Serious injury on board Berge Daisetsu, Portland, Victoria, on 11 January 2018

Final report

Report release date: 30/10/2019

Safety summary

What happened

On 11 January 2018, a team of six crewmembers was conducting cargo hold cleaning and painting under the supervision of the chief mate on board Berge Daisetsu. While working aloft, on a jury-rigged platform suspended from a cargo crane, the crane falling block and hook caught and then suddenly released from the hatch coaming. That resulted in shock loading of the platform and serious injuries to two crewmen.

What the ATSB found

The ATSB’s investigation found that prior to starting the work, the ship’s crewmembers had several discussions, made plans, and completed a risk assessment. However, the work was not conducted in accordance with company safety management procedures or industry best practice with regard to risk management and working aloft permit requirements.

Additionally, the deck crane was being operated with its working limits bypassed when used to support the ship’s crew during the painting task. This enabled the crane to reach a position which allowed the block to contact and catch on the hatch coaming.

Finally, the fall arrest equipment used by the crew on the platform was incorrectly attached. As such, had either of the crewmen fallen from the platform the equipment would not have worked correctly, resulting in serious or fatal injuries.

What's been done as a result

Berge Bulk Maritime has completed the supply of approved working aloft equipment to its geared bulk carriers and is progressing modification of vessel cranes for personnel lifting. Specific working aloft and bulk carrier safety training has been conducted and made mandatory for crewmembers every two years. In addition, a fleet-wide assessment of safety maturity is progressing.

Safety message

This accident illustrates the consequence of deviating from accepted safety management procedures and industry best practice. The use of machinery and equipment contrary to its intended purpose makes hazard identification difficult and exposes those directly involved to significantly increased risk.

 

The occurrence

On 2 January 2018, the 180 m, geared bulk carrier Berge Daisetsu (Figure 1) arrived in Gladstone, Queensland, after a voyage from Long Beach, United States. The ship was carrying a cargo of petroleum coke for discharge in three Australian ports (Gladstone, Newcastle and Portland). The following voyage was to carry a cargo of grain, necessitating cleaning and inspection of the holds by a cargo surveyor before they could be certified for carriage of grain. Voyage instructions and cleaning guidance were sent to the ship prior to it arriving in Australia.

Figure 1: Berge Daisetsu alongside in Portland

Figure 1: Berge Daisetsu alongside in Portland. Source: ATSB

Source: ATSB

Hold preparation

After departing Gladstone for Newcastle, New South Wales, the deck crewmembers, under the guidance of the chief mate, washed the empty cargo holds (numbers 1 and 4) with chemicals and water. A small amount of repair painting was also conducted in reachable areas. The guidance from shore management (Berge Bulk) advised that the chemical should be left on the surfaces for 30 to 45 minutes before washing down. However, in the hot conditions[1] this dwell time resulted in the chemical drying on the hold surfaces. This was in contrast to the safety management system procedures and chemical use advice to wash down before the surfaces dry.

Berge Bulk had engaged the services of a cargo surveying company to inspect the condition of the cargo holds and provide advice regarding the areas requiring attention and also the appropriate techniques to use. A surveyor inspected cargo holds 1 and 4 in Newcastle and, along with photographic appraisal by Berge Bulk shore management, determined that the holds did not meet the required standard of cleaning due, in part, to staining from the chemical used. On board discussions with the surveyor concluded that an acceptable solution was to paint the hold surfaces. However, this was not discussed with shore management, despite Berge Bulk policy and expectations that, other than touch-up painting of surfaces, hold painting was to be undertaken during drydockings.

The lower sections of each cargo hold could be painted from the hold bottom using paint rollers on extended handles. However, the upper sections needed to be accessed by other means. Berge Daisetsu did not have portable scaffolding equipment or dedicated suspended access (work) platforms which could be used for this task. Consequently, the master sought ideas for accessing the upper sections of the holds from those on board and discussed those options with the chief mate and bosun.

Improvised work platform

The decision was made to jury-rig a portable gangway which the ship carried[2] into a work stage which could then be suspended from the cargo crane hook via slings. This plan required working aloft which in turn required procedural safeguards including a permit to work aloft, a risk assessment and tool box meetings. Furthermore, the risk assessment associated with working aloft required approval from shore management. However, in this case, this approval was not sought.

The gangway (Figure 2) comprised an approximately 0.6 m wide by 4 m long aluminium base with stanchions and rope side rails. As a gangway it was designed to be supported at its ends only, with a safe working load of 150 kg. In preparation for the painting task, the gangway was rigged with additional ropes to secure the open ends and then with slings at either end for lifting and suspending from the crane. Tag lines were connected to the underside of each end of the gangway and run to the hold bottom where they were used to control the motion of the suspended staging.

The movement of the ship while underway was considered unsuitable for this work. Consequently, the master and chief mate agreed that the painting of the upper hold areas would proceed while the ship was alongside in Portland, Victoria.

Figure 2: Portable ship’s gangway as rigged for use as the suspended painting platform

Figure 2: Portable ship’s gangway as rigged for use as the suspended painting platform. Source: ATSB

Source: ATSB

The two-day sea passage from Newcastle to Portland was spent painting the lower sections of cargo holds 1 and 4 and discussing and refining the plans for painting the upper sections. The chief mate and bosun discussed the rigging and a hand sketch of how the stage would be supported was made (Figure 3).

Figure 3: Hand‑drawn sketch of the work plan

Figure 3: Hand‑drawn sketch of the work plan. Source: Berge Bulk

Source: Berge Bulk

At 2054[3] on 10 January 2018, Berge Daisetsu was all fast alongside in Portlan. Cargo discharge from cargo holds 2 and 5 commenced soon after and continued into the following day.

Preparation for painting

At 0800 on 11 January 2018, the chief mate held a toolbox meeting during which the painting in cargo hold number 4 was discussed. This was the first time the chief mate had undertaken hold painting on board Berge Daisetsu but he had done similar work on other ships using lifting equipment designed for the task.

At this meeting, the standard risk assessment for painting the upper sections of cargo hold number 4 by lifting basket (dated 11 January 2018) was worked through. The ship was not equipped with an approved lifting platform and this form did not include verification that the risk assessment had been approved by shore management as required. The working aloft permit to work for the job was discussed and completed and the chief mate signed the form as the responsible person in charge. The preparations for the work included discussion of the required personal protective equipment, use of safety harnesses, individual roles and responsibilities, communication and task details. After the incident, all involved persons stated that they were aware of the task requirements and of their duties during the task.

The deck crew gathered the necessary equipment, including the improvised work stage, guy ropes, safety harnesses, a double lanyard fall arrest safety line and painting implements (drums for the paint, paint rollers and extended handles). The work team consisted of the chief mate, in charge, the bosun, 3 able seamen (AB1, AB2 and AB3), an ordinary seaman (OS) and the deck cadet (cadet). At about 0830, they gathered on deck at the aft end of cargo hold number 4.

The bosun was tasked to drive number 4 crane to access the forward area of number 4 cargo hold and number 3 crane for the after part. He had driven cargo cranes on ships prior to Berge Daisetsu although this was the first time he had driven a crane for lifting personnel. None of the cranes on the ship were certified for the lifting of personnel.

The painting was to be done by AB2 and AB3, both experienced seafarers. As monitor, AB1’s role was to remain on the main deck and provide assistance to, and act as lookout for, those in the hold and assist the chief mate as required.

The OS and cadet, both with less than one year’s seagoing experience, were to manage the tag lines from the hold bottom, keeping the movement of the staging under control. Five radios were distributed to the chief mate, bosun, the staging crew, AB1 and to the OS.

In preparation for accessing the upper hold sections, the staging slings were placed over the hook and bound together to form a tight loop around the hook (Figure 4). AB2 and AB3, donned the safety harnesses and attached themselves one to each of the fall arrest line’s lanyards. Once readied, with rollers, extended handles and 20 litre buckets for paint, the ABs boarded the staging on the main deck. The free end of the fall arrest safety line was then tied off to one of the crane hook shackles, clear of the staging slings and the hook itself. Because the improvised arrangement had limited stability, the ABs stood one at each end of the staging to balance it. They were to work from these positions and limit their movement so as to not upset the staging and equipment on board.

Figure 4: Stage and hook configuration

Figure 4: Stage and hook configuration. Source: ATSB

Source: ATSB

The OS and cadet held the tag lines and controlled the motion of the staging as it was lifted off the deck and lowered over the hatch coaming into hold number 4. The tag lines were then lowered into the hold and the OS and the cadet transferred from the main deck to the hold bottom. Once there, they retrieved the tag lines and maintained control of the staging as it was moved into position for the painting to commence.

Painting cargo hold 4 from the suspended work platform

Crane access into the cargo hold was limited by the edge of the hatch coaming. With the crane hoist wire against the coaming the staging hung about 4.5 m away from the hold’s athwartship bulkhead. To reach the bulkhead the ABs used paint rollers fixed to extended handles. The rollers were brought back into the staging to be replenished with paint from the buckets of paint. The staging was moved into position by the bosun at the direction of AB2, via the radio. Once in the desired location, the staging was steadied by the OS and cadet using the tag lines which were then tied off to secure points in the hold (bulkhead eyes or lugs and tank lid hand holds).

The work proceeded without incident throughout the morning. On several occasions the progress of the work (Figure 5) was witnessed by the master. At 1200, the painting of the forward and starboard side areas of the hold was completed and the work team returned to the main deck and stopped for lunch.

Figure 5: Photograph, taken by the master, of work in cargo hold number 4 during the morning

Figure 5: Photograph, taken by the master, of work in cargo hold number 4 during the morning. Source: Berge Bulk, annotations by ATSB

Source: Berge Bulk, annotations by ATSB

During the lunch break a cargo surveyor boarded the ship to continue the earlier inspections and guidance. At about 1300 the chief mate took the surveyor to cargo hold number 4. The surveyor pointed out the remaining areas that required painting. At about 1400, the inspection of hold 4 was completed and they moved to cargo hold number 1. The chief mate asked AB1 to assist with the remaining inspection by opening number 1 hatch.

At about the same time, painting recommenced in cargo hold number 4. The jib of crane number 4 was slewed outboard and over the port side of the ship to allow sufficient room for crane number 3 to provide access to the aft coaming of cargo hatch number 4. The bosun operated crane number 3, however, in contrast to the morning’s operation, this crane would not plumb over the hatch coaming within its normal operating range. In order to reach overhead the aft coaming, the crane’s lower luffing limit protection was bypassed. This was done without the knowledge of crewmembers other than the crane driver.

The incident

Utilising crane number 3, the team commenced painting on the port side aft area of the hold bulkhead in the same manner as they had earlier in the day – AB2 and AB3 boarded the staging on the main deck, it was lowered into the hold and the OS and cadet took control of the tag lines from the hold bottom (Figure 6). AB1 was on the main deck providing assistance to both the painting team and to the chief mate as required.

Figure 6: Re-enactment of the approximate staging position at the time of the incident, looking aft from the crane driver’s position

Figure 6: Re-enactment of the approximate staging position at the time of the incident, looking aft from the crane driver’s position. Source: ATSB

Source: ATSB

By 1500 the chief mate and the cargo surveyor completed their inspection of hold number 1 and returned to the main deck, before moving aft to the accommodation and the ship’s office. AB1 had moved forward to close number 1 hatch. In cargo hold number 4, the work team had moved inboard and were painting an area just to port of the centreline and about 8 m above the hold bottom. The crane falling block[4] was against the aft coaming face with the hook hanging below the coaming edge and the staging below that (Figure 7). The ABs completed the work they could reach and sought to reposition the staging further to starboard. AB2 asked the bosun to move the hook forward, horizontally, clear of the coaming, by luffing the jib up. The ABs were standing at either end of the staging with the paint buckets and rollers beside them.

At about 1510, as the bosun raised the crane jib, the falling block caught on the lower edge of the hatch coaming. This went unnoticed by the work team and, as the jib was raised further, the block suddenly came free of the coaming sending an unexpected heavy shock into the staging, upsetting it and its load. Both ABs were knocked over on the staging, and landed heavily on their knees and lower body. The paint buckets and rollers fell to the hold bottom.

Incident response

At the time of the incident the chief mate was on the main deck adjacent to number 5 cargo hold and AB1 was returning along the deck, adjacent to number 1 cargo hold. Both heard the sound of the falling equipment and hurried to number 4 cargo hold to investigate. The bosun stopped moving the crane and could see both ABs laying on the staging, injured. Below, the OS and cadet had avoided the falling equipment, gained control of the tag lines and stabilised the staging. After quick observation of the area, the OS radioed the bosun to lower the staging to the hold bottom so assistance could be provided to the ABs. Once on the hold bottom first aid was provided to the two injured men.

Figure 7: Re-enactment of the painting stage in the cargo hold

Figure 7: Re-enactment of the painting stage in the cargo hold. Source: ATSB

Source: ATSB

From the main deck, the chief mate radioed the master telling him of the accident and requesting immediate shore assistance. The master contacted the shore-based international medical firm contracted by the company to provide medical advice. He also notified the agent, shore authorities and company officials. He then attended the site to assess the situation. Meanwhile, an ambulance was directed to the ship and arrived alongside at about 1600. Both seriously injured men were transferred to the local hospital for assessment and further treatment.

Berge Daisetsu departed Portland bound for Wallaroo, South Australia on 14 January 2018. During the voyage the cargo holds were satisfactorily cleaned under the guidance of the cargo surveyor who travelled with the ship. Any work aloft required for the clean and touch-up repairs were discussed with, and approved by, Berge Bulk shore management. A certificate of fitness to load grain was issued on 15 January 2018 for all cargo holds.

Figure 8: Re-enactment of the approximate location of the platform and falling block at the time of the accident

Figure 8: Re-enactment of the approximate location of the platform and falling block at the time of the accident. Source: ATSB

Source: ATSB

__________

  1. Deck logbook recorded air temperatures from 25 to 32° C during this period.
  2. Under the International Convention for the Safety of Life at Sea (SOLAS), 1974, Chapter II-1, Regulation 3-9 all ships require a means of embarkation on and disembarkation from them. Guidelines for the construction, installation, maintenance and inspection/survey of such means are contained in Maritime Safety Committee circular MSC.1/Circ.1331.
  3. Eastern Daylight-saving Time (EDT): Universal Co-ordinated Time (UTC) + 11 hours
  4. Crane manufacturer terminology and also known as a travelling block.

Context

Berge Daisetsu

At the time of the incident, Berge Daisetsu was registered in the Isle of Man, owned by the Berge Daisetsu Company (Marshall Islands), and managed by Berge Bulk Maritime (Singapore). The ship was built in 2015 in Japan and classed with DNV GL.

Cargo cranes

Berge Daisetsu has five cargo holds serviced by four, Mitsubishi 30 t capacity hydraulic deck cranes – crane numbers 1 to 3 have a working radius of 24 m and number 4 (aft) crane a working radius of 26 m. The cranes were not rated or approved for personnel lifting duty.

Crewmembers

Berge Daisetsu had a crew of 21 appropriately qualified Chinese nationals including 2 cadets. The master held a Chinese certificate of competency and had joined the ship in August 2017. This was his first contract with Berge Bulk but he had sailed as master in bulk carriers since 2010.

The chief mate held a Chinese chief mate’s certificate of competency and had been on board since July 2017. He first went to sea in 2007 and this was his second ship as chief mate, both were geared bulk carriers. This was the first time the chief mate had undertaken this task on board Berge Daisetsu but he had done similar hold painting work on other ships using lifting equipment designed for the task.

The bosun had a current Chinese certificate of proficiency as an able seafarer. He had worked at sea since 2007 and joined Berge Daisetsu in October 2017. This was his first time on this ship but he had driven cargo cranes on several previous occasions though this was the first time he had driven a crane for lifting personnel.

AB1 (monitor) held a Chinese certificate of competency as third officer in charge of a navigation watch and first went to sea as a deck cadet in 2014. This was his first ship with Berge Bulk and he joined Berge Daisetsu as an able seaman in October 2017.

AB2 (directing work from the platform) first went to sea in 2004 and held a Chinese certificate of proficiency as an able seafarer. This was his first time on board Berge Daisetsu and he had worked as a bosun or able seaman on several geared bulk carriers prior to joining Berge Bulk in 2016.

AB3 (assisting AB2 with painting) held a Chinese certificate of proficiency as an able seafarer. He joined Berge Daisetsu and Berge Bulk in October 2017 after several years’ experience serving as an able seaman on general cargo ships and bulk carriers.

The ordinary seaman had been at sea since 2017 and held a Chinese certificate of proficiency for seafarers (as rating forming part of a navigational watch). Berge Daisetsu was his second ship, both with Berge Bulk.

The deck cadet held a Chinese certificate of proficiency for seafarers having completed basic training. He joined Berge Bulk in 2017 and Berge Daisetsu was his first ship.

Berge Bulk Maritime

Berge Bulk Maritime (Berge Bulk) specialises in dry bulk ships and cargoes. From a fleet of 12 vessels in 2007, Berge Bulk has grown to operate and manage a fleet of over 70 ships in 2018. The fleet includes 12 ships of less than 40,000 DWT[5] (9 owned by Berge Bulk) all fitted with deck cranes. The remainder of the fleet consists of ships of more than 170,000 DWT in size. In 2017 Berge Bulk transported over 75,000,000 t of cargo.

The latest addition to the geared bulk fleet was Berge Snaefell (37,800 DWT), delivered in 2018. This ship is fitted with personnel riding certified deck cranes and was delivered with class approved platforms for working aloft.[6]

Industry guidance and legislation

Legislation,[7] reflected in industry guidance, states that no lifting equipment shall be used for lifting persons unless it is designed for the purpose, except in exceptional circumstances such as for rescue or in emergencies.

At the time of the incident, Berge Daisetsu was flagged in the Isle of Man (IOM). The IOM Merchant Shipping Act 1985, Merchant Shipping (Code of Safe Working Practices) Regulations 1989 require that multiple copies of the current UK Maritime and Coastguard Agency (MCA) Code of Safe Working Practices for Merchant Seafarers (COSWP) are carried on board and made available to all crewmembers. COSWP references MCA Marine Guidance Notes (MGN) and UK Statutory Instruments (Regulations).[8] While the referenced MCA notices do not apply to IOM‑registered vessels, it is expected that they be used as best practice guidelines. Further guidance on the standards for working and living conditions on board is provided by the IOM Merchant Shipping (Maritime Labour Convention) Regulations 2013.

Code of Safe Working Practices for Merchant Seafarers (United Kingdom Maritime and Coastguard Agency)

The MCA publication COSWP is a widely referenced nautical publication and is made available on board all Berge Bulk ships. The procedures and guidance in Berge Bulk’s safety management system (SMS) relied heavily on the advice and resources available in the COSWP. If guidance or training was required on board and not covered in the SMS, the master was directed to refer to the COSWP.

The COSWP provided best practice guidance for improving health and safety on board ships. Aspects relating to the working aloft task being undertaken on board Berge Daisetsu were addressed in the publication. This included, but was not limited to:

  • personal protective equipment (PPE) including protection from falls
  • permit to work (PtW) systems
  • work at height
  • provision, care and use of work equipment
  • lifting plant and operations including personnel lifting equipment.

Safety management system and work procedures

The Berge Bulk SMS document suite contained procedures, guidance and forms relevant to the task of hold cleaning and preparation for carriage of grain, and to the methods being employed on Berge Daisetsu on 11 January.

The SMS identified all work at a height of more than two metres above the deck as requiring a permit to work. In addition to this, risk assessments were required for cargo hold cleaning, working aloft and lifting operations with the work aloft risk assessment requiring shore management approval. Furthermore, the operation of lifting appliances was identified as a high risk task and advised that design limits were to be adhered to and safety devices working.

Relevant SMS documents for the painting task included:

  • health, safety and security policy
  • hold cleaning
  • permit to work systems
  • risk management
  • working aloft
  • operation of lifting appliances – a lifting appliance is one that is used for the purpose of suspending, raising, lowering or moving a load, including personnel.
Health Safety and Environmental policy

The Berge Bulk Health Safety and Environmental policy emphasised the safety of the crewmembers on board. Under this policy, the incorrect usage of any equipment was ‘strictly’ prohibited. On board Berge Daisetsu, the portable gangway (jury-rigged as the suspended work platform) was supplied to assist safe access to and from the ship. It was not intended to be used as a personnel lifting platform for cargo hold cleaning/painting.

Cargo hold cleaning

The cargo hold cleaning document stepped through stages of the inspection, cleaning and approval process. Subjects addressed included safety during cleaning, grades of hold cleaning, the use of cleaning chemicals and cargo contamination problems, including actions to minimise the contamination. The procedure dealt predominantly with cleaning and protection of paint systems and included the advice that chemicals should be washed off before they dry. Painting of surfaces was mentioned as part of damage repair, with the need to allow sufficient time for the paint to cure and harden emphasised.

Berge Bulk management advised that the crewmembers were instructed to chemically clean the cargo hold surfaces, scrubbing reachable areas only. Cleaning equipment provided for this task included high pressure water guns with a 15 m reach. After the cargo holds did not pass inspection, management expectations were that further cleaning would be required to remove the staining. This would be done at the surveyor’s guidance. Painting of holds, other than minor touch‑up, was usually done in dry dock after receiving inspection reports from the ship. In Berge Bulk’s experience the cargo hold area most affected during cargo operations was limited to areas less than 5 m above the hold bottom. This area could be reached with equipment made available on board the ship without the need for working aloft. Consequently, the ship’s crewmembers were not instructed, nor expected, to paint the upper area of cargo holds.

However, the on board discussions after the surveyor’s inspection concluded that painting the hold surfaces would result in an acceptable finish, and be completed more quickly than washing and scrubbing. This would however, require accessing the upper areas of the cargo holds and thus working aloft.

Permit to work procedure

The Berge Bulk permit to work (PtW) procedure included the steps:

  • assessment - including the need for a toolbox meeting and risk assessment
  • authorisation – included requiring that shore approval of risk assessments, if applicable, was to be received on board prior to commencing the task
  • monitoring – persons carrying out the task were to be supervised
  • response to change – empowered any responsible person to stop a job if unsafe conditions were found
  • closure.

Work aloft was one of the tasks identified as requiring a PtW.

The PtW procedure then listed barriers to be in place including supervision, use of safety harness and fall arrest equipment and that at least two safety barriers were to be in place.

A working aloft PtW form was completed for the task of ‘Paint bulkhead by lifting basket’ in hold number 4 on 11 January 2018. This form indicated that:

  • a risk assessment was completed with a resultant level of risk at 2 (on a scale of 3) – the form prominently included the notice that ‘whenever work is being carried out on board involving the risk of falling more than two (2) meters [sic], such work shall be considered “Working Aloft” and subjected to a risk assessment and permit-to-work.’
  • equipment had been checked
  • persons had been provided with safety harnesses
  • other safety measures taken included the use of safety belts and safety lines
  • the work and method of work had been agreed and understood
  • personnel were briefed
  • the chief mate was supervisor and person in charge and had signed on as person in charge as well as the person responsible for the work aloft.

The permit was approved and signed by the master.

Risk assessment procedure

The Berge Bulk SMS included a risk management procedure which had the objective to ‘cover risk management and risk mitigation to ensure that protective and precautionary measures are taken, which will reduce risks associated with operation to a level that is considered to be 'as low as reasonably possible and practicable.'’ One resource identified to assist users when assessing risk was to refer to the COSWP.

The risk management procedure worked through the steps to be taken including:

  • hazard identification
  • using the ‘Take 5’ – stop, think, identify, plan, proceed – technique to identify and mitigate hazards
  • the procedure for completing a toolbox talk
  • a list of the tasks requiring a risk assessment – this list included cargo hold cleaning, working aloft and lifting operations
  • the risk assessment procedure which included referring to the relevant permit to work procedure
  • a list of risk assessments requiring shore management approval prior to commencement of the associated activity, including working aloft.

A risk assessment was completed (dated 11 January 2018) for ‘Working aloft - Painting cargo hold by lifting basket’. This identified several precautions to be taken to reduce the risk of harm, including:

  • familiarization of the work place and surrounds prior to work commencing
  • all work team members must be briefed on the work to be done and proper communications are to be maintained
  • a responsible and knowledgeable person must continuously supervise and remain in communication with relevant personnel
  • all equipment to be used is to be inspected and tested.

The PtW was identified as one additional precaution to be taken to reduce the risk of harm.

Contrary to the SMS requirement, this risk assessment was not provided to shore management for approval.

Operation of lifting appliances procedure

The Berge Bulk operation of lifting appliances procedure identified this as a high risk task. The procedure therefore included precautions such as:

  • the appliance should never be operated outside its design limits
  • all safety devices as fitted are to be tested for good working order and under no circumstance must the safety devices be isolated or overridden.

However, the lifting appliance was used outside its design limits and with safety devices overridden.

Personal protective equipment usage

Personal protective equipment (PPE) is an essential tool for preventing injury in the workplace. However, to be effective it must be used correctly and as per manufacturer and industry recommendations. For the work aloft on board Berge Daisetsu, the risk assessment and PtW had correctly identified that PPE including safety harnesses, safety belts and safety lines was required. The equipment used included a twin-legged energy absorbing fall arrest lanyard. Several of these were on board at the time.

Figure 9: Energy absorbing double lanyard fall arrest equipment in use at the time

Figure 9: Energy absorbing double lanyard fall arrest equipment in use at the time. Source: Berge Bulk with annotations by ATSB

Source: Berge Bulk with annotations by ATSB

This type of lanyard[9] comprises a ‘Y’ configuration – the body of the ‘Y’ has the tear out energy absorbing component and the two legs have safety lanyards and attachment loops (Figure 9). The energy absorber loop is to be connected to the safety harness of the user and the lanyards are then used for attaching to strong points. One lanyard is attached to one point, and the second can be moved and attached to a second point some distance away. The first can then be disconnected and moved to another point, and so on. This arrangement allows a user to move about a worksite without ever being unhooked from a strong point.

Crane operation

The cargo crane in use at the time of the incident (number 3) served cargo hold numbers 3 and 4. It has a 30 t load capacity and 24 m maximum working radius (at 20° jib angle to the deck). The vertical position of the hook changed by 1,650 mm over the full range of jib angle movement from about 81° to 20° (error in level luffing).[10]

To get the work platform as close to the bulkhead as possible during the painting task required the crane’s falling block to be against the coaming. That positioning also limited the fore-aft movement of the hook and platform. To do this however, the crane was required to plumb over the hatch coaming. This was beyond its normal maximum working radius. The working zone luffing limit for the crane was 20°, but to plumb over the hatch coaming the jib needed to be at a lower angle of about 15°. To achieve this, the lower luffing limit of the crane was bypassed. This limit was routinely and regularly bypassed to allow the crane jib to be housed. However, operating with the bypass active for any other reason was prohibited.

