Section 21 (2) of the Transport Safety Investigation Act 2003 (TSI Act) empowers the ATSB to discontinue an investigation into a transport safety matter at any time. Section 21 (3) of the TSI Act requires the ATSB to publish a statement setting out the reasons for discontinuing an investigation. The statement is published as a report in accordance with section 25 of the TSI Act, capturing information from the investigation up to the time of discontinuance.
Overview of the investigation
On 8 May 2019, the ATSB commenced an investigation into the descent below minimum safe altitude involving a Regional Express Saab 340B aircraft, registered VH-OLM which occurred 15 km south-west of Williamtown Aerodrome (Newcastle Airport), New South Wales, on the evening[1] of 28 March 2019, at about 1942 Eastern Daylight-saving Time.[2]
As part of the investigation, the ATSB interviewed the aircraft flight crew and Williamtown Aerodrome air traffic controllers. The operator’s Route Manual was examined for information relating to the conduct of visual approaches and specific information about the operation of flights into Williamtown. The ATSB also reviewed Airservices Australia’s requirements of the conduct of visual approaches[3] and the required segment minimum safe altitude at Williamtown Aerodrome.[4]
Air traffic control (ATC) cleared the flight crew to conduct a visual approach via a right base circuit leg to runway 12, and told the flight crew to report once they were ‘on base’. The aircraft had descended to 900 ft when the flight crew contacted ATC to report that they were on base. The controller then looked for the aircraft again and observed that the aircraft was further away than the expected position (about 4.7 NM south of the airport) and according to the radar display, below the segment minimum safe altitude. The controller then issued a safety alert and instructed the flight crew to climb. The flight crew complied with the instruction to climb. The aircraft landed without further incident.
The ATSB found the flight crew had misjudged the aircraft’s position relative to the aerodrome while conducting a night visual approach.
ATSB comment
Based on a review of the available evidence, the ATSB considered it was unlikely that further investigation would identify any systemic safety issues. Consequently, the ATSB has discontinued this investigation.
The evidence collected during this investigation remains available to be used in future investigations or safety studies. The ATSB will monitor for any similar occurrence that may indicate a need to undertake a further safety investigation.
On 14 April 2019, an Aeroprakt A22LS Foxbat collided with terrain while conducting mustering operations on Aldville Station approximately 120 km north-west of Cunnamulla, Queensland. The aircraft sustained substantial damage and the pilot was fatally injured.
Recreational Aviation Australia (RAAus) is investigating the accident and has requested assistance from the Australian Transport Safety Bureau (ATSB) in:
recovering data from an on-board GPS unit
conducting metallurgical and failure analysis on components of the aircrafts control system
conducting failure analysis on the aircraft’s damaged wing covering.
To facilitate this work the ATSB has initiated an external investigation under the Transport Safety Investigation Act 2003.
Any enquiries relating to the accident investigation should be directed to RAAus at: www.raa.asn.au.
Final Report
What happened
On 14 April 2019 an Aeroprakt A22LS Foxbat, registered 24-8140, collided with terrain while conducting mustering operations on Aldville Station, approximately 120 km north-west of Cunnamulla, Queensland. The pilot was fatally injured and the aircraft sustained substantial damage.
Recreational Aviation Australia (RAAus) commenced an investigation and requested assistance from the ATSB to:
conduct detailed examination of a control system component and a section of wing fabric
download data from a damaged GPS unit that was on board the aircraft at the time of the accident.
To facilitate this work, the ATSB initiated an external investigation under the Transport Safety Investigation Act 2003.
Results
The ATSB conducted visual inspections and microscopic analyses on an eyebolt from the control system (Figure 1) and a piece of damaged wing fabric. Analyses of the eyebolt determined that it had failed due to overstress with no indication of fatigue. The wing fabric analyses indicated that the damage was consistent with that expected as a result of the ground impact.
Figure 1: Failed eyebolt showing fracture surface
Source: ATSB
The ATSB undertook data recovery from an accident damaged Lowrance Airmap 2000c GPS unit. A raw binary data file was recovered through a direct download of non-volatile memory. The file was unable to be interpreted by the ATSB and was supplied to RAAus.
With the completion of the examinations and data recovery, the ATSB has concluded its involvement in the investigation of this accident. Any further enquiries in relation to the investigation should be directed to Recreational Aviation Australia.
___________ This report has been released in accordance with section 25 of the Transport Safety Investigation Act 2003.
On 23 April 2019, a De Havilland Aircraft of Canada DHC-8-315, registered VH-XKJ and operated by Skippers Aviation, was conducting a charter flight from Perth Airport to the Duketon Gold Mine, Western Australia.
Shortly after take-off, the flight crew heard a banging sound and detected a reduction in power from the left engine. At about the same time, the pilot flying experienced a yaw through the aircraft controls. The crew also noted a gradual reduction in right engine power. The flight crew elected to conduct a return to Perth Airport, where an uneventful landing was conducted.
What the ATSB found
Following the occurrence, both engines were inspected and erosion damage was noted to the high‑pressure turbines. While both engines displayed erosion damage, the damage to the left engine was more pronounced. The erosion damage to the turbine likely disrupted the airflow through the left engine, inducing the symptoms reported by the crew and recorded in the aircraft flight data.
The decision not to shut down the malfunctioning engine immediately allowed the flight crew to concentrate on continuing the climb, during a period of increased workload. The left engine responded to an increase in power. However, the crew elected to return to the departure airport.
The ATSB determined that the gradual reduction in power on the right engine was not likely the result of a mechanical issue in the engine.
Safety message
A partial power loss presents a more complex scenario to flight crew than a complete engine failure. The engine is still providing some power, however the power may be unreliable and the reliability may be difficult to assess. This occurrence highlights the benefits of timely and appropriate flight crew action in response to a power loss on take-off.
In this case, the affected engine appeared to return to normal operation, however the flight crew continued with the return. Abnormal engine operation, even if only transient, can be an indication of a developing fault and therefore the safest course of action is to discontinue the flight as soon as possible.
The occurrence
What happened
On the morning of 23 April 2019, a De Havilland Aircraft of Canada DHC-8-315, registered VH‑XKJ (XKJ) and operated by Skippers Aviation, was being prepared for a charter flight to Duketon Gold Airport, about 750 km north-east of Perth, Western Australia. At about 0615 Western Standard Time,[1] XKJ departed Perth Airport with two flight crew, two cabin crew and 51 passengers on board.
Shortly after take-off, as the aircraft was climbing through approximately 250 ft above ground level, the first officer (FO), who was the pilot monitoring,[2] retracted the landing gear. At about this time, both flight crew detected a popping or banging sound from the vicinity of the number one (left) engine. The captain (pilot flying) also noted a slight left yaw[3] through the flight controls. The FO observed a reduction in torque, to just below 60 per cent on the left engine. The FO reported a ‘failure’, but further advised ‘it’s not indicating a failure’, as there was no associated master warning.[4]
The captain reviewed the left engine instrumentation and noted that torque was 58 per cent. Other indications, such as fuel flow, appeared relatively normal. The captain then advised that, because the left engine was still producing some power, they would not shut it down, but would conduct a return to Perth. As the aircraft climbed through a height of approximately 800 ft, the flaps were retracted, and the FO transmitted a PAN PAN[5] call. Perth air traffic control acknowledged, and the captain elected to return via a right circuit.
At about this time, the captain noted that the torque on the right engine was indicating lower than expected for the phase of flight. The captain advised the FO that they might need to upgrade to a MAYDAY.[6] The throttles on both engines were then advanced to approximately 80-90 per cent, with both engines responding as expected. In addition, the banging sound in the left engine ceased.
In preparation for landing, and to reduce airspeed, the throttles on both engines were retarded to about 30 per cent. The flight crew noted that, with this reduction in power, the banging sound in the left engine returned. Following a normal landing, the aircraft was taxied to the terminal, under power from both engines.
Context
Recorded Data
The aircraft’s flight data recorder (FDR) was downloaded by the operator and a copy of the relevant data provided to the ATSB. The flight data showed a sharp reduction in left engine torque as the aircraft climbed through 250 ft (see Figure 1). This was followed by a period of torque fluctuations, which aligned with the time that the flight crew reported hearing the banging sound coming from the left engine. The torque fluctuation was also coincident with minor fluctuations in the left engine inter turbine temperature (ITT), fuel flow, compressor (NL) and turbine (NH) percentages.
A slow reduction in right engine torque and ITT also occurred for the duration of the left engine power fluctuations, and until the torque increase on both engines was observed.
Engine Information
The aircraft was fitted with two Pratt & Whitney Canada (PWC) PW123E turboprop engines. These engines, serial numbers AW0067 (left engine) and AW0065 (right engine), had accumulated 19,212 and 20,354 hours in service respectively at the time of the incident.
The operator utilised an engine condition trend monitoring (ECTM) system to track the health of the various engines throughout its fleet of aircraft. This system allowed them to track trends in engine parameters over time and respond to them as necessary. The system also provided alerts in the event that there was a deviation from the trend in any of these parameters.
The engine maintenance manual (EMM) required that borescope inspections (BSI) be conducted every 1,500 hours for monitored engines and every 1,000 hours for unmonitored engines. In this case, while monitoring their engines using the ECTM system, the operator elected to align the BSI with other maintenance items and carry out the inspections every 1,000 hours under normal conditions.
In late August 2018, the ECTM system detected a change in the trend for both engines. The status changed from ’Trend Normal’ to ‘Notification’, based on an increase in ITT and decrease in the NH. This trend shift prompted the operator to conduct an out-of-cycle BSI and perform a power assurance run (PAR). This inspection was carried out in early September and both engines were found to have leading edge and tip erosion damage to the high-pressure turbine (HPT) blades. The damage to the left engine was more pronounced and a defect was raised in the engine’s maintenance log. Based on the guidance in the EMM, the left engine erosion damage required an increased inspection frequency for the BSI and PAR to every 300 hours from the previous 1,000-hour interval. In December and within the 300-hour interval, the next BSI revealed increased damage. It was judged, however, to still be within the required limits for continued operation, with the increased inspection frequency. At the time of the occurrence, the engine had accumulated a further 211 hours in service.
Post-incident maintenance
Following the occurrence, both engines underwent inspection and ground runs to ascertain possible contributors to the engine issue, including bird strike and component malfunction. A detailed examination of the left engine was then conducted by an engine overhaul organisation in consultation with the engine manufacturer. The examination noted the erosion damage to the leading edges and tips of the HPT blades. It also noted heavy erosion damage to the HPT shroud. Further, the HPT tip clearances[7] were described as ‘excessive’, however it was noted that no tip clearance limits were prescribed in the EMM. Hot section repairs were carried out to rectify this issue.
While the erosion damage on the right engine was less than that of the left, it was deemed viable to carry out hot section repairs at the same time. Both engines were subsequently refitted, and the aircraft was returned to service, with no further issues noted.
Operational Information
A section of the operator’s flight operations manual, Abnormal and emergency procedures, detailed actions to be taken in a variety of abnormal situations, including engine failure after take‑off. In addition, the quick reference guide detailed procedures for ‘engine fail/fire/shutdown (in flight)’. There was no specific information dealing with a partial power loss or abnormality in one or both engines.
The flight crew commented that the partial loss of power on one engine presented a more complex scenario than an engine failure. In that event, the crew would have completed the engine failure drill, as per their training, and could refer to the operator’s flight manual or the quick reference guide, if required. As this was not the case, there was some discussion in the cockpit and the decisions were made following assessment of the available information.
The flight crew advised the ATSB that including unusual events of this type in the training program would be of benefit. However, they also noted that it would involve addition to an already extensive training and check program.
The operator advised the ATSB that they considered the flight crew’s actions, in returning to the departure airport as soon as the problem was detected, was appropriate.
Safety analysis
Post-flight internal inspection of the engines revealed erosion damage to the high-pressure turbine blades of both engines. Given the high operating temperature/speed and low clearances that exist within turbine engines, erosion degradation over time is expected. However, this deterioration affects the optimum airflow through the engine and reduces the overall engine efficiency. In this case, the erosion to the left engine high‑pressure turbine is likely to have contributed to the power loss and banging sound experienced by the crew and the engine parameter variation recorded in the FDR data.
Skippers Aviation conducted engine condition trend monitoring on their fleet of aircraft. A change in the trend for the left engine triggered an alert, which prompted an internal borescope inspection and power assurance run to be conducted. Erosion to the high‑pressure turbine was noted and an enhanced maintenance program to monitor the damage had been initiated. Technical documentation available to Skippers Aviation assisted with the detection and monitoring of the damage. However, there was no specific tip clearance limit given in the engine maintenance manual. The ATSB noted that, while this occurrence happened when the engines were under close monitoring, the enhanced maintenance program was in accordance with the engine manufacturer’s requirements.
The crew also reported a reduction in right engine power. It was determined that, while a possible exacerbating factor, it did not affect the crew’s decision to conduct the return, as the PAN call and return to Perth had been initiated before the right engine low power was noted. The subsequent engine inspection identified erosion to the high-pressure turbine. However, it was less than that of the left engine. Additionally, the flight crew reported that the right engine responded normally to the power lever increase and operated as expected for the remainder of the flight. Based on that evidence, the ATSB concluded that the decrease in right engine power was unlikely due to a mechanical issue with the engine.
Possible causes for this reduction included, a transient engine issue, technical failure of the throttle mechanism, flight crew deliberate action or flight crew distraction. However, because the FDR did not record throttle position data the reason for this reduction could not be determined.
Findings
These findings relating to the engine malfunction and return of the Skippers Aviation DHC-8-315 registered VH-XKJ should not be read as apportioning blame or liability to any particular organisation or individual.
Excessive erosion to the left engine’s high-pressure turbine blades likely resulted in the power loss.
At the time of the occurrence, the maintenance program for the detected erosion was in accordance with the manufacturer's maintenance manual requirements.
The aircraft experienced an uncommanded gradual reduction of torque in the right engine, a mechanical issue with the engine as the cause was considered unlikely.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 23 March 2019, the cruise vessel Viking Sky experienced a blackout, causing loss of propulsion and steering, during a storm in Norway. The Norwegian Safety Investigation Authority (NSIA) initiated an investigation into the accident.
At the NSIA's request, the ATSB assisted with the collection of relevant information. To protect any information supplied by the NSIA to the ATSB, and the ATSB's investigative work to assist the NSIA, the ATSB initiated an investigation under the Transport Safety Investigation Act 2003.
As there were Australian passengers on board the Viking Sky at the time of the accident, Australia was a Substantially Interested State in the NSIA's investigation, and reviewed its final report into the accident. On 19 March 2024, the NSIA published the report, which is summarised and linked below.
In the afternoon of 23 March 2019, the cruise vessel Viking Sky experienced a blackout, causing loss of propulsion and steering, during a storm in the Hustadvika area of the Norwegian coast. The vessel is estimated to have come within a ship’s length of running aground with 1,374 persons on board, and the accident had the potential to develop into one of the worst disasters at sea in modern times.
The accident was caused by insufficient lubricating oil in all of the operating diesel generators’ lubricating oil sump tanks, in combination with pitching and rolling in rough seas. The investigation has identified operational, technical, and organisational safety issues that in different ways contributed to the blackout.
The blackout recovery was time consuming, and it took 39 minutes from the blackout until both propulsion motors were operational and the ship had sufficient power available to maintain between 1 to 5 knots ahead. Blackout drills had been carried out, but recovery from a full blackout without a standby generator had never been drilled on board. The engineers were therefore faced with a situation they were not practised in managing. The situation was stressful, the control system was complex, and a specific sequence of actions was needed. Insufficient training likely contributed to why the blackout recovery was time consuming.
When Viking Sky left Tromsø 21 March 2019, with one out of four diesel generators unavailable, both crew and passengers were unknowingly exposed to an increased risk as the vessel did not have the redundancy required under the Safe Return to Port (SRtP) regulations. As Viking Sky did not comply with the applicable safety standards, it should not have departed Tromsø under the prevailing circumstances.
The investigation has also found that the lube oil sump tank design was non-compliant with applicable regulations.
The NSIA issues a total of 14 safety recommendations to relevant parties with the aim of promoting maritime safety.
On 8 April 2019, at 0650 Eastern Standard Time, a Cessna Aircraft Company 182 aircraft, registered VH-DJN, departed Cloncurry Airport on a private flight to Mount Garnet aerodrome, Queensland (Qld), under visual flight rules (VFR). On board were the pilot and one passenger. The aircraft landed in Mount Garnet at 0920, where the passenger disembarked and left the aerodrome. The passenger planned to return to the aerodrome at about 1500 for an onward flight (in VH-DJN) to Charters Towers, Qld.
At 0934, the aircraft departed Mount Garnet for a 62 km VFR flight to Atherton Airport, where the pilot intended to refuel the aeroplane before returning to collect the passenger from Mount Garnet. However, 15 minutes after departing Mount Garnet and about 14 km from Atherton, the aircraft impacted trees and terrain on the Herberton Range. The impact fatally injured the pilot and the aircraft was destroyed.
What the ATSB found
The ATSB found that the pilot, who was qualified only to operate in visual meteorological conditions, flew toward and entered an area of low cloud and reduced visibility, which obscured rising terrain. This almost certainly resulted in the pilot losing visual reference with the ground and a controlled flight into terrain.
While it could not be determined whether it influenced the accident, the pilot had taken medication that had the potential to affect performance and was therefore required to be disclosed to the Civil Aviation Safety Authority (CASA). This medication had not been disclosed to the pilot's Designated Aviation Medical Examiner or recorded on the pilot's CASA medical file.
Safety message
The ATSB is concerned about the frequency of accidents, many fatal, which involve pilots flying with reduced visual cues. The risks associated with operating under the visual flight rules in adverse weather appear to be under-estimated. The ability to understand weather-related hazards and how to assess and mitigate them, are vital skills for pilots, particularly those who fly in challenging environments like mountainous terrain.
Weather conditions must be considered during pre-flight planning, assessed and reassessed during flight and pilots should have a rehearsed plan in case weather deteriorates.
VFR pilots should use a ‘personal minimums’ checklist to help control and manage flight risks through identifying risk factors that include marginal weather conditions and only fly in environments that do not exceed their capabilities.
During flight, pilots must continuously assess the weather for conditions that may adversely affect the safety of the flight and be prepared to use an alternative course of action if conditions deteriorate. They should make timely decisions to turn back, divert or hold in an area of good weather.
Pressing on into instrument meteorological conditions without a current instrument rating and a suitably-equipped aircraft, carries a significant risk of disorientation and a loss of spatial awareness from reduced visual cues. This can easily affect any pilot, no matter what their level of experience.
The occurrence
Accident day
On 8 April 2019, at 0652 Eastern Standard Time,[1] a Cessna 182G aircraft, registered VH-DJN, departed Cloncurry aerodrome on a private flight to Mount Garnet, Queensland, under the visual flight rules (Figure 1).[2] On board were the pilot and one passenger, who was the aircraft owner.
Figure 1: Map of Queensland locations relevant to the occurrence showing the approximate track of VH-DJN on the accident day
Source: Google Earth and aircraft GPS, annotated by ATSB
The aircraft landed at Mount Garnet aerodrome at 0920, where the passenger disembarked. The passenger left the aerodrome, intending to return at about 1500 for an onward flight to Charters Towers. In the interim, the pilot planned to fly to Atherton Airport to refuel and then return to Mount Garnet. Atherton Airport, elevation 2,460 ft above mean sea level (AMSL), was 63 km north-east of Mount Garnet aerodrome, elevation 2,156 ft AMSL. Between these locations lay the Herberton Range, where the highest peaks in the vicinity of the direct track reached about 4,000 ft AMSL.
The aircraft took off from Mount Garnet at 0934:31, with the pilot as the sole occupant. Based on the aircraft’s GPS data, it initially tracked directly towards Atherton Airport for about 4 minutes, before diverging east of the direct route (Figure 2).
Figure 2: Recorded flightpath of VH-DJN (red) and direct track (yellow)
Source: Google Earth overlaid with aircraft’s recorded GPS track, annotated by ATSB
The aircraft made small deviations right and left as it tracked north-east and passed overhead Wondecla at 0947:13 climbing through 4,144 ft. Over the next 30 seconds, the aircraft climbed to about 4,400 ft, which was the maximum height reached, before starting to descend. As the aircraft descended about 500 ft over the next 76 seconds, small changes in direction and two short climbs were made (Figure 3).
The aircraft’s last recorded GPS position was at 0949:02 at an altitude of 3,916 ft and heading north-north-east. The terrain elevation at that position was 3,774 ft[3] and the terrain and GPS altitudes were each correct to within about 100 ft.
The aircraft impacted the tree canopy and subsequently terrain, fatally injuring the pilot. The 130-metre-long wreckage trail was consistent with significant forward speed at impact (about 240 km/h ground speed based on GPS data) and the aircraft was destroyed. No radio transmissions by the pilot were recorded on any available frequency.
Figure 3: Terrain elevation (green) and VH-DJN GPS altitude (blue) for the accident flight
Source: Geoscience Australia and aircraft GPS recorded data
Previous day
The flights conducted on the day prior to the accident flight, 7 April, are depicted in Figure 4. The pilot operated VH-DJN alone from Townsville Airport, departing at 0557 and arriving at Charters Towers aerodrome at 0624. The (same) passenger joined the pilot at Charters Towers and after refuelling the aircraft, the pilot and passenger flew to Elrose Station, arriving at 0849. Later that day, the aircraft departed Elrose Station for a 27-minute flight to Cloncurry, where the pilot and passenger stayed overnight.
Figure 4: Map of Queensland locations relevant to the occurrence and previous day’s flights including the aircraft track
Source: Google Earth and aircraft GPS, annotated by ATSB
The pilot held a private pilot (aeroplane) licence that was issued under Civil Aviation Safety Regulations Part 61 in November 2014. The Civil Aviation Safety Authority (CASA) reported that the pilot’s original licence was issued in 1975. The ATSB was unable to obtain the pilot’s logbook after the accident. However, as at 8 July 2017, the pilot’s logbook had recorded 6,532 hours total aeronautical experience, at which time the pilot had recorded 3,967 hours on the Cessna 182 aircraft type.
The pilot’s last review was a night visual flight rules (VFR)[4] and single-engine aeroplane class rating fight review, conducted in April 2018 and valid until April 2020. Night VFR operations are based on visual procedures in visual meteorological conditions (VMC).[5] Additionally, the CASA advisory circular (AC) 61-05 Night VFR rating stated:
4.3.2 Night operations require proficiency in instrument flight (IF)…
4.3.3 Instrument flying skills are intrinsic to night flying; therefore, it is also desirable that IF proficiency be demonstrated before commencing actual night flying.
4.3.4 While NVFR flight must be conducted in VMC, a visual horizon is often not available and a sudden loss of visual reference is also possible (i.e. when turning away from a well-lit area, reduced visibility or even following inadvertent entry into cloud). Night flying training should therefore emphasise the importance of flying the aircraft by reference to the flight instruments integrated with visual flying, even in conditions where external lighting provides adequate visual reference.
The pilot had previously held a multi-engine aeroplane instrument flight rules (IFR) [6] rating, with the last renewal recorded in the logbook conducted in October 2010.
Medical and pathological information
The 73-year-old pilot held a Class 2 Medical Certificate, valid until September 2020. The certificate required the pilot to wear distance vision correction and a headset while flying and have vision correction available for reading.
The autopsy report identified that the pilot had coronary artery atheroma of a severity that could have led to a cardiac event. This was consistent with the general practitioner’s assessment that the pilot had a history of moderately high cardiovascular risk. However, it could not be determined whether this had occurred or had any influence on the pilot’s actions.
Post-mortem toxicological examination of the pilot’s blood revealed the presence of a benzodiazepine, a hypnotic sedative medication, consistent with a therapeutic dosage and a blood alcohol concentration (BAC) of 0.03 per cent. The pilot’s BAC reading may have been due at least in part to post-mortem alcohol production and no alcohol was detected in the urine. The pilot was reported to have consumed two alcoholic drinks with dinner the previous evening. This was not in accordance with patient guidelines for the sedative medication. Additionally, in some people, alcohol intake could increase the effects of the medication and make it harder for the body to break it down, but it was not known whether this was the case for the pilot.
The medication, which had been prescribed for the pilot, was listed by CASA as being ‘hazardous in aviation’ as it had effects and side-effects that could impair pilot performance. It was therefore not to be used without clearance by CASA or the pilot’s designated aviation medical examiner (DAME). Under the clinical practice guidelines for DAMEs, risk assessment protocols allowed consideration of a pilot’s need for medication use. That assessment involved reviewing the condition, symptoms, compliance with medications and treatments, and any relevant side effects.
