NSW Trains or freight operators.
NSW Trains receipt
NSW Trains did not have an active process in place to interrogate the ARTC WebRAMS portal for network operational information related to its Victorian operations. The activity of searching the ARTC portal was inadvertently discontinued around 2017 following a restructure within NSW Trains. For its operations within Victoria, NSW Trains drew on weekly operational notices (WONs) prepared by Metro Trains Melbourne (MTM) that were issued each Tuesday for the week commencing the Wednesday.[75] The WONs included safety information for metropolitan and regional services. The WONs did not, however, typically include ARTC train notices, and reference was instead made within the WON to the ARTC WebRAMS portal.
Each week, NSW Trains extracted information from the WON that was considered relevant to its Victorian operations. This process was used to produce an information pack for NSW Trains regional drivers that would operate in Victorian territory. This information pack was then placed in the pigeonhole of each driver at their Junee base. It was a driver’s responsibility to collect the information from their pigeonhole and assimilate that information.
No evidence was identified to indicate that NSW Trains was aware of TN 367 prior to the occurrence. WON Issue No.07, which was published on 18 February 2020, did not include information from TN 367. This WON did contain TN 266 (as amended on 13 February), which was the ongoing train notice for the Kilmore East to Donnybrook section at the time of the release of WON 07. Its direct inclusion in the WON was not standard practice and was instead the result of V/Line re-issuing ARTC TN 266 (as amended on 13 February) within its own safety information distribution system.
Extracts from WON 07 were prepared for distribution to NSW Trains drivers by 1139 on the morning of 20 February. The information pack (that did not include information on TN 367) was reported as being placed in the pigeonholes of regional drivers (at Junee) by 1247 the same day. It could not be confirmed whether the driver of ST23 had read the information pack issued on that day. There was no functioning system to assure that drivers read and understood the distributed safety information.
For its operations on the NSW portion of the ARTC network, NSW Trains received SAFE notices directly from ARTC.[76]
V/Line receipt and distribution
Normal V/Line process entailed driver supervisors checking the WebRAMS portal after the evening publishing of ARTC notices on that portal and distributing train notices to affected drivers.
In the case of TN 367, V/Line also received pre-information by email at 1333 on 19 February. ARTC provided V/Line with a draft of TN 367, although the distribution was not accompanied by an assessment of risk and risk controls. The notice was then circulated to various staff within V/Line with safety responsibilities. At 1434, a V/Line member of staff responded that:
there should be track force protection mainly, due to the fact that for the past week we have been running at line speed, thru No.1 road, now we have a change to No.2 road with the necessary speed reductions.
In response to receiving TN 367, V/Line published a V/Line safe working circular (SW.0024.2020), incorporating TN 367, for distribution to all drivers. The V/Line drivers that were to run through Wallan Loop on 20 February were also contacted by their driver supervisor prior to their shift and advised of the change in operating conditions at Wallan Loop.
The issuing of TA 17 to ST23 under TN 266 and TN 367
On 20 February, the issuing of the train authority (TA 17) for the passage of train ST23 followed the same processes as had been used during the previous 2 weeks. The NCO issued TA 17 to the signaller, and that process included a signaller readback. The copy of TA 17 completed by the signaller was consistent with the TA 17 that was completed by the NCO. The signaller’s copy of TA 17 was then transferred via the AQW to the driver of ST23, again consistent with the processes used in the previous weeks.[77]
Operating rules
Safeworking rules and use of train authorities
ARTC operating rules for Victoria were defined in the ARTC Code of Practice for the Victorian Main Line Operations (TA20).[78] This code described the following safeworking systems for those parts of the ARTC network covered by the code:[79]
centralised traffic control (CTC)
the train order system.
Prior to the signalling hut fire at Wallan in early February 2020, rail traffic through this section was managed using the CTC system described in section 17 of TA20. In the case of signal failure, this section provided for the use of caution orders and CTC arrival messages. The caution order form used in conjunction with a CTC system required that traffic ‘proceed cautiously’ …. ‘in accordance with Rule 1, Section 3’.[80]
The use of train authorities in the circumstances that were present between Donnybrook and Kilmore East in February 2020 was not provided for in TA20. The procedures associated with train authorities were specified in section 25 of TA20. This section stated that ‘Train Authority Working[81] must be used as specified by the individual operation of the safeworking system’. For sections with Centralised Traffic Control, the scope of train authority use was specified in TA20 as:[82]
to assist a disabled train
train to return to the crossing loop in the rear
working a train to the point of an obstruction on one or both sides.
For those circumstances where the use of a train authority was permitted, section 25 of TA20 described the methods of delivery, books of train authority forms, and verification protocols. The processes subsequently used in the train working between Donnybrook and Kilmore East were not consistent with those described in section 25 of TA20.
Communication requirements in TA20
Section 25 described that a driver must not proceed into the section unless the train authority was fully understood.[83] Verbal communication requirements were also specified in section 1 of TA20, although the direct applicability of this section to the train working arrangements in use at the time of the derailment is unclear. Section 1 stated that ‘the receiver must confirm the content of a message by repeating the message back exactly as it was received to the sender, if the communication is about: …… special working.[84]
The same clause of TA20 section 1 also addressed the relaying of communications and stated that ‘if it is not possible for a sender to communicate directly with an intended receiver, Competent Workers may relay the content’. In this case, direct communication between drivers (the intended receiver) and the NCO was possible via radio.
Condition affecting the network (CAN)
Within the ARTC operating rules for Victoria (TA20), Section 1, rule 7.a. provided information on the issuing of CAN warnings and stated that the ‘Condition Affecting the Network (CAN) form is used by Network Controllers when giving written warning to rail traffic crews if … faulty or potentially faulty level crossings have been reported’.[85] The use of a CAN to notify drivers of the manual operation of the level crossing protection at Wallan–Whittlesea Road was consistent with this description.[86]
Other rules
Other codes and rules that described potentially relevant safeworking systems and procedures were also reviewed (Appendix H). None were considered directly relevant to this occurrence.
Risk management
ARTC risk management system
ARTC captured operational risks on the ARTC network in its enterprise risk management system (ERMS). The ERMS was a repository of identified risks, risk controls and risk owners.
For the top event of derailment, 44 potential causes were recorded. The top event of derailment was for any train type, and risks associated with passenger operations were not separately considered.
Of the 44 identified causes of derailment, the cause ‘Train driver error (eg. overspeed)’ was listed and was linked to 15 risk controls. ‘Other rail operator’ was identified as the responsible party for 6 of these controls that pertained to the rolling stock operator, and included controls such as driver competency, route knowledge and fatigue management. ARTC was identified as the responsible party for the remaining 9 risk controls. Of these ARTC controls, the first 2 listed were ‘ATMS (where in place)’[87] and ‘Two person train operation (where in place)’. Neither of these controls was applicable to passenger train operations in Victoria. Of the remaining 7 controls allocated to ARTC responsibility, the most significant were ‘Network rules and procedures’, ‘Track signage’ and ‘Train graphs’ that were each rated as ‘partially effective’.
Within other causes for derailment, the risk control of ‘ARTC Safety Management System (SMS)’ was a common risk control and rated as ‘substantially effective’. For the derailment cause of ‘Human Factors’, train notices were listed as an administrative control and rated as ‘minimally effective’.
For operations of the XPT on the ARTC network, the risk management interface between ARTC and NSW Trains was described in a 2011 interface agreement that was agreed between ARTC and RailCorp.[88] The document included a risk review table describing the risk of derailment due to train overspeed, although this document had not been updated since the agreement in 2011.
ARTC risk management procedure
ARTC’s safety management system (SMS) included a risk management procedure that advised that the identification and management of risk occurs at all levels of ARTC.[89] This procedure was described as being consistent with ISO 31000:2018 Risk Management – Guidelines[90] (Standards Australia 2018) and included different types of risk assessment and approaches (Appendix I).
This risk management procedure included requirements for a risk study or assessment for a range of activities and system changes. It specified that formal risk studies were usually undertaken for complex activities where potential impact was likely to be significant. The listed types of activities where the procedure suggested a formal risk study may be considered appropriate included:
significant civil works, such as tunnel construction, bridge construction
technical operational changes, such as introduction of new signal/track infrastructure
safety-critical system changes, such as network control system changes.
Consistent with the overarching procedure, the relevant ARTC work instruction[91] for the application of risk management referenced alignment with ISO 31000. The work instruction specified establishing the objectives, context and scope to be carried out by the workshop convenor prior to a risk workshop taking place.
Application of risk management for train working arrangements
Risk workshop and development of risk management plan
For the train working arrangements between Donnybrook and Kilmore East from 6 February, a risk management plan was prepared. A limited risk workshop was conducted at about 1600[92] on 6 February and involved representatives from ARTC and its contractor, ActivateRail. There was no evidence of involvement of a risk specialist or risk manager in the process. The associated risk management plan was then finalised on 7 February.
This documented risk management plan was not updated for the duration of the temporary train working arrangements. ARTC advised that risks relating to the train working continued to be informally assessed as feedback was received and that changes were reflected in the amendments made to TN 266.
Context described in risk management plan
Within the ‘context setting’ section of the risk management plan, the background of the risk assessment was documented as being the re-signalling of Ararat Junction and referenced documents included the ‘Operations and Safety Commissioning plan for the commissioning of signalling at North Geelong C’. It is probable that previous plans were used as the basis for risk assessment, but not all sections of the risk management plan had been updated for the signalling disruption between Donnybrook and Kilmore East and the planned train operations.
Scope described in risk management plan
The scope documented in the risk management plan stated ‘the scope is specific to the rail operations and safeworking activities for the commissioning’. It is probable that the scope referred to a previous commissioning activity and was not updated for the extended period of train operations between Donnybrook and Kilmore East.
Consultation in risk assessment process
The ARTC risk management procedure stated that ‘a consultative approach with stakeholders must be used to determine the context, risk criteria and structure for the remainder of the process.’ The risk management plan for the train working between Donnybrook and Kilmore East identified rail operators as stakeholders. The risk worksheet associated with the plan was released to V/Line and labour-hire firm Programmed at about 1700 on 7 February, the day after TN 266 and the train working arrangements came into effect. NSW Trains and freight operators were not included in this distribution.
Outcomes of risk assessment described in risk management plan
The risk management plan for the ‘Operation of Train Auth Working between Donnybrook and Kilmore East’ identified 10 risks and associated control measures. The plan documented the treatment for each risk and ARTC was identified as the ‘responsible party’ for each risk and associated control.[93] The plan provided no evidence of treatments that had been considered but rejected.
Several described hazards were associated with works and commissioning of signals. There were no identified hazards or scenarios (and associated risks) specific to passenger train operations.
Risks associated with routing trains through Wallan Loop or derailment due to overspeed were not directly identified in the risk worksheet. There were also no subsequent changes to the risk management plan specific to the routing of trains through Wallan Loop on 20 February.
Of the 10 risk items that were identified in the plan, the risks most relevant to this investigation were:
rail operator not aware of the altered train working (risk item 2)
The identified risks and risk controls associated with risk item 6 and the level crossing protection at Wallan–Whittlesea Road are described at Appendix J.
Rail operator not aware of the altered train working (risk item 2)
The risk management plan described the hazard, cause and outcome associated with the operator (driver) not being aware of the altered train working (Table 1).
Table 1: Risk management plan description of risk item 2
Hazard
Rail Operators not aware of the altered working
Caused by
Train notices not received by train crews detailing the processes in place
Worst outcome
Train driver accepts the train authority and proceeds into the section not conversant with the altered working
For this risk, the plan identified 4 controls that were to be implemented, of which 2 controls, the timely issue of train notices and the ‘piloting’ of the train, were also relevant to the management of risks associated with the subsequent routing of trains through Wallan Loop (Table 2).
Table 2: Specified risk controls for risk item 2 and ATSB comment on implementation
Specified risk control
ATSB comment on the implementation of the control
Train notices will be issued in a timely fashion
All train notices were issued a short time prior to them taking effect.
The initial release of TN 266 was on 6 February and came into effect at 1900 the same day.
The 2 subsequent updates to TN 266 came into effect on the same day as their issue.
For the changed conditions at Wallan Loop, TN 367 was released on the ARTC portal at about 1845 local time (1815 in Adelaide) on the evening of 19 February, and the changed conditions (points set for the loop) existed by 1536 the following day (20 February).
Signals at the interface of the commissioning will have change of safeworking signage to indicate the interface between CTC and train authority working
Signage at Donnybrook and Kilmore East provided a visual cue to drivers at the extremities of the affected section of the transition between CTC and the altered train working.
This control was not relevant to the change to route trains through Wallan Loop.
Disarranged signals will have black crosses affixed to them
Black crosses were affixed near the base of disarranged signals rather than at the signal head and were reported as difficult to observe. In addition, the deviation from the practice of extinguishing affected signals resulted in confusion until signals were extinguished and the update reflected in the amended TN 266 issued on 13 February.
This control was not relevant to the change to route trains through Wallan Loop.
Although the risk management plan specified that trains would be piloted, a pilot was not made available for the trains operating during the altered working. Instead, an AQW was made available. Differences between the roles of pilot and AQW are discussed below.
For the changed conditions and routing of trains through Wallan Loop, this control was augmented by the issue of TN 367, which specified that the AQW was to advise the driver that the train would operate via No.2 track and of the speed limits required.
A pilot as a risk control
Although the definition of a ‘pilot’ varied across a number of references, descriptions were of a directive role (compared to that of the AQW described in TN 266). Consistent themes were that the role of a pilot involved directing the movement of the train, and that to perform their role the pilot required a full understanding of the route, the infrastructure and operational constraints.
Within the ARTC code of practice for operations in Victoria (TA20), the role of a pilot was mentioned within section 14 (Single Line Working) and section 15 (Infrastructure Works). These sections included detailed requirements for a pilot ranging from identification badges to tasks specific to the safeworking activity. Neither of sections 14 or 15 were applicable to the train operations in place at the time of the derailment of train ST23 and the described process for the AQW did not follow the requirements in these sections. There was no mention of the use of a pilot in section 25 of TA20 (Issue of Train Authorities).
The Rail Industry Safety and Standards Board (RISSB) Glossary defined the title of ‘Pilot’ as:
A Competent Worker, who accompanies, directs and advises rail traffic crews.
The ARTC Glossary[95] (applicable to NSW) included the following definitions pertaining to pilotage:
Pilot: a Competent Worker who accompanies, directs and advises Rail Traffic Crews
pilot: to direct or guide Rail Traffic Crews and advise them about local conditions and operating restrictions on running lines and at worksites.
Also applicable to NSW, the ARTC document ANRP 710: Piloting trains and track vehicles[96] contained specific requirements on what a pilot should do. Of note, the procedure advised that:
The driver was responsible for the safe operation of piloted trains and track vehicles.
The pilot needed to confirm their knowledge of the route.
The pilot needed to establish and maintain effective communication with the NCO.
The pilot needed to give clear directions (to the driver).
Comparing these requirements with the role of an AQW under TN 266 and TN 367:
The driver was similarly responsible for the safe operation of the train.
There was no clear requirement for the AQW to confirm their knowledge of the route.
The AQW was not required to, and did not, communicate with the NCO.
The AQW was not required to, and did not, direct drivers.
The role of an AQW for the train working arrangements
The role of an AQW was not defined nor referenced in either TA20 or the Code of Practice for the Defined Interstate Rail Network. The role of an AQW (or qualified worker) was also not defined by the industry body, RISSB.[97] The qualifications, knowledge and experience required of an AQW were also not described within the documentation for the train working arrangements between Donnybrook and Kilmore East in February 2020 (TN 266).
A primary task allocated to an AQW was to call (by mobile phone) the level crossing keeper (LCK) to ensure activation of the level crossing protection at the Wallan–Whittlesea Road prior to train arrival. TN 266 also described that the AQW was to advise the driver of the ‘work activities’ and affected infrastructure, and a later amendment to the notice added that ‘the rail movement may proceed through the section up to track speed as advised by the AQW’. Although not documented in TN 266, the AQW also performed the task of delivering the train authority and CAN notice to the driver of the train. There were no defined qualifications or experience requirements to perform the role of an AQW.
The role of an AQW was to provide information rather than be directive and there was no responsibility on the part of the AQW to ensure the driver understood the content of the train authority. Under TN 367, there was an additional requirement for the AQW to remind the driver that the train was to operate via No.2 track at Wallan Loop. However, there was no associated protocol for assuring driver understanding of the train authority, and no readback requirement between a driver and the AQW.
AQW experiences during the train working between Kilmore East and Donnybrook, including interactions with drivers, were explored in interviews. Described experiences included:
On the shifts prior to the change at Wallan Loop on 20 February, the AQWs told drivers that they could travel at line speed (at the driver’s discretion), that the crossing at Wallan–Whittlesea Road had been disabled, and that the LCK would be contacted to activate the crossing.
In the period that the disarranged signals were still lit (prior to the 13 February amendment to TN 266), the AQWs would generally inform drivers that they could pass any lit signals at normal speed.
Experiences and recall of train operating speeds varied across the AQW group. There was reasonable consensus that the XPT would generally operate at speeds around the line speed of 130 km/h, whereas V/Line trains would mostly travel at a lower speed, with one AQW suggesting typically around 75 km/h. The speed of freight operators varied.
AQWs varied in their recall of the speed of trains approaching the Wallan–Whittlesea Road level crossing. One AQW stated that they would advise the drivers to use caution going through this level crossing.
Interaction between the AQWs and train crew would vary. Although there were sometimes conversations with the drivers, one AQW described this as ‘cab-chat’.
Application of the role of AQW for train ST23
This shift was the first time the rail worker was performing the role of AQW. At the start of their shift, the AQW allocated to ST23 was briefed by a more senior AQW on the role of the AQW. The briefing included instruction on calling the LCK to facilitate and confirm level crossing protection at Wallan–Whittlesea, and the landmarks for making that call.
The briefing also included discussion on TN 367 that specified a requirement for the AQW to advise the driver that the train would operate via No.2 track at Wallan Loop and of the speed limits at entry to and exit from the loop. The AQW on ST23 was also in possession of a copy of TN 367. When at Kilmore East, the AQW was also briefed by the signaller on the particulars of the train authority and the speed restrictions. Based on this evidence, it is very likely that the AQW on train ST23 was aware that ST23 was being routed through Wallan Loop and of the requirement to advise the driver.
As previously noted, the AQW did not have experience as an AQW or as a pilot prior to this shift. The AQW also did not have front-of-train experience or route knowledge[98] for the section between Donnybrook and Kilmore East.
Also as previously noted, due to the absence of in-cab recordings the nature and content of the conversations that took place between the AQW and driver on ST23 are unknown.
Train recorded information
The Hasler RT recorder
Power cars XP2018 and XP2000 were each fitted with a Hasler RT data recorder. The Hasler RT is an electro-mechanical device that records data onto a waxed paper tape (roll). Data recorded included speed, distance, time, a combined power-vigilance parameter, and brake cylinder pressure. The Hasler equipment included an analogue speedometer located on the driver’s console.
Unlike modern data logger systems that provide digital information for a wide range of operating parameters, the Hasler tapes provide their limited information in graphical format. As a result, there is less precision in the data. GPS data from the train’s installed radio system was used to verify time, speed and position information.
Estimated train speed, throttle and braking
The Hasler and GPS data was analysed to assess recorded driver activities and train speed, including on the approach and into Wallan Loop (Appendix K). It was found that an emergency brake application was made when the train was travelling at about 129 km/h.[99] Brake cylinder pressure began to rise when the train was between 153 and 50 m from the turnout to Wallan Loop. The speed at entry to Wallan Loop was estimated to be between 114 and 127 km/h.
On the approach to Wallan, there was braking and throttle activity consistent with expected driver activity. A power application was made, and speed increased to about line speed after the confirmation was obtained from the LCK that the crossing protection at Wallan–Whittlesea Road was activated. There were no warnings provided by the vigilance system (therefore indicating there was driver activity) after the train departed Kilmore East.
Cab video and voice recording devices
The leading power car (XP2018) was not fitted with in-cab voice or video recording devices, nor was it required. As a result, there was no available evidence with respect to communications or interactions between the driver and AQW prior to the occurrence. Voice recording within the driver’s cab would have assisted the investigation in ascertaining the interactions within the cab, and the potential identification and analysis of any associated safety factors.
Derailment site
Site overview
The derailed train came to rest in a concertinaed arrangement and the leading power car had overturned onto its left side (Figure 13). The 5 passenger cars had derailed and were at various angles of incline. The rear power car was upright and still on track.
Figure 13: Train ST23
Source: ATSB
Turnout and track
At the time of the derailment, the points at the northern end of Wallan Loop were in their reverse position to provide entry to the loop (Figure 14). The points mechanism had been placed into the hand-operating mode[100] and the points were locked in position. The mechanism was also padlocked. These settings were consistent with the arrangements specified in TN 367 and TA 17.
Figure 14: No. 7 points at the northern entrance to Wallan Loop set to reverse
Source: CITS
There was no evidence of derailment prior to the turnout. Inspection identified evidence of derailment within and beyond the turnout. Track damage, including to rail and track formation, was extensive within No.2 track.
There was no evidence identified to indicate that the condition of the track at the northern entry to Wallan Loop was a factor in the derailment, noting also that the speed of the train exceeded the design rating of the turnout by a significant margin. The left rail of the turnout had been lifted a small amount at the commencement of the reverse route, possibly as a result of loading of the right side of the track in the vicinity of the crossing block[101] during the passage of ST23.
Power car XP2018
The leading power car (XP2018) had rolled onto its left side and come to a stop to the left of No.2 track and against a row of pine trees (Figure 15). With the power car on its side, the only reasonable access to the cab was through the right-side driver’s cab door.
At the time the site observations were made, the brake controller in the driver’s cab of power car XP2018 was in the emergency brake position with the power (throttle) controller in OFF and the reverser direction in forward. Both diesel fuel tanks of power car XP2018 had been torn open along their bottom left edge during the derailment and overturn.
Figure 15: Power car XP2018 overturned and access route via right door
Source: ATSB
Leading passenger car
Of the passenger cars, the first (car A) had the greatest tilt (about 30° from the vertical) and the most extensive exterior damage. It had come to rest on a row of pine trees (Figure 16).
Figure 16: The derailed position of car A (photograph taken after cutting of trees)
Source: CITS
Power car XP2018 crashworthiness and survivability
General inspection findings
Inspections of power car XP2018 were conducted to examine its crashworthiness performance and crew survivability features. The car was initially inspected at the derailment site, and further examined at the Auburn UGL facility (Figure 17).
Figure 17: Power car XP2018 at Auburn workshops on 10 March 2020
Source: ATSB
Scouring damage was present along the full left side of the power car that suggested the car had slid on its side for a significant distance. The car had retained its whole-body structural integrity, however both doors on the left side had been dislodged. There was evidence of a significant amount of ballast and earth having entered the driver’s cabin through the left-side driver’s cab door opening. Instruments, control panels and interior fittings were mostly intact.
The car’s forward windscreen had remained in place during the derailment.[102] The lower rear corner of the left-side quarter window had detached from the frame, although it was assessed that only a limited amount of ground material had entered the cab through that opening.
Inspection of left-side cab door
The left-side driver’s cab door was made from fibre-reinforced polymer and contained a glass window panel (that remained intact). The door was inward opening, hung with 2 hinges on its rear edge and closed by a single door latch on its forward edge. After the power car overturned onto its left side, the door separated from the door frame and was loose within the cabin.
Inspection identified that the 2 hinges had failed. The upper hinge knuckles had peeled open (Figure 18) and the fastening of the lower hinge to the door frame had failed (Figure 19).
Figure 18: Upper internal hinge of left cab door of XP2018
Source: ATSB
Figure 19: Lower internal hinge of left cab door of XP2018
Source: ATSB
Assessment of left-side driver’s cab door separation
Design standards for pressure loading
The configuration of the driver’s cab door and the potential scenarios leading to its separation from the door frame were considered. It was concluded through inspection of the components, and the probable comparative loading on the upper and lower hinges, that the most likely initial failure was of the upper door hinge.
A simplified assessment of the hinge was conducted using design loads from contemporary Australian and overseas industry standards.[103] Australian standard AS 7521:2018 (Standards Australia 2018a) specified that external vehicle doors were required to meet the United Kingdom’s Rail Safety and Standards Board (RSSB) standard GMRT2100. Issue 6 (2020) of that standard specified external static and aerodynamic loads that were both defined as 2.5 kPa for trains travelling up to 200 km/h. Analysis indicated that the upper hinge on the XPT would not be expected to fail with a 2.5 kPa external pressure, applied quasi-statically (Appendix L).
Design standards for loading when overturned
GMRT2100 did not specify loading associated with external impact during rollover but did note that ‘where hinged external doors are used, typically for cabs, it is good practice to pay particular attention to the design of the door frame and locks’. It further noted that ‘there is a risk that, in the event of a derailment resulting in a roll-over, the structure can flex sufficiently to spring the door open, with the subsequent risk of the ingress of ballast and debris’. Assessment of the door and door frame of ST23 concluded that, in this instance, the door probably failed at its hinges rather than opening. Regardless, the result was the same with the entry of debris.
Australian industry standard AS 7520.1-2022 (Standards Australia 2022) specified that:
The cab roof structure, cab mounting systems, and adjacent structures should be capable of supporting the weight of the locomotive (including the bogies) in the situation when the locomotive is resting on its side without exceeding the critical design stress in the main supporting members …..
There were no specific requirements in the standard that related directly to the external loading of doors when the vehicle was on its side, nor dynamic loadings associated with a vehicle impacting the ground.
Although these loading scenarios were not specified for doors, an assessment was made of the upper hinge considering the pressure applied to the cab door if the power car was resting on its side with its own weight evenly reacted across the side profile of the car. This scenario equated to an applied pressure of about 11 kPa. It was found that the upper hinge knuckles would probably unfurl under this applied external pressure or at least commence to plastically deform (Appendix L).
Loading on door of ST23
In the process of overturning and sliding on its side over uneven ground, the dynamic loading of the left-side driver’s cab door would be expected to be significantly higher than the static load case of the car resting on its side (11 kPa). Given the probable commencement of unfurling of the upper hinge knuckles in the static-load case, complete unfurling of the upper hinge knuckles in the higher dynamic-load scenario was considered very likely. Consistent with this finding, it was also concluded that the cab side-door attachments were probably not designed to withstand the power car overturning and sliding on its side.
Survivability assessment of access to/egress from driver’s cab
Access to the driver’s cab on overturned power car
The normal access to and from the XPT driver’s cab was through its side doors. With the power car on its left side, the right-side driver’s cab door, which was now at the top of the overturned power car, was the most accessible access route to the cabin and the train crew inside.
The right-side driver’s cab door of ST23 remained operable and was used by members of the passenger services crew to gain access to the cab. However, this access route was only accessible by able-bodied people climbing on top of the power car and there was no reasonably practical way to extricate any non-ambulatory people from the driver’s cab.
At the rear of the driver’s cab there was an internal door to access the machinery space, and at the rear of that space there were 2 rear door side exits and a rear central door. However, access to the driver’s cab via the machinery and equipment compartments with the power car overturned would be hazardous and probably unrealistic.
Contemporary Australian egress requirements
Australian industry standard AS 7522:2021 (Standards Australia 2021)[104] specified that enclosed cabs of rolling stock shall be fitted with sufficient emergency exits to provide escape paths to the vehicle exterior when the vehicle was upright and when overturned on its side. There was no requirement specified for how a person might move to such exits if the vehicle was overturned. In the case of the overturned ST23, the right-side door at the top of the overturned vehicle was available to able-bodied people.
AS 7522:2021 and a NSW standard (Transport for NSW 2017) contained a number of other egress requirements for passenger train rolling stock. However, requirements generally applied to new passenger cars, or following a major modification, and none were identified as directly applicable to the configuration of the XPT power car.
There were no Australian Standards identified that specifically referred to requirements for ground-level access to overturned locomotives or power cars.
Similar occurrence related to crew survivability in a power car
On 6 November 2004, a 10-vehicle high speed train (HST) was derailed when it struck a motor vehicle at a level crossing at Ufton Nervet, United Kingdom. The accident was investigated by the RSSB (2005).
The HST was travelling at about 160 km/h at the time of the collision. The leading power car and all trailing vehicles derailed. The leading power car overturned and slid on its left side for some distance. Five passengers, the train driver and the motor vehicle occupant were fatally injured.
