Section 21 (2) of the Transport Safety Investigation Act 2003 (TSI Act) empowers the ATSB to discontinue an investigation into a transport safety matter at any time. Section 21 (3) of the TSI Act requires the ATSB to publish a statement setting out the reasons for discontinuing an investigation. The statement is published as a report in accordance with section 25 of the TSI Act, capturing information from the investigation up to the time of discontinuance.
Overview of the investigation
At 0347 (Australian Eastern Daylight time – AEDT) on Tuesday 19 November 2019, at Picton NSW, the driver of a Qube freight train 3112 was checking on a report of a wheel defect on the fifth axle of the third locomotive in the train consist.
The possible defect was previously detected by the trackside inspection system at Exeter and the driver stopped 3112 at Burradoo to safely inspect the train. No defect was found.
The driver subsequently stopped the train on the mainline at Picton and disembarked in order to conduct a second inspection of the train. A Pacific National freight train passing on the adjacent line came within two metres of the driver of 3112.
ATSB’s preliminary evidence collection revealed:
The detection of the potential wheel defect was made by the appropriate wayside detection equipment and was notified correctly to the train crew.
The driver initially followed process and safely inspected the locomotive at Burradoo with no defect being found and continued the journey.
The driver took advantage of a routine stop at Picton to re-inspect the locomotive on the safe side of the train (i.e. the side of the train away from the opposing main line) and found a minor wheel defect.
The driver then made a decision to inspect the locomotive wheels from the other side of the train, next to the opposing main line, without seeking track protection, when the Pacific National freight train approached his location, leading to the near miss.
The driver acknowledged the decision was an individual action.
The driver of the Qube train was standing next to the train and took evasive action by holding onto the handrails of the locomotive ladder to avoid being struck by the Pacific National train.
ATSB comment
Given the acknowledged individual action taken by the driver of the Qube train 3112, and based on a review of the available evidence, the ATSB considered it was unlikely that further investigation would identify any systemic safety issues. Consequently, the ATSB has discontinued this investigation.
Section 21 (2) of the Transport Safety Investigation Act 2003 (TSI Act) empowers the ATSB to discontinue an investigation into a transport safety matter at any time. Section 21 (3) of the TSI Act requires the ATSB to publish a statement setting out the reasons for discontinuing an investigation. The statement is published as a report in accordance with section 25 of the TSI Act, capturing information from the investigation up to the time of discontinuance.
Overview of the investigation
On 2 December 2019, the ATSB commenced an investigation into a runway overrun involving a Gippsland Aeronautics GA-8, VH-MTX, at Rurruwuy, Northern Territory.
The aircraft departed Garrthalala for Rurruwuy at 1240 Central Standard Time[1] on a chartered passenger flight, with the pilot and three passengers on board. The pilot described the conditions at Rurruwuy as a ‘turbulent, thermally day’ and she elected to land on Runway 11 based on the windsock direction.
On final approach, the pilot noticed the airspeed was 2 knots above the planned reference landing approach speed. The pilot then assessed she was too high for her aiming point, which was the first tyre marker, and chose to aim for the second. The aircraft touched down beyond the second tyre marker, but then lifted off the runway. When the aircraft touched down again, it was beyond the halfway point of the runway.
The pilot attempted to stop the aircraft, but it overran the end of the runway resulting in substantial damage. There were no injuries to the pilot or passengers. Once the aircraft had stopped, the pilot noted that the windsock had shifted during the approach, favouring a landing on Runway 29.
Due to its relatively short length, Rurruwuy was classified by the operator as a ‘Marginal Airstrip’ for a GA-8, which meant specific pilot training was required. The pilot had completed this training prior to the occurrence.
As a result of the occurrence, the operator organised a pilot training day to discuss stabilised approaches.
As part of its investigation, the ATSB interviewed the pilot, and obtained information such as flight plans, photographs, maintenance information and details of the operator’s training procedures.
ATSB comment
Unexpected events during the approach and landing can exacerbate what is often a high workload period. Following standard operating procedures and correctly monitoring the aircraft and approach parameters provides assurance that an approach can be safely completed. If the criteria for safe continuation of an approach are not met, a go-around should be initiated.
Based on a review of the available evidence, the ATSB considered it was unlikely that further investigation would identify any systemic safety issues. Consequently, the ATSB has discontinued this investigation.
The evidence collected during this investigation remains available to be used in future investigations or safety studies. The ATSB will also monitor for any similar occurrences that may indicate a need to undertake a further safety investigation.
____________ [1] Central Standard Time: Coordinated Universal Time (UTC) + 9.5 hours
On 25 November 2019, a Cessna 210M, registered VH-SJW and operated by Mistar Holdings, was conducting a charter flight with four passengers from Darwin to Tindal, Northern Territory. Soon after departure, the pilot diverted 5 NM right of the planned track to avoid a large storm cell that was 5 NM left of track. About 10 minutes after departure, while maintaining 3,500 ft, the aircraft encountered sudden and sustained severe turbulence. Control of the aircraft was lost for over 3 minutes, and three passengers sustained minor injuries.
After landing at Tindal and inspecting the aircraft for potential damage, the pilot ferried the aircraft to Millingimbi. At Millingimbi, the pilot picked up four more passengers for a charter to Galiwin’ku (Elcho Island). The pilot reported the incident to the operator that evening. Upon receiving notification of the turbulence encounter, the operator grounded VH-SJW at Galiwin’ku, pending an engineering inspection.
What the ATSB found
At 10 NM from the thunderstorm, the pilot did not have sufficient separation to ensure safe passage.
Following the incident, the inspection carried out by the pilot was not sufficient to ensure the airworthiness of the aircraft beyond doubt. Flying another charter flight without an aircraft inspection by a qualified person exposed the operator, the pilot, and the passengers to elevated risk. In addition, the operator did not have guidance to direct pilots to seek advice or peer support following abnormal events.
What has been done as a result
The operator has developed case studies for pilots, emphasising weather avoidance and management of abnormal events. These have been integrated into proficiency checks to ensure solid understanding of theory, and practical application of weather avoidance, escape and post encounter management.
Safety message
The primary protection against thunderstorm related turbulence is avoidance. In this case, 10 NM was not far enough. Operators, pilots and passengers can work together to avoid flying in adverse weather. For instance, by starting a day’s flying early it can be completed before weather becomes a problem in the afternoon.
A pilot with the best intentions may make a suboptimal decision after experiencing an abnormal event. Operators can provide guidance to assist pilots to make good decisions in these situations, by providing peer support and emphasising the importance of reporting abnormal events in a timely manner. Early reporting reduces pressure in operations, allowing ample time to make alternative arrangements.
To support continuous improvement in performance, pilots should regularly review operational documents and industry advice, to build on experience, and develop a comprehensive knowledge of issues and strategies available.
The investigation
Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.
The occurrence
Planned flights
On 25 November 2019, at 1119 Central Standard Time,[1] a Cessna 210M, registered VH-SJW and operated by Mistar Holdings, departed Galiwin’ku (Elcho Island), Northern Territory, for a passenger charter flight with the pilot and three passengers on board. The flight had a planned stopover in Darwin, to collect another passenger, before continuing on to Tindal. From Tindal, the pilot planned to fly to Millingimbi empty, collect passengers, and return to Galiwin’ku (Figure 1). The flights were being conducted under visual flight rules (VFR).
The pilot briefed the passengers that seatbelts were to be worn at all times, and that they should be tight. The pilot visually checked the passenger’s seat belts before departure.
Figure 1: Charter flight route for VH-SJW
Source: Google Earth, annotated by the ATSB
Turbulence encounter
As per the forecast, on approach into Darwin Airport, the pilot noticed a large thunderstorm to the south of the city crossing the intended departure track. After landing at Darwin, the passengers disembarked and had about a 30-minute break before boarding the aircraft again.
The pilot accepted a departure delay from air traffic control (ATC) of 28 minutes. The air traffic controller recalled that multiple aircraft were requesting diversions due to storm activity. During this time, the pilot reviewed graphical area forecasts issued by Airservices Australia, and used Bureau of Meteorology weather radar to track the progress of the storm cell.
The aircraft departed Darwin at 1418 and the pilot was cleared to depart via VFR route 4. The pilot had identified that the storm cell was about 5 NM left of the planned track, so requested a diversion of 5 NM right of track to provide a 10 NM separation from the weather. ATC approved the pilot’s request. One of the passengers photographed the weather after they diverted (Figure 2).
Figure 2: Photograph taken by right centre row passenger
Source: Supplied by passenger aboard VH-SJW
About 10 minutes after take-off, the pilot reported maintaining an altitude of 3,500 ft. At about this time, and shortly after the photograph was taken, the aircraft was subjected to sudden severe turbulence.[2] The mobile phone used to take the photograph fell under the pilot’s rudder pedals with the first significant drop in altitude. The pilot’s checklist and an iPad were also loose in the cabin.
The pilot was wearing a four-point harness and the passengers, seated in the centre and rear rows, all wore lap belts. There was no facility for the pilot and passengers to communicate over an intercom. Due to the high noise environment in the aircraft cabin, the pilot could only communicate with passengers using hand signals. As a result, the passengers were not warned of potential turbulence, or instructed to check their seatbelts were tight, and stow loose items.
The pilot reported tightening their own harness and initially aimed to climb to 4,500 ft, hoping to climb over the turbulence. This strategy changed in order to retain visual meteorological conditions.
Turbulence penetration speed[3] for the Cessna 210M was 119 kt. The pilot stated that, during the incident, airspeed could not be controlled through changing power settings, and for the most part the airspeed could not be held below 155 kt. For extended periods, the pilot had no control over bank angle, height, or heading. At one stage, the airspeed dropped below 140 kt, and the pilot lowered the landing gear in order to create drag and slow the aircraft down.
The backrest of the centre row of seats in VH-SJW could be folded forwards for access to the rear row of seats, which was standard. One centre row passenger found it difficult to brace against the moveable seat back, and though wearing a seatbelt, reported not being sufficiently secure. This passenger’s neck was injured in the incident.
The turbulence encounter lasted about 3.5 minutes. Radar at Darwin recorded the aircraft’s highest groundspeed as 210 kt, and rate of descent at one point to be 5,000 ft/minute with a lowest altitude of 1,200 ft.
The pilot gave the passengers a ‘thumbs-up’ indication when control was returned and continued to Tindal Airport in mild turbulence and rain.
After landing
The aircraft landed at Tindal Airport at 1538, and the passengers disembarked 5 minutes later. The passengers reported that the pilot asked if they were okay but said the pilot did not de-brief them on the incident other than to say that it was normal turbulence. The pilot did not report the turbulence encounter to the operator or the ATSB.
A passenger stated that the group was distressed by the incident, and, with no debriefing or advice, they went directly to their accommodation. In retrospect, the passenger believed the group should have instead gone to hospital to be checked over. Three of the passengers later visited hospital for shoulder and neck injuries, and one case of damage to a pre-existing leg injury.
Recognising the potential for damage to the aircraft from the turbulence encounter, the pilot reported conducting a thorough daily inspection at Tindal. The pilot spent a total of 31 minutes on the apron at Tindal before departing for Milingimbi at 1614. At Milingimbi, the pilot met four passengers and flew them to Galiwin’ku.
At Galiwin’ku, the pilot told the operator’s base manager about the turbulence encounter. The base manager advised the pilot to contact the head of flight operations (HOFO). The pilot did so and the HOFO instructed the base manager to ground the aircraft and ordered an engineering inspection of the aircraft for flight under abnormal loads. An engineer carried out the inspection the following day and returned the aircraft to service after finding no defects.
Context
The pilot
The pilot of VH-SJW held a commercial pilot licence (aeroplane) and had 802 hours’ aeronautical experience, with 550 hours as pilot in command, and had flown in the region for the operator for 11 months. Upon commencement with the operator in December 2018, the pilot underwent a course of training designed to bridge the gap between commercial licence training and commercial operations in general aviation. This included exposure to decision making around adverse weather.
Weather information
Meteorological conditions over the northern half of Australia are favourable for thunderstorms from October through to March. Abundant moisture and instability is present through most of the Wet Season. During this time, low pressure lies across northern and central Australia, giving rise low-level convergence and vertical motion necessary for thunderstorm development. During these months, thunderstorms during the afternoon are a common occurrence due to the convergence of sea breezes with an east to south-easterly synoptic wind regime (Figure 3).
The convective cloud bases can be very high (sometimes up to 15 000 feet), with very severe downdraughts from the cloud base to the surface. For this reason, flights should never be conducted under or through precipitation (including virga) from towering cumulus or cumulonimbus clouds.
Figure 3: Mechanism of local storm generation
Source: ATSB
The weather forecast for Darwin received by the pilot before departure stated:
PROB30 TEMPO 2505/2514 VRB20G45KT 1000 THUNDERSTORMS WITH MODERATE RAIN BKN010 SCT025CB
That translated as a 30 per cent probability of thunderstorms for periods of at least 30 minutes but less than 60 minutes, and wind variable in direction with gusts up to 83 km/h (45 kt), accompanied by low cloud and rain with low visibility around Darwin from 1430 local time onwards. Tindal shared similar predicted conditions although any thunderstorms were expected for periods of less than 30 minutes.
The routine report of meteorological conditions at Darwin Airport at the time VH-SJW was readying for departure stated:
This translated as surface wind from the north-west at 18 km/h. Visibility was 10 km or greater, with showers in the vicinity of the airport. Cloud at 4,500 ft covered up to one half of the sky, and the layer included embedded cumulonimbus. The air temperature was 34 °C and the pressure (QNH) was 1,008 hPa. Additionally, a trend forecast was included with the report, warning of the expectation of periods of thunderstorms. These would have low cloud at 1,000 ft covering three quarters of the sky and cumulonimbus at 2,500 ft covering up to half the sky, bringing rain with variable wind gusting from 35 to 83 km/h, and reduced visibility of 1,000 m.
The pilot used information from a Bureau of Meteorology high-resolution Doppler radar, located 5.5 NM to the east of Darwin, to aid awareness of the weather conditions. There are, however, limitations to that technology. Heavy rain closer to the radar will absorb energy and reduce the displayed intensity of other cells behind it. Additionally, the image is a composite of the last 6 to 10 minutes of data and shows where the weather was, not where it is. A cell could be much closer and more intense than displayed.
Figure 4 shows satellite images that captured the build-up of thunderstorm activity on the day. In the first frame at 1230 Darwin (YPDN) is relatively clear of cloud. After VH-SJW arrives in Darwin, the next hour shows significant build-up of cloud on VH-SJW’s intended track to Tindal (YPTN).
Figure 4: Satellite images of thunderstorm development at the time
Source: Bureau of Meteorology annotated by ATSB
Procedures and guidance
In August 2019, the operator amended its operations manual with a section titled ‘Adverse weather operations’. This section required pilots to avoid thunderstorms by 20 NM during the cruise phase of flight. The pilot had signed to confirm receipt of the operations manual amendment on the day it was issued. The operator also created a training program to support the amendment. The pilot had not received the training before the incident flight.
The safety message of ATSB report AO-2017-102,[4] an investigation of a fatal turbulence penetration event involving a Cessna 210 in the Northern Territory, stated that diversions of 10 NM may not be sufficient. That report was presented by an ATSB investigator in the pre-season Top-End safety briefing hosted by the Civil Aviation Safety Authority in Darwin on 9 October 2019. The operator’s pilots on Galiwin’ku (Elcho Island) could not attend, and instead got together to watch the 2018 briefing which was available via the internet.
In interview, the HOFO stated that pilots were encouraged to report incidents, and in some cases, such as for birdstrike, there were written requirements and instructions for reporting and managing the event. Even though the operator provided pilots with extensive guidance on avoidance of adverse weather, the HOFO stated that there was no formal guidance for the actions for pilots to follow after encountering severe turbulence.
Safety analysis
Anticipating and avoiding turbulence
The primary tool for reducing the risk of turbulence encounters of this type is avoidance of the associated weather phenomenon. Advice existed for the pilot in the operations manual that a 20 NM separation was required. A previous ATSB investigation report stated that 10 NM separation may not be enough, and a recent seminar repeated the message. Unfortunately, partially due to the reality of remote area operations, the pilot missed these recent reminders.
By diverting 5 NM right of track, and being 10 NM from the cell, the pilot was still too close to the weather phenomenon. Although the extent of loss of control was unexpected, some turbulence could be reasonably foreseen.
The pilot was well secured by wearing a harness, yet the passengers and cabin were not sufficiently prepared. The brief before flight stated that seatbelts were to be worn at all times, and that they should be tight, and the pilot conducted a visual check before departure. During flight when turbulence is anticipated or encountered, these instructions should be repeated with instruction to stow all loose items. In this case, an inability to communicate via intercom with the passengers while airborne limited the pilot’s ability to prepare the cabin.
Post incident reporting
A loss of control due to weather is an immediately reportable matter for an air transport operation under Regulation 2.3 (3)(s) of the Transport Safety Investigation Act 2003. In accordance with section 18 of this Act, the occurrence must be reported as soon as is reasonably practicable to the ATSB by telephone and a follow up written report must be made within 72 hours. The requirement to ensure a report is made resides with all responsible persons having knowledge of the occurrence.
The pilot did not report the turbulence encounter to the operator until after the last flight. From that point, the pilot and operator both had a responsibility to report the encounter to the ATSB. The encounter was reported by the operator 7 days after it occurred. It is important for preservation of perishable evidence that occurrences are reported as soon as practicable.
Operational support and management of risk
During the turbulence encounter and loss of control, the pilot was sure that no airframe limitations were exceeded. If the limitations were not exceeded, the pilot was not legally required to cease operations in that aircraft. However, when encountering such a high level of turbulence, the aircraft instruments may not present an accurate picture of what the aircraft experiences. It was reasonable to assume that airframe limitations could have been exceeded.
A pilot may not recognise or appreciate the implications of an abnormal event until a much later time. An objective view from a peer or senior person can lead pilots to make better decisions after an abnormal event.
Without formal guidance as to next steps following an encounter with severe turbulence, the pilot did not report the incident, or seek outside input into decision-making. Subsequently, the pilot prescribed a suboptimal inspection for the circumstances. The pilot did recognise the potential for damage, and inspected the aircraft to the extent that a pilot could. Licenced aircraft maintenance engineers are qualified to inspect aircraft for abnormal flight loads, yet the pilot did not consider such an inspection was necessary. Although the later engineering inspection found no defects, continuation of flight without an appropriate inspection exposed the pilot, operator, and passengers to additional, avoidable risk.