The prescribed medication had not been disclosed by the pilot in the self-declaration required for medical certification or at any time subsequent to the pilot’s last CASA medical. The DAME was unaware of the pilot’s use of the medication and had therefore not conducted an aeromedical risk assessment.
Aircraft information
The Cessna 182G is an all-metal, four-seat, externally braced high-wing single-engine aircraft equipped with tricycle landing gear and designed for utility purposes. VH-DJN was manufactured in the United States and registered in Australia in 1964.
The aircraft was powered by a six-cylinder, normally aspirated, horizontally opposed and air-cooled engine. In such engines, fuel and air are mixed via a carburettor before flowing to the cylinders for ignition. Auxiliary fuel tanks were installed in the wing tips in 1991, in accordance with a Supplemental Type Certificate, which increased the usable fuel capacity from 270 to 358 L.
The pilot had owned and operated the aircraft from about 1985, until the registration was changed to the current owner (at the time of the accident) in March 2018. Following the change of registration, the pilot had continued to operate the aircraft for the owner and organise its maintenance.
The last maintenance release was issued following a periodic aircraft inspection conducted on 5 December 2018 at 9,392.1 aircraft hours. The last recorded engine maintenance was on 8 March 2019 at 9,422.7 aircraft hours, when the time-expired carburettor was replaced, and ground runs, idle adjustment and a test flight were conducted. While inconsistent recording of aircraft hours had previously been identified by CASA, there was no evidence of current issues with the maintenance of the aircraft.
The aircraft had previously been operated in the IFR category but was no longer approved for operations under IFR. This ceased when the pilot advised the maintainer that it was no longer required and the necessary maintenance for IFR approval had been discontinued. As such, it was still equipped with vacuum-driven instrumentation to allow a suitably qualified and experienced pilot to control the aircraft with reference to these instruments, such as in the case of inadvertent entry into instrument meteorological conditions (IMC).[7] The calibration and accurate functioning of these instruments, however, could not be assured by pre-accident maintenance or confirmed by post-accident inspection. The aircraft was also fitted with an autopilot.
Accident site and aircraft wreckage information
The accident site was located at an elevation of approximately 3,800 ft above mean sea level (AMSL) in the Herberton Range National Park. This was about 200 ft below the highest peak in the vicinity.
The aircraft wreckage was distributed in a linear pattern 130 m long, on a heading of 030 degrees. The debris trail started with the wheel faring then the lower section of the right wing; consistent with the aircraft being upright on first impact with the tree canopy. As the aircraft passed through the trees, the wings and fuselage had progressively disintegrated.
The distribution of the wreckage indicated that there was no pre-impact damage or in-flight breakup prior to the initial collision with the tree canopy. The wreckage trail and aircraft damage were consistent with significant forward inertia at the time of impact. Additionally, damage to the propeller was indicative of the engine delivering power when the aircraft entered the trees. Disruption to the aircraft limited complete flight control continuity checks, however, continuity was established where access was possible. Further, there was no evidence of the aircraft being in a stall condition, nor was there evidence of pre- or post-impact fire or a major oil leak.
The accident site and wreckage was consistent with a controlled flight into terrain. That is, the aircraft was under the control of the pilot when it impacted terrain, with no defect or unserviceability that would have otherwise prevented the normal operation of the aircraft.
Meteorological information
Graphical area forecast
The Bureau of Meteorology (BoM) provides aviation weather forecasts for ten graphical forecast areas in Australia. Weather areas and sub areas are used to highlight differing conditions within a graphical forecast area. Cloud heights in area forecasts are AMSL.
The flight from Cloncurry to Mount Garnet and the accident flight from Mount Garnet were in the Queensland – North (QLD-N) area. The BoM provided ATSB with area forecasts valid from 0300 to 0900 and from 0900 to 1500 EST. The flight from Cloncurry to Mount Garnet spanned the two validity periods, and the accident flight was in the later period.
Within the QLD-N area, for both validity periods, there were weather areas A and B and sub areas A1 and A2 within area A. About the first half of the flight from Cloncurry to Mount Garnet was in area B, the aircraft then entered area A and the final segment to Mount Garnet was in sub area A2 (Figure 5). The entire accident flight from Mount Garnet was within sub area A2.
Figure 5: Image from the graphical area forecast for area QLD-N issued at 0831 and valid from 0900 to 1500 EST
Source: Bureau of Meteorology, annotated by ATSB
Areas B and A (but not sub area A1 or A2)
The forecast weather was similar for areas B and A (but not sub area A1 or A2), with visibility greater than 10 km and scattered[8] cumulus/stratocumulus cloud with bases between 5,000 and 6,000 ft (AMSL), and tops at 9,000 ft. In the earlier forecast period only (valid until 0900), area A (but not sub area A1 or A2) additionally had scattered stratus clouds forecast, with bases at 1,500 ft and tops at 3,000 ft.
Sub area A2
The forecast for sub area A2, valid for, and relevant to the vicinity of the accident flight, included:
scattered to broken stratus clouds, with bases at 1,500 ft and tops at 3,000 ft
scattered to broken cumulus and stratocumulus clouds, with bases at 2,000-2,500 ft and tops at 8,000-9,000 ft.
The forecast visibility was greater than 10 km, reducing to 2,000-3,000 m in isolated[9] to scattered[10] moderate showers of rain. Moderate turbulence below 6,000 ft was also forecast for the sub area.
Grid-point wind and temperature forecast
Grid-point wind and temperature forecasts were obtained for the relevant period. Due to the terrain elevation in the area of the accident flight, the lowest grid-point wind and temperature data was for 5,000 ft AMSL. The forecast valid from 0700 to 1000 included wind from 090° True (easterly) at 26 kt and temperature 14 °C.
Aerodrome forecasts
The aerodrome forecast (TAF) for Cloncurry Airport valid for the morning’s departure, was south-easterly winds at 10 kt, CAVOK,[11] temperature 22 °C and the QNH[12] 1016.
There was no TAF for Mount Garnet or Atherton airports. Cairns and Innisfail are coastal airports close to sea level and located about 60 km north-east and south-east respectively, from the accident site. Those airports were also located in the graphical forecast sub area A2.
The TAF for Cairns Airport included 10 kt south-easterly winds, visibility greater than 10 km, light showers of rain, scattered cloud at 2,500 ft above aerodrome elevation (AAE) and broken cloud at 3,500 ft.
Innisfail TAF included 8 kt south-easterly winds, visibility greater than 10 km, scattered cloud at 2,000 ft AAE, broken cloud at 4,000 ft AAE. Between 0600 and 1200 for intermittent periods of up to 30 minutes, visibility was forecast to reduce to 3,000 m in showers of rain, with few cloud at 1,000 ft AAE and broken cloud at 1,800 ft AAE.
Bureau of Meteorology observations
Weather observations nearest the accident site were recorded at Mareeba Airport, about 35 km to the north-east. At 0900, the temperature at Mareeba Airport was 23.1 °C, the dew point temperature was 18.4 °C, wind south-easterly at 10 kt and the QNH was 1018.4 hPa.
Aerodrome weather observation reports for Innisfail and Cairns airports at 0930 and 1000 were consistent with the forecast, with two to three layers of cloud.
Weather radar images from Cairns (Saddle Mountain) radar between 0934 and 0957 showed light rain in Atherton (Figure 6).
Figure 6: Weather radar image from Cairns at 0951 showing light rain in Atherton
Source: Bureau of Meteorology, annotated by ATSB
Satellite imagery
Satellite imagery showed scattered to broken cloud coverage at the time of the accident flight, moving from the south-east. Based on the cloud top infrared satellite temperatures, the cloud base was likely at ground level in the vicinity of the accident site. Figure 7 depicts the aircraft track overlaid on colour satellite images taken at 0940 and 0950. Within the limitations of the depicted cloud positions, these images show that the aircraft tracked along areas of more broken cloud until the top of descent. Between the top of descent and the accident site at 0950, the cloud appears as an unbroken cell.
Figure 7: Aircraft track overlaid on satellite imagery at 0940 and 0950 EST
Source: Bureau of Meteorology, annotated by ATSB
Witness observations
The passenger reported that on the approach to Mount Garnet from Cloncurry, the pilot made minor deviations around and under scattered cloud.
Several pilots operating near Atherton Airport on the morning of 8 April 2019 reported low cloud and drizzle over the range. A flight instructor on a training flight tracking south-east towards Atherton around the time of the accident observed thick cloud to the ground on the range and assessed that there was no way to maintain VMC, so changed course to remain to the north, clear of the weather.
Another training aircraft approached Atherton Airport from Mareeba Airport at the time of the accident and the flight instructor on board reported low cloud and rain with reduced visibility moving in from the south. Shortly after landing, they experienced a very heavy rain downpour, which lasted for about 15 minutes.
Carburettor icing
The atmospheric conditions recorded at the Bureau of Meteorology Mareeba station (the closest station) at the time of the accident were applied to the Civil Aviation Safety Authority Carburettor icing probability chart. Based on this chart, the likelihood of carburettor icing[13] was ‘moderate icing for cruise or serious icing for descent’. A reduction in power that could result from carburettor icing was inconsistent with the aircraft damage sustained at impact. Therefore, it was concluded that carburettor icing was not a factor.
Pre-flight planning
Visual flight rules
VFR flights are required to be conducted in visual meteorological conditions (VMC) that ensure sufficient visibility to fly the aircraft while maintaining visual separation from terrain and other aircraft. Additionally, when operating at or below 2,000 ft above the ground (or water), the pilot was required to be able to navigate by visual reference to the ground (or water).
The VMC criteria, including minimum flight visibility and distance from cloud, were specified in the Airservices Australia Aeronautical Information Publication (AIP). Relevant to this flight, the AIP En Route 1.2 Section 2.5 Non-Controlled Airspace – Class G stipulated that, for aeroplanes operating at or below 3,000 ft AMSL or 1,000 ft above ground level (whichever is higher), a minimum flight visibility of 5,000 m must be maintained, including a requirement to remain clear of cloud and in sight of the ground or water.
No flight plan or search and rescue time[14] were lodged with air traffic services for the accident flight, nor were they required to be for VFR flights.
Weather planning
The pilot had a National Aeronautical Information Processing System (NAIPS) user identification to allow access to the NAIPS briefing and flight notification functions including access to weather information. NAIPS was able to be remotely accessed, including from electronic flight planning software OzRunways,[15] which was installed on the pilot’s iPad. Information provided by Airservices indicated that the pilot’s last logon to NAIPS was on 2 April 2019 (six days before the accident). However, although the pilot did not use NAIPS for weather planning close to the accident flight, this does not preclude the pilot having accessed weather forecast information through another means.
Fuel planning
On the morning of the accident flight, as neither the pilot nor the passenger had a fuel account self-service card, they were unable to refuel the aircraft in Cloncurry. Therefore, the pilot planned to fly from Mount Garnet to Atherton Airport, refuel the aeroplane and then return, while the passenger conducted business in Mount Garnet. The pilot had flown to Atherton to refuel on previous occasions, including from Mount Garnet.
Fuel records for the time the aircraft was on the ground in Charters Towers on April 7, show that 165 L of fuel was pumped from the bowser. The passenger reported that this had filled the main and auxiliary tanks to their 358 L capacity. Since refuelling, the aircraft had been airborne for 4 hours and 58 minutes and travelled 1,209 km (653 NM) before landing at Mount Garnet.
The passenger estimated there would have been 60 to 90 minutes of fuel remaining after landing in Mount Garnet; sufficient for the return flight to Atherton. Due to disruption of the fuel tanks and cockpit instruments, the amount of fuel on board at the time of the accident could not be determined. Fuel exhaustion was not considered probable given the aircraft’s forward speed at impact and propeller damage.
Visual flight into instrument meteorological conditions
Adverse weather conditions and reduced visual cues
By definition and legislation, flight under the VFR requires sufficient visual reference for a pilot maintain geographical, situational and spatial orientation. In less than VMC, pilots must be qualified, proficient and well-prepared to operate by reference to the aircraft instruments and under the instrument flight rules and the aircraft must be equipped and maintained to the required standard. Significant risks face VFR pilots flying into IMC. Research for the ATSB Avoidable Accidents publication Accidents involving Visual Flight Rules pilots in Instrument Meteorological Conditions found that about 10 per cent of VFR into IMC occurrences reported to the ATSB between 2009 and 2019 resulted in a fatal outcome. The resulting collision with terrain following VFR into IMC events have occurred in both controlled and uncontrolled flight.
Controlled flight into terrain
The ATSB (2007) has defined a controlled flight into terrain (CFIT) as one in which:
the aircraft is under the control of the pilot(s) and collides with terrain, water or obstacles
there is no defect or unserviceability that would prevent the otherwise normal operation of the aircraft
the pilot(s) have little or no awareness of the impending collision.
The aviation community has invested considerable time and resources in an attempt to reduce the risk of CFIT, particularly in the commercial sector. Measures such as terrain awareness warning systems have substantially reduced these types of accidents.
In the 10-year period up to the accident flight, 32 CFIT occurrences involving VH-registered aircraft were recorded in the ATSB database. Seventeen of those were classified as accidents, six of which involved fatal injuries to occupants. The fatal accidents occurred during general aviation operations, five of which were private flights, and one was a passenger-carrying charter operation.
The ATSB Aviation Research and Analysis Report CFIT: Australia in context 1996 to 2005 found that CFIT accidents occur most often in conditions of reduced visibility and mountainous terrain. Loss of situational awareness has been identified as a key contributing factor, particularly a loss of vertical situational awareness or ‘altitude error’.
Spatial disorientation and loss of control
Although not consistent with the accident site and wreckage or flight profile in this accident, the other risk associated with VFR into IMC is a loss of control due to spatial disorientation. Spatial disorientation occurs when the brain receives conflicting or ambiguous information from the body’s sensory systems. It is likely to happen in conditions in which visual cues are poor or absent, such as in cloud. Gibb and others (2010) explain that seeing the horizon is ‘crucial for orientation of the pilot’s sense of pitch and bank of the aircraft.’ In conditions of low visibility, the horizon may not be visible to the pilot, which can lead rapidly to disorientation.
Spatial disorientation presents a danger to pilots, as the resulting confusion can often lead to incorrect control inputs resulting in a loss of aircraft control. Gibb and others (2010) stated that ‘spatial disorientation accidents have fatality rates of 90–91 percent, which indicates how compelling the misperceptions can be.’
Factors contributing to VFR into IMC
A study by Wiegmann and Goh (2000) identified factors that may contribute to instances of VFR flight into adverse weather conditions. These included:
situation assessment – an inaccurate assessment by a pilot of the conditions
risk perception – a pilot may not appreciate the risks involved with continuing the flight
motivational factors – ‘get-home-itis’ or personal/social pressures to complete the flight.
In particular, the study found that, during the conduct of a simulated cross-country flight, a significant proportion of participants overestimated the visibility and cloud base. That is, they perceived the conditions to be better than what they actually were and continued into IMC rather than turning back.
Related occurrences
The ATSB has investigated numerous fatal accidents resulting from VFR into IMC occurrences that resulted in either spatial disorientation and associated loss of control, or controlled flight into terrain. Three of these are summarised here.
ATSB investigation AO-2015-131: Collision with terrain involving Airbus Helicopters EC135 T1, VH-GKK, 10 km NNW of Cooranbong, New South Wales, 7 November 2015
On 7 November 2015, the owner-pilot of an Airbus Helicopters EC135 T1, departed on a private flight from Breeza Terrey Hills, New South Wales. The flight was conducted under the visual flight rules and there were two passengers on board. About 40 km south-west of the Liddell mine in the Hunter Valley, the pilot diverted towards the coast, probably after encountering adverse weather conditions. Witnesses observed the helicopter overfly the Watagan Creek valley in the direction of higher terrain, then return and land in a cleared area in the valley. After 40 minutes on the ground, the pilot departed to the east towards rising terrain in marginal weather conditions. About 7 minutes later and approximately 9 km east of the interim landing site, the helicopter collided with terrain. The pilot and two passengers were fatally injured. The pilot likely encountered reduced visibility conditions leading to loss of visual reference leading to the collision with terrain.
ATSB investigation AO-2013-186: Collision with terrain involving Cessna 182, VH-KKM, 19 km WSW of Mount Hotham Airport, Victoria, 23 October 2013
On 23 October 2013, the pilot of a Cessna 182Q aircraft, operating under the visual flight rules, departed Moruya Airport, New South Wales on a private flight to Mangalore Airport, Victoria. The pilot was qualified for visual flight rules and had minimal total and recent flying experience. The flight route encompassed the Alpine National Park, where the forecast and actual weather included extensive thick cloud and severe turbulence. It was very likely that these conditions were encountered while flying over the Alpine National Park, shortly after passing Mount Hotham Airport. The pilot likely experienced reduced visibility to the extent that terrain avoidance could not be assured, resulting in the aircraft colliding with terrain in controlled flight. The pilot sustained fatal injuries and the aircraft was destroyed.
ATSB investigation AO-2012-130: VFR flight into IMC involving de Havilland DH-84 Dragon VH-UXG, 36 km SW of Gympie, Qld, 1 October 2012
On 1 October 2012, a de Havilland DH-84 Dragon Mk 2 aircraft took off on a private flight from Monto to Caboolture, Queensland. The pilot was not qualified for, and the aircraft was not equipped for instrument flight. About 2 hours after departure, the pilot contacted ATC and advised that the aircraft was in cloud. Over the next 50 minutes ATC provided assistance to the pilot but it was apparent that he was unable to navigate clear of the cloud. The aircraft wreckage was located on 3 October in high terrain; there were no survivors. The ATSB found that:
With no or limited visual references available in and near cloud, it would have been very difficult for the pilot to maintain control of the aircraft. After maintaining control in such conditions for about an hour and being unable to navigate away from the mountain range, the pilot most likely became spatially disoriented and lost control of the aircraft before it impacted the ground.
Loss of visual reference and controlled flight into terrain
The pilot held current qualifications to operate in day and night visual meteorological conditions and neither the pilot nor the aircraft were authorised to operate in instrument meteorological conditions (IMC). No flight plan or search and rescue time were lodged for the accident flight, and no radio calls were broadcast by the pilot. This was consistent with the pilot intending to operate the flight under the visual flight rules (VFR).
The forecast weather for the accident flight included low cloud extending to the ground in areas of higher terrain, and low visibility in cloud and showers of rain. The planned 20-minute flight was contained within a sub area of weather considerably worse than the previous flight the pilot conducted that day (from Cloncurry to Mount Garnet). Although the pilot did not access aeronautical weather forecasts via the NAIPS system, it could not be determined if the pilot accessed any weather forecast before departing Mount Garnet for Atherton. However, observed conditions were consistent with those forecast. In any event, it was likely apparent to the pilot shortly after take-off that there was a risk of encountering cloud, as several deviations were made from the direct route—consistent with tracking to avoid cloud.
The pilot had experience flying locally, had flown from Mount Garnet to Atherton previously and the aircraft was fitted with a GPS, but the cloud and low visibility almost certainly precluded the pilot from navigating by ground reference. The subsequent changes in aircraft direction and altitude were indicative of the pilot manually flying the aeroplane rather than having the autopilot engaged. These changes in track were also consistent with what would be expected if attempting to avoid weather, as the aircraft’s four previous recorded flights tracked direct to Atherton, except for one deviation due to cloud approaching Mount Garnet.
As the aircraft approached the Herberton Range it climbed to an altitude about 400 feet higher than the highest terrain in the area, but this was very likely not above the cloud tops. It could not be known whether the pilot then descended in an attempt to get under the cloud (having lost visual reference with the ground), or due to geographical disorientation, had assessed the aircraft was beyond the range and closer to Atherton. Either way, low cloud and reduced visibility obscured rising terrain, and this almost certainly resulted in the pilot losing visual reference with the ground and the aircraft colliding with terrain in level flight, under power and pilot control.
Undisclosed medication
The pilot was taking medication that had the potential to affect flying performance. There is a documented pathway for the Civil Aviation Safety Authority (CASA) and a Designated Aviation Medical Examiner (DAME) to manage certain medical conditions and medications, including the one being taken. The pathway requires an assessment of the associated risk and does not necessarily preclude a pilot from maintaining a medical certificate. However, the CASA medical process requires pilots to disclose medications and conditions so they can be assessed and managed.
The medication and associated condition had not been disclosed to the pilot's DAME or recorded on the pilot's CASA medical file. Although the medication had also not been taken in accordance with the patient guidelines, there was no evidence as to whether it influenced the pilot’s spatial awareness and decision-making performance on the accident flight.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the collision with terrain involving Cessna 182, VH-DJN, 14 km south-south-west of Atherton Airport, Queensland, on 8 April 2019.
Contributing factors
The pilot, who was qualified only to operate in visual meteorological conditions, flew toward, and entered an area of low cloud and reduced visibility, which obscured rising terrain. This almost certainly resulted in the pilot losing visual reference with the ground and a controlled flight into terrain.
Other factors that increased risk
The pilot was taking medication that had the potential to affect performance, and as such, was required to be disclosed to the Civil Aviation Safety Authority (CASA). This medication had not been disclosed to the pilot's Designated Aviation Medical Examiner or recorded on the pilot's CASA medical file.
Other findings
The pilot had an elevated risk of incapacitation due to heart disease.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
passenger
Bureau of Meteorology
Civil Aviation Safety Authority
Queensland Police Service
maintenance organisation for VH-DJN
Airservices Australia
recorded data from the GPS unit on the aircraft
Queensland Health Forensic and Scientific Services
Medicare and Pharmaceutical Benefits Scheme
General Practitioner
Designated Aviation Medical Examiner.
References
ATSB, 2007, CFIT: Australia in context 1996–2005, Aviation Research and Analysis Report B2006/0352. Available from www.atsb.gov.au
ATSB, 2011, Accidents involving visual flight rules pilots in instrument meteorological conditions, Aviation Research an Analysis Report AR-2011-050. Available from www.atsb.gov.au
Gibb, R, Gray, R and Scharff, L, 2010, Aviation Visual Perception: Research, Misperceptions and Mishaps, Ashgate Publishing Limited, Surrey, United Kingdom.
Wiegmann D & Goh J 2000, Visual flight rules (VFR) flight into adverse weather: An empirical investigation of factors affecting pilot decision making, Technical report ARL-00-15/FAA-00-8, Aviation Research Lab Institute of Aviation, Illinois.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the passenger
the aircraft maintainer
the Bureau of Meteorology
the Civil Aviation Safety Authority
Queensland Health Forensic and Scientific Services
General Practitioner
Designated Aviation Medical Examiner.
Submissions were received from the:
Bureau of Meteorology
aircraft maintainer
forensic pathologist.
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 29 March 2019, the catamaran ferry Fitzroy Flyer was on a scheduled trip between Cairns and Fitzroy Island, Queensland, with four crewmembers and 37 passengers on board. At about 1410, the port main engine overheated, and shortly after, a fire alarm activated in the port engine room. A crewmember and passenger investigated and reported smoke and fire. Initial attempts were made to extinguish the fire using portable extinguishers, but the success of these actions could not be confirmed. At about 1450, the master activated the port engine room fire suppression system.
All passengers were mustered and evacuated to two nearby vessels. At 1615 the master started the starboard engine and Fitzroy Flyer returned to Cairns at slow speed. By 1710, the ferry had been safely berthed without further incident.
What the ATSB found
No evidence of a fire or any fire damage was found in the engine room during inspections carried out after the incident. The signs seen by personnel were likely from smoke due to a loose and slipping fan drive belt and steam from the overheated cooling system.
The ATSB found that the on-board response did not follow company procedures as had been practised by crewmembers during emergency drills. More specifically:
the crew did not promptly deploy the vessel’s fire suppression system or apply boundary cooling to the area.
multiple entries were made into the contaminated port main engine room without suitable control measures in place.
passengers were transferred to other vessels while in open waters and without lifejackets (the engine room situation appeared to be under control at the time and the transfer unnecessarily exposed the passengers to increased risk).
an urgency message, informing and requesting assistance, was not sent.
What has been done as a result
Fitzroy Island Investments (Fitzroy Flyer’s owner-operator) reported that it has conducted a comprehensive evaluation and updating of the safety management system with emphasis on emergency procedures and drills. Schedules of regular shipboard staff training in procedures use and implementation, along with more frequent and targeted fire training and drills, have been implemented. In addition, a closed-circuit television camera surveillance system, with extended recording capability, has been fitted throughout the vessel.
Safety message
This occurrence highlights the importance of vessel operators having robust procedures and training for responding to fires and other emergencies on board, and for crewmembers to follow procedures and training in such situations. In particular, if a fire is suspected in an engine room, and further assessment is not possible, then crews should deploy the available suppression systems and transmit an urgency message.