The XPT was based on the HST design and had similar form and structural configuration (Figure 20). There were differences in the cab internal layout, window arrangement and driver’s cab side door detail.
Figure 20: HST (left) and XPT (right)
Source: Redditch Railway Interest Group and Government News
In the Ufton Nervet derailment, the leading power car came to rest on its left side with severe abrasions down the side of the car but with the whole-body structure substantially intact. There was structural failure at the top of a left leading pillar, this being the frame to which the left-side driver’s cab door was latched (Figure 21). The cab door had separated from the door frame and earth and ballast had entered the cab through the door aperture. In both the Ufton Nervet and Wallan derailments, the loss of the side cab door (when the power car overturned) resulted in material entering the cabin and impacting the occupants.
Figure 21: Ufton Nevert cab side damage (left) and Wallan cab side damage (right)
Skin penetrations are circled on the HST damaged at Ufton Nevert. The windscreens and windows have been removed on both trains.
Source: RSSB and ATSB.
The RSSB final investigation report into the Ufton Nevert derailment did not make a direct recommendation on the ingress of materials into the driver’s cab and referred the matter to the RSSB (2007) research project into cabin design and driver protection. The scope of this research project, which had already commenced at the time of the Ufton Nevert accident, was amended to include aspects of that accident; specifically, protecting the driver’s cab occupants from ingress of debris. The released report from this research project acknowledged that the door would open in such an accident and suggested the installation of partitions or reorientation of the door opening to screen the driver from the incoming debris.
Passenger car crashworthiness and survivability
Passenger injuries
There were 155 passengers and 5 crew members in the 5 passenger cars of train ST23. Available data from NSW Trains and Victoria Police was combined with passenger survey response data to estimate a total number of 61 passenger physical injuries.[105] This was comprised of 8 serious injuries and a reported 53 minor injuries.[106]
The estimated number of passengers in each car, the known injuries to passengers in each car, and the associated injury rate are shown in Table 3. The injury status for some passengers could not be determined, and it is possible there were more minor injuries. In addition to passenger injuries, the 5 members of the passenger services crew (1 in Car B and 4 in Car C) all received minor injuries.
Table 3: Estimated number of passengers in each car, known injuries and injury rate
Passenger car
Serious injuries
Minor injuries
Passengers
Injury rate
Car A (cabin / sleeper)
2
1
5
60%
Car B (first class)
3
28
52
60%
Car C (first class / buffet)
1
3
12
33%
Car D (economy class)
2
16
57
32%
Car G (economy class / baggage)
0
5
26
19%
Total
8
53
155
39%
Most injuries to passengers were a result of people being unprepared for the sudden deceleration or movement during and following the derailment. Passenger injuries were more prevalent and more severe in the forward passenger cars (as shown in the table above). Loose luggage also became projectile hazards during the derailment. Some luggage fell from overhead racks and there were instances of loose luggage causing injury to passengers and service crew.
Inspections
The 5 passenger cars were inspected to examine crashworthiness performance (Appendix M). Inspection of all passenger cars was conducted at the derailment site, and the leading passenger (sleeper) car (Car A) was further examined at the Auburn UGL facility. Inspections did not identify any passenger car structures that generated injuries by their design.
Evacuation routes from passenger cars
The majority (14) of the 18 exits in the passenger cars were available for use. Four exits were deemed unavailable, either due to obstruction, jamming or excessive height off the ground.[107] Of the 14 usable exits, 6 exits were considered freely available and 8 were operable but with some hindrance to their free use due to the distance from the ground, the angle of the access ladder, or some other hazard.
Most people were able to evacuate with limited assistance although sometimes with difficulty due to the distance to the ground or the angle of the car. Some passengers with special needs were assisted out of the carriages.
Passenger information
Passenger survey
Overview
The ATSB conducted a survey of passengers who were on board train ST23 at the time of the derailment. From 155 passengers reported to be on board, 83 responses to the survey were received: a response rate of 54%. The survey included questions on:
passenger demographics
passenger seating location
safety information and briefings
experiences during and after the event
the nature of injuries.
Safety information
On questions pertaining to safety information:
Most (70%) of the passengers who responded to the question about the provision of safety information reported that they either did not receive any safety information or could not recall receiving any.
Of the 63 responses about the format of the safety information provided, 8 passengers (13%) reported that they received the information from a briefing card.
Of the 74 responses to a question related to paying attention to the safety information provided, 57% reported that they did not pay attention.
Most (70%) of the survey respondents reported that, prior to the derailment, they did not know how to get out of the train in an emergency.
In response to questions on suggestions for improvement in safety information:
Ten passengers referred to the way in which safety information is provided by airlines.
Some passengers mentioned that better signage on the seat in front of them or at the end of carriages may have been helpful.
Other comments included increasing the number of announcements.
The evacuation
There were varied responses from passengers about the communication received from crew members following the derailment. This was at least in part due to the distribution of the crew, with 4 of the 5 crew members being in the buffet car at the time of the derailment and no crew members present in Car A, Car D or Car G. Most of the passengers who responded advised that initial crew instructions were to remain on board the train. Others reported being unsure about what to do. There was no report of any announcements being made via the public address system or the use of megaphones.
Passengers were asked to estimate how long it took to exit the train. The responses ranged from a ‘few minutes’ to up to 30 minutes, supporting other evidence that some passengers self‑evacuated prior to being instructed to do so by the passenger services crew. About half of the respondents indicated having difficulty exiting the train due to carriage orientation and/or difficulty with getting down to the ground. Once passengers were out of the train, crew members were observed instructing passengers to move off the adjacent tracks (due to concern of possible rail traffic).
Sixteen respondents utilised the free text question to provide praise for the handling of the emergency event by members of the train crew and first responders.
Emergency preparedness
Passenger safety information
Verbal safety briefing
The train operator’s procedures provided details of the verbal safety briefing to be conducted by the passenger services crew (Appendix N). Key messages included, but were not limited to:
to remain seated and wait for instruction from the crew
to leave luggage if instructed to evacuate
to refer to the safety card for further information.
Evidence suggested that it was probably the normal practice for crew supervisors to develop their own announcement script rather than using a pre-prepared script developed by NSW Trains.
Operator procedures specified the conduct of announcements at the departure point in Sydney and at selected stations en route to Melbourne, including at Albury. The replacement passenger services crew boarded at Albury and an announcement was made to passengers using the public address system. However, the announcement did not include the full safety briefing. Evidence suggests that some crew members were not familiar with the requirement to provide a safety briefing at Albury.
Written briefing information
Written information about what passengers should do in an emergency was contained in an ‘on‑board guide’ located in the back pocket of passenger seats. This guide was a 10-page booklet that contained general information about the train service and destinations, food and beverage menu items, and emergency procedures.
The messaging on emergency procedures contained in this guide (Appendix N) was consistent with the operator’s procedures for verbal briefings. The instructions on what to do in an emergency included guidance to:
remain seated until instructed by the crew or emergency services
leave luggage behind
be aware of hazards outside the train.
The instructions were in written form only and did not include diagrams or pictorials to supplement the text.
It was reported by passenger services crew members that on some trips there would be a large proportion of onboard guides missing from the back of passenger seats. Although there were a significant number of onboard guides present on ST23 on the day of the derailment, not all seats were provided with a copy. The passenger survey indicated that only a small number of passengers obtained safety information from this guide.
On-board safety signage
There was no onboard safety signage identified on ST23 that provided guidance to passengers on actions for them to take in the case of emergency.
Emergency response procedures
Emergency response plan
The train operator had an emergency response plan that was supported by operational procedures. The emergency response plan was summarised in the Countrylink Incident Response Summary (Appendix O). This summary was contained in onboard logbooks, and displayed on the bulkhead at crew stations (Figure 22).
Figure 22: Onboard incident response summary at a crew station
Source: NSW Trains, annotated by the ATSB
The response summary contained a 9-step action plan to be followed by the train crew in the case of a major incident or emergency. This action plan was supplemented by specified additional actions for 15 types of incidents, including derailment. The incident response summary also included guidance on communication protocol, deciding to evacuate, and evacuation procedures. A range of warnings were described, including to ‘evacuate to tracks only after receiving positive confirmation from Network Control Officer that train movements have been stopped …’.
Crew members were also provided with an ‘emergency pocket guide’ that included shortened advice on quickly assessing risk, and communicating with emergency services, the NCO and management.
There was no ready-use guidance available to crew members about what or how they should communicate with passengers in the period prior to the decision being made to evacuate. There were no documented standard phrases or positive commands to instruct passengers to remain seated or on board the train.
Procedures for an evacuation when not at a station
In circumstances where the train was not at a station and the crew had determined the situation to be life-threatening, they were required to conduct a risk assessment to determine the safest course of action. If an evacuation was required, the driver was responsible for securing the train, notifying the NCO and ensuring that all adjacent traffic had been stopped. The driver or PSS was then required to protect the train, determine an evacuation plan (including which doors to use), inform passengers and manage the evacuation.
Use of the public address system
The public address (PA) system was serviceable throughout the train journey prior to the derailment. Following the derailment, it was not utilised by the passenger services crew to communicate to passengers. It was not determined if its serviceability was affected by the derailment. There was also no specific procedure that advised the crew what to do if the PA system was unsuitable for use in an emergency.
Megaphones were available for use on board the train. There was no specific procedure describing when they should be used, and they were not used in this instance.
Passenger services crew training
ST23 crew training and assessment records
NSW Trains provided details of crew training courses that included content related to emergency evacuation (Table 4).
Table 4: Training courses covering derailment and evacuation
Course name
Frequency
Safeworking (PSS only)
Annually
CPR
Annually
Competency assurance check ride
Annually
WF25 Emergency ladder and evacuation
Every 2 years
IC01 Emergency and evacuation
Every 2 years
NCA01 NSW Operational staff competence assurance: Emergency and evacuation
Every 2 years
WX63R0109 Incident response plan
Every 2 years
First Aid
Every 3 years
The individual learning profiles of the passenger services crew on ST23 were compared with the courses required for passenger services crew. The review identified that not all the crew members had completed the required courses, several courses had not been completed at the frequency specified, and none of the passenger services crew members were recorded as having completed the listed course WX63R0109 (Incident response plan).
The facilitator guide for the incident response plan course was reviewed. Except for a specified instruction to use when initiating a passenger evacuation, the course material did not include other standard phrases or commands that the passenger services crew should use in an emergency, such as an instruction to remain on the train following a derailment. In addition, the training courses reviewed did not provide passenger services crew with the opportunity to practice using the PA or megaphone to make announcements, or use standard phrases or commands in an emergency context.
Assessment records were obtained for the passenger services crew members on ST23 and these included the written assessments for their most recent ‘NCA01 NSW Trainlink Operational Staff Competence Assurance: Emergency and Evacuation’ course. Review of these records found inconsistencies and, in some cases, an absence of the use of the marking scale. In several cases there was also an absence of assessor sign-off.
Training needs analysis
NSW Trains provided a report of a training needs analysis completed in April 2019.[108] This review included a detailed task analysis of passenger services crew roles, and the approach to training and assessment of required competencies. It identified that evacuation-related competencies should be trained and assessed practically, with a frequency of every 6–12 months. The report also included driver incapacitation scenarios and the use of high-fidelity mock-ups. The outcomes of this project had not been implemented at the time of the Wallan derailment.
Other information related to training and competency management
Research conducted by the NSW Independent Transport Safety and Reliability Regulator (ITSRR)[109] highlighted, among other things, that accident reports had a reoccurring theme in the deficiency of emergency procedures training provided to train crew (ITSRR 2004).
Published in July 2021 (post the Wallan derailment), the Office of the National Rail Safety Regulator (ONRSR) provided guidance about the management of rail safety worker competencies, which included a rail safety worker competency assessment fact sheet (ONRSR 2021) and various examples (including a competency register) of how organisations could record the competency requirements and expiries of train crew.
Review of regulator activities
Scope
ONRSR was the national rail regulator. A review was undertaken of potentially relevant regulatory activities in the 5 years preceding the Wallan occurrence.[110] Activities examined included reported overspeed occurrences, notified changes to safeworking arrangements, and relevant audit and inspection activity.
Notified occurrences associated with train overspeed from 2015
ONRSR was requested to provide notified overspeed occurrences on the ARTC network in Victoria in the 5 years prior to the Wallan occurrence.[111] Eleven overspeed occurrences were identified in the supplied data, including the following 5 that involved passenger trains:
6/1/2015 – an XPT passenger train went through a 40 km/h temporary speed restriction between Somerton and Donnybrook at 130 km/h.
11/7/2015 – a V/Line passenger train transited the turnout into Wallan Loop at over 90 km/h compared to the required 15 km/h. This overspeed occurrence was investigated by the ATSB.
29/12/2015 – a V/Line passenger train went through a 40 km/h temporary speed restriction at Euroa at 72 km/h.
13/3/2018 – an XPT reported travelling through a 40 km/h temporary speed restriction at Violet Town at excessive speed.
6/8/2018 – a V/Line passenger train went through a 40 km/h temporary speed restriction between Seymour and Benalla at the line speed of 130 km/h.
Notifications of change to network rules from 2015
ONRSR advised that 5 notifications of change to the Code of Practice for the Victorian Main Line Operations (TA20) were submitted by ARTC in the 5 years preceding the Wallan occurrence. None of these notifications of change related to the processes used at Wallan on 20 February 2020.
Audits and inspections from 2015
Topics not audited
ONRSR used a risk-based approach in its decisions and plans for regulatory activity. As a result, regulatory activity was targeted and operators and topics received different priority. For the ARTC network in Victoria in the 5 years before the Wallan occurrence, ONRSR advised that it did not conduct audits or inspections of ARTC on the following topics:
caution orders or train authorities
the use of AQWs or safeworking pilots
the risk of train derailment due to overspeed[112]
the overspeed of a V/Line passenger train at Wallan Loop (Victoria) on 11 July 2015.
ARTC risk management
ONRSR was requested to provide audit and inspection reports that included the topics of ARTC risk management systems and/or risk assessment processes associated with safeworking. ONRSR identified 4 audits and 6 compliance inspections conducted across 2017 and 2018 that included either or both of the requested risk topics.
Reports from these regulatory activities referenced concerns with the currency of the centralised risk register and ARTC’s introduction of a new Enterprise Risk Management System (ERMS). Of note, an audit in November 2018 made several observations, including that ARTC should consider the risk of passenger and freight train derailment separately in view of the different potential consequences and required controls.
NSW Trains systems for accessing and distributing safety critical information
ONRSR was requested to provide audit and inspection reports that included the topics of NSW Trains’ systems for accessing safety-critical information (such as train notices) from ARTC for operations on the Victorian network, and NSW Trains’ systems for disseminating such information. In response, ONRSR identified a total of 5 audit and 5 inspection activities between 2015 and 2018 that referred to either or both of these topics.
Consistent through these activity reports was reference to the issue of a Train Crew Weekly Information Pack (WIP) as the primary vehicle for distributing safety-critical information including train notices. There was no commentary or findings identified in the review that discussed the collection and immediate distribution of notices accessed from the ARTC WebRAMS portal.
Other occurrences at Wallan Loop investigated by the ATSB
V/Line high speed entry into Wallan Loop in 2015
In July 2015, a Melbourne to Albury V/Line service entered the southern turnout to Wallan Loop travelling at more than 90 km/h (compared to the required 15 km/h). The train remained on track, however some passengers required medical attention from the onboard service crew due to the rough ride as the train transited the turnout.
This occurrence was investigated by the ATSB (2017). It was found that signalling at the location was operating as designed and there were no signal sighting issues, but that the driver did not demonstrate effective awareness and train handling techniques. The report also made findings related to post-occurrence processes and actions.
As part of the investigation into the derailment of train ST23, further enquires were made into safety actions taken by ARTC and V/Line following the 2015 occurrence, and specifically consideration of train enforcement solutions at Wallan Loop (to automatically enforce train braking if a train was detected as being overspeed).
ARTC advised that consideration of train enforcement solutions at Wallan Loop was a matter for V/Line. Also, ARTC did not introduce any additional risk controls at Wallan Loop in response to the V/Line train overspeed occurrence.
V/Line advised that, following the 2015 occurrence, the potential application of the train protection and warning system (TPWS) on the ARTC Northeast standard gauge line was evaluated.[113] It was concluded by V/Line that (based on safety risk to its operations) there was a case to install TPWS at several locations on the ARTC North-east standard-gauge line (including at Wallan Loop) to protect against a V/Line passenger train overspeed or the passing of a signal at danger. TPWS was used for V/Line trains on the Victorian broad gauge networks and V/Line passenger rolling stock was fitted with compatible equipment.
The project to integrate TPWS (for V/Line trains) on the ARTC network was being funded by the Victorian Government and ARTC confirmed in its response to ATSB that it had been involved in discussions with V/Line and was committed to supporting the implementation of TPWS. TPWS was scheduled to be fitted at Wallan Loop in 2024.
TPWS would not be compatible with the XPT (and its NSW Trains replacement) or freight traffic.
Derailment of freight train at Wallan Loop November 2017
On 4 November 2017, freight train 7MC1 was signalled into the southern entry to the crossing loop at Wallan. Entering the loop, the leading bogie on the 37th wagon derailed.
The occurrence was investigated (ATSB 2019). It was found that the derailment occurred within a rapid transition of track superelevation from the main line to the loop track, resulting in wheel unloading. Following the derailment, ARTC completed rectification works and enhanced its work management processes for the response to geometry conditions. There was no aspect of this occurrence found to be relevant to the derailment of train ST23.
Safety analysis
Introduction
The derailment of the interstate passenger rail service (train ST23) between Sydney and Melbourne resulted in the death of the train’s driver and the accompanying rail worker, and serious injuries to 8 passengers. There was potential for further passenger injury that was probably mitigated by a row of trees limiting the rollover of the leading passenger car.
The report analysis first considers the physical scenario that resulted in the derailment of train ST23 and describes those factors unlikely to have influenced the occurrence.
Potential scenarios that may have led to the train travelling at near the track speed of 130 km/h as it approached the turnout to Wallan Loop are then considered. Evidence supporting the most likely scenario, that the driver of train ST23 was probably unaware of the routing of ST23 through Wallan Loop, is discussed. Other scenarios considered less likely are also presented. The mechanisms for informing the driver of the changed conditions at Wallan Loop and missed opportunities are then introduced.
The analysis further examines the underlying factors that either directly influenced this occurrence or increased the safety risk associated with train operations. The analysis discusses the train working system, risk assessment processes, risk controls, and the distribution of safety critical information. Comment is also made on the risk management of passenger trains on the ARTC rail network.
The remainder of the analysis considers factors associated with events following the derailment, including power car survivability following overturn and the preparedness of passengers and passenger services crew for a major emergency occurrence such as train derailment.
The derailment
At Wallan Loop, the track was configured with low speed turnouts to No.2 track from No.1 track that had a permitted speed of 130 km/h for passenger trains. The significant speed differential at this location created the risk of derailment due to overspeed that was controlled through driver compliance with the signalling system. When the signalling system became non-operational in February 2020, the risk of derailment at the turnouts due to train overspeed was (initially) effectively eliminated by locking the points to their normal position and removing the option to transit through No.2 track. The hazard at the turnouts and the risk of derailment were then re‑established on 20 February when the points were locked in their reverse position to route trains via No.2 track with (only) the implementation of administrative control that relied on ‘paper-based’ information exchange.
The investigation found that train ST23 entered the turnout to Wallan Loop travelling at between 114 and 127 km/h. The turnout was rated by ARTC for a train entry speed of 25 km/h and the maximum permitted operational speed was 15 km/h. In the absence of indications of infrastructure or rolling stock defects, it was concluded that ST23 derailed as a result of its speed significantly exceeding the speed rating of the infrastructure.
Recorded data indicated that ST23 was approaching Wallan Loop at 129 km/h[114] when there was a rise in brake cylinder pressure as a result of an emergency brake application. Assuming a nominal 2 seconds between the cues of the unexpected situation and braking system response,[115] the cues(s) that resulted in the brake application may have arisen when ST23 was between 120 and 220 m from the turnout (Appendix K).[116] Possible reasons for the driver realising the need to brake included recall of the points setting by the accompanying qualified worker (AQW) or the driver, or direct observation of the setting of the points at the turnout to the loop.[117] Given the AQW had no driving experience, the emergency brake application was almost certainly the action of the driver.
Site inspection indicated that the vehicles of the train derailed within the Wallan Loop turnout and No.2 track, and there was no indication of derailment prior to the turnout. Given the leading power car overturned onto its left side, the rolling over of the power car was more likely to have occurred (or commenced) within the right curve transitioning onto the tangent (straight) section of No.2 track. Damage to the exterior of the power car also suggested it had slid on its left side for a significant distance.
Factors unlikely to have influenced the occurrence
Driver incapacitation
There was no evidence identified to suggest that the driver was incapacitated leading up to the derailment, and there was evidence to support the proposition that the driver and AQW were functioning normally. The AQW was in contact with the level crossing keeper (LCK) less than 2 minutes prior to the derailment, had sounded normal in that conversation and did not raise any concerns regarding the condition of the driver. An earlier brake application for a 115 km/h track section, and a power application made shortly after the conversation between the AQW and LCK, also support the proposition that the driver was actively in control of the train.
The derailment occurred about 6.5 hours after the driver started their shift, a little under 5 hours after they commenced driving ST23, and about an hour after the driver’s scheduled end-of-shift. Although the driver may have been tiring towards the end of the train journey, there was no evidence, including in radio communications, that suggested that driver fatigue was a factor. A review of the driver’s roster and recent history found that there was insufficient evidence to conclude that the driver was experiencing a level of fatigue that would significantly affect performance.
There was no pre-existing health condition of the driver that was likely to have contributed to the accident and toxicology results did not identify any substance that may have impaired their performance.
Rolling stock condition
Inspections, testing and a review of maintenance records did not identify any adverse rolling stock condition or defect that was likely to have contributed to the derailment.
Track condition
There was no evidence identified to suggest that the condition of the track or turnout at the northern entry to Wallan Loop was a factor in the derailment, noting also that the speed of ST23 significantly exceeded the ARTC speed rating for the turnout. The facing points were found to be locked and in position for the train movement into No.2 track.
Factors leading to train overspeed
Discussion on potential scenarios
Scope
Having excluded the likelihood of driver incapacitation or defective train braking, this section discusses the evidence for, and likelihood of, the following scenarios that could have led to the overspeed of ST23 at the Wallan Loop turnout:
The driver of ST23 was not aware of the routing of ST23 via Wallan Loop and expected to travel on the straight track through Wallan.
The driver was aware of the routing of ST23 via Wallan Loop and forgot this information during the journey between Kilmore East and Wallan.
The driver lost awareness of their location in the section between Kilmore East and Wallan.
Approaching Wallan Loop, the driver misinterpreted an adjacent broad gauge signal (that was probably at proceed) as applying to the standard gauge track.
Driver awareness of changed conditions and expectancy
Prior to the derailment, there were a number of radio conversations between the NCO and the driver and there was no instance where the driver of ST23 expressed an understanding that conditions at Wallan Loop were different to what they had been during the previous 12 days, and that ST23 was being routed onto No.2 track on that day. In a radio conversation between the driver and the NCO about an hour before the derailment, the NCO mentioned that ‘you’re going via the loop there at Wallan’. There was no acknowledgement of the routing via the loop by the driver.
In another interaction with the NCO about 11 minutes before the derailment, when at Kilmore East receiving the train authority, the driver commented that they were in possession of the train authority and CAN and stated that they were ‘filled out ahh the same way it has been for the … rest of the time’. This latter interaction suggests that the driver may have believed that the track conditions were the same as they had been and that ST23 would proceed through Wallan in the same way as the driver had experienced in the preceding trips through the location, including on the day before.
Also while ST23 was stopped at Kilmore East for the driver to receive the train authority, the NCO mentioned ‘points all set for the loop’. The driver did not respond directly to this comment and there are a number of ways it could have been interpreted.
Expectations based on past experience strongly influence where a person will search for information and what they will search for (Wickens et al. 2023), and they also influence the perception of information (Wickens et al. 2022). In simple terms, people are more likely to see and hear what they expect to see and hear, and less likely to see and hear what they do not expect to see and hear. After the commencement of the alternative method of train working, the driver of ST23 ran the Junee–Melbourne–Junee round trip 4 times (8 times through the location) between 8 and 19 February. For all previous trips, the points at each end of Wallan Loop had been locked in the straight position, and trains could proceed through this location at normal track speed (130 km/h for the XPT). This experience likely developed an expectancy in the driver that strongly influenced their mental model on the day of the derailment.
Limitations of prospective memory
Another scenario is that the driver correctly assimilated the information from the train authority, the NCO’s mention of the transit through the loop and/or verbal information potentially provided by the AQW, but forgot about the changed conditions at the loop during the short journey between Kilmore East and Wallan Loop.
Remembering information about the use of the loop and associated speed restriction and applying it later would require prospective memory (Loukopoulos et al. 2009). Prospective memory refers to an intention to perform an action at a later time, and a delay between forming the intention and acting on it. It is known to be vulnerable to failure and has been associated with many incidents in aviation and other work domains (Dismukes 2012). Prospective memory errors have also been associated with previous incidents of overspeeding trains due to drivers forgetting a temporary speed restriction (Sato et al. 2020).[118]
Conditions that increase this vulnerability include the delay between the intention to do a task and the execution of the task being filled with other activities, an interruption to a task sequence, and the cues or prompts to retrieve the intention from memory not being explicit (Dismukes 2012). In the case of train ST23, the driver did not have any strong cues or prompts (such as signage or in‑cab alarms) for recalling the speed requirement. Conversely, there would probably not have been excessive task demands on the driver and, as far as is known, there were no distractions or interruptions to their normal driving activities. The interactions between the driver and the AQW during this period and any possible distractions could not be determined.
It is feasible that when ST23 approached the turnout loop, the driver recognised they were now approaching Wallan and remembered that they were being routed through Wallan Loop and made the emergency brake application. However, there was no evidence available to determine whether that scenario may have occurred or instead the driver reacted to being prompted by the AQW or observing the position of the points at the turnout.
Other possible scenarios
It is also possible that after departing Kilmore East, the driver lost awareness of their location within the 15 km section to Wallan, and only made a brake application after realising their proximity to Wallan Loop. Given the driver was familiar with the route and had travelled on this track several times in the preceding 12 days,[119] there was no compelling case to suggest a loss of positional awareness.
It was also considered whether the driver may have been confused by the broad gauge signal, which was probably at proceed. Given the experience of the driver, their familiarity with the route and their recent and repeated transits through the location with the standard-gauge signalling system not operating, there was also no compelling case to suggest that the driver had misread the broad-gauge signal as applying to the standard gauge track.
Summary
Having discounted several other possibilities, the remaining most likely scenarios were that the driver was either unaware of the routing through the No.2 track at Wallan, or the driver was aware of the routing but forgot (prospective memory failure). The recorded driving actions of applying power after receiving confirmation that the level crossing protection at Wallan had been activated and then making a late emergency brake application approaching the loop turnout were both consistent with, and plausible driver actions in the case of, either scenario.
There was, however, no direct evidence to support the proposition that a failure of prospective memory was a factor in this instance. No radio interactions between the driver and NCO suggested recognition by the driver of the routing through the loop, or the differences (compared to previous days) in the train authority that had been issued on that day. It was therefore concluded that there was insufficient evidence of a failure in the driver’s prospective memory.
Considering the radio communications between the driver and the NCO, and in the context of an expectation developed by this driver during 8 trips through the location in the 12 days after the signalling system was disrupted, it was concluded that it was more likely that the driver of ST23 was not aware that ST23 was being routed through Wallan Loop on that evening. Supporting the potential for such a scenario, there were several weaknesses in the delivery of information to the driver to overcome their expectancy, and several missed opportunities to confirm the driver’s understanding of the changed conditions.
Information available to driver and missed opportunities
Scope
This section discusses the information that was available (and not available) to the driver and introduces the missed opportunities for confirming driver awareness. These themes are developed further when discussing risk management and risk controls later in the analysis.