The operator demonstrated active risk management by grounding the aircraft to ensure its airworthiness after receiving a report of the occurrence. This set a visible benchmark of risk tolerance, which if supported by formal guidelines, would clearly set the operator’s expectations of its pilots.
Even in remote areas, pilots are not expected to manage the safety of a flight on their own, and facilities exist for pilots to enlist support and seek alternative solutions. Operators should ensure that there are well-communicated and structured solutions in place.
On the operational level, reporting issues as early as possible gives an operator time to develop alternative solutions for customers, which takes any acquired operational pressure away from the pilot. This supports pilots in cautious decision-making.
Another tool to assist in pilot decision-making is passenger debriefing. It is an opportunity for the pilot and passengers to process the occurrence and develop strategies for next steps and future avoidance.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the turbulence encounter and loss of control involving VH-SJW on 25 November 2019.
Contributing factors
Although the pilot diverted 5 NM right of track to avoid a large storm cell that was 5 NM left of track, the 10 NM separation from the storm was not sufficient and the aircraft encountered severe turbulence, resulting in a loss of aircraft control.
Other factors that increased risk
The operator provided no formal guidance to pilots with respect to immediate reporting of abnormal events, and the pilot did not make an immediate report.
The pilot flew another passenger charter flight in the incident aircraft before reporting the turbulence encounter and loss of control to the operator. Upon receiving the notification, the operator immediately grounded the aircraft for a precautionary airframe inspection.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
pilot of VH-SJW
passengers aboard VH-SJW
Mistar Holdings (operator of VH-SJW)
Department of Defence (air traffic control provider)
Bureau of Meteorology
Civil Aviation Safety Authority.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
pilot of VH-SJW
Mistar Holdings
Bureau of Meteorology
Civil Aviation Safety Authority
Department of Defence.
Submissions were received from the Bureau of Meteorology and Mistar Holdings (safety action only). The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 19 October 2019, a Piper PA-28-161, registered VH-XDI (XDI), operated by the Australian Airline Pilot Academy (AAPA), was inbound to Albury, New South Wales (NSW) from Wagga Wagga, NSW, on a training flight. The pilot was the only person on board. An ATR72-212A, registered VH-FVR (FVR), operated by Virgin Australia Airlines, was also inbound to Albury on a scheduled passenger flight from Sydney, NSW. There were two flight crew, two cabin crew and 66 passengers on board.
During the approach, the pilot of XDI turned on to the base leg of the circuit in front of FVR. The crew of FVR received a traffic collision avoidance system (TCAS) traffic advisory (TA) and conducted a missed approach to increase separation. Separation between the two aircraft reduced to about 110 metres horizontally and 75 feet vertically.
What the ATSB found
The ATSB found that the pilot of the PA-28 did not sight the ATR aircraft, which the controller had instructed them to follow, and did not advise the controller they did not have the aircraft sighted before turning in front of the ATR aircraft, resulting in a near collision. The crew of the ATR were aware that there was traffic in the area but did not assess the position of the PA-28, in relation to their aircraft until activation of the TCAS TA.
The ATSB also identified that the air traffic controller did not confirm that the pilot of XDI correctly understood the planned method of sequencing the two aircraft by requiring readback of the instruction to sight and follow the ATR, nor did they seek confirmation that it had been sighted. The controller did not identify the developing near collision as they were not effectively monitoring the aircraft in the circuit area due to their attention being focussed on another aircraft.
What's been done as a result
Following this occurrence AAPA implemented additional controls for students operating to Albury Airport. The academy also took action to ensure their pilots receive additional education and training on procedures for airports in Class D airspace (controlled airspace that surrounds general aviation and regional airports equipped with a control tower such as Albury) and complete training on air traffic control clearance requirements and compliance.
Virgin Australia have reminded all their crews of the separation that is provided in Class D airspace. Additionally, Virgin Australia and Airservices Australia have begun discussions to convene a cross industry stakeholder meeting to include operators, Civil Aviation Safety Authority, ATSB and the broader industry to discuss the ongoing risk to operations at non-controlled and airports in Class D airspace.
Safety message
This serious incident illustrates the danger of assumption and incomplete situational awareness.
Although separation between the two aircraft was the pilots’ responsibility on this occasion, the controller had recognised the potential conflict and implemented a plan to sequence their arrival. However, confirmation was not sought from the pilot assigned to follow the ATR that they understood the plan. Additionally, all parties made incorrect assumptions about the aircraft movements rather than taking positive action to confirm that adequate separation would be maintained.
The occurrence
What happened
On the 19 October 2019, at 1100 Eastern Daylight‑saving Time,[1] a Piper PA-28-161, registered VH-XDI (XDI), operated by Australian Airline Pilot Academy, was inbound to Albury, New South Wales (NSW), from Wagga Wagga, NSW. The pilot was conducting a training flight and was the only person on board. At the same time, a Virgin Australia Airlines ATR72-212A, registered VH‑FVR and operating as Velocity 1174, was also inbound to Albury on a scheduled passenger flight from Sydney, NSW. On board the aircraft were two flight crew, two cabin crew and 66 passengers.
The pilot of XDI contacted the controller and was cleared to enter Albury airspace from the north via Holbrook at 3,500 ft, below a broken cloud base at 4,000 ft but with visibility in excess of 10 km. While the aircraft was inbound, the crew of Velocity 1174 contacted the controller and was cleared to conduct an RNAV Z RUNWAY 25 approach.
Figure 1: Aircraft tracks as recorded by the ADSB systems on-board the aircraft
Image shows the inbound tracks of VH-XDI joining a right circuit and Velocity 1174 conducting a straight-in approach. The area a third aircraft was operating is also marked. Source: Airservices Australia, Google Earth - annotated by ATSB.
At approximately 1118, another aircraft (Aircraft 3) departed Albury on a local scenic flight towards Bethanga (Figure 1). Shortly afterwards, the controller tried to contact the pilot of XDI and after not receiving a response, they attempted contact a second time. This time the pilot responded and was instructed to join the mid‑downwind leg of the right circuit for runway 25. The pilot was then provided with an onwards clearance after the touch-and-go landing. Immediately after this, the crew of Velocity 1174 advised the controller that they were at the final waypoint[2] and the controller cleared them to land.
The controller subsequently advised the pilot of XDI that ‘…you’re number two following an ATR on about a four‑mile final, report traffic in sight’. The pilot acknowledged the instruction by advising the aircraft’s callsign but did not repeat any part of the instruction back to the controller. About 40 seconds later, XDI joined the downwind leg (Figure 1) for a right circuit to runway 25 (Figure 2).
Figure 2: XDI turning downwind with Velocity 1174 on approach
Source: Airservices Australia annotated by ATSB
After advising the pilot in XDI to report sighting the ATR and observing the aircraft join downwind, the controller diverted their attention to Aircraft 3 to ensure that aircraft did not pass in front of the ATR. The pilot of the third aircraft advised the controller that they had the Virgin aircraft sighted shortly after XDI turned on to downwind. The controller acknowledged this and requested that the pilot report with their intentions at Bethanga.
The controller advised the ATSB that, due to their focussed attention on the third aircraft, they were not monitoring XDI as the aircraft continued on the downwind leg and turned on to the normal base leg of the circuit (Figure 1). At that point the pilot of XDI had not sighted the ATR or advised the controller that they did not have it sighted (Figure 3).
Figure 3: XDI turning base with Velocity 1174 on about 3 km (1.8 NM) final
Source: Airservices Australia annotated by ATSB
As Velocity 1174 passed approximately 600 ft above ground level (AGL), the crew received a traffic collision avoidance system[3] traffic advisory (TCAS TA)[4] and, in response, began to visually acquire the aircraft causing the alert. They quickly identified the PA-28 below them; the aircrafts’ separation at that stage was about 111 metres (.06 NM) horizontal and 75 feet vertical. Due to the proximity of the two aircraft, the crew of Velocity 1174 immediately commenced a missed approach.
The controller reported not observing the near collision, only shifting attention back to the involved aircraft when the crew of the ATR reported the missed approach. This occurred 2 minutes and 14 seconds after the controller had instructed the pilot of XDI to report sighting the ATR. The controller advised that, as the ATR was already conducting a missed approach, a safety alert was not issued.
The pilot of XDI advised the ATSB that when Velocity 1174 was first sighted it was so close that the pilot lowered the nose of the aircraft to increase separation. The crew in Velocity 1174 was conducting a missed approach and passing above the PA‑28 when the controller contacted the pilot of XDI and advised that their aircraft had turned in front of Velocity 1174 and requested the pilot’s intentions. After the pilot of XDI acknowledged this request with registration only, the controller cleared the aircraft to land. However, due to an assessment by the pilot that the aircraft was too fast, a go-around was conducted. The controller then cleared XDI to depart the airspace.
Pilot of XDI
The pilot of XDI was an international student, completing flying training in Australia and had obtained a private pilot licence on the day before the incident (the pre‑requisite aviation English Language Proficiency test had been successfully passed a few months before). On the day of the occurrence, the pilot was conducting a navigation exercise as part of the commercial pilot licence syllabus. The pilot had flown to Albury on a number of occasions, both with an instructor and solo.
The pilot reported understanding the controller’s instructions during the incident flight, specifically the requirement to track as number two to the ATR. The ATSB reviewed recordings of the radio communications while XDI was inbound to Albury Airport. This review found that the radio transmissions from the controller and both Velocity 1174 and the third aircraft were spoken slowly and clearly, although the crew of Velocity 1174 referenced a radial and an inbound instrument flight rules (IFR)[5] waypoint that may not be familiar to some VFR pilots.
The pilot recalled that there was only one other aircraft operating in the circuit area (that is, the Velocity aircraft as per the controller’s instructions) at the time, which indicated that they were unaware that the third aircraft had departed. The pilot was also unaware that the Velocity call sign was that of a commercial aircraft.
After joining downwind, the pilot assumed the crew of the aircraft to be followed (Velocity 1174) had sighted XDI. Before turning on to the base leg of the circuit, the pilot recalled carrying out normal visual checks to ensure the base and final legs were clear. The check did not involve looking along the long final flightpath, as the pilot assumed that Velocity 1174, which had been cleared to land before XDI joined downwind, was either on short final or had landed.
Flight crew of FVR
The flight crew of FVR had been operating in cloud, becoming visual at around 4,000 ft AGL. The first officer, who was the pilot monitoring,[6] advised being aware of another aircraft in discussion with the controller but did not receive information on that aircraft and did not expect to, as the controller had instructed XDI to follow FVR in the circuit. They did not assess where the other aircraft was in relation to their approach.
The crew advised completing their required pre-landing checklists when the captain, who was the pilot flying, detected the TCAS TA. They immediately began scanning to visually acquire the aircraft. They advised that, as they sometimes received traffic advisories during approach from aircraft operating on the ground or at low level near an airport, they initially started looking on the runway surface. The TCAS display gave an indication that the aircraft was operating in the forward right quadrant from the aircraft. The first officer quickly identified the PA-28 on the base leg of the circuit and assessed that the aircraft, while very close, would pass behind them. The captain immediately initiated a missed approach.
The TCAS system was designed such that when the aircraft was on descent and passed below 900 ft AGL, the system would not generate a resolution advisory (RA) or an aural alert. The crew advised that they have regular training on responding to a TCAS RA but have not discussed how to manage a TCAS TA during an approach when the aircraft is below 900 ft and the RA and aural warning functions were inhibited.
Provision of separation in Class D airspace
The controlled airspace around Albury Airport was classified as Class D airspace.[7] In accordance with the Manual of Air Traffic Services (MATS) 2.4.1.1, when operating in Class D airspace, controllers were required to provide separation between two or more aircraft operating under IFR, and between aircraft operating under IFR with aircraft operating under Special Visual Flight Rules (VFR).[8] There was no requirement to apply a separation standard between an aircraft operating under IFR with an aircraft operating under VFR.[9] There was, however, a separation standard applied to all aircraft operating on the runway.
The Aeronautical Information Publication (AIP) En Route 1.1 section 2.2.1 stated that an air traffic control (ATC) clearance was required for all flights operating in Class D airspace. MATS stated that the objective of an ATC clearance[10] (clearance) was ‘to prevent collisions, and to expedite and maintain an orderly flow of air traffic’. Flight crews were required to follow all clearances and ATC instructions (instructions).[11]
En Route 1.4 section 2.2.1 stated that in the traffic circuit, pilots were ‘required to position their aircraft in such a manner that, while complying with clearances and instructions from ATC, they maintain the necessary separation from other traffic’. En Route 1.1 section 2.13.1.4 stated that when a pilot was ‘issued with a sequencing instruction, a pilot must follow the preceding aircraft and continue to do so unless otherwise instructed by ATC’. It also required that ‘if the preceding aircraft cannot be sighted and identified, the pilot must advise ATC’. MATS section 10.8.1.4.3 stated that the controller should ‘when necessary, obtain corroborative evidence from the pilot of one aircraft on the relative position of the second aircraft’.
MATS section 12.5.1 stated that ‘significant traffic information' is required to be given to pilots, where applicable, when they request a clearance to enter the aerodrome traffic circuit. MATS defined ‘traffic information’ as ‘information issued by an ATS unit to alert a pilot to other known or observed air traffic which may be in proximity to the position or intended route of flight and to help the pilot avoid a collision’. However, MATS 10.7.2.5 stated that traffic information should be provided where in the controller’s judgement, ‘one aircraft may observe the other aircraft either visually or by ACAS[12] and could be uncertain of the intention of that aircraft’.
Visual separation methods
MATS 10.7.2 permits the controller to base separation on the aircrafts’ projected flight paths, where the projected flight paths do not conflict. In this case, the controller observed one aircraft on straight-in final and observed the other turn on to the downwind circuit leg.
MATS 10.8.1 allows for the responsibility for visual separation to be assigned to the pilot. The controller passed traffic information in sufficient time and detail (ATR on 4 NM final) to enable the pilot of XDI to identify and maintain separation from FVR. MATS 10.1.5.2 advised that when the pilot acknowledged the instruction, they assumed responsibility for separation from FVR.
Summary
Apart from runway operations, there was no separation standard required between VFR and IFR aircraft operating in Class D airspace, but flight crew were required to follow the instructions provided by controllers. An instruction given by a controller is to prevent collisions, however, separation between aircraft was the responsibility of flight crew. While not applying separation standards, controllers use separation methods to ensure aircraft do not conflict. Additionally, traffic information should be passed in situations where the controller considers pilots may be uncertain of the intentions of a second aircraft.
Clearance readback
According to the AIP General 3.4–13 4.4 the pilot must read back ‘ATC clearances, instructions and information which are transmitted by voice’. According to MATS 9.2.2.13 ATC must ‘obtain a readback in sufficient detail that clearly indicates pilot's understanding of and compliance with all ATC clearances, including conditional clearances, instructions and information which are transmitted by voice’.
Airservices Australia assessed that the pilot was not required to read back the instruction that XDI was ‘…number 2 following an ATR on about a four-mile final…’, and to ‘…report traffic in sight.’ as the pilot had acknowledged the instruction and did not request clarification. Readback requirements were detailed in MATS section 9.2.2.13 subsections 1 and 2:
an ATC route clearance in its entirety, as well as any amendments
en route holding instructions
any route and holding point specified in a taxi clearance
any clearances, or instructions to hold short of, enter, land on, line-up on, wait, take-off from, cross, taxi or backtrack on, any runway or helicopter landing site (HLS)
assigned runway or HLS
any approach clearance
altimeter settings directed to specific aircraft, radio and radio navigation aid frequency instructions
secondary surveillance radar codes, data link logon addresses
level instructions, direction of turn, heading and speed instructions.
Airservices Australia advised that if the pilot of XDI had reported sighting the ATR, then they would have been issued a subsequent instruction to follow the aircraft, which would have been required to be read back.
Previous occurrences
A search of the ATSB database revealed that between 1 January 2010 and 31 December 2019, there were three near collisions (including this occurrence) involving regular public transport (RPT) aircraft in the vicinity of an airport, below 2,000 ft. Two of these occurred on short final at Albury Airport in 2019.
Safety analysis
The pilot of XDI understood the requirement to track as number two to the ATR but was unaware Velocity 1174 was a transport category aircraft conducting a straight-in approach to the airport. The assigned traffic sequence was intended to ensure separation was maintained, and hence it is likely the controller assessed that XDI was not significant traffic for the ATR and did not pass traffic information to its crew. Nevertheless, the crew of the ATR were aware that an aircraft was operating in the area but did not visually assess the position of XDI in relation to their approach path until the activation of the TCAS TA.
As the ATR was cleared to land prior to the PA‑28 entering the circuit area, the pilot of XDI assumed the ATR was either on short final or had landed before XDI turned on to the base leg of the circuit. Consequently, they did not check for aircraft on long final before turning base. However, when the pilot of XDI did not report sighting the ATR as expected, the controller was required to obtain corroborative evidence from the pilot on the position of the ATR. This was a missed opportunity by both the pilot and the controller to ensure separation was maintained.
While there was no requirement for the controller to provide separation between the two aircraft, the potential conflict between them had been identified by the controller and a plan established to sequence their approach. The controller passed responsibility for separation to the pilot of XDI with the instruction to sight and follow the ATR. However, they did not require the pilot of XDI to readback the instruction, removing the opportunity for the controller to confirm the pilot correctly understood the sequencing plan.
Additionally, once the instruction was given to the pilot of XDI, the controller focussed their attention on the third aircraft. This resulted in limited visual scanning of the ATR and PA-28, which in turn prevented visual identification of their developing proximity. In combination, these factors led to the near collision not being identified by the controller or the pilots until the crew of the ATR received the TCAS TA and reported commencing the missed approach.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the near collision between Piper PA 28, VH-XDI and ATR72, VH-FVR at Albury Airport, New South Wales, on 19 October 2019.
Contributing factors
The pilot of the PA-28 did not cite the ATR aircraft, which the controller had instructed them to follow, and did not advise the controller they did not have the aircraft sighted before turning on to the base leg of the circuit in front of the ATR aircraft, resulting in a near collision.
The crew of the ATR were aware that there was traffic in the area but did not assess the position of the PA-28, in relation to their aircraft until activation of the TCAS TA.
The controller did not seek confirmation that the pilot of XDI had sighted the ATR before diverting attention to an aircraft outside the circuit area. This interrupted the effective monitoring of the aircraft in the area and the developing near collision was not identified.
Other factors that increased risk
The controller did not confirm the pilot of XDI correctly understood the planned method of sequencing the two aircraft.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Virgin Australia Airlines and Airservices Australia have commenced discussions to convene a cross industry stakeholder meeting to include operators, the Civil Aviation Safety Authority, ATSB and the broader industry to discuss the ongoing risk to operations at non‑controlled and Class D airports. Virgin Australia Airlines also reiterated to their crews the separation that is provided within Class D airspace.