The investigation
The occurrence
Departure from Cairns
Each day, the catamaran ferry Fitzroy Flyer (Figure 1) operated three return transfers between Cairns and Fitzroy Island, Queensland, with each leg taking about 50 minutes.
At about 0700 Eastern Standard Time[1] on 29 March 2019, the master boarded the vessel to conduct pre-start up routines. Shortly after, three crewmembers boarded and prepared the passenger cabin for the daily operations. The first transfer of the day departed Cairns at 0800 and, at 1350, Fitzroy Flyer departed Cairns on its third transfer with 37 passengers on board.
At about 1410, about halfway to Fitzroy Island (Figure 2), the master noticed that the port main engine cooling water temperature reading was high and he reduced both engines to neutral. A crewmember, deckhand 1 (DH1), in the main cabin, noticed the reduction in speed and went aft to investigate. Shortly after, a fire alarm activated on the bridge console for the port engine room. Not all crewmembers carried radios and the master radioed the galley and instructed a crewmember to investigate. DH1 acknowledged and proceeded to the port engine room.
A passenger, who was a staff member on Fitzroy Island, overheard that a fire alarm had been activated and went to assist. He informed DH1 that he was a former firefighter and DH1 accepted his offer of assistance.
Figure 2: Position of Fitzroy Flyer in Mission Bay when the fire alarm activated
Source: Google Earth, annotated by ATSB
As DH1 and the passenger approached the engine room hatch lid, they could feel heat coming from it (Figure 3). As a precaution before opening the hatch lid, the passenger had collected a portable carbon dioxide (CO2) fire extinguisher. When the hatch lid was opened, they sighted light-coloured smoke. They then climbed down the ladder, which was ‘hot to touch’, into the engine room to investigate further. They saw smoke, tinged blue, near the fuel filters,[2] and the passenger released the CO2 extinguisher. They both then left the engine room and closed the lid.
Figure 3: Port engine room and entrance
Source: Fitzroy Investments, annotated by ATSB
Subsequent response actions
At about 1415, DH1 reported to the master that there was a fire in the port engine room. The ferry slowed to a stop and the master shut down the port main engine. He asked another crewmember, deckhand 2 (DH2), to remain in the wheelhouse while he went to investigate.
Shortly after, at about 1420, DH1 and the passenger met the master by the port engine room. DH1 advised there was a smell of electrical burning and smoke with a blue tinge was coming from near the fuel filters. They confirmed to the master that they believed there was a fire and that a CO2 extinguisher had been released into the space. The master stated that, as CO2 had just been released, he could not make an entry for several minutes, so he returned to the wheelhouse. Once there, he instructed DH2 to move the passengers to the muster stations at the bow of the vessel and then he tried to call the shore management company via mobile phone. No other external communications, such as an urgency message (PAN PAN), were made at this time. The third crewmember, deckhand 3 (DH3), assisted DH2.
At about 1425, the master radioed for DH1 to come to the wheelhouse and keep lookout. After DH1 arrived, the master went back down to the engine room entrance, where the passenger met him. The master then isolated the fuel and emergency fire flaps for the engine room.
At about 1435, the master opened the engine room hatch lid and went into the engine room—he held his breath, due to the earlier release of the CO2 extinguisher. He did not see any signs of ‘flames or fire’ but could feel heat in the space and saw either ‘smoke or steam’. He released a dry powder extinguisher into the engine room and closed the hatch lid on exit.
At about 1440, the master returned to the wheelhouse and contacted the Cairns Vessel Traffic Services (VTS) to advise of the situation. Shortly after, the master saw a passing vessel, Scuba Pro, and contacted the crew for assistance, telling them they may need to evacuate passengers from Fitzroy Flyer. Scuba Pro’s skipper advised they could take 13 passengers. The master told DH2 to find 13 volunteers to evacuate. DH2 made an announcement to the passengers about the situation.
By 1445, the master had established contact with shore management and advised them of the situation and that he had not activated the port main engine fire suppression system. The master was instructed to activate the suppression system and was informed that management would come out to the vessel to assist with logistics.
By 1450, on the master’s orders, DH1 had activated the port main engine fire suppression system. The master then contacted VTS to advise that 13 passengers would be evacuated to Scuba Pro and the fire suppression system had been activated.
Passenger evacuation
At 1500, Scuba Pro was alongside Fitzroy Flyer and passenger transfer started. This was not a straightforward process as there was a freeboard difference, requiring a large step down to the other vessel. Also, several passengers had reduced mobility and others had expressed reluctance to transfer to the other vessels in open waters. In addition, the passengers did not wear flotation devices (lifejackets) during the transfer.
By 1510, the master contacted another vessel, Millennium Spirit, and asked if they could accommodate the remaining 24 passengers.
At about 1520, Scuba Pro pulled away from Fitzroy Flyer and the master reported to VTS they had taken 13 passengers and that Millennium Spirit would take those remaining. Millennium Spirit was alongside Fitzroy Flyer at about 1530 and passenger evacuation started.
Shortly after, at about 1540, the shore management vessel came alongside Fitzroy Flyer and the marine operations manager (MOP) and designated person ashore (DPA) boarded. The MOP went to the upper deck and started off-loading baggage, while the DPA went to the port engine room. Once at the engine room hatch, he opened the hatch lid and went inside to inspect; DH1 maintained watch at the top of the ladder.
Return to Cairns
At 1600, the master radioed VTS and reported that all remaining passengers had been safely offloaded to Millennium Spirit, and Fitzroy Flyer was making way to Cairns on the starboard engine. At about 1710, Fitzroy Flyer was safely alongside in Cairns.
Shortly after, the engine room was ventilated and inspected. The engine was found to be low on coolant and the water pump drive belt showed signs of burning due to a loss of tension.
There were no signs of fire anywhere in the engine room.
Context
Vessel information
Fitzroy Flyer is a catamaran ferry built in 1988. It is 22 m long with 8.7 m beam and draught of 2.69 m and was owned by Fitzroy Island Investments Pty Ltd at the time of the incident. The ferry is a Class 1 (13 or more passengers) registered Australian domestic commercial vessel for operational areas C (restricted offshore, to 30 NM) and D (partially smooth waters). It was certified to carry 186 passengers and four crewmembers in sheltered waters.
The vessel has a service speed of 23 knots and is powered by two MTU 12V 183 TE72, 495 kW main engines, one in each hull. Electrical power is supplied by a single 75 kW Isuzu BB-4BG1TRD-01 four-cylinder turbocharged diesel engine, located in the generator room in the port hull.
The port and starboard engine rooms are each protected by a Novec 1230[3] fixed fire-suppression system. The systems were designed to flood the space and extinguish a fire by rapidly removing heat. The engine room needed to be isolated and secured, the system activated and then the space and conditions monitored.
Safety induction, training and emergency drills
The company’s safety management system (SMS) documented guidance for crewmember induction, training and emergency plans and drills. The designated person ashore (DPA) and the master were to check the effectiveness of the training. The master was responsible for conducting on-board training and emergency scenario drills.
All crewmembers had to complete a vessel safety induction before they commenced work on board. Training and competency were required in vessel safe operation, emergency equipment, the vessel layout/safety and administration. This included familiarisation with emergency procedures and duties, the engine room fire suppression systems, firefighting appliances, entry into void spaces/engine room, crew-only areas and the procedural manuals.
The emergency plans detailed the preparation, training and emergency procedures that the crewmembers should know. Specifically for a fire emergency, the crewmembers needed to know, amongst other things:
the muster stations for their shift
the location and use of firefighting equipment
the location of fuel and fan shut-offs and how to use the emergency fire flaps
correct emergency signals and to maintain proper and effective communication.
The SMS required that on-board emergency drills be conducted on a regular basis. The crewmembers practised the emergency procedures for seven different scenarios, including fire and ‘abandon ship’. The drill records showed that the crewmembers on board at the time of the incident had each completed one fire drill in the previous 4 months, and all but DH2 had completed an ‘abandon ship’ drill in the previous 4 months.
Emergency procedures
The procedures detailed the individual crewmembers’ duties in case of a fire emergency. For example, the master was to attend the wheelhouse, maintain radio communications and direct crewmembers. This was supported by a specific fire emergency checklist on board that detailed the actions to be taken in the event of a fire. This checklist included:
sound fire alarm—muster and account for all persons on board
identify and assess the type of fire and its location
shut all ventilation to affected areas and fight the fire if safe to do so
prepare lifesaving equipment and portable flotation devices
broadcast an urgency message to request assistance.
In addition to this were instructions for operating the main engine room fixed fire-suppression systems: secure the engine room access hatch, isolate the space and then activate the suppression system. The hatch lid was to remain closed for a sufficient period before entry was made. A warning sign on the hatch lid stated that the space should not be entered until it had been thoroughly ventilated.
Risk management
The SMS contained a register of 57 risk assessments for activities and operations involving the vessel. In particular, one risk assessment dealt with a ‘Fire on vessel’ (including engine room fire) and two others detailed controls for engine room and confined space entry.
The risk control measures required that only trained crew may access confined spaces, that the atmosphere should be tested, and that personal protective equipment and breathing apparatus should be worn. However, the vessel did not carry either self-contained breathing apparatus or suitable atmosphere testing equipment, nor was it required to do so. Further, the procedures required the master to be advised which crewmembers were entering the engine room.
Vessel management
The company designated person ashore (DPA) was responsible for monitoring the safe operation of the vessel. The DPA had direct access to the owner of the vessel and had duties which included monitoring the SMS and the on-board training.
The vessel’s master had complete authority on board and was responsible for taking all necessary actions in the interest of safety. The master could deviate from the documented procedures if human life was at risk, and could ask the company for help when deemed necessary.
Safety analysis
Source of smoke
During the leg from Cairns to Fitzroy Island, a fire alarm activated in the port engine room. After inspecting the room, the crew believed there was a fire on board and subsequently the passengers were evacuated. However, no evidence of a fire or any fire damage was found in the engine room during inspections carried out after the incident. The signs seen by personnel were likely from smoke due to a loose and slipping fan drive belt and steam from the overheated cooling system.
The remainder of this analysis will examine the procedures and actions regarding the response to the suspected fire.
Immediate response actions
All crewmembers on board the vessel had completed the mandatory safety induction and participated in emergency drills. The vessel’s masters had conducted emergency scenario training for on-board fires six times in the 4 months before the incident. The training involved using fire hoses, extinguishers, boundary cooling and activating the fire suppression system. The master and deckhand 1 (DH1) were familiar with the emergency procedures and had been involved in three and four drills respectively. With potentially 190 persons on board the vessel, any response to an emergency needed to be effective.
However, in this case the crew suspected there was a fire in the port engine room but did not follow their training and procedures. In particular, they did not promptly lock down the engine room, deploy the fire suppression system and apply boundary cooling to the area.
Prior to flooding the engine room with the fixed fire suppression agent, the master attempted to determine whether a fire was actually present. His assessment of the situation included obtaining advice from DH1 and the passenger, along with a personal inspection of the port engine room. He was unable to confirm that there was a fire and remained hopeful that the situation could be contained without the need to release the fire suppression system. However, after seeking shore management advice, the system was activated, about 30 minutes after DH1 first advised that there was a fire present.
When doubt exists and it is unsafe to confirm whether a fire is present, prudent action would be to use the systems in place early in the response to contain and limit escalation of the situation.
In addition, a number of other aspects of the emergency response were problematic, including the involvement of a passenger, uncontrolled entries into a dangerous space and limited communications.
Passenger involvement
A passenger on board Fitzroy Flyer offered assistance and became actively involved in the incident response, including making an entry into the engine room. The passenger reported seeing blue colouration and smoke, and released a CO2 extinguisher into the space. The passenger believed that the blue-coloured smoke indicated there was a fire present. His experience and observations, when relayed to the master, likely influenced the master’s decisions and the incident response.
However, only trained crewmembers were assigned emergency duties on board the vessel, and the passenger was not trained in the use of the vessel’s equipment or procedures. The emergency procedures and risk assessments did not refer to the involvement of any other persons, regardless of their (unverified) experience or willingness to assist. Although using other available resources during emergencies can be a useful strategy if insufficient resources are available or the situation is unusual and complex, in this case the situation should have been well within the capabilities of the crew on board to manage.
Entry into dangerous spaces
Risk controls were in place to protect crewmembers entering into dangerous spaces. However, the vessel did not carry the necessary equipment to allow entry as per the procedures. Consequently, several entries were made into the contaminated engine room without these precautions being followed. More specifically, the passenger and DH1 were in the engine room when the CO2 extinguisher was released, the master entered not long after the CO2 extinguisher was released (without any ventilation being applied), and the designated person ashore (DPA) entered about 50 minutes after the fire suppression system had been deployed (without any ventilation being applied).
As there was, as a minimum, smoke, and there had been a suspected fire as well as the release of firefighting media into the engine room, the atmosphere was contaminated. Therefore, entry into the space should have been carefully controlled with consideration given to the conditions existing and the extent to which these risk controls could have been in place before any entry.
Evacuation of passengers
During the incident, the master directed the passengers to muster and then decided to evacuate them to passing vessels. Due to the difficulties in transferring persons of varying capability between moving vessels in a seaway, and without lifejackets, the transfer of passengers off Fitzroy Flyer was problematic. The transfers did not follow the vessel’s evacuation procedure.
Furthermore, at this stage, the engine room situation appeared to be contained and the need to evacuate was not clearly apparent. With one operational engine, Fitzroy Flyer could have made its way to Fitzroy Island or Cairns. The passengers would not, then, have been exposed to further risk during the transfer. In such circumstances, it would have been prudent to keep the passengers on board Fitzroy Flyer, as the vessel was in fact the best lifeboat at the time. As a precaution, the other vessels could have remained close by for immediate access if the situation deteriorated or until they were no longer needed.
Internal and external communications
Fitzroy Flyer did not carry sufficient radios for the four crewmembers. This resulted in some of the crewmembers’ conversations having to be communicated face-to-face during the emergency and the passenger evacuation. Therefore not all of the crew were kept aware of the full situation.
Further, the emergency procedures required an urgency message to be broadcast to request assistance. Despite the initial reports of smoke and then the decision to evacuate the passengers, a message was not broadcast.
As with any emergency situation, communications are key, and early notice to nearby vessels and authorities is advised. These parties are then in a position to prepare and provide timely assistance, regardless of whether the situation escalates or not.
Findings
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Although the crew believed that there was a fire in the port engine room, no evidence of a fire was subsequently found.
Although the crew had received regular emergency response training for a fire, they did not follow some key elements of this training during the response to the suspected fire. In particular, the crew did not promptly deploy the engine room fire suppression system and apply boundary cooling to the area.
A passenger (a former firefighter) actively sought involvement in the response to the fire alarm. His actions and advice likely influenced the master’s decision making.
Several people made entries into the port engine room, even though it had not been adequately ventilated or the atmosphere tested.
Passengers were unnecessarily exposed to increased risk when they were evacuated, without lifejackets, to two vessels with varying freeboards, in open waters.
Communications throughout the incident were limited. On board there was not a sufficient quantity of UHF radios for all crewmembers and, externally, an urgency message was not broadcast.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Fitzroy Island Investments Pty Ltd (vessel manager)
As a result of this incident, Fitzroy Island Investments advised the ATSB that the following safety actions have been taken:
conducted a comprehensive assessment and update of the safety management system emergency procedures and drills documentation and procedures
introduced a system of regular (at least monthly) on-site training for masters and crew in the implementation of procedures
purchased additional radios and implemented procedures for radio use (including all crewmembers being required to carry a radio at all times while on board)
installed an eight zone closed-circuit television cameras (CCTV) system (with 1 month recording capability) throughout the vessel, covering engine rooms, wheelhouse, passenger areas and main muster points
clarified procedures to ensure all crewmembers are aware that passengers must not be involved in firefighting operations, even if they claim to be experienced
implemented a schedule for more frequent and specific fire training and drills.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 29 March 2019 at about 1857 JST (Japan Standard Time),[1] a Boeing 787-8 aircraft, registered VH‑VKJ, was operating by Jetstar as scheduled flight JQ15 from Cairns Airport, Queensland, to Kansai International Airport, Japan. During descent into Kansai, the aircraft experienced engine speed oscillations and temporary loss of thrust on the right and then the left engine. The aircraft landed safely at Kansai at 1919.
Investigation
The Japan Transport Safety Board (JTSB) was responsible for the investigation of this occurrence. As part of this investigation, the JTSB notified the ATSB as the State of the Operator of the aircraft. In accordance with clause 5.18 of Annex 13 to the Convention on International Civil Aviation, the ATSB appointed an accredited representative to assist the JTSB with the investigation. In order to facilitate that assistance, an investigation under the Transport Safety Investigation Act 2003 was commenced.
Findings
The JTSB investigation is now complete and identified the probable cause of the engine oscillations and temporary loss of thrust as being residue from a previous biocide fuel system treatment interfering with the fuel metering of both engines. That biocide treatment, Kathon FP1.5, was loaded into the aircraft’s fuel system two days before the occurrence. The JTSB identified a number of safety actions regarding the use Kathon FP1.5 as a biocide treatment.
The JTSB have released the final report into this investigation, which is available at www.mlit.go.jp/jtsb/airrep.
Any enquires relating to the investigation should be directed to the JTSB: www.mlit.go.jp/jtsb.
With the completion of the JTSB investigation, the ATSB’s assistance activities are also complete and the investigation closed.
_____________
The information contained in this update is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the JTSB final investigation of the occurrence.
On 14 April 2019, the pilot of a Pilatus PC-12/47E aircraft, registered VH-OWJ and operated by Royal Flying Doctor Service - Western Operations (RFDS), was conducting a medical transport flight under instrument flight rules from Merredin to Jandakot within Western Australia. A RFDS aeromedical crew consisting of a flight nurse and doctor were on board with a non-critical patient who was being transferred to a hospital in Perth. For the midnight departure, there were almost clear skies with minimal ambient and celestial lighting.
About 1.5 minutes after take-off, ‘Pitch Trim Runaway’ warnings activated and the pitch trim continued to move nose-down without any pilot or autopilot inputs. The pilot initiated the applicable emergency procedure but inadvertently selected the Flap Interrupt switch rather than the Trim Interrupt switch. Consequently (before the next checklist item was actioned), the pitch trim continued to runaway until it reached full nose-down with associated serious control difficulties.
The pilot did not identify the mis-selection and continued to address the emergency procedure without resolving the full out-of-trim condition. With the assistance of the doctor seated in row 2, the pilot managed to return to Merredin for a flapless landing. The aircraft was undamaged and the occupants uninjured.
What the ATSB found
The ATSB found that the pitch trim runaway occurred because of a malfunctioning relay in the manual (main pilot-engaged) stabiliser trim system.
As the (uninterrupted) pitch trim runaway progressed, the reinforcing cycle of increasing control loads, forced descent, and increasing airspeed was initially exacerbated by high engine torque. The airspeed reached 210 kts with increased risk of descent into terrain before the pilot reduced engine torque and airspeed to partially alleviate the control loads and arrest the descent.
After the pilot addressed items 2 and 3 of the emergency procedure, the malfunction was neutralised and the alternate stabiliser trim system was available to adjust the trim. However, the pilot did not identify those positive conditions and continued with items 4 to 8 of the procedure, which disabled the alternate stabiliser trim system, prevented pitch trim adjustment and prolonged the serious control difficulties.
The similarities between the Trim Interrupt and Flap Interrupt switches and the proximal location of the two switches, unnecessarily increased the risk of mis-selection and contributed to the excessive out-of-trim condition.
The ATSB found that the emergency procedures and systems information in the PC-12 Pilot Operating Handbook/Airplane Flight Manual and Quick Reference Handbook did not provide effective guidance or sufficient information for pilots contending with a pitch trim runaway. If the pilot selects the Trim Interrupt switch early in the sequence and does not need to adjust the pitch trim, the risk is not significant. In this incident, the lack of effective guidance and systems information probably had an adverse influence on the pilot’s capability to resolve the uninterrupted trim runaway condition and was a critical factor.
As a factor that increased risk, the effectiveness of RFDS training and checking processes for pitch trim runaway was undermined by incomplete systems knowledge and unrealistic practice exercises associated with training/checking in the aircraft (non-simulator).
What's been done as a result
Pilatus advised that a design change, to reduce the likelihood of a trim runaway, was developed before the occurrence to replace the mechanical pitch trim relays with solid-state relays but was not fully implemented due to limited parts availability. Both applicable service bulletins have now been published.
Pilatus also advised that the probability of erroneous activation of the Flap Interrupt switch instead of the Trim Interrupt switch has been reduced by the publication and active distribution of a Safety Information Letter (SIL-003) to all customers, operators and service centres. This includes a reminder of procedures when encountering a trim runaway condition.
The ATSB acknowledge these positive safety actions but notes that the Trim interrupt and Flap Interrupt switches on the PC-12 do remain identical and co-located, and there is potential for engineering controls to eliminate the mis-selection of the interrupt switches.
RFDS investigated the occurrence and implemented safety action such as increasing pilot awareness about the pitch trim systems and enhancements to their related training and checking processes.
Safety message
The ATSB advises operators of PC-12 aircraft to review their training/checking processes related to the pitch trim system to ensure that pilots are adequately prepared to manage a runaway emergency. More generally, operators and pilots are advised to enhance awareness of expected system behaviour from switch and other control selections.
For flight control emergencies such as out-of-trim conditions, there is an imperative to maintain control while resolving the technical problem. A critical factor for pilots to consider is control of airspeed and associated engine power.
Operators are encouraged to submit reports of PC-12 pitch trim defects to the Defect Reporting Service to facilitate the Civil Aviation Safety Authority’s monitoring of continuing airworthiness data.
The occurrence
Background
On 13 April 2019, a pilot employed by Royal Flying Doctor Service - Western Operations (RFDS) based at Kalgoorlie, Western Australia was rostered for a night standby duty between 1800 and 0600 Western Standard Time (WST). Soon after starting duty, the pilot and rostered medical crew was tasked to transfer a patient from Kalgoorlie and a patient from Albany to Jandakot within Western Australia. After consideration of the weather forecasts and medical status of the respective patients, the decision was made to proceed direct to Jandakot then conduct a flight to Albany and return, followed by a positioning flight to Kalgoorlie.
For this series of flights, the pilot was operating a Pilatus Aircraft Ltd. PC-12/47E aircraft, registered VH-OWJ, as a medical transport flight in the aerial work category under the instrument flight rules. At 2032, the pilot departed Kalgoorlie with a patient, flight nurse and doctor on board.
During the flight to Jandakot, the RFDS operations centre advised the pilot and medical crew of a patient at Merredin that required transfer to Jandakot as a higher medical priority than the Albany patient. For on-board patient care reasons, the flight continued as planned to Jandakot, landing at 2213. The pilot and medical crew were then re-tasked to conduct a flight to Merredin for the previously advised patient transfer.
The pilot departed Jandakot at 2253 and landed at Merredin aeroplane landing area (ALA) at 2341. This flight was described as normal except for diversions around storm cells that added 15 minutes to the planned flight time. The weather observed at Merredin was almost clear skies with a few scattered clouds to the south of the aerodrome and light winds.
Just after midnight, the pilot taxied the aircraft for runway 28 at Merredin ALA with the patient, flight nurse, and doctor on board. The pilot was seated in the front left control seat and the doctor was seated in the second row on the right, facing backwards.
The pilot conducted a normal take-off and was airborne at 0008:34. For the departure, the pilot was manually flying with the intention to engage the autopilot when the aircraft was established in the climb. As was typical for the phase of flight, the pilot was intermittently engaging the trim switches on the control wheel to make pitch trim adjustments. There was minimal ambient and celestial lighting for the departure.
Emergency condition and initial pilot response
At 0010:05 (about 1.5 minutes after becoming airborne), as the aircraft was on climb through 2,700 ft AMSL (1,400 ft above ground level)[1] at a (calibrated) airspeed[2] of 140 kt, the following occurred without any apparent precursors:
master warning light illumination
‘pitch trim runaway’ voice annunciation
‘pitch trim runaway’ warning message in red on the multi-function display
continued pitch trim movement in a nose down direction without pilot or autopilot input at the time (uncommanded).
The pilot recalled hearing and seeing those warnings and that the aircraft pitched nose-down violently shortly afterwards. With both hands pulling on the control column to raise the nose, the pilot found that the force required to move the control column was extremely high and required maximum effort. The pilot was unable to counteract the nose-down force and the aircraft developed a high rate of descent at approximately 2,000 ft/min.
In response to the warnings, the pilot initiated the Pitch Trim Runaway emergency procedure from memory. The pilot recalled that:
The first action was to select the Trim Interrupt switch on the centre console from NORM (normal) to INTR (interrupt). At the time, the pilot believed that this was carried out and that it was difficult to reach because of the high control column loads. (A ‘Flaps Caution’ was recorded at 0010:11, 6 seconds after the initial trim warning. This caution is consistent with operation of the Flap Interrupt switch instead of the Trim Interrupt and was not noticed by the pilot at the time.)