Prior to this accident, Berge Bulk had identified the need to have specific and approved equipment for working aloft, including work platforms available on its ships. This equipment had already made available on several ships. However, although an approved work platform for Berge Daisetsu had been manufactured, it was pending delivery to the ship at the time of the occurrence. Therefore, hold cleaning and touch-up work was limited to those areas that could be reached from the deck.

The company had also identified the need for working aloft in cargo holds and had commenced a process of having new ships fitted with deck cranes approved for personnel lifting in addition to cargo handling.

__________

  1. DWT – deadweight tonnes, a measure of the mass of cargo, fuel, water, stores etc. a ship can carry.
  2. Suspended work platform drawings evaluated to DNV GL standard DNVGL-ST-0378 ‘Standard for offshore and platform lifting appliances’ in accordance with European standard EN 14502-1 ‘Cranes – Equipment for the lifting of persons – Part 1: Suspended baskets’.
  3. Including: Isle of Man 1985, MERCHANT SHIPPING ACT 1985, MERCHANT SHIPPING (HATCHES, HOLD ACCESS AND LIFTING PLANT), REGULATIONS 1989, Isle of Man.
  4. Including guidance notes relating to work at height (MGN 410), lifting operations and lifting equipment (LOLER, MGN 332) and the provision and use of work equipment (PUWER, MGN 331).
  5. See Work at Height Safety Association (WAHSA) (UK), n.d., WAHSA Technical Guidance Note (TGN) 02 Guidance on the use of single and twin energy absorbing lanyards, WAHSA, Shropshire, UK. Available at www.wahsa.org.uk/
  6. Level luffing - keeping the hook at a constant level while the crane jib is luffed up or down.

Safety analysis

On 11 January 2018, a six‑member team was conducting cargo hold cleaning and painting under the supervision of Berge Daisetsu’s chief mate. While working aloft, on a jury-rigged platform suspended from a cargo crane, two persons were seriously injured when the crane falling block and hook made contact with the hatch coaming and upset the platform.

This analysis will explore the reasons for the platform upset and examine circumstances around the accident more broadly. This will include consideration of the safety management system and procedures in place for cargo hold painting and working aloft. In addition to this, the knowledge and use of equipment and machinery used for the task will be discussed.

The accident

In a decision probably motivated by efficiency, Berge Daisetsu’s crewmembers elected to paint the stained areas of the ship’s cargo holds, rather than clean them, in order to meet the requirements to pass inspection and obtain a Certificate of Fitness to Load Grain. While painting the upper areas of the aft bulkhead of cargo hold number 4, the work platform was suspended from number 3 cargo crane with the crane falling block flat against the hatch coaming to position the painters as close as possible to the bulkhead being painted. In this location and orientation, one of the falling block shackle pins protruded fore-aft and extended under the lower edge of the hatch coaming (Figure 10). This presented as a catch point should the hook be lifted vertically.

Figure 10: Crane hook and shackle in approximate position as at time of incident. Inset shows the view from the side with protruding hook shackle pin.

Figure 10: Crane hook and shackle in approximate position as at time of incident. Inset shows the view from the side with protruding hook shackle pin. Source: ATSB

Source: ATSB

To reach this location, the crane’s lower luffing limit was bypassed. Bypassing the limit removed control protections from the crane including its level luffing function. Operating the crane in this mode was prohibited by company procedures, against crane manufacturer advice and contrary to sound working practices.

The need to operate the crane with the limit bypass active was not identified or discussed at any stage during the planning, risk assessment, permit to work or toolbox discussions completed for the job. The bosun regularly drove the cranes and it is likely that he alone was aware that the crane was being operated with the bypass active. However, he was probably unaware of this specific fouling risk when operating with the limit bypassed.

Consequently, when AB2 (on the staging) asked the crane driver (bosun) to raise the jib to access an area to be painted, the falling block rose with the jib. AB2’s intent was that the platform would move horizontally and clear of the coaming using the level luffing function of the crane. However, as this function had been bypassed, the jib and falling block moved upwards and this likely led to the protruding hook shackle pin catching under the hatch coaming. As the fouling went unnoticed by the work party, the jib (and hook) continued to move and the shackle pin came free from the hatch coaming with a sudden movement which in turn transferred a significant force to the platform occupants, seriously injuring them.

Safety management system

At the time of the accident, safety management system (SMS) procedures required a risk assessment and a permit to work be completed for the cleaning and painting of the upper areas of the cargo hold. Berge Bulk policy for working aloft agreed with industry guidance in that only suitably designed, approved and certified equipment and machinery should be used for lifting personnel.

On board Berge Daisetsu, this task was undertaken using a jury-rigged portable gangway suspended from the cargo‑only crane(s) to access the upper areas of the cargo hold(s). The portable gangway was a common piece of ship equipment for use as a means of access to/from the ship and for no other purpose. Additionally, the cranes, though rated to lift 30 t, were not approved for lifting personnel.

Therefore, although the ship’s crewmembers had several discussions, made plans and completed a risk assessment in accordance with the SMS requirements, the equipment and machinery use was contrary to company policy and procedures. They were not suitable for the task and their use made hazard identification difficult and exposed the workers to increased risk.

While the decision to adapt on board equipment may have been motivated by a desire to expeditiously prepare the ship for loading, it may also indicate that:

  • detailed understanding of the use of machinery and equipment was lacking on board Berge Daisetsu
  • although the required on board familiarisation included the use of lifting appliances such as cranes, the systems to ensure this knowledge was acquired by users was ineffective.

Furthermore, the risk assessment completed during preparations for the work was not sent ashore for office approval prior to the work being commenced, as required by the SMS. Consequently, shore personnel were unaware that hold painting requiring working aloft was to be done. This removed the opportunity for external scrutiny of the task to determine whether it was necessary and to identify that it involved the use of non-approved equipment and machinery.

Proactive safety action taken by the company in response to this accident (see the section titled Safety issues and actions) included training and assessment of safety culture. The intention of that action was to ascertain whether these identified safety deficiencies were confined to this occurrence or symptomatic of a fleet‑wide issue.

Personal protective equipment

During site inspection after the accident, the crewmembers demonstrated how the equipment, including the personnel protective equipment, was being used at the time. During this demonstration it was apparent that the use of the twin legged energy absorbing fall arrest lanyard was not correctly understood. One lanyard was used for both workers (one person attached to each leg), in contrast to the correct usage of one lanyard per person. Furthermore, the energy absorber was excluded from use in the way in which the equipment was attached to the strong point (crane hook shackle). Figure 11 shows how the fall arrest lanyard was rigged.

Had either of the ABs fallen from the work platform, the fall arrest lanyard would not have worked as designed. As the energy absorbing end of the lanyard was incorrectly connected it is possible that the lanyard may have failed completely and the user(s) fallen, unchecked, to the hold bottom.

Figure 11: Composite image and sketch showing how the energy absorbing double lanyard was used and secured

Figure 11: Composite image and sketch showing how the energy absorbing double lanyard was used and secured. Source: ATSB

Source: ATSB

The use of safety equipment was discussed during the pre-work toolbox meeting and then on the worksite when all was inspected prior to work commencing. This process involved all crewmembers of the work team including the chief mate. Furthermore, the worksite was checked several times by the master. At no time were any concerns raised about the safety equipment being used or how it was being used. In particular, the use of a single fall arrest lanyard for two persons when several were available on board was not mentioned.

This suggests that the use of this equipment had not been explained or demonstrated to the ship’s complement and/or had been supplied to the ship without any explanatory or usage documentation.

Findings

From the evidence available, the following findings are made with respect to the serious injuries sustained on board Berge Daisetsu whilst berthed in Portland, Victoria on 11 January 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • The suspended painting platform was upset when the hook was moved and suddenly came free from being caught under the hatch coaming. This led to the occupants falling on the platform and receiving serious injuries.
  • Contrary to normal operating procedures, the deck crane was being operated with its working limits bypassed when used to support the ship’s crew during the painting task. This enabled the crane to reach a position which allowed the block to be in contact with and catch on the hatch coaming.
  • The task was not conducted in accordance with company safety management procedures or industry best practice with regard to risk management and working aloft permit requirements. Consequently, machinery and equipment were used in a way they were not designed or approved for, making hazard identification difficult and exposing the workers to increased risk.

Other factors that increased risk

  • The fall arrest equipment used was incorrectly attached to the workers on the suspended platform. Consequently, had either of them fallen from the platform the equipment would not have worked correctly, resulting in serious or fatal injuries. [Safety issue]

Safety issues and actions

The safety issue identified during this investigation is listed in the Findings and Safety issues and actions sections of this report. The ATSB expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the marine industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Knowledge and use of fall arrest safety equipment

Safety issue number: MO-2018-001-SI-01

Safety issue description: The fall arrest equipment used was incorrectly attached to the workers on the suspended platform. Consequently, had either of them fallen from the platform the equipment would not have worked correctly, resulting in serious or fatal injuries.

Additional safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence

Berge Bulk Maritime advised the ATSB that it has also taken the following actions as a result of this incident:

  • completed the fleet‑wide purchase and supply of Class‑approved work platforms for work aloft to all company-owned geared bulk carriers
  • commenced a programme to have all fleet geared bulk carriers’ cranes modified and approved for personnel lifting at scheduled dry dockings
  • engaged an external consulting company to conduct a fleet‑wide assessment of safety maturity by measuring the company’s level of safety practice and how well this is embedded in the behaviour and belief of employees. This assessment is intended to assist the development and implementation of an integrated company-wide safety strategy.

General details

Ship details

Name:Berge Daisetsu
IMO number:9713179
Call sign:2IPO5
Flag:Isle of Man
Classification society:DNV-GL
Ship type:Geared log / bulk carrier
Builder:The Hakodate Dock Co. Ltd, Hokkaido, Japan
Year built:2015
Owner(s):Berge Daisetsu Company Inc. (Marshall Islands)
Manager:Berge Bulk Shipping Pty. Ltd. (Singapore)
Gross tonnage:21,530
Deadweight (summer):34,533 t
Summer draught:9.822 m
Length overall:179.97 m
Moulded breadth:30.00 m
Moulded depth:14.05 m
Main engine(s):Mitsubishi 6UEC45LSE-Eco-B2
Total power:5,690 kW at 108 rpm
Speed:14.0 knots
Damage:Nil

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the master and crewmembers of Berge Daisetsu
  • Berge Bulk Maritime
  • Mitsubishi Heavy Industries
  • DNV GL
  • the Australian Maritime Safety Authority
  • the Isle of Man Ship Registry.

References

British Standards Institution 2010, BS EN 14502-1:2010 Cranes - Equipment for the lifting of persons. Suspended baskets, British Standards Institution, London. Available at www.bsi-global.com

DNV GL 2016, DNVGL-ST-0378 Standard for offshore and platform lifting appliances, DNV GL. Available at http://dnvgl.com

International Maritime Organization (IMO) 2009, MSC.1/Circ.1331 Guidelines for construction, installation, maintenance and inspection/survey of means of embarkation and disembarkation, IMO, London.

International Maritime Organization (IMO) 2014, The International Convention for the Safety of Life at Sea (SOLAS) 1974 as amended, IMO, London.

Isle of Man Ship Registry 1989, Government Circular 152/89, Merchant Shipping (Code of Safe Working Practices) Regulations 1989, Isle of Man Ship Registry, Douglas, Isle of Man, British Isles. Available at www.iomshipregistry.com/

Maritime and Coastguard Agency (MCA) 2006, Marine Guidance Note MGN 331 (M+F) The Merchant Shipping and Fishing Vessels (Provision and use of work equipment) Regulations 2006, (PUWER), MCA, Southampton, UK. Available at /www.gov.uk/government/organisations/maritime-and-coastguard-agency

Maritime and Coastguard Agency (MCA) 2006, Marine Guidance Note MGN 332 (M+F) The Merchant Shipping and Fishing Vessels (Lifting Operations and Lifting Equipment) Regulations 2006, (LOLER), MCA, Southampton, UK. Available at www.gov.uk/government/organisations/maritime-and-coastguard-agency

Maritime and Coastguard Agency (MCA) 2010, Marine Guidance Note MGN 410 (M+F) The Merchant Shipping and Fishing Vessels (Health and Safety at Work) (Work at Height) Regulations 2010, MCA, Southampton, UK. Available at www.gov.uk/government/organisations/maritime-and-coastguard-agency

Maritime and Coastguard Agency (MCA) 2017, Code of Safe Working Practices for Merchant Seafarers, MCA, Southampton, UK. Available at www.gov.uk/transport/maritime-safety

Work at Height Safety Association (UK) n.d., Guidance on the use of single and twin energy absorbing lanyards WAHSA TGN02 Technical Guidance Note 2 (formerly TGN04), viewed 05 October 2018. Available at http://www.wahsa.org.uk/guidance-notes/

Working at Height Association (WAHA) 2011, Twin Tail Lanyard Use (Rev 2), Technical Bulletin, WAHA Australia, viewed 05 October 2018. Available at www.waha.org.au/technical-bulletins/

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the master, chief mate, bosun, 3 able seamen, ordinary seaman and deck cadet from Berge Daisetsu, Berge Bulk Maritime, the Australian Maritime Safety Authority and the Isle of Man Ship Registry.

Submissions were received from Berge Bulk Maritime, the Australian Maritime Safety Authority and the Isle of Man Ship Registry. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_2.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number 338-MO-2018-001
Occurrence date 11/01/2018
Location Smelter Berth, Portland
State Victoria
Report release date 30/10/2019
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Marine
Marine occurrence category Injury
Occurrence class Incident
Highest injury level Serious

Ship details

Name Berge Daisetsu
IMO number 9713179
Ship type Cargo operations
Flag Isle of Man
Manager Berge Bulk Maritime
Departure point Portland, Victoria
Destination Wallaroo, South Australia
Damage Nil

Accredited representative to the NTSB investigation into the collision with terrain involving a Gregory S. Browning Zodiac 601XL registered N929GB, near Thompson's Station, Tennessee, United States, on 21 December 2017

Summary

On 21 December 2017, the pilot of a Gregory S. Browning  Zodiac 601XL departed Shelbyville Municipal Airport, Tennessee on a flight to Wifferdill Airport, Chapmansboro, Tennessee. A short time later, witnesses in the vicinity of Chapmansboro reported hearing a loud ‘boom’ similar to a crash. The aircraft was found in an open field in an upright position with substantial damage. The pilot, the only person on board, sustained fatal injuries. The National Transportation Safety Board (NTSB) of the United States commenced an investigation into the occurrence.

As Australia is the State of Manufacture of the engine, the ATSB requested to be appointed as an accredited representative to the NTSB investigation in accordance with clause 5.18 of Annex 13 to the Convention on International Civil Aviation Aircraft Accident and Incident Investigation. An ATSB investigator was appointed as accredited representative to the NTSB on 8 January 2018. To facilitate support to the NTSB investigation, the ATSB also initiated an investigation under the Australian Transport Safety Investigation Act 2003.

The NTSB has completed their investigation and the final report is available on the NTSB website.

Any enquires relating to the investigation should be directed to the NTSB at: www.ntsb.gov

Occurrence summary

Investigation number AE-2018-002
Occurrence date 21/12/2017
Location near Thompson's Station, Tennessee, USA
State International
Report release date 20/12/2019
Report status Final
Investigation level Defined
Investigation type External Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Model Gregory S. Browning, Zodiac 601XL
Registration N929GB
Sector Piston
Operation type Unknown
Departure point Shelbyville Municipal Airport, Tennessee, USA
Destination Wifferdill Airport, Chapmansboro, Tennessee, USA
Damage Substantial

Signals passed at danger by train 7750, Marshall, Victoria, on 2 January 2018

Final report

Report release date: 15/01/2020

Safety summary

What happened

On 2 January 2018 at about 1413, V/Line train 7750 was travelling from Waurn Ponds to Geelong as an empty car service not carrying passengers. Shortly after passing Marshall Railway Station, the train passed two signals at Danger. After passing these signals, the train entered the single line section between Marshall and South Geelong, and also the Marshalltown Road level crossing before the crossing booms had lowered. The driver applied braking as the train entered the crossing and the train came to a stop.

The 1305 V/Line Melbourne to Warrnambool passenger service, train 8865, had departed Geelong at about 1410 and was proceeding towards Marshall on the same single line section. The trains were scheduled to cross using the loop track at Marshall. The train controller in Melbourne was monitoring the progress of both trains in order to operate the points and signals at Marshall to effect the crossing. When he became aware that train 7750 was passing signals at Danger, the controller initiated a radio emergency fleet call instructing both trains to stop. When stopped, the distance between the trains was about 940 m.

What the ATSB found

The ATSB found that the driver of train 7750 did not respond to the Stop indications of signals MSL10 and MSL8 at Marshall. He subsequently made an emergency brake application, either after noticing that the Marshalltown Road level crossing booms were not lowered or possibly in a delayed recognition of signal(s) MSL10 and/or MSL8 being at Stop. The driver’s performance was probably influenced by symptoms associated with nicotine withdrawal, having not applied a nicotine patch on this day.

Following this incident, the driver of train 7750 tested positive for an inactive metabolite of cannabis, with levels suggesting use within the previous 7 days. It could not be determined whether cannabis use had affected the driver’s performance at the time of this incident.

V/Line’s drug and medical regimes had not previously identified that this driver had been using cannabis, and the driver had not been subject to random drug testing during his employment with V/Line.

The signalling system at Marshall was not fitted with any form of positive train protection system and was reliant on driver compliance with signal indications.

What's been done as a result

V/Line has installed a train protection system at this location to stop a train that has passed a signal at Danger. The system also has several over-speed sensors to prevent a train entering the Marshalltown Road level crossing when unprotected.

V/Line continues with planning for the provision of three-position signalling for this section as part of other infrastructure projects.

Safety message

Nicotine withdrawal can affect a driver’s performance. To minimise adverse impacts, attempts by safety-critical workers to stop smoking should be managed under medical supervision.

Rail operators should consider fitting authority-overrun intervention at locations (like Marshall) that present a heightened risk due to rail operations on a single, bidirectional track.

 

The occurrence

On 2 January 2018, the driver was rostered to commence work at 1158. He first ran the V/Line 1250 service from Southern Cross Station to Waurn Ponds. On arrival at Waurn Ponds, the driver changed ends and train 7750 departed empty cars[1] towards Geelong. The driver was to proceed to Geelong where the train would then form the 1435 passenger service to Melbourne (Figure 1).

Figure 1: Marshall Railway Station location relative to Waurn Ponds and Geelong

Figure 1: Marshall Railway Station location relative to Waurn Ponds and Geelong. Source: PASS Assets (Public Transport Victoria)

Source: PASS Assets (Public Transport Victoria) adapted by Chief Investigator, Transport Safety (Vic)

After passing the Departure signal at Waurn Ponds, there were five signals within the Marshall location over a distance of about 5 km. Distant signal[2] MSL22 was followed by four Home Signals,[3] MSL24, MSL26, MSL10 and MSL8 (Figure 2).

Figure 2: The sequence of signals through Marshall, travelling towards Geelong

Figure 2: The sequence of signals through Marshall, travelling towards Geelong.

Source: Chief Investigator, Transport Safety (Vic)

At 14:09:23[4], the train passed Distant signal MSL22 at a speed of about 86 km/h. This signal displayed a Caution indication, meaning that at least one Home signal within the Marshall location was at Stop. Prior to MSL24, the train’s speed was reduced to 57 km/h at the Surf Coast Highway level crossing, exceeding the Temporary Speed Restriction (TSR) of 40 km/h at that location.

The train speed was then increased and the train passed signal MSL24 (that was at Proceed) at a speed of about 85 km/h at 14:12:15. The train then continued at speeds of up to 94 km/h before reducing speed and passing MSL26 at about 71 km/h at 14:13:10. This reduction in speed was consistent with an approaching TSR of 70 km/h that applied just beyond signal MSL8.

The right-hand arm of signal MSL26, that was applicable for the straight-route, was at Proceed and the signal for the loop was at Stop. This indicated that the points were set for the straight (number 1) track and that train 7750 was authorised to proceed on this track.

The intention of the train controller was to hold train 7750 at MSL10 to allow the Warrnambool bound train (8865) to enter the loop (number 2) track. Train 7750 was then to proceed towards Geelong. Train 8865 would then have been required to remain in the loop at Marshall to allow a Warrnambool to Southern Cross train that was following train 7750 to also cross.

After passing MSL26, the speed of train 7750 further reduced. Home signals MSL10 and MSL8 were at Stop and the train passed both signals at a speed of about 64 km/h, at 14:13:24 and 14:13:29 respectively. The train had passed signals MSL10 and MSL8 without authority. This type of event is referred to as a Signal Passed At Danger (SPAD).

The driver reported noticing that the Marshalltown Road level crossing booms were up and making an Emergency brake application. The train entered the single line between Marshall and South Geelong and then the level crossing, before the booms had lowered.

The train controller had commenced his shift at 0700 working the ‘Geelong Room’ that managed rail traffic between Manor Junction[5] and Waurn Ponds. In preparation for the cross of the two trains at Marshall, he was observing the signalling control and CCTV VDU[6] when he saw train 7750 go through Marshall platform travelling too fast to stop at MSL10. Realising that train 7750 would not be able to stop, the train controller made a fleet radio transmission to all trains in the area to ‘Red Light’ (Stop). He then radioed the drivers of trains 7750 and 8865 to confirm that they had both stopped. The CCTV also allowed the train controller to confirm that train 7750 had stopped beyond the Marshalltown Road level crossing.

When both trains were stopped, the separation between train 7750 and train 8865 was about 940 m. For a single train travelling at an average speed of 85 km/h, this distance equated to about 40 seconds of travel.

Post-incident

Following the incident, the driver of train 7750 was drug and alcohol tested at Geelong at approximately 1538. Drug testing was by sampling oral fluid and returned a negative result. Testing for alcohol also returned a negative result.

V/Line subsequently requested (under its Rail Safety Worker Health Assessment processes) that the driver undertake a drug test by urine sample. This was taken at around 1000 the following morning (3 January). This testing returned a positive result for the presence of an inactive metabolite of cannabis.
__________

  1. The train was transferring to another location without passengers, and was not required to stop at any stations.
  2. In a two-position signalling system, a Distant signal is located prior to the first Home signal for a location and provides information to drivers on the indication of Home signals on the through route.
  3. Signals that are ‘absolute’ (or Stop-and-Stay) and directly protect higher-risk locations such as infrastructure at which a potential conflict of traffic exists. When cleared (at Proceed), this signal gives the driver the authority to enter the section.
  4. Times in this detailed sequence are based on train data records and expressed as hour:minutes:seconds
  5. Located between Little River and Werribee, on the Melbourne side of Geelong.
  6. Visual Display Unit(s)

Context

Marshall

Marshall is located on the single line between Geelong and Warrnambool, about 80 rail-km from Melbourne. The line is part of the regional intrastate network managed by V/Line Corporation. Adjacent to Marshall Railway Station was the main line (number 1 track) and a loop (number 2 track) to facilitate trains crossing or passing. Marshall Railway Station had a single platform adjacent to the number 1 track. Except where speed restrictions applied, the line speed for this track was 115 km/h.

Safeworking and signalling

Rail traffic between Geelong and Waurn Ponds was managed under the operating rules and procedures applicable to the Track Block Safeworking System. The object of this system is to prevent trains being in the section between two adjoining locations at the same time. Interlocking prevented the train controller from being able to place a signal controlling the entrance into a single line section to the Proceed position until the section was clear.

Fixed signalling through Marshall was two-position. This type of signalling is now uncommon in Victoria, having mostly been replaced with three-position signalling. Two-position signals are route signals that apply to a single route. Home signals do not provide information on the aspect of the next signal, nor specific guidance for the driver on the speed to the next signal. The driver of train 7750 indicated that he was familiar with the signalling system through Marshall.

Marshall had a signal sequence that comprised a Distant signal followed by a series of Home signals. For Geelong-bound trains, the signal sequence through Marshall was:

  • MSL22 (Distant signal)
  • MSL24 (Home signal)
  • MSL26 (Home signal) that included separate signal heads for the mainline and the loop tracks
  • MSL10 (Home Signal) and MSL12 (Home signal on the loop track)
  • MSL8 (Home signal).

MSL26 was located before Marshall Railway Station, and MSL10 and MSL8 following the station and before Marshalltown Road level crossing (Figure 3).

Figure 3: Extract of signalling diagram at Marshall Railway Station

Figure 3: Extract of signalling diagram at Marshall Railway Station. The diagram is based on the signalling diagram covering Marshall Railway Station. Key features are retained to show the location of signals MSL26, MSL 10 and MSL8 in relation to the station platform and Marshalltown Road level crossing.

The diagram is based on the signalling diagram covering Marshall Railway Station. Key features are retained to show the location of signals MSL26, MSL 10 and MSL8 in relation to the station platform and Marshalltown Road level crossing.

Source: PTV DMS, amended and annotated by Chief Investigator, Transport Safety (Vic)

The aspect displayed on Distant signals at each end of the Marshall location was governed by the status of the Home signals through Marshall and functioned automatically. For traffic coming from Waurn Ponds, if all mainline Home signals at Marshall were Clear, MSL22 would indicate Proceed (green). However, if any of MSL24, MSL26, MSL10 or MSL8 were at Stop, MSL22 would indicate Caution (yellow). A similar signalling sequence was in place for trains travelling from South Geelong to or through Marshall.

Home signals MSL10 and MSL8 were two-position, colour-light signals that displayed either a red (Stop) or green (Proceed) aspect (Figure 4).

Figure 4: Signals MSL10 and MSL8 at Marshall, pictured displaying ‘Stop’ indications

Figure 4: Signals MSL10 and MSL8 at Marshall, pictured displaying ‘Stop’ indications. The picture shows signal MSL10 adjacent to the Geelong-end of Marshall Railway Station. Signal MSL8 is identified in the distance, closer to the Marshalltown Road level crossing.

The picture shows signal MSL10 adjacent to the Geelong-end of Marshall Railway Station. Signal MSL8 is identified in the distance, closer to the Marshalltown Road level crossing.