The information that is discussed and the implications for the driver include:
train notice 266 and its reinforcement of the expectation that the loop was not being used
train notice 367 and its absence as pre-information for the driver
train authority 17 and weaknesses in the delivery processes for assuring driver understanding
communications between the NCO and driver as a missed opportunity
communications between the AQW and driver as a missed opportunity
rail resource management as a missed opportunity
cues in the real-world environment as a missed opportunity.
Train notice 266
Prior to the day of the derailment, the driver of train ST23 had driven through the location several times operating under the altered train working arrangements and the instructions of train notice 266 (TN 266). On 8 February, the driver had also repeated back the associated train authority for this method of working prior to their first transit under these conditions. The driver was therefore very likely familiar with the conditions specified in TN 266, and specifically the condition that the points at either end of Wallan Loop were locked in their normal position for transit on No.1 track. TN 266 did not contain any information suggesting the possible operation of trains through Wallan Loop (No.2 track). This meant that TN 266 had worked to establish a strong expectation (in the driver) that the points would be set to their normal position (for the straight).
Train notice 367
TN 367 was a potential source of pre-information about the change in conditions at Wallan Loop, however, the driver did not have a copy of TN 367 with them on ST23 and was probably unaware of this notice. This removed the opportunity for the driver to familiarise themselves with the changed conditions.
Train authority 17
The driver of ST23 received a copy of train authority 17 (TA 17) while stopped at signal KME16, about 12 minutes before the derailment. TA 17 detailed the changed conditions at Wallan Loop, including the requirement to slow to 15 km/h. However, this added text was towards the end of TA 17 and was not marked or highlighted in any way to indicate it was different to the previous train authorities that had been issued for the same section of track in recent weeks. In addition, the body text of the train authority was in upper case, which can be more difficult to read or scan than lowercase text (Wickens et al. 2022). It is therefore very plausible that the driver did not pick up the change from previous train authorities. The radio communication by the driver that the documentation was ‘…filled out … the same way it has been...’ suggests this was probably the case.
Consistent with the practice that was used during the 2 weeks of the altered train working arrangements, TA 17 was given to the driver by the AQW. It was the practice for signallers to deliver the train authority to the driver via an AQW, although this was inconsistent with the description in TN 266 that specified that the signaller was to deliver the train authority to the driver. Delivery of TA 17 directly to the driver of ST23 would have provided an opportunity for the driver to receive direct verbal advice of the changed conditions from the signaller during the transfer of the authority document.
The driver was also not required to (and did not) read back the contents of TA 17 to the NCO or the signaller, and almost certainly did not read back TA 17 to the AQW. Readback/hearback refers to the process of issuing and confirming track authorisation (Gertner and Acton 2003). Verbal rehearsal can result in the encoding of information in short-term memory (Greene 1987). Readback of safety-critical information is adopted by industries to ensure information is correctly understood by the sender and the (actioning) receiver, in this case the NCO and the driver of ST23 respectively. An industry guideline on safety critical communications (RISSB 2018) stated that to ‘ensure the message has been understood, require the recipient to repeat back the message if not already done by them’. In their similar manual, the Rail Safety Standards Board (RSSB 2017) in the United Kingdom outlined that:
To confirm that all parties have the same understanding of the communication, the person with lead responsibility must ask for a ‘repeat back’. This is a crucial step in making sure the arrangements have been fully understood by both parties. It provides the opportunity to identify any misinformation, misunderstandings, or omissions.
The person with lead responsibility should use the phrase ‘repeat back’ to confirm the understanding of both parties. It can also be used by others who don’t have the lead responsibility to confirm their understanding. It can be used to confirm details relating to who we’re talking to, what the situation is, or what actions are being given.
Had the driver of ST23 read back the full content of TA 17 to the NCO, it is probable that they would have realised the changed conditions at Wallan Loop, complied with the speed instruction and this occurrence would probably not have occurred.
NCO – driver communications
In addition to the driver’s acknowledgement of the receipt of train authority 17, there were other conversations between the NCO and driver that were missed opportunities for the NCO to confirm the driver’s understanding of the change in conditions at Wallan Loop. The NCO and driver had conversations that skirted the topic of the routing of ST23 through Wallan Loop, without achieving confirmation of driver understanding. Although these opportunities existed, there was no procedural requirement for the NCO to seek confirmation of the driver’s understanding. In addition, the NCO’s belief that there was a pilot on board probably provided some reassurance with the arrangements.
AQW – driver communications
Tasks of the AQW included delivering the train authority and CAN notice to the driver and organising the activation of level crossing protection at Wallan–Whittlesea Road. These tasks were completed by the AQW on train ST23.
For this day, TN 367 added the instruction for the AQW to remind the driver that the train would operate via No.2 track at Wallan Loop, although the notice did not include any procedural requirement on how this activity was to be conducted by the AQW or how driver understanding was to be ensured (such as by readback). The AQW was briefed on this requirement and would also have expected that the driver was likewise aware of TN 367. There was probably sufficient time from when the AQW boarded ST23 to its departure from KME16 for this exchange of information to occur.
In the absence of voice recordings from the driver’s cab, the details of conversations between the driver and the AQW are unknown. There are many plausible scenarios in which conversations may have occurred but may have been misinterpreted by either party.
The presence of an authority gradient can influence the effectiveness of personal interactions. An authority gradient refers to the perceived difference in status between different members of an organisation (RISSB 2018). Its presence can influence the effectiveness of the delivery and receipt of information between safety-critical personnel. There was insufficient evidence available to examine whether this may or may not have been a factor in this instance.
Rail resource management
Rail resource management (RRM) is the application of non-technical skills of rail safety workers, which includes team communication and co-ordination, planning and contingency management, critical decision-making, situational awareness, and workload management (Klampfer and others 2012). These skills enable operational staff such as drivers, guards, NCOs, signallers and rail workers to effectively manage hazards and errors in the workplace. In this instance, there were missed opportunities for application of RRM principles between the NCO and the driver to assure driver awareness of transit through Wallan Loop. There was insufficient evidence to conclude the nature of the probably missed opportunities to apply RRM principles between the AQW and driver.
Visual and audible cues for the driver
The driver was not provided with visual cues (such as signage or conspicuous warning devices)[120] or audible cues (such as in-cab alarms) to warn of the need to slow to 15 km/h when approaching Wallan Loop. These were significant absent risk mitigants and missed opportunities for cues in the real-world environment to address limitations in transmitting information by administrative systems and mitigate against a failure of prospective memory and expectation bias.
Deviation from established network rules
A safety management system (SMS) is a ‘formalised framework for integrating safety into the daily operations of an organisation and includes the necessary organisational structures, accountabilities, policies and procedures’ (Fox 2009). The Rail Safety National Law described an SMS as providing a ‘comprehensive and systematic assessment of any identified risks’.[121]
The ARTC SMS was listed several times as a risk control for derailment within the ARTC enterprise risk management system (ERMS). The Code of Practice for the Victorian Main Line Operations (TA20) formed part of the ARTC SMS and described the operating rules for the Victorian section of the North-east standard gauge rail corridor.
The use of train authorities in the circumstances that were present through Wallan in February 2020 was not provided for in TA20, and uncoupling from the established procedure and rules was observed. The use of train authorities became sanctioned through train notices and further ‘gained legitimacy through unremarkable repetition’ (Snook 1996). The final ‘drift into danger’ (Rasmussen 1997) was the application of the administrative arrangements to transit through a section that included a low-speed turnout. The effectiveness of the paper-based train authority as a risk control then relied on non-formalised person-to-person interactions.
The effective management of safety during unpredicted situations requires risk management processes that can comprehensively identify and assess risks, effective implementation of those processes, and organisational systems that ensure safety is not compromised at the expense of operations.
Weaknesses in risk management and stakeholder engagement were evident in both the initial establishment of the train working arrangements on 6 February, and then to operate trains through Wallan Loop on 20 February. Each of these phases, including the implemented risk controls is discussed separately in the following 2 sections of the analysis.
Train authority working arrangements established on 6 February
Risk workshop and risk management plan
For the proposed implementation of ‘train authority working’ between Donnybrook and Kilmore East, there was a brief risk assessment workshop involving ARTC and ActivateRail on the afternoon of 6 February, shortly before implementation of the train working solution. The timing of the workshop, the absence of key stakeholders (rail operators) from the process and the preconceived suitability of a previously used arrangement reduced the likelihood of the workshop identifying all risks associated with the proposed rail operations and the controls to appropriately manage those risks.
The risk management plan was finalised on 7 February, the day after release of TN 266 and the commencement of the train working arrangements. The plan had significant weaknesses, including:
The context setting described in the risk management plan was from a previous assessment that had limited relevance to the risk profile associated with the train operations between Donnybrook and Kilmore East. The context should have reflected the specific environment of the activity to which the risk management process was to be applied (Standards Australia 2018). In addition, ARTC’s risk management procedure specified that ‘Establishment of operational context is a requirement of the risk assessment process. A consultative approach with stakeholders must be used to determine the context’. Deficiencies in stakeholder consultation diminished the likelihood of the context being correctly defined.
The scope documented in the risk management plan was specific to the rail operations and safeworking activities for (signal) commissioning, referring to previous commissioning activity. This scope was not fully reflective of the extended period of passenger and freight operations between Donnybrook and Kilmore East. This scope definition limited the scope of hazard scenarios and risks being considered.
The effectiveness of controls at addressing identified risks was not recorded in the risk management plan. The ARTC work instruction for the application of risk management stated that it was essential to ‘determine whether the control (or combination of controls) adequately reduces the risk level’ and ‘identify whether additional control(s) are required’.
Individual risk control owners were not identified in the risk management plan, either by name or position. ARTC’s work instruction for the application of risk management stated that control owners were responsible for taking remedial action to address identified deficiencies of controls.
Controls were identified within the risk management plan but not implemented. Specifically, pilotage was identified as a control but was replaced by an AQW in practice.
Treatments considered but rejected were not documented. ARTC’s procedures stated that ‘It is essential that rejected proposed treatments and information regarding the decision to reject the proposed treatment is recorded against the risk…’.
It was concluded that ARTC risk management and oversight processes resulted in a risk management plan that was limited in context, scope and risk identification and, as a consequence, risk controls had significant weaknesses. The non-integrated and manual aspects of the process design introduced potential points of failure.
Risk controls for train working arrangements
Scope
The risk management plan set out a range of risk controls for 10 risk items that had been identified. The following risk controls used in train working arrangements from 6 February and that were most relevant to this occurrence are discussed in this section:
the issuing of train notices
the issuing of a train authority for each train movement
a rail worker to accompany each train movement.
Train notices
The risk management plan listed ‘train notices detail the commissioning activities’ as an administrative control for network controller officers (NCOs) not being aware of the proposed changes. The train notice being issued in a timely fashion was also listed as an administrative control for rail operators not being aware of the train working arrangements.
A train notice can provide early advice on changed network conditions although notices were acknowledged by ARTC as a ‘minimally effective’ risk control.[122] Weaknesses included potential points of failure in document distribution and receipt (that are discussed later in the analysis).
In addition, the effectiveness of train notices can be influenced by their form, content and complexity. TN 266 was a detailed 6-page document describing processes that deviated from established and accepted practices and was amended and reissued twice. As a result, interpretation of this detail and commitment to memory was likely varied across the driver community.
The risk management plan specified issuing train notices in a ‘timely fashion’. Although TN 266 and its revisions were issued prior to their application, there was limited time made available for operators to distribute the notice to key personnel, including safety and risk management staff and drivers. This in turn limited the opportunity for full consideration of the notice detail, internal consultation, driver briefing and implementation of additional risk controls by rail operators.
The veracity of TN 266 was also undermined by its inconsistency with the in-field processes that were implemented by ARTC and ActivateRail, and a lack of clarity in some areas. Examples included:
TN 266 specified that the signaller was to deliver the train authority to the driver whereas the practice was to deliver the train authority to the driver via the AQW.
TN 266 described that the driver must sign for the train authority on the butt of the form. However, there was no provision on the train authority for the driver to sign off.
TN 266 (original issue) specified that the driver must verify the train authority with the NCO. This requirement was not clear and could reasonably be interpreted as verification of the content of the authority by readback, as was undertaken by a number of drivers. The revised TN 266 (amended 13 February) specified that readback was not required.
TN 266 (amended 13 February) added the explicit requirement that the driver must approach the level crossing with caution, and be prepared to stop short of the crossing unless the ‘all clear’ hand signal has been provided. The application of the ‘prepared to stop’ clause (in practice) probably varied among drivers, and would have required a significant slowing of trains ahead of the crossing. Verbal (mobile phone) confirmation by the LCK (to the AQW) was probably often used to confirm that the crossing protection was activated and the train was clear to pass.
Review of train authority records also identified that on several occasions a train authority for the single line section between Donnybrook and Kilmore East NCO was issued prior to the previous train authority being cancelled, and so contrary to the requirements of TN 266.
It was concluded that the effectiveness of the issued train notice TN 266 and its amendments was undermined by their form, their inexactness, the limited consultation with stakeholders, the method of distribution and their release only a short time before coming into effect.
The issuing of a train authority
The processes established under TN 266 was for the train authority to be issued to the signaller rather than to the driver and there was no protocol to confirm that the driver, the actioning ‘receiver’ of the train authority information, understood the contents of that authority. Network rules (TA20) described that the receiver must confirm the content of a message by repeating the message back exactly as it was received, and that the receiver must not act on the communication until the sender confirms that the message has been repeated correctly.[123] However, driver readback of the train authority was actively discouraged, both in the amended TN 266 (13 February) and by ARTC network control.
Readback of safety-critical information is adopted by industries to ensure information is correctly understood by the sender and the (actioning) receiver, in this case the NCO and the driver. The absence of a protocol that would confirm driver understanding of the train authority was inconsistent with industry practice, and a significant weakness in this risk control. This weakness was exposed following the change to the train authority for routing of trains through Wallan Loop on 20 February and the absence of driver readback of the train authority process established on 6 February was probably a contributing factor to this occurrence.
A significantly more reliable method of issuing a train authority was directly from the NCO to the driver. This process would have involved the driver completing their copy of the train authority from the narration of its content by the NCO, and then repeating back its contents to the NCO to confirm its accuracy. Both the completion of the train authority form by the driver and the repeat back process would increase the likelihood of driver understanding. This process would probably have taken 2–3 minutes in this instance.[124]
Although less reliable than the NCO directly issuing the train authority to the driver, there were other enhancements to the process used that would have improved its effectiveness, including a mandated readback of the authority by the driver to the NCO. The repeating back of the information from the driver to the NCO was a practicable control, evidenced by some drivers repeating back the train authority even though this was not a requirement of TN 266.
A second weakness in the train authority process was its indirect delivery to the driver. Even though TN 266 described the signaller issuing the train authority to the driver, the accepted practice was for the train authority to be passed from the signaller to the AQW, and then from the AQW to the driver after boarding the train. This was contrary to the principles of TA20 that described relaying of communications by a competent worker (only) if it was not possible for a sender to communicate directly with an intended receiver.[125] This indirect delivery removed the opportunity for direct dialogue and information exchange between the signaller and the driver.
Although a risk management plan was produced by ARTC for the application of train authorities, there was no human factors assessment that may have identified weaknesses in the control as it was being implemented. In particular, the potential for human error inherent in the indirect method of issuing the train authority to the driver and the absence of readback by the driver to confirm their understanding was not considered by ARTC.
Rail worker to accompany the driver
Two controls in the risk management plan advised of the intended presence of a pilot. The first was that ‘Trains are piloted through the section’, and the second was ‘Level crossing in place to operate test switch, pilot on train announces approach’. However, the risk control of a pilot was not implemented and instead an AQW was provided as the control.
Industry references, including ARTC procedures, described a pilot as having a role that included providing direction to train crews and having interactions with the NCO. The Australian industry standard for the competency of piloting rail traffic (released after this occurrence) required a pilot to have demonstrated detailed knowledge of the route and the operating conditions.[126] Pilotage would therefore be expected to be a broader risk control than an AQW, and there would be less potential for an authority gradient with the driver.
In contrast, AQWs had limited tasks and were not required to have knowledge in train operations, nor be assessed as having route knowledge and front-of-train experience on the section of track between Kilmore East and Donnybrook. The absence of clearly defined qualification, capability and knowledge requirements weakened this control.
Tasks of the AQW included delivery of the train authority and CAN notice to the driver and to call the LCK to activate the level crossing protection at Wallan–Whittlesea Road. Evidence suggests that all AQWs involved in these processes successfully performed these tasks.
Potential risk controls that were not used
For signalling failure within a centralised traffic control (CTC) section, TA20 included train working processes using caution orders and other safeworking processes.[127] These processes were used up to 6 February and could have been continued for the full period of repairs. However, the impact on the service schedule was substantial due to the 25 km/h speed limit, increasing transit times to an hour or more (Table 5).
Table 5: Transit times for different average speeds through the affected 24 km section
Average train speed
18 km/h
24 km/h
72 km/h
96 km/h
120 km/h
Transit time (min)
80
60
20
15
12
From 6 February, a potential additional risk control was to apply a temporary speed restriction (TSR) to the Kilmore East to Donnybrook section while rail traffic was operating under administrative controls and without signals. Although not formalised as an instruction, several V/Line drivers chose to run at a slower speed through the affected section. Limiting train speed was not a control in the risk management plan nor was the control referenced as being considered and rejected.
Stakeholder engagement for train working arrangements
Consultation with stakeholders was a key component of the Australian and international standard for risk management (Standards Australia 2018). However, there was limited engagement and consultation with rail operators for the establishment of the train working arrangements that deviated from the standing network rules. Risk worksheets were only released to V/Line and labour hire firm Programmed (the day after implementation) and were not distributed to NSW Trains and freight operators.
The timeframe for V/Line to respond to the arrangements and the exclusion of several rail operators from the process, including the XPT operator, was a significant weakness in engagement strategy and risk management. These factors limited the opportunity for network users to influence risk identification and controls to manage those risks, and the opportunity to consider additional (direct) risk controls that operators might implement for their operations.
ARTC engagement with rolling stock operators continued to be limited after commencement of the train working arrangements even though there was disquiet amongst some drivers. Operator queries and feedback on the train working arrangements, while resulting in some amendments to TN 266, did not trigger a deeper review by ARTC of the risks to train operations and the adequacy of the risk controls that were being implemented.
It was concluded that ARTC risk management and oversight processes did not result in effective stakeholder engagement to support risk management and the development of risk controls for train working arrangements that deviated from ARTC network rules (TA20). This increased the safety risk associated with the rail operations.
Contractor involvement in the establishment of the arrangements
ActivateRail was engaged by ARTC to develop and manage a safeworking solution for train working between and Donnybrook and Kilmore East. Industry contracting guidelines (RISSB 2017) discussed the primary safety duty as being with the accredited operator (ARTC in this case), while also acknowledging the shared responsibilities of contractors to achieve safety outcomes.
ActivateRail contributed to the development of train working arrangements that were inadequately supported by risk management processes. ActivateRail did not have systems that ensured that its contributions were consistent with the risk management procedures of the accredited rail infrastructure manager (ARTC) and Australian risk management standards.
Example of increased risk during temporary signal suspension
A 2018 collision in the USA provides an example of increased risk associated with rail operations during signal suspension and highlights the importance of stakeholder engagement and risk assessment to manage these risks.
In February 2018 in Cayce, South Carolina, a train collided head-on with another, resulting in the death of the driver and conductor of an Amtrak Train, and injury to 115 passengers. The accident was investigated by the National Transportation Safety Board (NTSB 2019), and the identified probable cause of this collision was the failure to assess and mitigate the risk associated with operating through a signal suspension. The management of risk during signal outages was a matter considered further by the Federal Railroad Administration (FRA) and a review of FRA incident data showed that operations during suspended signal system presented increased safety risks (DOT 2018).
Arrangements for transit through Wallan Loop on 20 February
Risk management and stakeholder engagement
For the routing of trains through No.2 track at Wallan Loop on 20 February, there was no documented risk assessment or review of risk controls, and there was no review or update of the risk management plan. ARTC risk management and oversight processes did not result in a risk assessment of the (new) introduced risk of derailment at the low-speed turnouts, and implementation of available and practical risk controls that would manage that risk.
There was also limited engagement with rail operators and limited opportunity for operators to contribute to a review of risk controls. During the afternoon of 19 February 2020, ARTC provided V/Line with a draft of the train notice for the changed condition at Wallan Loop, although no assessment of risks or listing of controls accompanied the notice. The draft was circulated within V/Line and an opinion expressed within V/Line that ‘at the very least, there should be track force protection’ due to the changed running from No.1 track to No.2 track. V/Line was subsequently proactive in issuing its own safety circulars on the change and directly advising affected drivers of this changed condition at Wallan Loop.
There was no similar direct issue of pre-information on the changed condition at Wallan Loop provided to NSW Trains or freight operators. NSW Trains was therefore not provided with the opportunity (as had been given to V/Line) to consider the implications of the change during the afternoon of 19 February and consider pre-emptive actions. Their only potential pre-information for the organisation was via the issue of TN 367 on the evening of 19 February, and this notice was not collected by NSW Trains.
It was concluded that for the routing of trains through Wallan Loop on 20 February, ARTC risk management and oversight processes did not result in effective engagement with all rail operators impacted by this change. There was no engagement strategy and passenger train operator NSW Trains was not directly advised of the change.
Risk controls used
Existing controls were utilised for the routing of trains through Wallan Loop, with some expansion as described below:
the issue of train notices (train notice 367 was issued)
the issuing of a train authority for each train movement (no change to process, text of train authority updated)
a rail worker to accompany each train movement (additional tasks allocated to AQW).
TN 367
Issuing train notices was an existing control, and for the change at Wallan Loop TN 367 was issued. TN 367 described the change to operations via No.2 track and was distributed as an additional instruction to TN 266. It was issued on 19 February 2020 on the ARTC web portal, reportedly at about 1815 Adelaide time (1845 in Victoria and NSW). This was 15 minutes later than the listed time of daily publishing of notices on this portal. The issue of this notice on the evening prior to implementation was not consistent with the risk control of train notices in a ‘timely manner’, particularly in the context of the significance of the changed conditions.
This risk control relied on operators accessing the portal after it being published, processing that information internally, distributing the notice to those affected within their organisation, and potentially considering taking additional precautioning action. In the case of V/Line, the earlier awareness of the notice provided greater opportunity for this activity. In the case of NSW Trains, TN 367 was not obtained from the ARTC portal and TN 367 was not known to NSW Trains.
TN 367 was known to the NCO, signaller and AQW who were on duty on the evening of 20 February. They had all received direct copies of the notice, were familiar with its contents and were all aware of the routing of trains through No.2 track at Wallan Loop.
Issuing the train authority
For the changed conditions at Wallan Loop, there were changes to the content of the train authority but no change to the process of issuing the train authority under TN 367. The train authority was accurately updated to include specific detail on the routing of trains through No.2 track and the speed requirements at the entry to, and exit from, the loop. However as noted earlier in the analysis, the changes to the train authority text were not highlighted and the changes were probably missed by the driver of ST23.
The effectiveness of this risk control was already compromised by the existing process weaknesses, including the indirect issuing of the train authority and the absence of a full readback of the content of the train authority by the driver. The gap in confirming driver understanding became a critical weakness when the conditions at Wallan Loop changed. The driver of ST23 did not (and TN 266 instructed that they should not) read back the content of TA 17 prior to entering the affected section. It is very likely that readback would have resulted in the driver becoming aware of the routing of ST23 through Wallan Loop.
Rail worker to accompany the driver
This risk control was already compromised by the use of an AQW rather than pilot, and the absence of clearly defined qualification, capability and knowledge requirements for an AQW. These weaknesses were exposed when additional obligations were placed on the AQW in TN 367, and (for train ST23) the AQW risk control became the final opportunity to ensure the driver understood the changed conditions at Wallan Loop.
It has been concluded that the driver probably never became aware of the changed conditions at Wallan Loop. For such a scenario, the AQW risk control did not ensure that the driver of ST23 understood the changed conditions at Wallan Loop. There was insufficient evidence to conclude the reason for the probable breakdown of this process. A weakness in this control was the absence of any protocol for how driver understanding of the information on Wallan Loop might be confirmed (by the AQW), including no requirement for the driver to read back the train authority to the AQW. The effectiveness of this control was also probably not assessed for potential susceptibility to human error.[128]
In the case of train ST23, the susceptibility to human fallibility was probably augmented by the AQW on duty at the time of the derailment not being familiar with the corridor from the front of the train and this being their first time in the role. Had the AQW been familiar with the rail corridor and key landmarks, they would have been better placed to warn the driver of the overspeed of ST23 as it approached Wallan Loop.
Potential risk controls that were not used
Context
The decision to use Wallan Loop for rail operations on 20 February, and the introduction of low‑speed turnouts into the section, substantially increased the risk of derailment due to overspeed. The risk to passenger trains was heightened due to their line speed of 130 km/h and the potential for serious injury and fatality. The following are examples of additional risk controls that could have been considered to assist with the management of this risk.
Elimination of risk by not running passenger trains through No.2 track
The ARTC SMS identified that in situations where track was not used for some time, such as occurred with No.2 track at Wallan that February, track circuits could be at risk of unreliable detection due to rail head contamination. Trains were routed to run along No.2 track on 20 February to clean the rail head in preparation for testing and recommissioning of the signalling system at Wallan.
Instead of running passenger trains through Wallan Loop for the purposes of cleaning the rails, there were other options available that may have been considered, including a rail vehicle solely for that purpose or another cleaning process. In the absence of any risk assessment where options may have been raised and documented, there was no evidence identified that options other than running passenger trains through the loop were considered.
Temporary speed restriction for section
A potential risk control while routing through the loop was to apply a temporary speed restriction (TSR) to the Kilmore East to Donnybrook section operating under administrative controls. A suitable speed restriction for the full section, or part of the section that included Wallan Loop, would probably have reduced the risk of derailment due to overspeed at the Wallan Loop turnout.
Signage or conspicuous devices ahead of loop as visual cues
Potential (but not used) sources of information to alert the driver were speed signs and/or other conspicuous devices to advise of the reduced speed required to enter Wallan Loop. Without visual cues in the real-world environment, the driver was reliant on obtaining information solely from the administrative controls and remembering to later apply that information. Signage had the benefit of providing in-field cues to mitigate against the scenarios of failed administrative controls (to alert the driver of the changed conditions) and a failure of driver prospective memory. The use of signage was listed as a control for derailment in ARTC’s risk library.[129]
In-cab warnings as visual and audible cues
The XPT train was fitted with an in-cab equipment (ICE) digital train radio system as part of the National Train Communication System (NTCS). This system was used by some other networks for electronic authorities and proximity reminders for speed reduction.[130] ARTC had not implemented such systems on their network.
Track force protection
‘Track Force Protection in place as last form of defence’ was listed as a control in the risk management plan for the altered train working arrangements, although there was no context in the plan as to when, or when not, track force protection was to be applied.[131] TA 20 section 15, rule 3 described several circumstances where track force protection should be applied. These generally related to situations where equipment may be on track and not to the situation that existed at Wallan. Nonetheless, a form of protection through the section was practical and available and had been used for trackside works on the same day, and only a short distance from the loop.
Summary
For the routing of trains through Wallan Loop on 20 February, ARTC risk management and oversight processes did not result in the implementation of available and practical risk controls to manage the risk of derailment at the low-speed turnouts at Wallan Loop. Options included not running passenger trains through Wallan Loop, signage or other visual cues in the real-world environment, track force protection for the Wallan Loop section and a temporary speed restriction for part or all of the section.
Distribution of safety-critical information
Distribution by ARTC
For its Victorian network, each evening ARTC issued train notices (to rail operators) on its web portal.[132] This was a pull communication strategy that required rail operators to check the portal each evening. ARTC had a different method of issuing train notices applicable to its NSW network. In NSW, ARTC used a push communication strategy and SAFE notices were emailed to key contacts within rail operators, including NSW Trains. As a result, rail operators with operations in NSW and Victoria would receive ARTC safety notices in different ways, depending on the location.
Safety notices were a common mechanism for distributing safety information in many modes of transport and there were a range of strategies used to maximise the reach and reliability of information distribution. The methods used by ARTC to distribute safety information were sub‑optimal and there was scope to improve the effectiveness of this risk control and support the safety needs of rail operators.