Australian Airline Pilot Academy
Following this occurrence, AAPA conducted an internal investigation and implemented the following additional risk controls:
regular face-to-face seminars have been organised between controllers at Albury Tower and new students to explain operations in Class D airspace before students complete their first solo flight to Albury
a presentation on Albury Class D airspace has been prepared for inclusion in ground school together with a training package simulating ATC interactions and clearances
additional approvals and briefings are required before a student can flying solo to Albury.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the involved pilots and air traffic controller
Australian Airline Pilot Academy
Virgin Australia Airlines
Airservices Australia.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the involved pilots and air traffic controller
Australian Airline Pilot Academy
Virgin Australia Airlines
Airservices Australia
Civil Aviation Safety Authority.
Submissions were received from:
the involved air traffic controller
Australian Airline Pilot Academy
Virgin Australia Airlines
Airservices Australia
Civil Aviation Safety Authority.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
At about 1600 on 23 November 2019, three locomotive drivers signed on at the Bordertown siding, to prepare train 2122S for a journey to Adelaide, South Australia. Train 2122S moved out from the siding and onto the Bordertown crossing loop, where a driver detached the two locomotives so they could conduct a run-around movement and reattached the locomotives to the other end of the train consist.
As the locomotives started the run-around movement, the unattended wagons started to roll back towards the siding. The wagons rolled over a level crossing (which operated automatically as designed), bounced over a derailer (signalling infrastructure on the rail) and continued back into the Bordertown siding.
A driver who was still in the siding, observed the unattended rolling freight wagons, so ran alongside and commenced applying the handbrake on one of the wagons. The runaway wagons slowed and came to a stop, having rolled unattended for about 1,425 m. The wagons stopped about 47 m from the end of the siding, a road and level crossing.
There was only minor damage to the derailer, associated rodding and slight misalignment of sleepers.
What the ATSB found
The ATSB found that while detaching the locomotives, the brake pipe air taps were closed by the driver on ground uncoupling the wagons before a full application of the train air brakes by the driver in the lead locomotive. This prevented further reduction of brake pipe air pressure, so the wagon brakes did not fully apply. In addition, handbrakes were not applied to any wagons. Once the locomotives were detached, the lack of air brakes and handbrakes allowed the wagons to roll away on the descending grade.
While not contributing to the incident, the ATSB also found that the device (a baulk) installed at the siding for restraining runaway wagons was likely insufficient to restrain runaway wagons under some conditions.
What has been done as a result
Bowmans Rail issued a safety alert requiring uncoupled wagons to have all air exhausted and handbrakes applied when left unattended. The alert also reinforced that all procedures must be adhered to when coupling and uncoupling rollingstock. Additionally, Bowmans Rail have communicated the findings of their investigation and their expectations to train crew, as well as consulted on improvements planned for its Bordertown shunting processes.
The Australian Rail Track Corporation (ARTC) has installed an arrestor bed on the track at the Bordertown dead end, with further works to the arrestor bed planned in October 2020.
Safety message
This incident highlights how omitting a procedural step may result in over-reliance on remaining protective measures. In this case, the non-application of handbrakes increased reliance on the full application of wagon air brakes to prevent a runaway. However, a slight out of sequence implementation of the air brake process resulted in only partial application of the wagon air brakes and the subsequent runaway of unattended wagons. It is essential that all procedural steps are undertaken when uncoupling wagons for run-around movements.
The occurrence
At about 1600[1] on 23 November 2019, three locomotive drivers signed on for work at Bordertown, South Australia and proceeded to the Bordertown rail siding to prepare and operate train 2122S to Adelaide, South Australia.
To prepare for the journey to Adelaide, the crew needed to pull the train (two locomotives and 30 wagons) from the siding and onto the Bordertown crossing loop (Figure 1, green arrow). They then needed to detach the two locomotives and conduct a run-around movement (Figure 1, blue arrows), so the locomotives could be reattach to the other end of the train consist.
Figure 1: Intended train movement
Train 2122S moved out of siding and onto the crossing loop (green arrow). Locomotives detached for a run-around movement so they could be attached to the other end of the train consist (blue arrows).
Source: ARTC, modified and annotated by ATSB for clarity.
Driver 1, at the controls of the lead locomotive, contacted Australian Rail Track Corporation (ARTC) network control and obtained authority to enter the interstate rail network at the Bordertown crossing loop. Driver 2 was positioned in the cab of the trailing locomotive. Driver 3 took the siding motor vehicle, drove out to Crecoona Terrace and manually activated the level crossing equipment as train 2122S exited the siding and moved towards the loop track.
Driver 3 observed train 2122S as it exited the siding (green arrow in Figure 1) and deactivated the level crossing equipment as the train cleared the level crossing, then advised Driver 1 when the train was on the crossing loop and entirely past Signal 5. After the train stopped (green train symbol in Figure 1), Driver 3 travelled back to the siding to return the motor vehicle.
Driver 2 alighted from the cab of the trailing locomotive to uncouple the wagons from the locomotives. Driver 2 contacted Driver 1 by radio to verify that the train brakes had been applied. Driver 1 confirmed this action, so Driver 2 shut the brake pipe air taps between the trailing locomotive and the lead wagon, uncoupled the locomotive from this wagon, and then climbed back into the cab of the trailing locomotive. Driver 1 recalled that an initial brake application had been made to stop the train before being contacted by Driver 2, before moving the brake into a full service position just after responding to Driver 2.
At about 1620, the ARTC network controller cleared Signal 14 and Driver 1 commenced the run-around sequence by moving the locomotives towards Signal 14 and then out onto the main line (Figure 2, blue arrow). At about the same time, the unattended wagons had begun rolling back towards the siding. As the wagons rolled past Signal 5, the network controller received a signal passed at danger (SPAD) alarm. The wagons continued to roll, passing over the Crecoona Terrace level crossing (which operated automatically as designed). The ATSB calculated the runaway speed as having increased from about 12 km/h to about 18 km/h as the lead wagon traversed the track circuits between Signal 5 and Signal 1 (Figure 2), a distance of about 257 m (refer to Appendix A). The wagons then bounced over the derailer[2] and continued back into the Bordertown siding (Figure 2, green arrow). Note: Derailers are usually directional. That is, they are designed to protect the main line by derailing a runaway vehicle exiting a siding. In this case, the wagons were moving away from the main line, so were travelling in the opposite direction for which the derailer was designed and was therefore ineffective at derailing the wagons.
Figure 2: Unattended wagons roll back into the siding
The locomotives start the run-around movement by moving out onto the main line (blue arrow). The unattended wagons roll back, pass over the level crossing, bounce over the derailer and continue back into the siding (green arrow).
Source: ARTC, modified and annotated by ATSB for clarity.
Driver 3 had returned the motor vehicle to the siding and was walking towards the station platform to wait for train 2122S to collect him when it departed for Adelaide. The driver observed the unattended freight wagons rolling towards him. As the wagons reached him, the driver ran alongside and commenced applying the handbrake on one of the wagons. The runaway wagons slowed and came to a stop as the handbrake was being applied to this wagon. This driver then exhausted the brake pipe air at the last wagon, which applied the brakes to the remainder of the runaway wagons.
At about the same time, the ARTC network controller had contacted Driver 1 and queried the status of train 2122S, noting that it appeared that the wagons had rolled back into the siding. Driver 1 contacted Driver 3 who advised the loaded freight wagons had rolled into the siding and come to a stop before the baulk[3] at the end of the siding (Figure 2).
In total, the wagons of train 2122S had rolled unattended for about 1,425 m, stopping about 47 m from the end of the siding, immediately before the North Terrace level crossing.
There was only minor damage to the derailer, associated rodding and slight misalignment of sleepers.
Bordertown is located on the interstate rail network about 250 km south-east of Adelaide (Figure 3). The track consisted of a bi-directional main line and crossing loop, with a dead end siding extending from the crossing loop. The main line, crossing loop and dead end siding was owned and operated by the Australian Rail Track Corporation (ARTC).
Figure 3: Location
Image shows the rail corridors within South Australia with the location of Bordertown in relation to Adelaide.
The Bordertown crossing loop sits on a gradient of about 1 in 100 (1per cent). The siding track (about 1,460 m in length) continues at this gradient for about 500 m before gradually transitioning to level track for the final 500 m.
Train and rollingstock
Bowmans Rail was the owner and operator of freight train 2122S. The train consisted of two locomotives (GL111 leading and EL63 trailing) hauling 30 wagons. The total train length was about 502 m, and weighed about 1,488 tonnes. There was no evidence to suggest any fault or deficiency in rolling stock condition.
Train crew
Three Bowmans Rail locomotive drivers were crewing train 2122S. All drivers were requested to undertake a breath and drug test following the accident. The tests returned a negative result for each driver.
Driver 1 was an advanced trainee with about 5 years’ experience. Driver 2 had about 16 years’ experience and Driver 3 had about 11 years’ experience. All drivers held current driver and shunt competencies, and medical assessments.
Driver 1 had worked the Bordertown shunt movement a number of times previously as the ground person, however, this was the first time working the shunt at the controls of the lead locomotive.
Recorded data
Wagon brakes apply as brake pipe pressure is reduced. For a full brake pipe application, brake pipe air pressure typically needs to reduce to about 350 kPa throughout the entire train.
In this case, the locomotive data log[4] shows that when bringing train 2122S to a stop in the crossing loop, the brake pipe pressure started to reduce (aligning to time zero in Figure 4) at a constant rate for about 19 seconds (from 508 kPa to 413 kPa), until about 4 seconds after the lead locomotive had stopped (Figure 4). After this time, brake pipe pressure reduced rapidly over about 5 seconds to 330 kPa. Brake pipe pressure remained at 330 kPa for about 8 seconds before brake pipe pressure was restored to about 503 kPa (Figure 4).
Figure 4: Locomotive data
Locomotive data showing initial brake application as train 2122S came to a stop. Brake pipe pressure reduces further before full pipe pressure is restored.Note that time scale is relative time from initial brake application.
Source: ATSB
Bordertown operational procedures
A basic shunting principle is to ensure unattended wagons are secured and brakes applied, so as to prevent any unintended movement. Bowmans Rail procedure OP 2.56 - Shunting at Bordertown (dated 16th May 2018) stated the following:
Once the Train crew has stopped the movement on the crossing loop, a full brake pipe application is made and the locomotive is detached from the train consist. The approved ETM [end-of train marker] is placed into the rear knuckle pin, and the train pipe hose hung up on the receptacle provided. Sufficient handbrakes shall also be applied to prevent wagon movement.
Both Driver 1 and Driver 2 reported that they were aware of this procedure and made correct communication with respect to this requirement.
In this case, as the train slowed to a stop in the crossing loop, Driver 2 alighted from the trailing locomotive to uncouple the wagons. The two drivers recalled at interview that Driver 2 had sought verification that a full service application had been made of the train air brakes and Driver 1 had provided an affirmative response. Driver 2 then closed both brake pipe air taps between the trailing locomotive and the wagons, disconnected the brake pipe hoses, and uncoupled the wagons. The wagon air taps then remained closed, so any remaining air in the wagon brake pipe would have been sustained (referred to as having bottled the brake pipe air).
Driver 2 did not apply any handbrakes to the front wagons before boarding the locomotive for the run-around movement. Post-incident interviews suggested that it had become a practice for this crew to omit the step of applying handbrakes when undertaking a run-around movement at Bordertown. The reason provided was that if the ground person applied handbrakes at the uncoupled end, then they would be required to walk the length of the train to release the handbrakes once the locomotives had been coupled at the other end. Experience had shown that the wagons would remain stationary under full application of the train brake without the need to apply handbrakes. Not applying handbrakes saved time and expedited the run-around process in preparation for the journey to Adelaide.
Bowmans Rail provided a third driver for their Bordertown operations. This was primarily to assist with shunting movements and the manual operation of the level crossing. Post-incident interviews suggested that in the past, after reinstating the level crossing, the third driver would walk to the rear of the train and prepare it for reattaching the locomotives. For some drivers, this would include opening the brake pipe air tap. While the intention may have been to expedite reconnection, the act of opening the brake pipe air tap also exhausted the brake pipe, ensuring all wagon brakes were applied.
A recent addition to the Bordertown siding was the provision of a road vehicle. Bowmans Rail advised that the intent was for drivers to use the vehicle for transport to and from their accommodation (for recovery rest). It was not intended for the vehicle to be used while undertaking shunting or the run-around movement at Bordertown. In this case, the train crew used the vehicle while facilitating the run-around movement. After reinstating the level crossing, Driver 3 returned the road vehicle to the siding rather than attending the rear of the train in preparation for reconnecting the locomotives. Consequently, there was no opportunity to apply handbrakes or to exhaust the brake pipe at the rear of the train.
Runaway protection
ARTC guideline ETH-00-01 - Buffer Stops and Restraining Devices for Dead End Tracks outlined a range of restraining devices intended to protect people and property from an over-run at a dead end track. Where an over-run has the potential to cause significant damage or injury, then the restraining device must have the capacity to stop the rail vehicle/s. For example, at Bordertown, the dead end track was immediately adjacent a road and level crossing. An over-run at this location has the potential to injure people, so a restraining device is required to stop a runaway vehicle such as occurred on 23 November 2019.
The guideline used gradient and distance of a potential runaway to determine the approximate speed that the restraining device may need to contain. In this case, the track gradient was about 1 in 100 (1per cent) for about 500 m before levelling out over about 500 m with the final 500 m being level grade. The guideline suggest that a runaway wagon might reach in excess of 26 km/h due to a 1 per cent grade in excess of 300 m. However, a runaway wagon at this location would likely slow to some extent on the level section of track before reaching the dead end.
The restraining device installed at Bordertown was a Baulk, defined in the guideline as a rectangular piece of hardwood timber of approximately 300 by 200 mm, bolted to the track (Figure 5). The guideline stated that a baulk is suitable for runaway speeds up to 1.5 km/h, is primarily just a marker that provides little resistance, and would probably require further devices to arrest a runaway.
Figure 5: Bordertown siding runaway protection
Restraining device installed at Bordertown. A rectangular piece of hardwood timber of approximately 300 by 200 mm, bolted to the track, known as a baulk.
Bowmans Rail procedure Shunting at Bordertown required a full brake pipe application and the application of handbrakes to prevent movement of unattended wagons.
In this case, the locomotive data log shows that brake pipe air pressure did not reduce below 350 kPa (full brake pipe application) until about 8 seconds after the train had stopped in the crossing loop. However, 4 seconds after the lead locomotive stopped, there was a rapid reduction of pipe pressure from 413 to 330 kPa over about 5 seconds. It is possible that this was due the pipe pressure reduction being applied to a smaller volume of air, suggesting that Driver 2 had isolated the brake pipes at this point. As such, it is likely that while Driver 1 and 2 communicated with respect to verifying a full brake pipe application, Driver 2 closed the brake pipe air taps before the full service application of the train brake had propagated through to the rake of wagons. The bottled brake pipe air meant that the brake pipe air pressure was maintained at the level existing at the time the taps were closed, which was above 350 kPa. Since full service pressure had not been achieved, the wagon brakes had not fully applied.
Both Driver 1 and Driver 2 were aware of the procedure requiring full brake pipe application prior to detaching the locomotives and communication was made with respect to this requirement, but their action implementing the requirement occurred out of sequence. That is, Driver 1 confirmed full brake application while in the process of moving the brake handle, rather than at the completion of the full brake application. Driver 2 interpreted the response as having completed the full brake application, so closed the taps and detached the locomotives. The consequence was a partial application of the train brakes within the wagons rather than a full application.
As it was Driver 1’s first time working the Bordertown shunt at the controls of the lead locomotive, it is likely that the miscommunication between the two drivers was a result of the changed work dynamic, rather than a lack of training.
In addition, handbrakes were not applied to any wagons. With only partial application of the wagon air brakes and no handbrakes applied, there was insufficient braking force to prevent the wagons from rolling away on the descending grade.
Although handbrakes were a known part of the procedure, not applying handbrakes during the run-around at Bordertown had become a common practice for this crew, as it saved time and had not caused any issues in the past. Further, since Driver 3 needed to return the siding motor vehicle used to position at the level crossing as the train entered and stopped on the loop track, the driver was not in a position to apply handbrakes to the rear wagons. In addition, while not part of the procedure, the use of the motor vehicle meant that the driver was also not available to apply wagon brakes by opening the air tap and exhausting brake pipe air from the rear of the train.
Runaway protection
The restraining device installed at Bordertown was a Baulk, specified as suitable for runaway speeds up to 1.5 km/h (ARTC guideline).
In this case, the runaway speed was calculated as having increased to about 18 km/h before the wagons bounced over the derailer and continued rolling down to the level section of the siding track. The level grade, the likely partial application of wagon brakes and Driver 3’s application of a handbrake, stopped the wagons about 47 m from the baulk (Figure 6). With less braking applied, it is likely that the free-rolling wagons would have travelled further, reaching the Baulk at a speed faster than 1.5 km/h.
The Australian Rail Track Corporation (ARTC) guideline states that a baulk is primarily just a marker that provides little resistance, and would probably require further devices to arrest a runaway. The configuration at Bordertown was likely insufficient for restraining the potential speed and momentum of runaway wagons, which may subsequently encroach on a road and level crossing.
Runaway wagons stopped about 40 m from the baulk. The image illustrates how wagons that might roll to the end of the track may encroach on the road and level crossing.
Source: ATSB
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the runaway of wagons on the descending grade after disconnecting the locomotives to conduct a run-around movement at the Bordertown siding on 23 November 2019.
Contributing factors
The locomotive driver confirmed a full brake pipe application, via radio communication, while moving the brake handle rather than after the full application had been made. This resulted in the ground person closing the brake pipe air taps prematurely, preventing further reduction of brake pipe air pressure. Consequently, the wagon brakes did not fully apply.
Handbrakes had not been applied to any wagons before detaching the locomotives. The non-application of handbrakes had become a practice when undertaking run-around movements at Bordertown. With the insufficient air brake application, the lack of handbrakes resulted in the wagons rolling away on the descending grade.
Other factors that increased risk
The restraining device installed on the Bordertown siding track prior to the road and level crossing, was likely insufficient under some conditions, for restraining the speed and momentum of runaway wagons.
Safety actions
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. All of the directly involved parties are invited to provide submissions to this draft report. As part of that process, each organisation is asked to communicate what safety actions, if any, they have carried out to reduce the risk associated with this type of occurrences in the future. The ATSB has so far been advised of the following proactive safety action in response to this occurrence.