Source: Chief Investigator, Transport Safety (Vic)

Signalling control for Marshall was managed from Centrol[7] in Melbourne. The control workstation provided for remote control and monitoring of the signalling system. Train controllers could observe the status of all the signalling in the area and operate points and signals. The system was fitted with a SPAD alarm for this location (that would alert the controller), but in this instance the alarm volume had been turned down.

The train controller had control of all Home signals at Marshall. Home signals were operated individually, or a through-route could be set. In the through-route scenario, signals would clear when the section ahead became available without any call on the system from the train controller. However, whenever trains were to cross, the train controller was required to select and call for the desired route and clear the signals individually.

The safe application of signalling at Marshall was reliant on drivers responding correctly to signals, and did not include any additional enforcement controls to protect against a train exceeding its authority.

Marshalltown Road level crossing activation

The Marshalltown Road level crossing was track-circuit activated. However, when signal MSL10 displayed a Stop indication, the level crossing would not be activated if a train passed the signal and occupied the track circuit on the Geelong side of the signal. This configuration was to cater for a low-speed run-around movement[8] where a calling-on signal[9] provided authority for a locomotive to move from one end of a train to the other without activating the Marshalltown Road level crossing. Consistent with this configuration, train 7750 did not trigger the crossing protection system until it had travelled beyond signal MSL8, approximately 28 m before the level crossing.

Signalling system playback

The status of signals and the movement of trains through the section were captured on the recording of the train controller’s VDU. The colour of each track section also provided an indication of its status as follows:

  • Red indicated the presence of a train in the section
  • Green indicated the track was clear and the route was set
  • Blue indicated the track was clear but no route was set.

The first snapshot (Figure 5) showed the status of the network with train 7750 at the Waurn Ponds platform.

At this point, a route had been set (in green) from Waurn Ponds Railway Station to Marshall. Departure signal WPD10 was at Proceed, MSL22 at Caution (because MSL10 and MSL8 were at Stop), MSL24 and MSL26 were at Proceed, and MSL10 was at Stop to hold train 7750 at Marshall Railway Station.

Beyond MSL10, the track was clear but a route had not yet been set beyond MSL10. This route condition remained unchanged until train 7750 later occupied this single-line section of track.

Figure 5: Snapshot of VDU when train 7750 was at Waurn Ponds

Figure 5: Snapshot of VDU when train 7750 was at Waurn Ponds. A route had been set from Waurn Ponds to Marshall Railway Station. Distant signal MSL22 was at Caution (because MSL10 and MSL8 were at Stop) and signals MSL24 and MSL26 were at Proceed. Beyond MSL10, the track was clear but a route had not yet been set beyond MSL10.

A route had been set from Waurn Ponds to Marshall Railway Station. Distant signal MSL22 was at Caution (because MSL10 and MSL8 were at Stop) and signals MSL24 and MSL26 were at Proceed. Beyond MSL10, the track was clear but a route had not yet been set beyond MSL10.

Source: V/Line, annotated by Chief Investigator, Transport Safety (Vic)

The second snapshot (Figure 6) showed the status of the network as train 7750 passed WPD10. The route for train 8865 (green) was set from South Geelong through to MSL4 but the train had not yet been detected in this section. The status of signals and points at Marshall remained unchanged.

Figure 6: Snapshot of VDU after train 7750 had departed Waurn Ponds

Figure 6: Snapshot of VDU after train 7750 had departed Waurn Ponds. The route for train 8865 (the Melbourne to Warrnambool) was set through to MSL4 but the train had not yet been detected in the section beyond South Geelong. The status of signals and points at Marshall remained unchanged.

The route for train 8865 (the Melbourne to Warrnambool) was set through to MSL4 but the train had not yet been detected in the section beyond South Geelong. The status of signals and points at Marshall remained unchanged. Source: V/Line, annotated by Chief Investigator, Transport Safety (Vic)

The third snapshot (Figure 7) showed train 7750 having passed signals MSL24 and MSL26,and these had reverted to Stop. The train was now in the track sections adjacent to the Marshall Railway Station. It had passed MSL10, but had not yet reached MSL8. The Warrnambool-bound train 8865 occupied the section up to Distant signal MSL2.

Train 8865 had a route (green) set towards Marshall, but not beyond signal MSL 4, which was at Stop.

Figure 7: Snapshot of VDU when train 7750 was passing Marshall Railway Station

Figure 7: Snapshot of VDU when train 7750 was passing Marshall Railway Station.
Train 7750 had passed MSL24 and MSL 26, and the train was in the track sections adjacent to the Marshall Railway Station and beyond MSL10, but not yet past MSL8. The Warrnambool-bound train 8865 was in the section up to Distant signal MSL2, and had a route set  towards Marshall, but not beyond signal MSL 4 which was at Stop.

Train 7750 had passed MSL24 and MSL 26, and the train was in the track sections adjacent to the Marshall Railway Station and beyond MSL10, but not yet past MSL8. The Warrnambool-bound train 8865 was in the section up to Distant signal MSL2, and had a route set towards Marshall, but not beyond signal MSL 4 which was at Stop.

Source: V/Line, annotated by Chief Investigator, Transport Safety (Vic)

The VDU recording showed that train 7750 travelled beyond signal MSL8 and entered the Marshalltown Road level crossing travelling on the single line towards South Geelong (Figure 8). The level crossing protection had also activated (indicated by its change on the VDU from a black line to white).

This had placed the trains in potential conflict. Once past MSL8, the next Home signal that would face train 7750 was SGL19 at South Geelong, beyond the location of train 8865.

Figure 8: Snapshot of VDU when train 7750 passes MSL8 and enters the level crossing

Figure 8: Snapshot of VDU when train 7750 passes MSL8 and enters the level crossing. Train 7750 was now on the single line towards South Geelong, placing the trains in conflict.

Train 7750 was now on the single line towards South Geelong, placing the trains in conflict.

Source: V/Line, annotated by Chief Investigator, Transport Safety (Vic)

The recording then showed that train 8865 had passed signal MSL2 and entered the section up to signal MSL4, that was at Stop (Figure 9). The trains were now in adjacent track sections. There were no further signals that could have prevented train 7750 continuing to the location of train 8865.

Figure 9: Snapshot of VDU with trains 7750 and 8865 stopped in adjacent sections

Figure 9: Snapshot of VDU with trains 7750 and 8865 stopped in adjacent sections. Train 8865 would be held by signal MSL4 that was at Stop. However, there was no signal ahead of train 7750 that would prevent it from continuing to the location of train 8865.

Train 8865 would be held by signal MSL4 that was at Stop. However, there was no signal ahead of train 7750 that would prevent it from continuing to the location of train 8865.

Source: V/Line, annotated by Chief Investigator, Transport Safety (Vic)

The driver

The driver had been working with V/Line since 2005. His safeworking and route knowledge qualifications were current and he was certified as medically fit for duty. By arrangement with the rostering area, together with the mutual exchange of shifts with other drivers, he generally worked shifts commencing between 0900 and 1000. This resulted in him regularly running of services between Melbourne and Waurn Ponds.

On this day, his shift had commenced at about 1200. This shift and the previous 7 days rostering would not have contributed to a fatigue condition.

Nicotine withdrawal

The driver had been a heavy smoker. In his endeavours to stop smoking, he had been using nicotine patches for about 3 months

Tobacco smoking exposes the user to a significant number of substances. The nicotine component of tobacco is a particularly addictive compound, and it is largely this property of nicotine that leads to difficulty in ceasing smoking.[10] [11] [12]

Cessation of tobacco smoking, especially if abrupt, can lead to the development of nicotine withdrawal. This is a recognised clinical entity, with clearly established criteria laid down in the World Health Organisation’s International Classification of Disease. Symptoms of nicotine withdrawal usually appear quite quickly after the last tobacco intake (within 2-3 hours) and peak in 2-3 days.[13] Tobacco withdrawal can lead to a myriad of symptoms, including task-related effects such as difficulty concentrating, memory impairment and attention difficulties. There are also other potential psychological and physiological effects.

Smoking cessation strategies usually adopt the approach of gradually reducing the nicotine intake rather than suddenly stopping. The transdermal patch is typically the first choice in terms of therapies to assist smokers to quit.[14] It comes in a range of different nicotine doses, from 5 mg to 21 mg. The replacement regime depends on the usual cigarette intake of the smoker prior to quitting. For example, a smoker of more than 10 cigarettes per day might use a 21/14/7 mg regimen, that involves wearing a 21 mg patch daily for 6 weeks, then a 14 mg patch daily for 2 weeks, then a 7 mg patch daily for 2 weeks.

In this instance, the driver had maintained the use of a 21 mg patch, and had not yet commenced to taper the dosage. However, the driver reported that on the day of this incident he did not apply a nicotine patch.

Use of Cannabis

The driver reported that he had been using cannabis for about 2 months to assist with sleep and nicotine withdrawal issues. Cannabis contains over 530 chemical compounds, including over 100 pharmacologically active constituents known as cannabinoids.[15]

The most potent and psychoactive of these is ∆9-tetrahydrocannabinol (∆9-THC, or more simply THC). Cannabinoids act on a specific class of cell receptor, which are widely distributed in the brain. They tend to be particularly located in brain regions associated with cognitive processes, memory, pain perception and psychomotor coordination.[16]

THC is broken down into an inactive metabolite, 11-nor-9- tetrahydrocannabinol-∆9-carboxylic acid (THC-COOH). This substance is the principal secondary metabolite of THC and is excreted from the body over a period of days to weeks.[17] THC-COOH is the metabolite targeted in blood or urine testing for cannabis use.

A single dose of THC may take up to 30 days to be fully eliminated from the body. THC may be found in the urine for at least 48 to 72 hours after oral administration.[18] With repeated use, however, cannabinoids can accumulate in high levels in the body. Such chronic, long term use leads to accumulation of THC and THC-COOH in fatty tissue, with continued excretion into the urine for as long as 30 to 60 days from the time chronic use is halted.

The effects of cannabis on cognitive function and psychomotor performance are documented in literature. Studies have shown that acute cannabis use impairs cognitive functions such as attention and learning,[19] increases reaction time and causes difficulty in concentration.[20] [21] Cannabis can also adversely affect human performance of complex cognitive tasks for up to 24 hours, with the extent of effects post-exposure depending on the task complexity.[22] [23] One consistent finding with cannabis exposure is the adverse effect on memory. Cannabis-induced disruption of normal memory functions, particularly short-term memory, have been described.[24] [25] [26] [27]

Driver toxicology

The toxicology assessment for this driver used a urine sample collected from the driver at around 1000 on 3 January. Analysis performed on 4 January 2018 revealed the presence of THC-COOH in the urine. THC-COOH is the inactive secondary metabolite of THC and there is no specific biological effect of THC-COOH. Whereas the inactive THC-COOH can be detected in urine for more than 7 days after a single use, and longer for habitual use, urinary THC values have been shown to peak about two hours post cannabis use, and then decline to be unrecordable within 6 hours.[28] There was no level of THC (the active metabolite) recorded or reported in the toxicology assessment.

The presence of THC-COOH in urine at concentrations greater than 15 ng/mL is a strong indicator that the individual has used cannabis. If the urinary THC-COOH level is greater than 100 ng/mL, this indicates relatively recent use, probably within the previous 7 days. Levels greater than 500 ng/mL suggest chronic and recent use. The recorded level in the driver involved in this particular incident was 120 µg/L (equivalent to 120 ng/mL). This measured level was over 100 ng/mL and therefore suggests use of cannabis probably within the previous 7 days.

Methods for detecting cannabis use

Drug testing is generally effective at determining the presence of a drug or its metabolite. A drug test will have a minimum threshold (‘cut-off’ value) above which the test result will be considered positive, and below which it will be considered negative. A drug test may also be negative despite recent or ongoing drug use if the window of detection has passed or there has been adulteration of the specimen.

Oral fluid testing

Oral fluid testing for cannabis targets the active metabolite Delta-9-tetrahydrocannabinol (THC). This is the most potent and psychoactive of the metabolites of cannabis.[29] The consumption of cannabis via smoking leads to the oral tissues being exposed to high concentrations of THC. The THC is then released and is detectable in the saliva during the next several hours following use, and this process can last up to 24 hours.[30]

Oral fluid testing represents relatively new technology, being introduced in several countries in the last 10-20 years.[31] [32] In general, it is used for detecting the presence of certain drugs in settings such as the workplace or road traffic enforcement. The accuracy and reliability of these tests has also been improving over the years.[33]

Urine testing

Typically, urine is tested for THC-COOH, an inactive metabolite of cannabis. This metabolite can be detected in urine for more than 30 days after cannabis use, and so this test is effective at detecting prior use of cannabis. However, a positive result for this metabolite does not provide information about impairment at the time of testing. A more extensive test panel including testing for THC and 11-hydroxy-THC as well as THC-COOH could provide a more comprehensive picture of recent cannabis use.

Urine tests have some disadvantages, including a greater potential for false samples and adulteration. Products can be used to mask the presence of certain drugs in urine samples and intentional urine dilution may reduce drug concentration below the cut-off level of the test.

V/Line systems to identify employee use of cannabis

Relevant legislation

Drug and alcohol requirements for Rail Transport Operators and Rail Safety Workers were governed by the Rail Safety National Law (RSNL)[34] and associated Regulations. The RSNL required that rail operators prepare and implement a Drug and Alcohol Management Program (DAMP). It also required that Rail Safety Workers not carry out, or attempt to carry out, rail safety work whilst ∆9-THC (the active metabolite of cannabis) was present in their oral fluid or blood.

V/Line Policy and Procedures

V/Line had developed a drug and alcohol policy and implemented a drug-testing regime. The policy required that its employees not be under the influence of alcohol or illicit drugs or be impaired by any other drugs.[35] Further detail on the implementation of the policy was included in its management guide.[36]

Responsibilities

The management guide specified that employees, including drivers, report to work in a fit condition without detectable levels of alcohol or other drugs, and notify their manager if their ability to undertake rail safety work might be hindered by alcohol or any other drug.

The guide also detailed responsibilities for V/Line management including supervisors of drivers. Supervisor responsibilities included ensuring persons were not hindered by the presence of alcohol or other drugs whilst reporting for or being on duty. It also included a requirement to ensure the provision of information to employees about the problems arising from the consumption or use of alcohol, tobacco and other drugs.

Testing Program

Assurance of employee compliance with its alcohol and drug management policy included random[37] and post-incident drug testing. Testing was conducted by an independent agency. Employees working only in Victoria were tested using sampling of oral fluid.[38] This method included testing for the presence of cannabis metabolites in oral fluid. The program required testing of a minimum of 30 per cent of workers per annum, of which at least 25 per cent were required to be Rail Safety Workers (RSW). In practice, the proportion of RSW tested was significantly higher than this requirement. Between commencement of random testing in 2015 and 1 January 2018 (prior to this incident), there was one positive result returned from the random drug testing program, and that was for THC.

The guide also made provision for ‘for cause’ testing. In the event that a supervisor or manager had reasonable grounds to suspect that a person may not meet the drug and alcohol criteria, that person could be required to undergo testing. For the same period from 2015 to 1 January 2018, there had been one ‘for cause’ test, and it had returned a positive result for cannabis use. There was no specific training of supervisors to assist them to undertake fitness for duty assessment or to make decisions on the need to conduct ‘for cause’ testing.

In addition, its train drivers were classified as Category 1 Safety Critical Workers and were required to undertake medical assessment that included testing of urine for the presence of a number of prescribed drugs (including cannabis). Drivers were required to undergo Category 1 medical assessments every 5 years (up to the age of 50), every 2 years (50 – 60) and every year above age 60.

Other SPADs at or near Marshall

On 29 May 2015, a V/Line train passed signals MSL10 and MSL 8 at Stop.[39] Following its investigation of this incident, the ATSB reported that:

Marshall was re-established with infrastructure that catered for the relatively small number of passenger services. However, over a ten-year period, rail traffic increased significantly (16 services per week in 2005 to 160 in 2015), altering both the operating environment and the risk profile of the location. To improve the control of traffic through this location, there was scope to upgrade to three-position signalling and potentially introduce measures to mitigate against SPAD events.

In response to the May 2015 SPAD event, V/Line introduced a Temporary Speed Restriction (TSR) of 70 km/h at this location. This TSR was still in place at the time of the January 2018 SPADs.

Subsequent to the May 2015 SPAD, V/Line advised that its internal investigation had recommended a three-position signalling upgrade for the Geelong-Waurn Ponds section of track and that it was undertaking a study into the duplication of track between South Geelong and Waurn Ponds. V/Line has advised that track duplication was still under consideration.

Between January 2015 and January 2018, there were six other SPAD events between Waurn Ponds and South Geelong. Five involved signal MSL24 and one was at MSL4. All of these SPADs were attributed by V/Line to driver misjudgement. As a mitigation for the SPADs at MSL24, a 40 km/h TSR was introduced for the approach to this signal.

__________

  1. V/Line train control, located in Melbourne.
  2. Where the locomotive is moved from one end of the train to the other.
  3. Subsidiary signal fixed under the Home signal for the route concerned and when showing a 'Proceed' indication authorises the driver to proceed under control into a section of line which may be obstructed at any point.
  4. Kessler DA, Natanblut SL, Wilkenfeld JP, Lorraine CC, Mayl SL, Bernstein IB, Thompson L: Nicotine addiction: a pediatric disease. J Pediatr 1997; 130:518–524.
  5. The Health Consequences of Smoking—Nicotine Addiction: A Report of the Surgeon General. Rockville, MD, US Department of Health and Human Services, 1988.
  6. Royal College of Physicians of London. Tobacco Advisory Group. (2000). Nicotine addiction in Britain: a report of the Tobacco Advisory Group of the Royal College of Physicians. Royal College of Physicians.
  7. Hughes JR. Effects of abstinence from tobacco: valid symptoms and time course. Nicotine & Tobacco Research. 2007 Mar 1;9(3):315-27.
  8. Fiore MC: Treating tobacco use and dependence: an introduction to the US Public Health Service Clinical Practice Guideline.
  9. Mehmedic Z, Chandra S, Slade D, Denham H, Foster S, Patel AS, Ross SA, Khan IA, ElSohly MA. Potency trends of ∆9‐THC and other cannabinoids in confiscated cannabis preparations from 1993 to 2008. Journal of forensic sciences. 2010 Sep 1;55(5):1209-17.
  10. Hall W. Solowij N. Adverse effects of cannabis. Lancet 1998; 352:1611-6.
  11. O’Kane CJ, Tutt D, Bauer L. Cannabis and driving: a new perspective. Emerg Med 2002; 14:296- 303.
  12. Yesavage JA, Leirer VO, Denari M, Hollister LE. Carry-over effects of marihuana intoxication on aircraft pilot performance: a preliminary report. Am J Psychiatry 1985; 142:1325-9.
  13. Beautrais AL, Marks DF. A test of state dependency effects in marihuana intoxication for the learning of psychomotor tasks. Psychopharmacologia 1976; 46:37-40.
  14. Heishman SJ, Huestis MA, Henningfield JE, Cone EJ. Acute and residual effects of marijuana: profiles of plasma THC levels, physiological, subjective, and performance measures. Pharmacol Biochem Behav 1990; 37:561-5.
  15. Macavoy MG, Marks DF. Divided attention performance of cannabis users and non-users following cannabis and alcohol. Psychopharmacologia 1975; 44:147-52.
  16. Heishman, Huestis, Henningfield, Cone, op. cit.
  17. Yesavage, Leirer, Denar, Hollister., op. cit.
  18. Abel EL. Marijuana and memory: acquisition or retrieval? Science 1971; 173:1038-40.
  19. Darley CF, Tinklenberg JR, Roth WT, Atkinson RC. The nature of storage deficits and state- dependent retrieval under marihuana. Psychopharmacologia 1974; 37:139-49.
  20. Heishman SJ, Arasteh K, Stitzer ML. Comparative effects of alcohol and marijuana on mood, memory, and performance. Pharmacol Biochem Behav 1997; 58:93-101.
  21. Tinklenberg JR, Melges FT, Hollister LE, Gillespie HK. Marihuana and immediate memory. Nature 1970; 226:1171-2.
  22. Manno JE, Manno BR, Kemp PM, Alford DD, Abukhalaf IK, McWilliams ME, Hagaman FN, Fitzgerald MJ. Temporal indication of marijuana use can be estimated from plasma and urine concentrations of ∆9-tetrahydrocannabinol, 11-hydroxy-∆9-tetrahydrocannabinol, and 11-nor-∆9-tetrahydrocannabinol- 9-carboxylic acid. Journal of analytical toxicology. 2001 Oct 1;25(7):538-49.
  23. Huestis MA. Human cannabinoid pharmacokinetics. Chemistry & Biodiversity 2007 Aug;4(8):1770-804.
  24. Niedbala RS, Kardos KW, Fritch DF, Kardos S, Fries T, Waga J, Robb J, Cone EJ. Detection of marijuana use by oral fluid and urine analysis following single-dose administration of smoked and oral marijuana. Journal of Analytical Toxicology 2001 Jul 1;25(5):289-303.
  25. Steinmeyer S, Ohr H, Maurer HJ, Moeller MR. Practical aspects of roadside tests for administrative traffic offences in Germany. Forensic science international. 2001 Sep 15;121(1-2):33-6.
  26. Gallardo E, Barroso M, Queiroz JA. Current technologies and considerations for drug bioanalysis in oral fluid. Bioanalysis. 2009 Jun;1(3):637-67.
  27. Strano-Rossi S, Castrignanò E, Anzillotti L, Serpelloni G, Mollica R, Tagliaro F, Pascali JP, Di Stefano D, Sgalla R, Chiarotti M. Evaluation of four oral fluid devices (DDS®, Drugtest 5000®, Drugwipe 5+® and RapidSTAT®) for on-site monitoring drugged driving in comparison with UHPLC–MS/MS analysis. Forensic science international. 2012 Sep 10;221(1-3):70-6.
  28. Rail Safety National Law (South Australia) Act 2012, as applied in Victoria.
  29. SAPO-1, Policy – Alcohol and Drugs Management, dated 26/10/2016.
  30. SAMG-51, Alcohol, Tobacco and other Drugs Management Guide, Revision 1, dated 17/08/2017.
  31. The random drug testing program commenced in August 2015
  32. In NSW, urine testing was used for drug testing.
  33. ATSB, Investigation report RO-2015-009, Signals Passed at Danger by Train 1240 at Marshall near Geelong, Victoria on 29 May 2015

Safety analysis

The incident

The driver did not respond to the Stop indications of signals MSL10 and MSL8 and passed these signals without authority. His subsequent action to stop the train was either after noticing that the Marshalltown Road level crossing booms were not lowered, or possibly in a delayed recognition that signal MSL10 and/or signal MSL8 was at Stop. Had the driver not stopped the train, there were no other signalling defences to alert the driver against continuing through the section in conflict with the approaching Warrnambool-bound passenger train.

The actions of the train controller to monitor the passage of the trains and then make a radio call to stop trains were appropriate.

The driver

Nicotine withdrawal

Withdrawal from nicotine can produce a range of symptoms that can also affect human performance. The driver had been using the 21 mg patch for about 3 months. However, the driver reported that on the day of the incident he did not apply a patch. It is therefore likely that he was experiencing symptoms of nicotine withdrawal.[40]

Nicotine withdrawal symptoms typically become apparent within a few hours of last nicotine exposure. Task-related effects can include difficulty concentrating, memory impairment and attention difficulties. These and other symptoms of nicotine withdrawal probably had an adverse effect on the performance of the driver.

Cannabis use

Cannabis has a range of short and long term adverse effects on human health and performance. There is considerable evidence of a residual effect of cannabis during the 12 - 24 hour period following use, which may occur after a single dose. The residual drug effects observed involve impairment of performance on tests of focused attention, visual and verbal memory, and visuomotor functions.[41]

Oral fluid testing (taken about 90 minutes after the event) returned a negative result for the presence of the active metabolite of cannabis (THC). Subsequent urine testing identified an inactive metabolite at a level suggesting cannabis use probably within the previous 7 days. Based on the available evidence, it was not possible to determine if the prior use of cannabis had affected the driver’s performance on the day of the event.

Expectancy

Train 7750 was a non-passenger-carrying train returning to Geelong and was therefore not required to make passenger stops at any stations, including at Marshall Railway Station. It is possible that the notion of the service being ‘express’ established in the driver’s mind an expectation that the train would have an unimpeded passage through to Geelong and that all signals would be at Proceed. It is possible that this expectancy affected the driver’s observation of, or perception of, the signal indications of MSL10 and MSL8.

Recall of Distant signal indication

When passed by train 7750, Distant signal MSL22 was at Caution, indicating that a subsequent signal within the Marshall location was at Stop. This Caution indication warns the driver to be prepared to stop at any upcoming Home signal within the Marshall group of signals, and the driver of train 7750 was familiar with its function and meaning.

However, this information was not utilised by the driver as the train approached signal MSL10. It is probable that the information indicated by Distant signal MSL22 was forgotten by the driver some time during the 4 minutes after passing MSL22. Such a lapse in short term memory would be consistent with symptoms associated with nicotine withdrawal.

Signalling information for driver

With two-position signalling, a Home signal at Stop (Red) may directly follow a Home signal at Proceed (Green), as it did in this case. Whereas, with three-position signalling, a driver is presented with signal aspects that indicate the status of the next signal. These aspects are also speed-related and in many locations have sequences that require the train speed to be reduced over several signal sections before a Stop indication is displayed. Three-position signalling would therefore have provided the driver with more information on the status of the next signal.

Drug testing

This driver

This driver had not been tested under the random drug testing program, and his use of cannabis had not been detected by V/Line prior to this event.

Comparison between oral fluid testing and urine testing

The detection window for oral fluid testing for cannabis use is much smaller than that for urine testing. The window of detection for cannabis in oral fluid testing is up to 24 hours, compared with 30 days or longer for testing of urine. The longer window for urine testing is due to the progressive metabolism of cannabinoids that are excreted in the urine over time.

The differences in detection windows and the targeted metabolite create different interpretations for a positive result for each type of test. Given the shorter detection window and the targeting of THC, a positive oral fluid test is indicative of recent use (within 24 hours).[42] [43] In contrast, a positive urine test indicates prior exposure to cannabis which could be 30 days prior or more. The prolonged detection window for urine testing is well outside the corresponding window of cannabis-induced impairment. A positive oral fluid test for cannabis, therefore, is much more likely to be correlated with cannabis-induced impairment, although there can be individual variation.[44]

‘For-cause’ testing

V/Line drug management guidelines provided that ‘for cause’ testing could be conducted should a supervisor have grounds to believe that an employee did not meet the drug criteria. However, supervisors were not trained in how to identify impairment or assess whether such grounds existed.