NSW Trains
Accessing ARTC web portal
NSW Trains did not have a functioning process for accessing the ARTC portal for train notices applicable to its Victorian operations and instead relied on Victorian weekly notices which did not normally include the ARTC train notices. The discontinuation of routine checking of the ARTC portal for Victorian network safety notices followed changes to the NSW Trains internal structures in 2017. The loss of these processes reflects a failure of change management within NSW Trains at the time of restructure.
From 2017, there were very likely gaps in NSW Trains’ awareness of operational information for the ARTC network in Victoria, and gaps in weekly information packs provided to XPT drivers operating on that network. The repercussions were a diminished opportunity for NSW Trains to consider any new operational risks and possible controls, and the absence of pre-information to drivers on changes to network conditions.
Distribution to drivers
For drivers commencing their shift at Junee, NSW Trains prepared weekly information packs that were distributed via pigeonhole. NSW Trains did not have a functioning system to monitor that drivers starting their shift at Junee received and had understood distributed safety information. This potentially weakened the reliability of train notices as a risk control.
V/Line receipt and distribution of safety information
Aided by receiving advance information on the proposed train working arrangements directly from ARTC, V/Line distributed this information within its organisation. Then, following receipt of advance information on the changed conditions at Wallan Loop (in TN 367), V/Line was proactive in distributing TN 367 within its safety information system, and driver supervisors briefed affected drivers of the changed conditions at Wallan Loop.
Risk management on the ARTC rail network
Context
The risks and risk controls associated with overspeed derailment at low-speed turnouts on the ARTC network were considered more broadly in the context of the following occurrences in Victoria:
the derailment of a freight train at Benalla in June 2006 (ATSB 2007)
the overspeed of a V/Line passenger service at Wallan in July 2015 (ATSB 2017)
this most recent occurrence of ST23 derailment at Wallan in February 2020.
During normal operations, the primary risk control at the Benalla and Wallan turnout locations was driver compliance with signalling.[133] In the Benalla (2006) and Wallan (2015) occurrences, driver unawareness was a factor in the overspeed. In all three cases, the common factor was the residual risk of a low-speed turnout within the track section, and a failure of risk controls to manage that infrastructure risk.
As part of this (2020) investigation, the ATSB sought information from ARTC and V/Line on their consideration (following the 2015 occurrence) of train enforcement solutions at Wallan Loop to protect against train overspeed.[134] In response:
ARTC provided the advice that consideration of train enforcement solutions at Wallan Loop was a matter for V/Line. Following the 2015 overspeed event, there were also no other new risk controls implemented by ARTC at this location. The Office of the National Rail Safety Regulator also provided advice that it did not conduct audits or inspections of ARTC on the topic of the overspeed occurrence at Wallan Loop in 2015.
V/Line advised that an internal assessment following the 2015 occurrence had identified that there was a case for additional protection at Wallan and several other locations on the ARTC North-east line (in Victoria) to manage the risk of passenger train derailment due to overspeed. The train protection and warning system (TPWS)[135] was subsequently scheduled to be installed at Wallan and several other locations on the ARTC standard gauge corridor between Melbourne and Albury.[136] The installation was to be funded by the Victorian government.
The installation of TPWS on the standard gauge corridor would facilitate enforced braking of V/Line passenger trains at installed locations but would not provide overspeed protection for incompatible rolling stock operated by NSW Trains (for example, the XPT and its replacement) and freight operators.[137]
Potential barriers to improvements in rail safety
Scope
This section of the analysis discusses identified potential barriers to safety improvements on the national rail network. It is beyond the scope of this investigation to quantify the influence of these factors on safety risk and the conclusions are listed as general findings to this report.
The following are discussed:
ARTC risk management for passenger train safety
the overlapping safety responsibilities of ARTC and rolling stock operators
slow adoption of available technologies
diversity of train protection systems in Australian rail networks.
ARTC risk management for passenger train safety
An operator on the ARTC network (V/Line) found that the residual risk of derailment (due to overspeed) for its passenger services should be reduced at higher risk locations on that network. This raises questions as to the role of the RIM in assessing and managing residual risk to passenger train safety that is primarily a result of hazards associated with infrastructure layout. Review of ARTC risk materials found that the ARTC enterprise risk management system (ERMS) was opaque on the assessment and treatment of the risk of passenger train derailment due to overspeed. This opacity had the potential to result in missed opportunities for ARTC to identify and implement additional risk controls to advance safety for passenger train operations on the ARTC network.
Considering the overspeed occurrences at Benalla and Wallan specifically, it was concluded that there were opportunities for improved safety management at higher risk locations that included low-speed turnouts. Examples of risk controls available to ARTC as the rail infrastructure manager at these higher risk locations included speed limits, changes to track and/or signalling infrastructure, and a variety of technological solutions to reduce the likelihood, or manage the outcome, of human error. In the absence of action by ARTC at these higher risk locations, unilateral action has been taken by one passenger train operator (V/Line) to address the potential for train overspeed at such locations. Other above rail operators will not benefit from these risk controls.
Safety responsibilities of infrastructure managers and rolling stock operators
Rail safety regulation in Australia described safety responsibilities (individually) applicable to the rail infrastructure manager (RIM) and the rolling stock operator (RSO). The mechanism for the management of overlapping regulatory obligations to reduce risk so far as is reasonably practical (SFAIRP) was less clear. The safety interface agreement was one available vehicle to facilitate engagement and potentially achieve joint safety outcomes. In the instance of ARTC and NSW Trains, the (safety) interface agreement had not been updated since 2011 and did not provide evidence of a proactive consultative regime that contributed to improved safety.
Barriers to improved safety on the ARTC rail network include the absence of an effective concept of shared safety responsibility between RIM and RSO, mechanisms that encourage proactive safety improvement where safety responsibilities overlap, and a framework to resolve funding barriers.
Slow adoption of available technologies
Metropolitan and several regional networks in Australia have adopted technological solutions to mitigate the risks associated with human error. Examples of regional applications include train protection and warning systems on the Victorian regional network, and in-cab information and warning systems on the NSW country regional network.
The roll out of available technologies on the ARTC network was slow by comparison. The ARTC advanced train management system (ATMS) was initiated by ARTC in 2005 and was operational on only a small portion of its network, and opportunities to utilise existing train radio systems to enhance in-cab information and warning had not been taken.
Diversity of train management systems in Australian rail networks
Technological advances in train management systems provide opportunities for significant improvements in the safety of rail transport. There are several technical options and rail networks around Australia are adopting an array of solutions to meet their operational needs (RISSB 2021b).[138] Each network solution requires network users (rolling stock) to interface with the management system for that network.
The range of systems being adopted across Australia raises questions around interoperability and the safety implications of an uncoordinated application of train management technologies.[139] An uncoordinated approach may result in lost opportunities for improved safety while also introducing interface risks.
Power car survivability
Detachment of driver’s cab door
When the leading power car overturned and slid on its side, the left-side driver's cab door detached from the door frame. Although the sequence of door component failures could not be ascertained with certainty, analysis confirmed that the knuckles of the upper hinge would probably unfurl during an overturn event, and that the door attachments were probably not designed to withstand such a loading scenario.
The left-side cab door probably detached early in the sequence of the power car overturning and sliding. With the door aperture open, ballast and earth entered the cab, impacting and trapping the driver and the accompanying qualified worker (AQW) who were inside. A similar derailment in Ufton Nevert in the United Kingdom where the train driver died involved the overturn of a power car of similar design (to the XPT) and track material entering the driver’s cabin.
Contemporary Australian industry standards referred to international standards that required cab side doors to meet external pressures that had aerodynamic origins. Neither these standards nor the Australian standard covering structural integrity included requirements for cab doors following overturn. There was no other Australian standard identified that included requirements to prevent or mitigate against the potential ingress of ballast materials into the driver’s cab following overturn.
Access and egress
Access was available to the driver’s cab via the right-side door, however it proved a difficult route to provide assistance to the driver and AQW in the overturned power car. Without ground-level access to the interior of the cab, passenger services crew and emergency first responders were inhibited in their ability to provide effective assistance to the trapped driver and AQW, prolonging the train crew’s exposure to the adverse environment within the cab.
Contemporary Australian rail industry standards did not include requirements for ground-level access to or egress from driver's cabs in the event of a rollover.[140] This can hinder escape by occupants or immediate access to rolling stock interiors by other crew members and first responders.
Fuel tank breach
The lower left-side edge of both fuel tanks on the leading power car were breached, allowing diesel fuel to drain from the tanks. The fuel tanks were single-skinned and exposed to penetrating and abrading materials in the case of derailment.
The derailment and overturn of a CountryLink Xplorer at Baan Baa in May 2004 resulted in the Office of Transport Safety Investigation (OTSI) recommending that the rolling stock owner (Railcorp at that time) review ‘the design, positioning and protection of fuel tanks on its diesel fleet’ (OTSI 2005). A review of records indicated that a response was provided to the rail regulator by Railcorp indicating that its review had found that there was no significant risk reduction to be obtained by changing the design, positioning and protection of fuel tanks on its diesel fleet.
Passenger safety
Scope
Following the derailment, some passengers started to self-evacuate the train onto the adjacent tracks prior to the train crew directing an evacuation, and prior to the crew receiving confirmation that all trains had been stopped.
This section of the analysis considers the factors that may have led to the passengers’ actions, including the safety information provided prior to the derailment, the communication from crew members during the incident and the training received by crew members to be able to manage such incidents.
Passenger safety information
Overview
The post-occurrence passenger survey revealed a low level of assimilation of onboard safety information and it is probable that the majority of passengers on ST23 were not aware of the specified actions for passengers in the case of an emergency event such as derailment. A range of reasons were given by passengers, including not recalling or not paying attention to safety announcements, and not reading the safety information located at the rear of the onboard guide.
Although passenger attention to safety briefings and retention of the information provided is difficult to ensure, it is important that operators provide passengers the best opportunity of receiving and comprehending safety information. NSW Trains provided passenger safety information to passengers in various formats, including verbal and written information. However, the methods used to convey safety information in this case were not effective for probably the majority of passengers. This meant that, following the derailment, there was greater reliance on passenger services crew to provide instructions to passengers on what to do, and specifically the instruction to remain on the train until it was confirmed safe to evacuate.
Verbal briefing
Passenger inability to recall that information had been provided does not mean that they did not receive the information, however it does indicate that the methods used to provide the information had limited effectiveness.
Although there was a standard announcement documented within the operator’s procedures, it was probably not unusual for a passenger services supervisor (PSS) to prepare their own briefing. This meant that it could not be assured that passengers would receive safety information fully consistent with the NSW Trains’ guidelines.
In addition, there were occasions where passengers boarded at intermediate stations where the briefing was not provided, and in the case of ST23 a full safety briefing was not given in Albury. Any gaps in verbal briefing were compounded by ineffective onboard written safety information.
Written information
Printed instructions provide passengers with a greater opportunity to understand emergency information. This is particularly important when not all passengers receive a verbal briefing when they first board a train.
Passengers on the XPT were provided written safety information in an onboard guide that contained other information not relevant to safety. The passenger survey indicated that only a small portion of passengers accessed that information, and some passengers also commented that information presented like that on airlines (as a safety card) may have been helpful.
The safety information in the onboard guide was presented without any pictorials. Research supports the combination of text and pictorials, particularly for information that is not familiar. The use of both text and pictorials can increase a person’s ability to translate meaning (Mandl and Levin, 1989). In addition to the format of the written information, it was reported that the onboard guides were not present in the back of every passenger seat.
In addition, signage containing simple instructions to guide passengers on what to do in an emergency were not present on ST23. Some of the surveyed passengers mentioned that better signage on the seat in front of them or at the end of carriages may have been helpful.
Communication to passengers in an emergency
Following the derailment, not all passengers received immediate instruction to remain on board the train. This was in part due to the location of the passenger services crew members at the time of the derailment, which limited the opportunity to immediately communicate directly with passengers in remote passenger cars. As a result, some passengers decided to self-evacuate, probably within a few minutes of the derailment and prior to the adjacent tracks being confirmed by the passenger services crew as being safe for the evacuation.
This situation highlights the importance of communicating with all passengers quickly, especially when they are physically dispersed in different passenger cars. Crew members might achieve this via the use of the public address (PA) system or megaphones. Neither the PA system nor megaphones were used in this instance.
NSW Trains’ procedures referred to the use of the PA system in an evacuation to advise passengers to be prepared to evacuate, however there was no procedure that provided train crew with standard phrases or positive commands to inform passengers of the need to remain on board the train.
The incident response summary guidance located at the passenger service crew stations on ST23 were comprehensive, however they could not be considered a quick reference. Additionally, there was no reference to the use of the megaphones in an emergency to assist in maintaining control of passengers on board, or once they had been evacuated.
Passenger services crew training in emergency procedures
All the passenger services crew members except one had completed some form of emergency and evacuation training. The training included material related to a train derailment and an opportunity for participants to talk through scenarios. However, none of the scenarios were hands‑on or practical in nature. Research (Arthur et al. 2013) shows the importance of practice for skill acquisition and retention, particularly for those tasks that may not be performed on a regular basis.
It is acknowledged that a 2019 NSW Trains training needs analysis identified that evacuation‑related competencies for passenger services crew should be trained and assessed practically. However, changes recommended by this review had not yet been implemented at the time of the Wallan derailment.
Training and assessment administration
Administrative processes for the conduct of written assessments (in this case for emergency and evacuation training) of the passenger services crew on ST23, such as signing of examinations, recording of marks, and the use of the documented marking system, were not consistent with the principles of assessment and rules of evidence (ASQA 2015).
Not all passenger services crew members had been recorded as having completed the required emergency procedures training and some were outside the recurrency requirements. There was also no matrix or recording system that identified the required training and frequency for different crew roles. This meant that the management of the train crews’ competency in emergency procedures was inconsistent and it was unclear how the standards were being applied.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the derailment of train ST23 at Wallan on 20 February 2020.
Contributing factors
The derailment
Low-speed (15 km/h) turnouts from the 130 km/h through track at Wallan Loop resulted in a risk of derailment due to train overspeed. This risk was re-introduced into the section on 20 February.
Train ST23 did not slow sufficiently to negotiate the turnout to Wallan Loop. ST23 was travelling at between 114 and 127 km/h when it entered the turnout compared to the specified operational speed for the turnout of 15 km/h.
The driver was probably unaware of the routing of ST23 into Wallan Loop and their understanding of this routing was not confirmed. During the preceding 12 days, the driver had very likely developed a strong expectation that while signals were not operating trains were not being routed via No.2 track at Wallan Loop.
Train working arrangements and risk management
The driver of ST23 did not (and was not required to) read back the content of train authority 17 prior to entering the affected section. Readback of the train authority would likely have resulted in the driver becoming aware of the routing of ST23 through Wallan Loop.
Train working arrangements established by ARTC on 6 February 2020 excluded communication protocols to confirm driver understanding of the content of the train authority giving them permission to enter that section. This gap in communication protocols became a critical weakness in this risk control when the track configuration was changed to route trains through Wallan Loop on 20 February.
For the routing of trains through Wallan Loop on 20 February, ARTC did not implement available and practical risk controls to manage the risk of derailment due to overspeed at a Wallan Loop turnout.
For the routing of trains through Wallan Loop on 20 February, ARTC risk management and oversight processes did not result in a documented assessment of the introduced risks and the application of controls necessary to manage those risks. (Safety issue)
For the routing of trains through Wallan Loop on 20 February, ARTC processes did not result in its effective engagement with network users that would be affected by this change. (Safety issue)
Power car survivability
The power car left-side door detached from its frame when the power car overturned and slid on its side. This allowed earth and ballast materials to enter the driver’s cab of train ST23, impacting and trapping the driver and the accompanying qualified worker.
Passenger services crew and first responders were unable to render immediate and effective assistance to the trapped driver and accompanying qualified worker due to the lack of ground level access to the driver's cabin.
Other factors that increased risk
Risk management
For the establishment of train working arrangements that deviated from ARTC network rules, ARTC risk management and oversight processes resulted in a risk management plan that was limited in context, scope and risk identification and risk controls that had significant weaknesses. (Safety issue)
For the establishment of train working arrangements that deviated from ARTC network rules, ARTC stakeholder engagement did not support its management of the safety risks to network users and the development of agreed risk controls. (Safety issue)
For the establishment of train working arrangements that deviated from ARTC network rules, ActivateRail did not implement processes to ensure its contributions were consistent with the risk management procedures of the accredited rail infrastructure manager (ARTC) and Australian risk management standards. (Safety issue)
Train working arrangements
ARTC use of train authorities in the circumstances that were present between Donnybrook and Kilmore East in February 2020 was not provided for in the ARTC Code of Practice for the Victorian Main Line Operations (TA20). In the absence of effective risk management and stakeholder engagement, deviation from the established practices introduced the potential for a degraded level of rail safety.
The effectiveness of the ARTC train notices as a risk control was undermined by their form, their inexactness, the limited consultation with stakeholders that would be affected, their method of distribution, and their release only a short time prior to each coming into effect.
The practice of the train authority being delivered to the driver by the accompanying qualified worker rather than directly from the signaller removed an opportunity for direct contact and an exchange of safety information between the signaller (who had been issued the train authority by the network control officer) and the driver.
ARTC did not specify the qualification and knowledge requirements of persons who were to perform the safety critical role of an accompanying qualified worker. (Safety issue)
The accompanying qualified worker used by ARTC for train ST23 was not familiar with the rail corridor environment between Kilmore East and Donnybrook from front of train.
Distribution of safety critical information
ARTC distribution of safety information by train notice was sub-optimal. There was scope to improve reliability of safety information distribution and to consider opportunities for operators in Victoria (and SA and WA) to receive direct distribution of train notices for their operations on the ARTC network. (Safety issue)
NSW Trains did not have a functioning process for obtaining safety information from the ARTC web portal for its rolling stock operations within Victoria and did not routinely obtain ARTC train notices. (Safety issue)
NSW Trains did not have a functioning system to monitor that drivers starting their shift at Junee received and had understood distributed safety information. (Safety issue)
Power car survivability
Contemporary Australian industry rail standards did not include structural requirements for cab doors, or other performance-based requirements, that addressed the protection of train crew in the case of vehicle overturn. (Safety issue)
Contemporary Australian industry rail standards did not include requirements for ground-level access to or egress from driver's cabs in the event of a rollover. (Safety issue)
Passenger safety
A significant number of passengers self-evacuated onto tracks that had not been confirmed safe by the train crew.
The majority of passengers on ST23 were probably not aware of the NSW Trains’ specified actions for passengers in the case of an emergency event such as derailment.
NSW Trains’ methods of providing safety information to passengers (including verbal safety briefings, onboard guides and signage) did not provide reasonable opportunity for all passengers to have knowledge of what to do in an emergency. (Safety issue)
NSW Trains’ procedures did not provide specific instructions to passenger services crew on when, how and what to communicate to passengers in an emergency. (Safety issue)
NSW Trains’ training of passenger services crew did not include periodic simulated exercises that would allow crew members to demonstrate and maintain the knowledge and skills required in an emergency. (Safety issue)
NSW Trains did not have systems in place to achieve outcomes in emergency response training consistent with its competency framework for passenger services crew. (Safety issue)
Other findings
Factors unlikely to have influenced occurrence
Evidence suggests that both the driver of ST23 and the accompanying qualified worker were fit for normal functioning and were not incapacitated at the time of the derailment.
Rolling stock testing, inspections, and a review of maintenance records did not identify an adverse condition or defect that was likely to have contributed to the derailment.
There was no evidence identified to suggest that the condition of the track at the northern entry to Wallan Loop was a factor in the derailment.
Voice recorders on rolling stock
Voice recording within the driver’s cab would have assisted the investigation to examine the interactions within the cab, and to potentially identify additional safety factors.
Potential barriers to safety improvements on the ARTC rail network
The ARTC enterprise risk management system was opaque on the assessment and treatment of the risk of passenger train derailment due to overspeed at higher risk locations (such as Wallan Loop). This probably resulted in missed opportunities for ARTC to identify and implement additional risk controls to advance safety for passenger train operations on the ARTC network.
Where risks were shared between the rail infrastructure manager (RIM) and rolling stock operators (RSO), there was the potential for lost opportunities for safety improvement. A review of the (safety) interface agreement between ARTC and NSW Trains did not identify an active safety interface mechanism for the promotion of improved safety.
The rollout of technological solutions on the ARTC rail network to mitigate risks associated with human error was slow in comparison with several other regional rail networks in Australia.
The uncoordinated application of train management technologies on Australian rail networks could result in lost opportunities for improved safety while also potentially introducing interface risks.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Risk management for routing trains through Wallan Loop
Safety issue description: For the routing of trains through Wallan Loop on 20 February, ARTC risk management and oversight processes did not result in a documented assessment of the introduced risks and the application of controls necessary to manage those risks.
Stakeholder engagement for routing trains through Wallan Loop
Safety issue description: For the routing of trains through Wallan Loop on 20 February, ARTC processes did not result in its effective engagement with network users that would be affected by this change.
Safety issue description: For the establishment of train working arrangements that deviated from ARTC network rules, ARTC risk management and oversight processes resulted in a risk management plan that was limited in context, scope and risk identification and risk controls that had significant weaknesses.
Stakeholder engagement to deviate from network rules
Safety issue description: For the establishment of train working arrangements that deviated from ARTC network rules, ARTC stakeholder engagement did not support its management of the safety risks to network users and the development of agreed risk controls.
Contractor processes to support deviation from network rules
Safety issue description:For the establishment of train working arrangements that deviated from ARTC network rules, ActivateRail did not implement processes to ensure its contributions were consistent with the risk management procedures of the accredited rail infrastructure manager (ARTC) and Australian risk management standards.
Definition of knowledge requirements of safety critical workers
Safety issue description: ARTC did not specify the qualification and knowledge requirements of persons who were to perform the safety critical role of an accompanying qualified worker.
Safety issue description: ARTC distribution of safety information by train notice was sub-optimal. There was scope to improve reliability of safety information distribution and to consider opportunities for operators in Victoria (and SA and WA) to receive direct distribution of train notices for their operations on the ARTC network.
Safety issue description: NSW Trains did not have a functioning process for obtaining safety information from the ARTC web portal for its rolling stock operations within Victoria and did not routinely obtain ARTC train notices.
NSW Trains distribution of safety information to drivers
Safety issue description: NSW Trains did not have a functioning system to monitor that drivers starting their shift at Junee received and had understood distributed safety information.
Standards for protection of train crew from debris
Safety issue description: Contemporary Australian industry rail standards did not include structural requirements for cab doors, or other performance-based requirements, that addressed the protection of train crew in the case of vehicle overturn.
Standards for accessing crew in overturned vehicle
Safety issue description: Contemporary Australian industry rail standards did not include requirements for ground-level access to or egress from driver's cabs in the event of a rollover.
Safety issue description: NSW Trains’ methods of providing safety information to passengers (including verbal safety briefings, onboard guides and signage) did not provide reasonable opportunity for all passengers to have knowledge of what to do in an emergency.
Safety recommendation description: The Australian Transport Safety Bureau recommends that NSW Trains undertake further work to improve the methods used to provide safety information to ensure that passengers are given a reasonable opportunity to gain knowledge of what they may be required to do in the event of an emergency.
Guidance on passenger communications in an emergency
Safety issue description: NSW Trains’ procedures did not provide specific instructions to passenger services crew on when, how and what to communicate to passengers in an emergency.
Simulated exercises in emergency management training
Safety issue description: NSW Trains’ training of passenger services crew did not include periodic simulated exercises that would allow crew members to demonstrate and maintain the knowledge and skills required in an emergency.
Safety issue description: NSW Trains did not have systems in place to achieve outcomes in emergency response training consistent with its competency framework for passenger services crew.
Safety actions not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future.
ARTC
ARTC advised that a standing Train Notice has been issued requiring the Network Controller, when issuing a Train Authority to the Rail Traffic Crew, to receive a read back of the Train Authority from the Rail Traffic Crew in full. Confirmation of having read and understood the content of Train Authority is provided by the Rail Traffic Crew via signature, with the time of the Train Authority read back also recorded.
NSW Trains
NSW Trains advised that it has taken the following additional steps to reduce the risks associated with this type of occurrence in the future:
Introduction of a range of initiatives to enhance safety critical communications including:
the development of a new program to strengthen the quality of safety critical communication across all NSW Trains rail safety workers (as well as digitisation)
benchmarking of NSW Trains' systems against safety critical communication systems used by other rail operators
five risk workshops with key internal and external stakeholders to identify opportunities to strengthen safety critical communications
exploration of future digital solutions for safety critical communications.
Additional resources to ensure that NSW Trains has 24/7 shift manager coverage to enhance frontline crew ability to liaise directly with a supervisor.
Programmed
Programmed advised that actions undertaken to strengthen existing controls around placement of rail workers included:
Receiving job orders from customers and confirming these in writing by the recruitment and placement teams following a verification against recognised competency frameworks and network rules ie RISSB, TA20 etc.
Employing a dedicated National Rail Training and Compliance Manager who is responsible for monitoring and verifying RIW competencies of Programmed’s rail safe working crews. This extends to arranging RIW refresher training.
Implementing a new technology platform for undertaking desktop and in field audits that includes a verification of training and qualification to the role types being supplied.
Sources and submissions
Sources of information
The sources of information during the investigation included:
Australian Rail Track Corporation
NSW Trains
Sydney Trains
ActivateRail
Programmed
ARG Rail
V/Line
Office of the National Rail Safety Regulator
Victoria Police
References
ASQA (Australian Skills Quality Authority) (2015) Standards for Registered Training Organisations (RTOs) Table 1.8-1 Principles of assessment [contained in Users Guide to Standards for VET Accredited Courses, Appendix 6: Principles of Assessment]
ATSB (Australian Transport Safety Bureau) (2007) Rail Occurrence Investigation Report 2006005 Derailment of Train 5MB7 at Benalla, Victoria on 2 June 2006, Australia.
ATSB (Australian Transport Safety Bureau) (2017) Investigation RO-2015-011 Over-speed of V/Line passenger train 8625 over points at Wallan loop Wallan, Victoria on 11 July 2015, Australia.
ATSB (Australian Transport Safety Bureau) (2019) Investigation RO-2017-016 Derailment of freight train 7MC1 at Wallan, Victoria on 4 November 2017, Australia.
Arthur W, Day E, Bennett W and Portrey A (2013) Individual and team skill decay. The science and implications for practice, Routledge New York.
Dismukes, RK (2012) ‘Prospective memory in workplace and everyday situations’, Current Directions in Psychological Science, 21(4):215-220.
DOT (Department of Transportation) (2018) Draft Safety Advisory Related to Temporary Signal Suspensions, Federal Register Vol. 83, No. 78: Page 17701, U.S.A.
DOT (Department of Transportation) (2018a) Safety Advisory Related to Temporary Signal Suspensions, Federal Register Vol. 83, No. 224: Page 58685, U.S.A.
DOTARS (Department of Transport and Regional Services) 2002 Code of practice for the defined interstate rail network, Volume 3 (Operations and safeworking) Part 1 (Rules), Australia.
Eames A (2007) RSSB Research Programme - T190 Optimising Driving Cab Design for Driver Protection in a Collision (Debris Ingress), Issue 4, Rail Safety and Standards Board UK
Fox K (2009) How has the implementation of Safety Management Systems (SMS) in the transportation industry impacted on risk management and decision making? Lund University.
Gertner J and Acton S (2003) Railroad dispatcher communications training materials. Technical Report No. DOT/FRA/ORD-03/12. Washington, DC: Federal Railroad Administration.
Greene RL (1987) ‘Effects of maintenance rehearsal on human memory’, Psychological Bulletin, 102(3): 403–413.
ITSRR (Independent Transport Safety and Reliability Regulator) (2004) Train door emergency egress and access and evacuation procedures, NSW.
Klampfer B, Grey E, Lowe A, Hayward B and Branford K (2012) ‘Reaping the benefits – how railways can build on lessons learned from crew resource management’ in Wilson, JR, Mills A, Clarke T, Rajan, J and Dadashi, N (eds) Rail human factors around the world: impacts on and of people for successful rail operations, CRC Press, Leiden.
Loukopoulos LD, Dismukes RK and Barshi, I (2009) ‘The perils of multitasking’, AeroSafety World, 4(8):18-23.
Mandl H and Levin JR (1989) Knowledge acquisition from text and pictures, Elsevier New York.