Safety action by Bowmans Rail
Bowmans Rail issued a safety alert on 24 November 2019, advising of the incident that had occurred at Bordertown on 23 November 2019. The alert stated that the following action was to be undertaken:
All unattended wagons are to have all air exhausted from them when uncoupled
The appropriate amount of hand brakes are to be applied to wagons when required
Three step protection procedures are to be adhered to when coupling and uncoupling rollingstock.
Air taps on unattended wagons are not to be left closed until all air has been exhausted from wagons.
Since the initial safety alert, Bowmans Rail has taken the following additional proactive safety actions:
The completion of staff toolbox briefings on the findings and outcomes of its internal investigation.
The provision of additional staff briefings on its expectations and processes with respect to securing rollingstock and locomotives.
The completion of a review triggered by the incident, of its operational risk assessment for Bordertown operations. This review identified a need to evaluate and amend, in consultation with train crews, the processes within the Bowmans Rail procedure OP 2.56 - Shunting at Bordertown. The outcome of the review was planned for incorporation into a revised version of the OP 2.56 - Shunting at Bordertown procedure prior to the resumption of its Bordertown operations in mid-late 2020.
Safety action bythe Australian Rail Track Corporation
The Australian Rail Track Corporation has installed an arrestor bed on the track at the Bordertown dead end. ARTC has further works planned in October 2020 to complete the arrestor bed with a graded slope as per ARTC ETH-00-01 Buffer Stops and Restraining Devices for Dead End Tracks – Appendix C.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
Bowmans Rail
Australian Rail Track Corporation
Train crew
recorded data from the locomotive data log.
References
ARTC guideline ETH-00-01 - Buffer Stops and Restraining Devices for Dead End Tracks (dated 2 July 2012)
Bowmans Rail procedure OP 2.56 - Shunting at Bordertown (dated 16th May 2018)
RISSB Glossary of Railway Terminology
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Bowmans Rail
Australian Rail Track Corporation
Office of the National Rail Safety Regulator
the train crew.
Submissions were received from:
Australian Rail Track Corporation.
Office of the National Rail Safety Regulator
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Appendices
Appendix A – Speed calculations
The signalling infrastructure at Bordertown utilises track circuits to detect rail vehicles as they occupy defined sections of track. The wagons from train 2122S were uncoupled while occupying track A5T (Figure 7). As the unattended wagons rolled back into the siding (Figure 7, green arrow), the lead axle of the lead wagon sequentially occupied tracks 7AT, 296T, 9T and A1T.
Figure 7: Bordertown track numbers
Illustration showing track circuit numbers occupied as the unattended wagons rolled back into the siding.
Source: ATSB
A signalling event logger recorded the times at which each track was detected as occupied. This time coincided with the wagon’s lead axle transitioning the junction between two track circuits, providing the time duration that the lead axle had occupied a specific track. Knowing the duration the lead axle occupied the track and the length of the track (measured onsite) allowed for calculating the average speed the lead axle travelled as it traversed each track circuit.
Table 1: Calculated speed as lead wagon passed between Signal 5 and Signal 1
Track circuit
Track length (m)
Duration (sec)
Calculated speed (km/h)
7AT
125.0 m
37.1 sec
12.1 km/h
296T
27.0 m
7.0 sec
13.9 km/h
9T
105.7 m
20.1 sec
18.9 km/h
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
Section 21 (2) of the Transport Safety Investigation Act 2003 (TSI Act) empowers the ATSB to discontinue an investigation into a transport safety matter at any time. Section 21 (3) of the TSI Act requires the ATSB to publish a statement setting out the reasons for discontinuing an investigation. The statement is published as a report in accordance with section 25 of the TSI Act, capturing information from the investigation up to the time of discontinuance.
Overview of the investigation
The ATSB commenced an investigation into an engine pod strike involving a Singapore Airlines Cargo Boeing 747-412F freighter, registered 9V-SFO, which occurred at Sydney Airport on 28 November 2019.
The flight crew were conducting an approach to runway 34L at night. The automatic terminal information service (ATIS) stated the wind was 040° at 15 kt (crosswind of 12 kt), and the latest weather observation reported the wind as 040° at 22 kt with gusts up to 32 kt. The flight crew stated they briefed for the threat of strong, gusty crosswinds. The captain was the pilot handling for the landing.
During the approach, the flight crew recalled experiencing moderate turbulence and undershoot shear below 300 ft. When passing 200 ft, the airspeed rapidly trended below the minimum approach speed, the first officer called ‘speed’ and the captain recovered the target speed.
As the aircraft entered the flare it drifted right of centreline, followed by a sudden uncommanded roll to the left. In response, the flight crew initiated a rejected landing manoeuvre, during which the number 1 engine pod struck the ground. After a second approach, the aircraft landed without further incident.
Engineering inspections identified damage to the number 1 engine fan cowl and thrust reverser skin panel. Following maintenance action, the aircraft returned to Singapore where it underwent further inspections. As a result, damage to the number 1 engine main gear box was identified as being beyond the serviceable limit and the engine was removed from service.
As part of its investigation, the ATSB:
interviewed the flight crew and examined their training records
analysed recorded data from the aircraft’s flight data recorder (FDR) and cockpit voice recorder (CVR)
reviewed Boeing’s flight data analysis and other documents
reviewed air traffic control recordings
examined engineering reports, documents, manuals and correspondence relating to the operator’s Boeing 747 operation
reviewed Bureau of Meteorology (BoM) weather forecasts and analysis
conducted significant analysis of potential wake turbulence
reviewed data related to the 2020 low-level windshear alert system trial at Sydney Airport
reviewed other investigations and references where similar themes had been explored.
Analysis of recorded data indicated that the aircraft was responding correctly to flight control inputs made by the pilot flying and that the inputs were appropriate for the environmental conditions. Research and analysis undertaken by the ATSB demonstrated that wake turbulence was not a factor.
Prior to the occurrence no windshear was forecast, broadcast by air traffic controllers, or detected by aircraft or ground systems. However, during the approach, the aircraft was affected by moderate undershoot shear and wind gusts during the landing. About 4 minutes after the occurrence, a Boeing 737 landed on runway 34R. That flight crew advised air traffic controllers they lost about 15 kt of airspeed during the flare due to moderate undershoot shear. Controllers subsequently broadcast to all aircraft there was moderate undershoot shear on runway 34R.
Following the incident, Singapore Airlines made minor procedural changes and enhanced its simulator training program by requiring demonstrated competency in all crosswind landing techniques.
Low-level windshear alerting systems
At low altitudes (below 1,000 ft) during critical stages of landing and take-off, windshear can present a significant hazard to aircraft. Low-level turbulence and windshear can be caused by many processes; however, regardless of the cause, a well-designed low-level windshear alerting system is capable of detecting operationally-significant windshear and turbulence in near real time.
In 2001, there was a windshear event involving a Boeing 737 at Brisbane Airport (ATSB investigation 200100213). The ATSB recommended that BoM expedite the development, testing, and installation of advanced weather radar systems to detect hazardous windshear in high-risk airport terminal areas. In response, the BoM advised that it would continue to derive the maximum operational utility from existing and future Doppler radar systems, as the cost of specialised radar systems was high and they were not fully suitable for general weather work. Additionally, BoM advised it would maintain knowledge of international research and development of experimental low-level windshear alert systems.
In 2007, there was a micro-burst event involving a Boeing 747 at Sydney Airport (ATSB investigation AO-2007-001). The investigation raised a safety issue, which stated that there was no ground-based automatic low-level windshear warning system at Sydney Airport. At that time, BoM and Airservices Australia initiated scoping activities and a proposed system was identified. A risk assessment identified that, with existing controls (including onboard windshear detection systems), the risk level was within the broadly acceptable range.
In 2013, meetings were held with industry to discuss the proposed solution. The airline participants agreed that unexpectedly encountering windshear did not pose a significant threat to aviation at Sydney Airport. The substantial expense of the proposed system, and environmental challenges associated with siting additional anemometers required by that system, were noted. Overall, it was concluded that the benefits of continuing with the proposed system were not sufficient to justify the cost at that time.
In 2020, Sydney Airport identified that the cost of a light detection and ranging (LIDAR) system had reduced significantly and did not have the same environmental impact. A LIDAR working group was established involving Sydney Airport, BoM, Airservices Australia, airlines and a pilot’s union to consider the implementation of the system, particularly given the benefits over other systems. In general, a ground-based LIDAR system is much better at detecting turbulence in clear air, whereas onboard systems are more effective for turbulence within detectable precipitation, such as rain. BoM advised the ATSB:
Scanning doppler lidar is able to observe turbulence in the atmosphere at smaller scales than is possible with existing anemometer and wind profiler assets at Sydney. As a result, automated alerts derived from the lidar data are able to capture transient and small scale turbulent features that are, by design, not typically represented in current aeronautical meteorology products such as the TAF and WS Warning. Integrating lidar observations into the turbulence forecast process for Sydney airport is therefore likely to result in improved turbulence and low level wind shear forecast quality.
A trial of a low-level windshear alerting system using a scanning doppler LIDAR system was conducted at Sydney Airport. The trial proved the effectiveness of the system to enhance awareness of turbulence and low-level wind shear when it occurs, and the working group is now considering implementation issues.
The ATSB strongly encourages the use of LIDAR systems at airports such as Sydney Airport where turbulence-related events have been known to occur.
Reasons for the discontinuation
Based on a review of the available evidence, the ATSB considered it was unlikely that further investigation would identify any new systemic safety issues or important safety lessons. Consequently, the ATSB has discontinued this investigation.
The evidence collected during this investigation remains available to be used in future investigations or safety studies. The ATSB will also monitor for any similar occurrences that may indicate a need to undertake a further safety investigation.
On 20 October 2019, an I.C.P. Savannah aircraft, recreational registration 19-7429, collided with terrain near the Emkaytee aerodrome, Northern Territory. The pilot was fatally injured.
In response to this accident, Recreational Aviation Australia (RAAus) commenced an investigation. As part of its investigation, RAAus requested technical assistance from the ATSB.
The ATSB initiated an investigation under the Transport Safety Investigation Act 2003 and assisted RAAus by downloading flight data from the aircraft’s Dynon Electronic Flight Instrument System (EFIS) The Dynon EFIS was successfully downloaded. However, the data logging functionality of the device was not enabled. No flight data was retrieved from the device.
With the completion of the examinations and data recovery, the ATSB has concluded its involvement in the investigation of this accident. Any enquiries relating to the accident investigations should be directed to RAAus at: www.raa.asn.au
On 10 November 2019, a Fokker F28 Mk0100 (F100) aircraft, registered VH-UQN, was on final approach at night to runway 33 at Rockhampton Airport, Queensland. The aircraft was slightly high on the approach profile when smoke haze from nearby bushfires reduced the visibility on approach, obscuring the vertical approach lighting.
At about 400 ft above ground level, the aircraft encountered moderate turbulence affecting the aircraft’s approach profile. At about 300 ft, the airspeed reduced below the minimum approach speed and the pilot flying encountered increased resistance in the thrust levers while trying to recover airspeed. After a short period, the pilot forced the thrust levers to the desired setting. The aircraft’s engines responded, airspeed increased accordingly, and the aircraft landed safely.
What the ATSB found
The ATSB found that, when on final approach, the flight crew encountered reduced visibility and moderate turbulence from a bushfire, which added uncertainty and the late identification of a high approach profile. While attempting to regain the correct profile, the airspeed reduced below the minimum allowable speed, activating the automatic flight envelope protection or alpha mode before the aircraft started to accelerate. The flight crew were unaware of the alpha mode activation.
The operator’s initial type qualification training for the F100 aircraft and cyclic training did not adequately prepare the operator’s pilots to identify and respond to alpha mode activations during critical phases of flight. The ATSB further identified that the aircraft’s rate of descent exceeded the operator’s stabilised approach criteria for a short period during the approach; however, it was also identified that there was no permissible exceedance criteria in the stabilised approach criteria for transient exceedances.
There was an 8-day delay in reporting the incident to the ATSB. It was identified that the operator’s recently-installed internal safety reporting system provided warnings that adequately reflected the urgency of reporting, but contained a visual display peculiarity that subtlety concealed reportable matters, resulting in the report being unprocessed for 6 days.
The ATSB also identified that the acting safety systems manager was unable to effectively conduct the role due to limited experience in the role, increased workload, and remote working conditions during this time. This, along with other key changes, limited the operator’s capacity to provide effective safety assurance.
What has been done as a result
The operator issued an operations notice to pilots, which included guidance on the dangers of low thrust and low airspeed situations during performance decreasing conditions. The notice also provided greater guidance about the activation of alpha mode within its fleet. The operator updated its cyclic simulator training to include alpha mode activation scenarios and developed alternative procedures for pilots when encountering alpha mode activations.
Further, the operator proactively implemented an update to its safety reporting system that highlighted reportable matters by removing lesser priority indicators. It further introduced a statistical reporting tool to monitor the above system enhancement to ensure ATSB reporting obligations were measured and appropriately reported. In addition, it finalised the internal safety manual and standard operating procedures, developed a position handover checklist, and reviewed its company policy manual to detail the formal delegation of duties relating to key safety post holder positions.
Safety message
Flight crew awareness of automatic flight protections and their subsequent effect is paramount to the safe operation of passenger transport flights. Effective initial and cyclic training, and assessments in these systems, is important to ensure that pilots respond appropriately to these situations during critical phases of flight.
Operators are reminded that effective change management is an essential part of any safety management system. Changes to key safety management systems, key post holder positions, and the procedures and processes that support systems and personnel, need to be carefully managed in order to operate a robust and effective safety management system.
The occurrence
On 10 November 2019, a Fokker F28 Mk0100 (F100) aircraft, registered VH-UQN, was being operated by Alliance Airlines on a regular public transport flight from Brisbane to Rockhampton, Queensland. The flight crew had conducted a Brisbane to Rockhampton return flight earlier in the day, which was uneventful, and the weather was favourable with light winds. Bushfires had started to the north-east of Rockhampton Airport; however, the smoke associated with the fires did not have any effect on the earlier flight.
The aircraft had departed Brisbane for the third sector of the day at about 1857 Eastern Standard Time[1] and was scheduled to arrive at Rockhampton at 2000. The first officer (FO) was designated as the pilot flying and the captain was the pilot monitoring.[2] There were no weather concerns apart from smoke haze, which had worsened across south-east Queensland.
The flight crew reported that the flight was uneventful while en route to Rockhampton. Prior to descent, they conducted a standard briefing, which included the speeds required for the approach and the threat of reduced visibility due to smoke. Nearing Rockhampton, they were directed by air traffic control to conduct a standard instrument arrival procedure[3] from the south-east onto runway 33[4] at Rockhampton Airport (Figure 1).
Figure 1: Approach track to Rockhampton Airport
Source: Google Earth, annotated by the ATSB
Once established on final approach for runway 33, the FO recalled disconnecting the autopilot at about 700 ft. At about 560 ft above ground level, the meteorological minima[5] of the instrument approach, the flight crew recalled that the aircraft was maintaining the correct approach profile and speed, and noted that an additional spot fire could be seen about 1 km to the north-west of the airport. As they continued, smoke was observed to drift across the approach path due to a north‑westerly wind change. Descending below 560 ft, the weather conditions and visibility began to deteriorate.
The flight crew reported that the slant visibility[6] to the runway began to reduce, and smoke discoloured the precision approach path indicator (PAPI)[7] lights from their usual red/white appearance, to an orange colour. The FO indicated that they were unable to discern any vertical guidance from the PAPI. At about 400 ft, the aircraft was also affected by light to moderate convective turbulence from the nearby bushfire.
As the PAPI discolouration cleared, the FO recalled seeing one red light on the PAPI, indicating that the aircraft was slightly high on its approach path. In response, the FO reduced the aircraft’s pitch attitude and reduced the thrust by overriding the autothrottle system. The aircraft then encountered a downdraft, which further increased the rate of descent and decreased airspeed.
At about 300 ft, the captain observed the airspeed trending towards the minimum allowable airspeed (VMA). The FO recalled attempting to increase thrust to recover the reducing airspeed, at which time they encountered stiff thrust lever resistance. The FO reported that, about 2 seconds after encountering the thrust lever resistance, the captain called ‘speed’.[8] The FO responded by informing the captain that the thrust levers were ‘stuck’. Shortly after, the captain called ‘speed’ a second time. The captain recalled considering taking over and conducting a go-around, however, noticed that the aircraft airspeed was below VMA. Due to the aircraft position, the unknown reason for the blocked thrust levers and reduced stall margin, the captain did not command a go-around.
Due to the resistance to the advancement of the thrust levers, it took a few more seconds before the FO was able to forcibly move the thrust levers forward to the desired setting. The FO recalled that airspeed increased, the thrust lever resistance reduced, and a normal landing was safely carried out at about 1958.
The flight crew discussed the incident after engine shutdown. As part of their troubleshooting of the incident, they did not believe that an alpha mode activation[9] had occurred due to the activation prior to VMA -5 kt. They could not recall any other indication on the flight deck that alerted them to the possible activation of alpha mode during the approach.
The captain grounded the aircraft and contacted maintenance watch to organise engineering assistance from Brisbane. An engineer arrived the next morning and examined the aircraft systems, however, could not identify any technical fault with the aircraft. As a precaution, the engineer disabled the aircraft’s autothrottle system in accordance with approved maintenance procedures. The aircraft was released to service and operated back to Brisbane for further testing.
The captain held an Air Transport Pilot (Aeroplane) Licence and was appropriately qualified to conduct the flight. The captain also had an engineering background and had previously worked domestically for a number of airlines, before joining the operator in 2016. The captain had about 5,270 hours total time, with about 1,726 hours on the aircraft type, and was familiar with Rockhampton Airport, having operated there routinely for a number of years.
The first officer (FO) also held an Air Transport Pilot (Aeroplane) Licence, was appropriately qualified, and had extensive airline and charter experience both domestically and internationally. Having returned from expatriate international airline operations as a captain on Boeing 767, 757 and 777 aircraft, the FO worked for the operator for about 18 months prior to the incident, and had accumulated about 20,709 hours total time, with about 890 hours on type.
Training
General information
Civil aviation safety regulations require pilots to undergo regular assessment of skills and knowledge in particular operational areas to ensure competency. Proficiency checks assist in combatting the normal degradation of critical skills over time and serve as an important opportunity for operators to standardise and educate flight crew about recent operational changes, safety information, organisational guidelines and provide education on specific subjects. Most passenger transport operators satisfy this requirement by flight crew participation in an approved training and checking system called flight crew cyclic training. This training occurs numerous times a year and at set intervals.