After a short interval to focus on raising the nose, the pilot pulled the Pitch Trim circuit breaker on the essential bus to the OPEN position. (An Autopilot Fail Advisory was recorded at 0010:39, 34 seconds after the initial trim warning. This was coincident with cancellation of Pitch Trim Runaway warning and consistent with opening of circuit breaker)
The Trim Interrupt switch was selected back to NORM. (Based on the first action, this was probably the Flap Interrupt switch.)
Following those actions, the pilot was concerned that there was no change to the condition of the aircraft. This was contrary to the pilot’s expectations from training, which was that the Trim Interrupt switch should have stopped the dive and the opened circuit breaker should have relieved the situation. (Either or both actions would stop the manual trim motor from further operation but would not relieve the control loads existing at the time this action was taken.)
According to the recorded data, the pitch trim continued to operate in the runaway condition until it reached full nose down position 16 seconds after the warnings were issued. During that 16‑second period, the following data was recorded (see the indicative flight data plot in Figure 1):
engine torque remained at the take-off and initial climb setting of 42 lb (black trace)
pitch attitude went from +9.5 degrees (nose-up) down to -7.5 degrees (purple trace)
airspeed increased from 135 kt to 182 kt (red trace)
altitude initially continued to climb until 3,000 ft then reduced to 2,600 ft (green trace).
Over the next 6 seconds, the situation continued to deteriorate until the pilot reduced engine torque. At about that point, the airspeed had reached 210 kt and the altitude was down to 2,400 ft. The pilot recalled that the control forces eased somewhat following reduction of engine torque.
During the next 2 minutes, the pilot managed initially to raise the pitch attitude to 12 degrees, arrest the descent at 2,000 ft and climb to 2,700 ft, while reducing the airspeed to 125 kt. However, this was momentary as the pitch attitude cycled down to -3 degrees then back to 12 degrees with corresponding descent/climb and airspeed increase/decrease.
Figure 1: Indicative data plot showing key aircraft parameters before, during, and in the 2 minutes after the active phase (yellow band) of the pitch trim runaway.
Parameter scales not shown but are available in Figure 3.
Source: ATSB
Continuation of emergency condition and return to Merredin
By the end of that 2-minute sequence, the pilot was making a slow left turn to return to Merredin ALA and the master caution and pitch trim runaway warning activated for a short period (coincident with cancellation of the autopilot fail advisory). It is not clear from the pilot’s recollection why that occurred but it is consistent with the closing and reopening the pitch trim circuit breaker.
The pilot continued to experience severe control difficulties with another sequence of pitch attitude down to -7.5 degrees and back up to 8 degrees. The aircraft descended to a minimum altitude of 1,700 ft (400 ft above ground level) and reached a maximum airspeed of 180 kt (Figure 3).
After this sequence, the pilot decided that it was not possible to overpower the elevator force alone and requested the assistance of the doctor seated in the adjacent row. The doctor turned in the seat, reached into the cockpit, and pulled on the right control column. This had a positive effect on the variation of pitch attitude and associated airspeed and altitude parameters, although full control was not established.
At this point, the pilot continued with the Pitch Trim Runaway procedure from memory and sought to select the Trim Interrupt switch to INTR again and pulled the Alternate Trim circuit breaker. The pilot then pushed the Alternate Stab Trim switch intermittently, which appeared to have no effect in relieving elevator pressure. (At about this time the master caution and pitch trim runaway warning activated again for a short period, coincident with cancellation of the autopilot fail advisory and consistent with the closing then reopening the Pitch Trim circuit breaker).
As the aircraft was now in the Merredin circuit area, the pilot’s attention was on preparation for landing. When the flaps were selected to 15 degrees, the pilot noticed the ‘Flap’ caution on the crew alerting system (CAS) and realised the flaps were not available.
On the downwind circuit leg for runway 28, the pilot extended the landing gear. This was followed by a rapid descent from 2,150 ft to 1,650 ft (350 ft AGL) with a ground proximity warning system (GPWS) alert (Figure 2). In response, the pilot (with the doctor’s continuing assistance) pulled on the control column to raise the nose, and increased engine torque. Altitude was recovered to a maximum of 2,200 ft.
The pilot turned onto the base circuit leg and allowed the aircraft to descend. As the pilot turned onto the final approach, the aircraft overshot the runway centreline and required adjustment. On short final, the aircraft was high and the pilot was coordinating with the doctor to adjust the pitch attitude for landing. At one point, the pitch attitude was too high and activated the aural stall warning.
At about 30 ft above the runway, the pilot asked the doctor to let go of the control column and reduced engine torque to idle. The aircraft touched down firmly at 0017:15 and the pilot applied full reverse thrust and normal braking to bring the aircraft to a stop about 200 m from the end of the runway. The pilot taxied the aircraft to the parking area and shut down.
The RFDS operations centre dispatched an aircraft to Merredin to transfer the patient and RFDS personnel to Jandakot.
Figure 2: Aircraft track and vertical profile
Source: Google earth, annotated by ATSB
Post-occurrence examination and rectification
RFDS maintenance engineers travelled to Merredin to inspect the aircraft, download data, and remove the lightweight data recorder (LDR) for the ATSB. The engineers reported that the:
pitch trim was in the full nose-down position (leading edge of adjustable stabiliser fully up)
Trim Interrupt switch was selected to NORM
Flap Interrupt switch was selected to NORM
Pitch Trim circuit breaker was closed (pushed in)
Pitch Trim Alternate circuit breaker was open (pulled out)
other switches and circuit breakers were in normal positions.
The engineers secured a copy of the aircraft condition monitoring system (ACMS) and fault history database (FHDB) files for analysis by system technical specialists and provision to the ATSB. The LDR was removed and dispatched to the ATSB laboratory in Canberra where cockpit voice and flight data was recovered and analysed. A flight data plot for the complete flight follows as Figure 3.
When the aircraft was powered up, the Pitch Trim Runaway warning was immediately active. When the Trim Interrupt switch was selected to INTR, it cleared the warning and stopped the trim from operating. Based on the FHDB fault codes and continuing Pitch Trim Runaway warning, the technical specialists advised that the troubleshooting focused on the relays in the left relay panel.
RFDS maintenance engineers found that the manual pitch trim DOWN relay (identification number K161E2) had malfunctioned in a mode consistent with contacts that were stuck closed rather than being open (as would be expected with the coil de-energised). This relay was replaced and applicable operational and functional tests carried out with no further defects identified. The aircraft was certified as serviceable and flown back to Jandakot Airport without incident.
The ATSB notes that based on recorded data, for the last part of the occurrence flight, both the Pitch Trim circuit breaker and Pitch Trim Alternate circuit breaker remained open. Based on correlated parameters in the recorded data, the Pitch Trim circuit breaker was then closed when the aircraft was subsequently powered up on the ground by the pilot.
From other correlated parameters in the recorded data, the Trim Interrupt switch was not selected to INTR at any time during the flight.
Figure 3: Recorded data plot for complete flight showing the key parameters and active phase (yellow band) of the pitch trim runaway with start of doctor assistance (blue line).
The pilot held a commercial pilot licence with aeroplane category rating, an instrument rating with multi-engine aeroplane endorsement, and a Flight Instructor Rating. On application to RFDS in May 2018, the pilot’s total aeronautical experience was 1,587 hours. This included 1,370 hours as pilot in command, 384 hours multi-engine (Piper PA-31 Navajo and PA-34 Seneca), and 154 hours instrument flight time.
After joining RFDS in July 2018, the pilot received the specified training and assessment for a new pilot without prior PC-12 or similar aircraft type operating experience. This included:
Pilot induction training – including use of flight check system
Ground school - PC-12/47E (NG) Engineering Course
Human Factors and Non-Technical Skills Refresher Course
Flight training with flight review in PC-12/47E aircraft
Line Oriented Flight Training (medical transport flights with supervisory pilot)
Instrument Proficiency Check
Check-to-line assessment – passed in September 2018.
Training and check records indicate that the pilot progressed without any significant difficulties. The training/check pilot who approved the pilot for line operations recommended that, due to the pilot’s relatively low experience level, a follow-up check be conducted earlier than the required 6 months.
During the first three months of PC-12 operation as a line pilot, the pilot inadvertently exceeded an engine limit on take-off, and extended the landing gear above the maximum landing gear operating airspeed. RFDS investigated the landing gear exceedance and found that the pilot accepted an amended route, was then high on approach, and checked the airspeed, but did not recognise the high speed before extending the gear. As recommended, the pilot was debriefed/counselled with plans to simulate a similar scenario at the next check.
In February 2019, the RFDS Head of Training and Checking (HOTAC) conducted a Progress Check with the pilot during daylight in visual meteorological conditions. This included a pitch trim runaway scenario after take-off that required the pilot to carry out the emergency procedure. The HOTAC advised that the pilot’s response was in accordance with the Pilatus PC-12 Quick Reference Handbook (QRH). There was no record of a specific scenario similar to the landing gear exceedance. The overall assessment was satisfactory/competent and the pilot continued as a PC‑12 line pilot for the next two months until the occurrence.
At the time of the occurrence, the pilot’s total aeronautical experience was 2,108 hours including 521 hours on the PC-12/47E aircraft type. The pilot held a Class 1 medical certificate valid until February 2020.
Aircraft information
The PC-12/47E is a large single-engine turboprop pressurised aircraft designed and built by Pilatus Aircraft Ltd in Switzerland. This aircraft was manufactured as serial number 1411 in July 2013 and registered VH-OWJ in October 2013. At the time of the occurrence, the total time in service was recorded as 7,377 hours.
The aircraft was maintained by the CASA-approved RFDS maintenance organisation in accordance with an authorised system of maintenance based on the Pilatus Progressive Inspection Phases. At the time of the occurrence, a maintenance release[3] was in effect for the aircraft.
The most recent scheduled maintenance was a Progressive Mini Inspection completed on 28 March 2019 at 7,311 hours’ total time in service. This included a functional check of the Trim Interrupt switch, Alternate Stabiliser Trim switch and runaway aural warning system. No defects were recorded.
There were no significant deferred defects or line maintenance recorded before the occurrence. The pilot who operated the aircraft on the previous shift earlier that day did not record any issues with the aircraft.
PC-12 flight control systems
Pitch trim system
The primary flight controls—aileron, elevator and rudder—are actuated through a conventional system of push-pull rods and carbon steel cables. Each primary control is equipped with an electrically operated (DC) trim system to alleviate the variable aerodynamic loads transmitted by the control system. A visual indication of trim position is displayed to the pilot on the multi-function display (see Pitch trim runaway warnings).
For pitch trim (nose up/down, related to elevator control loads), the leading edge of the ‘T-tail’ horizontal stabiliser is moved up and down through a defined range by an actuator. This actuator contains two separate electric motors that operate independently according to three different control inputs. The ATSB developed a schematic diagram of the three pitch trim power circuits (Appendix A). Refer to Figure 4 for trim system features.
One of those trim motors—manual stabiliser trim motor—provides the primary means for the pilot or copilot to adjust the pitch trim. When the pilot selects the pilot trim engage switch and trim up/down switch on the control wheel simultaneously, the trim control circuit energises the up or down pitch trim relay.[4] That connects power from the Essential Bus and Pitch Trim circuit breaker through the applicable relay contacts to the manual stabiliser trim motor then circuit to earth via the de-energised relay.
In normal operation, trim movement will cease once the pilot releases the switches. However, in this occurrence, the pitch trim down relay stuck closed and continued to provide power to the manual stabiliser trim motor until the pitch trim circuit breaker was opened.
The other trim motor—alternate stabiliser trim motor—is utilised by either the autopilot or the alternate stabiliser trim switch (labelled as ‘Alternate Stab Trim’). When the autopilot is controlling the pitch trim, the auto drive circuit (from the Modular Avionics Unit) energises the up or down auto pitch trim relay in the Trim Adapter. That connects power from the Essential Bus and Pitch Trim circuit breaker through the respective relay contacts (and auto pitch trim engage relay) to the alternate stabiliser trim motor then circuit to earth via the relays.
The Alternate Stab Trim switch is located on the front centre console. When the autopilot is disengaged, selection of the switch to the nose up or down position provided power from the Main Bus and Pitch Trim Alternate circuit breaker (through the de‑energised auto pitch trim engage relay in the Trim Adapter) to the alternate stabiliser trim motor.
All of the trim power circuits (including rudder and aileron trim) were routed through a ‘Trim Interrupt’ switch located on the front centre console. When this switch was in the default position of NORM (normal), it closed the circuit between the various circuit breakers and related components in each system to allow normal operation. If this switch was selected to INTR (interrupt), it opened every trim power circuit simultaneously and prevented all trim operation until the switch was returned to NORM. (This switch was guarded with a clear perspex cover. All switch labels were backlit).
The ATSB highlights that although the autopilot trim system utilises the alternate stabiliser trim motor, it is powered from the same source as the manual trim system (Pitch Trim circuit breaker) rather than the power source for alternate stabiliser trim (Pitch Trim Alternate circuit breaker). This detail was not explicitly covered in the PC-12 Pilot’s Operating Handbook and Airplane Flight Manual (POH/AFM) and RFDS pilots advised they were not aware of that design characteristic. As discussed in Safety analysis, this had a subtle effect on training/checking practices and interpretation of the pitch trim runaway emergency procedure.
A representative of Honeywell Aerospace, the designer and provider of in-service support for the pitch trim system, advised the ATSB that there was no documented instance of a runaway attributed to the alternate stabiliser trim circuit (Appendix A – blue lines).
Figure 4: Pilatus PC-12/47E trim system features
Source: Pilatus and ATSB
Pitch trim runaway warnings
The pitch trim system monitored the power and control circuits for both trim motors and detected when there was power applied but no corresponding manual trim engagement, autopilot trim drive signals, or alternate stabiliser trim command. In any of those cases, the crew alerting system (CAS) produced the following effects:
master warning or caution light illuminated
‘Trim Runaway’ aural alert
‘Pitch Trim Runaway’ message displayed in the CAS window of the systems multi-function display (Figure 5).
Once the master warning or caution is acknowledged, the aural alert is cancelled but the message continues to display while the out-of-limit condition such as a trim runaway is operative. In the case of a malfunctioning relay in the manual trim system (such as this occurrence), the message will disappear if any of the following actions are carried out:
Manual trim engage switch on control wheel is activated
Trim Interrupt switch is selected to INTR
Pitch Trim circuit breaker is pulled open.
The ATSB notes that conditions 2 and 3 will cancel the message and stop a related runaway but condition 1 will only cancel the message without any effect on a runaway condition. The recorded data showed that the pitch trim runaway warning was cancelled and reactivated three times in the 32-second period after the initial warning. This was consistent with the pilot attempting to use the manual trim, which was ineffective in resolving the runaway.
Figure 5: Sample multi-function display showing acknowledged CAS messages
Source: Pilatus
Wing flaps
The wing flap system is electrically actuated and controlled by a selector handle on the centre console to the right of the engine control quadrant. Located forward of the flap selector handle is a Flap Interrupt switch (Figure 4) that disables normal operation of the flap system and generates a ‘Flap’ caution message on the CAS if the switch is selected to INTR. Irrespective of subsequent switch selections, the flaps will not operate until reset on the ground.
In this occurrence, there was evidence from flight data of power being removed from the flap system at the beginning of the initial 16-second trim runaway event, consistent with the operation of the Flap Interrupt switch (see Figure 3 - dark blue trace coded as Flap Controller Fail).
Pilatus advised the ATSB that the Flap Interrupt switch was utilised in the original PC-12 wing flap design as part of the alternate flap switch circuit that allowed the pilot to correct a flap asymmetry. In the PC‑12/47E model, there is no pilot access to the alternate flap switch and no requirement for the pilot to operate the remaining Flap Interrupt switch.
The ATSB notes that, as can be seen in Figure 4 (bottom right), the Flap Interrupt switch and Trim Interrupt switch appear to be the same type of switch and are located on the same panel, either side of the Alternate Stab Trim switch (refer to the following Safety analysis section).
Aircraft operating procedures – Pilatus
Pilot’s Operating Handbook and Quick Reference Handbook
The primary reference for operation of the PC-12/47E is the Pilot’s Operating Handbook and EASA Approved Airplane Flight Manual (POH/AFM) produced by Pilatus. In Section 3 Emergency Procedures, the general comments include the following guidance:
Some situations require rapid action, leaving little time to consult the emergency procedures. Prior knowledge of these procedures and a good understanding of the aircraft system is a prerequisite for safe aircraft handling.
The emergency procedures included a sequential list of action items in case of a pitch trim runaway. These procedures were also presented in the Quick Reference Handbook Emergency Procedures (QRH) booklet produced by Pilatus and available in the cockpit for the pilot to consult as required and as circumstances permitted (Figure 6).
Pilots could also select this procedure as one of the electronic emergency checklists on the multi-function display. This operation required a number of button pushes to select the checklist and scroll through the items. RFDS did not advocate use of this feature and that practice was not a factor in this occurrence.
Pilatus advised that if item 1 of the procedure was carried out immediately following a pitch trim runway warning, the control forces would be acceptable and the pilot would be able to perform the subsequent actions without acute stress.
The ATSB noted that in the scenario where items 1-3 would neutralise a pitch trim runaway condition, the subsequent control forces experienced by the pilot could be uncomfortably high due to timing of the trim interrupt or changes to phase of flight and/or aircraft configuration. If that occurs, the pilot can only adjust pitch trim using the alternate stabiliser trim. The procedure, however, did not communicate that clearly and specified alternate stabiliser trim as item 8.
It should also be noted that item 8 will not be effective if the complete procedure is actioned in numerical sequence. In that case, action in accordance with item 5 to open the Pitch Trim Alternate circuit breaker disconnects power from the alternate stabiliser pitch trim circuit. As the pilot in this occurrence found, any subsequent attempts to use the alternate stabiliser trim switch in accordance with item 8 will be futile.
Supplementary information
In February 2017, Pilatus issued Safety Information Letter (SIL) 003 to all customers, operators and service centres as an ‘Important reminder of procedures and operations of PC-12 (all models) when encountering a trim runaway condition.’ For reference, a copy of this letter is at Appendix B.
Some points from the letter that are relevant to this occurrence:
In the case of a trim runaway condition, as an immediate action, activate the guarded “Trim Interrupt” switch (refer to POH Section 3).
Hands-on training reduces the activation time and minimizes the risk of erroneously activating the “Flaps Interrupt” system switch (which cannot be reset in-flight).
By pulling its associated Circuit Breaker (CB), the affected trim motor will be isolated before the pilot can attempt to regain control of the unaffected systems (refer to POH Section 3).
To regain control of the unaffected systems, simply reposition the “Trim Interrupt” switch to NORM (refer to POH Section 3).
A reduction in airspeed will significantly reduce the existing out-of-trim forces and will help the pilot regain full control of the aircraft (refer to POH Section 3).
The PC-12 trim system is designed to assure that the pilot does not have to counteract continuous or excessive control forces after encountering a trim runaway. In case of a runaway on one of the pitch trim motors, the remaining one can be used to regain normal control forces.
Pilatus advised the ATSB that RFDS confirmed receipt of the transmittal notice for SIL-003 on 7 March 2017. Since then, the SIL has been listed as one of the additional technical information items on the Pilatus document portal accessible to RFDS. Pilatus noted that the SIL is also publically available on their website.
The ATSB notes that RFDS did not have a record of having received or formally considered the operational implications of this letter. One of the training/check pilots recalled the letter and advised that RFDS incorporated the pitch trim runaway response from the QRH into check flights. The content of the letter and potential effect in this occurrence is considered in the following Safety analysis section.
Normal procedures
As part of the POH/AFM Normal Procedures section, the daily Pre Flight checklist included items to confirm that the Trim Interrupt and Flap Interrupt switches were in the NORM/GUARDED positions. These were visual checks that did not involve operation of the switches. RFDS normal procedures were consistent with the POH/AFM.
For PC-12 aircraft operated under Transport Canada airworthiness approval, Pilatus specified a daily check of the pitch trim interrupt system in the ‘Before Starting Engine Procedure’. This originated in 1997 as part of the aircraft certification review process by Transport Canada. Transport Canada considered that the trim interrupt system was the sole means of disconnection for an uncommanded runaway and the system failure analysis did not take into account all of the factors. Pilatus responded by including a periodic check of the trim interrupt function in airworthiness limitations and integrating the daily check into the Canadian-specific POH/AFM.
Aircraft operating procedures – RFDS
The RFDS Operations Manual specified general aircraft operating procedures and PC-12 operating procedures. As a general principle, RFDS required pilots to comply with all requirements, instructions, procedures, or limitations in the applicable POH/AFM and QRH.
In an emergency, pilots were required to action the defined recall items from memory and then refer to the appropriate written procedures for confirmation. The subsequent actions were then to be actioned/confirmed as necessary and any notes/warnings reviewed. It was acknowledged that in some circumstances, pilots might need to continue subsequent actions from memory.
The pilot advised that the physical demands of counteracting the serious out-of-trim condition did not allow for review of the procedure in the QRH booklet. In context, this was an unavoidable constraint of single-pilot operation and was not considered to be a factor in the occurrence.
From March 2019 onwards, the RFDS PC-12 operating procedures nominated the first four items of the Pitch Trim Runaway procedure as recall items. These items were recorded in the operations manual and were the same as the POH/AFM and QRH except for item 3 which incorporated a conditional phrase:
3. TRIM INTERRUPT switch if trim runaway continues … NORM
In the POH/AFM and QRH, this conditional followed item 3 and applied to item 4 onwards rather than item 3.
Item 3, as presented by RFDS, could be interpreted to mean that the power to the trim systems was only to be reinstated if the trim runaway continued. However, the trim runaway could not continue without the reinstatement of power through the Trim Interrupt switch (and almost certainly the Pitch Trim circuit breaker), so the phrasing was nonsensical. In the context that the trim interrupt remained in NORM, and the POH/AFM/QRH procedures were primary references, it is unlikely that the procedural inconsistency had any effect on this occurrence.
RFDS advised that the recall items for emergency procedures had recently been added to their PC-12 operating procedures as an update to reflect current practices. They were aware that the RFDS pitch trim runaway procedures varied from the POH/AFM and QRH as a result of inaccurate transcription but this had not been communicated to pilots. This was corrected after the occurrence.
Pilot training and checking – RFDS
Training and checking framework
RFDS held a Civil Aviation Safety Regulation (CASR) Part 141 certificate and operated a CASA‑approved Training and Checking organisation under Civil Aviation Regulation (CAR) 217. The Part 141 certificate authorised RFDS to conduct the required class rating flight training and flight review to qualify pilots for the PC-12 aircraft type. (RFDS referred to this as conversion training.) The CAR 217 approval authorised RFDS to conduct recurrent training and checking including regular operator proficiency checks (OPCs).
The first stage of the RFDS PC-12/47E ‘conversion training’ was a 6-day ground school facilitated by an experienced PC-12 instructor in accordance with a Facilitators Guide. Reference material included the POH/AFM, QRH, engineering training manual, PowerPoint presentations, videos, cockpit mock-up, components, and an aircraft. Information about the pitch trim system was available from the POH/AFM and a guided inspection of an aircraft. Learning assessments were carried out during and at the end of the course.
The second stage of PC-12/47E conversion training was flight training in the aircraft in accordance with a flight training syllabus. This was usually carried out over 5 flights and approximately 12 flight hours. The syllabus included review of CAS warnings/cautions such as Pitch Trim Runaway and use of the QRH. A flight review was incorporated into this training.
Following conversion training, pilots completed 50-100 hours of line oriented flight training (LOFT) with a training/check pilot or supervisory pilot in the aircraft. RFDS specified a number of competency items and discussion topics to be covered during LOFT. These did not specifically include Pitch Trim Runaway.
When pilots had completed all of the LOFT elements and were considered ready, a check pilot conducted a check-to-line assessment consisting of at least two sectors, one night sector, and a minimum of two instrument approaches. RFDS specified a number of elements to be assessed during normal operation and some emergency/abnormal scenarios. These did not include Pitch Trim Runaway.
Once a pilot was checked to line, recurrent checking consisted of two checks in any 365-day period. One of those checks was an instrument proficiency checks (IPC) to satisfy the regulatory requirements of CASR Part 61. The alternate check was an OPC that consisted of a technical quiz and flight sequences to assess pilot response to at least four emergency scenarios. In addition, an annual line check was carried out to allow assessment of a medical flight sector.