National Vocational Education and Training Regulator Act 2011 (Cth)
NTSB (National Transportation Safety Board) (2019) Amtrak Passenger Train Head-on Collision With Stationary CSX Freight Train Cayce, South Carolina February 4, 2018. NTSB/RAR-19/02 PB2019-101308, U.S.A.
OTSI (Office of Transport Safety Investigation) (2005) Investigation report Road Motor Vehicle Struck by Countrylink Xplorer Service NP23a on Baranbah Street Level Crossing (530.780kms), NSW.
RAIB (Rail Accident Investigation Branch) (2008) Investigation report 22/2008 Train overspeeding through an emergency speed restriction at Ty Mawr Farm Crossing on 29 August 2007, U.K.
RAIB (Rail Accident Investigation Branch) (2016) Investigation Report 14/2016 Overspeed at Fletton Junction, Peterborough 11 September 2015, U.K.M
RISSB (Rail Industry Safety and Standards Board) (2014) ANRP- Centralised traffic control, version 1.2, Australia.
RISSB (Rail Industry Safety and Standards Board) (2014a) ANRP – Network Communication, version 1.3, Australia.
RISSB (Rail Industry Safety and Standards Board) (2017) Contracting in the Rail Industry, Accreditation and Safety Management Systems Guideline, Version 1.0, Australia.
RISSB (Rail Industry Safety and Standards Board) (2018) Guideline - Safety critical communications, Version 1.0, Australia.
RISSB (Rail Industry Safety and Standards Board) (2021) Development and Maintenance of Network Rules, Australia.
RISSB (Rail Industry Safety and Standards Board) (2021a) Interoperability Impact Plan version 1.0, Australia.
RISSB (Rail Industry Safety and Standards Board) (n.d.) Hazard register, RISSB website, accessed 8 March 2022.
RSSB (Rail Safety and Standards Board) (2005) Formal Inquiry: Collision with a Road Vehicle and Subsequent Derailment of Passenger Train 1C92 1735 hrs Paddington to Plymouth at Ufton Automatic Half Barrier Level Crossing on 6 November 2004, UK
RSSB (Rail Safety and Standards Board) (2007) Research Programme T190: Optimising driving cab design for driver protection in a collision (Debris Ingress),U.K.
RSSB (Rail Safety and Standards Board) (2017) Safety critical communications: the manual, U.K.
RSSB (Rail Safety and Standards Board) (2020) Railway Group Standard GMRT2100 Rail Vehicle Structures and Passive Safety, Issue 6, UK
Rasmussen J (1997) ‘Risk management in a dynamic society: a modelling problem’, Saf. Sci. 27 (2–3), 183–213.
Sato A, Onoma N and Masuda T (2020) ‘Prospective calling method to prevent excessive train speed’, Quarterly Report of RTRI, 61(4):290-296.
Snook SA (1996) Practical Drift: The Friendly Fire Shootdown over Northern Iraq, ProQuest Dissertations Publishing.
Standards Australia (2017) Management of Network Route Competence (AS 7454:2017), Rail Industry Safety and Standards Board
Standards Australia (2018) Risk management: Principles and guidelines (AS/NZS ISO 31000:2018), http://standards.org.au
Standards Australia (2018a) Interior Crashworthiness (AS 7521:2018), Rail Industry Safety and Standards Board
Standards Australia (2021) Access and Egress (AS 7522:2021), Rail Industry Safety and Standards Board
Standards Australia (2022) Australian railway rolling stock - Body structural requirements - Part 1 - Locomotive (AS 7520.1:2022), Rail Industry Safety and Standards Board
Transport for NSW (2017) Passenger Rolling Stock Access and Egress, Version 1.0 including TN 041:2017 (T HR RS 04001 ST) State of NSW
Wickens CD, Helton WS, Hollands JG and Banbury, S (2022) Engineering psychology and human performance, 5th edn, Routledge, New York.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to organisations and individuals to confirm factual accuracy and/or where parties were potentially affected by findings within the report. Submissions from those parties were reviewed and, where considered appropriate, the text of the draft report amended accordingly.
Appendices
Appendix A – Rolling stock condition assessment
Derailment site observations
Observations were made at the derailment site prior to the rolling stock being moved. The preliminary observations did not identify evidence of rolling stock defects or equipment failures potentially causal to the derailment. All vehicles remained mechanically coupled, although some couplers had sustained damage in the derailment. All bogies remained attached to their car body.
Testing of braking and vigilance systems
Static brake testing on the leading power car (XP2018) was conducted at the Auburn UGL facility to determine whether the brakes were degraded prior to the derailment.[141] Testing also included assessment of the vigilance control system that initiates a brake application in the case of driver incapacitation. There was no evidence found that the brake system or vigilance control system on XP2018 was defective or may have contributed to the derailment. Also, the driver of ST23 did not report any issues with the braking system prior to the derailment.
Power car XP2018 twist test
A twist test on power car XP2018 was conducted at the Auburn facility to determine the vehicle’s capacity to negotiate track twist.[142] The twist test arrangements were in accordance with the twist (packing) described in RailCorp Standard ESR0001-200 (2013) that represented the standard current at the time of the derailment. The testing found a maximum wheel unloading of 57.3%, compared to the maximum permissible value of 60%. Given this result, it is unlikely that the twist performance of the leading power car contributed to the derailment.
Train radio performance
The radio system was function tested and radio logs reviewed to assess the condition of the radio system shortly prior to the derailment. During testing, the system was operational although with some degraded performance, probably due to derailment damage and removed antennas. Based on results of this function testing and the review of radio log files, the Sydney Trains specialist maintenance group responsible for the train communications concluded that there was no evidence to suggest that the onboard communications systems were non-operational or defective at the time of the occurrence.
A review of maintenance records also found that the train radio system was within the required maintenance inspection timeframes and compliant at the time of the derailment. The most recent inspection of communications equipment on XP2018 was on 6 February 2020, and for power car XP2000 the inspection was on 4 February 2020.
Bogie and wheel inspections
The strip-down inspection of the bogies of power car XP2018 did not identify defects likely to have contributed to the derailment. There was minor distortion of the bogie frames, possibly as a result of the derailment. Non-destructive testing identified cracking of one brake bracket casting in the trailing bogie, probably a result of the derailment.
There were no pre-existing adverse conditions identified in the bogies of the passenger cars. Review of bogie and wheelset sheets did not identify any areas of concern with the condition of the bogies at the time of overhaul or wheelset change. Bogie weights at time of overhaul were within specification. Braking components including brake levers and cylinders were within specified dimensions and clamping forces at the time of servicing.
Wheel profile measurements taken following the derailment were compared to the WPR2000 profile specified for these vehicles. No sharp flanges were identified, and profiles were within tolerance and generally close to the WPR2000 profile. The most recent routine wheel measurement also indicated flange and rim thickness were within engineering standards.
Maintenance status of ST23 on 20 February 2020
Maintenance of the XPT fleet was managed using the Sydney Trains enterprise asset management (EAM) system. Work orders were generated within the EAM in accordance with the requirements of the technical maintenance plan (TMP). The TMP specified the frequency of tasks required for the power cars and trailer (passenger) cars. Maintenance inspections included major inspections and trip inspections (prior to service). In addition to the maintenance regime, heavy overhauls were conducted at specified frequencies.
Open and closed faults for the 120 days prior to the derailment were reviewed. There were no open faults identified that would suggest the train was operating at increased risk relevant to the derailment sequence. Review of closed faults did not show any recent faults that might have been addressed incorrectly and created increased risk.
At the time of the derailment of ST23, a number of work orders within the TMP were listed as ‘open’ although none of the open orders were found to be relevant to the risk of derailment. It was also found that ST23 entered service with work orders for the Trip Inspection of all cars identified as ‘open’. However, review of records identified that most tasks had been completed prior to the train entering service. Those tasks that were not completed were not considered potential contributors to the derailment.
Appendix B – ST23 driver roster and fatigue assessment
The driver’s actual and scheduled duty hours for the 2 weeks prior to the occurrence are shown in Table 6. The driver commenced a series of duty periods at about 0215 on 19 February, with the second commencing at about 1815 and ending at about 0100 on 20 February. After about 12 hours free of duty, the driver’s third duty period commenced at Junee at 1315 and the scheduled sign-off time in Melbourne was 1845.[143]
Table 6: Scheduled and actual duty times for the driver of ST23
Date
Work activity
Roster start
Roster finish
Actual finish
Actual hours
7 February
Off
8 February
Junee to Melbourne
0215
0745
0859
6:44
8 February
Melbourne to Junee
1815
0100
0105
6:50
9 February
Off
10 February
Junee to Melbourne
0215
0745
0832
6:17
10 February
Melbourne to Junee
1815
0100
0100
6:45
11 February
Off
12 February
Junee to Melbourne
0215
0745
0832
5:36
12 February
Melbourne to Junee
1815
0100
0127
7:12
13 February
Off
14 Feb 2020
Off
15 Feb 2020
Junee to Sydney
1341
2116
2231
8:50
16 Feb 2020
Melbourne to Junee
0725
1340
Note 1
Note 1
17 Feb 2020
Off
18 Feb 2020
Off
19 Feb 2020
Junee to Melbourne
0215
0745
Note 1
Note 1
19 Feb 2020
Melbourne to Junee
1815
0100
Note 1
Note 1
20 Feb 2020
Junee to Melbourne
1315
1845
Note 2
6:28
Note 1. The driver had not submitted actual worked hours for the period 16 to 20 February as of the day of the occurrence.
Note 2. The derailment occurred at about 1943.
It was reported that the driver normally slept 8 hours a night, though less at times when doing shift work. Information from the driver’s mobile phone included phone calls, messages sent and physical activity (steps taken in each 1-hour period). There was no such phone-related activity for a 5-hour period at night prior to the first shift on 19 February (as well as an earlier period of more than 60 minutes in the afternoon), a 6.5-hour period prior to the second shift on 19 February, and an 8-hour period prior to the shift commencing on 20 February. For the 2 nights prior to these shifts, there were periods of more than 10 hours without such phone activity.
Overall, it was not possible to determine the quantity or quality of sleep obtained by the driver in the days leading up to the occurrence. However, based on the available information (including the length of the duty period and the time of day), there was insufficient evidence to conclude that the driver was experiencing a level of fatigue known to adversely influence performance at the time of the occurrence.
Appendix C – Train Notice 266 initial issue
Appendix D – Train Notice 266 as amended 13 February
Appendix E – The train authority form used under TN 266
Appendix F – Train Notice 367
Appendix G – The train authority form used after TN 367
Appendix H – Other rules and codes
Scope
The operating rules for Australian Rail Track Cooperation’s (ARTC’s) Victorian network were described in the ARTC Code of Practice for the Victorian Main Line Operations (TA20). This appendix provides a brief summary of other codes and rules that were reviewed for any possible relevance to the protocols that were established between Donnybrook and Kilmore East in February 2020.
Code of Practice for the Defined Interstate Rail Network
Volume 3 of the Code of Practice for the Defined Interstate Rail Network described safeworking rules and route standards for the Defined Interstate Rail Network in Western Australia, South Australia, parts of New South Wales and a small section of the Victorian network west of Dimboola (DOTARS 2002).[144] The document had the intention to ‘provide a more unified, harmonised and efficient operation’ and was aligned with 'occupancy control systems and occupancy authorities' defined in AS 4292.5 (Standards Australia 2006).
This code described the potential use of train authorities to pass fixed signals at stop through a section during Centralised Traffic Control (CTC) system failure, where the cause was not unsafe track. Section 3.9 of the code also specified a range of procedural requirements for preparing and issuing train authorities, including step by step instructions for the processes of communication between the train controller and the ‘recipient’ of the train authority. There were broad similarities between the train authority format requirements of this code and the train authorities used between Donnybrook and Kilmore East in February 2020, but also some variation in detail and the application of narration and readback requirements. The system used in February 2020 could therefore not be described as being consistent with all the detail of this code.
Australian Network Rules and Procedures for CTC
The Australian Network Rules and Procedures, and the subsequent National Rules Framework, (RISSB) described how access providers and access users could operate safely on the Australian network.[145] Rules for the CTC system were described in ANRP5001 (RISSB 2014) and stated that if the function to control points and signals failed, the network control officer (NCO) could institute a method of special working.
Special working was included in the RISSB glossary and defined as ‘working rail traffic using an Alternate Proceed Authority (APA) or manual block working’. The RISSB glossary stated an APA may be used to authorise rail traffic movements when the proceed authority normally provided by the safeworking system was not available. In the instance at Wallan, the issuing of caution orders and other safeworking requirements specified in TA20 for the CTC system was available and had been applied in the initial days of the signalling failure.
Australian Network Rules and Procedures for Network Communication
Industry guidance on communications (RISSB 2014a) allowed for the relaying of communications when it was not possible to communicate directly with the intended receiver. However, direct communication between train control and train drivers was always available between 6 and 20 February 2020, as evidenced by train drivers confirming receipt of train authorities and CAN forms to train control.
Appendix I – ARTC types of risk assessment
Appendix J – Risk management of level crossing protection
The ARTC risk management plan for the train authority working between Donnybrook and Kilmore East in February 2020 described the controls being used to manage the risks associated with the absence of automated activation of the level crossing protection at Wallan–Whittlesea Road. The risk management plan described the hazard, cause and outcome associated with the deactivated level crossing (Table 7).
Table 7: Risk management plan description of risk item 6
Hazard
Train operates through non operating level crossing at Wallan
Caused by
Level crossing taken out of service and no protection in place
Worst outcome
Collision with road vehicle or pedestrian leading to injury or fatality.
For the identified risk, the risk management plan identified 2 controls that were to be implemented by the on-duty level crossing keeper (LCK) and the accompanying qualified worker (AQW). Those controls and how they were implemented are described in Table 8.
Table 8: Specified risk controls for risk item 6 and ATSB comment on implementation
Specified risk control
ATSB comment on the implementation of the control
Level crossing (keeper) (LCK) in place to operate test switch
An LCK was located at the Wallan–Whittlesea Road level crossing and would communicate with the AQW of the approaching train. When notified, the LCK would activate the crossing protection and confirm its activation with the AQW. There were no instances identified where this process had failed.
Pilot on train announces approach
An AQW (not a ‘pilot’) on board the approaching train would contact the LCK by mobile phone at sufficient distance to warn of the train’s approach, confirm successful activation of the crossing protection by the LCK, and advise the driver of its activation. There were no instances identified where this process had failed.
Appendix K – Train recorder (Hasler) analysis
The Hasler RT recorder
Power cars XP2018 and XP2000 were each fitted with a Hasler RT data recorder and the tapes from the 2 power cars were recovered for analysis (Figure 23). Limited parameters are recorded and included time, speed, throttle and vigilance control (on the same trace), and brake cylinder pressure.
Figure 23: Hasler waxed paper rolls removed from power cars XP2018 and XP2000
The photograph shows the recovered waxed tapes. The centre roll is the tape from power car XP2000. The left and right rolls are the tape from power car XP2018 that jammed during its removal and was torn at one location. Source: CITS
Data processing
To process the data, both tapes were scanned and examined using photographic software. The traces for each recorded parameter were assessed for alignment with key events, such as start/stop points. Some horizontal re-alignment of parameters was required and both the horizontal and vertical scales of the images were calibrated for measurement.
Wheel diameter corrections
The Hasler used a pre-set (average) wheel diameter to calculate both speed and distance from the measured revolutions of the left wheel on the second axle of the power car (wheel 3).[146] Actual speed may deviate from that recorded (and displayed) due to differences between this pre-set diameter and the diameter of the actual wheel providing the feed to the Hasler system. The actual measured wheel diameter for both power cars was larger than the pre-set value.
The recorded values for speed and distance were corrected for the ratio of actual-to-pre-set wheel diameter (Table 9). The larger actual wheel diameter on the XP2018 (compared to the pre-set) meant that the recorded speed was about 2% lower than the actual train speed.
Table 9: Measurements used for speed and distance correction factor
XP2018 – leading
XP2000 – trailing
Pre-set diameter (mm)
1,000
1,000
Measured diameter (mm)
1,019.2
1,011
Ratio (correction factor)
1.0192
1.011
Uncertainties in recorded data
An initial review identified a likely recording anomaly in the latter part of the XP2018 data. All channels recorded noise in the latter phase, likely associated with the derailment. An overlay of the data from the 2 power cars showed the discrepancy (visible as diverging speed toward the end of the data) and also confirmed that the speed data prior to this occurring was consistent (Figure 24).
Figure 24: Overlay of data recordings from XP2018 and XP2000
The image shows an overlay of speed records from power cars 2018 and 2000. It indicates consistent speed records after departing Kilmore East, then a consistent initial sharp deceleration of both cars followed by diverging speed records during the derailment.
Source: ST23 Hasler recordings annotated by the ATSB
There were also potential inaccuracies in the XP2000 data in the latter stages due to uncertainty in the measured wheel rotation being an accurate measure of train speed during this phase.
Other sources of train speed
GPS data from the installed ICE radio system[147] was interrogated and used as a comparator for time, speed and position information. Although only coarse GPS data was available due to the system’s polling frequency, it provided a source for comparison with the Hasler data and an enhanced confidence in the assessed train speed. The GPS data was also the primary source for locating the position of ST23 when stopped prior to signal KME16.
Throttle and braking events
One limitation of the fitted Hasler data recorder was that it did not record the positions of the driver’s throttle and brake handles. Instead, it recorded a generic power ON-OFF parameter and brake cylinder pressure.
Between Kilmore East and Wallan, the Hasler recorded that power was applied on departing Kilmore East at approximately 19:34:57. Application of power was maintained until around 19:41:34 and remained off until 19:42:20. During this 46 seconds, 2 periods of brake application were recorded that controlled the speed of the train to between 115 km/h and 120 km/h. The reductions in speed were consistent with permanent speed restrictions of 115 km/h between 55.43 km and 53.52 km at Wondong, and between 52.00 km and 51.21 km at Heathcote Junction. At 19:42:20, application of power was recorded. This was maintained until a power off and brake application was recorded at approximately 19:43:22. No records of vigilance control acknowledgements were recorded for the journey of train ST23 between Kilmore East and Wallan loop as brake and throttle controller movements would have acted as vigilance control system task linked activities.
The data from both power cars indicated that, at a point just prior to the commencement of deceleration, the power moved from ON to OFF and there was a rapid increase in brake cylinder pressure. For each recording, the points at which brake cylinder pressure began to rise and then reached a steady state were determined. The steady state pressures were noted for each record and compared with expected values. For both power cars, the recorded pressure was above that expected for a Notch 7 (full-service) application (345 kPa). The pressure recorded on XP2018, the leading power car, was about 378 kPa, which was in line with the pressure expected for an emergency application (375 kPa). Although the pressure recorded on XP2000 was lower, about 358 kPa, it was still substantially above the full-service value. These results indicated that it was very likely that the brake application was an emergency application. The speed of the train at the commencement of braking was about 129 km/h.[148]
Location of rise in brake cylinder pressure
Due to known limitations and potential anomalies in the Hasler data recording, obtaining position information from the data with respect to fixed points on track was difficult to achieve with high levels of accuracy. Therefore, the position at which brake cylinder pressure began to rise and the speed at which the train entered the turnout could not be directly read from the Hasler data.
Instead, the Hasler speed and distance data was used to calculate estimates of position considering different known stop locations. This was cross-checked using data from other sources to provide greater confidence. The different methods yielded slightly different results, however all indicated that the brake cylinder pressure started to rise before entry to the Wallan Loop (Table 10).
Table 10: Estimated limit points of rise in brake pressure and speed at entry to turnout
Distance from brake cylinder pressure rise to No.7 points
50 m
153 m
Speed at No. 7 points
127 km/h
114 km/h
The brake cylinder pressure increase was a result of an emergency brake application, presumed to be by the driver in response to a cue or cues. To provide an estimate of when the cue(s) for braking may have presented, a nominal 2 second period from the cue(s) to brake cylinder pressure rise has been used.[150] Based on this figure, the cue(s) may have presented when ST23 was between about 120 and 220 m from the turnout.
Train handling of ST23 during journey
The Hasler recordings and the GPS data were examined to evaluate any potential trend in speed exceedance by ST23 during the Victorian segment of the journey. The ARTC Route Access Standard specified a maximum speed for express passenger trains in Victoria (including the XPT) of 130 km/h in areas where no local speed restrictions applied.[151] The assessment focussed on any identifiable trends and did not include local speed restrictions remote from the event.
Review of the GPS data identified 11 speed peaks of between 133 and 137 km/h in the Victorian section. These exceedances within the GPS data were cross-checked with the Hasler recordings and similar peaks identified, including a maximum actual value of about 139 km/h.[152]
None of the overspeeds identified were for a significant duration. These observations suggest that the driver was targeting line speed and occasionally overshooting. There was no evidence identified to suggest unusual train handling.
Vigilance parameter
The locomotive was fitted with a vigilance system. The installed Hasler data recorder did not record all information on driver activity associated with the vigilance system and its information was therefore of limited value.[153] However, the Hasler did record a vigilance parameter. The last point at which the vigilance parameter was recorded as active was prior to the stop at signal KME28. There were no vigilance parameter events recorded between ST23 departure from signal KME16 and the derailment.
Appendix L - Driver’s cab side door separation
Sequence of door attachment failure
There were 3 potential failure scenarios of the left-side driver’s cab door considered plausible:
External loading on the door led to the knuckles of the upper hinge unfurling. This was then followed by the failure of the lower-hinge fastening and disengagement of the door latch.
External loading on the door led to failure of the lower hinge fastening. This was then followed by failure of the upper hinge and disengagement of the door latch.
External loading on the door and flexing of the car body led to disengagement of the door latch, followed by the failures at both hinges.
Although the sequence of failure cannot be confirmed with certainty, it was concluded through inspection of the components and the comparative loading on the upper and lower hinges that the more likely component to fail first was the upper hinge.
Evaluation of upper hinge
To evaluate the upper-hinge behaviour under defined loads, simplified loading was assumed. The external force was assumed to be an even pressure acting over the entire door, as used in design standards. This was converted to a point load (F) applied at the centroid of the door’s external surface, and resolved into balanced forces acting on the attachments in the frame from the external door surface (Figure 25).
Figure 25: Inside view of cab door opening and fitting locations (dimensions in mm)
Source: ATSB
The glass fibre composite cab door was a plug shape that rotated inward on the hinges mounted on the inner rear edge of the door frame. The door hinges were fabricated from 3 mm thick stainless steel, and attached to the door frame by bolts into tapping plates (Figure 26).
Figure 26: Door and doorframe section drawing
Source: Commonwealth Engineering (NSW) Drawing 022010940-1 annotated by CITS.
Unfurling of upper hinge knuckles
The upper hinge failed through the unfurling of its knuckles from the hinge pin. The lower (still closed) knuckle disengaged from the rotating pin and the 3 upper knuckles unfurled (Figure 27).
Figure 27: Failed hinge knuckles (upper hinge)
Source: ATSB
The mechanism of the failure of the upper hinge provided a specific failure mode for assessment. Loading of the 3 knuckles that unfurled was assumed for the estimation of material stresses in specified loading scenarios and compared against material yield strength. Dimensional assumptions were also made for the unfurling sequence (Figure 28).
Figure 28: Assumed hinge unfurling sequence
Source: ATSB
Outcomes of simplified load analysis
The potential for hinge failure by unfurling of knuckles was assessed against 2 load scenarios; an externally applied quasi static pressure of 2.5 kPa (GM/RT 2100 aerodynamic loading criteria) and a static pressure based on the power car lying on its side (AS7520.1-2022).
Aerodynamic load case of 2.5 kPa
Considering a 2.5 kPa static external pressure, the simplified analysis indicated that the door attachments would withstand the pressure and the knuckles of the upper hinge would not unfurl.
Load case for power car resting on side
An evenly distributed pressure from the self-weight of the power car when on its side, resulted in a static pressure on the cab door of about 11 kPa. Under this load, the simplified load analysis suggested that the upper-hinge knuckles would probably unfurl, or as a minimum commence plastic deformation.
Load case experienced by ST23
Under the dynamic loading conditions experienced by ST23 during the action of overturning and subsequent sliding, the cab door would be expected to have experienced loading significantly greater that the 11 kPa static (resting on side) load case. Based on the probable failure of the upper hinge (by unfurling) in the static (11 kPa) load case, the knuckles of the upper hinge would be expected to unfurl in the dynamic loading experienced by ST23. This analysis therefore confirmed the plausibility of the failure of the upper hinge by unfurling as the possible first point of failure.
Appendix M – Passenger car crashworthiness information
Introduction
This appendix provides a brief description of the observed damage to internal spaces of the passenger cars that formed part of ST23 (Figure 29).
Figure 29: Passenger cars
Source: Vehicle images supplied by Sydney Trains, annotated by CITS
Passenger car XAM2179 (Car A)
Car A had a sleeper/cabin configuration and was the leading passenger car. The car had 9 cabins that could each seat 3 passengers. Some cabins were fitted with forward-facing seats and others with rear-facing seats.
The car came to rest at an angle of about 30° to its left. External damage included 4 broken exterior windows on the left (passenger aisle) side of the carriage and exterior damage to the roof line above the windows as a result of the car striking pine trees adjacent to the track. Damage within the sleeper car included collapsed interior lining in the passenger aisle. Two cabins had cracked glass partitions, most likely from being struck by luggage or passengers.
Passenger car XL2229 (Car B)
Car B was a first-class car with 56 forward-facing passenger seats in a single open cabin.
The car came to rest at an angle of approximately 17° to its right. There was no evidence of structural failure or dislodged internal fittings acting as projectiles. The only significant damage to the cabin was exterior binding at the front right corner with the car ahead (Car A). This prevented the use of the exits at this location.
Passenger car XBR2155 (Car C)
Car C was half first-class forward-facing seating with the other half being the buffet section. It was near upright when it came to a stop. The car suffered no interior damage of consequence.
Passenger car XF2201 (Car D)
Car D was an economy-class car with 68 forward-facing passenger seats in a single open cabin. It was near upright when it came to a stop. The car suffered no interior damage of consequence.
Passenger car XFH2108 (Car G)
Car G was half economy class forward-facing seating with the other half being the baggage section. It was at an angle of about 10° when it came to a stop. The car suffered no interior damage of consequence.
Appendix N – Passenger safety information
Extract of operator’s procedures on content of verbal briefing
NSW Trains’ procedures specified the following safety content for the verbal briefing:
If you require assistance in an emergency, push the red emergency call button at either end of your carriage.
In the unlikely event of an emergency, please remain seated, stay calm and wait for instructions from the onboard staff.
Staff are trained in emergency procedures and know how to proceed. We will help you exit the train swiftly and safely if an evacuation is necessary.
If instructed to evacuate, leave your luggage behind.
In an emergency, it is often safer to remain on-board rather than to evacuate.
For further information, please refer to the safety card in the seat pocket or table in front of you
Extract of safety information in onboard guide
The section in the onboard guide on emergency procedures stated:
If you’re unable to locate a nearby emergency exit, ask a crew member to show you. All crew members are trained in emergency procedures and can help you exit the carriage or evacuate the train quickly and safely.
What to do in an emergency
1. Push the red emergency call button at either end of your carriage.
2. Alert a crew member immediately.
3. Stay calm and remain seated until you’re instructed by crew members or by rescue, fire or police personnel.
4. When asked to move, leave luggage behind, use handrails and watch out for trip hazards.
5. If told to evacuate the train, please be aware of your surroundings and watch out for hazards. Do not exit the train in a tunnel or on a bridge unless you are told to do so. Follow safety instructions from trained personnel at all times.
6. After leaving the train, move away from the tracks and follow directions to an assembly area organised by crew. Stay together and remain there until further instruction.
Appendix O – Countrylink incident response summary
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
[1] A serious injury is defined in the Transport Safety Investigation Regulations 2021 as an injury that requires, or would usually require, admission to hospital within 7 days after the day when the injury is suffered.
[2] Train authority: an instruction in the prescribed format issued by a network control officer in connection with the movement of a train.
[3] Train notice: operational information issued by or on behalf of the rail infrastructure manager.
[4] The points at either end of Wallan Loop were placed in the hand operating mode and clipped in the normal position; With the points at either end of Wallan Loop set to their normal positions, trains would continue on the straight track (No.1 track) rather than being diverted into the loop (No.2 track).