All of the operator’s flight crew were required to complete initial type qualification training on the F100 before progressing to cyclic training and proficiency program assessments.
Alpha mode protections were covered in the operator’s initial type qualification training by all flight crew. However, at the time of the incident, ongoing cyclic training did not include alpha mode protection proficiency training or assessment. Both flight crew reported that the initial training received covered only the alpha mode activation and thrust increase and did not identify other aspects such as the sensation of blocked thrust levers.
The operator stated that, at the time of the occurrence, the training provided in the initial type rating was that recommended by the aircraft manufacturer. The type certificate holder advised that there was no obligation for them to create a flight crew training syllabus with associated training schedules for initial type training, nor for recurrent proficiency training. For that reason, such a flight crew training syllabus had not been issued. The type certificate holder further advised that, at the request of the operator after the occurrence, they had provided a recommended procedure for the demonstration of alpha mode for training purposes, although this was not specifically intended for critical phases of flight.
Captain
The captain completed initial type training on 5 May 2017 with the required element of alpha mode protection completed at that time. The captain’s last cyclic training assessment was conducted on 9 August 2019 and indicated a satisfactory-above satisfactory skill level, and good technical knowledge and skills. A further line check conducted on 3 September 2019 also supported the cyclic training results.
The captain recalled that there had been no further training in alpha mode, and expressed concern that there was no standard call or crew resource management process in place for flight crew to communicate the activation and resolution of an alpha mode activation.
First officer
The FO conducted initial type training on the F100 and was assessed as competent on 28 June 2018. Part of this training required satisfactory assessment of the element relating to alpha mode protection. The FO reported that the initial simulation demonstration in respect to alpha mode was conducted at about 5,000 ft, which was considerably different to experiencing it on approach to land at night in turbulence.
Cyclic training was undertaken on 12 May 2019, with results of this assessment indicating an above satisfactory skill level with very good technical knowledge and skill. A line check conducted on 30 July 2019 further supported the results of the cyclic training.
Recent history
Both flight crew were based in Brisbane and the operator reported that their individual rosters provided them with sufficient sleep opportunity in the nights prior to the incident. They both reported having a normal amount of sleep leading up to the incident. The FO reported being on 4 days of leave before working the day prior, and both flight crew reported being fully alert on the flight. The captain also reported not noticing any impact on the FO’s alertness during the flight.
Aircraft information
General
The Fokker F28 Mk0100 (F100) is a low-wing, twin-engine, medium-size, short-range, jet aircraft used by several regional carriers in Australia. It is powered by 2 Rolls-Royce RB.183 TAY medium by-pass, rear mounted turbofans. As of 28 June 2021, 24 F100 aircraft were in service with the operator.
Post-incident engineering testing
During initial troubleshooting at Rockhampton, the engineer concluded that the report of blocked thrust levers occurred when the autothrottle system (ATS) was engaged and that no fault codes or system reliability issues were identified.
After an uneventful return flight to Brisbane, further testing on the aircraft systems was conducted. This testing revealed no evidence of any malfunction within the alpha mode system, and further review of recorded flight data by the manufacturer revealed that the alpha mode functioned correctly. In addition, testing of the dynamic rods, which can introduce a stuck thrust lever sensation, was carried out as a part of the system troubleshooting and a resistance anomaly was identified through fault codes that displayed on the automatic flight control and augmentation system (AFCAS) maintenance panel. The engineer replaced the flight augmentation computer as a precaution and, after multiple system checks, returned the aircraft to service. Further testing of the dynamic rods by the operator identified a technical anomaly, however, this was not considered a factor in the incident.
Automatic flight control and augmentation system
System overview
The aircraft was fitted with an AFCAS that received information from the flight management system, and other flight and navigation data systems. It monitors the aircraft configuration, engines and other aircraft systems. The AFCAS integrates this data and displays the information to the pilots on the aircraft state and reference airspeeds and provides guidance on aircraft flight profile and navigation. The AFCAS also provides a number of aircraft flight envelope protection features, which includes minimum speed protection.
Minimum speed protection
The minimum speed protection system was based on an automatically calculated minimal allowable airspeed (VMA). The VMA is calculated by the AFCAS and is dependent on the aircraft weight, flap settings, flight phase and altitude information. In flight, VMA is displayed as the top of the amber strip located on the primary flight display speed scale (Figure 2). Minimum speed protection consists of 3 sub-system elements; the most relevant to this incident being the VMA protection and alpha modes.
Figure 2: Minimum allowable airspeed on the primary flight display
Source: Operator, annotated by the ATSB
VMA protection
The AFCAS does not accept speed selections below VMA, and aircraft speed deceleration to less than VMA is prevented by the AFCAS using either elevator or thrust control. The aircraft manufacturer identified limitations in this protection, stating that:
VMA protection may be not adequate in conditions of strong turbulence or during fast decelerations.
For those identified conditions, alpha mode then provides low speed protection.
Vertical speed indicator
Vertical speed is displayed on the right side of the primary flight display and is indicated in a positive and negative scale by an electronic needle indication with an abbreviated number display (Figure 2) in hundreds of feet per minute. The scale deflection does not have identified values, rather, it relies on flight crew knowledge to interpret the smaller dot above and below the level indicator as 500 ft/min marks, and larger scale marked in 1,000 ft increments. The abbreviated number display adjusts in increments of 100 ft/min, but only identifies the rate of decent in hundredths of the displayed rate. For example, 700 ft/min is identified as 7 on the abbreviated display.
Alpha mode
Alpha mode was designed to protect the aircraft from an aerodynamic stall[10] by automatically applying a controlled escalation of engine thrust to increase aircraft airspeed to VMA, or the selected airspeed set by the flight crew, whichever is higher. This potentially prevents the aircraft from entering a low speed, high angle of attack[11] state, where it would be vulnerable to loss of control.
The F100 Aircraft Operations Manual, section 1.18.4, stated that one of the system behaviours on activation of alpha mode was a thrust limit change to take-off/go-around (TOGA) thrust.
Indication is provided to flight crew on the flight deck through the primary flight display (Figure 2), the thrust limit change displays the climb (CLB) indication in the top left of the flight display from a green CLB to a white CLB.
Alpha mode activation will occur for a number of flight conditions, including, but not limited to, if the aircraft’s airspeed drops 5 kt below 1.3 times the stall speed in a given configuration. However, alpha mode activation could occur at higher speeds if the aircraft is subject to an increasing load factor,[12] fast decelerations at low thrust settings, or in conditions that may exacerbate these factors, such as atmospheric turbulence. For the incident flight, the aircraft type certificate holder indicated the VMA varied between 131–132 kt.
The ATS increases thrust by a deliberately controlled increase (forward movement) in the throttle lever position. The amount of thrust required is dependent on the aircraft’s airspeed increasing to VMA or the selected airspeed, whichever is higher, and could increase thrust up to the TOGA setting. The increased thrust will increase airspeed, potentially preventing the aircraft from slowing to the point of stall. The ATS controls the increased thrust to the engines through the dynamic rods.
Dynamic rods
The F100 is fitted with mechanical/electrical connecting rods joining the thrust levers and the thrust control cable system, known as dynamic rods (Figure 3). The dynamic rods are fitted with switches, which activate allowing normal pilot input on the thrust levers to override the ATS by opening the autothrottle engage clutches. When alpha mode is active, these switches are deactivated and the thrust levers may appear rigid, requiring significant effort to move them.
The system is designed to prevent flight crew from reducing thrust further during a low-speed event, thereby potentially providing protection against a low-speed loss of control. However, the increased thrust lever force required also affects the normal operation of the thrust lever to increase thrust.
Figure 3: Dynamic rods schematic
Source: Operator, annotated by the ATSB
The dynamic rod behaviour under alpha mode was specific to the operator’s F100 fleet. The Fokker F28 Mk070 (F70) series, also operated by the operator, was also fitted with alpha mode but did not have the dynamic rod feature. A modification was available to remove the dynamic rod behaviour in the F100; however, this had not been incorporated into any of the operator’s F100 fleet at the time of the incident. The operator reported that it had considered incorporating the modification across the Fokker fleet, but this was not achievable due to part availability and cost.
Thrust lever resistance
At the time of the incident, The F100 Aircraft Operations Manual provided a caution regarding the thrust level resistance experienced when the aircraft was in alpha mode as:
CAUTION:
The force override switches are de-activated during alpha mode operation and if, at this moment, the pilot attempts to manually advance the thrust levers to speed up engine response, he experiences heavy override forces which may give the impression that the thrust levers are blocked. Although not recommended, ATS can be overridden by holding the ATS disconnect buttons [on the thrust levers] depressed and advancing the thrust levers until the speed is above VMA and the alpha mode is deactivated.
If significant force is applied to the thrust levers while alpha mode is active, the pilot could advance the thrust levers by overpowering independent slip clutches within the system. However, this does not deactivate alpha mode, but does manually increase the thrust. When the aircraft regains airspeed to VMA or the selected speed set by the flight crew, alpha mode will deactivate. This restores the dynamic rod switches to normal functionality, and the increased thrust lever force will no longer be experienced by the pilot.
Approach stability
The stabilised approach concept is identified by the International Civil Aviation Organization as a set of criteria to maintain a stable approach speed, descent rate, vertical flight path, and configuration to the landing touchdown point to reduce the occurrence of controlled flight into terrain. The operator’s stabilised approach criteria, detailed in the Operations Policy and Procedures Manual – Standard operating procedures, stated:
All flights must be stabilized by 1,000 feet above airport elevation in instrument meteorological conditions (IMC) and 500 feet above airport elevation in visual meteorological conditions (VMC).
The approach is stabilized when all of the following criteria are met.
-the aircraft is on the correct flight path;
-only small changes in heading/pitch are required to maintain correct flight path;
-the aircraft speed is not more than VREF + 20 knots indicated airspeed and not less than VREF;
-the aircraft is in the landing configuration;
-sink rate is no greater than 1,000 feet per minute; if an approach requires a sink rate of greater than 1,000 feet per minute, a special briefing should be conducted;
-power setting is appropriate for the aircraft configuration and is not below the minimum power for approach as defined by the aircraft operating manual;
-all briefings and checklist have been conducted;
-specific types of approaches are stabilized if they also fulfil the following
-instrument landing system (ILS) approaches must be flown within one dot of the glideslope and localizer
-a Category II or Category III (ILS) approach must be flown within the expanded localizer band
-unique approach procedures or abnormal conditions requiring a deviation from the above elements of a stabilized approach require a special briefing.
An approach that becomes unstabilzed below 1,000 feet above airport elevation in IMC or below 500 feet above airport elevation in VMC requires an immediate go-round.
The ATSB reviewed the manuals of a number of Australian domestic and international carriers and identified that it was common for these operators to provide exceedance limitations in their procedures to allow flight crew discretion to momentarily exceed a part of the stabilised approach criteria during an attempt to correct the transient exceedance.
When discussing the concepts and terms associated with a stabilised approach, the International Civil Aviation Organization (International Civil Aviation Organization, 2015) noted that ‘normal bracketing corrections’ or momentary exceedances from pre-determined stabilised approach criteria was acceptable in some circumstances. For example:
Upon establishing visual contact with the runway environment, the pilot should be able to continue to a safe landing using normal bracketing corrections, or, if unable, should perform a missed approach.
These corrections relate to bank angle, rate of descent, and power management. Considering the operating limitations stated in the aircraft’s approved flight manual, the recommended ranges of acceptable momentary exceedances to stabilised approach criteria were:
course guidance variation depending on the approach type
maximum bank angle of 30º if specified in the approved operating manual used by the pilot
± 300 ft/min deviation in rate of descent
permissible power range if specified in the approved operating manual
momentary overshoots made necessary by atmospheric conditions.
At the time of the incident, the operator did not have a policy regarding momentary exceedances.
Recorded information
General information
VH-UQN was fitted with a flight data recorder (FDR) and cockpit voice recorder (CVR). Upon returning to Brisbane, the operator downloaded, and analysed the FDR data using flight data analysis program software. The ATSB reviewed this data, along with FDR analysis conducted by the aircraft type certificate holder, and this is summarised below.
Due to the extended period from the incident and it being reported to the ATSB, the CVR record of the flight had been overwritten. As such, the investigation was not able to verify the timeline of flight crew communications, which may have provided additional information.
Flight path and thrust data
At about 800 ft on descent on final approach, an airspeed of 137 kt was selected by the flight crew. The landing gear had been extended and the flaps were in the landing configuration. Flight data indicated the aircraft was stable at that time with a rate of descent (RoD) of about 750 ft/min, a pitch attitude of 1° nose down, and thrust lever angle (TLA) of 37°.
At about 630 ft, the autopilot was disconnected.
At about 550 ft, the aircraft was pitched to about 3° nose down and the RoD increased to about 1,100 ft/min, with a TLA of 33° and an airspeed of 138 kt.
At about 490 ft, the aircraft was pitched to about 2° nose down with a RoD of about 1,200 ft/min. The thrust levers indicated ‘OVERRIDE’ on the FDR data, as the auto throttle servo motors were not engaged, meaning the AFCAS could not reposition the thrust levers. However, the position of the thrust levers was still changing with a TLA of 29°. The airspeed had increased to 139 kt.
At about 450 ft, the thrust levers were reduced to 21° TLA and the aircraft was pitched to about 3° nose down.
Between about 400 ft and 300 ft, the TLA was further reduced to 17° and the pitch attitude maintained at 3° nose down as the RoD increased to a maximum of 1,270 ft/min.
At about 250 ft, the airspeed fell below V
At 203 ft, the airspeed had reached its lowest recorded reading of 127 kt, about 27 kt above the stall speed. The FDR data indicated TOGA limit activation, triggering the minimum speed protection of alpha mode and the ATS increased the thrust over a period of about 7 seconds to recover airspeed.
The aircraft speed accelerated above VMA, about 3 seconds after alpha mode activation at about 165 ft. The aircraft made a normal landing.
Approach stability
The operator’s flight data analysis software triggered 2 high RoD events during the approach at 586 ft and the second at 371 ft (Figure 4).
Figure 4: Flight path trajectory for VH-UQN at Rockhampton
Source: ADI occurrence flight summary, annotated by the ATSB
Data for the initial stages of the approach indicated that the aircraft was relatively stable until about 600 ft, when the aircraft’s rate of decent began to increase past 1,000 ft/min. At about 370 ft, a maximum descent rate of 1,270 ft/min was recorded as the airspeed reduced to 135 kt. This added instability to the approach, however, the descent rate was not sustained above 1,200 ft/min for greater than 6 seconds. The flight crew did not consider the momentary increases in RoD as leading to an unstable approach requiring a go-around.
Speed reduction below VMA
The FDR data indicated that, at 0957:55, the aircraft’s airspeed reduced below the VMA of 132 kt and continued to reduce to the lowest recorded speed of 127 kt about 3 seconds later, about 5 kt below VMA. The activation of alpha mode increased thrust, and airspeed increased above VMA about 3 seconds later.
The F100 Aircraft Operations Manual, section 1.18.04 (Version 11, Issue 3 Page 2) detailed a caution relating to the activation of alpha mode with low thrust settings:
CAUTION:
When ATS engages as a result of alpha mode activation with the engines spooled down or in case of a high deceleration rate, the speed may fall well below VMA before the aircraft starts to accelerate.
Meteorological information
Forecast conditions
Prior to departure, the flight crew reviewed the operator’s pre-flight briefing documents and accessed the weather forecasts from the national aeronautical information processing system[13] on an iPad. The Bureau of Meteorology graphical area forecast for Rockhampton indicated reduced visibility down to 4,000 m in isolated smoke with moderate turbulence below 10,000 ft in thermals. Low-level, the grid-point wind and temperature forecast indicated a wind strength of about 15 kt from the south-south-east, changing to a north-westerly at about 10 kt. The forecast en route conditions were consistent with the flight crew’s recollections on the day.
Actual weather conditions
Prior to landing at Rockhampton, the flight crew obtained the local weather from the automatic terminal information service,[14] which indicated visibility of 5,000 m in smoke. The flight crew further stated that 3,600 m was the minimum visibility required for landing. They reported that the flight conditions on previous sectors that day had been affected by reduced visibility from smoke haze over most of south-east Queensland.
The flight crew reported no significant turbulence at higher altitudes. However, on final approach, they reported that the turbulence increased as the aircraft descended, and continued until after the approach minima where moderate turbulence was experienced. The captain described moderate turbulence as being ‘physically moved around in your seat’ with fluctuating airspeed and vertical speed indications on the aircraft instrumentation.
Bushfires and visibility
Heightened bushfire activity had been present for a number of weeks across south-east Queensland. Some effects such as reduced visibility from smoke, remained an ongoing challenge for aircraft operators during that time.
The flight crew reported sighting a number of bushfires in the vicinity of the airport. One was located about 1 km to the north-west of the airport, with further larger fires to the south-west as they approached Rockhampton. As the flight crew made their final approach to land, the north‑westerly wind strengthened with an associated wind change, and localised smoke began drifting across the runway.
The flight crew recalled that, as the aircraft descended through about 1,400 ft, the effects of increasing wind were felt, and approaching about 560 ft, slant visibility began to deteriorate with smoke discolouring the precision approach path indicator (PAPI). The flight crew stated that they received reduced vertical visual cues on approach to the runway, however, the runway lights remained visible throughout the entire approach.
Convective turbulence
Convective turbulence can be described as rising warm or hot air creating unstable atmospheric conditions. It can be created by the normal heating of air over the earth’s surface or by the hot air from a bushfire or combustion process. Heated air is less dense than the cooler air around it and rises. Cooler air will rush in underneath to fill this void also producing wind changes and air turbulence. These updrafts of hot air and downdrafts of cooler air can produce gusty fluctuations in vertical and horizontal air masses, causing in-flight turbulence.
Airport information
Precision approach path indicators
Rockhampton Airport was equipped with precision approach path indicators (PAPI), which are an array of lights located beside the runway providing visual reference and vertical guidance to pilots up to 20 NM (37 km) from the runway at night, right down to landing (Figure 5).
The PAPI lights are normally located abeam the 1,500 ft runway markers and are characterised by 4 high intensity light beams with coloured filters. Dependent on the aircraft’s vertical profile, the pilot would see either red or white lights. A normal 3° approach path would be identified by equal numbers of red and white lights. If the aircraft was below the glideslope, there would be more red lights than white, and above glideslope, more white lights than red would be displayed.