SPAD mitigation at Marshall

The Marshall location was not equipped with any form of authority-overrun intervention. A previous ATSB investigation[45] identified that, particularly due to increased traffic and associated risks at Marshall, ‘there was scope to introduce measures to mitigate against SPAD events’.

The Train Protection and Warning System (TPWS)[46] was installed at many locations with three-position signalling. TPWS initiates train braking to reduce the potential consequences of a SPAD event.

The train control system included an audible SPAD alarm for this location, to alert the train controller. However, in this instance, its volume had been turned down.
__________

  1. Expert Opinion: Signals Passed at Danger by Train 7750, Marshall, Victoria 2 January 2018, Flight Medicine Systems, Dr David G. Newman 30 April 2018
  2. Pope HG, Gruber AJ, Yurgelun-Todd D. The residual neuropsychological effects of cannabis: the current status of research. Drug Alcohol Depend 1995; 38:25-34.
  3. Menkes DB, Howard RC, Spears GF, Cairns ER. Salivary THC following cannabis smoking correlates with subjective intoxication and heart rate. Psychopharmacology. 1991 Feb 1;103(2):277-9.
  4. Gross SJ, Worthy TE, Nerder L, Zimmermann EG, Soares JR, Lomax P. Detection of recent cannabis use by saliva δ9-THC radioimmunoassay. Journal of Analytical Toxicology. 1985 Jan 1;9(1):1-5.
  5. Huestis, op. cit.
  6. ATSB, Investigation report RO-2015-009, op.cit.
  7. A train protection system developed in the UK and used on the Victorian rail network.

Findings

From the evidence available, the following findings are made with respect to the Signals Passed at Danger by Train 7750 at Marshall, Victoria on 2 January 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • The driver did not respond to signals MSL10 and MSL8 at Stop and passed the signals without authority.
  • The driver did not use a nicotine patch on the day of the incident, probably leading to nicotine withdrawal and associated symptoms that affected performance.

Other factors that increased risk

  • The driver had been using cannabis and this was not identified by V/Line.
  • The signalling system was not equipped with any form of authority-overrun intervention
  • The volume of the audible SPAD alarm at the train controller’s station had been turned down.

Other findings

  • V/Line did not provide training to its driver supervisors to assist them to effectively identify and take action to manage possible drug use by safety critical workers.

Safety issues and actions

Additional safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Following this incident, V/Line applied a 40 km/h speed restriction at this location as a temporary measure, issued a SPAD alert, and briefed drivers on risks associated with this location and empty car movements. This empty cars service also became a normal passenger run from Waurn Ponds.

V/Line completed its installation of a bespoke (two position signalling) TPWS for this location in June 2019. The system is designed to automatically apply the braking of a train that has had a SPAD. The system also has several over-speed sensors that are designed to prevent a train occupying an unprotected Marshalltown Road level crossing.

V/Line continues with planning for the provision of three-position signalling for this section as part of other infrastructure projects.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • The driver of train 7750
  • V/Line
  • Medvet testing contractor.

References

Abel EL. Marijuana and memory: acquisition or retrieval? Science 1971; 173:1038-40.

ATSB, Investigation report RO-2015-009, Signals Passed at Danger by Train 1240 at Marshall near Geelong, Victoria on 29 May 2015

Beautrais AL, Marks DF. A test of state dependency effects in marihuana intoxication for the learning of psychomotor tasks. Psychopharmacologia 1976; 46:37-40.

Darley CF, Tinklenberg JR, Roth WT, Atkinson RC. The nature of storage deficits and state- dependent retrieval under marihuana. Psychopharmacologia 1974; 37:139-49.

Expert Opinion: Signals Passed at Danger by Train 7750, Marshall, Victoria 2 January 2018, Flight Medicine Systems, Dr David G. Newman 30 April 2018

Fiore MC: Treating tobacco use and dependence: an introduction to the US Public Health Service Clinical Practice Guideline.

Gallardo E, Barroso M, Queiroz JA. Current technologies and considerations for drug bioanalysis in oral fluid. Bioanalysis. 2009 Jun;1(3):637-67.

Gross SJ, Worthy TE, Nerder L, Zimmermann EG, Soares JR, Lomax P. Detection of recent cannabis use by saliva δ9-THC radioimmunoassay. Journal of Analytical Toxicology. 1985 Jan 1;9(1):1-5.

Hall W. Solowij N. Adverse effects of cannabis. Lancet 1998; 352:1611-6.

Heishman SJ, Arasteh K, Stitzer ML. Comparative effects of alcohol and marijuana on mood, memory, and performance. Pharmacol Biochem Behav 1997; 58:93-101.

Heishman SJ, Huestis MA, Henningfield JE, Cone EJ. Acute and residual effects of marijuana: profiles of plasma THC levels, physiological, subjective, and performance measures. Pharmacol Biochem Behav 1990; 37:561-5.

Huestis MA. Human cannabinoid pharmacokinetics. Chemistry & Biodiversity 2007 Aug;4(8):1770- 804.

Hughes JR. Effects of abstinence from tobacco: valid symptoms and time course. Nicotine & Tobacco Research. 2007 Mar 1;9(3):315-27.

Kessler DA, Natanblut SL, Wilkenfeld JP, Lorraine CC, Mayl SL, Bernstein IB, Thompson L: Nicotine addiction: a pediatric disease. J Pediatr 1997; 130:518–524.

Macavoy MG, Marks DF. Divided attention performance of cannabis users and non-users following cannabis and alcohol. Psychopharmacologia 1975; 44:147-52.

Manno JE, Manno BR, Kemp PM, Alford DD, Abukhalaf IK, McWilliams ME, Hagaman FN, Fitzgerald MJ. Temporal indication of marijuana use can be estimated from plasma and urine concentrations of ∆9-tetrahydrocannabinol, 11-hydroxy-∆9-tetrahydrocannabinol, and 11-nor-∆9-tetrahydrocannabinol- 9-carboxylic acid. Journal of analytical toxicology. 2001 Oct 1;25(7):538-49.

Mehmedic Z, Chandra S, Slade D, Denham H, Foster S, Patel AS, Ross SA, Khan IA, ElSohly MA. Potency trends of ∆9‐THC and other cannabinoids in confiscated cannabis preparations from 1993 to 2008. Journal of forensic sciences. 2010 Sep 1;55(5):1209-17.

Menkes DB, Howard RC, Spears GF, Cairns ER. Salivary THC following cannabis smoking correlates with subjective intoxication and heart rate. Psychopharmacology. 1991 Feb 1;103(2):277-9.

Niedbala RS, Kardos KW, Fritch DF, Kardos S, Fries T, Waga J, Robb J, Cone EJ. Detection of marijuana use by oral fluid and urine analysis following single-dose administration of smoked and oral marijuana. Journal of Analytical Toxicology 2001 Jul 1;25(5):289-303.

O’Kane CJ, Tutt D, Bauer L. Cannabis and driving: a new perspective. Emerg Med 2002; 14:296- 303.

Pope HG, Gruber AJ, Yurgelun-Todd D. The residual neuropsychological effects of cannabis: the current status of research. Drug Alcohol Depend 1995; 38:25-34.

Rail Safety National Law (South Australia) Act 2012.

Royal College of Physicians of London. Tobacco Advisory Group. (2000). Nicotine addiction in Britain: a report of the Tobacco Advisory Group of the Royal College of Physicians. Royal College of Physicians.

SAMG-51, Alcohol, Tobacco and other Drugs Management Guide, Revision 1, V/Line 17/08/2017.

SAPO-1, Policy – Alcohol and Drugs Management, V/Line, 26/10/2016.

Steinmeyer S, Ohr H, Maurer HJ, Moeller MR. Practical aspects of roadside tests for administrative traffic offences in Germany. Forensic science international. 2001 Sep 15;121(1-2):33-6.

Strano-Rossi S, Castrignanò E, Anzillotti L, Serpelloni G, Mollica R, Tagliaro F, Pascali JP, Di Stefano D, Sgalla R, Chiarotti M. Evaluation of four oral fluid devices (DDS®, Drugtest 5000®, Drugwipe 5+® and RapidSTAT®) for on-site monitoring drugged driving in comparison with UHPLC–MS/MS analysis. Forensic science international. 2012 Sep 10;221(1-3):70-6.

The Health Consequences of Smoking—Nicotine Addiction: A Report of the Surgeon General. Rockville, MD, US Department of Health and Human Services, 1988.

Tinklenberg JR, Melges FT, Hollister LE, Gillespie HK. Marihuana and immediate memory. Nature 1970; 226:1171-2.

Yesavage JA, Leirer VO, Denari M, Hollister LE. Carry-over effects of marihuana intoxication on aircraft pilot performance: a preliminary report. Am J Psychiatry 1985; 142:1325-9.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to Directly-Involved Parties. Submissions were received from V/Line and the Office of the National Rail Safety Regulator. These submissions were reviewed and where considered appropriate, the text of the draft report amended.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2018-001
Occurrence date 02/01/2018
Location Marshall
State Victoria
Report release date 15/01/2020
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category SPAD (signal passed at danger)
Occurrence class Incident
Highest injury level None

Train details

Train operator V/Line
Train number 8865
Type of operation Passenger
Departure point Southern Cross Station, Victoria
Destination Warrnambool, Victoria
Train damage Nil

Train details

Train operator V/Line
Train number 7750
Type of operation Empty cars
Departure point Waurn Ponds, Victoria
Destination Geelong, Victoria
Train damage Nil

Derailment of freight train 7MC1, Wallan, Victoria, on 4 November 2017

Final report

Report release date: 06/03/2019

Safety summary

What happened

At 1523 on Saturday 4 November 2017, Qube Logistics freight train 7MC1 was signalled into the crossing loop at Wallan, Victoria. Entering the loop from the main line, the leading bogie on the 37th wagon derailed and travelled in a derailed state until the train stopped within the loop. At this stage, the locomotive crew were unaware of the derailment.

Following the passing of an opposing passenger service, and signals clearing, 7MC1 commenced its departure from the loop. Shortly after, a member of the public made the crew of 7MC1 aware that a wagon was derailed and the train was brought to a stand.

What the ATSB found

The ATSB found that the leading left-hand wheel of the leading bogie of wagon LQAY 00025D climbed the left-hand stock rail within the turnout from the crossing loop to the cripple track. The second wheelset of the same bogie derailed several hundred metres into the loop after the train commenced its departure from the loop.

It was found that the derailment occurred within a rapid transition of track superelevation from the main line to the loop track, resulting in the unloading of the leading left-hand wheel. The twist through the location exceeded network requirements and the basis for its acceptance was not documented.

In addition, the track alignment through the turnout to the cripple track probably resulted in the wheel tracking towards the left stock rail. The condition of some sleepers was also degraded resulting in a reduced effectiveness of rail fastenings.

The wagon and its loading was compliant with network requirements.

What's been done as a result

ARTC completed rectification works at the derailment location to address the identified twist exceedances. Works included improving track geometry, the installation of turnout bearers with resilient fastenings and mechanised tamping.

ARTC has also enhanced work management processes for the response to geometry conditions in accordance with ARTC’s Safety Management System.

Safety message

Effective management of track defects is critical to minimising the risk of derailment and maintaining safe rail operations.

 

The occurrence

Train 7MC1 was an intermodal freight service between Melbourne and Junee operated by Qube Logistics Rail Services (Qube) on 4 November 2017. It comprised two QBX-class locomotives and 46 wagons. After loading and pre-departure inspections, the train departed Melbourne at 1315.

At Somerton, about 22 km into its journey, there was a change in the train crew. After departing Somerton, the changeover locomotive driver felt that the train was not performing as expected, suspecting that the second locomotive was not powering. The driver stopped the train to check the Multiple Unit (MU) cable connection between locomotives. They attended to the MU connection and on resuming, the driver was satisfied that the second locomotive was powering.

Figure 1: Wallan Loop layout and signalling

Figure 1: Wallan Loop layout and signalling. Source: Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

Prior to Wallan, the crew of train 7MC1 was contacted by network control[1] and advised that their train would be routed into the crossing loop at Wallan to allow an opposing passenger train to pass (Figure 1).

Train 7MC1 was stopped prior to the loop at the Wallan Home signal (WLN/2). The signal then cleared to display a Low Speed Caution indication meaning a maximum speed of 15 km/h. The train departed at about 1523[2] and then entered the loop at about 13 to 14 km/h.

As 7MC1 was entering the loop, the leading wheelset of the 37th wagon (LQAY 00025D) derailed. The leading left-hand wheel of the wagon climbed[3] the stock rail[4] beyond the point blade in the cripple track turnout, ran along the railhead and dropped to the outside of the rail (Figure 2).

Figure 2: The location of the point of mount within the cripple track turnout

Figure 2: The location of the point of mount within the cripple track turnout. <p>Source:  Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

The train continued its entry into the loop at around 13 km/h and then commenced braking for about 240 m before stopping at the Loop Home Departure signal (WLN/U6).[5] The train was now fully within the crossing loop. There was no loss of brake pipe continuity and the train crew were not aware of the derailment.

The V/Line Standard-Gauge passenger service 8620 that was running from Albury to Southern Cross Station then passed 7MC1. Its driver radioed to the crew of 7MC1 that their train was ‘complete’ and ‘looked ok’.[6]

Once the passenger train had cleared, 7MC1 received a signal indication to depart Wallan. As it was departing, the № 2 axle on the same bogie derailed and a member of the public who had seen the derailed wagon drove alongside the locomotive and signalled to the crew to stop.

The train was brought to a stand. Damage to the train was limited to wagon LQAY 00025D that had derailed all wheels of its leading bogie (Figure 3).

Figure 3: The derailed bogie (both wheelsets) after the train was brought to a stop

Figure 3: The derailed bogie (both wheelsets) after the train was brought to a stop. 
This picture shows the derailed wagon after the train was stopped when departing Wallan Loop.
Source: Chief Investigator, Transport Safety (Vic)

This picture shows the derailed wagon after the train was stopped when departing Wallan Loop. Source: Chief Investigator, Transport Safety

The track sustained damage to sleepers over a distance of several hundred metres (Figure 4).

Figure 4: Typical damage to concrete sleepers within the crossing loop

Figure 4: Typical damage to concrete sleepers within the crossing loop. Source:  Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

Post-occurrence

The locomotive driver contacted the ARTC network controller and informed them of the situation while the driver’s assistant went back to inspect their train.

ARTC network control requested that the lead portion of 7MC1 continue its journey, as the train was now blocking the main line. 7MC1 was divided between the 33rd and 34th vehicles and departed Wallan at 1935 to Kilmore East where the train crew were drug and alcohol-tested. The drivers were cleared to continue and 7MC1 departed Kilmore East at 1945.

Recovery

Representatives from Qube’s maintenance contractor attended the site on 6 November to re-rail LQAY 00025D. After re-railing, the wagon was transferred to the Melbourne end of the loop. It was then moved towards the cripple track[7] adjacent to the loop. During this move, the leading axle of the wagon in the direction of travel derailed on the cripple track turnout. This was on a different section of track to the earlier derailment and the bogie was in a damaged condition.

This bogie was again re-railed and successfully shunted into the cripple track. The wagon was unloaded and the bogies changed out and transported to Melbourne where they were quarantined for further inspection.

__________

  1. The ARTC train control office for the Standard-Gauge network between Sydney and Somerton.
  2. All times are in Eastern Daylight saving Time (EDT).
  3. The Point of Mount (PoM) at which the wheel flange climbed the rail and commenced running along the rail.
  4. The outside, continuous rails of a turnout.
  5. The train speed was logged at about 13 km/h when braking was applied to bring the train to a stand within the loop.
  6. Refers to the train being intact from one end to the other, and the last vehicle being properly identified.
  7. A cripple track is used for stabling disabled rolling stock clear of the main line.

Context

Track

Location

Wallan loop is located about 47.3 rail km from Melbourne on the Victorian North-Eastern Standard-Gauge main line between Melbourne and Albury. The Australian Rail Track Corporation (ARTC) was the Rail Infrastructure Manager. It managed network rail traffic from its control centre in Junee, NSW, and track maintenance for this section of track from Seymour, Victoria.

Wallan crossing loop layout

The track at Wallan included the crossing loop and a cripple track for disabled rolling stock. The southern end of the loop consisted of a right-hand turnout from the main line and a second right-hand turnout to the cripple track. The Normal direction of this second turnout led into the crossing loop proper and to a short left-hand curve before the loop track curved right paralleling the main line (Figure 5).

Figure 5: The southern entry from the mainline into Wallan Loop and the cripple track

Figure 5: The southern entry from the mainline into Wallan Loop and the cripple track. Source:  Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

The turnout at the southern entry to the crossing loop was located on a 1247 m radius main line curve with minimal gradient. The main line track has a superelevation[8] of 100 mm that transitioned to the flat loop track over a distance of about 24 m.

The cripple track turnout was on timber sleepers. At the derailment location, sleepers were in degraded condition with an observable loss of effectiveness in the rail fastenings.

Track geometry

Standards

The ARTC track geometry standards specified defect categories for track gauge, horizontal alignment (line), vertical alignment (top) and twist (variation in actual cross level). The standard noted that the specified maintenance response was based on an isolated geometric defect, and a more stringent response than that mandated by the geometry alone may be necessary if deterioration of the infrastructure both at the defect and on adjoining track is in evidence.

The required response to a defect varied depending on the permitted train speed. Response requirements reduced as train speed reduced. The standard also defined response timeframes (Figure 6).

Figure 6: Response categories and timeframes

Response 
category
Inspect
(see notes 1 and 3)
Repair
(see notes 2 and 3)
Other responses
(see note 3)
E1
(Emergency Class 1)
Prior to next trainPrior to next trainWhere the response category cannot be reduced below E1 by a reduction in speed, trains may only pass the site under the control of a pilot. Assessment of the defect by a competent worker should be made to determine if the train can be piloted.
E2
(Emergency Class 2)
Within 2 hours or prior to the next train, whichever is greatestWithin 24 hoursIf the defect cannot be inspected or repaired within the nominated time and the response category cannot be reduced below E2 by a reduction in speed, trains may only pass the site at speeds up to 20 km/h following assessment by a competent worker.
P1
(Priority Class 1)
24 hours7 days 
P2
(Priority Class 2)
7 days28 days 
N  A deviation from design geometry up to the lowest level of P2 defect does not require any action above the normal inspection regime.

Notes:
In the event of failure to inspect reported faults by the specified time the allowable speed should be reduced by at least one speed band. A revised inspection period in line with the lower speed band may then be used. If the defect is subsequently inspected the speed may be raised to the higher band subject to repair being achievable within the nominated period for the higher band.

In the event of an inability to repair the track, the fault should be reassessed on site prior to expiry of the repair response time. The repair period can only be extended by the Civil Engineering Representative or a person with delegated authority from the Civil Engineering Representative.

If the cause of a defect is known and it is known that it will not deteriorate into an unsafe condition an alternative response to that shown is permitted with appropriate documentation and approval by the Civil Engineering Representative or nominated representative.

   

Source: ARTC Code of Practice, Track Geometry Section 5

Twist criteria

Two criteria applied to track twist. Short twist was measured over 2 m (approximating typical wagon bogie wheel spacing) and long twist was measured over 14 m (approximating a typical spacing of wagon bogie centres). Higher levels of twist were permitted in transition curves.

Track geometry recording car and maintenance response

Prior to the incident, the track geometry of the Wallan Loop was last assessed on 1 September 2017, using the AK Car.[9] The inspection flagged two Emergency twist defects at the southern end of Wallan Loop and near the location of the derailment (Figure 7).

Figure 7: E Class defects identified near the derailment location

Defect typeCategoryCategory criteria[10]Measured by AK Car[11]Chainage[12]
Long twistE1>74 mm[13]77 mm47.312 km
Short twistE223-24 mm24 mm47.317 km

Source: ARTC Track Recording Car and Code of Practice, Track Geometry Section 5

Documentation indicated that the two defects were closed out on the asset management system on the same day as the inspection. There was no indication of any repair activity to correct the defects and no supporting documentation or approvals permitting the defect condition.

The previous two track-recording runs through the derailment site, in April 2017 and December 2016, also identified short and long twist defects categorised for emergency response.

Post-incident geometry measurement

Following the derailment, track gauge and cross level measurements were taken through the derailment location (Figure 8).

Figure 8: Point of wheel mount

Figure 8: Point of wheel mount. Source:  Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

The PoM was at a chainage of approximately 47.316 km.[14] Static twist measurements peaked around this location. A measured peak static long twist of 78 mm[15] extended from 14 m before the PoM, up to the PoM. The measured peak static short twist[16] was about 22 mm about 2 m ahead of the PoM. These values were comparable to the E-defects measured by the AK Car.

The maximum measured (no-load) wide gauge through the location was 20 mm at the PoM. This was within permitted maintenance tolerances. Review of the most recent AK Car data, measured under load, indicated a peak wide gauge of 31 mm at a chainage of 47.319 km. This falls within the P2 (Priority Class 2) defect category for this low speed track.

Track lateral alignment through the cripple track turnout was also sub-optimal and there was a significant dip in both rails at the transition (mechanical joint) from the main line turnout to the cripple track turnout (Figure 9).

Figure 9: Transition from main line turnout to cripple track turnout

Figure 9: Transition from main line turnout to cripple track turnout. This picture shows a close-up view of the track through the derailment location and shows the rail lateral alignment around the point of mount. 
The deviation in rail line is exaggerated by the telephoto effect.
Source:  Chief Investigator, Transport Safety (Vic)

This picture shows a close-up view of the track through the derailment location and shows the rail lateral alignment around the point of mount. The deviation in rail line is exaggerated by the telephoto effect.
Source: Chief Investigator, Transport Safety (Vic)

The train

Consist

Train 7MC1 comprised two QBX-class locomotives and 46 loaded wagons conveying shipping containers. It was 1,018 m long and had a gross mass of about 3,300 t. It had been loaded at Westgate sidings at Qube’s intermodal terminal in Melbourne. A Melbourne-based crew prepared and examined the train prior to its departure from the terminal, and then operated the train until a crew change-over at Somerton.

Wagon

The derailed wagon was designated LQAY 00025D. It was the 37th wagon from the locomotives and was “B” end leading. There were four wagons of this type in the consist, two ahead of the derailed wagon (2nd and 23rd), and one behind (the 46th and the last vehicle).

LQAY wagons are 19.3 m (60’) skeletal container wagons manufactured in China by Meishan Rolling Stock Works. The derailed wagon was one of 100 ordered by Macathur Intermodal Shipping Terminal (MIST) with production commencing in 2005. The use of this type of vehicle and bogie on the ARTC network was approved by ARTC in the form of a TOC Waiver in October 2009. As these wagons were initially operated on the Rail Infrastructure Corporation’s (RIC) NSW network they were required to meet the then RIC Minimum Operating Standards for Rolling Stock. ARTC’s Engineering Standard for Rolling Stock WOS 01 was based on these RIC requirements.

LQAY wagons are fitted with three-piece bogies with a steering arm mechanism linked to primary rubber pad arrangement between the side frame and axle box. They also have variable friction damping on the secondary springs and constant contact side bearers (Figure 10).

Figure 10: The derailed bogie after its transport to Melbourne

Figure 10: The derailed bogie after its transport to Melbourne. Source:  Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

Wheel profile

The bogies were delivered in 2005 with wheels profiled to the WPR 2000[17] profile. This was the profile preferred by RIC, the original network destination for this wagon. The profile was subsequently changed to the ANZR-1[18] profile, listed in the ARTC Route Access Standard General Information, for freight rolling stock operating on the Defined Interstate Rail Network. There was no evidence provided by the Rolling Stock Operator of a change management process associated with this change in wheel profile.

The WPR 2000 wheel profile is a worn wheel profile that was designed to increase wheel life compared to the ANZR-1 through limiting wear of the wheel flanges (Figure 11). It achieved this by utilising a more conical tread profile that generates a larger rolling radius difference between the wheels on a common axle. This increased the wheelsets ability to steer through curves and hence placed less load on the wheel flange.

Figure 11: Comparison between the WPR 2000 (blue) and ANZR-1 (red) wheel profiles

Figure 11: Comparison between the WPR 2000 (blue) and ANZR-1 (red) wheel profiles. Source:  Australian Transport Safety Bureau

Source: Australian Transport Safety Bureau

While the increased steering capability of the WPR 2000 wheel profile offered less flange wear, it had been shown in use to lower the critical speed[19] for some combinations of wagon type and rail profile leading to undesirable dynamics known as hunting[20]. The ATSB understands that the flatter tread profile of the ANZR-1 was generally less susceptible to hunting and therefore the preferred profile for freight rolling stock operating on the ARTC Defined Interstate Rail Network (DIRN). It was also an option on other track where it could be demonstrated that a vehicle was experiencing bogie instability.

Wagon maintenance

LQAY wagons were on a preventative maintenance (PM) program. Maintenance records for LQAY 00025D indicated that:

  • On 30 November 2016 both bogies and all wheelsets were replaced.
  • The wagon had its last PM inspection on 24 October 2017.
Wagon type testing

Type testing of the LQAY wagon type was conducted in China in September 2005 and covered wagon numbers 00001 – 00100. The type testing was in accordance with the RIC Minimum Operating Standards for Rolling Stock and witnessed on behalf of MIST by Interfleet Technology. The type testing included a static vehicle twist test and vehicle/bogie swing test.

The twist test examined potential wheel unloading in response to track twist. Twist was simulated by packing wheels on one side of the wagon (Figure 12). For the type testing of the LAQY wagons, the packing used was P1 = 18 mm, P2 = 86 mm and P3 = 86 mm. The wheel unloading (the reduction in wheel load) was measured for the leading wheel (P0).

Figure 12: Test configuration for twist type testing, and centre-bowl engagement criterion

Figure 12: Test configuration for twist type testing, and centre-bowl engagement criterion. Source: QUBE, modified by Chief Investigator, Transport Safety

Source: QUBE, modified by Chief Investigator, Transport Safety

During this twist test, a maximum wheel unloading of 23% was measured, compared to the requirement of ‘…the loss of absolutely no more than 60% of the static wheel load for any wheel’. The measured engagement of the vehicle centre plate within the bogie centre casting was 14 mm, equal to the minimum permitted (Figure 12).

The purpose of the vehicle/bogie swing test is to evaluate clearance when a wagon is navigating tight curves. The criteria used in testing was a 70 m simple curve. This testing found adequate clearances for normal operations. The only adverse finding was fouling when the handbrake was applied.