Training and checking practices – pitch trim runaway
In the RFDS training and checking framework, it was a requirement that the emergency procedures in the QRH were addressed during PC-12 conversion training, check-to-line, OPC, and as required for IPC. RFDS identified six critical manoeuvres with an increased level of threat (such as emergency descent and engine failure after take-off) that required specific assessment during OPCs. Other emergencies, such as Pitch Trim Runaway, could be addressed in an OPC at the discretion of the check pilot.
Pilatus did not recommend a method for in-flight practice of Pitch Trim Runaway, other than the guidance provided in Safety Information Letter SIL-003 that there was a benefit to hands-on training for correct operation of the Trim Interrupt switch. Although RFDS specified techniques for their training/check pilots to use in simulating some emergencies such as engine failures, there was no documented method for pitch trim runaways. The ATSB derived information about practices from interviews with RFDS training/check pilots including those involved in the pilot’s training and checking.
It was not possible to replicate a pitch trim runaway in a serviceable aircraft nor would that be desirable in-flight. As such, it was common practice for RFDS training/check pilots to introduce a pitch trim runaway scenario by annunciating the warning callout ‘Trim Runaway’ and advising of the associated CAS warning message. The physical effects might be described by the training/check pilot, or represented either by using the alternate stab/manual trim to provide trim input or by application of a progressive force to the control column.
Training/check pilots expected pilots to respond by recalling and following the Pitch Trim Runaway procedure, starting with item 1 - identification of the Trim Interrupt switch. There was variation as to whether the switch was actually selected to INTR or whether this action was indicated in accordance with the touch drill principle. At this point, the training/check pilot would generally stop trim inputs or release force on the control column, as the case might be. The ATSB notes that trim interruption will stop trim inputs but will not alleviate control forces developed to that point.
If the training/check pilot initiated the pitch trim runaway on final approach, the likely outcome was a landing without a requirement for further actions from the emergency procedure. In all other situations, training/check pilots would expect that the pilot would proceed with further items of the procedure. For actions involving circuit breakers (items 2, 5, 6), it was a general principle that these were not pulled opened during practice of emergencies to prevent inducing problems in electrical systems. As such, the circuit breaker action items would be effected through touch drills or referenced by the pilot in discussion with the check pilot.
Although the end-point of a pitch trim runaway scenario was not defined and could vary according to the operational context, it was common for check pilots to facilitate the exercise so the complete procedure was addressed. This was consistent with a general misunderstanding in RFDS that the autopilot trim was powered through the Pitch Trim Alternate circuit breaker (rather than Pitch Trim circuit breaker). Consequently, it was perceived that items 4 onwards of the emergency procedure (Figure 6) may be required to address a malfunction in the autopilot trim system. On completion of the procedure, the check pilot could restore normal trim operation or might advise the pilot to use the alternate stab trim for trim operation during the next phase of flight.
In assessing pilot response to a pitch trim runaway scenario, training/check pilots were focussed on pilot recall of the QRH emergency procedure items and correct identification/confirmation of the applicable switches and circuit breakers. The representation of pitch trim runaway and effects of indicative actions did not consistently reflect actual behaviour of an aircraft during such an emergency.
The pilot of this occurrence expected that the control problems would be rectified when the Trim Interrupt switch was selected to INTR. If the pilot had promptly made that selection as intended, the control loads would have been manageable but the loads would not have been alleviated.
Following the occurrence, RFDS training/check pilots noted that the power control lever could obscure the Trim Interrupt switch when the lever was in the maximum position (used for take-off and initial climb). The ATSB confirmed that this was the case if the pilot’s seat was adjusted to provide a standardised field of vision with reference to the visual alignment device.
Pitch trim runaway occurrences
RFDS Western Operations
RFDS advised of seven pitch trim runaway events involving their PC-12 aircraft, including this occurrence. The ATSB requested data about these events and compiled the following table. For context, please note that all of the aircraft were PC-12/47E NG models and each of the events involved different registrations.
Table 1: RFDS Western Operations Pilatus PC-12/47E pitch trim runaway events
Ref
Occurrence date
Aircraft hours
Occurrence description
Fault
1.
10 June 2013
N/A
Single pilot operation – Day.
On approach at 500 ft, pitch trim runaway nose-up.
QRH recall items including Trim Interrupt carried out.
Nil use of Alternate Stab Trim. Reported use of manual trim.
Missed approach, normal landing.
Manual trim relay.
2.
5 May 2015
7,631
Two pilot (LOFT) operation - Day.
On approach at 300 ft, pitch trim runaway nose-up.
QRH first recall item – Trim Interrupt only carried out (due context).
Nil use of Alternate Stab Trim – not applicable.
Normal landing.
Manual trim relay.
3.
17 February 2017
3,821
Single pilot operation - Day.
On final approach, pitch trim runaway nose-down.
QRH recall items including Trim Interrupt carried out.
Alternate Stab Trim switch used to adjust trim.
Normal landing.
Manual trim relay.
4.
22 August 2018
11,912
Two pilot (LOFT) operation - Day.
On downwind approach, pitch trim runaway nose-up.
QRH recall items including Trim Interrupt carried out.
Nil use of Alternate Stab Trim.
Normal landing.
Trim adaptor (autopilot related).
5.
19 January 2019
3,431
Single pilot – Day.
On descent with autopilot on, pitch trim runaway.
QRH recall items including Trim Interrupt carried out plus Pitch Trim – Alternate circuit breaker pulled.
Nil use of Alternate Stab Trim.
Diversion and normal landing.
Trim adaptor (autopilot related).
6.
14 April 2019
(occurrence)
7,377
Single pilot – Night.
After take-off, pitch trim runaway nose-down.
QRH recall items carried out but Trim Interrupt mis-selected. Control difficulties. Further items.
Nil use of Alternate Stab Trim.
Return for flapless landing with control difficulties.
Manual trim relay.
7.
3 August 2019
(post occurrence)
12,272
Two pilot (LOFT) operation - Day
After take-off, pitch trim runaway nose-down.
Recall items including Trim Interrupt carried out.
Alternate Stab Trim switch used to adjust trim.
Return for normal landing.
Manual trim relay.
The ATSB reviewed the occurrence descriptions and maintenance records for the five pitch runaway events recorded before the occurrence, and interviewed the pilots involved except for one trainee pilot who was no longer with RFDS.
In one of those events (Ref. 2), the aircraft was on short final and the pilot operating under supervision carried out item 1 of the procedure then landed the aircraft. The training/check pilot advised the ATSB that the aircraft was controllable and there was no requirement or time to action further items of the procedure before landing.
In another event (Ref. 3), the pilot was on approach and the pilot actioned the recall items followed by appropriate use of the Alternate Stab Trim switch. The pilot advised the ATSB that knowledge of the system was gained from RFDS training/checking and from self-study.
In the other three events (Ref. 1, 4, 5), the same pilot was involved as pilot in command including one event under supervision of a training pilot. The pilot involved in the three events had joined RFDS in 2012. Prior to that, the pilot was employed as a corporate jet pilot for 3 years. In 2019, the pilot’s total experience was 11,900 hours including 3,000 hours on the PC-12. These three events are noteworthy in that the Alternate Stab Trim switch was the only means available to adjust trim but was not utilised following the recall items, and there were anomalies in the pilot in command’s technical understanding of the events and pitch trim system.
The pilot response to the first pitch trim runaway was consistent with the recall items of the procedure but the pilot did not realise that manual trim was consequently inoperative and was not aware that the Alternate Stab Trim could be used for trimming. In response to the two other events, the pilot continued the emergency procedure beyond the recall items and in at least one case pulled the Pitch Trim Alternate circuit breaker. That was not consistent with the recorded fault and it is not clear if and how the pilot trimmed the aircraft as reported.
RFDS Central Operations
The ATSB requested pitch trim runaway occurrence data from RFDS Central Operations (RFDSCO), as another operator of similar PC-12 aircraft. RFDSCO advised that there was no record of any verified pitch trim runaway events involving their PC-12 aircraft in the 9 years prior to the occurrence that such data had been recorded. For context, RFDSCO operate a mix of PC-12/47E NG aircraft and earlier series aircraft.
ATSB database
The ATSB conducted a search of the occurrence database for pitch trim runaway events involving the PC-12 aircraft type and a comparative aircraft type, the Beechcraft/Raytheon/Textron King Air. Apart from this occurrence, no pitch runaway events for either type were recorded in the ATSB database.
As reported in a previous section, RFDS identified six other pitch trim runaways involving their PC‑12 aircraft. These were not reported to the ATSB.
In response to a query from the ATSB, RFDS advised that the other pitch trim runaways were considered to be routine defects and handled via the incident reporting and/or maintenance reporting systems. Each of the events recorded in the incident reporting system were reviewed by the Head of Flying Operations and considered to have been handled appropriately.
The Transport Safety Regulations 2003 stipulate reporting of certain events to the ATSB. For a non-air transport operation such as RFDS, the use of any procedure for overcoming an emergency was prescribed as a routine reportable matter. The ATSB considered that a pitch trim runaway required a pilot to action the applicable emergency procedure and was therefore a routine reportable matter.
Pilatus records
At the request of the ATSB, Pilatus provided pitch trim runaway occurrence data for the PC-12 aircraft type. Pilatus recorded 56 pitch trim runaway events world-wide between 1999 and 2019. These occurred in all phases of flight and included at least 45 events involving the PC-12/47E model.
In 47 of the pitch trim runaway events, the recorded maintenance action was replacement of one or both of the manual trim relays or the (autopilot-related) trim adapter unit. None of the recorded maintenance actions were applicable to the alternate stabiliser trim circuit.
The amount of detail in the event descriptions varied and some did not provide information about pilot actions. For 10 events, there was recorded alternate stab trim use by the pilot and for three events, the pilot reported having insufficient time to action the emergency procedure before landing. In one event, the pilot tried to use the alternate stab trim but it did not operate.
Where pilot action was reported, it was common for the Trim Interrupt switch to be selected with associated stopping of the pitch trim runaway. There were no reports of pilot mis-selecting the Flap Interrupt switch instead of the Trim Interrupt switch.
Instructions for Continuing Airworthiness – Pilatus
As the aircraft manufacturer and type certificate holder, Pilatus produced specifications and instructions for continued airworthiness of the PC-12 aircraft type. Those instructions included periodic functional checks of the pitch trim system and procedures for troubleshooting and component replacement. Up to the month before the occurrence, there were no specific maintenance requirements for the manual trim system relays or trim adapter unit. As such, the relays remained in service ‘on‑condition’ until a defect was detected.
In March 2019, Pilatus issued Service Bulletin SB 27-024 to provide for replacement of the trim adapter unit that used electro-mechanical relays (auto pitch trim) with a unit that uses solid-state relays. At the time of the occurrence, Pilatus had prepared Service Bulletin SB 27-023 to provide for replacement of the two electro-mechanical relays in the manual pitch trim system with one solid-state relay. This was not issued until March 2020 due to limited parts availability.
Pilatus advised that the two Service Bulletins were developed to address a known reliability issue with the electro-mechanical relays. Due to frequent switching at their load limits, the relay contacts had a decreased operational life of approximately 25,000 cycles.
Examination of PC-12 pitch trim system relays
The electro-mechanical relays used in the PC-12 pitch trim system were a two-pole, double-throw design. Each pole consisted of a common terminal that was switched between a normally open contact and a normally closed contact. For this installation, only one pole was utilised.
Defective relay removed from VH-OWJ
The ATSB examined the manual pitch trim DOWN relay (identification number K161E2) removed from VH-OWJ to characterise the failure mode and assess the implications for continuing airworthiness. A visual inspection of the relay did not identify any anomalies (Figure 7). The markings were consistent with the specifications.
To record the internal configuration of the relay, the ATSB arranged for an x-ray before the relay was altered (Figure 8). This showed that for both poles of the relay, the normally open contacts were closed and the normally closed contacts were open. Electrical continuity checks of the pins were consistent with that anomalous configuration.
The ATSB detached the casing from the base of the relay to examine the internal mechanism (Figure 9). A visual inspection of the mechanism confirmed the anomalous configuration of the contacts and revealed the failure type for the normally open contacts.
For the relay pole connected to the pitch trim circuit (active), the normally open contact was melted and fused close. There was sooting on surfaces near the contacts and black contaminant from the black caps that covered the contacts. Beads of gold-coloured metallic material was observed on surfaces near the contacts. As a result of the fused contact, the other contacts were fixed in anomalous positions.
The relay manufacturer advised the ATSB that the condition of the contacts was consistent with a significant high-energy event that occurred while the relay was energised. The melting and welding of the contacts without circuit breaker activation is indicative of a short-duration high-current event such as a lightning strike. It was not possible for the manufacturer to determine the root cause of the relay failure.
Figure 7: External condition of defective relay
Source: ATSB
Figure 8: X-ray of defective relay showing anomalous configuration of the contacts (circled).
Source: ATSB
Figure 9: Opposite end views of relay mechanism showing the two sets of anomalous contact conditions
Source: ATSB
Other relay removed from VH-OWJ
The ATSB obtained and examined the manual pitch trim UP relay (identification number K161D2) from VH-OWJ. This relay was installed in the aircraft at the time of the occurrence and was functioning normally at the time of removal.
A visual inspection of the relay did not identify any anomalies and the markings were consistent with the specifications. The ATSB detached the casing from the base of the relay to examine the internal mechanism.
The active normally-closed contacts showed a localised build-up of metallic material on one contact surface (pimple-shaped) with corresponding loss of material from the other surface. This was consistent with electrical arcing.
Defective relay from other PC-12
The ATSB obtained and examined the manual pitch trim DOWN relay (identification number K161E2) from the RFDS aircraft that sustained a trim runaway on 3 August 2019 (Table 1, item 7).
A visual inspection of the relays did not identify any anomalies and the markings were consistent with the specifications. The ATSB detached the casing from the base of the relay to examine the internal mechanism.
The internal condition of the relay was similar to the defective relay from VH-OWJ. The active normally-open contact was melted and fused close. There was sooting on surfaces near the contacts and beads of gold-coloured metallic material was observed on surfaces near the contacts. As a result of the fused contact, the other contacts were fixed in anomalous positions.
The active normally-closed contacts showed localised material transfer that was similar to that observed to contacts in the manual pitch trim UP relay from VH-OWJ.
PC-12 Pitch trim defect reports
The ATSB provided details of the relay examination and analysis to CASA. They conducted a search of the CASA Defect Reporting Service (DRS) database for reports of defects in the PC-12 autopilot and flight control systems. This identified a number of reports including one report of a faulty pitch trim adapter (to a non-RFDS aircraft). No reports of manual pitch trim relay defects were identified.
For aircraft maintained under the Civil Aviation Regulations, it was a requirement that major defects be reported to CASA immediately. This included defects that caused, or that could cause, a control system failure. The list of examples published by CASA included serious malfunction of flight controls without specifying any types.
CASA uses defect reports as a means of identifying trends in design and maintenance reliability for the benefit of aviation safety. Reports are collected by CASA and maintained in a database. It is of benefit to both CASA and the aviation industry that the database contains accurate and relevant information. From this database, information may be:
obtained to provide reliability statistics and trend monitoring of aircraft, engines, propellers, systems and components - CASA shares this information with other regulatory authorities
used as a basis for development or review of an Airworthiness Directive (AD)
used for the development of other advisory publications, such as Airworthiness Bulletins
used for other appropriate regulatory purposes.
RFDS advised that no defect reports were submitted to CASA in relation to the malfunctions that resulted in pitch trim runaway events. This practice was based on the definition of a major defect as that which affects the safety of an aircraft or cause the aircraft to become a danger to persons or property. As there were secondary systems to manage a pitch trim runaway, RFDS did not consider the associated malfunctions to be major defects.
The ATSB was unable to establish if relay malfunction with pitch trim runaway was classified as a major defect as described in the Civil Aviation Regulations. Nevertheless, operators are encouraged to submit reports of PC-12 pitch trim defects to the DRS to facilitate CASA monitoring of continuing airworthiness data. __________
In the early stages of a medical transport flight, the pilot was confronted with a pitch trim runaway emergency condition. Despite pilot actions intended to stop the runaway, the runaway was not interrupted and the pilot struggled to control the aircraft for the rest of the flight. The pilot made a good decision to enlist the assistance of the doctor and managed to coordinate their inputs to land the aircraft.
The pilot was qualified to conduct the flight and had about 7 months experience of similar operations in the PC-12 type. This patient transfer from Merredin was not a high priority flight and the aircraft was serviceable for the departure. Although the pilot was on a night shift and the take-off from Merredin was just after midnight, there were no indications of fatigue.
The safety analysis following seeks to explain how the event developed and identify the important safety considerations.
Technical failure and warnings
During normal operation of the PC-12 aircraft with the autopilot off, the pilot seeks to minimise control wheel forces by intermittently selecting the engagement switch in conjunction with the up/down switch on the control wheel. These actions energise the applicable relay and power the trim motor to move the horizontal stabiliser as directed. When the pilot releases the switches, the control circuit de‑energises the applicable relay with the usual effect of opening the power circuit to the manual trim motor and stopping trim movement.
Soon after take-off from Merredin, the pitch trim system continued to operate in a nose-down direction without pilot input or autopilot commands because of a malfunctioning relay in the manual (main pilot‑engaged) stabiliser trim system. The trim system immediately detected a pitch trim runaway and triggered the applicable Crew Alerting System (CAS) warnings.
The Master Warning, ‘Trim Runaway’ callout, and the Pitch Trim Runaway message on the Multi-function Display (MFD) provided an effective alert as to the nature of the emergency and correlated with the anomalous control forces experienced by the pilot. In this fully electric trim system (no trim wheel), the other indication available to the pilot was the trim indicator on the MFD.
As was typical for aircraft such as the PC-12, the CAS warnings did not specify the malfunctioning circuit/components or the required actions. In such cases, the pilot is required to action the applicable emergency procedure to stop the runaway, identify the affected circuit, disable the affected circuit, and utilise the unaffected circuit to make any required trim adjustments.
Initial pilot response
In response to the CAS warnings, the pilot sought to carry out the first recall item of the Pitch Trim Runaway emergency procedure by selecting the Trim Interrupt switch to INTR (interrupt). The pilot managed to action this item about 6 seconds after the warnings activated. However, recorded flight data shows that the pilot inadvertently selected the Flap Interrupt switch to INTR rather than the Trim Interrupt switch and did not identify the mis-selection.
Common aviation operational practice, also advocated by RFDS, involves an ‘identify-confirm-action’ process to minimise the inadvertent selection of wrong switches and buttons. In that context, the ATSB considered the following factors that might have influenced the pilot to mis‑select the interrupt switch:
emergency flight control condition at low altitude on dark night
visibility of the Trim Interrupt switch and label
similar location and appearance of the two interrupt switches
lack of familiarity with operating the Trim Interrupt switch during training/checking.
In the situation where there is sudden onset of an emergency condition affecting control forces at low altitude on a dark night, it is natural for the pilot to feel a sense of concern and urgency. This might have been heightened by unfamiliarity with the scenario that could not be realistically simulated in the aircraft. As such, it would be expected that the pilot would be experiencing some level of stress.
As the trim runaway progressed, the pilot’s attention was primarily focussed on controlling the aircraft and counteracting the developing pitch-down forces with both hands on the control wheel. Given the pilot reported that any hand movements from the control wheel were quick, it is likely that the pilot allocated a low level of attention to identifying and confirming the appropriate interrupt switch.
During take-off and initial climb the power lever was in a forward position. In a pilot’s normal field of view, the power lever obscured the Trim Interrupt switch but not the Flap Interrupt switch. This rendered the Flap Interrupt switch as relatively more accessible and in the circumstances, at higher risk of being mis-selected. At the same time, the cockpit lighting was dimmed for the dark‑night take-off in accordance with standard practice and that unavoidably reduced the readability of the backlit switch labels.
The Trim Interrupt switch and Flap Interrupt switches were both located in the centre console and appeared to be the same type of switch with a similar function (Figure 4 bottom right). Although the switches were differentiated by being located either side of the Alternate Stab Trim switch, and the Flap Interrupt switch was located forward of the Flap Selector Handle, the similarities increased the risk of mis‑selection.
Training and checking practices were generally oriented towards touch drills and it was unlikely that the pilot was familiar with physical operation of the Trim Interrupt switch. Given the Pilatus advice that hands-on training minimises the risk of erroneously activating the Flap Interrupt switch, it is likely that a higher level of familiarity would have assisted the pilot.
The ATSB considered the contextual factors to identify those that increased risk and might have contributed to the occurrence. Although the operating environment and visibility of the trim interrupt switch increased the degree of difficulty for the pilot, those elements are generally unavoidable and were not considered to be safety factors. The risk associated with the other two factors —interrupt switch similarities and RFDS training/checking practices—is discussed in the following section.
Following inadvertent selection of the Flap Interrupt switch, there were indications that the results were contrary to the pilot’s intention—the pitch trim continued to operate and the runaway warning message remained on the CAS display. Later, the pilot also noticed the ‘Flap’ caution message in association with attempted flap extension. However, the pilot did not associate those indications with the mis-selection.
One of the reasons for this was the surprise and confusion resulting from non-alleviation of the control forces in response to the attempted trim interrupt. That was a natural response that was probably influenced by the inconsistent representation of trim interrupt effects in training/checking. The pilot experienced a high level of stress that adversely affected the pilot’s ability to carry out the next item immediately (which would have stopped the runway) and to problem-solve.
Research has confirmed common-sense understanding that situations involving acute stress, such as an out-of-control aircraft, are particularly harmful to higher order cognitive processes, such as decision-making (Dismukes, Goldsmith and Kochan, 2015). Acute stress impairs decision-making, leading to the consideration of fewer options and an increased tendency to make biased decisions. Attention becomes difficult to control, and tends to be easily distracted by alarms and other threatening signals. Anxious thoughts interfere with the resources needed to understand and resolve the emergency situation.
A potentially complicating factor in the pilot’s response was the momentary cancellation and recycling of the CAS warnings from pilot use of the manual trim switches. This characteristic was only evident because of the unsuccessful trim interrupt and was a subtle indication that manual trim was the affected circuit that had not been de-powered. The pilot was not expected to have that level of implicit systems knowledge and did not consider the possibility of switch mis-selection. In that case, the unexpected aircraft behaviour was confusing and treated as a symptom of the underlying technical problem.
As a consequence of the Trim Interrupt remaining in NORM (normal) due to the inadvertent selection of the Flap Interrupt switch, and the Pitch Trim circuit breaker initially remaining closed, power continued to be supplied through the malfunctioning relay to the manual stabiliser trim motor. The pitch trim reached the full nose down position 16 seconds after the runaway started. This created serious control difficulty for the pilot, which was exacerbated by the increasing airspeed.
Airspeed management
From the start of the pitch trim runaway, as the manual trim motor moved the horizontal stabiliser to a higher angle, the stabiliser produced progressively more lift that translated to nose-down force. The pilot was physically unable to fully counteract that force with the control wheel and the aircraft nose lowered. In the consequent descent, the airspeed increased with an associated increase in stabiliser lift and nose-down force. The pilot found this harder to counteract and the aircraft nose lowered further. This was a reinforcing cycle that reoccurred during the sequence relative to the counteracting effort applied to the controls.
In addition, when the pitch trim runaway began, the power lever was in the maximum engine torque position specified for take-off and initial climb. It remained in that position for the next 22 seconds and was a significant contributor to the initial airspeed increase. The airspeed reached 210 kts with increased risk of descent into terrain before the pilot reduced engine torque and airspeed to partially alleviate the control loads and arrest the descent.
The Pitch Trim Runaway procedure included a note after item 7 advising pilots to reduce speed if the control forces are high. In the circumstances, the most effective means to reduce airspeed was to reduce engine torque.
The ATSB considered that the time taken by the pilot to reduce engine torque after the pitch trim runaway warning was associated with the pilot’s cognitive and physical workload as discussed in the previous section. It is likely that the pilot was prioritising aircraft control and conduct of emergency procedures, and did not perceive an immediate need to reduce engine torque. In addition, as the trim runaway developed, it became more difficult to remove a hand from the control wheel to adjust the power lever.
For flight control emergencies such as out-of-trim conditions, there is an imperative to maintain control while resolving the technical problem. A critical factor for pilots to consider is control of airspeed and associated engine power.
Continuation of emergency procedure
As control loads allowed, the pilot managed to carry out item 2 of the emergency procedure by opening the Pitch Trim circuit breaker. This de-powered the circuit with the malfunctioning relay and manual actuator motor so that the fault condition was effectively neutralised. As the trim had already run to full nose down (due to not stopping when the pilot selected the wrong interrupt switch), the only indication that this action had been successful was removal of the CAS message from the MFD.