[5] Residues such as iron oxides can hamper electrical connection between wheel and rail and therefore impact the performance of a signalling system.
[6] Rail traffic was stopped to permit workers to change the points.
[7] The normal position of the turnouts was for routing on the straight, and the reverse position was for the loop.
[8] For these works, the applied track force protection provided for flagmen to warn approaching trains, and for trains to comply with the signals shown by the flagmen.
[9] ARTC document ANGE 220 Unreliable Track-Circuit Operation dated 11 October 2015 (applicable to NSW).
[10] Stopping times at stations are those recorded by NSW Trains.
[11] The ARTC Network Control office for this section of track was located in Junee, NSW.
[12] An alarm had been received by ARTC Network Control for a possible signal passed at danger (SPAD) at Tallarook, 23 km north-east of Kilmore East. The NCO indicated that there had been power outages at this location, that may have showed up as a SPAD. The driver indicated that all signals had been ‘clear’ through Tallarook.
[13] The decision around the order of trains through the location was made following discussions between the NCO and their supervisor. NSW Trains operations were informed of the holding of ST23 at Kilmore East and the delay to that service.
[14] This signal protected the broad-gauge crossover going into the Apex ballast quarry. It was called an ‘Intermediate Home’ because it was in an intermediate location along the passing lane.
[15] The passing lane (an extended crossing loop) was about 7 km in length.
[16] Accompanying qualified worker: the term used in train notices for the worker that would accompany the driver between Kilmore East and Donnybrook.
[17] The AQW’s copy of TN 367 was found within the driver’s cabin.
[18] A CAN was a warning of an unsafe condition affecting, or potentially affecting, the network.
[19] Home departure signal KME16 was protecting the turnout at the end of the passing lane.
[20] In Australia, locomotive and train operating cabs were generally not fitted with voice recording devices.
[21] The latest version of TN 266 was explicit in not requiring the driver to repeat the contents of the train authority back to the NCO. Also under the train working arrangements described in TN 266, there was no requirement for the NCO to read the content of TA 17 to the driver.
[22] Within this section, there were 115 km/h speed restrictions applied to some sections of track.
[23] Speed maintained until approximately the 51 km mark. There was a 115 km/h permanent speed restriction at Heathcote Junction between the 52.00 and 51.21 rail-km locations.
[24] Active protection on the other level crossings on the Kilmore East-to-Donnybrook section were working normally and it was only the Wallan–Whittlesea Road level crossing that required local operation.
[25] The person who activated the level crossing protection locally at the crossing, colloquially referred to as the bellhop.
[26] Range estimated from train recorded data (Appendix K).
[27] Passenger numbers based on available data from the operator.
[28] For open radio broadcast on this ARTC corridor, crew were to switch their radios to channel 6. Of the two crew members making emergency calls, one immediately changed to channel 6 and the other a short time later, probably following prompting. The remainder of the crew were then required to also switch to channel 6 to maintain ongoing communications among the crew members.
[29] V/Line’s network train control centre located in Melbourne.
[30] The emergency services call centre time stamp.
[31] Using tools sourced from the train’s emergency breakdown kit.
[32] A serious injury is defined in the Transport Safety Investigation Regulations 2021 as an injury that requires, or would usually require, admission to hospital within 7 days after the day when the injury is suffered. A minor injury is any other reported physical injury that does not meet the serious injury threshold.
[33] NSW Trains was an agency of the NSW State Government and was within a division of Transport for NSW (TfNSW).
[34] Schedule—Rail Safety National Law, Part 1—Preliminary, Section 4 - Interpretation (RSNL version: 3.10.2019 to 30.6.2020)
[35] Schedule—Rail Safety National Law, Part 3—Regulation of rail safety, Division 3—Rail safety duties Interpretation (RSNL version: 3.10.2019 to 30.6.2020)
[37] Due to the delay in the service on this day, arrival in Melbourne would have been later than the rostered end of shift.
[38] Health and fitness requirements for Rail Transport Operators and Rail Safety Workers were governed by the Rail Safety National Law (RSNL) and associated Regulations.
[39] NSW Trains procedures NTTWP100 Responsibilities of Train Crews and NTOSP11 Train evacuation and detraining when not at a station refer to the duties of the driver and the PSS/Guard.
[40] The training was limited to ‘within work on track work authority limits’ and not the arrangements in place for the train working arrangements between Donnybrook and Kilmore East.
[41] Detailed work-placement records were available from 2014.
[42] The ActivateRail representative (contracted by ARTC) was performing the role of signaller at 1530, and had been involved in developing and implementing the safeworking solution for train working between and Donnybrook and Kilmore East.
[44] VicTrack was a State-owned organisation that owns Victorian rail land, assets and infrastructure.
[45] Rail Safety National Law, Part 1—Preliminary, Section 4— Interpretation (RSNL version: 3.10.2019 to 30.6.2020)
[46] Rail Safety National Law, Part 3—Regulation of rail safety, Division 3—Rail safety duties (RSNL version: 3.10.2019 to 30.6.2020)
[47] Standard gauge trains did not stop at Wallan.
[48] TA20 ARTC Code of Practice for the Victorian Main Line Operations, Section 2, Rule 13 g.
[49] Signal ES1712 was located at 51.77 km rail-km from Melbourne
[50] The indication of this signal at the time ST23 passed is not known with certainty because its state was not recorded. However, broad gauge rail traffic records indicated that the signal was more likely to be at proceed. If not at proceed, the signal would have been at its alternate ‘caution’ indication, a single yellow light.
[52] Azimuth is the clockwise horizontal angle (in degrees, minutes and seconds) from true north to the sun.
[53] Altitude is the vertical angle (in degrees, minutes and seconds) from an ideal horizon to the sun.
[54] Computed using National Mapping Division's sunmoonposn program, version 1.1.
[55] A 45 minute delay would be the result of a 24 km/h average speed compared to a 96 km/h average speed over the 24 km section; The issuing of caution orders and applying other safeworking rules in accordance with TA20 also increased the workload on network control resources.
[56] ActivateRail offered professional advisory services, project managers as well as worksite supervisors, site managers and track safety personnel.
[57] Project representatives suggested signals remained lit to assist electrical testing, and as location markers for drivers.
[58] A CAN notice was issued because the Wallan–Whittlesea Road level crossing protection was affected by the signalling system failure and was being manually operated.
[59] TA20 Section 5 Rule 5 Clause b stated ‘Light signals not in use are distinguished by a black cross on the front of the lights. The lamps are not to be lit’.
[60] Some V/Line drivers and the RTBU (Rail Tram and Bus Union) had expressed concern at signals remaining lit within the affected section. On 10 February, a driver refused to pass a lit signal within the section without authority to proceed.
[61] Rule 1, Section 3, pertained to the process when stopping at and then passing automatic signals that were displaying a stop indication. When applied, the rule required the train to proceed with caution and at a speed not exceeding 25 km/h.
[62] In doing so, the train authority was issued by the NCO to the signaller rather than a driver.
[63] Issued because the Wallan–Whittlesea Road level crossing protection was being manually operated. TA20 section 1, clause 7, described the issuing of a CAN warning in a range of scenarios that included faulty or deactivated level crossing warning equipment.
[64] Figures for train authorities issued includes all notices issued until the derailment of ST23, including those issued after the issue of Train Notice 367.
[65] The NCO involved was not the NCO on duty at the time ST23 transited the affected area.
[66] The same ‘anomaly’ existed in the descriptions for southbound travel
[68] There was no available evidence with respect to the communications between the driver of ST23 and the AQW.
[69] Temporary speed restriction: a speed, less than the maximum allowable permanent signposted speed, applied for track, signal, train equipment, or environmental conditions.
[70] Preparation and Distribution of Operational Notices OPE-PR-001, Version Number 1.2, 31 May 2019
[73] The ARTC procedure specified that proposed standing train notices should be lodged (with ARTC operational staff) at least 10 days prior to their application, although it did not specify a publication timeframe requirement.
[74] The update of WebRAMS was reported to have been actioned in Adelaide at 1815 central daylight time, which was 1845 eastern daylight time.
[75] The WON was published by the Office of Rail Safety Manager (a part of MTM) on behalf of MTM and V/Line.
[76] SAFE Notices are used by ARTC on its NSW and Queensland corridors to give notice of changes or exceptions to ARTC Network information publications.
[77] Although consistent with the process used by signallers and AQWs in the previous weeks, TN 266 described that ‘the signaller will deliver the Train Authority and CAN to the driver of the rail movement as required’.
[78] At the time of the derailment, Issue 2.1, 01 July 2018
[79] Safeworking is an integrated system of operating rules and procedures that defines the interaction between workers and engineered systems. Of primary concern of a rail safeworking system is safe operations including train separation and speed management.
[80] Rule 1, Section 3 specified proceeding at a speed not exceeding 25 km/h.
[81] The phrase ‘Train Authority Working’ was used in section 25 of TA20. ARTC advised that this type of working had previously been used in Victoria during commissioning activities following signalling system upgrade.
[82] The scope of application of train authorities was similarly defined for the Train Order System.
[85] There were a number of other scenarios for which a CAN would be issued including a temporary speed restriction.
[86] The application was, however, inconsistent with the rule that specified that the ‘Network Controller must dictate the CAN warning details direct to the rail traffic crew'. There was provision for relaying the message when direct communication between an NCO and a driver was not possible. However, radio communication was possible.
[87] Advanced train management system that monitors and manages rail traffic
[88] ARTC and Rail Corporation New South Wales (RailCorp) entered into an interface agreement in 2011 for RailCorp operations on the ARTC network. The functions of Railcorp were transferred to NSW Trains and other entities on 1 July 2013 and at the time of the derailment of ST23 at Wallan in February 2020, the 2011 interface agreement was the applicable interface agreement between ARTC and NSW Trains.
[89] ARTC (2019) RSK-PR-001 Risk Management, version 1.4
[90] The objective of AS ISO 31000:2018 is described within the standard as being to provide guidelines on managing risk faced by organisations. The application of these guidelines can be customised to any organisation and its context, is not industry or sector specific, and the standard also provides a common approach to managing any type of risk.
[91] ARTC (2019) Application of Risk Management, RSK-WI-001
[92] Approximate time of risk assessment advised by ARTC.
[93] The plan did not identify individual risk owners as required by the ARTC risk management procedure.
[94] The risk assessment reference to ‘piloted’ is different to TN 266 that refers to an accompanying qualified worker (AQW).
[96] ANRP 710 Piloting Trains and Track Vehicles, Network Procedures (11 October 2015). This document was only applicable to the NSW portion of the ARTC network.
[97] A competent worker was defined as a worker certified as competent to carry out the relevant task (RISSB).
[98] Route knowledge: Essential knowledge required to enable rail traffic crew to work safely over a route (Standards Australia 2017).
[99] The speed display on XP2018 would have been reading about 127 km/h.
[100] No. 7 points were controlled by a dual-control point machine. They could be operated in motor (remote operation) or hand (manual operation) mode.
[101] Crossing block: a casting or fabricated steel component that enables a wheel travelling along one rail to pass through the rail of a track which crosses its path.
[102] Following the derailment, the windscreen was removed by rescuers to improve access to the driver’s cab.
[103] Given the age of the power car and its apparent compliance with door loading specified in contemporary standards, there was no attempt to assess the door against loading requirements in historical standards.
[104] AS 7522:2021 Access and Egress, Rail Industry Safety and Standards Board, sections 6.1.6 and 6.3.3.9
[105] There were also reports of instances of post-traumatic stress disorder (PTSD) that are not included in this injury total.
[106] A serious injury was defined in the Transport Safety Investigation Regulations 2021 as an injury that required, or would usually require, admission to hospital within 7 days after the day when the injury was suffered. A minor injury was any other reported physical injury that did not meet the serious injury threshold.
[107] Exits were considered not usable (by height) if the bottom rung of the ladder was more than 1.5 m from the ground.
[108] NSW Trains Competence Assurance; NSW Trains Risk Based Training Needs Analysis, NSW Trains, 2019.
[109] The rail safety regulatory functions of this body were transferred to the national regulator, ONRSR.
[110] Activities were reviewed for the period January 2015 to 20 February 2020.
[111] Under the ONRSR reporting scheme, overspeed incidents were captured in the broader category of safeworking rule or procedural breach. ONRSR provided details of 262 incidents in this category, and 11 were identified as overspeed.
[112] Audit activity 3827 (November 2018) referred to the risk of passenger train derailment as a result of overspeed.
[113] Between 2000 and 2006, the Regional Fast Rail (RFR) project in Victoria upgraded track and signalling infrastructure on major regional lines to allow passenger trains to run at speeds of up to 160 km/h. RFR contractors Thiess-Alstom Joint Venture (TAJV) and Regional Rail Link (RRL) offered the TPWS to provide additional protection from the risk of trains passing signals (at stop) without authority and potentially colliding with other trains or derailing. The rail safety regulator at the time of the project was satisfied that TPWS was a suitable system for use in Victoria based on independent advice that TPWS was compatible with Victorian signalling principles and could be implemented with minimal changes to Victorian rail industry signalling standards, operating rules or maintenance practices, and it was a proven system having been in operation in the UK since 2000.
[114] The speed display on XP2018 would have been reading about 127 km/h.
[115] This is a nominal figure incorporating driver reaction to cues and system response. Human reaction times may vary considerably due to individual differences and other factors such as expectation and workload.
[116] The distance range is an estimate only, and the cues to make a brake application may have presented earlier.
[117] The ability to observe the points setting would have depended on several factors including the train’s distance from the points, lighting conditions at the time, the environment of the driver’s cab, and the eyesight of the individuals.
[119] With signals initially lit and then several trips with all signals within the section extinguished.
[120] A conspicuous warning device is a permanent or temporary indication which provides information to, or requires action to be taken by, train crews.
[121] Rail Safety National Law (SA) Act 2012, Part 3, Division 6.
[126] TLIC0030 (Pilot rail traffic with due consideration of route conditions) released in 2022 (after this occurrence).
[127] For these circumstances, TA20 also specified the use of CTC arrival messages within the section.
[128] As described in the ARTC Risk Management Overview - Workshop participants guide (2018). This stated that ‘two key factors to consider when determining the effectiveness of a control are: whether the control is adequate, and how susceptible the control is to human error or non-compliance’.
[130] Such systems can be found on the Country Regional Network (CRN) in NSW that is managed by UGL.
[131] Track Force Protection involves the use of hand signals and audible track warnings to control the movement of rail traffic through a worksite.
[132] The same system was used for distributing notices in South Australia and Western Australia
[133] The ARTC ERMS risk control of advanced train management system (ATMS) was not operating in Victoria, and the risk control of two-person train operation was not applicable to V/Line or NSW Trains passenger train operations which operated with single-person crewing.
[134] Train enforcement pertains to the forced (automated) initiation of train braking in the case of train overspeed.
[135] TPWS was used elsewhere in Victoria (on regional and metropolitan networks) to enforce braking of V/Line trains passing a signal at stop or detected as travelling too fast to comply with the next signal.
[136] TPWS was scheduled for installation at Wallan Loop in 2024.
[137] TfNSW advised that the new NSW TrainLink regional trains (Regional Rail Project) will be fitted with automatic train protection (ATP) systems that are compatible with the Sydney Trains network (ETCS Level 2) and provisioned to allow the future fitment of onboard systems to interface with the ARTC advanced train management system (ATMS).
[138] Examples include the advanced train management system (ATMS) on the ARTC network, the European train control system (ETCS) of various levels, and communications-based train control (CBTC) systems.
[139] The National Transport Commission (NTC) is progressing a rail interoperability framework through an Interoperability Advisory Group. The NTC was established through the National Transport Commission Act 2003 and the Inter-governmental Agreement for Regulatory and Operational Reform in Road, Rail and Intermodal Transport.
[140] While AS 7552:2021 states that ‘enclosed cabs of rolling stock shall be fitted with sufficient emergency exits to provide escape paths to the vehicle exterior when the vehicle is upright and when overturned on the side’, these emergency exits may not be accessible at ground level.
[141] Static testing was conducted on power car XP2018 as the trailer cars immediately behind in the consist were damaged and without significant repairs could not be tested. Some components of XP2018 damaged during the derailment required repair in preparation for the brake testing.
[142] The variation in the cross-level between two track locations separated by a nominated distance interval.
[143] Due to the delay in the service on this day, arrival in Melbourne would have been later than the rostered end-of-shift.
[144] Adopted by ARTC as Code of Practice for the Defined Interstate Rail Network, volume 3 operations and safeworking, Part 1: Rules, ARTC Version 3.0: 01 July 2018 (also referenced Issue 3.0- ARTC Annotated Version)..
[145] RISSB developed the Australian Network Rules and Procedures into a National Rules Framework. The Framework provided a principles-based platform for rail transport operators in development of their own rulebooks.
[146] An average wheel diameter was used to accommodate wear and a reducing diameter during the wheel’s life.
[147] The ICE radio GPS speed is not displayed to the driver in the locomotive cab.
[148] The speed display on XP2018 would have been reading about 127 km/h.
[149] Braking data for XPT full-service braking (with 80% average deceleration), full seated load and a 1:150 descending grade indicates a stopping distance from 130 km/h of 1,120 m.
[150] Includes braking system response and driver reaction. Reaction times of individuals can vary considerably.
[152] Actual speed calculated by correcting the recorded speed for actual wheel diameter. The recorded speed was about 2% lower than this estimated actual.
[153] AS 7527:2015 (amendment 2019) recommended that legacy, tape based data loggers should, as a minimum record the following information: train speed, distance, time, and brake status (i.e. brake pipe pressure or brake cylinder pressure).
Interim report
Report release date: 10/06/2021
This Interim Report details factual information established in the investigation’s evidence collection phase and ATSB interim observations of that evidence. An Interim Report has been prepared to provide progress information to the public and the rail industry, and information on safety actions so far taken. This Interim Report does not contain findings or safety factors, that will be detailed in the Final Report.
The information contained in the Interim Report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 (Cth).
Prior to the occurrence
At about 2343[1] on 3 February 2020, the Australian Rail Track Corporation (ARTC) identified that Centralised Traffic Control (CTC) signalling had been disrupted on the Somerton to Albury line between Donnybrook and Kilmore East. A subsequent investigation by ARTC determined that a road vehicle had struck overhead wiring in Wallan, impacting power supplies to the rail signalling system. A fire in the Wallan signalling hut led to extensive damage to equipment and cabling.
As a result of the damage to the signalling system at Wallan, ARTC commenced managing rail traffic through the location using Caution Orders. Under this instrument, trains were required to proceed cautiously, resulting in significant delays to rail services using this section of the standard-gauge network. As repair of the signalling system was expected to take a significant period of time, alternative train working arrangements to Caution Orders were considered by ARTC.
ARTC commenced managing rail traffic through the location using a Train Authority[2] instrument on the evening of 6 February.[3] The instrument was used for the 24 km section between Kilmore East (at about the 63.8 km[4] mark) and Donnybrook (at about the 40.2 km mark). Wallan Loop was located between these locations, from the 49.058 km mark to the 47.268 km mark.
Notification to network users of the change to the use of Train Authorities was by an ARTC Train Notice.[5] The relevant Train Notice (TN 266) was issued on 6 February, updated on 7 February and further amended on 13 February. In the arrangements established, the points at Wallan Loop had been set for the straight and locked in that position. ARTC did not impose any additional speed restrictions through the section. The maximum permitted speed for the XPT when travelling on the main line through Wallan was 130 km/h.
On 19 February, Train Notice TN 266 was supplemented with a further Train Notice (TN 367) advising of a change at Wallan Loop, with trains to be diverted through the loop for a short period on 20 February. The purpose of routing trains through the loop was to remove any contamination that may have developed on the rail head while the loop track was not being used.[6] This was in preparation for signal system testing and re-establishment of the CTC signalling system over the coming days.
Between 1453 and 1536 on 20 February,[7] the points at either end of Wallan Loop were manually reconfigured from their Normal position to their Reverse position.[8] This change meant that rail traffic travelling in either direction after this time would be diverted from the main line into the crossing loop track (No.2 Road). Train Notice TN 367 reflected this change and also specified a 15 km/h speed limit for entry into the loop, and a limit of 35 km/h when exiting the loop. Between 1600 and 1837, Track Force Protection[9] for the laying of conduit was also in place near Wallan, between the 46.3 km and 45.4 km marks.
The first train to pass through Wallan Loop in this altered configuration was southbound V/Line train 8620. Immediately prior to train 8620 departing Kilmore East, the train controller advised the driver that they were going to be the first train through Wallan Loop in the past 72 hours. It departed Kilmore East at about 1623 and the Train Authority was cancelled at 1647 for its arrival at Donnybrook.
The second train through the loop was northbound V/Line train 8625. When stopped at Donnybrook and during exchanges between the driver and the network controller, there was no mention by either party of transiting through Wallan Loop. The train departed Donnybrook at about 1857. Train ST23 operated by NSW TrainLink was to be the third train through the loop.
Train ST23 from Sydney to Albury
On 20 February 2020, passenger train ST23 departed Central Station in Sydney, New South Wales (NSW) at 0741, just after the scheduled departure time of 0740. ST23 was to travel through NSW, and into Victoria to its destination in Melbourne (Figure 1).The service was scheduled to stop at several stations en-route to arriving at its final destination at Southern Cross Station (Melbourne) at 1830 that evening. ST23 comprised leading power car XP2018, five passenger cars of varying configuration, and a trailing power car.
Figure 1: Train route from Sydney to Melbourne
Source: Google Maps, annotated by CIT
The train proceeded south and arrived at Junee in southern NSW at 1452,[10] about 85 minutes behind schedule. ST23 was a single-driver operation, and there was a change of driver at Junee. The train departed Junee at 1456 and continued south, arriving in Albury on the NSW-Victorian border at 1637. There was a change in passenger services crew at Albury. The new passenger services crew comprised a Passengers Services Supervisor (PSS), a crew member training for the supervisory role, and three passenger attendants.
Train ST23 from Albury
The train departed Albury at 1644, about 89 minutes behind schedule, and entered the Victorian section of its journey. After departing Albury, the PSS made an announcement covering a welcome, the delay, and emergency procedures. Tickets were checked and crew walked through the passenger cars checking door locks and equipment. Later, the driver was provided with a snack while stopped at Wangaratta Railway Station and the train departed that station at 1722.[11] Beyond Benalla, the focus of several attendants was on meal activities in the buffet car. The crew described the journey as normal although passengers were reported to be frustrated with the delays.
At about 1840, ARTC Network Control[12] contacted the driver of ST23 regarding a network alarm that had been received.[13] Later in the communication, the network controller advised the driver that due to the altered train working, ST23 would come into Kilmore East and wait until a V/Line train had passed. As part of this communication, the controller mentioned that ‘you’re going via the loop there at Wallan’. The response from the driver did not reference the train’s route via the Wallan crossing loop.
Train ST23 at Kilmore East
The service continued south before coming to a stand at Intermediate Home[14] signal KME28, that was at Stop. It was about 1856. There was a standard-gauge passing lane at Kilmore East, with designated East and West Lines, and ST23 had been routed via the East Line (Figure 2).[15]
Figure 2: Kilmore East standard-gauge passing lane (shown in black)
The schematic shows the track at Kilmore East including the passing lane. Only the signalling for the standard-gauge track is shown. Source: ARTC, modified and annotated by CITS
The driver of ST23 contacted ARTC Network Control at about 1904 and inquired when they might receive permission to proceed. ST23 was required to wait until the V/Line train 8625 had cleared the single-line section.
At around this time, several rail workers were preparing for the arrival of ST23 at signal KME16. These rail workers were to assist with the alternate train working that had been implemented between Kilmore East and Donnybrook. Amongst these rail workers were an in-field signaller and an Accompanying Qualified Worker (AQW).[16] The AQW would board the train and accompany the driver from Kilmore East to Donnybrook. Both the signaller and the AQW had just started their shift and ST23 was the first train they were assisting that evening.
At about 1915 while ST23 was stopped at signal KME28, the in-field signaller positioned near signal KME16 contacted ARTC Network Control to advise that he had come on shift and taken over from the previous in-field signaller. During this call, Train Authority number 17 (TA17) for ST23 to proceed between Kilmore East and Donnybrook was issued to the on-ground signaller by the network controller. The controller read TA17, describing that the authority was issued in accordance with Train Notices 266 and 367, that the points at Wallan Loop were set and secured for number 2 track, and that there was a maximum speed entering the loop of 15 km/h, and a maximum speed exiting the loop of 35 km/h. There was then a full read back of TA17 by the in-field signaller. The network controller noted the time of the read back as 1920. A Condition Affecting Network[17] number 7 (CAN7) was then completed by the signaller under the instruction of the controller. This notice was to warn train crew of the condition of the Wallan-Whittlesea level crossing protection, and that the protection was being manually operated. The read-back of CAN7 by the in-field signaller was noted by the controller as being completed at 1921.
ST23 was held at signal KME28 on the East Line until the northbound V/line passenger train 8625 had transited the Donnybrook to Kilmore East single-line section, passed signal KME2 and was travelling along the West Line through Kilmore East. The V/Line train was clear of the single-line section by about 1925 and, soon after, ST23 was given permission by the network controller to proceed to Home Departure signal KME16,[18] still on the East Line within the Kilmore East location.
ST23 arrived at signal KME16 at about 1931. The train was met by several rail workers that included the in-field signaller and the AQW. The AQW boarded the lead power car and joined the driver at the head of the train. It was intended that the AQW would accompany the driver of ST23 for the 24 km section to Donnybrook. The XPT cab was not fitted with a cab voice recording facility (and was not required to be), and there is no record of the conversation between the AQW and driver.[19]
At about 1932 while the train was stopped at signal KME16, the driver and ARTC Network Control communicated via the train radio. This exchange included confirmation by the driver that he was in possession of ‘authority 17 and CAN number 7 filled out the same way it has been’.
During this communication between the network controller and driver, the controller did not read the content of TA17 to the driver and there was no read back of the content of TA17 by the driver.[20] The controller commented ‘points all set for the loop’. The driver’s response to the controller did not reference transiting via the crossing loop or number 2 track at Wallan. There was no communication between the controller and driver regarding the maximum speed of 15 km/h for entering the crossing loop.
The derailment of train ST23
The train departed signal KME16 at about 1934 and entered the single-line section towards Wallan. The line speed for the XPT between Kilmore East and Donnybrook was 130 km/h.[21] After departing from signal KME16, the speed of the train was increased and maintained between 100 km/h and 120 km/h.
The AQW was to ensure that the level crossing protection[22] at Wallan–Whittlesea Road in Wallan was in place for the passage of the train.[23] A Level Crossing Keeper (LCK)[24] was located at the crossing to perform the manual activation. The AQW contacted the LCK at approximately 1941, when the train was at about the 52 km mark. The LCK reported activating the crossing protection at Wallan–Whittlesea Road, and confirmed its activation to the AQW. This phone call lasted about 53 seconds and the LCK did not recall anything unusual about the communications with the AQW. The call had been completed when the train was about 4.5 km from the level crossing and 2.7 km from the entry to Wallan Loop.
At about 1943, ST23 was approaching the northern end of Wallan Loop at about the track’s line speed. A brake application was made a short distance before the turnout, probably between 50 and 153 m from the points. This slowed the train a small amount before it entered the turnout travelling at a speed probably between 114 and 127 km/h. The train was not able to negotiate the turnout to the crossing loop track at this speed and derailed. The leading power car rolled onto its left side. All vehicles derailed excepting the rear power car (Figure 3).
Figure 3: Aerial photograph of derailment site
Source: ATSB
Emergency response
At the time of the derailment, there were 155 passengers,[25] six train crew and the AQW aboard the train. The driver and AQW were in the driver’s cab, four passenger services crew were in the buffet car (the third passenger car) and another passenger services crew member was in the second passenger car.
After the train came to a stop, the PSS called the train crew on a hand-held radio and received responses from the other members of the passenger services crew. However, the driver did not respond and the AQW was not in possession of a NSW Trains issued radio.
Around this time, members of the train crew attempted to report the emergency using their radios. A V/Line signaller based at Wallan heard and responded to one of the emergency calls. The Wallan signaller contacted Centrol[26] and, at about 1945, Centrol contacted ARTC Network Control at Junee relaying the information that the XPT may have derailed. In this conversation, Centrol also advised ARTC that V/Line would stop trains on the broad-gauge tracks that ran parallel to the standard-gauge. In response to the Centrol call, ARTC initiated its response.