Wagon loading

Wagon LQAY 00025D was loaded with two containers. At its leading end was an empty 20-foot refrigerated container with a reported mass of 3.2 t. Behind this was a 40-foot container loaded with strapped bundles of recycled paper and having a reported mass of 26 t (Figure 13). Wagon tare was 19.9t, giving a total mass of 49.1 t. This compares with the train consist report that records a total mass of 69 t. The reason for this discrepancy is unknown.

The two containers wholly occupied the length of the wagon. The mass distribution of the containers and wagon tare resulted in an estimated 21 t at the leading bogie and about 29 t at the trailing bogie of (Figure 14).[21] The difference of about 8 t was within the ARTC Route Access Standard[22] requirement of no more than 20 t.

Figure 13: Paper bundles loaded in the 40-foot container

Figure 13: Paper bundles loaded in the 40-foot container. Source: Qube Logistics

Source: Qube Logistics

Figure 14: The container loads and the resultant mass at each bogie

Figure 14: The container loads and the resultant mass at each bogie. The mass at each end has been rounded up, resulting in a total rounding error of 1 t, and an apparent total mass of 50 t compared to the actual total mass of 49 t.
Source:  Chief Investigator, Transport Safety (Vic) based data from Qube

The mass at each end has been rounded up, resulting in a total rounding error of 1 t, and an apparent total mass of 50 t compared to the actual total mass of 49 t.
Source: Chief Investigator, Transport Safety (Vic) based data from Qube

Post incident inspection

A detailed inspection was conducted on both bogies of wagon LQAY 00025D. The derailed bogie was designated LHSY113 (Figure 15).

Figure 15: The derailed bogie at the post-incident inspection

Figure 15: The derailed bogie at the post-incident inspection. This picture shows the bogie that derailed. It shows damage to the centre bowl liner and some components, all believed to have occurred after the bogie derailed.











Source:  Chief Investigator, Transport Safety (Vic)

This picture shows the bogie that derailed. It shows damage to the centre bowl liner and some components, all believed to have occurred after the bogie derailed. 

Source: Chief Investigator, Transport Safety (Vic)

No wear or damage conditions were identified that were considered contributory to the derailment. Wear to both bogies was minimal and consistent with the recent December 2016 overhaul. In addition, surface condition of constant contact side bearers did not indicate any unusual behaviour.

Wheel wear was within the operating requirements and similar on both bogies. Wheel wear on the derailed bogie was relatively light and evenly matched from side to side indicating the bogie had been tracking well. Wear on the wheel flanges was more than expected for a steering bogie, but was within tolerance.

The performance of self-steering bogies is, in part, dependant on the wheel profile used. A change was made from the higher steering WPR 2000 wheel profile to the lower steering ANZR-1 wheel profile and this may have contributed to the more than expected wheel flange wear.

Type of bogie

The LQAY wagon bogies were of a ‘self-steering’ bogie design. The steering mechanism is an adaptation of a design pioneered by Dr Herbert Scheffel in the 1970’s in South Africa[23]. The design sought to improve the curving performance of bogies by permitting the wheelsets to steer into curves reducing wheel and rail wear while retaining good stability and resistance to hunting. This bogie design is often referred to as the Scheffel Bogie.

Scheffel’s design mounted the wheelsets to sub-frames that were diagonally linked and utilised rubber shear pads (springs) to permit motion between the sub-frame and bogie frame. Configured in this way, the design permits yawing of the axles in response to wheelset steering forces, allowing them to adopt a ‘radial’ configuration that greatly improves curving performance (Figure 16). The design also resists shear motion between the two wheelsets and is therefore said to have good resistance to hunting.

Figure 16: The principle behind the steering bogie

Figure 16_A: The principle behind the steering bogie. The figure identifies the key design components (top) and radial steering (lower).
Source:  Australian Transport Safety Bureau
Figure 16_B: The principle behind the steering bogie. The figure identifies the key design components (top) and radial steering (lower).
Source:  Australian Transport Safety Bureau

The figure identifies the key design components (top) and radial steering (lower). Source: Australian Transport Safety Bureau

The magnitude of response of the steering mechanism is dependent on several factors including the wheel profiles used, with the resulting wheelset steering forces having an influence on the performance of the steering mechanism.

Train handling

Data logger

The lead locomotive was fitted with a data logger that provided a recorded history of the locomotive’s movements and train handling, including powering and braking during the sequence of events (Figure 17).

Figure 17: Key sequence of events from the locomotive data logger

TimeComment
15.21.207MC1 stopped at signal WNL/2
15.22.58

Power applied (notch 3) and 7MC1 commenced move towards Wallan Loop

The throttle is modulated between notch 3 and notch 1

Speed 13 to 14 km/h

15.31.177MC1 brought to a stand at signal WNL/U6. The train then remained stationary for about 17 minutes
15.48.32

7MC1 commenced to depart loop

Power applied between notch 1 and notch 3

Maximum speed 14 km/h

15.51.547MC1 is brought to a stand

Source: Chief Investigator, Transport Safety (Vic)

7MC1 entered Wallan Loop at low speed and power was being applied between notch 1 and notch 3. In-train coupler action would have been minimal and it is unlikely that there was sufficient in-train forces generated to contribute to the derailment.

Locomotive crew

Both crewmembers were qualified for their respective roles and held current medical certification.

Victoria Police conducted post-incident alcohol and drug tests on the locomotive crew at Kilmore East with non-positive results for all tests.

__________

  1. The height difference between the rails. The outer rail on a curve is often elevated above the inner rail to facilitate higher curving speeds.
  2. The AK Car is part of a three-car train that records track geometry on the standard-gauge network.
  3. ARTC Code of Practice, Track Geometry Section 5, Table 5.5.
  4. Absolute values shown. In the direction of travel, the left-hand rail was descending relative to the right rail.
  5. The distance in rail km from a reference point in Melbourne.
  6. As specified for a transition curve.
  7. The estimated error tolerance on chainage at the PoM is +/- 2 m.
  8. Track was measured by several parties with small, but inconsequential, variances in the hand measurements.
  9. Measured over 2 m.
  10. Standard AS 7514.2 Australian Standard – Railway Rolling Stock Wheels – Part 2: Freight Rolling Stock (2010) Appendix A.2
  11. Standards AS 7514.2 Australian Standard – Railway Rolling Stock Wheels – Part 2: Freight Rolling Stock (2010) Appendix A.1
  12. Critical speed: The lowest speed at which hunting is demonstrated. Can also be used to describe speed at which a resonant response occurs with cyclic track irregularities.
  13. Hunting: Uncontrolled and undesirable cyclic lateral and yaw displacements of the wheelsets of a vehicle, generally worsening with increasing speed.
  14. The mass distribution is an approximation.
  15. This document defines the terms and conditions upon which ARTC grants access to its Network. It is intended to aid Train Operators to ensure trains are planned, constructed, inspected, maintained, loaded and operated in accordance with route attributes.
  16. Original patent link.

Safety analysis

The derailment

Site evidence was conclusive that the flange of the leading left-hand wheel on the wagon LQAY 00025D climbed the left-hand stock rail in the turnout to the cripple track, a short distance past the point blade. The derailment was clear of moving turnout components including the point blade.

Flange climb derailment

Flange climb derailments initiate when the outward lateral force (L) applied by the wheel on the rail results in the wheel climbing the rail gauge face. This critical point is determined by several factors including the vertical load on the wheel (V), the angle of the wheel flange and the coefficient of friction between the rail and wheel.

A generally adopted limit for preventing flange climb is known as Nadal’s limit.[24] Nadal’s limit defines a limiting lateral on vertical force ratio (L/V) for given wheel geometry and friction conditions. Flange climb becomes more likely as the L/V ratio increases beyond this value. This means that either an increase in lateral force, a decrease in vertical force or a combination of both will increase the risk of flange climb.

The lateral force of the wheel against the rail may increase due to a track feature such as a tight curve or lateral misalignment or by a condition of the bogie that affects its tracking. A reduction in the vertical load, also referred to as wheel unloading, can be associated with a track feature such as twist and can also be influenced by wagon condition including loading.

Track geometry

Twist

Near the point of flange climb, there were long and short twist defects. The long twist was of comparable magnitude to the value used in type testing of the LQAY wagon and the short twist was probably at least 20 percent[25] greater than that used in the type testing. The track twist would have contributed to an unloading of the leading left-hand wheel of LQAY 00025D.

Alignment

Site observations indicated that traffic was probably tracking towards the Down leg[26] around the derailment location. For north-bound traffic (the incident train), this meant that vehicles were probably typically tracking to the left towards the stock rail of the turnout to the cripple track. The rail alignment through the cripple track turnout and the track configuration through this location probably influenced wagon tracking behaviour.

Gauge

Track gauge measured statically after the derailment was at its widest at the point of wheel climb, but was within permitted tolerances. Under dynamic conditions, the wide-gauge at this location was about 50 percent higher, but also not at a level that would have required emergency corrective action.

Sleeper condition and effectiveness of rail fastenings

The most-recent AK Car assessment recorded a wide gauge of 31 mm at a chainage about three metres past the point of mount. This exceeded the static (no-load) peak gauge measurement of 20 mm through this location. Considering the degraded condition of sleepers and the loss of effectiveness of the fastenings, it is probable that there was some movement of the stock rail under dynamic load, probably adversely impacting track geometry.

Track defect management

At and near the point of mount, there were two identified twist defects categorised as requiring immediate emergency response. Records indicated that these twist defects had existed for at least 12 months.

The long track twist through the location was a result of the superelevation being rapidly transitioned from about 100 mm on the main line curve through to the flat crossing loop track. The dynamic short twist within this transition was more severe, and probably the result of localised ballast subsidence under the load of rolling stock.

The acceptance of the track in this condition contrary to the network geometry standards was not supported by documentation and approvals as required by the standard.

Wagon performance

This wagon type and its loading was compliant with network requirements and the post-incident bogie inspection did not identify a condition that may have contributed to the derailment.

It is possible that the response of wagon LQAY 00025D to the track geometry anomalies was different to other wagons. A factor that may have influenced its response was its load distribution.

No conclusion was drawn from the second derailment of the vehicle as it was being transferred to the cripple track. The bogie was damaged and the second derailment occurred on a different part of the track to the first.

__________

  1. Nadal, M.J., Locomotives à Vapeur; (Collection: Encyclopédie Scientifique, - Bibliothèque de Mécanique Appliquée et Génie, 1908).
  2. Based on a short twist of 24 mm measured under the dynamic conditions of the AK Car. Under the loading of LQAY 00025D, the dynamic twist in the track may have been greater.
  3. The left-hand rail when facing away from Melbourne.

Findings

From the evidence available, the following findings are made with respect to the derailment of train 7MC1 at Wallan on 4 November 2017. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • ARTC allowed identified track twist defects to remain in track contrary to network track geometry requirements. [Safety Issue]
  • Track twist contributed to unloading of the leading left-hand wheel of wagon LQAY 00025D.
  • Track alignment probably resulted in the leading left-hand wheel of wagon LQAY 00025D tracking to the left-hand stock rail as the wagon passed through the cripple track turnout.
  • When traversing the cripple track turnout towards the crossing loop, the leading left-hand wheel of wagon LQAY 00025D climbed the left-hand stock rail, and the wagon derailed.

Other factors that increased risk

  • The degraded condition of some sleepers through the location reduced the effectiveness of rail fastenings, probably adversely affecting track geometry under dynamic load.

Other findings

  • The operation of the train was consistent with network practice and unlikely to have contributed to the derailment.
  • Post-incident bogie inspection did not identify a condition that may have contributed to the derailment.

Safety issues and actions

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Track defect management

Safety issue number: RO-2017-016-SI-01

Safety issue description: ARTC allowed identified track twist defects to remain in track contrary to network track geometry requirements.

Additional safety action

ARTC has completed rectification works at Wallan to address the twist exceedances in the vicinity of the turnout from the loop to the cripple track. The geometry was initially corrected on 23 December 2017. Follow-up works were completed on 19 March 2018 and included the installation of turnout bearers with resilient fastenings and mechanised tamping (Figure 18).

Figure 18: The derailment location after rectification works

Figure 18: The derailment location after rectification works. Source:  Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

Sources and submissions

Sources of information

  • Qube Logistics (Rail) Services
  • Australian Rail Track Corporation

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the Australian Rail Track Corporation, Qube Logistics Rail Services, the Rail Regulator, and the locomotive drivers. Submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2017-016
Occurrence date 04/11/2017
Location Wallan
State Victoria
Report release date 06/03/2019
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Incident
Highest injury level None

Train details

Train operator Qube Logistics Rail Services
Train number 7MC1
Type of operation Freight
Departure point VicDock, Melbourne, Victoria
Destination Junee, Victoria
Train damage Minor

Undetected engine thrust reverser deactivation involving Airbus A320, VH-VQG, Gold Coast Airport, Queensland, on 18 December 2017

Final report

Report release date: 05/09/2019

Safety summary

What happened

On the morning of 18 December 2017, a Jetstar Airways Airbus A320 aircraft, registered VH‑VQG was on final approach for Gold Coast Airport, Queensland. The aircraft was operating as a scheduled passenger flight, from Adelaide, South Australia.

After a normal descent and touchdown, the captain selected both engine thrust reversers. The left engine thrust reverser did not activate. The aircraft decelerated using normal braking and taxied to the gate without further incident. There was no damage to the aircraft, or injuries as a result of the incident, and the captain reported the thrust reverser issue for investigation.

What the ATSB found

During overnight maintenance in Adelaide, the left engine thrust reverser lockout pin had been installed. However, the pin was not removed after the maintenance, resulting in the aircraft returning to service with the thrust reverser deactivated.

The lockout pin was located at the top of the engine and its 1 m red warning flag was difficult to see in the prevailing low‑light conditions. This probably led to the engineer not seeing the flag and removing the pin.

Further, the lockout pin was not booked out of the tool store nor was its installation recorded in the technical log. As a result, the checks that these procedures provided to ensure the pin's removal were missed.

What's been done as a result

The aircraft’s maintenance organisation, Qantas, advised that it is taking safety action that includes the following:

  • Highlighting the importance of the aircraft maintenance manual precautions to maintenance staff at Adelaide.
  • Lengthening all thrust reverser lockout pin warning flags to hang past the closed engine cowls. The pin will also have a warning notice attached for placement on the engine thrust reverser controls during maintenance.

The aircraft manufacturer, Airbus, advised that the August 2019 revision of the aircraft maintenance manual introduced an operational test of the thrust reverser system to confirm its re‑activation after maintenance tasks.

Safety message

This investigation highlights the importance of considering the environmental conditions in which equipment and tools will potentially be used, as well as the importance of following procedures that in this instance should have resulted in detecting the error.

When considering the effectiveness of equipment, tooling and procedures that aim to minimise the likelihood and/or consequences of an error, an engineered solution is generally more effective than relying on procedural compliance. Further, a functional check is generally more effective within procedural compliance than a self-check of work. See the ATSB research report, An overview of human factors in aviation maintenance (AR-2008-055), available from the ATSB website.

 

The occurrence

What happened

On the morning of 18 December 2017, a Jetstar Airways (Jetstar) Airbus A320 aircraft, registered VH‑VQG (VQG) was on final approach to Gold Coast Airport, Queensland. The aircraft was operating as a scheduled passenger flight, from Adelaide, South Australia, with two flight crew, four cabin crew, and 140 passengers.

At about 0845 Eastern Standard Time,[1] air traffic control cleared VQG to land. After a normal descent and touchdown, the captain (pilot flying) selected both engine thrust reversers.[2] The right engine thrust reverser activated but the left engine reverser did not, and the flight crew received a ‘reverse fault’ alert. They continued with the landing and the aircraft decelerated to a taxi speed using normal braking. The captain moved the thrust reverser controls to the stowed position, the aircraft was taxied to the gate without further incident and the passengers disembarked.

While taxiing, the captain cycled the thrust reverser levers and the alert extinguished. Nevertheless, the captain reported the thrust reverser issue for investigation by engineering personnel.

The subsequent engineering inspection found the left engine thrust reverser lockout pin installed, effectively deactivating the reverser. The lockout pin was removed, the thrust reverser confirmed to be operating normally and the aircraft returned to service.

There was no damage to the aircraft, or injuries as a result of the incident.

Overnight maintenance

Maintenance on the aircraft’s left engine was carried out in Adelaide during the night before the incident flight. Two A320 licensed maintenance engineers had carried out that maintenance.

One of the engineers (engineer 1) began his scheduled night shift at about 1900 on 17 December, and he described the weather that evening as hot and humid. He initially thought he was the only engineer on that shift to carry out maintenance certification on four A320 aircraft, and stated that he felt ‘stressed’ and under pressure. The other engineer (engineer 2) had been called in to work overtime that evening. He started his shift at 1830, carrying out other tasks before being assigned to assist engineer 1 with VQG later that evening.

At about 2300, after completing their other tasks, the engineers commenced maintenance on VQG. This maintenance was unscheduled and involved investigating an engine bleed air issue. Jetstar had not provided paperwork for this task. Engineer 2 began collecting the consumables required for the task. Engineer 1 went to the tarmac tool store to get a lockout pin, required to be installed on the engine to prevent inadvertent activation of the thrust reverser.

After locating the lockout pin with some difficulty, engineer 1 hurried back to the aircraft without booking out the pin on the store’s computer system. He opened the left engine cowling and, using a stand to access the top of the engine, installed the pin. Procedures required the pin’s installation to be entered in the aircraft’s technical log. The log was located in the line office, and the engineer decided to record it in the log later.

A couple of hours later, the engineers completed investigating the bleed air issue. By this time, it had started raining. Engineer 1 made a visual inspection around the engine in preparation to close the cowling. The available lighting had reduced as half the tarmac lights automatically turn off at midnight. Engineer 1 missed seeing the lockout pin and its 1 m long red warning flag, and closed the cowling (Figure 1). The flag was shorter than those on the pins in the hangar tool store at Adelaide, which had been lengthened to 4 m after a previous incident to make them more obvious. Additionally, the stand that engineer 1 had used to install the pin, and which may have reminded him about it, had been removed for another task.

The aircraft maintenance manual thrust reverser de-activation procedure also required the use of specific warning labels in the cockpit, stating that ‘thrust reverser HCU [hydraulic control unit] is de-activated’. This procedure was not used during this maintenance task.

Figure 1: Photograph of a thrust reverser lockout pin and warning flag (non-reflective)

Figure 1: Thrust reverser lockout pin and warning flag (non-reflective)

Source: Operator, annotated by the ATSB

Shortly after 0230 on 18 December, the engineers completed the maintenance on VQG, and went to the line office to complete the paperwork. The engineers recorded different parts of the completed maintenance, but neither entered the installation of the lockout pin in the technical log.

At the release to service of VQG, a tooling inventory check was conducted. As the pin was not booked out on the store’s computer, it did not show up during the check.

The aircraft was released to service with the lockout pin installed.

Similar occurrences

AO-2018-064[3]

In September 2018, the engine thrust reversers on a Jetstar A320 aircraft did not activate when landing at Sydney Airport, New South Wales. The ATSB investigation into that occurrence found that the thrust reverser lockout pins on both engines were not removed after maintenance at the Brisbane Airport, Queensland facility before the flight.

In that case, the aircraft maintenance lockout pins (fitted with warning flags) were substituted with in-service pins without flags. Further, the functional check of the thrust reversers following reactivation as per the operator’s task card for that planned maintenance was not carried out. The investigation also found that operational pressure to expedite the maintenance probably influenced the deviation from procedures.

January 2017

In January 2017, the right engine thrust reverser on a Jetstar A320 aircraft did not activate when landing at Melbourne Airport, Victoria. The operator’s investigation found that the thrust reverser lockout pin was not removed after maintenance at Adelaide before the flight.

In that case, the aircraft maintenance lockout pin also had a 1 m red warning flag and was not booked out on the store’s computer system.

Safety analysis

The left engine thrust reverser did not activate when VH‑VQG landed at the Gold Coast Airport because its lockout pin was installed. Engineers had installed the pin during maintenance in Adelaide before the flight, but missed removing it due to a number of reasons.

The maintenance in Adelaide was carried out in the night under artificial lighting on the tarmac. The lighting significantly reduced at midnight when the tarmac lights automatically dimmed (half extinguished). In addition, it was raining when engineer 1 carried out a visual inspection before closing the engine cowling. These conditions made it difficult to see the lockout pin’s red warning flag.

The red colour of the flag was also harder to see in the artificial lighting,[4] and the flag was not fitted with reflective material. The lockout pin was located at the top of the engine, where its 1 m flag was not as conspicuous as other longer flags, which would have hung below the engine to the tarmac. Further, the stand used to install the pin, which might have served as a reminder, had been removed. The combination of these factors probably led to the pin not being removed.

Procedures aimed at ensuring the lockout pin’s removal were not followed. These procedures included booking items out on the tool store’s computer system. As the pin was not booked out, its return to the store could not be checked. Further, the pin’s installation was not recorded in the technical log, which meant its removal went unnoticed and unrecorded.

Finally, the required cockpit warnings associated with thrust reverser deactivation were not used, thereby removing an opportunity to identify that the pin had not been removed before the aircraft was returned to service.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The lockout pin on the left engine thrust reverser was not removed after maintenance, resulting in the aircraft returning to service with the thrust reverser deactivated.
  • The location of the thrust reverser lockout pin at the top of the engine meant that its 1 m red warning flag was difficult to see in the prevailing low‑light conditions. This probably led to the engineer not seeing the flag and removing the pin.
  • The lockout pin was not booked out of the tool store nor was its installation recorded in the technical log. As a result, the checks that these procedures provided to ensure the pin's removal were missed. Additionally, the required cockpit warnings associated with thrust reverser deactivation were not used, removing an opportunity to identify that the thrust reverser was disabled.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Qantas

The aircraft maintenance organisation, Qantas, has advised the ATSB that it is taking the following safety actions:

  • Highlighting the importance of the aircraft maintenance manual precautions, and the limitations of human performance on the stages of maintenance, to maintenance staff at Adelaide.
  • Lengthening all thrust reverser lockout pin flags to hang past the closed cowls. The pin will also have a warning notice attached for placement on the engine thrust reverser controls during maintenance.
  • Focused audits on work practices for tooling and documenting maintenance activities.
  • Reiterating the responsibilities of engineers to those involved in this incident.

Airbus

The aircraft manufacturer, Airbus, advised that the August 2019 revision of the aircraft maintenance manual introduced an operational test of the thrust reverser system to confirm its re‑activation after maintenance tasks. 

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours.
  2. The purpose of the engine thrust reversers is to decelerate the aircraft on the ground, either routinely or during an emergency.
  3. Available at www.atsb.gov.au
  4. An effect known as the Purkinje shift, red will appear darker relative to other colours as light levels decrease.

Occurrence summary

Investigation number AO-2017-117
Occurrence date 18/12/2017
Location Gold Coast Airport
State Queensland
Report release date 05/09/2019
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Warning devices
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer Airbus
Model A320-232
Registration VH-VQG
Serial number 2787
Aircraft operator Jetstar Airways
Sector Jet
Operation type Air Transport High Capacity
Departure point Adelaide, South Australia
Destination Gold Coast, Queensland
Damage Nil

Fire on board BBC Xingang, Newcastle, New South Wales, on 11 December 2017

Final report

Report release date: 25/05/2018

What happened

At midnight[1] on 10 December 2017, the multi-purpose, general cargo ship BBC Xingang (Figure 1) berthed at Mayfield number four berth in Newcastle, New South Wales. The cargo to be discharged comprised containers and ‘project cargo’, which consisted of large structures of various shapes and sizes. Some of the cargo had gel-coated surfaces that could be easily damaged, and these components were covered with cloth for protection during transport.

Figure 1: BBC Xingang

Figure 1: BBC Xingang. Source: Tropic Marine Images, Shipspotting.com


Source: Tropic Marine Images, Shipspotting.com

Sea fastenings (or stoppers) were used to secure the project cargo during sea passage. The stoppers were metal brackets welded to the ship’s deck, and they needed to be removed before the cargo could be discharged. To remove the stoppers, oxy-acetylene cutting and gouging techniques were required.

In preparation for removing the stoppers, the chief mate and deck crew had reviewed the ship’s risk assessment for hot work and completed the ship’s hot work permit. The master had notified Newcastle port of the intended work and a hot work audit report had been completed by a port representative.

At about 0600 on 11 December, a work team, including a site supervisor and a boilermaker, from a local engineering firm (Varley) boarded the ship. This team had a current Varley Job Safety and Environmental Analysis (JSEA) for hot work to remove stoppers on board ship and had completed a Varley hot work permit.

At 0630, the chief mate convened a safety meeting involving the Varley boilermaker and relevant crewmembers. The process of removing the stoppers was discussed along with the safety measures and procedures to be followed. Hot work requirements, including the hot work permits and risk assessments, were reviewed. Individual duties, including that of the fire watch, were explained and assigned. The ship’s crew were responsible for providing firefighting equipment (such as extinguishers and hoses) and controls such as the fire watch.

The work commenced in the number two cargo hold tween deck.[2] In preparation for the hot work, gaps between the tween deck pontoons were filled and covered with fire blankets (made from woven fibre and leather) to stop sparks from falling onto the cloth-covered cargo in the lower hold (Figure 2).

Figure 2: Worksite showing stoppers, after the incident

Figure 2: Worksite showing stoppers, after the incident. Source: Briese Schiffahrts annotations by ATSB

Source: Briese Schiffahrts annotations by ATSB

The fire watch consisted of two crewmembers in contact via VHF radio, one on the tween deck and the other in the lower hold. A small diameter fresh water hose was laid out and a makeshift water spray extinguisher readied for immediate use in the lower hold. Cargo in the lower hold was covered with the transport cloth but was not covered with fire blankets.

At 1015, the boilermaker began removing the stoppers. The work site was overseen by ship’s crewmembers, the port captain[3] and the Varley site supervisor. The port captain asked that sparks be directed away from the cargo to protect the component surfaces. This request, in some cases, resulted in the sparks being directed toward gaps between the tween deck pontoons.

The work continued as expected and, at 1100, the boilermaker stopped to relocate to the next stoppers on the tween deck. As part of checking the new work area, he lifted a fire blanket and could see small flames and smoke in the lower hold through the gap in the tween deck pontoons. He immediately raised the alarm. The lower hold fire watch was notified on the radio. At the time he was notified he was not near the area directly under where the work was being conducted. After moving to the relevant area, he quickly extinguished the fire using the water hose and water spray. Figure 3 shows the location of the work site and the fire in the ship’s hold (elevation view and plan view).