The pilot then sought to carry out item 3 of the procedure to return the Trim Interrupt switch to NORM. It is assumed that the pilot returned the Flap Interrupt switch to NORM instead of the Trim Interrupt, consistent with earlier mis-selection of the Flap Interrupt switch. This did not have any further effect as the Trim Interrupt switch remained in NORM throughout the flight and the wing flaps remained inoperative irrespective of subsequent switch selections.
At this point, the pilot was required to make a decision according to the status of the trim runaway. With the fault condition neutralised and power available to the operable trim circuits, the pilot could have adjusted the pitch trim using the Alternate Stab Trim switch and regained full control of the aircraft. That would have been consistent with the intent of the procedure, although it was listed as item 8 in the procedure. However, the pilot did not use the alternate stab trim and decided to proceed with further items of the procedure, consistent with the condition ‘If trim runaway continues’.
The pilot opened the Pitch Trim Alternate circuit breaker as per item 5 and closed the Pitch Trim circuit breaker as per item 6. This had dual adverse effects. First, power was removed from the operative alternate trim system and second, power was restored to the malfunctioning relay and manual trim motor for a short period. (This reactivated the warnings and prompted re-opening of the Pitch Trim circuit breaker.) As a consequence of opening the Pitch Trim Alternate circuit breaker (item 5), when the pilot tried to use the Alternate Stab Trim as per item 8 of the procedure, the circuit was inoperative and this did not have any effect.
While maintaining partial control of the aircraft in difficult circumstances, the pilot managed to neutralise the malfunctioning relay in the early stages of the sequence. However, the pilot missed a critical opportunity to use the Alternate Stab Trim switch to recover control of the aircraft. By continuing the emergency procedure from item 4 onwards, the pilot disabled the operative trim system and prolonged the serious control difficulties.
The ATSB acknowledges that the serious difficulties experienced by the pilot in this phase of the emergency resulted from non-selection of the Trim Interrupt switch and consequent full nose-down pitch trim before the Pitch Trim circuit breaker was pulled. In addition to the extreme flight loads and deleterious effects of acute stress on decision-making, another consequence was absence of trim operation as an indication of runaway status. As such, when the pilot was required to assess the effect of recovery actions, the only effective indicator was activation/cancellation of the Pitch Trim Runway CAS message.
Irrespective of the ineffective actioning of item 1 of the emergency procedure, the subsequent actions required for recovery of control—items 2, 3 and 8—were unchanged. The pilot, however, did not have capability to resolve the out-of-trim condition, which relied in part on resources provided by Pilatus and training/checking provided by RFDS. These aspects are discussed in following sections.
The ATSB notes that pilot capability in this aircraft-specific context should not rely on certain levels of total aeronautical experience levels or operational experience on comparative aircraft types.
Trim Interrupt and Flap Interrupt switches
The pilot’s mis-selection of the Flap Interrupt switch in place of the Trim Interrupt switch contributed to the development of severe control forces. One of the factors identified by the ATSB was the similar location, appearance, and function of the Trim Interrupt and Flap Interrupt switches.
To manage the risk of switch mis-selection generally, RFDS training/check pilots advocated the practice of identify–confirm–action. In relation to the Trim Interrupt switch, pilots were required to identify the switch when pitch trim runaways were addressed during training/checking. RFDS pilots were also familiar with the location of both switches from the pre-flight inspection conducted on a pilot’s the first flight of the day in a particular aircraft.
Pilatus inferred there was a risk of erroneously activating the Flap Interrupt switch and that hands‑on training would reduce that risk. In the RFDS context, mis-identification of the Trim Interrupt switch was not evident during training and checking and, in the previous pitch trim runaway occurrences, the pilots had correctly identified and actioned the Trim Interrupt switch. However, the artificiality of the training/checking environment and the relatively benign conditions experienced by most pilots during the previous pitch trim runaways occurrences (daylight and phases of flight other than take-off/initial climb) were very different from conditions of this occurrence.
In the 57 pitch trim runaway events recorded by Pilatus, there were no reports of mis-selection of the Flap Interrupt instead of the Trim Interrupt switch. Although this indicates that the risk is generally not high, it may be sensitive to phase of flight and environmental conditions. There was insufficient information in the Pilatus data to make an assessment of that risk.
The risk of mis-identification could be reduced by pilots manipulating the switch during training/checking and by increased awareness of the effects of inadvertent selection of the Flap Interrupt switch. Consideration could also be given to daily pre-flight operation of the Trim Interrupt switch as implemented for Canadian PC-12 aircraft. Although these procedural controls reduce the risk, it would be preferable to implement an engineering control to remove the hazard.
The similarities between the Trim Interrupt and Flap Interrupt switches and the proximal location of the two switches unnecessarily increased the risk of mis-selection. While visually distinguishing close proximity switches and controls has long been shown to be an effective strategy (for example, landing gear and flap retraction levers are typically designed to resemble the lever’s function), given pilots are not required to access the Flap Interrupt switch, consideration could also be given to preventing access to it altogether.
Pilatus emergency procedure and systems information
Pilatus advised pilots in the POH/AFM that the prerequisites for safe aircraft handling in an emergency is prior knowledge of the applicable procedure and a good understanding of the aircraft systems. The ATSB used this statement as a reference point to assess the related factors in pilot capability.
Prior knowledge is taken to be familiarity with the content and application of the Pitch Trim Runaway procedure. In this case, RFDS required the pilot to memorise at least the first four items of the Pitch Trim Runaway procedure and addressed this in PC-12 flight training and the recent OPC. Despite mis‑selection of the Trim/Flap Interrupt in this occurrence, the pilot demonstrated familiarity with all of the items of the procedure by addressing each in turn.
Pilatus did not nominate any recall items (also known as memory, phase-1 or bold-faced checks) for PC-12 emergency procedures. In the case of the Pitch Trim Runaway procedure, Pilatus advised the ATSB that their preference would be designation of item 1 as the only recall item to place the focus on the crucial item and positively arrest any trim runaway from any cause. Although the ATSB recognises there are benefits to minimising recall items, there is nothing to indicate that the number of nominated recall items in RFDS procedures were a factor in this occurrence.
The degree of knowledge required for a good understanding of aircraft systems is dependent in part on the complexity of the aircraft and the nature of the pilot-systems interface. Given the relative complexity of the aircraft and regulatory requirements, RFDS provided a PC-12 ground school to the pilot that covered the pitch trim system with reference to the POH/AFM. It would be natural for this theoretical knowledge to be consolidated and/or extended by the PC-12 flying training and operator proficiency checks (OPCs).
Given the pilot was able to recall the emergency procedure and was trained with reference to the Pilot Operating Handbook/Airplane Flight Manual (POH/AFM), the ATSB considered the content and format of the emergency procedure and systems information provided by Pilatus. The associated training/checking aspects are addressed in the following section.
Pitch Trim Runaway emergency procedure
The copy of the Pitch Trim Runaway emergency procedure from Figure 6 is repeated here for ease of reference.
After item 3 of the emergency procedure, the pilot was required to make an assessment and decision about the status of the runaway and act accordingly. This assessment/decision point was defined in the procedure by the condition—‘If trim runaway continues’. Correctly understood, the implication is that the fault is not in the manual trim system and autopilot trim system but in the alternate stabiliser trim circuit.
The alternate stabiliser trim circuit is not used during normal operations and does not require any relays to be energised for operation. As such, the risk that this circuit would fail in an unsafe runaway condition is very low relative to a manual trim or autopilot circuit failure. This was consistent with advice from Honeywell that there was no record of any such failure.
The alternative condition at the assessment/decision point—if trim runaway does not continue—was implied but not specified in the procedure. In this more likely scenario, the fault in the manual or autopilot trim systems has been neutralised by item 2 (opening of Pitch Trim circuit breaker). Then, without any guidance from the procedure, pilots needed to understand that the procedure from item 4 to item 7 should not be continued and alternate stab trim was the only means available to trim the aircraft for the rest of the flight.
Significantly, alternate stabiliser trim was not specified in the procedure until item 8. This had two related adverse effects. First, pilots are not guided to use the alternate stabiliser trim at the point where it almost certainly would be effective at recovering from an out-of-trim condition (after item 3). Second, if the procedure is carried out in a sequential manner, item 5 (Pitch Trim Alternate circuit breaker open) will render item 8 (alternate stabiliser trim) inoperable.
Another consequence of lack of guidance and continuation of the procedure is that item 6 (Pitch Trim circuit breaker—Close) will reactivate the pitch trim runaway in almost all cases.
One of the notes near the end of the Pitch Trim Runaway procedure advised pilots to ‘Reduce speed if control forces are high’. The pilot response to the abnormal control forces was consistent with this advice but the airspeed reached high-risk figures before the pilot took effective action. In this case, the pilot was probably not prompted by the note in the procedure. However, if the note was positioned earlier in the procedure, it is possible that pilot would have acted earlier to reduce the airspeed and risk of loss of loss of control.
Pilatus advised the ATSB that instead of reliance on descriptions within the emergency procedure, the objective of the emergency procedures must be understood and ingrained during training for the procedure to be effectively executed. This was more applicable when the pilot is managing the emergency and unintended consequences. Pilots were directed to SIL-003 for a clear description of the requirements. A copy of SIL-003 is at Appendix B and ATSB assessment of the SIL is in the next section.
The ATSB considered that the PC-12 Pitch Trim Runaway emergency procedure did not clearly define the two conditions for pilot consideration after item 3. In addition, the specified action in response to the most likely condition—pitch trim runaway discontinues (as indicated by no active warnings)—was out of sequence. Given the confounding situation and complexity of the PC-12 pitch trim system, it is likely that a clearly defined and logically sequenced procedure would have assisted the pilot to regain control.
Pitch trim systems information
From an operational perspective, the primary reference for systems information was the POH/AFM. This included the following information relevant to this occurrence:
The alternate stabilizer trim motor could be used as a backup through actuation of the Alternate Stab Trim switch.
In the case of uncommanded trim operation, all trim operation could be stopped by lifting the switch guard and pressing the Trim Interrupt switch.
If a stabiliser trim runaway of the main system is sensed a CAS ‘Pitch Trim Runaway’ warning will be displayed and a ‘Trim Runaway’ will be heard.
The ATSB notes that although this information is helpful to a pilot contending with a pitch trim runaway, it does not provide guidance as to when the Alternate Stab Trim switch should be used or the significance of the CAS warning as an ongoing indicator of system status.
Additional information about pitch trim runaway was available in Pilatus Safety Information Letter SIL‑003. However, RFDS did not incorporate the SIL into their operational reference material and the pilot was not aware of it.
The additional information would have been generally helpful to the pilot and would have emphasised the importance of reduced airspeed in managing the out-of-trim loads. Nevertheless, the ATSB identified missed opportunities in SIL-003 to explain and clarify aspects of pitch trim runaway:
Hands-on training was advised to reduce the risk of erroneously activating the Flap Interrupt switch but pilots were not informed of the associated risk factors, symptoms or corrective action if that occurred.
Information was provided about the purpose of pulling a circuit breaker, without further guidance as to how the affected trim motor would be identified.
Pilots were advised that control of the unaffected systems could be regained by simply repositioning the Trim Interrupt switch to NORM, without guiding pilots to use the Alternate Stab Trim switch.
Neither SIL-003 nor POH/AFM informed pilots/operators that both the manual pitch trim and autopilot pitch trim were powered from the Pitch Trim circuit breaker. In the absence of that information, there is a risk of misapprehension that the autopilot pitch trim was powered from the Pitch Trim Alternate circuit breaker on the (correct) basis that the autopilot pitch trim utilised the alternate trim motor.
A consequence of this misapprehension is that pilots/operators may not realise that the first 3 items (and item 8 as required) of the pitch trim runaway procedure will almost certainly be sufficient to address a runaway condition. There is a risk that pilots will unnecessarily address all of the items in the procedure and not resolve a pitch trim runaway, as happened in this occurrence. The effect of this misapprehension on RFDS training/checking is discussed in the next section.
Another characteristic not covered in the information for pilots applies when the manual trim circuit is the active cause of a pitch trim runway. If the pilot engages manual trim, perhaps instinctively, the CAS warnings are cancelled for the duration of the engagement then reactivate on manual trim disengagement. Pilot awareness of this characteristic might be of assistance in an ill-defined emergency such as this occurrence.
In the context of this occurrence, the ATSB considered that the systems information in the PC-12 POH/AFM did not provide a detailed description of the pitch trim system or effective guidance in the management of a pitch trim runaway. Although SIL-003 presented additional information, it did not effectively compensate for the lack of detailed systems description and guidance in the POH/AFM.
Summary and finding
The PC-12 pitch trim system is complex and the CAS warnings for pitch trim runaway do not specify the malfunctioning circuit or the required actions. As a result, pilots are required to recall and action emergency procedures, interpret system indications, and act accordingly to resolve a pitch trim runaway.
This occurrence demonstrates that the consequences of a pitch trim runaway can be critical if the trim is not interrupted early in the emergency. In the context of this occurrence, the applicable risk controls such as the emergency procedure and systems information did not provide effective assistance to the pilot. The other RFDS pitch trim runaway occurrences did not have critical consequences but indicate variability in the effectiveness of these risk controls.
The relatively experienced pilot involved in three of the previous pitch trim runaway events was familiar with the emergency procedure and POH/AFM but did not interpret the system indications appropriately or act according to the intent of the procedure. During post-occurrence RFDS training/checking, it was apparent that there was variability in pilot understanding of the pitch trim system and associated emergency procedures. Given that variability, the ATSB considered that the occurrence pilot’s relative inexperience was not an important factor in the occurrence.
Pilatus recorded 47 pitch trim runaway events that were associated with defective relays in the manual trim system or the trim adaptor. In those events, the only method available to adjust the trim was use of the Alternate Stab Trim switch, which was reported in 11 of the events (one was unsuccessful). Taking into account those 11 events and the 3 events where the emergency procedure was not fully actioned due to the operational context, there were 33 pitch trim runaways where pilot use or non-use of Alternate Stab Trim is unknown. As such, there is insufficient information to derive a conclusion from the Pilatus data regarding pilot understanding of the pitch trim system and emergency procedure.
Given the pilot in this occurrence was familiar with the emergency procedure and trained by qualified personnel with reference to the POH/AFM, the ATSB considered the content and format of the emergency procedure and systems information in the POH/AFM in the context of RFDS and Pilatus occurrence data.
The ATSB found that the emergency procedures and systems information in the PC-12 POH/AFM and Quick Reference Handbook (QRH) did not provide effective guidance or sufficient information for pilots contending with a pitch trim runaway. If the pilot selects the Trim Interrupt switch early in the sequence and does not need to adjust the pitch trim, the risk is not significant. In this case, the lack of effective guidance and systems information probably had an adverse influence on the pilot’s capability to resolve the uninterrupted trim runaway condition and was a critical factor.
RFDS training and checking
The pilot’s capability to implement the Pitch Trim Runaway emergency procedure with a good understanding of the aircraft systems relied to a large extent on the training and checking provided by RFDS. Their training and checking organisation conducted the required ground school and flight training to qualify the pilot to operate the PC-12 aircraft type. This was supplemented by supervised line flying (LOFT) and operator proficiency checks (OPC) as specified by RFDS.
The PC-12 ground school was the primary means for RFDS to equip the pilot with the requisite knowledge of a wide range of aircraft systems. This included the pitch trim system, which was addressed with reference to the POH/AFM and as part of a guided inspection of an aircraft. Given the POH/AFM did not provide a detailed description of the pitch trim system and RFDS training/checking pilots were unaware of some characteristics, the information provided to the pilot accordingly had some limitations.
By the time the pilot was trained in 2018, Pilatus had issued SIL-003 (in 2017) as a reminder of the trim runaway procedures in the POH/AFM and to highlight decision-making considerations after the trim runaway condition is stopped. RFDS had not formally considered this document and it was not a supplementary reference in the ground school. Although this document would have been generally helpful to the ground school facilitator and this pilot, the focus of the SIL was operational and it did not provide any further significant detail about the pitch trim system. As such, the absence of the SIL from the ground school references was not considered to be a factor in the occurrence.
Although systems knowledge is not the prime focus of flying training, supervised line flying or operator proficiency checks, these processes generally help to consolidate the pilot’s understanding of aircraft systems and might show if there were any critical knowledge deficiencies. There was no indication of any such deficiencies.
The PC-12 flying training and operator proficiency checks were the primary means for RFDS to develop and verify the pilot’s capability to manage in-flight emergencies such as pitch trim runaway. These training/checking activities were oriented to the recall and practice of the applicable emergency procedures in the QRH. As a result, it could be expected that the pilot was familiar with the content of the procedures and location of the applicable switches and circuit breakers.
Although the pilot was able to recall the items in the emergency procedure, the initial switch selection was incorrect and the pilot actioned further items of the procedure without resolving the severely out-of-trim condition. The ATSB considered two aspects of the training/checking processes that might have played a role.
First, the practice exercises for pitch trim runaway were not consistent with the likely failure modes and recovery actions. Prior to this occurrence, RFDS operated on the basis that the manual trim was powered from Pitch Trim circuit breaker and the autopilot trim (utilising the alternate trim motor) was powered from the Pitch Trim Alternate circuit breaker. As a result, in response to a practice pitch trim runaway, pilots were expected to complete the first stage (items 1-3) at a minimum and it was common to continue the procedure (items 4-8) to represent an autopilot-related runaway scenario.
Actually, both manual and autopilot systems are powered from the Pitch Trim circuit breaker so the first stage (items 1-3) and item 8 (as required) of the emergency procedure are sufficient to manage a pitch trim runaway in all recorded cases to date. In the absence of a clear definition of failure modes, the pilot was conditioned to continue the emergency procedure beyond the first stage without use of the Alternate Stab Trim.
RFDS misunderstanding of the pitch trim system can be attributed in part to the lack of specific detail in the POH/AFM and unclear definition of the likely fault conditions in the emergency procedure. Although there was a report of some consideration of SIL-003 and consequent inclusion of pitch trim runaway scenarios in checks, RFDS did not formally consider the implications for their training/checking practices.
The key piece of additional information provided by the SIL was the advice:
Hands-on training reduces the activation time and minimizes the risk of erroneously activating the “Flaps Interrupt” system switch (which cannot be reset in-flight).
In the pre-occurrence context, with no instances of mis-selections in occurrences or training/checking, it is unclear if RFDS would have adopted that practice as an exception to the touch-drill principle. Nevertheless, Pilatus consider SIL-003 to be effective additional guidance for the management of a pitch trim runaway.
Second, the RFDS training/checking was carried out in-aircraft and this has inherent and unavoidable constraints for the practice of some emergencies. It is not technically feasible or necessarily safe to initiate a pitch trim runaway in the aircraft so the training/checking pilot described a scenario and/or discreetly made a flight control input. Accordingly, the trainee did not experience the realistic effects of a pitch trim runaway with the applicable CAS indications. Then, the pilot generally responded with a touch-drill and did not fully experience the physical action and system feedback.
As a consequence of both aspects, the occurrence pilot had developed an expectation that selection of the Trim Interrupt to INTR should have stopped the dive and the opened circuit breaker should have relieved the situation. In reality, the trim interrupt function simply stops the trim where it is and the opened circuit breaker does not provide any further relief at that point.
The ATSB found that the effectiveness of RFDS training and checking processes for pitch trim runaway was undermined by incomplete systems information and unrealistic practice exercises associated with training/checking in the aircraft (non-simulator).
Relay failure
The ATSB examined the defective manual pitch trim DOWN relays removed from VH-OWJ and another PC-12 that sustained a pitch trim runaway. In both relays, one set of the normally open contacts were fused together in a similar way. According to the relay manufacturer, this type of damage was consistent with a short-duration high-current event such as a lightning strike.
The transfer of material between contacts in the manual pitch trim UP relay removed from VH-OWJ and the manual pitch DOWN relay from the other PC-12 showed that the related circuits had been subjected to regular arcing.
Based on examination of the three manual pitch trim relays from two different aircraft, the ATSB considered that the risk of surge voltage and over current in the PC-12 pitch trim system was probably not limited to a particular aircraft. The relay failures recorded by RFDS and Pilatus in connection with pitch trim runaway events are indicative of the same failure mode. Considering the near identical failure mode within the same pitch trim relay of varying aircraft, it is less likely that the cause would be a random event such as a lightning strike. The ATSB considers that the failure is more likely due to a characteristic associated with the pitch trim circuit, such as potential surge currents cause by switching the inductive load of the pitch trim actuator.
At the time of the occurrence Pilatus had identified a reliability issue concerning the mechanical relays in the PC-12 pitch trim system. This is consistent with the ATSB’s concern that a characteristic of the pitch trim circuit may have contributed to the relay failure.
Pilatus have developed service bulletins to introduce solid-state relays into the pitch trim power circuits. The ATSB notes that solid-state relays are also susceptible to failure from surge voltages. A typical failure mode for solid-state relays is short-circuit, in which case the load would not be turned off and a pitch trim runaway would occur.
Although Pilatus service bulletins SB 27-023 and SB 27-024 address the reliability of relays in the pitch trim system, the ATSB considers that the risk of pitch trim runaway may not be significantly reduced. As such, Pilatus may need to conduct further research into the electrical loads present in the PC-12 pitch trim system to identify and address the source of the high energy events that damage relays.
Findings
From the evidence available, the following findings are made with respect to the pitch trim runaway and partial loss of control involving a Pilatus PC-12/47E, registered VH-OWJ that occurred near Merredin, Western Australia on 14 April 2019. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
Contributing factors
Soon after take-off in dark-night conditions, the pitch trim system continued to operate in a nose-down direction without pilot input or autopilot commands (pitch trim runaway) because of a malfunctioning relay in the manual (main pilot-engaged) stabiliser trim system.
In response to the Crew Alerting System warnings, the pilot initiated the Pitch Trim Runaway emergency procedure but inadvertently selected the Flap Interrupt switch rather than the Trim Interrupt switch (item 1). Consequently (before the next checklist item was actioned), the pitch trim continued to runaway until it reached full nose-down with associated serious control difficulties.
After the pilot addressed items 2 and 3 of the emergency procedure, the malfunction was neutralised and the alternate stabiliser trim system was available to adjust the trim. However, the pilot did not identify those positive conditions and continued with items 4 to 8 of the procedure, which disabled the alternate stabiliser trim system, prevented pitch trim adjustment and prolonged the serious control difficulties.
The similarities between the Trim Interrupt and Flap Interrupt switches and the proximal location of the two switches unnecessarily increased the risk of mis-selection and contributed to the excessive out-of-trim condition.
The emergency procedures and systems information in the PC-12 Pilot’s Operating Handbook/Airplane Flight Manual and Quick Reference Handbook did not provide effective guidance or sufficient information for pilots contending with a pitch trim runaway. If the pilot selects the Trim Interrupt switch early in the sequence and does not need to adjust the pitch trim, the risk is not significant. In this case, the lack of effective guidance and systems information probably had an adverse influence on the pilot’s capability to resolve the uninterrupted trim runaway condition and was a critical factor.
Other factors that increased risk
As the (uninterrupted) pitch trim runaway progressed, the reinforcing cycle of increasing control loads, forced descent, and increasing airspeed was initially exacerbated by high engine torque. The airspeed reached 210 kts with increased risk of descent into terrain before the pilot reduced engine torque and airspeed to partially alleviate the control loads and arrest the descent.
The effectiveness of RFDS training and checking processes for pitch trim runaway was undermined by incomplete systems knowledge and unrealistic practice exercises associated with training/checking in the aircraft (non-simulator).
Other findings
The PC-12 Crew Alerting System (CAS) provided clear and salient warnings of the pitch trim runaway and indications of the ongoing status of the pitch trim system. As was typical for aircraft such as the PC-12, the CAS was not designed to specify the malfunctioning circuit.
In difficult operational circumstances, the pilot enlisted the assistance of non-flying crew to counter the very high control loads and managed to coordinate the dual control inputs to return and land without wing flap at Merredin.
At the time of the occurrence, the aircraft manufacturer was developing and implementing replacement components for the pitch trim system to improve reliability. Further research into the electrical loads present in the PC-12 pitch trim system may be required to find and address the source of high energy events that damage the relays.
Safety issues and actions
The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.
Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the [aviation, marine, rail - as applicable] industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: The similarities between the Trim Interrupt and Flap Interrupt switches and the proximal location of the two switches unnecessarily increased the risk of mis-selection and contributed to the excessive out-of-trim condition.
Additional safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
RFDS Western Operations
RFDS safety, quality and risk personnel carried out an investigation of the occurrence with a focus on the cause of the pitch trim runaway and the actions of the pilot and crew in response to the event. This resulted in six recommendations and the following safety action by RFDS:
Pilatus was asked to investigate more reliable relays for the pitch trim system.