The PAPI light display is susceptible to the line-of-sight limitations of distance and visibility. The presence of smoke is likely to discolour the light array and make distinguishing colour from red to white difficult (Aeronautical Research Labratories, 1981).
Figure 5: PAPI light indications
Source: ATSB
Safety management systems
High and low-capacity regular public transport operator certificate holders in Australia are required to manage the safety of their operations on a day-to-day basis. Part of this responsibility falls within a safety management system (SMS), which requires a systemic approach to setting policy and safety objectives, to manage safety risk, provide safety assurance, and to communicate safety outcomes within the organisation.
Safety assurance is one key component of an SMS and relies upon the systematic monitoring and measurement of the operator’s safety performance and evaluating safety management processes and practices. Safety assurance provides demonstrable safety outcomes from the SMS and enables benchmarking to provide verifiable organisational performance to an acceptable level of safety.
Organisations experience change due to a number of factors such as business improvements that may result in changes to internal systems and processes or procedures. As stated by the International Civil Aviation Organization (2018), these changes may:
…affect the effectiveness of existing safety risk controls. In addition, new hazards and related safety risks may be inadvertently introduced into an operation when change occurs. Hazards should be identified and related safety risks assessed and controlled as defined in the organization’s existing hazard identification or SRM [safety risk management] procedures.
Organisational information
Safety occurrence reporting
Reporting process
The operator’s safety department was responsible for the reporting of regulatory and safety related information to government departments such as the Civil Aviation Safety Authority (CASA) and ATSB. In the instance of an ATSB immediately or routine reportable matter,[15] defined under the Transport Safety Investigation Act 2003 and Regulations (2003), a responsible person who had knowledge of the reportable matter was to provide a written report to the ATSB within 72 hours from the time of the occurrence.
Incident and accident reports were submitted electronically through the operator’s reporting system and reviewed by the safety department. Occurrence data collected under the reporting system was used to identify developing trends and to provide safety management oversight of the airline’s operations. The reports were then distributed to subject matter experts in different departments for feedback and validation. Once validated, the safety department consolidated the departmental responses and then provided an organisational response to CASA and the ATSB.
This incident was reported through the safety reporting system by the captain 2 days after, on 12 November 2019. However, the report was overlooked within the reporting system until 16 November 2019. The ATSB received the report from the operator on 19 November 2019, 9 days after the incident.
Changes to the safety occurrence reporting system
A new safety reporting system was implemented in June 2019, as the operator transitioned safety management system software providers to a new supplier. The web-based system was designed to provide safety management support for airlines and other aviation organisations. The SSM described the new system as a:
…fairly intuitive and accountable system where nothing could be purposely hidden or changed within the system unless the change was recorded and justified.
One unique element of the system was the electronic tracking of occurrences and reports as they were reported online through the safety systems portal. Once logged, each occurrence had a unique identifier and started a virtual 72-hour countdown timer (Figure 7) to track the assessment, validation, and reporting of each occurrence. Primarily, this was to ensure safety assurance action within the prescribed period of an ATSB reportable matter.
The timer initially appeared yellow and then progressively changed to red indicating the time remaining for the submission of the written report to the ATSB. Once completely red, the report was overdue to the ATSB. The countdown timer offered a dashboard review screen where multiple occurrences could be reviewed in a date-based order.
Figure 6: Safety management reporting system 72-hour countdown timer
Source: Operator
When a report had been submitted to the ATSB, the timer was removed. However, for reports that did not require notification to the ATSB, the timer remained and appeared red until it had been validated. The operator indicated that these reports could potentially take several days to validate. As such, multiple reports with red timers would be visible on the dashboard. However, if a report was submitted late, as was the case for this incident, the report would appear in the list below other reports that had already been processed. With this setup, there was no obvious indication that a late report had not been submitted and was outstanding for ATSB reporting.
Another key element of the introduction of the web-based safety reporting system was that this enabled safety reporting from employees using mobile platforms such as crew iPads, thus enhancing the timeliness and ease of reporting.
Changes in internal processes
The SSM identified that any change to a key system introduces risk. The introduction of the new reporting system required significant redevelopment of organisational process, manuals and supporting guidance documents. Some of these changes were yet to be fully implemented into the internal safety systems standard operating procedures at the time of the incident. One such procedure was related to the operator’s process for providing further information to external requests received from the ATSB and CASA.
Part of the introduction also included educating staff on the new system and required changes to work practices. This included dissemination of information, the briefing of operational departments, and staff education on changes to internal manuals and documented processes. During this time, the SSM and the ASSM had been employed for a period of less than 6 months and were responsible for the implementation of much of this work to support the new safety reporting system changes.
Key safety post holder positions
Safety systems manager
The safety systems manager (SSM) began working with the operator in July 2019 and was responsible for the day-to-day management of the SMS as well as the safety reporting system. They were also responsible for the implementation and integration of the new safety reporting system, and the procedures and supporting guidance documentation. At the time of the incident, the SSM was on leave for 3 weeks and was not contactable. The SSM role was passed on to the acting SSM (ASSM).
Acting safety systems manager
The ASSM started with the operator in June 2019, in the substantiative position of safety and quality manager. This position entailed responsibility for dangerous goods, work health and safety, environment, and emergency response. The ASSM was also identified by CASA as an alternate postholder for the SSM position and provided support to the SSM position when required.
The ASSM stated that there was an expectation that extra duties would be accommodated by staff, in addition to their existing duties. Therefore, during the period as ASSM, they were still required to conduct their normal role in addition to the tasks of the SSM. The ASSM reported that part of their substantive role required travel to remote mine sites to conduct audits. They advised that they had travelled from Brisbane to Adelaide for the week of the handover from the SSM and then travelled to a north-western Australian mine site for 4 days, which had intermittent internet access and mobile phone coverage.
Handover of safety systems manager role
On 1 November 2019, the SSM sent an email to internal staff, notifying them that the ASSM would be acting in the position until 21 November 2019. CASA was also advised by the SSM of the same absence.
The SSM recalled that there was no formal handover or training undertaken for the acting role, and that a brief discussion was held relating to the internal operating procedure of checking the safety reporting system every 12 hours. The ASSM also recalled not receiving a formal handover, however, recalled receiving an email with a number of tasks to complete shortly before departing for the 4-day audit.
The SSM was unaware that the ASSM was planning to be away travelling during the time required to fulfil the role of ASSM. The SSM also remarked that, while not against company policy, this situation was most likely not optimal as the ASSM role required access to a computer, and a reliable internet and phone connection to work effectively while remotely based.
Changes in key positions
Prior to the incident, the SSM had been in the role for about 5 months before going on leave and passing the role to the ASSM. The ASSM had been in their substantive role for about 6 months before acting in the role of SSM as an alternate post holder. This was the first time the ASSM had conducted this role.
The overall quality manager was reported to have been in the position for a couple of years and the general manager was reported to have been in that position for about 20 months.
Organisational and role assimilation
Successful integration of a new staff member into an organisation is referred to as organisational assimilation and it consists of a number of factors including learning how to interact with new co-workers, understanding organisational norms, adjustment of the employee’s expectations around involvement in the organisation and adaption to the new role (Myer & Oetzel, 2003). New employees may adapt their expectations of the new role based on their previous experiences.
Both organisational and role assimilation is dependent on the individual’s previous experiences and how different they find the new role and the organisation. Generally, the longer the employee has been with the organisation, then the greater the time the employee has to adjust their expectations of the role, to conform to the requirements of the organisation.
Likewise, the time taken by an employee to assimilate into a new role and organisation, while substantial, cannot be quantified. This remains subject to the individual’s ability to make sense of
the new role and organisation (Weick, 1995) and relies on their will and ability to adapt in order to attain the required competency.
Related occurrences
Perceived thrust levers being stuck during alpha mode
In 2009, another Australian operator of Fokker 100 aircraft had an event during the base leg of an approach. The crew reported that when they attempted to increase thrust, they found that the thrust levers appeared to be blocked. After about 5 seconds, they were able to push the thrust levers forward, using a much greater force than normal to overcome the autothrottle system, by which time the airspeed had decreased to VMA. Subsequent investigation by the operator identified no technical problems with the aircraft.
As a result of the event, that operator developed educational material to support cyclic training, specifically covering alpha mode indications and thrust lever blockage.
In 2014, the same operator had a different operational occurrence in which the crew correctly recognised an alpha mode activation. Further information was then also provided to the operator’s crew on specific combinations of automation modes likely to result in the activation of the alpha mode function.
The other Australian operator subsequently advised the ATSB that this information about alpha mode activation was incorporated into its initial Fokker 100 pilot type rating ground school training material as well as its recurrent ground and simulator training.
On 25 June 2013, the flight crew of an Airbus A320-232 aircraft were conducting an instrument landing system approach with autoland training at Sydney Airport, New South Wales. During the approach, the training captain (pilot flying) disconnected the autothrust system by retarding the thrust levers to the IDLE STOP and asked the FO to assess the effect on the proposed approach. After briefly referring to the Quick Reference Handbook, the flight crew extended the landing gear and wing flap and finalised the pre-landing checklist. The flight crew then became involved in a discussion about the requirements in the handbook for the proposed approach.
With engine thrust at idle and the aircraft in a high drag configuration, the airspeed quickly reduced to below the minimum approach speed. The captain was in the process of applying thrust when the aircraft’s alpha-floor protection system activated. TOGA thrust was automatically commanded by this system and the flight crew conducted a missed approach.
The ATSB found that, during an autoland training exercise with the autothrust disengaged, both pilots were distracted by their consideration of a training scenario. As a result, they did not identify the airspeed reducing below the target approach speed in sufficient time to prevent activation of the aircraft’s alpha-floor protection system.
On 7 September 2013, an Airbus A320 aircraft, was on descent into Auckland, New Zealand via a required navigation performance approach to runway 23 Left. During the later stages of their descent, the flight crew managed the aircraft speed to meet an air traffic control request and according to applicable company speed restrictions.
The auto-flight system sequenced to final approach mode passing about 4,200 ft, but exited final approach mode when the flight crew subsequently levelled the aircraft approaching 3,000 ft. The flight crew levelled the aircraft to reduce speed to comply with a company speed restriction of 210 kt maximum below 3,000 ft. Having slowed sufficiently, subsequent manipulation of the auto‑flight system resulted in the inadvertent engagement of open climb mode, which resulted in an increase in engine thrust and aircraft acceleration.
Attempting to avoid exceeding the limiting speed applicable to the existing aircraft configuration, the captain retarded the thrust levers to the idle stop, inadvertently disconnecting the auto-thrust system. The flight crew resumed the approach, unaware that the auto-thrust system was disconnected, and therefore no longer controlling aircraft speed. As the aircraft continued to decelerate, soon after the final stage of flap was selected for landing, the flight management guidance system generated a low energy warning. As the flight crew was responding to the low‑energy warning, alpha-floor auto-thrust mode engaged. The flight crew accelerated the aircraft to approach speed using manual thrust control and was able to continue the approach for an uneventful landing.
The operator made findings with respect to flight crew communication, aircraft energy state monitoring, wider automation management and mode awareness issues, and the procedures governing the reinstatement of aircraft control following intervention by the pilot not flying. The operator also found that there may be some commonly held misunderstandings with respect to some aspects of the instrument approach procedures.
While on final approach to runway 33 at Rockhampton Airport, the aircraft became slightly high on approach. Attempted corrections by the first officer (FO) to regain the approach path resulted in the aircraft entering a low speed/low thrust configuration, which activated the alpha mode protection. In response, the flight crew attempted to increase thrust, but the thrust levers appeared to be ‘blocked’. The FO forcibly moved the thrust levers and the aircraft was subsequently landed safely.
A post-flight engineering assessment found no evidence to indicate a technical problem, or failure of any of the mechanical components in the system, which may have led to the blocked thrust levers or inadvertent activation of alpha mode.
This analysis will consider the circumstances that preceded the incident, including weather, visibility, flight crew training, and stability of the approach. Changes to key safety management reporting systems and safety personnel, as well as post-incident circumstances such as organisational delays and the management of safety reporting, will also be discussed.
High approach profile
On the day of the incident, the southern Queensland aviation network was affected by widespread reductions in visibility due to bushfire generated smoke haze. Additionally, the Rockhampton area was impacted by moderate, low-level, convective turbulence from localised bushfires.
During descent at night into the strengthening north-westerly wind, the aircraft was buffeted by rising hot air and encountered smoke from the bushfires close to Rockhampton Airport. Convective turbulence from rising and sinking air affected the aircraft’s vertical speed on the approach. Reduced visibility was encountered on final approach as smoke discoloured the runway lighting and precision approach path indicators (PAPI), rendering the vertical approach guidance lights temporarily unusable.
During the late stages of the approach, the flight crew reported that, at about 400 ft, the smoke discolouration of the PAPI lights reduced and they identified that they were slightly high on the approach profile. The aircraft’s airspeed and vertical approach profile was affected by convective turbulence from a local bushfire, impacting the flight crew’s ability to maintain the approach path.
The FO reduced the thrust setting and lowered the nose of the aircraft to correct for being slightly high on the approach path. This, coupled with convective turbulence, very likely resulted in an increased rate of descent and subsequent airspeed reduction towards the minimum approach speed (VMA).
High descent rate
Flight crew reaction to changing in-flight performance, requires them to identify a parameter change is occurring, decide to apply correction, apply the correction technique, monitor the correction for change against the parameter, identify that the desired parameter has been regained, reduce corrective input, and monitor for change.
The aircraft’s flight data noted 2 high rate of descent events when below 600 ft on approach, with a maximum rate of about 1,200 ft/min for a short period of time. This exceeded the operator’s stable approach criteria, which required a rate of less than 1,000 ft/min. The identification of the high descent rate may not have been as immediate as the data suggested, as the flight crew were in the higher workload phase of landing in challenging conditions. Granularity of the vertical speed indicator increments, abbreviated vertical speed readout and display layout most likely affected the flight crew’s ability to readily identify the increased rate of descent above 1,000 ft/min. This required greater attentional resources to identify, correct and monitor the rate than the flight crew had available with the late PAPI identification (as the smoke cleared) of the slightly high approach profile while entering convective turbulence.
Low airspeed management
While on final approach, the FO overrode the autothrottle system, manually reduced the thrust setting and lowered the nose of the aircraft to correct for being slightly high on the approach path. This, combined with the convective turbulence from the bushfire, resulted in a fluctuating rate of descent, peaking at about 1,200 ft/min for about 6 seconds. The recorded flight data showed that the airspeed decreased below the minimum approach speed (VMA). As a result of the low speed, low thrust condition, alpha mode activated at 203 ft.
Consequently, after the captain’s second ‘speed’ call, the FO had to forcibly move the thrust levers forward to counteract the thrust lever resistance, as a result of alpha mode activation. The alpha mode activation combined with flight crew’s actions resulted in the aircraft responding to the increased thrust.
The airspeed increased above the VMA about 3 seconds after alpha mode activated. Alpha mode then disengaged, allowing free movement of the thrust levers, which may explain why the FO described experiencing a reduction in thrust lever resistance. While the airspeed reduced to 5 kt below VMA for 1 second, the airspeed remained above the stall speed by about 27 kt before recovering, and a normal landing made.
Mode confusion
During the approach to land, both pilots identified the deceasing airspeed and attempted to rectify this. However, neither recognised that alpha mode had activated. The FO had identified that the thrust levers appeared blocked but could not identify why this occurred. Consequently, they continued to force the thrust levers forward, without knowing that the alpha mode system was actively increasing thrust to recover airspeed. The flight crew continued the approach and considered that the conduct of a go-around may place the aircraft in a nose high, slow speed condition without the sufficient thrust, thereby increasing the risk of loss of control.
After an uneventful landing, the flight crew discounted the possibility of an alpha mode activation as they recalled that the airspeed had not reduced below the minimum approach speed. Mode awareness is a type of situational awareness based on the pilot’s understanding of aircraft configuration and flight control system modes. Being aware of the active mode(s) and understanding the corresponding actions and responses is necessary for proper use of the autoflight system. Ineffective auto-flight system mode awareness has been identified as a contributing factor in many occurrences since the introduction of complex auto-flight systems (United States Federal Aviation Administration, 1996).
Flight crew training on alpha mode
As per the operator’s standard practice, the flight crew had been checked as competent on their understanding of alpha mode during their initial aircraft type training. However, the simulator demonstration was conducted at altitude and did not include elements of competency relating to alpha mode activation in different flight configurations and states, or at critical times such as final approach. Further, the training did not include the higher force caused by the dynamic rod lockout, which was only applicable to the operator’s F100 fleet. The operator’s flight crew may operate both variants at different times.
In addition to the initial training, flight crews were not routinely assessed on alpha mode during cyclic training. Recurrent or cyclic training was a mechanism for developing and assessing flight crew performance across a range of necessary competencies. This ensured that each crew member was adequately trained and proficient for the aircraft type and their position held. As highlighted by the Civil Aviation Safety Authority, recurrent or cyclic training assists with the prevention of the degradation of critical skills over time.
In this case, it had been more than 1–2 years since the flight crew had completed their initial type training for the F100, noting that this did not capture all aspects regarding alpha mode. As such, the flight crew were not aware that alpha mode activation could occur above the minimum approach speed in different aircraft states, or that thrust lever resistance would be experienced when in this mode. Therefore, the initial type qualification training on the F100 did not adequately prepare pilots to recognise and recover from an alpha mode activation during a critical phase of flight, such as during approach to land. Also, there was no further cyclic training in relation to alpha mode activation and procedures to support flight crew decision making when such an activation occurred.
Stabilised approach criteria
The operator’s criteria for stabilised approach was reviewed and found to be consistent with the International Civil Aviation Organization (ICAO) recognised standard operating procedures. The operator provided this information to flight crew by publication in the Operations Policy and Procedures Manual – Standard operating procedures.
The review of other operators’ manuals found that their procedures allowed for momentary exceedances of the stabilised approach criteria. This allowed flight crew to continue an approach with some flexibility to external environmental influences. The operator’s published stabilised approach criteria did not reflect this flexibility, and the operator’s internal investigation did not consider the approach to be unstable and no further mention of the stabilised approach criteria was identified.
New safety reporting system
The operator’s newly introduced safety reporting system displayed submitted reports on a dashboard in date and time order and assigned a visual coloured 72-hour countdown timer to aid in tracking. This visual tool was displayed against all submitted reports, not just those required to be notified to the ATSB. However, due to the design of the system, ATSB notifiable reports that were submitted late would not only have appeared further down the list but appeared overdue. Similarly, other occurrences that did not require reporting to the ATSB, however required validation by the relevant department responsible managers, would have also appeared overdue.