Figure 3: Number 2 cargo hold, elevation and plan views of worksite

Figure 3: Number 2 cargo hold, elevation and plan views of worksite. Source: Briese Schiffahrts with annotations by ATSB

Source: Briese Schiffahrts with annotations by ATSB

An inspection of the work site following the fire identified that molten metal and other hot material produced by the hot work had burned through the fire blankets. This hot material fell onto the material covering the cargo in the lower hold, resulting in the fire. As a result of the fire, the material covering the cargo was damaged and some surface blemishes were apparent on the cargo itself (Figure 4). No other damage was reported. Subsequent inspection of the cargo covering material found it to be 100 per cent polyester transport cloth with a maximum rated temperature of 200 °C.

Following the fire, all work to remove the stoppers was suspended and the incident was reviewed. Procedures and safety measures were reassessed during a meeting of ship’s crew and the shore contract team. The cutting procedure was amended to direct the sparks away from deck openings and containment of sparks around the work area was improved. Further, additional filling material was added to holes in the tween decks used for removable hand rails, and the lower hold fire watch was directed to monitor the area directly below the work rather than the general vicinity. Work resumed at 1315 and continued to completion without further incident.

Figure 4: Cargo covering material and cargo surface damage

Figure 4: Cargo covering material and cargo surface damage. Source: Briese Schiffahrts

Source: Briese Schiffahrts

BBC Xingang

BBC Xingang is a multi-purpose, heavy lift, general cargo ship registered in Antigua and Barbuda. The ship was built in 2013 by Tianjin Xingang Shipbuilding Heavy Industry, China and classed with DNV GL.

The ship has an overall length of 125.8 m, a moulded breadth of 22.0 m and a deadweight of 8,970 t at its summer draught of 7.60 m. The multi-purpose ship can carry containers and/or general cargo. It has two cargo holds with tween decks. Two 350 t capacity cranes are mounted on the port side and can be used in combination to lift loads up to 700 t.

At the time of the incident, BBC Xingang was owned by Briese Schiffahrts ‘Hatshausen’, operated by BBC Chartering & Logistics and managed by Briese Schiffahrts, all of Germany.

Previous incidents

The ATSB has, on two previous occasions, investigated fires on board Briese Schiffahrts managed vessels in Australian ports.[4] On both occasions the fire was started during hot work to remove sea fastenings. In the BBC Baltic fire, flammable cargo coverings were also found to have ignited. The damage caused was considerably more than that sustained on BBC Xingang.

As a consequence of the previous incidents, Briese Schiffahrts had completed significant safety actions, which were in place at the time of the current fire. These included improved shipboard procedures, risk assessments, permits to work, safety meetings and provision of equipment such as fire blankets and mats.

Safety analysis

The task of removing sea fastenings, originally welded in place to prevent movement of the cargo during the sea voyage, involved hot work, cutting and gouging techniques. This hot work produced sparks, globules of molten steel of various sizes and other hot material. To protect the sensitive surfaces of the cargo, the debris produced by the hot work was directed away from the cargo and more toward gaps/holes in tween deck pontoons.

The work area and the gaps/holes in the pontoons were protected by fire blankets. However, the molten metal produced was of sufficient size and intensity to burn through the protective fire blankets and fall onto the cargo stowed in the deck below. This cargo was covered with transport cloth to protect it during transport but was not protected from the hot debris by covering with fire blankets. Transport cloth is made of 100 per cent polyester and will ignite if directly exposed to fire. As a consequence, when the hot material fell onto the unprotected transport cloth it resulted in the fire.

A fire watch was present in the lower hold but had not been directed to closely monitor immediately below the work site. Therefore, the fire watch was not in position to immediately react when the molten metal fell from above. It was only when the flames and smoke were observed by the boilermaker that the response was initiated and the fire extinguished.

Despite the safety actions taken after previous fires, flammable cargo coverings were again ignited during sea fastening removal on this occasion. Careful consideration must be given to the use of such materials. Prior to hot work, cargo coverings should be carefully assessed and adequate protection against damage or fire due to hot material should be provided.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

The fire on BBC Xingang started during the oxy-acetylene cutting and gouging removal of sea fastenings. Molten metal and other hot material produced by this work burned through protective fire blankets in place around the site, and fell onto unprotected cargo below.

  • The cargo stowed below the work site was covered with flammable polyester material which had not been adequately identified and protected prior to the work commencing.
  • A fire watch was present in the lower hold but had not been directed to closely monitor immediately below the work site so was not in position to quickly react when the molten metal fell from above.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety actions in response to this occurrence.

Briese Schiffahrts

On board BBC Xingang, replacement fire blankets were obtained and a safety meeting convened to discuss the incident. This meeting, attended by all ship’s crewmembers, discussed the circumstances of the incident, reviewed relevant existing fleet circulars, reviewed the risk assessment and went through procedures and processes relating to this work and the role of the fire watch.

Varley

Varley advised the ATSB that it had:

  • reviewed and updated the Job Safety and Environmental Analysis (JSEA) to implement added control measures for hot work
  • amended work procedures to:
    • improve coordination and communication between vessel management and third party contractors regarding expectations of fire watchers and firefighting equipment prior to starting work
    • ensure inspections are conducted on all cargo and materials in lower holds, prior to starting any hot work in the tween decks
    • ensure that if suspect items are found in the lower hold that communications with work teams and site management include focus on safety expectations and hot work controls
    • include using heat proof tape to cover gaps in the tween decks with fire blankets added on top
    • use fire blankets to protect items in the lower hold.

BBC Chartering

BBC Chartering advised the ATSB of the following safety action:

  • gaps/holes in the tween decks will be covered by fire resistant tape in addition to other measures such as using fire blankets to protect areas below hot work.

Vestas

Vestas advised the ATSB that as part of cargo handling guidance, storyboards explaining safety measures to be taken while welding, cutting and grinding are shared with vessel owners, carriers, and freight forwarders contracted for the carriage of Vestas cargo.

Safety message

Ship fires due to hot work to remove sea fastenings are a constant danger. The continuing incidence of hot work related fires during the removal of sea fastenings highlights the importance of maintaining vigilance throughout the entire process. This is especially important if this is a regular task and is at risk of becoming routine. Procedures and practices along with the equipment available for completion of the task need to be reviewed and assessed and used as appropriate.

Hot work requires the implementation of comprehensive risk controls and procedures. These should include, but not be limited to, detailed, task-specific appraisals, risk and hazard assessments, work permits and pre-work toolbox meetings. Ultimately, the responsibility for the implementation of these controls rests with the ship, in consultation with third parties if involved. This is especially important when shore labour is employed to complete the work and multiple organisations’ work requirements and procedures are involved.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. All times referred to in this report are local time, Coordinated Universal Time (UTC) + 11 hours.
  2. The tween deck is a deck located about mid depth in the cargo hold. It consists of pontoons, which are removable steel structures running the full width of the hold (about 17 m), about 7 m long and 0.8 m deep.
  3. A senior official appointed by the ship’s owners to oversee cargo handling and associated work including the fitting or removal of cargo securing arrangements such as stoppers.
  4. In 2012, investigation 293-MO-2012-002 involving BBC Baltic. In 2008, investigation 245 involving BBC Islander.

Occurrence summary

Investigation number 337-MO-2017-011
Occurrence date 11/12/2017
Location Newcastle
State New South Wales
Report release date 25/05/2018
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Marine
Marine occurrence category Fire
Occurrence class Incident
Highest injury level None

Ship details

Name BBC Xingang
IMO number 9508483
Ship type Cargo
Flag Antigua and Barbuda
Manager BBC Chartering and Logistics (Germany)
Departure point Newcastle, New South Wales
Destination Mackay, Queensland

Fractured bogie frame on coal train TM78A, Kooragang, New South Wales, on 12 December 2017

Final report

Report release date: 17/03/2020

Safety summary

What happened

On 12 December 2017, a fractured bogie was identified on Pacific National train TM78A during a roll-by inspection at the Kooragang Coal Terminal, New South Wales. The fracture was on bogie NDCA 1199 of wagon NHBH 42954J. This wagon operated loaded between Tahmoor Colliery and Kooragang prior to identifying the fractured bogie.

What the ATSB found

The ATSB found that a fatigue crack went undetected during preventative maintenance activities prior to the structural failure of the bogie frame. It is probable that the fracture was visible at the time of unloading at Newcastle Coal Infrastructure Group on 11 December, which went undetected. The fractured bogie was identified during a roll-by inspection on 12 December, likely preventing a derailment.

What's been done as a result

Pacific National made changes to the maintenance standards used during scheduled maintenance, to increase the area of the bogie frame subjected to non-destructive testing. These changes are aimed at identifying and addressing fatigue cracking prior to the escalation of the defect.

Safety message

Asset managers should ensure that inspection techniques effectively monitor and report on asset condition. Risk controls should also be continuously assessed to control risk to an acceptable level through the life cycle of the asset.

 

The occurrence

What happened

On the morning of 12 December 2017, train TM78A operated by Pacific National (PN) was unloading coal at the Kooragang Coal Terminal (KCT).[1] At the time, a maintenance worker was conducting a roll-by inspection[2] after the train moved through the unloading bay. The worker visually identified a crack on the lead bogie of wagon NHBH 42954J, this was the 35th wagon in the direction of travel. The train was stopped and the wagon was removed to allow for inspection.

The train operated between KCT to Clarence on the 10 December, before returning to Newcastle Infrastructure Coal Group (NCIG). On 11 December the train operated empty from NCIG to Tahmoor before returning loaded to KCT (Figure 1). During these journeys, the trackside condition based monitoring equipment recorded elevated bearing temperatures on axle 4 of wagon NHBH 42954J, as well as an increased angle of attack (AoA).[3] These recordings did not generate an alert at the time of passing the various detection sites and the train continued to operate until the fractured bogie was visually identified by the maintenance worker.

Figure 1: Incident location

Figure 1: Incident location. 
Source: Geoscience Australia, annotated by OTSI

Source: Geoscience Australia, annotated by OTSI

Safety analysis

A PN maintenance worker was located inside the unloading bay at NCIG on 11 December, this worker’s primary function was to observe the wagon doors close. It was not clear if this worker was deemed to additionally be conducting a roll-by inspection. The worker was positioned on the opposite side (to the bogie fracture) of wagon NHBH 42954J and did not report any defects. The bogie was probably visibly fractured at the time based on the increased AoA.

The roll-by inspection completed on 12 December was completed by a single worker, with the worker positioned on the same side as the fractured bogie and the defect was identified. The axle showed signs of rotating forward and up relative to the frame as the fracture opened under the weight of the wagon (Figure 2). As the fracture opened the effective axle spacing changed, lengthening the wheelbase on the side of the cracked frame. PN maintenance standards permit roll-by inspections being completed by a single worker. The defect was detected during a roll-by inspection, however could have been missed if the worker was positioned on the opposite side.

Figure 2: Fractured bogie frame NDCA 1199

Figure 2:  Fractured bogie frame NDCA 1199.
Source: Pacific National, annotated by OTS

Source: Pacific National, annotated by OTSI

The train underwent unit train maintenance (UTM) and a full train examination (FX) on 8 December 2017 at the PN Lithgow maintenance depot. During this inspection, there were no defects reported in relation to bogie NDCA 1199. Prior to identifying the fractured bogie, the train was compliant with the PN technical maintenance plan.

Bogie NDCA 1199 underwent schedule maintenance in July 2015. The bogie frame was subjected to non-destructive testing (NDT) consisting of magnetic particle inspection (MPI) and tested in accordance with PN procedure WMM 11-08_06 One Piece Bogie Inspection. There were no defects detected at the time of testing and the location of the fracture was at the extremity of the area subjected to NDT. Evidence of remnant MPI marker paint was present on the outboard plate, but there was no apparent marker paint on the inboard plate at the region of the fracture.

Fatigue cracking has historically been identified in the NDCA bogies at the welded junction joining the vertical plate and bottom plate section due to the design and manufacturing process used to build this class of bogie at the time. The NDCA bogie is comprised of welded steel plates to form a single piece box section bogie frame.

Prior to this occurrence, a derailment occurred in 2011 at Leigh Creek, South Australia. This derailment was reportedly the result of a fractured NDCA bogie. The bogie fracture increased the wheelbase on the side of the fractures, likely placing additional loading on the axle bearing as the axle tracked abnormally, this led to the bearing overheating and failing.

Post-occurrence inspection of the bogie NDCA1199 showed a fatigue crack most likely initiated at the toe of the weld on the inboard corner of the bogie side frame before progressing across the lower plate and inboard vertical plate (Figure 3). The inboard fracture face was smooth and displayed beach marks (slow progression), while the outboard face was jagged in appearance indicative of rapid progression.

Figure 3: NDCA 1199 fracture analysis

Figure 3: NDCA 1199 fracture analysis.
The image shows the bogie fracture from the underside of the bogie to show the three fracture faces. 
Source: OTSI

The image shows the bogie fracture from the underside of the bogie to show the three fracture faces. Source: OTSI

The trackside condition based monitoring equipment recorded increased bearing temperatures from 10 December after departing Clarence, as well as an increased AoA on 11 December. Analysis of this recorded data following the event, indicates that the change was likely the result of the bogie frame fracture progressing. As the fracture progressed, the wheelbase (spacing between the axles) increased between axle 3 and 4, affecting the AoA and placing additional loading on the bearing.

At the time of passing through the various trackside condition based monitoring sites, the recorded bearing temperatures did not trigger an automatic alarm to notify the rail infrastructure manager (RIM) or PN. The track side detection equipment utilises algorithms to determine critical levels[4] that trigger automatic alarms to advise the RIM or operator. In relation to bearing temperature, only warm or hot bearing alarms will trigger an automatic alarm that requires immediate attention. Low bearing temperature alerts and AoA are recorded by the system but do not generate automatic alarms.

The wagon loading for the previous journeys was reviewed and indicated, that between 10 December and 12 December, the wagon operated within the allowable 100 t gross limit. The operation of the train and wagon loading does not appear to have contributed to this occurrence.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • A fatigue crack likely originated at the toe of a weld on the inboard lower plate of the bogie frame that was not identified during the preventative maintenance activities, prior to the structural failure of the frame. The fatigue cracking most likely progressed across the full face of the lower plate and inboard side plate before rapidly progressing across the outboard side plate.
  • The NDCA bogie design has a history of fatigue cracking which increases the risk of derailment if the cracking is not identified. Pacific National had processes in places to identify fatigue cracking but this crack was likely not detected due to the location of the defect.
  • Trackside condition based monitoring equipment recorded elevated bearing temperature and increased angle of attack in the days prior to the fractured bogie being identified. This was likely a result of the bogie fracture progressing. The recorded temperature did not trigger an automatic alert to advise the rail infrastructure manager or operator.

Safety action

The ATSB has been advised of the following safety action in response to this occurrence.

Pacific National

As a result of this occurrence, Pacific National has advised the ATSB that they have taken the following safety actions:

Bogie Survey

Pacific National undertook a visual inspection of all NDCA bogie frames for evidence of cracking as directed by Office of the National Rail Safety Regulator (ONRSR).

Revised Maintenance Standard

Pacific National revised maintenance standard WMM 11-08_06 One Piece Bogie Inspection to increase the area subjected to NDT testing during schedule overhauls. The entire side frame is now tested on the inboard and outboard plates as well as the underside of the bogie frame through the horn cheek area.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Kooragang Coal Terminal is operated by Port Waratah Coal Services (PWCS).
  2. Roll-by inspections are a visual inspection of moving rail traffic to identify equipment, loading security or other defects or failure.
  3. Angle of attack (AoA) refers to the alignment of the train axle and wheels relative to the rail.
  4. Bearing and Brake Temperature Alarm Model, T HR RS 133003 ST, Version 1.0. Issue date 12 January 2017. Asset Standards Authority, Transport NSW.

Occurrence summary

Investigation number RO-2017-018
Occurrence date 12/12/2017
Location Kooragang Coal Terminal, Number 3 Departure Road
State New South Wales
Report release date 17/03/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Rolling Stock Irregularity
Occurrence class Incident
Highest injury level None

Train details

Train operator Pacific National
Train number TM78A
Type of operation Freight
Departure point Kooragang Coal Terminal, New South Wales
Destination Tahmoor, New South Wales
Train damage Substantial

Near collision involving Cessna 210, VH-SYT, and Cessna 206, VH-HPA, 46 km south-west of Darwin Airport, Northern Territory, on 6 December 2017

Final report

Report release date: 17/01/2019

What happened

On 6 December 2017, at about 0800 Central Standard Time,[1] a Cessna U206G (C206) aircraft, registered VH-HPA (HPA) and operated by Hardy Aviation, taxied at Darwin Airport, Northern Territory (NT). A Cessna 210L (C210) aircraft, registered VH-SYT (SYT) and operated by Chartair, taxied not far behind HPA.

The pilots of the aircraft were both operating charter flights to Port Keats, NT, under the visual flight rules (VFR),[2] and had planned to track at 8,500 ft. Their initial clearance, in accordance with the traffic management plan for Darwin, was to track via VFR route 5, which tracked south for 5 NM then south-west (Figure 1). Both aircraft were taxiing to depart from runway 18. Prior to take-off, the pilot of each aircraft was advised by air traffic control[3] that the other aircraft would also be tracking to Port Keats at 8,500 ft.

Figure 1: Extract of Darwin Visual Terminal Chart showing VFR Route 5 and direct track to Port Keats

Figure 1: Extract of Darwin Visual Terminal Chart showing VFR Route 5 and direct track to Port Keats. Source: Airservices – annotated by ATSB

Source: Airservices – annotated by ATSB

The pilot of HPA, with two passengers on board, observed SYT taxiing and saw only the pilot on board. He assumed, therefore, that SYT would probably be light and expected it would quickly overtake and out-climb HPA.

Shortly after take-off, the pilot of HPA contacted the Darwin approach controller and reported passing 800 ft on climb to 2,000 ft. The Australian Defence Air Traffic System (ADATS) controller’s situation display indicated the aircraft’s altitude as 700 ft at that time, based on the transmission from the aircraft’s mode C transponder (see the section titled Radar altitude). The controller then cleared HPA to track direct to Port Keats at 8,500 ft.

The pilot of SYT was cleared for take-off about 1 minute after HPA. Once airborne, he immediately looked for, and sighted HPA. Just before 0808, the pilot of SYT contacted the approach controller and reported passing 600 ft on climb to 2,000 ft, with HPA in sight (Figure 2). By the end of that transmission, the controller’s situation display radar altitude for SYT indicated 100 ft. The displayed level information differed from the pilot’s reported altitude by more than the permitted tolerance of 200 ft (see the section titled Radar altitude) but there was no indication that the controller identified that discrepancy.

Figure 2: Google Earth image overlaid with aircraft tracks

Figure 2: Google Earth image overlaid with aircraft tracks. Source: Google Earth and radar data – annotated by ATSB

Source: Google Earth and radar data – annotated by ATSB

In response to the transmission by the pilot of SYT, the controller advised that the preceding traffic (HPA) was now tracking direct to Port Keats at 8,500 ft, and then asked whether direct tracking was also being sought for SYT. The pilot of SYT responded ‘affirm, when available’. The controller advised him to expect that clearance in 1 minute.

The approach controller reported that SYT was left on VFR route 5 for about 1 minute to segregate it from HPA, before being re-cleared to track direct to Port Keats at 8,500 ft. The pilot of SYT reported that the direct track to Port Keats put SYT on a similar track to HPA. Therefore, he kept HPA in sight, and manoeuvred to the right of its track, expecting to overtake it.

The pilot of HPA expected that SYT would be either just to the left (based on the VFR route’s initial southerly track compared to the direct track to the south-west) or directly behind HPA. At 0812, the pilot of HPA requested (and received) a clearance to stop climb at 6,500 ft ‘due to faster following traffic’. This transmission was intended to make the pilot of SYT aware that he knew SYT would be close behind, and for vertical separation between the two aircraft.

Three minutes later, the approach controller asked the pilot of SYT if he still had the preceding traffic in sight, and the pilot responded ‘affirm’. The controller then advised him that HPA was now on climb to the amended level of 6,500 ft.

As SYT approached 5,500 ft, the pilot of SYT could see his aircraft was gaining on HPA, and assessed it would soon overtake HPA. Shortly after, HPA moved through the 10 o’clock position[4] of the pilot of SYT who then lost sight of it behind SYT’s left wing.

At 0816, when about 15 NM south-west of Darwin Airport, the pilot of SYT reported to the approach controller that he was ‘just coming up on HPA’s 3 o’clock position and lost sight’ of that aircraft. The controller advised that HPA was ‘climbing through 6,200 [ft] at the moment, probably half a [nautical] mile to your left’. The pilot of SYT responded ‘Sierra Yankee Tango’, and did not sight HPA.

The controller then gave HPA traffic information: ‘SYT is on your right 3 o’clock, half a [nautical] mile, climbing through 5,500 [ft]’. The pilot of HPA responded that he was ‘looking’. The pilot of HPA looked to his right, but did not see SYT.

The radar data at that time indicated lateral separation between the aircraft was 0.27 NM (500 m), with SYT behind and slightly right of HPA and 800 ft below. About 30 seconds later, an ADATS conflict alert (CA)[5] activated on the controller’s situation display (SYT indicated 5,600 ft and HPA 6,400 ft). When HPA reached 6,500 ft, the pilot levelled the aircraft off and completed the top of climb checks.

At 0817, the approach controller asked the pilot of SYT ‘Do you have that traffic in sight or would you prefer a different level or tracking?’ The pilot of SYT responded ‘Negative, traffic not in sight… happy to maintain this track if HPA has us in sight’. The controller then asked the pilot of HPA if they had SYT in sight. The pilot of HPA responded ‘Negative’ and advised that HPA was now maintaining 6,500 ft.

The pilot of SYT reported that, at that time, he still thought the aircraft were half a nautical mile (900 m) apart and was expecting HPA to be out to his left. However, the radar data indicated that HPA was 800 ft vertically above, and 0.18 NM (333 m) laterally away from SYT.

At 0818 the CA activated again while neither pilot had the other aircraft in sight. The radar data at the time indicated that SYT was at 5,900 ft, HPA at 6,500 ft with a lateral separation of 0.13 NM (241 m).

The approach supervisor reported that, at that stage, there was still just over 500 ft vertically between the two aircraft and that he instructed the approach controller to maintain 500 ft separation between the aircraft.

In response to the direction from the supervisor, the controller asked the pilot of SYT if he would ‘like to stop climb 6,000 [ft]?’, to which he responded ‘Negative, I’ll continue on to 8,500 [ft], happy to take 3 [nautical] miles right of track if that puts us out of conflict’. The pilot of SYT reported that he was puzzled by the question because at that stage his altimeter was indicating an altitude of 6,300-6,400 ft. The radar data at the time showed SYT at 6,000 ft, HPA at 6,500 ft and 0.086 NM (160 m) lateral separation between the aircraft, which were then about 20 NM south-west of Darwin Airport.

The pilot of SYT commented that as soon as he made that request to deviate three nautical miles right of track, HPA came from the left top corner of his windshield across the nose to the bottom right in front of him and filled the windscreen. He estimated the two aircraft passed 3‑4 m apart.

The pilot of HPA was looking out to his 3 o’clock position when the pilot of SYT was in the process of requesting the deviation right of track. SYT appeared in the pilot of HPA’s 5 o’clock position and he reported being surprised by its close proximity. He and the passengers in HPA estimated the aircraft came within 5 m of each other.

The controller then cleared SYT to deviate up to three nautical miles right of track and advised that ‘HPA by radar is on top of you 6,500 [ft]’.

Both pilots reported that by the time the approach controller cleared SYT to deviate right of track, the two aircraft had already passed each other and the separation between them was increasing. SYT was now to the left of HPA and the pilot of SYT had HPA in sight. The closest proximity according to the radar data was 100 ft vertically and 0.02 NM (37 m) laterally.

The approach controller reported that the CA activated again and SYT did not seem to be deviating to the right, just continuing to climb. The controller observed SYT passing 6,200 ft on the situation display and, as it was now less than 500 ft below HPA, they issued a safety alert. The approach supervisor reported also directing the controller to issue a safety alert at that time.

After the aircraft had already passed each other in close proximity, the pilot of SYT responded ‘Say again’. The approach controller then responded ‘Safety alert: HPA by radar is on top of you 6,500 [ft]. Deviate up to 3 [nautical] miles right of track and maintain 6,000 [ft] until clear’.[6]

The approach controller recalled assessing that SYT might be required to descend to the cleared altitude of 6,000 ft at the time the instruction was issued. In response to that transmission, the pilot of SYT advised that HPA was now to the right of their track, so SYT would stay to the left.

The two aircraft continued to Port Keats without further incident.

VFR aircraft in Class C airspace

In Class C airspace, VFR aircraft are provided with traffic information on other VFR aircraft and are not separated by air traffic control (ATC). The approach supervisor commented that there was no responsibility for ATC to provide separation between those two aircraft. However, they were entitled to a traffic service and a safety alert if the controllers assessed there was a problem.

Civil Aviation Regulation (CAR) 163 stated that ‘The pilot in command of an aircraft must not fly the aircraft so close to another aircraft as to create a collision hazard.’ In addition, CAR 163A states that ‘the flight crew of an aircraft must… maintain vigilance so as to see, and avoid, other aircraft.’

The approach supervisor commented that they had an expectation that the pilots of the involved aircraft would have had an understanding of the relative performance of each other’s aircraft and that they would maintain visual contact and be able to keep clear of each other.

While pilots of VFR aircraft are responsible for avoiding other VFR aircraft, according to MATS 2.2.1.1, the objectives of Air Traffic Services include to ‘prevent collisions between aircraft.’ The approach supervisor commented that when pilots of VFR aircraft lose sight of each other, the requirements of the safety alert come into place.

Darwin VFR aircraft operations

A large number of VFR aircraft operate charter flights to and from Darwin Airport. The controllers reported that VFR aircraft often tracked in close proximity to each other, although when there were more than two aircraft departing on the same track, ATC usually provided instructions to segregate them. In addition, ATC often separated VFR aircraft from instrument flight rules aircraft by issuing the pilots of the VFR aircraft with tracking instructions.

The controller commented that when multiple aircraft depart together bound for the same location, they are usually from the same operator, but in this incident they were not. He also commented that this might have contributed to the slower aircraft departing ahead of the faster one. If the two aircraft were from the same operator, the pilots may have sequenced themselves so the faster aircraft would depart first. The pilot of SYT said in future, taxiing out, he would contact the ground controller and ask if they could depart ahead of the slower aircraft. In addition, in a similar situation, as soon as possible, he would put his aircraft on a track 5 NM right of the other aircraft.