Feedback was provided to Pilatus regarding the Pitch Trim Runaway emergency procedure and the potential to change it to reduce confusion.
RFDS considered that the timing of the initial engine torque reduction (when the airspeed reached 210 kt) led directly to a situation where the aircraft and crew were placed at catastrophic risk. With reference to the RFDS Just Culture process, this was considered to be negligent and, taking into account the pilot’s other incidents, the pilot’s employment was terminated.
RFDS amended the PC-12 operating procedures in their Operations Manual to present the first phase of the pitch trim runaway emergency procedure in accordance with the Pilatus PC-12 POH/AFM and QRH.
The RFDS Head of Training and Checking convened a review of the adequacy of processes in regard to pitch trim runaway. This led to the following activities:
Briefing on revised pitch trim system information to all PC-12 pilots
Development of a training presentation to describe operation of the pitch trim system
For PC-12 conversion, addition of training between ground school and flight training to provide opportunity for pilots to review and if possible physically action emergency procedures in an aircraft on the ground
Refresher training for pitch trim runaway for all PC-12 pilots on next scheduled checks
For a practice pitch trim runaway, pilots were now expected to physically action the Alternate Stab Trim switch
Provision of the RFDS investigation report (with redactions for privacy) to all PC-12 pilots.
Following the occurrence, senior training and checking personnel had the opportunity to participate in a modified PC-12/47E ground school and simulator flight refresher course provided in the US by Flight Safety International. This included a pitch trim runaway scenario with similar complications to the occurrence.
A number of recommendations were proposed including:
Enhancement to the PC-12 ground school with more emphasis on emergency procedures and their impact on aircraft systems
Consideration of practice to retard the engine power lever as initial response to pitch trim runaway for better access to Trim Interrupt switch and enhance control of airspeed and control forces.
Where possible, allow pilots to physically action controls such as Alternate Stab Trim that are specified in a drill
Opportunities for training pilots and all PC-12 pilots to practice emergency scenarios in a full motion simulator.
The sources of information during the investigation included the:
Pilatus Aircraft Ltd.
Honeywell Aerospace
Royal Flying Doctor Service – Western Operations
Pilot and medical crew of VH-OWJ
RFDS pilots involved in other pitch trim runaway occurrences
Royal Flying Doctor Service – Central Operations
Transport Canada.
References
Dismukes, R., Goldsmith, T. E., & Kochan, J. A. (2015). Effects of acute stress on aircrew performance: literature review and analysis of operational aspects.
Submissions
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the Civil Aviation Safety Authority, Transport Canada, Swiss Transport Safety Board, Pilatus Aircraft Ltd, Honeywell Aerospace, Royal Flying Doctor Service – Western Operations, the pilot and medical crew of VH-OWJ, and Royal Flying Doctor Service – Central Operations.
Submissions were received from the Civil Aviation Safety Authority, Swiss Transport Safety Board, Royal Flying Doctor Service – Western Operations, and Pilatus Aircraft Ltd. Those submissions were reviewed and where considered appropriate, the text of the draft report was amended.
Appendices
Appendix A – PC-12/47E Pitch trim system wiring diagram
The ATSB adapted this circuit diagram from the maintenance data produced by Pilatus to show the status of key components of the system at the time of the pitch trim runaway. The red lines trace the active power circuit through the malfunctioning relay. That circuit can be de-energised by the Trim Interrupt switch and/or Pitch Trim circuit breaker. The blue lines trace the power circuit that can be activated by the Alternate Stab Trim switch provided the Pitch Trim Altn circuit breaker is closed and the Trim Interrupt switch is NORM.
Note, both pilot and autopilot controlled pitch trim circuits are powered via the Ess Bus and Pitch Trim circuit breaker. The Main Bus and Pitch Trim Altn circuit breaker only powers the Alternate Stab Trim circuit.
Figure A1: PC-12/47E Pitch trim system wiring diagram
Source: Adapted from Pilatus PC-12 maintenance data by the ATSB
Appendix B – Pilatus PC-12 Safety Information Letter SIL-003
Source: Pilatus Aircraft Ltd.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
Occurrence summary
Investigation number
AO-2019-019
Occurrence date
14/04/2019
Location
4 km west of Merredin
State
Western Australia
Report release date
13/05/2020
Report status
Final
Investigation level
Defined
Investigation type
Occurrence Investigation
Investigation status
Completed
Mode of transport
Aviation
Aviation occurrence category
Loss of control
Occurrence class
Serious Incident
Highest injury level
None
Aircraft details
Manufacturer
Pilatus Aircraft Ltd
Model
PC-12/47E
Registration
VH-OWJ
Serial number
1411
Aircraft operator
Royal Flying Doctor Service of Australia (Western Operations)
On 31 March 2019, freight train 7MB9, operated by Specialised Container Transport (SCT), derailed while exiting the refuge at Goulburn, New South Wales. A total of five wagons derailed, with wagons coming to a rest foul of both the Up and Down main lines. Prior to the derailment, the driver of train 7MB9 was authorised to pass signal G38 at Stop. This signal could not be cleared due to a track circuit fault. The track circuit fault occurred the evening before, after train 2343 passed through the refuge. At that time, the network controller contacted the on-call signal electrician and it was agreed that trains could continue by passing the signal at Stop.
What the ATSB found
The ATSB found that train 7MB9 derailed due to a broken rail. A crack likely initiated from a lack of weld fusion at the foot of the rail in an aluminothermic junction weld. This defect area was located in a portion of rail not easily detectible through continuous ultrasonic testing, and was not detected during routine maintenance. Train 7MB9 was authorised to pass signal G38 at Stop as the signal could not be cleared. The signal was likely at Stop as a result of the Up rail breaking under the previous train, 2343, that passed through the section. The track failure went undetected.
Following the derailment, a number of other factors were identified that increased the risk of a derailment in the refuge and on the main line. These were communicated with the rail infrastructure manager while the ATSB was on site.
What's been done as a result
The Australian Rail Track Corporation repaired the section of track at Goulburn damaged by the derailment immediately following the occurrence. Additionally, a process is currently being trialled to provide assistance to network controllers when responding to track circuit faults.
Safety message
Network rules that permit degraded operations must be assessed to ensure that the application of these rules do not increase risk to an unacceptable level. Personnel responsible for implementing these rules should have sufficient guidance to assess when it is safe to continue operating trains, or under what conditions operations can continue.
It is critical that areas of the rail that cannot be easily tested during scheduled continuous ultrasonic testing are tested thoroughly at the time of welding to ensure that the weld is free from defects.
The occurrence
What happened
At 2300,[1] on 30 March 2019, a track circuit fault occurred after train 2343 entered the Goulburn refuge loop in the Down[2] direction. The Main South A Network Controller (NC), located at Junee, contacted the driver of train 2343 to confirm that the train was complete after entering the loop. The driver confirmed that the train was complete and they had not parted (causing the track circuit to show as occupied).
At 2320, the NC contacted the on-call Signal Electrician (SE) as the track circuit continued to fail intermittently. The NC reported that there was a track failure over 115 points after a train passed into the refuge. The NC reported that the points had failed, but they could work around the fault by authorising trains to pass signals at Stop. The SE reported that there had been some rain and that the fault could possibly be related to the ingress of water. The NC and SE agreed that the fault could remain and an inspection would be undertaken in daylight hours.
At 0403, on the 31 March 2019, train 7MB9 operated by Specialised Container Transport (SCT Logistics) was contacted by the NC while approaching Goulburn in the Up direction (Figure 1). The NC advised there was a track circuit fault and that the train would divert via the refuge loop before returning to the Up main. The driver was advised that the points were set and they were authorised to pass signal G38 at Stop.
Figure 1: Location map
Source: Geoscience Australia with annotations by OTSI
Train 7MB9 was travelling at 17 km/h as it traversed over points 115B and 115A when, at 0416, the driver noticed a loss of brake pipe (BP) pressure and brought the train to a stand. The NC received a track circuit fault indicator and contacted the driver of 7MB9. The driver advised the NC that 7MB9 may have parted and that he would check the status of the train. Shortly afterwards, the driver confirmed 7MB9 had derailed while passing through the turnout and the NC implemented safeworking protection (Figure 2).
A total of five wagons derailed due to a broken Up rail at 225.413 km[3] with the wagons coming to a rest across the Up and Down main lines (Figure 3 to Figure 5).
The Bureau of Meteorology (BOM) automatic weather station at Goulburn airport[4] recorded 30.8 mm of rainfall on 30 March 2019 and 4.8 mm on 31 March 2019. There was no other significant rainfall in the week prior. The temperature was between 4.6 °C to 14.1 °C on 31 March 2019.
Train information
2343
Southern Shorthaul Railroad (SSR) train 2343 was the previous train to pass over the track. It was travelling from Picton to Milvale, New South Wales. This train consisted of three locomotives and a rake of 43 wagons. The train manifest indicated that the wagons were unloaded at the time of passing through the refuge loop.
7MB9
Train 7MB9 was operating between Melbourne and Brisbane at the time of the derailment. This train consisted of three locomotives and a rake of 42 wagons.
The contents of a number of derailed wagons leaked onto the track. The train manifest showed there were no dangerous goods on board. The highest recorded axle load listed in the manifest was 22.88 t, which was within the maximum allowable loading limits for operating on this section of track. Inspection of the derailed wagons did not identify any defects believed to have contributed to the derailment.
Track infrastructure
The section of track at Goulburn was standard gauge (1435 mm) and managed by the Australian Rail Track Corporation (ARTC).
The refuge loop consisted of 47 kg/m welded rail, fastened to timber sleepers. The Up and Down main lines consisted of 53 kg/m welded rail, fastened to concrete sleepers.
Joining rail track
Joining of rail track can be completed by a number of methods, these include mechanical (bolted) or welded joints. The method used varies depending on the location and type of track being joined or repaired. Aluminothermic (thermit)[5] and flashbutt[6] welding processes are approved for use when joining sections of rail within ARTC managed track.
ARTC’s engineering standards permit the joining of dissimilar rail sizes through the use of a junction rail or junction weld.[7]
Junction rail, is a section of rail specifically designed and forged rail with two different sizes. This is then welded through standard aluminothermic welding processes for the appropriate rail size.
Junction weld, is a specialised type of aluminothermic welding designed to directly join dissimilar rail sizes. Specific moulds are used to match the dissimilar rail sizes that are being joined.
ARTC advised that rails of dissimilar sizes are typically joined via junction welds and not through the use of junction rails.
Following rail welding, visual and ultrasonic post-weld testing is carried out to check the weld complies with ARTC standards and manuals.[8][9]
Manual ultrasonic weld testing is completed using hand-held equipment with a number of testing probes to allow for the rail head, web and foot of the rail to be inspected (Figure 6). Hand-held ultrasonic testing is only carried out directly after welding or in response to defects detected through other methods such as continuous ultrasonic testing.[10] The foot of the rail is not typically ultrasonically tested after the weld has been certified.
Source: ARTC, Manual for Non-Destructive Testing of Rail ETN-01-04, modified by OTSI
Track maintenance
Routine track inspection and testing is conducted to identify defects and maintain safe operation. The requirements for these inspections are set out in ARTC Civil Technical Maintenance ETE-00-03.
Track patrol
This section of track was inspected weekly as part of a track patrol, this is completed on foot or from a hi-rail[11] or rail vehicle. The inspection scope is a general visual inspection, including the condition of the rail and joints, sleepers and fasteners, points and crossings, ballast, track geometry and stability and drainage. This inspection provides a level of assurance but is limited to detection of large or obvious defects.
Ultrasonic rail testing
Ultrasonic rail testing provides a non-destructive testing (NDT) method to detect internal and surface defects. The frequency of testing is based on the maximum allowable track speed and gross tonnes of rail traffic over the section of track. Refuges with a track speed of 25 km/h or less, are tested at twice the time period of the adjacent mainline. The track speed in the Goulburn refuge is 20 km/h and required continuous ultrasonic rail testing or manual hand-held testing to be conducted every 244 days.
Ultrasonic testing provides a level of assurance but does not and cannot detect all defects. The ability of this method to detect rail defects (Figure 7) will vary depending on the method of ultrasonic testing utilised, but also on the calibration of the equipment. Calibration of testing equipment is performed on a rolled steel test piece to represent a section of rail, however, may not be representative of a rail weld to the same degree. Continuous ultrasonic rail testing is capable of detecting defects in the rail head and through the web of the rail to the foot. Defects in the rail foot either side of the web are outside the detectable area unless hand-held testing equipment is used (Figure 8).
Figure 7: Rail defect types
Source: ARTC. Non-Destructive Testing of Rail (for Internal and Surface Defects) ETE-01-03
Figure 8: Continuous ultrasonic rail flaw detectable area
Regions detectable through continuous ultrasonic rail flaw inspection is shown in grey.Source: Transport for NSW, modified and annotated by OTSI
Network rules
The network rules utilised by ARTC in New South Wales permit signals to be passed at Stop under certain conditions, these are detailed in ANSG 608 Passing Signals at STOP. This rule is used when a NC cannot clear a signal for an intended movement. Prior to authorising a train to pass a signal at Stop, the NC must assess the condition of the block[12] ahead for the section of track (Figure 9).
There are a number of potential reasons why a signal may not be able to be cleared, these can include, but are not limited to:
the track circuit is still occupied
an electrical fault (damaged bonding, insulated joint, water ingress, loose or faulty electrical connection)
a broken rail.
Figure 9: Passing signals at Stop
Source: ARTC, Extract from ANSG 608 Passing Signals at STOP
In addition to ANSG 608, network controllers have general rule ANGE 220 Unreliable Track-Circuit Operation to assist when responding to track circuit faults. This rule details the required response when a track circuit fails to detect track occupancy or provides false detection of rail traffic (Figure 10). In this incident, the track circuit at Goulburn provided a false detection of rail traffic after the passage of train 2343.
Figure 10: Unreliable track-circuit operation
Source: ARTC, Extract from ANGE 220 Unreliable Track-Circuit Operation
Post-derailment inspection completed on 31 March 2019 determined that the Up rail broke at an aluminothermic junction weld joining 47 kg/m and 53 kg/m rail. The fracture face exhibited signs of oxidation across the foot and web of the rail, with two small sections in the rail head without oxidation indicating a fresh fracture surface (Figure 11). The rail head at the break also displayed some signs of end batter.[13]
The Down rail was also found to be broken at approximately 225.426 km. The rail displayed no pre-existing defects or oxidation, although the brittle fracture was indicative of overload. The Down rail appeared to have broken secondary to the Up rail, this was likely as a consequence of the derailment.
Figure 11: Broken Up rail
Source: OTSI
The primary function of track circuits is to detect track occupancy and allow for the operation of signalling equipment and separation of trains. Discontinuities in the track circuit can indicate a fault such as a broken rail, although may not detect all instances of a broken rail. The track circuit before the derailment indicated that the section of track was still occupied after train 2343 passed through the refuge. When considering the possible causes of the track circuit fault, coupled with the end batter on the rail, it is likely the Up rail was broken prior to the derailment of train 7MB9.
The leading locomotives and two wagons of 7MB9 traversed points 115B and 115A before the 6th position wagon derailed when the broken Up rail skewed to the left (in the direction of travel), resulting in the uncoupling of the 5th and 6th position wagons. The derailed wagons were pushed by the momentum of the trailing wagons and concertinaed across the Up and Down main lines. The 6th wagon came to rest on its side approximately 80 m from the point of derailment.
Maintenance records indicated that the track was subjected to continuous ultrasonic testing on 5 November 2018, with no discontinuities identified. Review of available ultrasonic test recordings indicated that no abnormalities were detected over this section of track dating back to 2013.
Further analysis of the broken Up rail undertaken by an independent metallurgist on behalf of ARTC identified a lack of weld fusion on the foot of the rail between the two rail types. The lack of weld fusion most likely went undetected at the time of welding. This weld fault likely created a stress raiser leading to the initial fracture at the foot of the rail. ARTC were unable to provide welding or maintenance records for the junction weld, however they assessed the weld as having had a long service life.
It is likely the fracture progressed from the foot of the rail and through the rail cross-section after the date of the last ultrasonic inspection. The crack was most likely detectable once the defect propagated into the web of the rail, however, testing was not due until July 2019, as per ARTC maintenance standards. This defect would have been unlikely to be detected during a routine track patrol inspection, in particular, a track patrol completed from a hi-rail vehicle.
Passing signals at Stop
Network rule ANGE 220 Unreliable Track-Circuit Operation required the NC to contact the on-call SE when they became aware of the false detection of rail traffic. This rule permitted trains to block work[14] or pass signals at Stop until the track circuit could be certified as working correctly. In response to the track circuit fault, the NC contacted the SE and advised they could continue to operate by passing signals at Stop. The SE agreed and suggested that the fault could have been the result of wet weather in the area.
Review of the audio recordings indicated that the NC advised the driver of train 7MB9 there was a track failure on the other end of the refuge (in the direction of travel), the points were set for the train to return to the Up main, and that the driver was authorised to pass signal G38 at Stop. This information was repeated back by the driver. During this communication the driver sought confirmation that the points were set to return to the Up main which was confirmed by the NC.
The driver was authorised to pass signal G38 at stop while on approach to Goulburn at 0403. On arriving at the signal, the driver did not stop at the signal before passing, as required by network rule ANSG 608. Authorising trains to pass a signal at Stop before arriving at the signal is permissible. This could, however, lead to a train passing the incorrect signal as positive confirmation between the driver and network controller is lost.
The driver was not advised that the condition of the track was unknown and had not been inspected prior to the train traversing points 115B and 115A. The driver operated train 7MB9 at approximately 17 km/h through the turnout, which was within the track speed limit. If the 7MB9 first stopped at signal G38, the train would initially have travelled at a slower speed until either reaching track speed or derailing. Had the NC advised the driver that the condition of the track was unknown, the driver may have operated the train at a slower speed through the turnout, which may have reduced the consequences of this occurrence.
At the time of the occurrence, ARTC’s network rules permitted continued operation of trains until the track circuit could be certified as working. These rules did not provide guidance for the NC to continue to assess, the changing conditions and ensure safe operation. Additionally, the rules did not restrict the track speed of trains authorised to pass signals at Stop.
While passing signals at Stop is permissible under ANSG 608 Passing Signals at STOP, the potential causes or conditions for passing the signal must be fully assessed. Track circuit faults following a recent train movement could indicate a broken rail and should be considered as the source of the fault prior to authorising trains to pass signals at Stop.
The Rail Industry Safety and Standards Board (RISSB) network rule for passing signals at Stop[15] recommends trains operate at restricted speed when the signal is at Stop for an unknown reason. This rule is not mandatory for rail infrastructure managers, but provides industry recommended practice.
Site examination
During the post-derailment inspection there were a number of factors identified that could have increased the risk of a derailment.
During the derailment, the sleepers in the turnout shifted laterally with pooled water present under the sleepers. There was rain during the previous day and night, however the track and ballast was raised above ground level with the ballast retaining water (Figure 12). To satisfactorily meet the design requirements, ballast must be free-draining (not clogged by dirt and mud) so that it allows water to run through it and off into the drainage system.[16]
The ballast and sleepers at the site of the broken Up rail were destroyed, preventing a detailed inspection. The broken sleepers in this area fractured into small pieces and appeared to indicate some degree of decaying and the ballast appeared fouled with mud and dirt. It is likely that the track condition at the point of derailment was similar to that of the area in the turnout. It is possible the fouled ballast reduced the track stability and may have allowed greater track movement in this area.
Under the 10th wagon, there were also six sleepers in a row where the fastener was either displaced and not securing the rail foot, or was secured to the sleeper but not in contact with the foot of the rail (Figure 13). It did not appear that these fasteners had displaced as part of the derailment sequence and appeared to be a pre-existing defect.
ARTC advised that in 2017, they identified decayed sleepers in the refuge. In May 2017, ARTC replaced 70 sleepers with concrete sleepers between the 225.440 km and 225.590 km. A further 200 sleepers had been identified as requiring replacement and were being monitored annually. There were no concrete sleepers near the point of derailment.
Figure 12: Refuge track condition near point of derailment
Source: OTSI
Figure 13: Ineffective rail fasteners
Source: OTSI
While walking the derailment site, the ATSB also identified points 114A on the Down main with ineffective heel block[17] fastening. One heel block bolt was found in the four-foot[18] and the second bolt securing the point switch was loose (Figure 14). The ATSB raised the defect with the ARTC representative on the day of the derailment.
Maintenance records indicated that the most recent track patrol was performed on 28 March 2019, with no reported defects at this location. It was not possible to determine when the bolt dislodged, however the derailment is not believed to have contributed to these defects found on the adjacent track.
From the evidence available, the following findings are made with respect to the derailment of freight train 7MB9 that occurred at Goulburn, New South Wales on 31 March 2019. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
Contributing factors
A crack propagated from the foot of the Up rail at a junction weld and was not detected by ARTC maintenance activities. It is likely that after the date of the last continuous ultrasonic testing, a crack progressed through the foot and into the web of the rail.
Other factors that increased risk
ARTC's network rules did not provide suitable guidance to assess continued safe operation when responding to track circuit faults. Additionally, the network rules permitting signals to be passed at Stop did not require a reduction in speed when the condition of the track was unknown. [Safety issue]
Post-incident inspection of the derailment site identified a number of factors that increased the risk of a derailment in the refuge and main line. ARTC’s maintenance activities had identified some but not all of these factors prior to the derailment. [Safety issue]
Other findings
The Up rail broke at an aluminothermic junction weld, joining 47 kg/m and 53 kg/m rail at 225.413 km.
The track circuit fault was likely the result of the Up rail breaking as train 2343 passed through the turnout, which went undetected prior to train 7MB9 derailing.
Safety issues and actions
The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.
Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the [aviation, marine, rail - as applicable] industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Safety issue description: ARTC's network rules did not provide suitable guidance to assess continued safe operation when responding to track circuit faults. Additionally, the network rules permitting signals to be passed at Stop did not require a reduction in speed when the condition of the track was unknown.
Safety issue description: Post-incident inspection of the derailment site identified a number of factors that increased the risk of a derailment in the refuge and main line. ARTC’s maintenance activities had identified some but not all of these factors prior to the derailment.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
Australian Rail Track Corporation (ARTC)
Office of National Rail Safety Regulator (ONRSR)
Specialised Container Transport (SCT).
References
Australian Rail Track Corporation (2009). Manual for Non-Destructive Testing of Rail ETN-01-04, September 2009.
Australian Rail Track Corporation (2011). Used Rail and Welding Policy ETF-01-01, April 2011.
Australian Rail Track Corporation (2015). Passing Signals at STOP ANSG-608, October 2015.
Australian Rail Track Corporation (2015). Unreliable Track-Circuit OperationANGE-220, October 2015.
Australian Rail Track Corporation (2016). Code of Practice - Section 1 Rail, July 2016.
Australian Rail Track Corporation (2018). Non-Destructive Testing of Rail (for Internal and Surface Defects) ETE-01-03, July 2018.
Australian Rail Track Corporation (2019). Civil Technical Maintenance ETE-00-03, March 2019.
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to Australian Rail Track Corporation, Office of National Rail Safety Regulator, Specialised Container Transport and Transport for NSW.
Any submissions from those parties will be reviewed and where considered appropriate, the text of the draft report will be amended accordingly.
Submissions were received from Australian Rail Track Corporation and Office of National Rail Safety Regulator. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 25 March 2019, a suburban passenger train (DW17), operated by Queensland Rail (QR) Citytrain, exceeded its limit of authority by passing signal DP29 at Park Road Station, Brisbane, while it displayed a stop indication. The signal passed at danger (SPAD) occurrence resulted in a near collision with another suburban passenger train (1E65), which was proceeding in the same direction on an adjacent line to a merging conflict point.
The potential of collision was prevented by the actions of a tutor driver in the driving cab of 1E65, and a network control officer who transmitted an emergency stop command after receiving a SPAD alarm. DW17 exceeded its limit of authority by 305 m and stopped 55 m past the conflict point, while 1E65 stopped about 70 m prior to the conflict point. There were no injuries, however DW17 ran through the points, which were set for 1E65, resulting in minor infrastructure damage.
What the ATSB found
After DW17 stopped at Park Road, with the platform departure signal (DP29) displaying a stop indication, the driver did not apply the operator's ‘stopped at a red’ procedure. After receiving the allright signal from station staff indicating station duties were complete, the train’s guard promptly provided the driver with the rightaway signal, even though the departure signal was still displaying a stop indication. The driver then promptly departed the station platform without effectively checking and confirming the departure signal. The actions of the guard and the driver were probably associated with a very high level of expectancy that, after receiving the allright signal and the rightaway respectively, the departure signal was indicating a proceed aspect.