Emergency services recorded the first ‘000’ call for assistance from a train passenger, time-stamped 19:45:06.[27] This was followed by a series of calls from other passengers, members of the train crew, and members of V/Line and ARTC.
Around this time or soon after, some passengers started to self-evacuate from the train. A member of the train passenger services crew was allocated to manage passengers on the track, and two services crew members remained on the train to attend to passengers. The other two passenger services crew went to the lead power car. Here, they entered the power car through its the right-side cab door, accessible from the ‘top’ of the car laying on its left side. Finding it difficult to assist from within the cab, they then went to the outside and attempted to gain ground-level access by breaking the windscreen of the driver’s cab.[28] However, attempts by the passenger services crew to gain this ground-level access were unsuccessful.
The first emergency services to arrive on site was Victoria Police at about 2003, followed by further emergency, medical and fire services. However, both the driver and the AQW did not survive the accident.
As a result of the movement of the passenger cars during the derailment, eight passengers were seriously injured and 53 received minor injuries. The five passenger services crew located in the passenger cars also received minor injuries.
ST23 and the XPT fleet was operated by NSW TrainLink, the operating name of NSW Trains, an agency of Transport for NSW (TfNSW).[29] NSW Trains provided passenger services in regional NSW and between the east coast capital cities of Melbourne (Victoria), Sydney (NSW) and Brisbane (Queensland).
Train crew
The driver
The driver of ST23 had been associated with the rail industry for about 40 years, employed in a range of roles including driving, training, and management. They returned to driving in mid-2016 as a Regional Driver with NSW Trains and were assessed as competent on the Junee - Melbourne route in July 2019.The driver had been medically assessed as fit-for duty (unconditional) in accordance with requirements for a Category 1 Safety Critical Worker.[30]
The driver regularly drove the XPT services between Junee and Melbourne. They would run the Junee to Melbourne leg and, following a period of rest in Melbourne, the return leg to Junee. After the commencement of alternate train working through Wallan on 6 February 2020, the driver ran the Junee–Melbourne–Junee round trip (including a rostered rest period in Melbourne) four times between 8 and 19 February. On 20 February, the driver’s shift commenced at Junee at 1315 and the scheduled sign-off time in Melbourne was 1845.[31]
The accompanying qualified worker
The Accompanying Qualified Worker (AQW) aboard ST23 was employed by Programmed: a labour-hire organisation that provided skilled workers across a range of industries including transport. Programmed supplied several personnel to ARTC from 4 February for the management of rail traffic between Kilmore East and Donnybrook.
The AQW had been with Programmed since 2006. Records[32] indicate that the worker had been engaged by several rail operators in Victoria in various roles, in recent years primarily as a Track Force Protection Coordinator or hand signaller. The AQW was certified to Track Protection Coordination level 3.2, most recently renewed in March 2019. They had been medically assessed as fit-for duty (unconditional) in accordance with requirements for a Category 1 Safety Critical Worker.
The AQW had been engaged at Wallan from 4 February, primarily in the role of Level Crossing Keeper at the Wallan–Whittlesea Road crossing. All shifts from February had been night shifts that mostly commenced at about 1900. On 20 February, the AQW had just commenced the night shift. This was their first shift providing AQW services through Wallan, and this was their first train that evening.
Passenger services crew
There were five passenger services crew aboard ST23, one more than the normal complement of four. The passenger services crew consisted of:
A Passenger Services Supervisor (PSS) responsible for overall supervision of the passenger operations
A Senior Passenger Attendant (SPA) responsible for the buffet operations and ticket sales
A Passenger Attendant 2 (PA2) responsible for general passenger duties along the train
A Passenger Attendant 4 (PA4) responsible for assisting the SPA in the buffet, and assisting with general passenger duties along the train
An additional crew member designated acting Passenger Services Supervisor (aPSS) who was shadowing the PSS as part of on-the-job training.
Train information
The XPT (Express Passenger Train) was first introduced into service in 1982 and was based on the InterCity 125/Class 43 design used in the United Kingdom. The fleet of XPT vehicles were maintained by Sydney Trains.[33]
The XPT operating service ST23 on 20 February 2020 comprised seven vehicles that included five passenger cars (Figure 4). The leading three vehicles were manufactured by ABB Transportation in Dandenong, Victoria and commissioned in 1993. The trailing four vehicles were manufactured by Comeng in Granville, NSW and commissioned between 1981 and 1984.
Figure 4: Train configuration
Source: Vehicle images supplied by Sydney Trains, annotation by CITS
The power car comprised a forward driver’s cab with two seating positions, ahead of the compartment housing propulsive machinery (Figure 5). The primary access to the driver’s cab was via its side doors.
Figure 5: Power car layout and cab seat arrangement
Source: RailCorp (NSW Transport), annotation by CITS
Infrastructure
Track
The XPT service was running on the standard-gauge track that connects Sydney and Melbourne. The track was part of the Defined Interstate Rail Network (DIRN) and was managed by the Australian Rail Track Corporation (ARTC).[34]
The standard-gauge track between Kilmore East and Donnybrook was a single, bi-directional line used by the XPT, V/Line passenger services and rail freight. There were passing lanes at Kilmore East and Donnybrook and a 1,550 m crossing loop at Wallan (Figure 6). The northern entry to this loop was located about 1.8 km north of Wallan–Whittlesea Road. At the southern end of the Wallan loop was Wallan Railway Station that serviced broad-gauge passenger trains.[35]
Figure 6: Standard-gauge track and signals at Wallan Loop
The schematic shows the standard-gauge track at Wallan including the crossing loop. The standard-gauge tracks are shown in black, and the adjacent broad-gauge tracks in red. Only the signalling for the standard-gauge track is shown in this figure. Source: ARTC, modified and annotated by CITS
Wallan Loop northern turnout
The turnout at the northern end of the Wallan Loop was located at the 49.058 km mark. For southbound trains approaching the northern end of Wallan Loop, there was a downhill gradient of approximately 1:150 and the track was tangent (straight) for about the final 800 m of the approach to the turnout. The approach track was comprised of 60 kg/m rail, fastened to concrete sleepers.
The turnout design was rated for a train speed of 25 km/h and the maximum operational speed was 15 km/h in accordance with the ARTC operating code of practice.[36] It consisted of 60 kg/m rail on timber bearers, with a cast V-crossing.
Following the left turnout, the right curve (in the direction of travel) leading onto the No. 2 Road had a radius of about 422 m.[37][38]
Signals
Entry to the northern end of Wallan Loop was normally controlled by signal WLN8. Signal WLN8 was a 3-position Home signal able to authorise movement in the Up direction. When operational, signal WLN8 could provide ‘Clear Normal Speed’, ‘Low Speed Caution’ or ‘Stop” indications (Figure 7). For movements into the crossing loop, the ‘Low Speed Caution’ indication would be used.
At the time of the derailment, signal WLN8 was extinguished and was fitted with a black cross near its base to indicate that it was not functioning (Figure 7).
Figure 7: Signal WLN8 possible indications (left) and on day of occurrence (right)
The figure shows the possible indication for signal WLN8 (when operational), and a photograph of the signal extinguished on the day of the occurrence. The photograph of signal WLN8 also shows the black cross that was attached to the signal post. Source: CITS
A broad-gauge distant signal was located about 45 m to the north of WLN8 and was probably indicating a Proceed (green) aspect at the time ST23 passed (Figure 8).[39] This broad-gauge signal did not apply to the operation of ST23 that was running on the standard-gauge line.
Figure 8: The tracks and signalling at the northern end of Wallan Loop
The photograph shows the approach to the Wallan Loop turnout. The photograph has been modified to show the extinguished state of standard-gauge signal WLN8 and the probable Proceed (green) indication of broad-gauge distant signal at the time of the derailment. The black cross that was fitted near the base of signal WLN8 at the time of the derailment is not shown in this figure. Source: V/Line training video, with signal indications modified and annotated by CITS
Environmental conditions at Wallan
Weather
The conditions at the derailment location were dry. At 1930 at the nearest weather station at Kilmore Gap,[40] the temperature was recorded as 13°C, and the wind was from the south at 32 km/h.
Location of sun
The derailment occurred about 30 minutes before sunset. At 1943 at Wallan, the sun was at an azimuth[41] of 259°48'28" and altitude[42] of 5°02'59".[43] The direction of travel was 223° from true north, meaning the sun was about 36° to the right of the driver’s direct view ahead.
Management of rail traffic (safeworking)
Safeworking systems and rules
Purpose
Safeworking is an integrated system of operating rules and procedures that defines the interaction between workers and engineered systems for the safe operation of a railway.[44] Of primary concern is safe operations including train separation and speed management.
Operating rules
ARTC operating rules for Victoria were defined in the ARTC Code of Practice for the Victorian Main Line Operations (TA20).[45] This Code formed part of ARTC’s Safety Management System (SMS).[46] The Code described two safeworking systems, Centralised Traffic Control (CTC) and the Train Order System.[47]
Centralised Traffic Control
Prior to the signalling hut fire at Wallan in February 2020, standard-gauge rail traffic through this section was managed using the CTC system of safeworking described in section 17 of TA20. In the case of signal failure in a CTC system, this section provided for the use of Caution Orders. The Caution Order form used in conjunction with a CTC system required that traffic ‘proceed cautiously’ …. ‘in accordance with Rule 1, Section 3’.[48]
Train Authorities
The procedures associated with Train Authorities were specified in section 25 of TA20, and also in section 17 for the CTC system. The circumstances specified for the use of Train Authority with a CTC system were:[49]
To assist a disabled train
Train to return to the crossing loop in the rear
Working a train to the point of an obstruction on one or both sides.
The Code specified that ‘Train Authority Working[50] must be used as specified by the individual operation of the safeworking system’.
ATSB observation
The use of Train Authorities in the circumstances that were present through Wallan in February 2020 was not provided for in the ARTC Code of Practice for Main Line Operations (TA20).
Use of Train Authority working in previous projects
ARTC advised that Train Authority working had previously been used during commissioning activities, often following signalling system upgrade.
Implementation of Train Authority working at Wallan
Background
Late on 3 February 2020, the Australian Rail Track Corporation (ARTC) identified that signalling had been disrupted between Donnybrook and Kilmore East. As a result of the damage to the signalling system, ARTC commenced managing rail traffic through the section using Caution Orders. To reduce traffic delays associated with Caution Orders, ARTC commenced managing rail traffic through the location using Train Authorities from 1900 on 6 February.[51]
Resourcing for altered train working arrangements
ARTC implementation of altered train working arrangements between Donnybrook and Kilmore East involved the engagement of several contractors. ActivateRail[52] was contracted to provide specialist rail project services, and labour hire firms Programmed and ARG Rail[53] supplied several rail workers.
Establishment of altered train working arrangements
A system of train working was established between Home Departure signals at Donnybrook and Kilmore East and notified by the issue of Train Notice 266. In this notice, operators were advised that rail traffic would operate by means of Train Authority. The notice included the processes that would be used and also advised that the points at either end of Wallan Loop would be clipped in the Normal position. Signage would be located at either end of the affected section advising drivers of the demarcation between CTC and Train Authority working.
Issuing of Train Authorities in the altered train working
The system used in February 2020 for issuing a Train Authority to a driver travelling between Kilmore East and Donnybrook involved the on-duty ARTC Network Control Officer (NCO) at Junee, an in-field signaller and an accompanying qualified worker (AQW). The key steps used in practice were:
The in-field signaller was provided with partially completed Train Authority (TA) forms.
The in-field signaller positioned themselves at whichever end of the Kilmore East – Donnybrook section that was to receive the next train.
Prior to the arrival of the next train, the in-field signaller contacted the NCO to obtain details of the TA specific to the next train movement. The NCO dictated the details of the TA to the signaller and the signaller completed the form accordingly.
The in-field signaller would then read back the completed TA to the NCO to verify its contents.
A Condition Affecting Network (CAN)[54] notice was also completed by the signaller under the instruction of the controller.
The in-field signaller would give the completed TA to the AQW (together with the CAN) and, on the train’s arrival, the AQW would board the driving cab of the train. There was no contact between the in-field signaller and the driver of the train.[55]
Once on board, the AQW would give the TA and CAN notice to the driver. The driver would then contact the NCO to verify the TA. ARTC required the driver to verify the TA by its number. There was no expectation that the driver would read the TA to the NCO.[56]
The use of Train Authorities between Kilmore East and Donnybrook in February 2020 was notified in Train Notice 266 (TN 266), issued on 6 February 2020 and commenced at 1900 on that day.
TN 266 was amended and reissued on 7 February. This amended notice advised that, in exception of a rule[58] within TA20, some disarranged signals may be lit, and that they would have a black cross affixed to the signal post.[59]
TN 266 was further amended and re-issued on 13 February 2020. Amendments included:
Removal of the advice that signals in the section may remain lit.[4]
Addition of text advising that ‘Repeat Back of the Train Authority is not required to be undertaken by the driver of the rail movement’.
Replacement of ‘The rail movement may proceed through the section in the normal manner’ with ‘The rail movement may proceed through the section up to track speed as advised by the Accompanying Qualified Worker’.
Train Notice 367 was issued on the evening of 19 February 2020 and contained additional instruction to TN 266. It advised that ‘In addition to instructions contained in Train Notice 266 / 2020 issued on 13/02/2020 the following temporary alteration to working will apply’.
TN 367 included advice that:
the points at Wallan Loop would be set for the No. 2 Track and that the maximum speed at entering the loop was 15 km/h and the maximum speed exiting the loop was 35 km/h.
TN 367 also included advice that ‘The Accompanying Qualified Worker must remind train crews of trains that the train will operate via No. 2 track at Wallan’.[62]
New, part-completed, Train Authority forms that included detail consistent with TN 367 were issued to the in-field signallers and ARTC Network Control, replacing the previous Train Authority forms.
Risk management
Safety Management System
ARTC’s Safety Management Systems (SMS) included procedures requiring risk assessments for standard and ‘out-of-course’ safeworking arrangements.[63] This procedure identified the potential need for a risk study or assessment for a range of activities and system changes. The procedure for risk management specified that formal risk studies were usually undertaken for complex activities where potential impact was likely to be significant. The listed types of activities where a formal risk study may be appropriate included:
Significant civil works, such as tunnel construction, bridge construction
Technical operational changes, such as introduction of new signal/track infrastructure
Safety critical system changes, such as network control system changes.
The procedure also specified that formal risk assessment was undertaken in order to identify potential risks, their causal and contributory factors, the likelihood and consequence of the risk eventuating, and controls that may be implemented to prevent the risk or otherwise minimise the impacts of the risk. It specified that a formal, documented risk assessment must be conducted in various circumstances (including when notifiable changes are planned to the SMS and/or network configuration and as directed in project management procedures). This could include the identification and assessment of risks associated with:
Achievement of organisational objectives
Operational activities of the organisation
Projects
Impending changes to the organisation, operational environment or systems.
Risk assessments associated with altered train working through Wallan
Initial risk assessment
A risk assessment for the operation of rail traffic between Donnybrook and Kilmore East by Train Authority working was reported as being conducted at approximately 1600[64] on 6 February 2020 and the associated documentation finalised on 7 February. The risk assessment involved representatives from ARTC and ActivateRail and was based on previous applications of Train Authority working by ARTC.
The risk assessment for Wallan contained 10 identified hazards and associated control measures. Hazards and risks associated with routing trains through Wallan Loop were not directly identified in the risk worksheet. Hazard number 2 (Rail Operators not aware of the altered working) was indirectly relevant to any potential train operations through the loop (Table 1).
Table 1: Extracts of risk assessment for altered train working
Hazard
Caused by
Worst Outcome
Control
Risk Rank
2
Rail Operators not aware of the altered working
Train notices not received by train crews detailing the processes in place
Train driver accepts the train authority and proceeds into the section not conversant with the altered working
Train Notices will be issued in a timely fashion.
Signals at the interface of the commissioning will have change of Safeworking signage to indicate the interface between CTC and Train Authority working.
Disarranged signals will have black crosses affixed to them.
ARTC reported that the risk worksheet was released to V/Line and Programmed. NSW Trains and freight operators were not included in this distribution. The documented risk assessment was not updated after 7 February 2020. However, ARTC has advised that risks relating to the altered train working continued to be informally assessed as feedback was received and that changes were reflected in the amendments made to Train Notice 266.
Risk assessment for travelling through Wallan Loop
There was no documented risk assessment specific to the routing of trains through Wallan Loop on 20 February and the release of Train Notice 367. The risk controls adopted for this change included the provision of information to operators through the issue of TN 367, and a note within that notice that the AQW was to advise the driver that the train will operate via No. 2 Track at Wallan Loop and of the speed limits required (for entry to and exit from the loop).
ATSB observation
Formal risk assessment was not used to identify hazards and available risk controls to manage the risk associated with train overspeed at the entry to Wallan Loop.
Distribution of safety notices
ARTC
Procedures defined the processes to be followed for preparing, reviewing, approving and issuing Operational Notices (including Train Notices) on the ARTC Network.[66] Different processes applied to different parts of the ARTC network.
Approved operational notices for Victoria, South Australia and Western Australia were published on the ARTC WebRAMS (Rail Access Management System) portal.[67],[68] Standing Train Notices were specified as being uploaded to this portal at approximately 1800[69] each evening. Access to WebRAMS was available to ARTC customers and stakeholders via an allocated User ID system. Rail operators were required to access the safety notices through this portal.
For the New South Wales and Queensland network, the ARTC procedures for distribution of operational notices specified direct transmission to selected internal and external stakeholders.
ARTC Distribution of Train Notice 367
Formal distribution of Train Notice 367 by ARTC to rail operators was via the WebRAMS portal. ARTC reported that TN 367 was uploaded to WebRAMS as part of an automated system update at 1815[70] on 19 February 2020.
In addition to the formal release, information regarding transit via Wallan Loop and the release of TN 367 was shared with V/Line. There was no active engagement by ARTC with, or direct release of TN 367 to, NSW Trains or freight operators.
NSW Trains
Sources of safety information for operation on the Victorian network
For its operations within Victoria, NSW Trains drew on Weekly Operational Notices (WONs) prepared by Metro Trains Melbourne (MTM) and issued each Tuesday for the week commencing the Wednesday.[71] The WONs included safety information for metropolitan and regional services. The WONs did not, however, typically include ARTC Train Notices, and reference was instead made within the WON to the ARTC WebRAMS portal.
NSW Trains did not routinely interrogate the ARTC WebRAMS portal for network operational information related to its Victorian operations. For its operations on the NSW portion of the ARTC network, it received train notices directly from ARTC.
ATSB observation
NSW Trains systems for obtaining network safety information for operations within Victoria did not include accessing information via the ARTC web portal.
Distribution of safety information to drivers
Each week, information considered relevant to its Victorian operations was extracted from the WON. This was used to produce an information pack for its regional drivers that would operate in Victorian territory. This information pack was then placed in the pigeon-hole of each driver at their Junee base. It was the driver’s responsibility to collect information from their pigeon-hole.
NSW Trains distribution of Train Notice 367
No evidence has been identified to indicate that NSW Trains was aware of Train Notice 367 prior to the occurrence. WON Issue No. 07 that was published on 18 February 2020 did not include information from TN 367. Extracts from WON 07 were prepared for distribution by 1139 on the morning of 20 February and were reported placed in the pigeon-holes of regional drivers (at Junee) by 1247 the same day.
ATSB observation
NSW Trains and its regional drivers coming on shift were probably not aware of the issuing of Train Notice 367 by ARTC and the possible operation of the ST23 through Wallan Loop on 20 February 2020.
WON Issue No. 07 that was published on 18 February 2020 did contain Train Notice 266 (as amended on 13 February). This was the ongoing operational notice for the Kilmore East to Donnybrook section at the time of the release of WON 07. It’s direct inclusion in the WON was not standard practice, and was the result of V/Line re-issuing ARTC TN 266 (as amended 13 February) within its own system.
V/Line distribution of Train Notice 367
Normal V/Line process entailed driver supervisors checking the WebRAMS portal after the evening publishing of ARTC notices on that portal and distributing train notices to affected drivers.
In this instance, on the evening of 19 February, V/Line also published a V/Line safe working circular (SW.0024.2020) incorporating TN 367, for distribution to all drivers including those running broad-gauge services. The V/Line drivers that ran through Wallan Loop on 20 February were also contacted by their driver supervisor prior to their shift and advised of the change.
Derailment site information
Position of leading vehicles
The derailed train came to rest in a concertinaed arrangement. The lead power car had rolled onto its left side and decelerated at a higher rate than trailing vehicles (Figure 9).
Figure 9: Leading three vehicles in the derailment
The photograph shows power car XP2018 on its left side, and first two passenger cars A and B. Source: CITS
Of the passenger cars, the first (Car A) had the greatest tilt of about 30 degrees from the vertical. It had come to rest on a row of pine trees and its trailing end had bound with the next car, Car B (Figure 10). The row of pine trees had probably stopped Car A from rolling onto its side.
Figure 10: The derailed position of Car A (left photograph taken after removal of trees)
The left photograph shows Car A rolled to its left and supported by pine trees, and the right photograph shows the trailing end of Car A bound with the leading end of the next car, Car B. Source: CITS
Points position and turnout
At the time of the derailment, the points at the northern end of Wallan Loop were in their Reverse position to provide entry to the loop (Figure 11). The point mechanism had been placed into hand-mode [72] and the points locked in the Reverse position. The mechanism was also padlocked.
There were a number of witness marks on rails and within the track that indicated that wheels had derailed within the turnout. There were no derailment marks identified prior to the turnout.
Figure 11: No. 7 points at the northern entrance to Wallan Loop
Source: CITS
Train recorded information
The Hasler RT recorder
Power cars XP2018 and XP2000 were each fitted with a Hasler RT data recorder. The Hasler RT is an electro-mechanical device that records data onto a waxed paper tape (roll). Data recorded included speed, distance, time, a combined power-vigilance parameter, and brake cylinder pressure. The Hasler equipment included an analogue speedometer located on the driver’s console.
The Hasler tapes from the two power cars were recovered for analysis (Figure 12). During retrieval, the Hasler tape from XP2018 jammed in the recorder and was damaged. However, all information was recovered and data relevant to the investigation was not affected.
Figure 12: Hasler waxed paper rolls removed from power cars XP2018 and XP2000
The photograph shows the recovered waxed tapes. The centre roll is the tape from power car XP2000. The left and right rolls are the tape from power car XP2018 that jammed and was torn at one location. Source: CITS
Data processing
Unlike modern data logger systems that provide digital information for a wide range of operating parameters, Hasler recorders provide limited information in graphical format. In addition to the limited range of information, the format can introduce a loss of precision in the presentation of recorded data.
To process the data, both tapes were scanned and examined using photographic software. The traces for each recorded parameter were assessed for alignment with key events, such as start/stop points. Some horizontal re-alignment of parameters was required and both the horizontal and vertical scales of the images were calibrated for measurement.
Wheel diameter corrections
The Hasler used a pre-set (average) wheel diameter to calculate both speed and distance from the measured revolutions of the left-hand wheel on the second axle of the power car (wheel 3).[73] Actual speed may deviate from that recorded (and displayed) due to differences between this pre-set diameter and the diameter of the actual wheel providing the feed to the Hasler system. The actual measured wheel diameter for both power cars was larger than the pre-set value, hence recorded speed and distance were lower than the actual values.
The recorded values for speed and distance were corrected for the ratio of actual-to-pre-set wheel diameter (Table 2). The larger actual wheel diameter on the XP2018 (compared to the pre-set) meant that the recorded speed was about 2% lower than the actual train speed.
XP2018 – leading
XP2000 – trailing
Pre-set diameter (mm)
1000
1000
Measured diameter (mm)
1019.2
1011
Ratio (correction factor)
1.0192
1.011
Uncertainties in recorded data
An initial review identified a likely recording anomaly in the latter part of the XP2018 data. All channels recorded noise in the latter phase. An overlay of the data from the two power cars showed the discrepancy (visible as diverging speed toward the end of the data) and also confirmed that the speed data prior to this occurring was consistent (Figure 13).
Figure 13: Overlay of data recordings from XP2018 and XP2000
The image shows an overlay of speed records from power cars 2018 and 2000. It indicates consistent speed records after departing Kilmore East, then a consistent initial sharp deceleration of both cars followed by diverging speed records during the derailment. Source: ST23 Hasler recordings annotated by ATSB
There were also potential inaccuracies in the XP2000 data in the latter stages due to uncertainty in measured wheel rotation being an accurate measure of train speed during this phase.
Other sources of train speed
GPS data from the installed ICE radio system[74] was interrogated and used as a comparator for time, speed and position information. While only coarse GPS data was available due to the system’s polling frequency, it provided a source for comparison with the Hasler data and an enhanced confidence in the assessed train speed. The GPS data was also the primary source for locating the position of ST23 when stopped prior to signal KME16.
Throttle and braking events
One limitation of the fitted Hasler data recorder was that it did not record the positions of the driver’s throttle and brake handles. Instead it recorded a generic power ON-OFF parameter and brake cylinder pressure.
The data from both power cars indicated that, at a point just prior to the commencement of deceleration, the power moved from ON to OFF and there was a rapid increase in brake cylinder pressure. For each recording, the points at which brake cylinder pressure began to rise and then reached a steady state were determined. The steady state pressures were noted for each record and compared with expected values. For both power cars, the recorded pressure was above that expected for a Notch 7 (Full-Service) application (345 kPa). The pressure recorded on XP2018, the leading power car, was about 378 kPa which was in line with the pressure expected for an Emergency application (375 kPa). While the pressure recorded on XP2000 was lower, about 358 kPa, it was still substantially above the Full-Service value. These results indicate that it was very likely that the brake application was an Emergency application. The speed of the train at the commencement of braking was about 129 km/h.[75]
Location of rise in brake cylinder pressure
Due to known limitations and potential anomalies in the Hasler data recording, obtaining position information from the data with respect to fixed points on track was difficult to achieve with high levels of accuracy. Therefore, the position at which brake cylinder pressure began to rise and the speed at which the train entered the turnout could not be directly read from the Hasler data.
Instead, the Hasler speed and distance data was used to calculate estimates of position considering different known stop locations. This was cross-checked using data from other sources to provide greater confidence. The different methods yielded slightly different results, however all indicated that the brake application was commenced before entry to the Wallan Loop (Table 3).
Table 3: Estimated start of braking and speed at entry to turnout
Distance from brake cylinder pressure rise to No.7 points
50 m
153 m
Speed at No. 7 points
127 km/h
114 km/h
Train handling of ST23 during journey
The Hasler recordings and the GPS data were examined to evaluate any potential trend in speed exceedance by ST23 during the Victorian segment of the journey. The ARTC Route Access Standard specified a maximum speed for express passenger trains in Victoria (including the XPT) of 130 km/h in areas where no local speed restrictions applied.[77] The assessment focussed on any identifiable trends and did not include local speed restrictions that were remote from the event.
Review of the GPS data identified 11 speed peaks of between 133 and 137 km/h in the Victorian section. These exceedances within the GPS data were cross-checked with the Hasler recordings and similar peaks identified, including a maximum actual value of about 139 km/h.[78]
None of the over-speeds identified were for a significant duration. These observations suggest that the driver was targeting line speed and occasionally overshooting. There was no evidence identified to suggest unusual train handling.
Vigilance parameter
The locomotive was fitted with a vigilance system. The installed Hasler does not record all information on driver activity associated with the vigilance system and its information is therefore of limited value.[79] However, the Hasler does record a vigilance parameter. The last point at which the vigilance parameter was recorded as active was prior to the stop at signal KME 28. There were no vigilance parameter events recorded between ST23 departure from signal KME 16 and the occurrence.
Cab video and voice recording devices
Power car XP2018 was not fitted with in-cab voice or video recording devices, nor was it required. As a result, there is no available evidence with respect to any communications or interactions that may have taken place between the driver and AQW prior to the occurrence.
Voice and video recording within the driver’s cab would have assisted the investigation in ascertaining the interactions within the cab, and the potential identification and analysis of associated safety factors.
ATSB observation
Voice and video recording within the driver’s cab would have assisted the investigation in the identification and analysis of potential safety factors.