The approach controller commented that the C206 and C210 were very similarly performing aircraft, and their speeds can vary depending on how many people and how much cargo and fuel is on board, so the type of aircraft is not always a good indication of relative performance.

In accordance with Darwin’s traffic management plan, all VFR traffic are cleared to depart via a published VFR route, except those going to the nearby islands. After departure most aircraft are cleared for direct tracking as soon as practicable. The VFR route 5 tracks 5 NM south of Darwin then south-west, and would have been within a couple of miles left of the direct track. The pilot of SYT had planned to track via VFR route 5 in accordance with their standard operating procedures.

The pilot of HPA was using an electronic flight bag[7] and tracked direct to Port Keats once cleared. The pilot of SYT reported maintaining a constant heading direct to Port Keats after receiving clearance to track direct, and that he ‘was checking the heading continuously’ and the two aircraft were ‘paralleling until he lost sight of HPA’.

Conflict alert

In Class C airspace in Darwin, when aircraft operate within 3 NM horizontally and 1,000 ft vertically, a CA activates. In response, the controller usually announces to the other controllers and supervisor what separation standard is in place – whether it is ‘traffic’, or another standard such as ‘500 ft’ vertical separation. The approach supervisor commented that it was normal for Darwin for the conflict alert to activate between VFR aircraft.

ATSB investigation AO-2011-011 identified a safety issue at Williamtown (Newcastle Airport), New South Wales associated with conflict alerting. The conflict alerting function had been disabled following a risk analysis and advice from safety specialists, due to numerous, unavoidable spurious alarms at Williamtown. During a trial period in which the alerts were activated, a Department of Defence investigation found that the alert function did not assist controllers in the identification or resolution of traffic conflicts and that false alerts may have resulted in controller desensitisation.

Limitations of see‑and‑avoid

The limitations of see-and-avoid practices are well known and documented. Civil Aviation Advisory Publication (CAAP) 166-2(1) Pilots’ responsibility for collision avoidance in the vicinity of non‑controlled aerodromes using ‘see-and-avoid’[8] discusses see-and-avoid in non-controlled airspace, but much of the content is relevant to pilots of all VFR aircraft including in controlled airspace.

Alerted see-and-avoid, where the pilot is directed where to look to sight another aircraft, is much more effective than un-alerted. However, there are still a number of factors that affect a pilot’s ability to sight another aircraft. In this incident, the pilot of SYT lost sight of HPA when it was above and diagonally to his left, as it was then obscured by SYT’s left wing. Additionally, when the pilot advised ATC that he had lost sight of HPA, the controller responded that HPA was half a mile to his left, and then advised the pilot of HPA that SYT was half a nautical mile to his right in his 3 o’clock position. A review of the radar data identified that the relative positions of the aircraft differed from that advised by the controller.

Radar altitude

An aircraft’s transponder operating in mode C transmits a signal that permits a secondary surveillance radar ground station to determine the distance and bearing to the aircraft as well as its altitude.

Aircraft altimeters and ATC situation display show barometric altitude below the transition altitude (10,000 ft in Australia). Aircraft mode C transponders sense and transmit static air pressure to ground‑based surveillance equipment. That equipment converts the value into the corresponding pressure altitude and, if below the transition altitude, applies an input from a ground‑based QNH to obtain the equivalent barometric altitude. The calculated altitude is displayed to controllers with a resolution of 100 ft.

MATS section 9.7.5.5 Display tolerance stated that ‘when the displayed pressure altitude-derived level information differs from the pilot-reported or known altitude by more than 200 ft: a) advise pilot; b) request check of pressure setting; and c) confirm current level.’

When the pilot of HPA reported passing 800 ft, the displayed altitude was 700 ft and therefore within tolerance. However, when the pilot of SYT first contacted the approach controller and reported passing 600 ft, the aircraft’s label on the situation display indicated 100 ft by the end of the pilot’s transmission, which was outside the 200 ft tolerance. The 500 ft discrepancy between SYT’s displayed radar altitude and actual aircraft altitude correlated with the recorded radar data from Airservices Australia while the aircraft was in cruise. There was no indication that the controller detected the discrepancy.

Because of this discrepancy, SYT was about 500 ft higher and therefore about 500 ft closer vertically to HPA than displayed. Allowing for this, the closest proximity between the aircraft around the time of the occurrence was within 100 ft, and this proximity occurred before the controller issued the safety alert. Given the radar is only displayed to the nearest 100 ft, this was consistent with the pilots of both aircraft reporting that the aircraft came within 3–5 m of each other at the same altitude and that they had passed before the safety alert was issued.

Safety analysis

Development of the occurrence

The pilots of the two aircraft were required to see and avoid each other. SYT was trailing, but faster than, HPA. That relative positioning reduced the opportunity for the pilot of HPA to identify the developing proximity event, as SYT was below HPA as the two aircraft converged. As SYT closed on HPA, the pilot of SYT lost visual contact as the wing structure visually obscured HPA. The pilot of SYT identified that his aircraft was about to overtake HPA, but did not manoeuvre to keep HPA in sight or request an alternative clearance. The pilot of SYT lost sight of HPA while the aircraft were about 500 m and 800 ft apart.

Although the pilot of SYT did not manoeuvre to maintain sight of HPA, he did advise ATC that he had lost visual contact with that aircraft. When requested, ATC will provide VFR flights in Class C airspace with a suggested course of action to avoid other VFR flights, but the pilot is still required to see and avoid other aircraft.

As neither pilot requested ATC to provide avoiding action, the controller did not issue alternative segregation instructions at that time and the two aircraft continued to converge. The controller did, however, provide traffic information to both pilots and offered alternative tracking.

The controller issued a safety alert and instructions when the vertical separation depicted on the situation display between the aircraft reduced to about 500 ft. However, due to a combination of radar accuracy/resolution and the altitude of SYT on the situation display not being within the required 200 ft tolerance, the aircraft were much closer than the indicated 500 ft. Consequently, the safety alert was issued after the near collision and so neither pilot had an appreciation of just how close the aircraft were until they re‑sighted each other as they passed in close proximity.

Had the controller verified the initial altitude of SYT on first contact, they would have identified the discrepancy between the reported and displayed altitudes. The controller would then have had an accurate indication of the vertical distance between the two aircraft.

See-and-avoid limitations

Obstruction by the aircraft’s wing is one of many factors identified by ATSB research that affect a pilot’s ability to sight another aircraft. This occurrence therefore highlights the difficulties of the see-and-avoid principle, even when the pilot is given information about (or alerted to) the other aircraft’s position. Airborne collision avoidance systems (ACAS) provide valuable information to alert pilots of other aircraft in their proximity and can direct the pilot to take avoiding action, thereby reducing the risk of collision.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The approach controller did not verify the initial altitude of VH-SYT, which was outside the allowable 200 ft tolerance. That resulted in the two aircraft being significantly vertically closer than displayed and, in turn, the controller issuing a safety alert after the near collision had occurred.
  • After the pilot of VH-SYT lost sight of VH-HPA, he advised air traffic control and took no further action to ensure segregation between the aircraft.

Safety message

Pilots and air traffic controllers have a joint responsibility to avoid collisions between aircraft. In controlled airspace, air traffic controllers are not required to provide pilots of aircraft operating under the VFR with separation from other VFR aircraft. While air traffic controllers can provide traffic information to pilots of VFR flights, see-and-avoid is the primary means of preventing collisions between VFR aircraft.

The limitations of see-and-avoid techniques are well known and are detailed in the ATSB publication Limitations of the See-and-Avoid Principle. When pilots are alerted to the location of another aircraft, this significantly improves their ability to sight the other aircraft. However, as detailed in the publication, many factors can affect a pilot’s ability to sight another aircraft. The publication was written in 1991 and states that ‘Because of its many limitations, the see-and-avoid concept should not be expected to fulfil a significant role in future air traffic systems.’

Both VH-SYT and VH-HPA were equipped with mode C transponders, but neither aircraft was equipped with any airborne collision avoidance system (ACAS) technology, nor were they required to be by regulation. Such a system provides information to increase a pilot’s awareness of nearby aircraft and therefore reduces the risk of a mid-air collision.

Recent advancement of ACAS technologies has made them viable for general aviation aircraft and they should be considered. The ATSB report (AO-2016-015) into a near collision involving a Saab 340 aircraft and a glider in 2016 outlined a proposal by the industry body, Australian Strategic Air Traffic Management Group, to the Civil Aviation Safety Authority (CASA). It recommended the adoption of standards for ADS‑B technology to be fitted in general aviation aircraft to enable awareness of other aircraft traffic and thereby reduce the risk of mid-air collisions.

Following industry consultation, CASA is proposing to relax the equipment and installation standards for ADS-B fitment in VFR aircraft. The aim is to make it cheaper and easier for aircraft operating under VFR to purchase and use the technology.

About this report

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope, fact-gathering investigation was conducted in order to produce a short summary report, and allow for greater industry awareness of potential safety issues and possible safety actions.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Central Standard Time (CST): Coordinated Universal Time (UTC) + 9.5 hours.
  2. Visual flight rules (VFR): a set of regulations that permit a pilot to operate an aircraft only in weather conditions generally clear enough to allow the pilot to see where the aircraft is going.
  3. The Australian Defence Force provides the air traffic control services associated with Darwin Airport.
  4. O’clock: the clock code is used to denote the direction of an aircraft or surface feature relative to the current heading of the observer’s aircraft, expressed in terms of position on an analogue clock face. Twelve o’clock is ahead while an aircraft observed abeam to the left would be said to be at 9 o’clock.
  5. The CA activated when aircraft were within about 1,000 ft and 3 NM of each other.
  6. ATC will issue a Safety Alert to aircraft, in all classes of airspace, when they become aware that an aircraft is in a situation that is considered to place it in unsafe proximity to: terrain; obstruction; active restricted or prohibited area; or other aircraft.
  7. Electronic flight bags can electronically store and retrieve documents required for flight operations, such as maps, charts, the Flight Crew Operations Manual, Minimum Equipment Lists and other control documents. See CASA CAAP 233-1.
  8. Available from CASA’s website: www.casa.gov.au

Occurrence summary

Investigation number AO-2017-116
Occurrence date 06/12/2017
Location 46 km south-west of Darwin Airport
State Northern Territory
Report release date 17/01/2019
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Near collision
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model U206G
Registration VH-HPA
Serial number U20605002
Aircraft operator Hardy Aviation NT
Sector Piston
Operation type Charter
Departure point Darwin, Northern Territory
Destination Port Keats, Northern Territory
Damage Nil

Aircraft details

Manufacturer Cessna Aircraft Company
Model 210L
Registration VH-SYT
Serial number 21061052
Aircraft operator Chartair
Sector Piston
Operation type Charter
Departure point Darwin, Northern Territory
Destination Port Keats, Northern Territory
Damage Nil

Collision with terrain involving PZL Warszawa-Okecie M-18A Dromader aircraft, VH-WHR, 9 km north-west Emerald Airport, Queensland, on 1 December 2017

Final report

Report release date: 05/02/2019

What happened

On the morning of 1 December 2017, an M-18A Dromader aircraft (Pratt & Whitney PT6A engine), registered VH-WHR (WHR) prepared for an aerial agricultural spraying operation at a private airstrip, 9 km north of Emerald Airport, Queensland. The aircraft was operated by Central Highlands Aerial Services and was conducting a spray operation on an 81-hectare paddock (Figure 1, shown in green), about 6 km west‑south‑west of the airstrip.

Figure 1: Application area (green), accident site (blue) and track flown (yellow)

Figure 1: Application area (green), accident site (blue) and track flown (yellow). Source: Google earth, annotated by the ATSB

Source: Google earth, annotated by the ATSB

The pilot conducted a pre-flight inspection of WHR and found everything to be serviceable. He was also the last person to fly the aircraft, three days prior to the accident, and had not identified any problems.

The wind was reported to be 4‑6 kt from the northeast. The spraying operation was standard with no major hazards in or around the paddock ‑ the pilot had sprayed the paddock several times in the past conducting the same spray pattern flying east and west.

At about 0604 Eastern Standard Time,[1] the aircraft arrived at the paddock and the pilot conducted several short spray runs in the south-western corner to ensure there was no overspray onto an adjoining paddock. He then conducted several back-to-back spray runs in the same corner (Figure 1) and at about 0614, he commenced a racetrack pattern over the remainder of the paddock.

At about 0620, a witness located about 1 km from the paddock observed the aircraft complete the ninth racetrack pattern run and commence a turn to the right to line up for the next run. The witness estimated that about three quarters of the way through the turn, while lining up for the next run, the aircraft rapidly pitched down and the right wing collided with the ground. The aircraft subsequently flipped, and came to rest inverted and facing in the opposite direction to the flight path about 20‑30 m from the initial contact point (Figure 2).

Figure 2: Accident site

Figure 2: Accident site. Source: Police

Source: Police

At about 0622, the witness called emergency services and proceeded to the accident site. When the witness arrived at the wreckage, he found the pilot had exited the aircraft through the broken cockpit side window.

Ambulance officers treated the pilot before transporting him to hospital. He was admitted to treat his injuries, which included a fractured left leg, three fractured left ribs, bruises, cuts to his left side, and concussion. The pilot was wearing a helmet at the time of the accident and it was damaged from impact with the aircraft structure (Figure 3). The pilot had no recollection of the accident and no mechanical issue was identified that may have contributed to the accident.

Figure 3: Damage to the left side of the pilot’s flight helmet

Figure 3: Damage to the left side of the pilot’s flight helmet. Source: Police

Source: Police

While the track of the aircraft during the spray operation was recorded, other parameters such as airspeed, time, altitude, and aircraft attitude were not. Figure 4 shows the final four racetrack pattern turns back towards the west. The last inbound turn (shown in blue) was conducted at a smaller turn radius than the previous three turns in that direction. The track data finished about 460 m from the accident site.

Figure 4: Final four right turns from an easterly track (last shown in blue)

Figure 4: Final four right turns from an easterly track (last shown in blue). Source: Google earth, annotated by the ATSB

Source: Google earth, annotated by the ATSB

The pilot joined the operator in January 2015, gaining about 800-flight hours in WHR (with the installed PT6A engine) and flew the previous flight in WHR three days prior to the accident. He did not report any concerns with the aircraft.

The maintenance release for WHR was issued about 40 flight hours prior to the accident and no outstanding maintenance or defects were recorded.

Safety analysis

About three quarters of the way through a turn, as the aircraft was lined up for the next racetrack pattern spray run, the aircraft was observed to rapidly pitch down and collide with the ground. Analysis of the limited available recorded data showed that the final turn was flown at a tighter radius than the previous racetrack pattern turns. In combination, this could indicate that the accident was the result of an aerodynamic stall. However, there was insufficient information to determine if that occurred.

The pilot was unable to remember the final turn and could not provide a reason for the track variation or why the aircraft pitched down. No mechanical defects were noted with the aircraft, on the maintenance release, during the previous flight, or up to the section of the accident flight the pilot could remember. A post‑accident inspection of the aircraft by the operator did not identify any defects. From the limited available information, it was not possible to determine the reason for the accident.

The pilot was wearing his own personal flight helmet at the time of the accident. During the accident, the left side of the helmet struck the internals of the cockpit. Based on the degree of damage to the helmet, it probably prevented the pilot receiving more serious head injuries.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • During a turn, and for reasons that could not be determined, VH-WHR pitched down and collided with the ground.
  • The helmet worn by the pilot probably prevented more serious head injury.

Safety message

The International Civil Aviation Organization circular 85-AN/71 Safety in aerial work Part 1. Agricultural Operations discusses the importance of reducing serious head injuries by wearing a correctly fitting flight helmet. Pilots operating aircraft in agricultural operations are particularly vulnerable to accidents involving major or fatal head injury. The circular also discusses the need to select a helmet which provides effective protection and that is part of the pilot’s personal flying equipment as was the case in this accident.

About this report

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope, fact-gathering investigation was conducted in order to produce a short summary report, and allow for greater industry awareness of potential safety issues and possible safety actions.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 Hours.

Occurrence summary

Investigation number AO-2017-115
Occurrence date 01/12/2017
Location 9 km north-west Emerald Airport
State Queensland
Report release date 05/02/2019
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Serious

Aircraft details

Manufacturer PZL Warszawa-Okecie
Model M-18A Dromader
Registration VH-WHR
Serial number 1Z018-07
Aircraft operator Central Highlands Aerial Services
Sector Piston
Operation type Aerial Work
Departure point Emerald, Queensland
Destination Emerald, Queensland
Damage Substantial

Data entry error and operational non-compliance involving Airbus A320, PK-AZE, Perth Airport, Western Australia, on 24 November 2017

Final report

Report release date: 02/06/2020

Safety summary

What happened

On 24 November 2017, an Airbus A320 aircraft, registered PK-AZE and operated by PT Indonesia AirAsia, departed Perth, Western Australia on a scheduled passenger flight to Denpasar, Indonesia. Shortly after take-off from runway 21, the aircraft turned left, contrary to the cleared standard instrument departure, and at a height of about 223 ft above ground level, which was below the minimum height for turns specified by the operator. Air traffic control (ATC) assigned a series of headings to the flight crew. The aircraft was also turned through one of the headings assigned by ATC. An additional heading was subsequently issued by ATC to return the aircraft back to its planned track. The flight continued to Denpasar without further incident.

What the ATSB found

The ATSB found that during pre-flight preparations, the first officer (FO) as the pilot flying programmed the flight management guidance system (FMGS) using runway 03 based on the assumption that their departure runway would be the same as the runway on which they had previously landed. That programming occurred prior to the FO obtaining the automatic terminal information service (ATIS) information, which stated that runway 21 was in‑use. In addition, the captain did not separately listen to the ATIS as required by the operator’s procedures and likely relied on the briefing conducted by the FO.

Despite the various cues available to the flight crew, including several ATC instructions for using runway 21 and airport signage, and the flight crew reporting feelings of unease about the flight preparations, the incorrect programming of the FMGS was not detected. Shortly after take-off, the aircraft’s flight director indicated a left turn was required. The FO commenced a left turn and engaged the autopilot, which continued the left turn to navigate towards the first programmed waypoint (in-line with the opposite runway direction and behind the aircraft). However, ATC quickly noticed the diversion from their cleared track and corrected the crew’s heading.

Once the crew had detected the error, the captain reprogrammed the correct flight plan in the FMGS, rather than selecting the heading assigned by ATC. This resulted in the aircraft turning through the assigned heading, requiring further instructions by ATC.

It was also established that ATC were unaware of the nature of the problem and were not utilised fully as an additional resource to assist the flight crew.

What's been done as a result

Following the incident, Indonesia AirAsia have included a similar ‘change of departure runway’ scenario in their line operations flight training. Further, they have plans to launch a cross-departmental initiative to increase the awareness and skill sets of pilots, especially in the area of threat and error management.

Safety message

This incident demonstrates that deviating from standard procedures, even slightly, can render them ineffective and result in errors. Data input errors continue to be one of ATSB’s SafetyWatch priorities.

It further highlights the significance of stopping and re-evaluating the situation while on the ground when there is a feeling of uncertainty about the flight, even if it results in undesirable delays. This provides an opportunity to detect errors before they affect operations. Once airborne, workload and time limitations become even more critical due to the rapidly changing situation.

 

The occurrence

Pre-flight preparation

On 24 November 2017, at about 1145 Western Standard Time,[1] an Airbus A320 aircraft, registered PK-AZE and operated by PT Indonesia AirAsia, was being prepared for a flight from Perth Airport, Western Australia to Denpasar (Bali) Airport, Indonesia. The captain was the pilot monitoring (PM) and the first officer (FO) was the pilot flying (PF).[2] The captain conducted the exterior inspection of the aircraft while the FO entered the flight plan into the flight management guidance system (FMGS) as per the required cockpit preparation procedure.

The crew had operated the aircraft into Perth on the previous sector, and the aircraft had arrived 46 minutes after the scheduled arrival time. The previous flight had landed on runway 03. Believing that they would be using the same runway for take-off, as he had done on previous occasions, the FO entered runway 03 into the FMGS.

The FO then listened to the automatic terminal information service (ATIS),[3] which stated the runway‑in‑use for departure was runway 21, and wrote ‘runway 21’ on the paper flight plan. He then calculated and entered the aircraft’s take-off speeds based on runway 03 into the FMGS. The FO reported he would normally listen to the ATIS first, then input data into the FMGS, but to make it easier on this occasion he programmed the FMGS first and then listened to the ATIS.

When the captain returned to the flight deck after conducting the exterior inspection, he asked the FO which runway would be used for take-off. The FO stated that it was runway 03. The captain reported that he did not listen to the ATIS. However, he cross-checked the information entered in the FMGS, which included comparing the flight plan with the anticipated standard instrument departure (SID)[4] chart.

The FO then conducted the take-off briefing. He later recalled stating that the departure would be from runway 03. The captain also recalled that the FO’s take-off briefing stated that they would be departing from runway 03.

At 1201, the flight crew received their airways clearance from air traffic control (ATC) to depart for Denpasar using the AVNEX TWO SID and to climb to 5,000 ft as per the SID. The AVNEX TWO SID was available for both runway 03 and runway 21, with different initial waypoints before converging (refer to section titled Perth departure procedures).

The FO reported he ‘felt that there might be something wrong’ with the FMGS programming and advised the captain, but they both continued with the preparation.

Taxi to runway 21

At 1213, the flight crew received a taxi clearance from ATC and commenced taxiing (Figure 1). The clearance included a series of instructions to taxi to the holding point for runway 21 on taxiway ‘Whiskey’. The flight crew read back this clearance correctly.

Figure 1: Taxi and take-off path (in red) of PK-AZE

Figure 1: Taxi and take-off path (in red) of PK-AZE.
Source: Airservices Australia (modified by the ATSB)

Source: Airservices Australia (modified by the ATSB)

At 1218, the Perth tower controller provided instructions to hold short of runway 21. Shortly after, he cleared the flight crew to line up on runway 21. The flight crew read back both instructions correctly. Prior to reaching the holding point for runway 21, the flight crew received an electronic centralised aircraft monitor (ECAM)[5] message BRAKE SYS 1 FAULT.[6] The captain reported that he actioned the message using the appropriate checklist. After actioning the message, the captain reported feeling there was something wrong, but was unsure of the issue.

At 1220, the controller cleared the aircraft for take-off on runway 21, which the flight crew read back correctly. At that time, the flight crew noticed the runway mode[7] had not activated on the flight mode annunciator.[8] They did not think it was unusual as sometimes the mode did not activate, particularly if the instrument landing system[9] was unavailable.

Take-off from runway 21

After becoming airborne during take-off, both pilots’ navigation displays showed the next waypoint[10] was MIDLA (Figure 2). Both flight crew noticed the flight director[11] on their primary flight display was commanding a left turn. Shortly after, following the flight director, the FO turned the aircraft left and then engaged the autopilot. Recorded flight data showed the aircraft was manually turned at 223 ft above ground level (AGL) (refer to section titled Minimum height of turns).

Figure 2: Flight path of PK-AZE from runway 21

Figure 2: Flight path of PK-AZE from runway 21.
Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB

About 20 seconds later, the tower controller instructed the flight crew to turn right onto a heading of 200°. The captain read back the instruction correctly, selected the assigned heading on the flight control unit and engaged heading mode. The autopilot began to bank the aircraft to the right. As this happened, the controller asked the flight crew to confirm the instruction of heading 200°, which the flight crew read back incorrectly as 300°. The tower controller consulted another controller about the aircraft’s track, the issued instruction, and whether to cancel the aircraft’s assigned SID.

About this time, the captain took over PF duties from the FO. The flight crew were instructed to maintain the assigned heading of 200° and contact the departures controller. After the flight crew contacted the departures controller, they were cleared to climb to flight level (FL)[12] 180 and instructed to turn right onto a heading of 270°, which the flight crew acknowledged and selected. Shortly after, the captain gave the PF duties back to the FO and soon began reprogramming waypoints in the FMGS. The FO recalled being unaware the captain was reprograming the FMGS.

At 1225, the controller instructed the flight crew to maintain heading 290°. At this time, the captain selected waypoint SWANN in the FMGS. Flight data showed that the autopilot lateral mode changed from heading mode to navigation mode at that time, which resulted in the aircraft diverging from the instructed heading. The controller repeated the instruction to turn to heading 290°. The flight crew selected 290° on the flight control unit and re-selected heading mode, and the autopilot turned the aircraft to that heading (Figure 2).

The departures controller asked the flight crew whether they were issued ‘the AVNEX SID’, which the flight crew confirmed. The controller then asked whether operations were normal, which the flight crew also confirmed. The flight continued to Denpasar without further incident.

__________

  1. Western Standard Time: Coordinated Universal Time (UTC) + 8 hours.
  2. Pilot flying (PF) and pilot monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
  3. Automatic terminal information service (ATIS): The provision of current, routine information to arriving and departing aircraft by means of continuous and repetitive broadcasts during the hours when the unit responsible for the service is in operation.
  4. Standard instrument departure: A designated instrument flight rules departure route linking the aerodrome or a specified runway of the aerodrome with a specified point, normally on a designated air traffic services route, at which the en route phase of a flight commences.
  5. The electronic centralised aircraft monitor (ECAM) monitors aircraft systems, displays aircraft system information, and specifies flight crew actions to be taken in the event of abnormal or emergency situations.
  6. BRAKE SYS 1 FAULT: an alert indicating a fault detected in one channel of the brake system control unit.
  7. Runway mode: provides lateral guidance orders during take-off roll and initial climb out (up to 30 ft radio altitude) if a localiser signal is available.
  8. Flight management annunciator: a display located at the top of each pilot’s primary flight display and informs the crew of the active and armed auto flight and auto-thrust modes.
  9. Instrument landing system: standard ground aid to landing comprising two radio guidance beams and two markers for linear guidance. The system was operational on the day of the incident.
  10. Waypoint: predetermined and accurately known geographical position forming start or end of a route segment.
  11. Flight director: a guidance aid that is overlaid on the attitude indicator and shows the attitude required to follow a certain trajectory. It computes and displays the pitch and bank angles required in order for the aircraft to follow a selected path.
  12. Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 180 equates to 18,000 ft.