As previously mentioned, safety reporting systems are an essential tool within a safety management system for gathering valuable safety information. This information could be used for identifying occurrences that required further investigation, for discovering lessons learnt, and for providing a useful source of information for hazard identification. However, this was reliant on a system design that was effective.
In this case, when the captain’s safety report was submitted about 2 days after the incident, it was not likely displayed on the initial dashboard screen due to the date order and it would have been listed below already overdue reports. This meant that it would not have been clearly visible to the safety department staff. This system characteristic was not identified prior to this incident, which made identification and subsequent report tracking more difficult for the safety department. In turn, this did not allow for the effective prioritisation of submitted safety reports.
Organisational change
There had been a significant turnover of staff within the operator’s safety department prior to the incident, with a number of key staff having only been in their respective positions for less than 6 months. This coincided with the introduction of the new safety reporting system. This reduced short-term organisational memory relating to the introduction of the new system, and came at an important stage of system implementation, with the redevelopment of new supporting processes under the operator’s standard operating procedures. This required increased education to the operator’s staff on the use of the new system, by the safety systems department. This likely affected the safety systems manager (SSM) and the acting SSM (ASSM), with increased tasks and workload during a period of organisational and role assimilation within the operator.
The ASSM was approved as the alternate postholder position for the SSM. However, having not previously acted in the role, and with a limited handover, it was unlikely that the ASSM was able to adequately fulfil the requirements of this role in addition to their ordinary workload and remote duties.
Implementation of supporting processes into the operator’s standard operating procedures for the new safety reporting system relied on the SSM to review and make changes to the existing organisational process. However, all procedures had not yet been finalised, in particular, that relating to further requests for information for immediately and routine reportable matters to the ATSB. Therefore, there was little guidance available to the ASSM regarding ATSB reporting.
Safety assurance is a key component of a safety management system. Of particular importance are changes to internal systems and processes or procedures. As previously highlighted by the International Civil Aviation Organization, such changes could inadvertently introduce new hazards and associated risks to an operation. The system change, coupled with new employees in the safety department, and the redevelopment of internal processes, did not identify the visual display deficiencies and possible unintended outcomes of the new safety reporting system. This increased the safety department’s workload and introduced an increased risk of some reports not being appropriately classified, reported, or acted upon in a timely manner.
Findings
ATSB investigation report findings focus on safety factors (that is, occurrences and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the operational event involving a Fokker F28-Mk0100, VH-UQN, at Rockhampton, Queensland, on 10 November 2019. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Contributing factors
On final approach to land at Rockhampton Airport, reduced visibility and turbulence from a bushfire added uncertainty and late identification of a high approach profile.
On final approach, the flight crew experienced a low airspeed management event.
The operator’s training for the Fokker F28-Mk0100 did not prepare pilots for alpha mode activation during critical phases of flight. (Safety issue)
The flight crew were unaware the alpha mode had activated, resulting in mode confusion prior to and after they advanced the thrust levers on final approach.
Other factors that increased risk
On short final, the aircraft's rate of descent increased beyond the operator's stable approach criteria. The crew did not consider that the approach was unstable and continued the approach due to perceived blocked thrust levers, and possible adverse consequences of conducting a go-around.
Changes in the operator's key safety post holder positions, safety reporting systems and internal processes reduced effective safety assurance. (Safety issue)
The operator’s safety management reporting system did not enable the effective prioritisation of submitted safety reports. (Safety issue)
Other key findings
Although the operator provided guidance to flight crews about the stable approach criteria, it did not specifically permit transient exceedances of the set criteria.
Associated with a number of reasons, there was a significant delay in the occurrence (which was a routinely reportable matter) being reported to the ATSB.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety management reporting system
Safety issue number: AO-2019-063-SI-01 Safety issue description: The operator’s safety management reporting system did not enable the effective prioritisation of submitted safety reports.
Flight crew training
Safety issue number: AO-2019-063-SI-02 Safety issue description:The operator’s training for the Fokker F28-Mk0100 did not prepare pilots for alpha mode activation during critical phases of flight.
Organisational change
Safety issue number: AO-2019-063-SI-03 Safety issue description: Changes in the operator's key safety post holder positions, safety reporting systems and internal processes reduced effective safety assurance.
Safety action not associated with an identified safety issue
Additional safety action Alliance Airlines
The operator advised that an update to its stabilisation policy and associated criteria was being conducted and this will also introduce guidance on transient exceedances of the criteria.
Glossary
AFCAS
Automatic flight control and augmentation system
ASSM
Acting safety systems manager
ATIS
Automatic terminal information system
ATS
Autothrottle system
CASA
Civil Aviation Safety Authority
EST
Eastern Standard Time
FAA
United States Federal Aviation Administration
FDR
Flight data recorder
FO
First officer
ICAO
International Civil Aviation Organization
IMC
Instrument meteorological condition
PF
Pilot flying
PM
Pilot monitoring
PAPI
Precision approach path indicator
NAIPS
National aeronautical information processing system
RNP
Required navigation performance
RoD
Rate of descent
SOP
Standard operating procedure
SSM
Safety systems manager
TLA
Thrust lever angle
TOGA
Take-off/go-around
UTC
Coordinated universal time
VMC
Visual meteorological condition
VMA
Minimum allowable airspeed
Sources and submissions
Sources of information
The sources of information during the investigation included:
The flight crew
Alliance Airlines PTY Limited
Virgin Australia Regional Airlines
the aircraft type certificate holder
the recorded flight data
Civil Aviation Safety Authority
Bureau of Meteorology
Airservices Australia.
References
Aeronautical Research Laboratories. (1981). Hazards of colour coding in visual approach slope indicators. Melbourne: Aeronautical Research Laboratories.
International Civil Aviation Organization. (2018). Safety Management Manual (Doc 9859). Montreal, Canada: International Civil Aviation Organization.
International Civil Aviation Organization. (2015). LOC-1/CFIT-2 Safety enhancement initiative:Model advisory circular for air operators – standard operating procedures for flight deck crewmembers.
Myer, K. K., & Oetzel, J. G. (2003). Exploring the dimensions of organizational assimilation: Creating and validating a measure. Communication Quarterly, 438-457.
Weick, K. (1995). Sensemaking in organisations. Thousand Oaks, CA: Sage.
United States Federal Aviation Administration. (2003). Advisory Circular 120-71A. In Standard Operating procedures for flight deck crewmember (pp. 14-15). Washington: Federal Aviation Administration.
United States Federal Aviation Administration. (1996). The Interfaces between Flightcrews and Modern Flight Deck Systems. Washington: Federal Aviation Administration.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Alliance Airlines PTY Ltd
the flight crew
the acting safety systems manager
the safety systems manager
Fokker Services and Dutch Safety Board
the Civil Aviation Safety Authority
the Bureau of Meteorology.
Submissions were received from Alliance Airlines PTY Ltd, the captain, the safety systems manager and Fokker Services. The submissions were reviewed and, where considered appropriate, the text of the final report was be amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the morning of 4 November 2019, an Airbus A320-200 aircraft, registered VH-VQG (VQG), was operating a scheduled passenger flight from Sydney, New South Wales, to Sunshine Coast, Queensland (Qld). As the aircraft was on final approach to land, a proximity event occurred with an Aero Commander 500 aircraft, registered VH-UJS (UJS), which was departing Sunshine Coast Airport on the reciprocal runway. The two aircraft paths converged, until the pilot of UJS conducted a right turn and increased the separation between them. The flight crew of VQG continued the approach and UJS continued to Maryborough, Qld, without further incident. The time of the incident was outside the operating hours of Sunshine Coast Airport air traffic control tower and it was therefore operating as a non-controlled aerodrome.
What the ATSB found
The ATSB found that important radio broadcasts made on the common traffic advisory frequency (CTAF) were not heard by the flight crew of VQG and the pilot of UJS regarding each other’s position and intention. These included the inbound broadcasts made by VQG and the take-off broadcast made by UJS. In addition, the flight crew of VQG determined the most suitable runway based on the radio-transmitted aerodrome weather information service. However, this was either recorded incorrectly or heard incorrectly such that the chosen runway was the less favourable of the two options for the wind direction. This resulted in the aircraft approaching the opposite runway to other aircraft at the time. Finally, the pilot of the departing aircraft did not confirm the location and intention of the inbound aircraft prior to commencing take-off, as it was assumed the inbound aircraft would use the most suitable runway for the conditions.
Safety message
When operating in uncontrolled airspace and around non-towered aerodromes, it is important to ensure that the location and intention of surrounding traffic is well understood and communicated prior to commencing take-off or landing.
The ATSB SafetyWatch highlights the broad safety concerns that come out of our investigation findings and from the occurrence data reported to us by industry. One of the safety concerns is safety around non-controlled aerodromes. The ATSB SafetyWatch page provides information and resources about staying safe around non-controlled aerodromes. In addition, the ATSB booklet A pilot’s guide to staying safe in the vicinity of non-controlled aerodromes outlines many of the common problems that occur at non-controlled aerodromes, and offers useful strategies to keep yourself and other pilots safe.
The Civil Aviation Safety Authority has also produced a resource booklet ‘be heard, be seen, be safe’ which is in relation to radio procedures in uncontrolled airspace, and highlights that radios must always be used in conjunction with a safe ‘see-and-avoid’ procedure.
The occurrence
What happened
On the morning of 4 November 2019, the flight crew of an Airbus A320-200 aircraft, registered VH-VQG (VQG) and operated by Jetstar Airways, were conducting a scheduled passenger flight from Sydney, New South Wales, to Sunshine Coast, Queensland (Qld).
Prior to commencing the descent, both flight crewmembers of VQG independently listened to the Aerodrome Weather Information Service (AWIS) for Sunshine Coast Airport. Both reported hearing that the wind was from 230° (Magnetic) at 6 or 7 kt and recorded it on the take-off and landing data card. Based on those wind conditions, they assessed that runway 18 would be the most suitable runway for landing as it was the most into wind. The flight crew noted that the wind direction from the AWIS differed from the aerodrome forecast and routine aerodrome weather report[1] they had obtained prior to the flight, which was 340° True (329° Magnetic), but assessed that was reasonable for a coastal aerodrome. The flight crew then calculated the landing data using their electronic flight bag[2] software. In accordance with normal procedures, they assessed that for the aircraft landing weight and runway length available they could safely land with a tailwind of up to 10 kt if necessary.
At 0622 Eastern Standard Time (EST),[3] the flight crew of VQG contacted Brisbane Centre air traffic control (ATC) to advise that they were on descent to flight level 130[4] and on approach to Sunshine Coast Airport. As this was outside Sunshine Coast ATC Tower operating hours, the airspace was Class G (uncontrolled) and pilots of aircraft in the vicinity of the airport were communicating on the common traffic advisory frequency (CTAF).[5] Pilots conducting flights under the instrument flight rules (IFR) were also required to report to Brisbane Centre on a different frequency. Brisbane Centre provided a traffic information service to IFR flights about other conflicting IFR aircraft and observed (known) visual flight rules flights. Therefore, the VQG flight crew had one radio on the CTAF and another on the Brisbane Centre frequency, which allowed them to hear both frequencies.
At about 0625, the first officer (FO) who was the pilot monitoring (PM),[6] broadcast on the CTAF stating they were 30 NM south of the field, at an altitude of 10,500 ft and were tracking for a left circuit for runway 18[7] with an estimated arrival time of 0636 at Sunshine Coast. About 2 minutes later the PM made a similar broadcast on the CTAF, with updated altitude and position, again stating their intention to land on runway 18. During that time, the flight crew of VQG were also communicating with the pilot of another aircraft operating to the south of Sunshine Coast Airport who agreed to hold to the south of the field until VQG had landed.
A few minutes later, at about 0631, the PM made a third broadcast on the CTAF stating their altitude, position and intention to land on runway 18.
About 25 seconds later, the pilot of an Aero Commander 500 aircraft, registered VH-UJS (UJS) and operated by General Aviation Maintenance as a freight charter flight, broadcast on the CTAF that he was taxiing for runway 36 at Sunshine Coast Airport. The planned flight was from Sunshine Coast to Maryborough, Qld. Shortly after, the pilot of UJS also contacted Brisbane Centre stating that UJS was taxiing for runway 36. Brisbane Centre responded, advising of the inbound aircraft (VQG) that was turning onto final for approach from the north-east, ‘landing about 36’.[8] Brisbane Centre did not stipulate the runway being used by VQG, nor were they required to. The pilot of UJS later reported that he had observed other aircraft using runway 36 while he was refuelling at Sunshine Coast Airport, and that it usually takes him around 3 minutes on average from start up with his radios on, to being airborne.
At about the same time, the PM of VQG was communicating on the CTAF with the pilot of an aircraft (VH-XTU) to the north of the airport, which was identified by the flight crew of VQG as a potential conflict as per the operator’s ’Ten, Ten, One’ rule.[9] Also at that time, Brisbane Centre was attempting to contact VQG flight crew, regarding the taxiing call made by UJS, however contact was delayed as VQG was communicating on the CTAF with VH-XTU.
On entering the runway, the pilot of UJS visually checked to the south where he believed VQG was approaching from. After not visually sighting VQG, the pilot of UJS commenced take-off without making direct contact with VQG on the CTAF and confirming their location, making a ‘rolling’ (for take-off) broadcast on the CTAF at 06:33:30.
As this broadcast was being made, Brisbane Centre was still attempting to contact VQG, and the flight crew of VQG later reported not hearing the take-off broadcast made by UJS. After the communication with Brisbane Centre was established and finished, a different aircraft broadcast on the CTAF for about 20 seconds.
Once that broadcast finished, the PM of VQG broadcast on the CTAF that they were on final approach[10] for runway 18 and asked the pilot of UJS if he was holding short of the runway. The pilot of UJS responded that they were airborne, had VQG sighted and would track to VQG’s left (make a right turn). Table 1 shows a summary of the relevant radio broadcasts made on the CTAF and Brisbane Centre frequencies.
Table 1: Summary of the relevant CTAF and Brisbane Centre (shaded) radio broadcasts made by the pilots of aircraft VH-VQG and VH-UJS
Time
Frequency
Summary
0625:36
CTAF
VH-VQG first inbound broadcast
0627:11
CTAF
VH-VQG second inbound broadcast
0631:28
CTAF
VH-VQG third inbound broadcast
0631:53
CTAF
VH-UJS makes taxiing broadcast at Sunshine Coast airport
0632:24
Brisbane Centre
VH-UJS makes taxiing call, Centre informs them of inbound VH-VQG ‘turning onto final for approach’ ’about 8 miles north-east’ ’landing about 36’
0632:45 – 0633:18
CTAF
VH-VQG coordinating with VH-XTU, who was on the runway 18 Zulu approach. VH-XTU advised that they would be breaking off at the final approach fix for a circuit.
0632:58
Brisbane Centre
Centre informs VH-VQG of VH-UJS taxiing
0633:30
CTAF
VH-UJS makes ‘rolling’ broadcast from runway 36
0633:30
Brisbane Centre
Centre attempts to contact VH-VQG
0633:38
Brisbane Centre
Centre attempts to contact VH-VQG
0633:40
Brisbane Centre
VH-VQG responds they are communicating with VH-XTU on CTAF, Centre confirms they are also aware of VH-UJS, and VH-VQG responds ‘affirm’
0634:06
CTAF
Another aircraft is broadcasting their position and intention
0634:35
CTAF
VH-VQG broadcasts they are turning 5 mile final runway 18 and queries if VH-UJS is holding short of the runway
0634:48
CTAF
VH-UJS responds ‘negative, airborne’ and that he had VH-VQG sighted and would track to their (VH-VQG’s) left
Source: Airservices Australia and AvData, summarised by the ATSB
Within seconds, a short-term conflict alert (STCA) for the two aircraft was presented on the Brisbane Centre display (Figure 1). The two aircraft passed each other with a recorded separation of 0.7 NM horizontally and 265 ft vertically.
Figure 1: The position of the aircraft in the area in relation to Sunshine Coast Airport, and the alerts that were displayed to Brisbane Centre for the two aircraft VH-UJS and VH-VQG. The aircraft to the north, VH-XTU, is also shown.
Source: Airservices Australia, annotated by the ATSB
The flight crew of VQG discussed conducting a missed approach as a result of the proximity event. However, they assessed it was safer to continue with the approach due to the other aircraft in the area that they had already de-conflicted with, and although there was a tailwind, it was assessed as within tolerance. At about 0637, VQG landed at Sunshine Coast Airport and UJS continued to Maryborough without further incident.
In this occurrence, VQG was fitted with a functional traffic collision avoidance system (TCAS).[11] However, it was inhibited (as a standard) such that when the aircraft was on descent and below 900 ft the system did not generate a resolution advisory (RA)[12] or an aural alert and all traffic, including UJS, was marked as a traffic advisory only.
Safety analysis
The pilots from both aircraft did not hear some of the important radio broadcasts made by the other aircraft regarding their location and intention and did not establish direct communications with each other until after UJS was airborne. The pilot of UJS likely did not have his radio on at the time the flight crew of VQG made their inbound radio broadcasts, therefore missing the opportunity to understand that they were intending on landing on runway 18. There was about 97 seconds between the taxi and take-off broadcasts made by UJS, reducing the amount of time available to determine the location and intention of VQG. The flight crew of VQG did not hear the rolling broadcast made by the pilot of UJS, which occurred at the same time as Brisbane Centre was contacting VQG on the Centre frequency.
It was noted that the flight crew of VQG recorded the aerodrome wind direction as 230° (Magnetic) when planning their approach. However, local aerodrome wind direction was reported as 329° (Magnetic). It is unknown if the flight crew of VQG misheard the airport weather information recording or if the recording was incorrect, as a copy of the recording was unable to be obtained. The incorrect wind information obtained or understood by the flight crew of VQG led them to plan their approach on the least favourable runway for the wind direction at the time, and in conflict with other aircraft operating in and out of the airport.
The pilot of UJS believed that VQG would be landing on runway 36, as it was the most suitable for the wind conditions at the time and other aircraft operating at the airport had been using runway 36. This resulted in the pilot of UJS relying on unalerted see and avoid, to de-conflict with the inbound VQG. This occurred after UJS became airborne and the reciprocal trajectory of VQG was observed.
Findings
From the evidence available, the following findings are made with respect to the separation issue between two aircraft, VH-UJS and VH-VQG, where VH-UJS took off from runway 36 while VH-VQG was landing on opposing runway 18, resulting in reciprocal paths for the two aircraft before the pilot of VH-UJS conducted a right turn to increase separation from VH-VQG.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Important radio broadcasts on the CTAF were not heard by the flight crew of VH-VQG and the pilot of VH-UJS regarding each other’s positions and intentions, leading to them continuing to use reciprocal runways.