Rolling stock condition assessment
Overview
Scope of condition assessment
The assessment of rolling stock condition was led by OTSI. The assessment involved vehicle inspections, oversight and review of testing conducted by Sydney Trains on behalf of ATSB, and a review of maintenance records. Specific testing was conducted on braking, vigilance and communication systems. The twist characteristics of power car XP2018 were also assessed.
Assessments were conducted at several locations and included observations at the derailment site on 21 February 2021, inspection of vehicles XP2000 and XFH2108 at the Sydenham Maintenance Centre on 6 March 2020 and inspection of vehicles XP2018, XAM2179A, XL2229, XBR2155 and XF2201 at the Auburn UGL facility on 10 March 2020. Further inspection and testing was witnessed by OTSI at the Auburn UGL facility.
Summary findings of rolling stock condition assessments
Based on post-incident testing of safety critical systems including braking, vigilance and communications systems, vehicle and component inspections, and a review of maintenance records, no rolling stock condition or defect has been identified that was likely to have contributed to the derailment.
ATSB observation
Completed post-incident assessment of ST23 rolling stock did not identify a condition or defect that was likely to have contributed to the derailment. This included braking, vigilance control and radio communications systems.
Incident site observations
General
Observations were made at the derailment site prior to the rolling stock being moved. The preliminary observations did not identify evidence of rolling stock defects or equipment failures potentially causal to the derailment. All vehicles remained mechanically coupled although some couplers had sustained damage in the derailment. All bogies remained attached.
The derailed vehicles exhibited wheel tread damage consistent with (and typical for) running on track ballast. The wheels on the leading passenger vehicle (XAM2179) exhibited significantly more wheel tread damage than those of power car XP2018, suggesting that power car XP2018 had travelled in an upright derailed state for a shorter distance than the following passenger vehicle. This was consistent with the power car overturning early in the derailment sequence.
Brake controller position
At the time the site observations were made, the brake controller in the driver’s cab of power car XP2018 was in the Emergency brake position with the power (throttle) controller in OFF and the reverser direction in Forward.
Sydney Trains maintenance systems
Maintenance of the XPT fleet was managed using the Sydney Trains Enterprise Asset Management (EAM) system. Work orders were generated within EAM in accordance with the requirements of the Technical Maintenance Plan (TMP). The TMP specified the frequency of tasks required for the power cars and trailer cars. Maintenance inspections included Major Inspections and Trip Inspections (pre-release to service). In addition to the maintenance regime, heavy overhauls were conducted at specified frequencies.
The Major Inspection was typically completed at 90-day intervals and inspected the condition of the carriage in greater detail. The task list for each Major Inspection varied with the inspection cycle, with some tasks completed more frequently than others.
Review of maintenance system
Open work orders
At the time of the derailment of ST23, a number of work orders within the TMP were listed as Open. However, none of the Open orders were found to be relevant to the risk of derailment.
It was also found that vehicles of ST23 entered service with work orders for the Trip Inspection of all cars identified as Open. However, review of the task list identified that most tasks had been completed prior to the train entering service. Those tasks that were not completed were not considered potential contributors to the derailment.
Fault management
Open and closed faults for the 120 days prior to the derailment were reviewed. There were no open faults identified that would suggest the train was operating at increased risk relevant to the derailment sequence. Review of closed faults did not show any recent faults which might have been addressed incorrectly and created increased risk.
Bogies and wheelsets
Bogie overhaul and wheelset records
Review of bogie and wheel set sheets did not identify any areas of concern with the condition of the bogies at the time of overhaul or wheelset change. Assessment of bogie weights at time of overhaul were within specification. Braking components including brake levers and cylinders were within specified dimensions and clamping forces at the time of servicing.
Bogie post-incident overhaul
Overhaul of bogies from ST23 has not identified defects relevant to the derailment. Inspection and overhaul of all bogies was not yet complete at the time of finalising the Interim Report.
Condition of wheels
The last routine wheel measurement indicated flange and rim thickness were within engineering standards.
Wheel profile measurements taken following the incident were compared to the WPR2000 profile specified for these vehicles. No sharp flanges were identified, and profiles were within tolerance and generally close to the WPR2000 profile.
Braking and vigilance systems
Static brake testing and vigilance system
Static brake testing on power car XP2018 was conducted at Auburn, NSW.[80] The purpose of this testing was to determine whether the brakes were degraded prior to the derailment. In preparation for the static brake testing, some of the items damaged during the derailment were repaired and the testing supported by workshop services.[81]
Given the damage sustained by the rollover derailment, the performance of the braking system and the vigilance control system was better than expected. There was no evidence found that the brake system or vigilance control system on XP2018 contributed to the derailment.
Review of maintenance records for braking system
During the (pre) Trip Inspection, the braking system was required to be tested. The test consisted of a functionality check of the braking system including brake pipe pressure, automatic and electro-pneumatic brake function, driver safety system (operator enable handle and pedal) and the vigilance control unit. Sydney Trains was unable to provide brake testing capture sheets from the most recent Level 1 or Level 2 brake testing and advised that the tasks were completed and signed off within the EAM but no paper records were available. The absence of these brake testing sheets prevented a more detailed assessment of the brake condition at the time of these maintenance checks. However, a review of the fault history did not show any known faults.
Additional to the testing, there were no known reports of issues with the braking system during the journey of ST23 prior to the derailment.
Power car XP2018 response to track twist
A twist test on power car XP2018 was conducted at Auburn, NSW. The purpose was to determine this vehicle’s capacity to negotiate track twist. The twist test arrangements were in accordance with the twist (packing) described in RailCorp Standard ESR0001-200 (2013) that represented the standard current at the time of the derailment. For testing, vehicle suspension was retained in its as-derailed condition that included some contained debris, and some suspension damage.
The testing found a maximum wheel unloading of 57.3 per cent, compared to the maximum permissible value of 60 per cent. Given this result, it is unlikely the twist performance of this vehicle contributed to the derailment.
Train radio performance
Post incident function testing and log review
The radio system was function tested and logs reviewed to assess the condition of the radio system just prior to derailment. The train radio system had sustained damage during the derailment and antennas had been removed, resulting in some performance degradation during testing.
Based on results of radio function testing and the review of radio log files, the Sydney Trains specialist maintenance group responsible for the train communications concluded that there was no evidence to suggest that the on-board communications systems were non-operational or defective at the time of the incident.
Assessment of recordings of communication between the train driver and ARTC Network Control were consistent with the train radio system operating normally.
Maintenance records of communications system
The maintenance history for the communication equipment fitted to ST23 was reviewed, with the primary focus being power cars XP2018 and XP2000. The review found that the train radio system was within the required maintenance inspection timeframes and compliant at the time of the derailment. The most recent inspection of communications equipment on XP2018 was completed on 6 February 2020, and on 4 February 2020 for XP2000.
Rolling stock crashworthiness and survivability
Scope
The ATSB conducted crashworthiness and survivability inspections of the lead power car and the five passenger cars. Inspections included an examination of features pertinent to the survivability and evacuation of the train crew and passengers. The unoccupied rear power car remained upright and on track and was not inspected for its crashworthiness.
Inspections were conducted at the derailment site on 21 February. Power car XP2018 and the leading passenger (sleeper) car were further examined at the Auburn UGL facility on 10 March 2020.
Power car XP2018
General findings
Damage to the vehicle’s exterior indicated that the lead power car had slid on its side for some distance (Figure 14). The driver’s cab retained its structural integrity. However, the left-side cab door separated from the door frame, and the left-side engine room door at the rear of the power car was dislodged. Fuel tanks on the left side were also breached.
The car’s forward windscreen remained in place during the derailment. The screen was subsequently removed by rescuers to access the driver’s cab. The lower rear corner of the left-side quarter window had detached from the frame, sufficient to allow a limited amount of ground material into the cab.
Internally within the cab, equipment and fittings remained mostly intact. Instruments, control panels and interior linings contained little or no damage. The driver’s side (left-side) headrest was detached from the seat back.
Figure 14: Power car XP2018 at Auburn workshops 10 March 2020
Source: ATSB
Driver’s left-side cab door
The most significant damage to the power car was to the left cab entry door. The cab door had been secured with two hinges on its rear edge and a single door latch on its forward edge. The glass fibre composite doors were a plug shape and rotated inward on the rear door frame. The hinges were attached to the door and frame using bolts secured to embedded plates (Figure 15).
Figure 15: Door and doorframe section drawing
Source: Commonwealth Engineering (NSW) Drawing 022010940-1 annotated by CITS.
The door hinges had failed as a result of the external loading during the sliding event. The door had become disconnected from the door frame and loose within the cabin. The door-side fingers of the upper hinge had peeled open (Figure 16) and the lower hinge had failed by the loss of fastening on the frame-side of the hinge (Figure 17).
With the door aperture open, the rear of the door frame had acted as a scoop for ballast and dirt which accumulated inside the cab. A significant amount of material was found to have entered the cab space.
ATSB observation
The left cab door of the power car did not withstand the external loading associated with power car 2018 rolling on to its side. This resulted in materials entering the driver’s cab of the power car.
Figure 16: Upper internal hinge of left cab door of XP2018
Source: ATSB
Figure 17: Lower internal hinge of left cab door of XP2018
Source: ATSB
Evacuation routes from driver’s cab
The normal access to and from the driver’s cab was through the side doors. At the rear of the cab, there was an internal door to the machinery space and at the rear of that space there were a further two door exits either side of the car, and a rear central door. With the power car on its left side, the right driver’s cab door was the most accessible access route to the cabin and the crew inside. The right driver’s cab door remained operable and was used by members of the crew to gain access to the cab. This access route was only accessible by able bodied people climbing on top of the vehicle and there was no practical way to extricate any survivor if they themselves were not ambulatory.
ATSB observation
With power car XP2018 on its left side, there were no points of entry at or near ground-level.
Rear left door
The rear external machinery space entry door on the left side of the power car had also been dislodged but the top hinge did not fully part from the frame (Figure 18). There was a build-up of ballast and dirt at the base of the door.
Figure 18: The rear left-side door of power car XP2018
The left photograph shows a full view of the rear left-side door of XP2018, and the right photograph the base of the door pushed-in by track ballast and dirt. Source: ATSB
Passenger cars
Overview
Inspections did not identify any structures that would have generated injuries by their design. In the lead passenger car, some windows had been shattered introducing a hazard. It was also reported that luggage had fallen from overhead racks, some of which struck passengers and service staff causing injury.
Most injuries to passengers were a result of people being unprepared for the sudden deceleration or losing their balance when their car lurched or tilted. Passenger injuries were more prevalent and more severe in the forward passenger cars.
Passenger car XAM2179 (Car A)
XAM2179 was the leading passenger car and had a cabin/sleeper configuration. It consisted of nine cabins which could seat three passengers each. Some cabins had forward facing seats while others were rear facing. This sleeper car came to rest rolled to about 30 degrees to its left. External damage included four broken exterior windows on the left (passenger aisle) side of the carriage and exterior damage to the roof line above the windows from the passenger car striking pine trees adjacent to the track. The trailing end had also bound with the leading end of the following car, XL2229.
Damage within the sleeper car included collapsed interior lining in the passenger aisle. Two cabins had cracked glass partitions most likely from being struck by luggage or passengers (Figure 19).
Figure 19: Passenger car A, left-side corridor (left) and fractured glass partition (right)
Source: ATSB
Being the most widely spaced seats in the train, these occupants had the largest free-flight distance available that can lead to more serious injuries. The injuries in this car were most likely the result of passengers being thrown a significant distance before impacting structures and fittings. Injuries occurred to people sitting in both forward- and rearward-facing seats.
Passenger car XL2229 (Car B)
This was a first-class car with 56 forward-facing passenger seats in a single open cabin. It was seating an estimated 52 people at the time of the derailment. It was the car with the most reported injuries and the most reported serious injuries. The injuries were most likely the result of passengers being thrown from their seats or being hit by luggage falling from the overhead racks. The car came to rest at an angle of approximately 17 degrees to its right.
There was no evidence of structural failure or dislodged internal fittings acting as projectiles. The only significant damage to the cabin was exterior binding at the front right corner with the car ahead, Car XAM2179. This prevented the use of the exits at this location.
Passenger car XBR2155 (Car C)
This car was half first-class forward-facing seating with the other half being the buffet section. It was near upright when it came to a stop. The car suffered no interior damage of consequence.
Passenger car XF2201 (Car D)
This was an economy-class car with 68 forward facing passenger seats in a single open cabin. It was the most heavily populated car in the set with an estimated 57 passengers in this car at the time of the derailment. Comparatively fewer injuries were reported in this car. It was near upright when it came to a stop. The car suffered no interior damage of consequence.
Passenger car XFH2108 (Car G)
This car was half economy class forward facing seating with the other half being the baggage section. The baggage section was locked meaning there was only one pair of exits (forward) immediately obvious to passengers. A key to the baggage compartment was available behind breakable glass. This would have permitted a second set of exits to be used through the baggage compartment, however in this instance these rear exits were not used. This car was at an angle of about 10 degrees when it came to a stop and had the least number of reported injuries and the lowest injury rate. The car suffered no interior damage of consequence.
Evacuation routes from passenger cars
The majority of exits in passenger cars were available. Six of the 18 exits for passengers could be considered freely available. A further eight exits were operable and available but with some hindrance to their free use due to the distance from the ground, the angle of the access ladder, or some other hazard. Four exits were deemed not to be available, either due to obstruction, jamming or excessive height off the ground.[82]
Most people reported, and general evidence suggests, that the majority of passengers were able to evacuate without or with limited assistance. Some special needs passengers were assisted out of the carriages.
While not obstructing the evacuation, the angle of two carriages slowed some people getting off. The longitudinal angle of most cars was negligible, however the lateral angle (roll) of the front two passenger cars was significant.
Passenger information
Passenger numbers and injuries
Based on information supplied by the rail operator and Victoria Police, the total number of passengers on board ST23 at the time of the derailment was 155.[83]
Available injury information from the operator and police was combined with ATSB passenger survey response data to estimate a total number of passenger physical injuries of 61.[84] ,[85] This total figure was comprised of 8 serious injuries and 53 minor injuries.<[86]
Passenger survey
Overview
The ATSB conducted a survey of passengers that were aboard train ST23 at the time of the derailment. From 155 passengers reported to be on board, 83 responses to the survey were received: a response rate of 54 per cent. The survey included questions on:
passenger demographics
passenger seating location
safety information and briefings
experiences during and after the event
the nature of injuries.
Safety information
On questions pertaining to safety information:
Seventy per cent of passengers who responded to the question about the provision of safety information reported that they either did not receive any safety information or could not recall receiving any.
Of the 63 responses about the format of the safety information provided, eight passengers reported that they received the information from a briefing card.
Of the 74 responses to a question related to paying attention to the safety information provided, 57 per cent of passengers reported that they did not pay attention. Some passengers mentioned that the reason for not paying attention was that there was no information provided.
Seventy per cent of survey respondents reported that, prior to the event, they did not know how to get out of the train in an emergency.
In response to questions on suggestions for improvement in safety information:
Ten passengers referred to the way in which safety information is provided by airlines.
Some passengers mentioned that better signage on the seat in front of them or at the end of carriages may have been helpful.
Other comments included increasing announcements.
The evacuation
There were varied responses about the communication received from crew members following the derailment. This was at least in part due to the distribution of the crew, with four of the five crew being in the buffet car at the time of the derailment. There were no crew members in three of the cars at the time of the derailment. Most of the passengers who responded advised that initial crew instructions were to remain on board the train. Others reported being unsure about what to do. There was no report of any announcements being made via the public address system or the use of loud hailers.
Responses indicated that some passengers self-evacuated before receiving instructions from the crew. Passengers were asked to estimate how long it took to exit the train. The responses ranged from a ‘few minutes’ to up to 30 minutes, supporting other evidence that some passengers self-evacuated prior to being instructed by train crew. About half of the respondents indicated having difficulty exiting the train due to carriage orientation and/or difficulty with getting down to the ground.
Once passengers were out of the train, crew members were observed instructing passengers to move off the adjacent tracks (due to concern of possible rail traffic).
In response to questions on areas for improvement in emergency response, suggestions included:
a greater number of staff members to manage an emergency
crew training in emergency management
leadership and direction, including more information being provided to passengers
consistency in the information provided.
Sixteen respondents utilised the free text question to provide praise for the handling of the event by members of the train crew and first responders.
ARTC advised[87] that, since the incident, it had taken the following steps to improve the safety of its operations, that are relevant to two ATSB Observations:[88]
ARTC has developed an amendment to TA20 to facilitate an “Alternative Proceed Authority”. Once implemented, TA20 will provide for a new form of safeworking, similar to Train Authority Working, that can be implemented in circumstances where Centralised Traffic Control (CTC) is not operational for an extended period of time. The proposed amendment to TA20 has been the subject of initial user consultation including internal briefing sessions with operational areas within ARTC’s business and external briefing sessions with rail operators. A Human Factors assessment is scheduled to be undertaken in relation to the proposed amendment in Quarter 4 of Calendar Year 2021. The proposed amendment will then be subject to further formal stakeholder consultation and ARTC’s management of change processes prior to implementation.
ARTC is developing a new risk assessment tool for abnormal circumstances, to be known as an Event Flow Work Tool, with a focus on risk scoring and authority escalation requirements. A prototype has been developed and is to be further work shopped with Network Controllers prior to implementation.
Until the steps referred to in 1) and 2) above have been completed, ARTC has implemented an interim requirement that the implementation of any altered method of safeworking, other than Caution Orders, requires a formal Risk Assessment and approval by ARTC’s Executive Risk Committee.
ARTC has developed an amendment to TA20 to include a new rule titled “Train Notices”. Once implemented, the new rule will clarify the manner and circumstances in which the operation of TA20 may be amended through the issue of Train Notices. Implementation of the new rule is subject to consultation wit
NSW Trains
NSW Trains advised[89] that, since the incident, it had undertaken a number of safety actions. Safety actions taken included:
The development of new procedures for the daily access of the ARTC WebRams system
Amendment of procedures to include confirmation of receipt of safety critical information by train crew prior to them starting their day of operations
Additional resources to ensure that NSW Trains has 24/7 frontline leader coverage across the network
The review of interface agreement risks from all rail infrastructure managers (RIMs) to identify and assess NSW Trains' systems and procedures for managing interface safety risks with the relevant RIMs
A range of initiatives to enhance safety critical communications including:
the development of a new program to strengthen safety critical communication across NSW Trains (TrainLink) rail safety workers
international benchmarking against safety critical communication systems used by other rail operators
risk workshops with key internal and external stakeholders to identify opportunities to strengthen safety critical communications
the development of a business case for future digital solutions for safety critical communications. ____________
The investigation is continuing and will include further consideration of the following:
management of train operations, including implementation of altered train working, risk management and communications
distribution of safety critical operational information
train operations and further human factors analysis
survivability and crashworthiness standards relevant to this type of event
finalisation of derailment sequence analysis
finalisation of rolling stock and track condition assessments
passenger services crew training and preparedness for a derailment event
passenger safety information
similar occurrences.
Relevant parties are notified of critical safety information identified during the course of the investigation so that appropriate and timely safety action can be taken.
A final report will be released at the conclusion of the investigation.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
Preliminary report
Report release date: 03/04/2020
The information contained in this report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this update. As such, no analysis or findings are included in this report.
The occurrence
On 20 February 2020, passenger train XPT ST23 departed Central Station in Sydney, New South Wales (NSW), at about the scheduled departure time of 0740.[1] The service was scheduled to stop at several stations en-route to its final destination at Southern Cross Station in Melbourne, Victoria that evening at 1830 (Figure 1).
Figure 1: Train route from Sydney to Melbourne
Source: Google Maps, annotated by Chief Investigator, Transport Safety
The train proceeded south and arrived at Junee in southern NSW at 1452,[2] about 85 minutes behind schedule. At Junee there was a change of driver before the train continued south, arriving in Albury on the NSW-Victorian border at 1637, still about 85 minutes behind schedule. There was a change in passenger car crew at Albury.
The train departed Albury at 1644 and entered the Victorian section of its journey. The service continued south, stopping at several stations before coming to a stand at Intermediate Home[3] signal KME28 at Kilmore East, at about 1856. Signal KME28 was at Stop, and the driver contacted Network Control at about 1904 to inquire when he might receive permission to proceed. There was a standard-gauge passing lane at Kilmore East, with East and West Lines (Figure 2).[4]
Figure 2: Kilmore East passing lane (standard-gauge track shown in black, with signals)
Source: ARTC, modified and annotated by Chief Investigator, Transport Safety
The XPT waited at signal KME28 on the East Line until the north-bound V/line passenger train 8625 had transited the Donnybrook to Kilmore East single-line section, passed signal KME2 and was travelling along the West Line through Kilmore East. The V/Line train was clear of the single-line by about 1925 and, soon after, the XPT was given permission by Network Control[5] to proceed to Home Departure signal KME16,[6] still on the East Line within the Kilmore East location.
As a result of damage to signalling equipment, a 24 km section from Kilmore East signal KME16 (at about the 63.8 km mark)[7] to Donnybrook (at about the 40.2 km mark) was being managed using an alternative safeworking system.[8] Wallan was located in this section, about 48 rail-km from Melbourne.
At signal KME16, XPT ST23 was met by several rail workers, including a Signaller and an Accompanying Qualified Worker (AQW).[9] The AQW boarded the lead power car and joined the driver at the head of the train as part of the alternative safeworking system in place for the 24 km section to Donnybrook.
At about 1932 while the train was still stopped at signal KME16, the driver and the Network Control Officer communicated over the radio about the Train Authority[10] for the section through to Donnybrook. The train then departed signal KME16 and entered the single-line towards Wallan. The line speed for the XPT in this section was 130 km/h and after departing, the speed of the train was increased towards this line speed.
One function of the AQW was to ensure that the level crossing protection[11] at Wallan–Whittlesea Road in Wallan was in place for the passage of the train.[12] The Level Crossing Keeper[13] positioned at this level crossing reported receiving a call from the AQW and activating the crossing protection.
The train was now approaching Wallan. Earlier that afternoon, the points at either end of Wallan Loop had been changed from their Normal position to their Reverse position.[14] This change meant that rail traffic, in both directions, would be diverted from the Main Line (straight) into the loop track (No.2 Road). A Train Notice[15] reflected this change and also specified a 15 km/h speed limit for entry into the loop, and a limit of 35 km/h for exiting the loop.
At about 1943, XPT ST23 was approaching the northern end of Wallan Loop at about the track’s line speed. Recordings from the train indicate an Emergency brake application a short distance before the points. This slowed the train a small amount before it entered the turnout travelling at a speed in excess of 100 km/h. The train was not able to negotiate the turnout to the loop track at this speed and derailed. All vehicles derailed excepting the rear power car (Figure 3).
Figure 3: Aerial photograph of derailment site
Source: ATSB
During the derailment sequence, the leading power car rolled onto its left side and the XPT driver and the AQW sustained fatal injuries. Three passengers were seriously injured and 36 received minor injuries.[16] Five train crew that were in the passenger cars also sustained injuries.
Context
Track information
The XPT service was running on the national standard-gauge track that connects Sydney and Melbourne. The track is part of the Defined Interstate Rail Network (DIRN) and is managed by the Australian Rail Track Corporation (ARTC).[17]
The standard-gauge track between Kilmore East and Donnybrook was a single, bi-directional line that serviced the XPT, V/Line passenger services and rail freight. There were passing lanes at Kilmore East and Donnybrook and a 1,550 m crossing loop at Wallan. The northern entry to this loop was located about 1.8 km north of Wallan–Whittlesea Road (Figure 4).
Figure 4: Wallan Loop (standard-gauge track shown in black, with signals)
Source: ARTC, modified and annotated by Chief Investigator, Transport Safety
Train information
The first XPT (Express Passenger Train) commenced service in 1982. The XPT fleet is operated by NSW TrainLink[18] and provides passenger services in regional NSW and between the east coast capital cities of Melbourne, Sydney and Brisbane. XPT vehicles are maintained by Sydney Trains[19].
The XPT ST23 running on 20 February 2020 included five passenger cars (Figure 5). The leading three vehicles were manufactured by ABB Transportation in Dandenong, Victoria and commissioned in 1993. The trailing four vehicles were manufactured by Comeng in Granville, NSW and commissioned between 1981 and 1984.
Figure 5: Train configuration
Source: ATSB, vehicle images supplied by Sydney Trains
Train data logger
Both power cars were fitted with a Hasler RT data logger. The data logger is an electro-mechanical device that records speed, distance, time, a combined power-vigilance parameter, and brake cylinder pressure parameters. These parameters are recorded on a waxed paper tape (roll). The Hasler system also included an analogue speedometer located on the driver’s console.
The train’s speed is derived from the measurement of the rotation of the left hand wheel on the second axle of the power car. In order for this rotation to be translated into distance (and speed), an average wheel diameter is assumed. Actual speed may deviate from that recorded (and displayed) due to differences between this assumed diameter and the diameter of the actual wheel providing the feed to the Hasler system.
The Hasler tapes from the two power cars were recovered at the accident scene and examined by the ATSB. Corrections to the recorded speed were made to account for the differences between the assumed wheel diameter and the actual wheel diameter on each power car. The results from both recorders indicated a speed of about 130 km/h approaching Wallan Loop.[20] The Hasler analogue speedometer would have read less than this, probably between the 125 km/h and 130 km/h marks.[21]
The data from both recorders indicate that there was an Emergency brake application nearing the turnout to the loop, and an associated small reduction in speed prior to the train entering the loop. The Hasler recordings will be the subject of further detailed analysis and review against other evidence.
Train crew and passengers
The XPT is a single-driver operation. The driver of the XPT was designated as a Regional Driver, and at the time of the derailment, an AQW was also in the driver’s cab. Both the driver and AQW suffered fatal injuries in the derailment.
Within the passenger vehicles, there were five further crew members including a Passenger Service Supervisor, Senior Passenger Attendant and three Passenger Attendants. All five have reported injuries.
There were 153 passengers recorded as being on the train at the time of the derailment, of which 39[22] have reported injuries.
Management of rail traffic (safeworking)
Safeworking is an integrated system of operating rules and procedures that defines the interaction between workers and engineered systems for the safe operation of a railway.[23] Of primary concern is safe operations including train separation and speed management according to infrastructure.
Relevant to this occurrence, the signalling infrastructure used for standard-gauge traffic through Wallan was damaged as a result of a fire in a track-side equipment hut on 3 February 2020. From 6 February, Train Authority Working was established to manage traffic between Home Departure signals DBK6 and DBK18 at Donnybrook[24] and KME4 and KME16 at Kilmore East.[25] The alternative safeworking arrangements permitted only one train in the section between Donnybrook and Kilmore East at any one time, and Wallan Loop was not being used for trains to cross or pass. From the commencement of Train Authority Working on 6 February, Wallan Loop was configured for trains to travel along No.1 Road.[26] This changed to the No.2 Road on 20 February.
Further investigation
The areas explored and requiring further investigation include:
Derailment sequence: Further investigation will include a detailed examination and review of available evidence to refine the derailment sequence.
Track condition: To date, site observations and preliminary review of track data have not identified adverse conditions directly contributing to the derailment. Further investigation will include the detailed examination of post- and pre-occurrence track geometry and maintenance information.
Rolling Stock condition: To date, site observations and vehicle workshop inspections (that commenced 6 March) have not identified adverse conditions directly contributing to the derailment. Inspections are ongoing and include detailed inspection of vehicles and testing of braking and driver safety systems.
Crew and passenger survivability: Detailed survivability inspection of the leading power car XP2018 and all passenger vehicles is complete. A passenger survey is being conducted researching passenger experiences of the derailment and subsequent evacuation and emergency response.
Train operation: Further investigation will include a detailed examination of the operation of the train drawing on a wide range of evidence sources.
Management of train operations: Further investigation will include a detailed examination of the alternative safeworking systems used to manage rail traffic at this location from 6 to 20 February 2020.
Other areas of investigation: Further areas of investigation may be identified as the investigation progresses.
Acknowledgements
The ATSB would like to acknowledge the significant assistance provided by all involved parties during the initial investigation, particularly in the context of the impact of COVID-19 on business operations and the community.
The information contained in this report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this update. As such, no analysis or findings are included in this report.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.