Context

Personnel information

Captain

The captain held an Air Transport Pilot (Aeroplane) Licence, multi-engine command instrument rating, and a valid Class 1 Aviation Medical Certificate. He had a total of 13,487 hours of aeronautical experience, of which 3,974 hours were on the Airbus A320. The captain had been assessed as meeting the requirement of the International Civil Aviation Organization English proficiency at a level 5 standard.[13]

The captain’s last instrument rating line check was on 18 November 2017 and the last line check was completed on 29 August 2017. Although the line check was passed with an overall marginal score of two out of five, the results indicated mostly satisfactory (required standard) scores of three. Deficiencies noted in the check were in knowledge and application of standard operating procedures and operations manual, and threat and error management as both PF and PM. Previous simulator training and check sessions identified similar issues.

First officer

The first officer (FO) held a Commercial Pilot (Aeroplane) Licence, a multi-engine instrument rating, and a valid Class 1 Aviation Medical Certificate. He had a total of 955 hours of aeronautical experience, of which 766 hours were on the Airbus A320. The FO had been assessed as meeting the requirement of the International Civil Aviation Organization English proficiency at a level 4 standard.

The FO’s last instrument rating line check was on 15 August 2017 and the last line check was completed on 30 June 2017. The line check was passed with all items scored as three out of five, which indicated a satisfactory result and the required standard was met. Previous simulator training and check sessions included comments about reading and understanding paper checklist procedures.

Fatigue considerations

A review of the flight crew’s rosters and sleep obtained found there was a low likelihood they were experiencing a level of fatigue known to have a demonstrated effect on performance.

Meteorological information

The Perth automatic terminal information service (ATIS) details relevant at the time of the aircraft’s departure indicated that the wind direction and strength was variable,[14] with a maximum tailwind of 3 kt on runway 21. The temperature was 32 °C, with CAVOK[15] conditions.

Perth Airport information

Perth Airport, with an elevation of 67 ft, is located about 10 km to the east of the city. A further 10 km to the east is the ‘Darling Scarp’ (Darling Range), an escarpment extending 345 km north-south from about Bindoon to Pemberton.

Perth Airport has two runways, 03/21 and 06/24. The movement areas, including the taxiways and runways, were marked with guidance signs, designed to assist pilots and other users with navigating the airport. These included signs that identified the holding point position with the runway designation.

Perth departure procedures

A standard instrument departure (SID) is a designated instrument flight rules departure route linking either an aerodrome or a specified runway with a specified point, normally on a designated air traffic services route, at which the en route phase of a flight commences.

At Perth, the ‘AVNEX TWO’ SID was used for both runways and in all directions (Figure 3). When departing from runway 03 using this departure, after take-off the crew were to maintain a heading of 016° (magnetic) for 4 NM (about 7 km) and conduct a left turn at waypoint MIDLA. For runway 21, the crew were to maintain a heading of 196° for 4 NM (about 7 km) and turn right at waypoint NAVEY at or above 2,500 ft above mean sea level.

Figure 3: AVNEX TWO AirAsia SID chart

Figure 3: AVNEX TWO AirAsia SID chart.
Source: Aerostratus, modified by the ATSB

Source: Aerostratus, modified by the ATSB

Operational information

Procedures and checklists

Cockpit checklists are an essential tool for overcoming limitations of pilot memory, and ensuring that action items are completed in sequence and without omission. According to Degani & Wiener (1993):

The major function of the flight deck checklist is to ensure that the crew will properly configure the airplane for any given segment of flight. It forms the basis of procedural standardization in the cockpit.

From the pre-flight preparations to the take-off, the crew completed a number of procedures and checklists where there were multiple opportunities to detect a data entry error. The relevant extracts from these checklists and procedures from the Indonesia AirAsia Flight Crew Operating Manual are below. The captain and FO were assigned specific tasks applicable to all flights.

Preliminary cockpit preparation procedure

The Preliminary Cockpit Preparation procedure specified that both flight crew were to separately obtain and calculate the aircraft’s take-off performance data. In this case, the pilot monitoring (PM) was required to cross‑check the pilot flying’s (PF’s) calculations. Specifically, the procedure stated that:

Each flight crewmember independently computes the preliminary performance data in accordance with the technical condition of the aircraft/or other criteria that may impact the aircraft performance (e.g. NOTAM [notice to airmen], runway condition, aircraft configuration).

AIRFIELD DATA.................................................................................................... OBTAIN

Obtain data needed for initializing the system, preparing the cockpit and for preliminary take-off performance computation. The airfield data should include: RUNWAY IN USE, ALTIMETER SETTING, and WEATHER DATA.

PRELIMINARY TAKEOFF PERFORMANCE……………COMPUTE AND CROSSCHECK

Cockpit preparation procedure

As detailed below in the Cockpit Preparation procedure, the PM was required to check the flight plan (‘F-PLN’) entered by the PF into the flight management guidance system (FMGS) with the relevant navigation chart and ‘paper’ flight plan. The PM was also required to check the data, including the airfield information entered into the FMGS by the PF. The take-off briefing was then conducted by the PF. During that briefing, both flight crew were required to cross-check the parameters referred to by the PF to ensure that they had been set or programmed correctly.

F-PLN A page..............................................................................COMPLETE AND CHECK

The flight crew must check, modify, or insert (as applicable) the F-PLN in the following order, according to the data given by ATIS, ATC, or MET.

F-PLN.........................................................................................................................CHECK

Check the F-PLN using F-PLN page and ND PLAN mode versus the computer (paper) flight plan or navigation chart.

FMS PREPARATION…………………………………………………………………….CHECK

After the PF prepared the FMS [FMGS], the PM checks:

The airfield data

All FMS entered data

The takeoff performance data with the data computed on his EFB [electronic flight bag]

TAKEOFF BRIEFING……………………………………………………......………PERFORM

Before pushback or start procedure

In the Before Pushback or Start procedure, the flight crew were required to confirm the final take‑off data as follows:

FINAL TAKEOFF DATA........................................................... CONFIRM or RECOMPUTE

If take-off conditions did not change, verify and confirm that the preliminary take-off data are still valid.

FMS F-PLN page......................................................................................................SELECT

It is recommended to display the F-PLN page on the PM side.

Taxi procedure

For the Taxi procedure, the PM was to obtain the taxi clearance for the assigned runway, and both flight crew confirm any changes to the take-off briefing.

TAXI clearance......................................................................................................... OBTAIN

ATC clearance...................................................................................................... CONFIRM

TAKEOFF BRIEFING............................................................................................CONFIRM

Before take-off procedure

The Before Take-Off procedure required the PM to obtain the take-off clearance from ATC and both flight crew confirm to the runway for departure using the available cues, such as those listed below.

TAKEOFF OR LINE UP CLEARANCE………………………………………………..OBTAIN

TAKEOFF RUNWAY…………………………………………………………….……CONFIRM

Confirm the line up is performed on the intended runway. Useful aids are:

The runway markings

The runway lights

Take-off procedure

In the Take-off procedure below, the PM was to monitor the navigation display (ND) and confirm the aircraft was lined-up on the runway centreline.

PFD/ND…………………………………………………………………….....………MONITOR

If an ILS [instrument landing system] that corresponds to the departure runway is tuned, RWY mode appears. If not, no lateral mode appears until the aircraft lifts off.

Check the FMS position on the ND (aircraft on runway centerline).

Minimum height of turns

Although flight crews were to follow the designated SID procedure after take-off, the Indonesia AirAsia Flight Crew Operating Manual specifically stated:

Procedures to be followed after take-off, during the approach and go around are as per SID (including Radar departure) and STAR. No turns shall be commenced below 400ft AGL [original emphasis].

Operational philosophy

Flight crew guidance

The Indonesia AirAsia Flight Crew Training Manual and standard operating procedures provided guidance to flight crew for both normal and abnormal situations. There was no specific procedure listed on managing data entry errors detected in-flight, but general Airbus principles were included in the manuals.

Golden rules for pilots

The Flight Crew Training Manual states the pilots’ responsibility is to ‘fly, navigate, communicate’ in that order, along with additional considerations. The flight crew must perform these three actions in sequence and must use appropriate task sharing in normal and abnormal operations, in manual flight or in flight with the autopilot engaged.

‘Fly’ indicates that the PF must concentrate on ‘flying the aircraft’ in order to achieve and maintain flight parameters such as pitch attitude, bank angle, airspeed, and heading. The PM must assist the PF and must actively monitor flight parameters, and call out any excessive deviation using standard phraseology. The PM's role of ‘actively monitoring’ is very important. Therefore, both flight crew must focus and concentrate on their tasks to ensure appropriate task sharing and maintain awareness of the situation and immediately resolve any uncertainty as a crew.

‘Navigate’ refers to and includes the following ‘know where ...’ statements, in order to ensure awareness of the situation, including know where you are, know where you should be, and know where you should go.

‘Communicate’ involves effective and appropriate crew communication between the PF and the PM, and between flight crew and ATC. In abnormal and emergency situations, the PF must recover a steady flight path, and the flight crew must identify the flight’s status. The PF must then inform ATC and the cabin crew of the flight’s status and the flight crew’s intentions.

Communication also applies to communicating adjustments or changes to the information and/or equipment on the flight deck, such as FMGS alterations or flight path modifications. The other flight crew must be informed and an acknowledgement obtained.

The Flight Crew Training Manual also stated to take action if things do not go as expected. If the aircraft does not follow the desired vertical or lateral flight path, or the selected targets, and if the flight crew does not have sufficient time to analyse and solve the situation, the flight crew must immediately take appropriate or required actions, as follows:

the PF should change the level of automation from managed guidance[16] to selected guidance,[17] or from selected guidance to manual flying.

the PM should perform the following actions in sequence: communicate with the PF; challenge the actions of the PF, when necessary; and take over, when necessary.

Similar occurrences

A search of the ATSB’s database found similar occurrences involving incorrect data entry into the aircraft’s systems and navigation errors:

ATSB investigation AO-2015-029

On 10 March 2015, an Airbus A330 aircraft operated by AirAsia X was conducting a regular passenger service from Sydney, New South Wales. On departure from runway 16R (right) the aircraft was observed by ATC to enter the departure flight path of the parallel runway, 16L (left). Following advice from ATC, the flight crew identified a problem with the on-board navigation systems. Attempts to troubleshoot and rectify the problem resulted in further degradation of the navigation system, as well as to the aircraft’s flight guidance and flight control systems. The crew elected to discontinue the flight but were unable to return to Sydney as the weather had deteriorated in the area and the available systems limited the flight to approaches in visual conditions. The aircraft was instead radar vectored to Melbourne, Victoria and the flight completed in visual conditions.

The ATSB found that when setting up the aircraft’s FMGS, the captain inadvertently entered the wrong longitudinal position of the aircraft. This adversely affected the onboard navigation systems. However, despite a number of opportunities to identify and correct the error, it was not noticed until after the aircraft became airborne and started tracking in the wrong direction. The flight crew attempted to troubleshoot and rectify the situation while under a heavy workload. Combined with limited guidance from the available checklists, this resulted in further errors by the flight crew in the diagnosis and actioning of flight deck switches. Finally, the ATSB identified that effective monitoring and assistance by ATC reduced the risk to the occurrence aircraft and other aircraft in the area.

ATSB occurrence 201806598

On 26 September 2018, a foreign-operated Boeing 737-800 was conducting a regular passenger service from Melbourne, Victoria. During initial climb, the aircraft did not adhere to the assigned runway 34 KEPPA 1 SID and conducted an early left turn. ATC queried the crew about which waypoint they were tracking to. The crew responded they were tracking to ATNOL, which was the first waypoint on the KEPPA SID 1 from runway 27. It was subsequently determined the crew had entered the incorrect departure runway of runway 27 into the flight management computer.

__________

  1. The International Civil Aviation Organization has defined six levels of language proficiency, the top three levels (4, 5 and 6) are acceptable for operational flight crew. Level 4 (operational) requires retesting every 3 years, level 5 (extended) requires retesting every 6 years and level 6 (expert) does not require further testing.
  2. The term ‘variable’ is used when the reporting of a mean wind direction is not possible such as, in light wind conditions (3 kt or less) or if the wind is veering or backing by 180° or more.
  3. Ceiling and visibility okay (CAVOK): visibility, cloud and present weather are better than prescribed conditions. For an aerodrome weather report, those conditions are visibility 10 km or more, no significant cloud below 5,000 ft, no cumulonimbus cloud and no other significant weather.
  4. Managed mode: To fly along the pre-planned flight plan, entered in the flight management guidance system.
  5. Selected mode: For specific ATC requests, or when there is not sufficient time to modify the flight plan.

Safety analysis

Introduction

Very shortly after take-off from runway 21 at Perth, Western Australia, the aircraft was turned at a low height in the opposite direction to their clearance and towards an escarpment. Air traffic control (ATC) assigned a series of headings to the flight crew to correct their path. During that time, the aircraft also turned through one of the assigned headings. An additional heading was issued by ATC to return the aircraft back to its planned track. The flight continued without further incident.

Although there were time delays for the flight crew’s sectors that day, there was insufficient evidence to indicate that this contributed to the development of the incident.

This analysis will examine why the incorrect runway was programmed into the flight management guidance system (FMGS) and why this error was not detected by the flight crew. It will also discuss the flight crew’s pre-flight preparations with regard to obtaining the automatic terminal information service (ATIS) and explore their actions in response to the early turn.

Incorrect runway-in-use

Based on their recent landing on runway 03, the first officer (FO), who was the pilot flying had the expectation that the take-off runway would remain the same, as experienced on previous occasions. Consequently, he entered runway 03 into the FMGS in preparation for the departure. This was done prior to listening to the ATIS and obtaining the airfield data, which indicated that runway 21 was in-use. This was performed out-of-sequence, where the operator’s procedure required the airfield data to be obtained before programming the FMGS. While the FO commented in his interview that he would normally follow the procedure, on this occasion, he elected to program the FMGS first to make it ‘easier’.

Although the FO correctly noted the ATIS details for runway 21 on his paper flight plan, he did not detect that it was different to what he had programmed. In this case, the FO may not have detected the runway he used for programming was different due to not having an expectation it would have been incorrect. Expectations can influence perception, as people often hear what they expect to hear and see what they expect to see (Hawkins 1987). Research has also found that the pilots checking their own work are less likely to detect their own error than cross-checking by other crew members (Thomas, Petrilli, and Dawson 2004).

Independently cross-checking the runway-in-use

The captain did not separately obtain the ATIS as required by the operator’s procedures and likely relied upon the FO’s briefing that runway 03 was the runway-in-use. Further, he subsequently either did not check or detect that runway 21 was written on the flight planning documents nor that it was inconsistent with the information programmed into the FMGS.

Cross-checking is a fundamental element in all multi-crew operations and is a vital mechanism for detecting errors. An exploratory study of error detection processes during normal line operations conducted by Thomas and others (2004) identified that cross-checking and monitoring of other crew actions was the most frequently observed error detection process. By not obtaining the ATIS independently and cross-checking the runway-in-use, this removed an opportunity for the captain to identify the programming error prior to take-off.

Non-detection of error

Research conducted during normal line operations has found over half of errors made by flight crew remain undetected (Thomas, Petrilli, and Dawson 2004). In this case, the error in the pre‑flight programming remained undetected until after take-off. However, aside from cross‑checking procedures, there were multiple opportunities available to the flight crew that would have provided them with the opportunity to identify the incorrectly entered runway. These were:

  • Prior to, and during taxiing, the flight crew received taxi instructions and several clearances from ATC referencing runway 21, which were all read back correctly.
  • The flight crew reported that, during take-off, they both noticed that the runway mode had not activated. However, they explained that the mode might also not activate if the instrument landing system was not available, rather than considering this as a programming error.
  • While taxiing to the runway, there were guidance signs identifying the runway designation.

Of note, the flight crew received an electronic centralised aircraft monitor (ECAM) message around the same time ATC issued a hold‑short instruction for runway 21. This message directed the flight crew’s attention to responding to the ECAM message at a time potential cues to the error were available, such as the instruction and airport signage. Further, although the flight crew reported at two separate times, they felt there was something wrong with the preparation, they decided to continue with the flight. Even when cues to an error are provided there is a likelihood they can be dismissed or explained away if the information is not consistent with a person’s expectations (Hawkins 1987).

Turn contrary to clearance and published procedure

The FMGS was programmed for the runway 03 AVNEX TWO departure, which required a left turn after take-off at waypoint MIDLA. Therefore, after take-off from runway 21, the flight director indicated a left turn was required to capture the flight path to waypoint MIDLA to the north. The recorded flight data showed that the aircraft was turned left when at 223 ft above ground level. This was contrary to the runway 21 departure, which required a right turn at waypoint NAVEY to the south not below 2,500 ft. This was also below the operator’s stipulated minimum turn height of 400 ft.

The left turn continued momentarily after the autopilot was engaged but was quickly corrected when ATC assigned a heading instruction for the flight crew to regain the cleared flight path. During the left turn, the flight crew had not realised the autopilot was flying a different path to what was actually cleared. A left turn was consistent with the crew’s expectations based on their pre-flight briefing for runway 03, although the low height of the directed turn should have been unusual and not consistent with the briefing. Following the flight director at this stage suggests the crew were relying on automation at the expense of their own monitoring, possibly due to an over-reliance on automation (Parasuraman and Riley 1997).

Managing an unexpected situation after take-off

The flight crew were in an abnormal situation when they identified the programming error in the FMGS. Air traffic control provided the flight crew with a number of heading instructions to regain the cleared flight path and also asked if operations were normal, which they confirmed was the case. As highlighted by Tullo (2010), ATC can potentially assist with problem-resolution in abnormal situations. In this case, ATC were unaware of the nature of the problem and the flight crew did not utilise them fully as an additional resource. By making ATC aware of the abnormal situation, it could have potentially reduced the flight crew’s workload in deciding subsequent action to evaluate and solve the problem. This may have reduced the need for the flight crew to reprogram the FMGS at a time when their workload would have already been high, as they were required to complete other checklists.

Although the flight crew correctly identified the problem, the captain’s chosen solution of reprogramming the FMGS increased workload during an already high workload situation. Such circumstances reduces the ability to monitor the flight path (Dismukes and others 1998).

With reference to the operator’s ‘fly’ then ‘navigate’ golden rule for pilots, the role of the captain as pilot monitoring was to focus on the flight parameters including heading and communicate any deviations to the pilot flying. In this case, while ATC had provided the necessary navigation information (heading), the captain attempted to achieve this objective by manipulating the aircraft’s FMGS rather than selecting or flying to the given heading, at the expense of monitoring the flight parameters. During that time, the aircraft also turned through one of the assigned headings and an additional heading instruction was needed to be issued by ATC to return the aircraft back to its planned track.

Findings

From the evidence available, the following findings are made with respect to the data entry error related operational non-compliance of an Airbus A320, registered PK-AZE that occurred at Perth Airport, Western Australia, on 24 November 2017. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • Based on a recent landing, the first officer assumed runway 03 would be in use and programmed this runway for take-off into the flight management guidance system (FMGS) before listening to the automatic terminal information service (ATIS). Although the first officer copied runway 21 from the data recorded onto the flight plan, he did not notice this differed from what he had programmed into the FMGS and briefed the captain for a runway 03 take-off.
  • The captain did not obtain any independent information about the runway‑in‑use for pre‑departure checks, including listening to the ATIS and reviewing data recorded on the flight plan, and likely relied on verbal information from the first officer.
  • The incorrect programming of the FMGS was not detected before take-off despite numerous cues that the departure runway and flight path was different to what was briefed. Although the flight crew sensed there was something amiss with their pre-flight preparation, they continued without further checking.
  • Shortly after take-off from runway 21, the aircraft was turned left at 223 ft above ground level. This was below the minimum allowable height of 400 ft stipulated by the operator, and well before and in the opposite direction to the cleared standard instrument departure.

Other factors that increased risk

  • The flight crew did not communicate the nature of the problem to air traffic control and so did not effectively utilise air traffic control as an available resource. This resulted in the captain unnecessarily reprogramming the FMGS at a time when workload was already high.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action taken by Indonesia AirAsia in response to this occurrence.

Line operations flight training, and threat and error management

Following the incident, Indonesia AirAsia have included a similar change of departure runway scenario in their line operations flight training. Further, they have plans to launch a cross-departmental initiative to increase the awareness and skill sets of pilots, especially in the area of threat and error management.

General details

Captain

Licence details:Air Transport Pilot’s Licence (Aeroplane), issued July 2008
Endorsements:A320 systems
Ratings:

Class ratings: single-engine land, multi-engine land

Type ratings: B737-3/4/5, A320

Instrument rating: multi-engine land

Medical certificate:Class 1, valid to March 2019
Aeronautical experience:13,487 hours
Last flight review:August 2017

First officer

Licence details:Commercial Pilot’s Licence (Aeroplane), issued 2014
Endorsements:A320 systems
Ratings:

Class ratings: single-engine land, multi-engine land

Type ratings: A320

Instrument rating: multi-engine land

Medical certificate:Class 1, valid to June 2019
Aeronautical experience:955 hours
Last flight review:June 2017

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • flight crew
  • Indonesia AirAsia
  • Airservices Australia.

References

Degani, A and Wiener EL 1993, Cockpit checklists: Concepts, design, and use, Human Factors, 35(2), 28-43.

Dismukes RK, Young GE, Sumwalt III RL, and Null CH 1998, Cockpit interruptions and distractions: Effective management requires a careful balancing act. ASRS Directline, issue 10, pp. 4-9.

Hawkins, FH 1987, Human factors in flight. Aldershot: Ashgate.

Orasanu, J 2010, Ch. 5. Flight crew decision-making. In Kani, B, Helmreich, R, Anca, J. Crew resource management (2nd ed). San Diego: Academic Press.

Parasuraman, R and Riley, V 1997, Humans and automation: Use, misuse, disuse, abuse. Human factors, 39(2), 230-253.Thomas, MJW, Petrilli, RM, and Dawson, D 2004, An exploratory study of error detection processes during normal line operations. Proceedings of the 26th Conference of the European Association for Aviation Psychology.

Thomas MJ, Petrilli RM, and Dawson D 2004, An exploratory study of error detection processes during normal line operations (Doctoral dissertation, European Association for aviation psychology).

Tullo FJ 2010, Teamwork and Organizational Factors. In Kani, B, Helmreich, R, Anca, J. Crew resource management (2nd ed). San Diego: Academic Press.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the flight crew, Indonesia AirAsia, Airservices Australia, and the Civil Aviation Safety Authority.

Submissions were received from Indonesia AirAsia, Airservices Australia, and the Civil Aviation Safety Authority. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Preliminary report

Report release date: 29/06/2018

This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

Sequence of events

On 24 November 2017, at about 1200 Western Standard Time,[1] the crew of an Airbus A320 aircraft, registered PK-AZE and operated by AirAsia Indonesia, was being prepared to depart on a scheduled passenger service from Perth Airport, Western Australia for Denpasar (Bali) Airport, Indonesia. The captain was designated as the pilot monitoring and the first officer (FO) was designated as the pilot flying.[2]

While the captain was conducting the pre-flight walk around, the FO entered the flight plan into the flight management guidance computer (FMGC). Believing that they would be using runway 03 for take-off, as they had recently landed on this runway, he entered this into the FMGC. He then listened to the automatic terminal information service,[3] which indicated the runway-in-use was runway 21. When the captain returned to the fight deck, the FO completed the pre-flight and departures briefing using runway 03. At 1201, the crew received their clearance from air traffic control (ATC) to depart for Denpasar using the AVNEX TWO standard instrument departure (SID)[4] and to climb to 5,000 ft using the SID (Figure 1). At 1213, the crew commenced taxiing. The crew also received ATC clearances to taxi to, and line-up on runway 21, which was read back correctly by the crew.

Figure 1: AVNEX TWO standard instrument departure

Figure 1: AVNEX TWO standard instrument departure. Source: Naviga, modified by the ATSB

Source: Naviga, modified by the ATSB

At 1220, the aircraft took off from runway 21. Shortly after take-off, the aircraft was turned left at 260 ft above mean sea level (AMSL) (Figure 2), which was contrary to the SID procedure and below the minimum safe altitude stipulated by the operator. The runway 21 SID required a right turn at or above 2,500 ft at waypoint[5] NAVEY (Figure 1) and the operator stipulated that turns should not be commenced below 400 ft above ground level.

After observing the aircraft turning left on radar, ATC re-cleared the crew onto an assigned radar heading. ATC later confirmed with the crew they were issued with the AVNEX TWO SID and asked if operations were normal. The crew reported operations normal and the aircraft was turned to intercept the flight planned route and continued to Denpasar without further incident.

Figure 2: Flight path of PK-AZE (in white) showing the left turn (waypoints highlighted in blue)

Figure 2: Flight path of PK-AZE (in white) showing the left turn (waypoints highlighted in blue). Source: Google earth and Air Asia Indonesia, modified by the ATSB

Source: Google earth and Air Asia Indonesia, modified by the ATSB

Recorded data

The aircraft’s flight data recorder was downloaded, and a copy was provided to the ATSB. A review of that recording found:

  • the waypoint MIDLA was the first selected waypoint in the flight management guidance computer, which was the first waypoint on the AVNEX TWO SID for runway 03 (Figure 1)
  • when manually flown, the aircraft was turned left at 260 ft AMSL
  • after multiple heading changes were made by the crew, waypoint SWANN was selected at 8,104 ft, which was the second waypoint on the runway 21 AVNEX TWO SID.

Ongoing investigation

The investigation is continuing and will consider the following:

  • operator pre-flight procedures and checklists
  • crew training and qualifications
  • aircraft systems.

______________
The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this preliminary report. As such, no analysis or findings are included in this update.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Western Standard Time is Coordinated Universal Time (UTC) + 8 hours.
  2. Pilot flying (PF) and pilot monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
  3. Automatic terminal information service (ATIS): The provision of current, routine information to arriving and departing aircraft by means of continuous and repetitive broadcasts during the hours when the unit responsible for the service is in operation.
  4. Standard instrument departure: A designated instrument flight rules departure route linking the aerodrome or a specified runway of the aerodrome with a specified point, normally on a designated air traffic services route, at which the en route phase of a flight commences.
  5. Waypoint: A specified geographical location used to define an area navigation route or the flight path of an aircraft employing area navigation.

Occurrence summary

Investigation number AO-2017-114
Occurrence date 24/11/2017
Location Perth Airport
State Western Australia
Report release date 02/06/2020
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Aircraft preparation
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer Airbus
Model A320
Registration PK-AZE
Serial number 5098
Aircraft operator PT Indonesia AirAsia
Sector Jet
Operation type Air Transport High Capacity
Departure point Perth, Western Australia
Destination Denpasar Airport, Indonesia
Damage Nil