The flight crew of VH-VQG assessed runway 18 as the most into wind runway based on information obtained from the aerodrome weather information service, however this information was either recorded incorrectly or heard incorrectly such that runway 36 was instead more favourable. This resulted in the aircraft approaching the opposite runway to what was being used by other aircraft at the time.
The pilot of VH-UJS commenced take-off without confirming the location and intention of VH-VQG, assuming that they would be landing on runway 36, which had been used by previous landing and departing aircraft.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 11 November 2019, at about 1510 Central Standard Time, a Bombardier DHC-8-315 aircraft, registered VH-ZZE and operated by Surveillance Australia, was about to start the take-off roll from Darwin Airport, Northern Territory, on a surveillance flight. There were four crew on board.
The aircraft was on the departure runway with the brakes on. Power was applied to both engines, but when take-off power was reached, and prior to the release of the brakes, the crew heard a loud bang. The take-off was aborted, and air traffic control advised the crew of smoke from the right engine. After reviewing the engine instrumentation, the crew shut down the engine and returned the aircraft to the maintenance hangar.
A subsequent inspection of the runway identified metal fragments behind the aircraft’s take‑off position. An external inspection of the right engine revealed significant damage to the power turbine (PT) assembly.
What the ATSB found
The PT shaft of the aircraft's right engine fractured due to fatigue cracking, resulting in secondary damage and engine failure. The fatigue cracking initiated at corrosion pitting, which was probably associated with prolonged low‑altitude operation in a marine environment.
The PT shaft originally installed in the engine was replaced during its first overhaul in 2011 due to excessive corrosion pitting. However, the finding of corrosion was not escalated by the maintenance organisation to Pratt & Whitney Canada (P&WC), possibly due to the informal reporting process at the time (this process was replaced in 2018 with formal guidance and criteria for reporting such findings).
The ATSB investigation also identified that the PT shaft in Pratt & Whitney Canada PW100 series engines operating in certain marine environments is susceptible to corrosion pitting, which can grow undetected between scheduled inspections, increasing the risk of shaft fracture and engine failure.
What has been done as a result
Pratt & Whitney Canada advised the ATSB that it had commenced a review of historical overhaul experience of the PT shaft in an effort to identify which engines and operators are potentially exposed to an increased risk of PT shaft corrosion.
In addition, P&WC has proposed a range of safety action to address the safety issue concerning corrosion-related fracture of PT shafts in PW100 series engines that should complement its formalised reporting. This includes considering a borescope inspection of the PT shaft between overhauls during hot section inspections (HSI) with defined corrosion inspection criteria. A method to remove contaminants from inside the shaft during service is also being investigated. Additional mitigating action for engines within the PW100 engine fleet that have completed an HSI but are potentially exposed to the risk of PT shaft corrosion, is also being assessed.
While the proposed actions should address the safety issue, no timeline for their implementation was provided. As such, the ATSB has issued a safety recommendation to P&WC to support the proposed action.
Safety message
The corrosion-related fracture of the power turbine shaft of the aircraft’s engine in this occurrence highlights that corrosion pitting that exceeds repair limits on safety‑critical components should be a warning sign to manufacturers, maintainers, and operators that the existing maintenance strategy may not be effective.
Additionally, manufacturers should provide guidance and criteria to maintenance organisations for assessing and reporting corrosion on safety‑critical components. This enables identification of whether the maintenance strategy is effective or if changes are required to reduce the risk of in‑service failures.
The occurrence
On 11 November 2019, at about 1510 Central Standard Time,[1] a Bombardier DHC-8-315 aircraft, registered VH-ZZE (ZZE) and operated by Surveillance Australia,[2] was about to start the take-off roll from Darwin Airport, Northern Territory, on a surveillance flight. There were four crew on board – the captain (pilot monitoring), the first officer (FO) who was the pilot flying, and two system operators.[3]
The aircraft was on the departure runway with the brakes on. Power was applied to both engines, but when take-off power was reached, and prior to the release of the brakes, the crew heard a loud bang. In response, the captain aborted the take-off, reduced both power levers to flight idle, and instructed the FO to contact air traffic control (ATC) to advise they were aborting the take-off and had an engine issue. Air traffic control acknowledged the advice and reported sighting smoke from the right engine before informing emergency services. The captain checked the right engine instrumentation and advised the crew that the torque gauge had failed, and the propeller RPM gauge indicated zero. Other indications for the gas core of the engine, such as fuel flow, appeared normal. The captain instructed the FO to shut down the engine.
After confirming the aircraft brake, hydraulic and electrical systems were functioning, the crew returned the aircraft to the maintenance hangar. A subsequent inspection of the runway by a safety car identified metal fragments behind the take-off position of ZZE.
The right engine was subsequently removed from the aircraft with an external inspection revealing that all of the second-stage power turbine (PT) blades had separated from the disk (Figure 1). The PT assembly could not be rotated but the propeller shaft turned freely.
Figure 1: Rear-view of engine showing second-stage PT damage
The aircraft, registered VH-ZZE (ZZE), formed part of the operator’s fleet of 10 DHC-8 aircraft, which provided aerial surveillance operations for the Australian Border Force. Some of the aircraft began these operations in 1996 and all were fitted with Pratt & Whitney Canada (P&WC) PW100 series engines.
Operating environment
These aircraft were used for maritime surveillance activities, which required extensive flying at low level over the sea. The elevated moisture and salt content in the air at those levels created a corrosive operating environment. The fleet accumulated approximately 15,000 hours per year, with all aircraft and engines being exposed to a marine environment for a similar amount of time.
According to P&WC, there are other PW100 series operators within the global fleet that also conducted maritime surveillance activities.
Aircraft and engine information
The aircraft was a Bombardier DHC-8-315, manufactured in 2007 and operated by Surveillance Australia since March 2008. The aircraft was fitted with two P&WC PW123E turboprop engines, which form part of the PW100 series engine family.
The PW123E engine has a compressor comprising a low pressure (LP) and a high-pressure centrifugal impeller, each driven by an independent axial turbine. In addition, there is a reverse flow annular combustor and a two-stage power turbine (PT) that provides the drive for the reduction gearbox and propeller shaft. At the time of the incident, the right engine, serial number AT0010, had accumulated 25,801.51 hours in service and 12,254.21 hours since its last overhaul.
Engine examination
The damaged engine was transported to a P&WC maintenance facility in Canada for a detailed technical examination, supervised by the Transportation Safety Board of Canada. The following is a summary of the examination’s findings.
Visual examination of the diffuser case, which contained the LP centrifugal impeller, showed corrosion at several locations (Figure 2). The LP impeller blades showed leading edge erosion.
All PT stage 1 and stage 2 blades had fractured through tensile overload (Figure 3).
The PT shaft (serial number A0030D9A) had fractured in two locations, referred to as surface ‘A’ and ‘B’ (Figure 4). Visual examination of the inner diameter next to surface A indicated corrosion pitting (Figure 5).
No. 6 and No. 7 bearing oil transfer tubes had evidence of impact damage, and the vent transfer tube was fractured.
The turbine interstage baffle was found buckled.
The LP turbine disk assembly showed rubbing and cracks at the blade tips.
The PT stator and vane ring exhibited impact damage.
The exhaust case was deformed.
Figure 2: Diffuser case showing areas of corrosion
Source: P&WC, annotated by ATSB
Figure 3: Power turbine disk assemblies with all blades fractured
Source: P&WC, annotated by ATSB
Figure 4: Fractured PT shaft
Circled locations A and B refer to the two different fracture surfaces. Source: P&WC
Figure 5: Corrosion pitting of PT shaft internal diameter next to fracture surface A
Source: P&WC, annotated by ATSB
Metallurgical analysis
Following the engine examination, P&WC conducted a metallurgical analysis on the PT shaft which found that:
Fatigue cracks had initiated from corrosion pits on fracture surface A. Due to the corrosion, the material thickness was 25 per cent below the minimum thickness requirement.
The base material (steel alloy) and its hardness were consistent with the design specification.
The corroded layer near the fracture origin showed the presence of sodium, phosphorus, sulphur, and chlorine.
Fracture surface B showed evidence of bending (as opposed to torsional) overload fracture.
The analysis concluded that the PT shaft had fractured from fatigue cracking, which initiated at the internal corrosion pitting at surface A. The fracture of the shaft at surface B was considered secondary. After the shaft fractured, the PT stage 1 and stage 2 disks moved backwards. The stage 1 disk subsequently went into an overspeed condition, which caused the blades to fracture by tensile overload near each blade platform as designed.[4] The stage 2 disk contacted the exhaust duct, resulting in the blades fracturing through tensile overload, at various heights above the blade platforms, from impact and overspeed.
The damage to the bearing oil transfer tubes, turbine interstage baffle, PT stator, PT vane ring, exhaust case and LP turbine disk assembly were consistent with secondary damage due to the PT shaft fracture. According to P&WC, the LP impeller leading edge erosion, diffuser corrosion and PT shaft corrosion was due the engine’s operational environment.
Power turbine air system and corrosion protection
During normal engine operation, some of the air flowing through the compressor is delivered to the inside of the PT shaft via internal and external tubes. This air is used to seal bearings and cool the PT stage 1 and stage 2 disks (Figure 6).
Figure 6: PW100 series air system
The black arrows show the direction of air flow. The green colour denotes PT shaft related air flow. Source: P&WC, annotated by ATSB
Internal corrosion resistance is provided by an aluminium coating applied to the inside of the shaft during manufacture. P&WC stated that during the metallurgical analysis, it was not possible to evaluate the coating near the surface fractures. However, there were no other indications, such as delamination, which would suggest the coating had been incorrectly applied. P&WC also indicated that based on in-service experience, the aluminium coating had historically provided good corrosion protection.
Engine washes
P&WC advised that engine desalination washes,[5] which are commonly used to clean and remove corrosive contaminants from the compressor and turbine sections, are not intended to perform a similar function for the PT shaft. As the shaft is part of the air system, water and washing fluid can enter the shaft during an engine wash, but not for the purpose of cleaning or removing contaminants. Any residual fluid inside the shaft is expected to evaporate when a post-wash engine run is performed in accordance with the engine maintenance manual (EMM). At the time of the occurrence, there were no maintenance procedures to clean the internal surface of the PT shaft.
Power turbine shaft maintenance
The PT shaft did not have an operational service life and was maintained ‘on condition’. It was subject to maintenance at each overhaul which included cleaning, inspections and, if applicable, repairs.[6] The aluminium coating was removed as part of the cleaning process and then re-applied after inspection or after any repairs. Any corrosion on the shaft (if observed) was evaluated against the repair limits. If within limits, the shaft was repaired, otherwise it was replaced.
The time between overhaul (TBO) depended on whether the operator’s engine maintenance regime was hard-time or soft-time (on‑condition). Engines maintained on hard-time maintenance were overhauled every 8,000 hours. Engines maintained on‑condition, using P&WC’s on‑condition Maintenance Program (OCP), were overhauled based on the condition of the engine, which could extend the TBO beyond 8,000 hours. To be eligible for the OCP, an operator was required to conduct additional inspections and checks between overhauls, but there were no additional tasks required for the PT shaft. The operator was utilising an OCP for its DHC-8 engine fleet.
Engine maintenance history and management of findings
Engine AT0010 was manufactured in 2000 and was fitted to various other DHC-8 aircraft in the operator’s aerial surveillance fleet throughout its life. The original PT shaft (serial number A000547M) was removed for the engine’s first overhaul at 13,547.3 hours in March 2011 due to ‘deep corrosion pitting’ on the inner diameter of the shaft, beyond the repair limits. Corrosion was also observed on various components throughout the engine’s gas path. The shaft was replaced with the subject PT shaft (serial number A0030D9A) that was new from manufacture, which then accumulated 12,254.21 hours in service before fracturing.
The operator advised that post wash engine runs were being performed on its DHC-8 fleet after every engine wash in accordance with the EMM. In addition, engine AT0010 had not experienced any extended periods of inactivity, so had not undergone any preservation[7] since its last overhaul.
P&WC managed in-service findings by categorising them into one of five categories. This process was to ensure the communication of in-service findings which had affected, or had the potential to affect, flight safety or aircraft availability. Category 5 (CAT 5) was introduced in 2018 and covered unusual or unexpected findings discovered by maintenance organisation’s during scheduled engine maintenance.[8] It was intended to provide P&WC with visibility of potential warning signs that might need assessment.
P&WC stated that the reporting process at the time of the engine’s first overhaul in 2011 was informal and relied primarily on the maintenance organisation’s judgement of what constituted an unusual finding worth reporting. Historical P&WC records indicated that the P&WC overhaul facility did not raise the PT shaft corrosion finding during the engine’s first overhaul. Although the introduction of the CAT 5 process provided procedural guidance for maintenance organisations to raise unusual findings, P&WC further stated that engineering judgement, rather than specific criteria, would still be exercised when raising a CAT 5.
Other occurrences
P&WC advised that this PT shaft fracture was the first confirmed to have occurred due to corrosion. P&WC had previously received images of a similar looking fracture, but the parts were not in a condition that allowed for detailed examination. Therefore, the cause of that fracture could not be determined.
Since this occurrence, corrosion on the inside of a PT shaft was discovered during a hot section inspection (HSI)[9] of another engine in the operator’s DHC-8 fleet. While a PT shaft inspection is not normally carried out during an HSI, P&WC elected to conduct an unscheduled visual inspection of the shaft as a result of this occurrence. The shaft was subsequently sent to its maintenance facility in Canada for further analysis.
Examination of the power turbine (PT) shaft by the engine manufacturer, Pratt & Whitney Canada (P&WC), identified conclusively that it fractured due to fatigue cracking that originated from corrosion pitting. Excluding the low pressure impeller leading edge erosion and diffuser corrosion, the observed damage to other engine components, including the second PT shaft fracture location, was consistent with secondary damage due to the initial fatigue fracture.
Although the gas core of the engine continued to operate after the PT shaft fracture, no power could be transmitted to turn the section of the PT shaft still connected to the gearbox and propeller. As a result, no engine power was available, and the crew shut down the engine.
Power turbine shaft corrosion
The corrosion products identified at the PT shaft fracture origin indicated that the corrosion was probably caused by salt-laden air. Since air from the compressor entered the PT shaft during normal engine operation, corrosion causing contaminants (for example, salt) and moisture within the ambient air probably built up on the inside of the shaft, allowing corrosion to occur.
The engine had been operated at low altitude over the sea throughout its life, with PT shaft and air system corrosion evident at its first overhaul and subsequent engine examination. These observations supported P&WC’s conclusion that the PT shaft corrosion was caused by the engine’s operational environment.
As a result of the operator utilising an engine on-condition maintenance program, the engine operated significantly beyond the hard-time overhaul of 8,000 hours, with no additional maintenance of the PT shaft. Coupled with the absence of a cleaning process to remove contaminants from the shaft during inactivity, meant an increased operational time and calendar time between PT shaft inspections, both of which probably contributed to corrosion formation and growth.
Since post wash engine runs were being performed and the engine had not undergone any preservation, it was unlikely that any fluid or moisture would have remained in contact with the shaft surface for any extended period while the engine was inactive. There were also no indications that the shaft’s protective aluminium coating had been incorrectly applied. Therefore, it was unlikely that any of these factors contributed to the observed PT shaft corrosion.
Corrosion management
The information obtained by the ATSB during this investigation indicated three instances of corrosion forming within the PT shaft of PW100 series engines that grew undetected between the scheduled overhaul inspections. All three occurred within the operator’s engine fleet which have been used primarily in a marine environment, with one resulting in a fracture of the shaft.
The PT shaft fracture due to marine environment exposure demonstrated that the existing protective coating and maintenance requirements were not sufficient to prevent progression to corrosion‑related fatigue fracture. Although corrosion pitting may not always lead to a fracture before overhaul, it provides sites for fatigue crack initiation, presenting an increased risk of premature fatigue fracture.
Given the power turbine shaft design and function is the same across all PW100 series engines, and there are other PW100 series operators conducting maritime surveillance activities, there is potential for this risk exposure to extend to other operators within the global fleet.
While P&WC indicated that based on its experience the PT shaft coating provided good corrosion protection, corrosion pitting outside of repair limits might not necessarily have been reported by maintenance organisations during overhaul. Reporting such findings was probably less likely prior to the introduction of the additional guidance through the CAT 5 process in 2018. Therefore, P&WC may have had limited visibility on engines exposed to an increased risk of PT shaft corrosion.
Although engine AT0010 exhibited ‘deep corrosion pitting’ of the PT shaft outside of repair limits at the engine’s first overhaul, the finding was not escalated by the maintenance organisation to P&WC for further assessment, possibly due to the informal reporting process in place at the time. Additionally, it does not appear that the location, extent, size, and depth of the corrosion was recorded. Furthermore, there was no recorded information available regarding an assessment of the finding. Therefore, there was insufficient information to determine whether that specific finding should or should not have been escalated.
Nevertheless, the circumstances of this occurrence illustrate the importance of specific guidance and criteria on how to assess corrosion. In this instance, this would probably have provided P&WC with greater visibility of engines in the global fleet that are exposed to an increased risk of corrosion-related failure.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the engine failure during take-off involving a Bombardier Dash 8, registered VH-ZZE, which occurred at Darwin Airport, Northern Territory, on 11 November 2019.
Contributing factors
The power turbine shaft of the aircraft’s right engine fractured due to fatigue cracking, resulting in secondary damage and engine failure.
The fatigue cracking in the engine’s power turbine shaft initiated at corrosion pitting, which probably resulted from prolonged low‑altitude operation in a marine environment.
The power turbine shaft in Pratt & Whitney Canada PW100 series engines operating in certain marine environments is susceptible to corrosion pitting, which can grow undetected between scheduled inspections. This increases the risk of shaft fracture resulting in engine failure.[Safety issue]
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: The power turbine shaft in Pratt & Whitney Canada PW100 series engines operating in certain marine environments is susceptible to corrosion pitting, which can grow undetected between scheduled inspections. This increases the risk of shaft fracture resulting in engine failure.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
aircraft operator (Surveillance Australia)
flight crew
recorded data (CVR and FDR)
engine manufacturer (Pratt & Whitney Canada)
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the flight crew
Cobham Aviation Services
Pratt & Whitney Canada
De Havilland Aircraft of Canada
Transportation Safety Board of Canada
Transport Canada
Civil Aviation Safety Authority
A submission was received from:
Pratt & Whitney Canada
The submission was reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.