The occurrence involved a new generation rollingstock (NGR) train. In contrast to previous QR suburban passenger trains, where the guard was positioned in the middle, the NGR had the guard positioned at the rear, and station staff provided assistance (if required) to passengers who were boarding or alighting in the middle of the train. The NGR fleet commenced operations in December 2017, and in January 2019 there was a change to procedures that required station staff at suburban stations to provide the allright signal for all NGR services. This significantly increased the frequency that allright signals were provided to guards of NGR trains at suburban stations.
Following this change there were 5 start against signal SPADs involving NGR trains at suburban platforms between March 2019 and March 2020, with a sixth SPAD in April 2021. The investigation found that there were limitations in QR’s application of risk management and change management processes relevant to the introduction of the NGR that increased the risk of a start against signal SPAD. Specifically, multiple processes did not effectively consider the risk of station staff at suburban platforms providing the allright signal for all NGR trains even when the platform departure signal displayed a stop indication, which was in contrast to how allright signals were being provided in practice for all trains at the 3 central business district stations and 2 other designated stations.
At station platforms where a guard could not sight the departure signal, signal aspect indicators (SAIs) were installed. With the introduction of the NGR, with the guard at the rear of the train, a significant number of SAIs had to be installed or moved. The investigation found that QR’s procedures for the installation of SAIs did not provide sufficient guidance to ensure their consistent and conspicuous placement at station platforms. This problem, combined with an SAI’s non-salient indication when the platform departure signal displayed a stop indication, increased the risk that an SAI would not be correctly perceived by a train guard.
Although not a contributing factor, the investigation found that, associated with a late-notice roster change, the guard was probably experiencing a level of fatigue known to adversely influence performance. In addition, QR’s fatigue management processes for Citytrain train crew had limited processes in place to actively identify and manage the risk of restricted sleep opportunity resulting from late-notice roster changes.
What has been done as a result
QR advised that it had reviewed, consulted and implemented a revised Operational Readiness program, which involved simplifying the operational readiness assessment process and integrating safety change management into the assessment criteria for future projects. The ATSB notes that, with regard to the issues associated with the change to the allright procedure, the risk of this specific safety issue has decreased as guards have become more familiar with the location of signal aspect indicators and the new processes at suburban station platforms. This has seen a decrease in the rate of start against signal SPADs in recent times. The ATSB will continue to examine change management issues in current and future investigations.
In addition, QR also issued an important safety notice to rail traffic crew and rostering personnel regarding unplanned shifts and required that rostering personnel complete a checklist when arranging unplanned shifts with less than 12 hours notice prior to the start of the shift. QR also will review its fatigue risk management standard later in 2022.
Safety message
Where there are limited engineering controls to manage SPAD occurrences, it is vital that train drivers and guards routinely apply the procedures designed to minimise the risk of a SPAD. This is particularly important during the station dispatch process, when expectancies and distractions have been demonstrated to have undesired influences on performance.
Rail operators are reminded to apply structured risk management and change management processes. In particular, operators should apply a formal change management process to assess the potential risk of a procedural change before determining that the change is minor in nature. Operators also should ensure they understand the undocumented or informal risk controls that are in place in their operation, and how exactly operational personnel are applying current procedures, prior to introducing changes.
A commonly-overlooked aspect of risk management is the need to consistently monitor and review the health of risk controls, either existing or newly-introduced, through a variety of activities and to continuously look for opportunities to improve the operator’s risk position.
The occurrence
Overview
On 25 March 2019, a suburban passenger train (DW17), operated by Queensland Rail (QR) Citytrain, was en route from Cannon Hill to Northgate, Queensland, on the Cleveland line. The train consisted of ‘new generation rollingstock’ (NGR). It departed Park Road Station while the departure signal (DP29) was displaying a red aspect (or stop indication). The network control officer (NCO) made an emergency call to the driver, who stopped the train.
Events prior to arriving at Park Road Station
DW17 was scheduled to stop at all stations between Cannon Hill and Northgate (Figure 1). It departed Cannon Hill on time at 1201.[1] The rail traffic crew consisted of a driver and a guard.
Figure 1: Excerpt of Brisbane suburban network showing origin (Cannon Hill) and destination (Northgate) of train DW17
Source: QR, modified by the ATSB
The train travelled towards the city on green signals before encountering a yellow (restricted) aspect in signal LS059, which was located on the approach to Buranda Station (the station prior to Park Road). As it passed over the automatic warning system (AWS)[2] magnet applicable to the signal, the AWS generated an audible and visible alarm in the driving cab, advising the driver of the restricted signal ahead. The driver acknowledged the alarm by pressing and releasing the AWS button.
After stopping at the Buranda Station platform, the driver placed the brake controller in full service but did not place the direction controller into neutral. This was inconsistent with the operator’s ‘start on a yellow’ procedure (see Citytrain driving procedures). The train departed Buranda on time at 1211:30.
The train then passed signal DP17 (displaying a flashing yellow aspect) and signal DP23 (displaying a single yellow aspect). Prior to passing each signal, the AWS generated a restricted signal alarm in the driving cab and the driver responded accordingly. Signal DP23 was the authority to proceed into platform 2 at Park Road Station. The driver subsequently reported that, based on the previous signal indications, they were expecting a red signal at Park Road Station.
Arrival at Park Road Station
At 1214:00, DW17 passed over the AWS magnet for signal DP 29 (the departure signal for platform 2 at Park Road), and the driver acknowledged the alarm. At that time, DP29 was displaying a red aspect.
At 1214:25, the train stopped at the relevant platform stopping mark at Park Road Station. The driver did not move the direction controller to neutral or apply the park brake, which was inconsistent with the operator’s ‘stopped at a red aspect’ procedure (see Citytrain driving procedure).
Signal DP29 was displaying a stop indication because the NCO had planned to briefly delay DW17 at the platform. This was to allow another suburban passenger train (1E65), which was running late, to proceed in advance of DW17 and pass through the middle road (platform 3) to connect with the down suburban line (Figure 2).
Figure 2: Signal DP29, the middle road and the down suburban line at Park Road Station
The image was taken from the forward-facing camera of DW17 on the day of the occurrence. It shows the down suburban line, which DW17 was traversing, and the red aspect in signal DP29. The middle road was set for the path of 1E65 to run in advance of DW17.
Source: QR, modified by the ATSB
1E65 was scheduled to run all stops between Beenleigh and Ferny Grove. The train departed Beenleigh 5 minutes late at about 1117. It recovered some lost time and arrived at Yeerongpilly Station (4 stations prior to Park Road) at 1207, 3 minutes behind schedule.
At the Yeerongpilly Station platform there was an unplanned driver change. A tutor driver, who was providing a trainee driver with route tuition, seconded the train at the platform and the trainee took over driving duties. At 1214:50, 1E65 came to a stop at platform 3 at Park Road. The platform 3 departure signal (DP27) displayed a green aspect to allow 1E65 to run in advance of DW17.
Signal passed at danger (SPAD)
On platform 2 at Park Road, a station porter aided a passenger in a wheelchair to board DW17. At 1215:02, the porter gave the ‘allright signal’[3] to the guard to signify platform duties were complete. There was no requirement in the allright process for station staff to check the indication in the departure signal. At that time, signal DP29 was still displaying a red aspect.
As signal DP29 was not visible from a guard’s location at the rear of an NGR train, a signal aspect indicator[4] (SAI) had been installed on the platform to assist guards with the process of providing ‘rightaway’ signals to drivers (Rightaway signal procedure).
The guard of DW17 stated that, after the train stopped, they stepped from the train onto the platform in accordance with the rightaway procedure. They noticed the porter assist a passenger into the train and then provide the allright signal. The guard said they then checked the SAI and noted that it was illuminated (indicating that DP29 was displaying a proceed indication). They then boarded the train and, at 1215:03, they provided the rightaway signal (2 bells) to the driver.
A review of closed-circuit television (CCTV) footage determined that the SAI was not illuminated and the guard did not step from the train onto the platform at Park Road, although they looked up and down the platform from within the crew compartment at the rear of the train.
On receipt of the rightaway, the driver pressed the doors closed button and waited for the ‘doors open’ tile to extinguish. At 1215:25, the driver applied traction power, and at 1215:27 the train (DW17) departed the platform on the down suburban line (with the departure signal DP29 still displaying a red aspect). The driver subsequently reported that they could not recall checking or sighting the status of signal DP29 prior to departing the station, and they were prompted to depart after receiving the rightaway from the guard.
At about the same time that DW17 departed from platform 2 on the down suburban line, 1E65 departed from platform 3 on the middle road (with the departure signal DP27 displaying a green aspect). The down suburban line and the middle road merged at a point about 250 m past signal DP29.
At 1215:34, the universal traffic control[5] (UTC) system at the Brisbane rail management centre generated an alarm to the NCO, which stated ‘train DW17 past signal 29 at STOP’. At the same time, the UTC system showed train 1E65 had passed signal DP27. The trains were traveling in the same direction on a collision course.
Response to the SPAD
Initially, the crews of both trains were unaware of the circumstances as they accelerated away from their respective platforms. However, the tutor driver in the driving cab of 1E65 soon became aware that the train on the adjacent track (DW17) had exceeded its authority and there was potential for collision at the merging points. At that time, the speed of 1E65 was 43 km/h. The tutor driver initially directed the trainee driver to apply the brakes to slow the train, but on hearing an emergency stop command over the train radio, the tutor driver directed the trainee to stop the train.
At 1215:43, the NCO transmitted ‘emergency, emergency, emergency’ DW17 stop your train, emergency, emergency, emergency DW17 Park Road stop your train’. The NCO then immediately transmitted a similar message for 1E65, and then transmitted ‘all trains Park Road stop your trains’ twice in succession. All of these messages were transmitted over the ultra high frequency (UHF) open radio network and could be heard by all drivers.
Initially, the driver of DW17 thought the emergency command was for another train, but then noticed the points ahead were set in reverse for the train on the middle road (that is, 1E65) (Figure 3). The driver then recognised that the emergency stop command related to their train, and that they had exceeded their limit of authority by passing signal DP29. At 1215:56, while travelling at 54 km/h, the driver applied the brakes, and the train came to a stop at 1216:08.
Figure 3: Points set in reverse for the path of 1E65
The image was taken from the forward-facing camera of DW17 immediately prior to the train running through the points that were set for 1E65.
Source: QR, modified by the ATSB
At 1216:10 the crew of 1E65 advised they had stopped their train. At 1216:17, the driver of DW17 also advised that their train was stopped.
DW17 exceeded its limit of authority by about 305 m (about 55 m past the conflict point between the 2 lines); 1E65 stopped about 70 m prior to the conflict point.
The SPAD occurrence resulted in no injuries and only minor damage to rail infrastructure. The damage was due to DW17 running through the points, which were set in reverse to facilitate the movement of 1E65 from the middle road to the down suburban line at Park Road.
As the damaged infrastructure was located under DW17 when it stopped, QR personnel evacuated the passengers from the train under the authority of an all trains block.[6] The passengers were assisted off the train and escorted along the permanent way back to Park Road Station. 1E65 was authorised to return to platform 3, from where the service continued to the city via the dual gauge line.
DW17 was an electric suburban passenger train operated by Queensland Rail (QR) Citytrain and timetabled to travel between Cannon Hill and Northgate. On departure from Park Road Station, it had 41 passengers on board.
DW17 was a new generation rollingstock (NGR) train, unit number 726. NGR trains consisted of 6 cars with a driving compartment at each end. They were operated with the guard positioned in the rear driving compartment. The trains were 146.7 m long and weighed 260 t.
The train operated as designed and there were no reported or recorded faults that influenced its serviceability. The train was fitted with an event recorder and front-of-train camera. These systems operated effectively during the occurrence sequence, and relevant information from these systems are included in this report where relevant.
Rail crew information
Driver qualifications and experience
The driver of DW17 joined QR in 1963 and gained train driver qualification in 1976 and they had almost 43 years’ service as a train driver.
In 1987, the driver obtained the qualification to operate electric multiple unit (EMU) trains. In January 2018, the driver achieved an additional qualification to operate NGR trains. DW17 was the only NGR train the driver operated on 25 March 2019. They reported having operated NGR trains about 30–40 times since they obtained their qualification and had last operated an NGR train on 23 March.
The driver was route competent[7] to operate trains throughout the Brisbane suburban rail network and frequently worked passenger trains from Cleveland to the city via Park Road. The driver reported being familiar with the signalling arrangements at Park Road and had traversed through Park Road platform 2 on numerous occasions.
Records supplied by QR showed that the driver was involved in a previous SPAD occurrence at signal SB21 (South Brisbane) on 23 August 2009. On that occasion, the driver did not apply the ‘stopped at a red’ procedure when stopped at the platform departure signal and did not check the departure signal after receiving a false (incorrect) rightaway signal from the guard. The driver’s 2009 SPAD occurrence at signal SB21 showed similarities to that of the SPAD at signal DP29 on 25 March 2019.
Driver medical information and recent work history
The driver underwent a medical assessment (rail category 1 – high-level safety worker) on 11 March 2019 and was assessed as fit for duty. Following the SPAD occurrence on 25 March 2019, the driver undertook a mandatory drug and alcohol test, which produced negative results (that is, no drugs or alcohol detected).
The driver’s duty times for the day of the occurrence (25 March 2019) and previous days are shown in Table 1. They had a day off duty on 16 March, followed by 7 shifts in a row prior to another day off duty on 24 March. They commenced duty on 25 March at 0412. The shifts on 15, 17 and 18 March were also originally designated as days off duty.
Table 1: Day-of-operations duty times for driver over previous 10 days
Date
Work activity
Duty start
Duty end
Duty time
Time free (of duty)
15 Mar 2019
Train driving, various routes
0845
1445
6.0 hours
43.1 hours
16 Mar 2019
Day off
40.0 hours
17 Mar 2019
Train driving, various routes
0747
1543
7.9 hours
12.4 hours
18 Mar 2019
Train driving, training
0406
1242
8.6 hours
16.1 hours
19 Mar 2019
Train driving, various routes
0447
1047
6.0 hours
16.8 hours
20 Mar 2019
Train driving, various routes
0334
0934
6.0 hours
20.0 hours
21 Mar 2019
Train driving, various routes
0537
1425
8.8 hours
12.6 hours
22 Mar 2019
Train driving, various routes
0300
0900
6.0 hours
16.9 hours
23 Mar 2019
Train driving, various routes
0353
0953
6.0 hours
> 24 hours
24 Mar 2019
Day off
25 Mar 2019
Train driving, various routes
0412
1253
8.7 hours
The driver stated that they obtained 6 hours sleep on the night of 24 March and felt well rested before commencing duty at 0412 on 25 March. They noted that 6 hours sleep was the minimum they needed to function effectively.
The driver operated multiple train services and had 2 meal breaks on the 25 March prior to operating a train from Bowen Hills to Cannon Hill and then commencing the DW17 service from Cannon Hill to Northgate. DW17 was scheduled as their last train service of the day.
Guard qualifications and experience
The guard of DW17 commenced work with QR in 1974 and performed various roles before being appointed to the position of train guard in 1984. In 1990, they transferred to Brisbane (Mayne depot) and thereafter worked as a Citytrain guard up until the SPAD occurrence on 25 March 2019.
The guard became qualified to conduct duties on NGR trains in August 2018. They stated they had conducted operations on NGR trains on numerous occasions, primarily on the Gold Coast line (including through platform 3 at Park Road). However, they had never worked an NGR train on the Cleveland line from Cannon Hill before and had never stopped on platform 2 at Park Road on an NGR train. Accordingly, they had not previously used the signal aspect indicator (SAI) for DP29 before 25 March 2019 (see also Communication of information about the location of the SAIs at Park Road).
Guard medical information and recent work history
The guard underwent a medical assessment (rail category 2 – safety critical worker) on 14 November 2018 and was assessed as fit for duty. Following the SPAD occurrence on 25 March 2019, the driver undertook a mandatory drug and alcohol test, which produced negative results (that is, no drugs or alcohol detected).
The guard’s duty times for the day of the occurrence (25 March 2019) and previous days are shown in Table 2. They had 2 days off duty before commencing duty at 0412 on 25 March.
Table 2: Day-of-operations duty times for the guard over previous 6 days
Date
Work activity
Duty start
Duty end
Duty time
Time free (of duty)
20 Mar 2019
Day off
21 Mar 2019
Guard duties, various routes
1500
2359
9.0 hours
12.0 hours
22 Mar 2019
Guard duties, various routes
1200
2100
9.0 hours
> 24 hours
23 Mar 2019
Day off
24 Mar 2019
Day off
25 Mar 2019
Guards’ duties, various routes
0412
1312
9.0 hours
The guard was originally rostered to commence work at 0900 on 25 March 2019. However, at 2208 on 24 March, a QR roster clerk called the guard to ask if they could start work at 0412. The guard, who was awake at the time, accepted the earlier start time. Soon after that conversation, the guard required more information on the new shift so they called the on-duty roster clerk to gain these details. During these calls, the guard did not advise the roster clerks of any concern with undertaking the changed shift.
The guard recalled waking at 0200 on 25 March. Based on the available evidence, the ATSB concluded that the guard probably had approximately 3.0–3.5 hours’ sleep prior to starting work. The guard recalled feeling normal on the day of the occurrence.
The guard operated the same train services as the driver of DW17 on 25 March, including having 2 meal breaks prior to the occurrence.
Station and signal information
Park Road Station
Park Road is an interchange station for the Gold Coast and Cleveland lines. It is located about 4.3 rail km south-east of Roma Street Station and serves the Brisbane suburb of Woolloongabba. The station has 4 platforms (Figure 4) and caters mainly for medium to high frequency suburban passenger traffic.
Figure 4: Platform configuration at Park Road Station
The image shows the platform configuration at Park Road, relevant signals, and the direction of travel of trains DW17 and 1E65. Source: Google maps, modified by the ATSB
Signal DP29
Signal DP29 was located at the 4.238 km mark.[8] It was about 5.8 m off the departure end of platform 2 at Park Road and 10 m from the 6-car stopping mark on the platform. Traditionally, signals at or near to the end of platforms were referred to as platform departure signals, although some suburban station platforms (such as at Buranda Station) did not have a departure signal.
Signal DP29 was a 4-aspect colour light signal, capable of displaying green, double yellow, yellow or red aspects and was fitted with light emitting diodes (LEDs). Figure 5 provides information about the function of the different aspects. More generally, the term ‘proceed’ is used to refer to a signal displaying a green, double yellow, single yellow or flashing yellow aspect, and ‘restricted’ is used to refer to a signal displaying a double yellow, single yellow, flashing yellow or red aspect.
Figure 5: Four-aspect colour light signal indications
The image shows the indications displayed by a 4-aspect colour light signal and their authority. At some locations, a flashing yellow aspect is part of the 4-aspect colour light sequencing.
Source: Queensland Rail (QR)
The signal had an unrestricted sighting distance greater than 100 m, and the designated track speed approaching the signal was 40 km/h. The positioning and sighting of the signal complied with QR standard MD-10-95 (Signalling positioning principles).
QR advised there had been one other recorded SPAD occurrence at signal DP29 since 1996. This occurred in April 2004 and was categorised as a ‘signal restored in face of train’ occurrence, rather than a driver initiated SPAD.
Although signal DP29 was well positioned from a sighting perspective, the driver of DW17 stated they did not see the red aspect in the signal as the train approached and stopped at the platform. The driver said that they had lowered the windscreen blind to reduce sun glare reflecting off the dashboard and this may have restricted the sighting of the signal.
A review of station closed-circuit television (CCTV) footage showed that the blind was in a lowered (but not fully lowered) position on the windscreen as the train entered the station platform. The ATSB re-enacted the occurrence based on information from the driver and evidence from the station CCTV footage. The re-enactment showed that the position of the windscreen blind would not have hindered the driver’s view of the red aspect in the signal (Figure 6).[9]
Figure 6: A view of signal DP29 from the driver’s seat of an NGR service stopped at the 6-car stopping mark at platform 2 Park Road
The photo, taken from the driver’s seat of an NGR service, shows the red aspect in signal DP29 with the front blind almost fully drawn.
Source: ATSB
In August 2017, an SAI was installed on platform 2 at Park Road Station as part of the introduction of NGR trains (see Location of the SAI on platform 2 at Park Road).
Citytrain driving procedures
Safe driving procedures
The QR suburban rail network had limited engineering or technical controls in place to detect potential or actual SPADs and manage their risk (see ATSB report RO-2018-002).[10] Consequently QR heavily relied on front line staff to manage risk through their compliance with procedures.
QR procedure MD-11-72 (TSD professional driving – Safe driving) outlined rules for train drivers to apply ‘to mitigate the incidence of Signals Passed at Danger (SPAD) and other adverse operational safety events’. The procedure stated:
Safe Driving focuses on planning, prioritising, communicating and taking appropriate positive actions. The methods of Safe Driving are important defences against the risk of error and are intended to reduce errors and mitigate risk in the event of errors occurring…
The technique shall be incorporated into all aspects of day to day driving, driver training, driver monitoring, assessment, accreditation and reaccreditation programs. The principle of the driving method is based around thinking safety, behaving and acting proactively and positively in all situations which could arise. Safe driving is mandatory.
The procedure included several specific rules to mitigate the risk of SPADs, and those relevant to the 25 March 2019 SPAD occurrence are outlined below.
Approaching yellow aspects
If a train was approaching a signal displaying a double yellow or single yellow aspect, the driver was required to reduce the train speed to (or below) 75% of the designated track speed when passing the signal. When approaching a signal displaying a flashing yellow aspect, the driver was required to pass the signal at a speed no greater than 40 km/h, or the designated track speed, whichever was the lower.
As signal LS059 (prior to Buranda Station) was displaying a single yellow aspect, the train speed was required to be limited to 45 km/h after departing Buranda. However, the train was accelerated to about 57 km/h before traction power was shut off as it approached signal DP17 (which was displaying a flashing yellow aspect). Under braking, the train passed DP17 at 47 km/h (in excess of the 40 km/h limit) and continued to slow to 25 km/h as it passed through a turnout with a 25 km/h speed limit.
Start on a yellow
When the platform departure signal was displaying a single yellow or flashing yellow aspect, then the driver was required to fully apply the train brakes (that is, to the full service position) and place the direction controller into the neutral position. The same action was required if there was no departure signal (such as at the Buranda Station platform) and the signal prior to the platform was displaying a single yellow / flashing yellow aspect.
Evidence from DW17’s event recorder showed that the driver did not fully comply with the ‘start on a yellow’ procedure at the Buranda Station platform; although they applied the train brakes to full service, they did not move the direction controller to the neutral position.
Approaching a red aspect
When approaching a signal displaying a red aspect, the driver was required to apply the ‘20 / 20’ rule. This stated that the driver must reduce the speed of the train to 20 km/h when passing over the AWS magnet (located about 80 m prior to the signal) and target a stopping point 20 m prior to the signal.
DW17’s event recorder showed that the train speed was moderately above 20 km/h passing over the AWS magnet for signal DP29. However, the driver demonstrated caution when approaching the signal, suggesting they were aware of its indication.
Stopped at a red aspect
When an electric suburban train stopped at a station platform and the departure signal was displaying a red aspect, the driver was required to:
move the brake controller to the full service position
place the direction controller into the neutral position
After stopping the train at the Park Road platform, the driver of DW17 placed the brake controller to full service but did not move the direction controller to neutral or apply the park brake.
The driver stated that they were aware of QR’s start on a yellow and stopped at a red procedures and the reasons for the procedures, and agreed that they were a good idea for reducing the risk of a SPAD. The driver also stated that sometimes they followed these procedures, but at other times they tailored their own risk management measures, which they felt confident with, and they had applied this approach successfully over many years as a driver.
Safe driving assurance data
QR commenced a process to review event recorder data to collect data on driver compliance with key SPAD mitigation rules in April 2018 (see ATSB report RO-2018-002). QR advised that data for the periods from September 2018 to March 2019 indicated compliance rates as follows:
87% for the 75% rule (approaching a single yellow or double yellow aspect)
55% for the start on a yellow rule
99% for the 20 / 20 rule
92% for the stopped at a red rule.
Risk triggered commentary driving
To assist with reducing the frequency of SPADs, QR introduced risk triggered commentary driving (RTCD) in 2008–2009, and subsequently Citytrain made it a mandatory requirement for its drivers in 2011 for situations where they were approaching restricted signals. QR procedure MD-13-165 (TSD professional driving – risk triggered commentary driving) stated:
At a basic level, RTCD involves RTDs [drivers] acknowledging the aspect of the restricted signal, and intended actions, by speaking aloud. By applying RTCD, RTDs can listen to their thoughts and the subsequent actions they are planning to apply. This allows RTDs to ‘sense check’ what they should do next.
RTCD is required to be applied continuously from the acknowledgement of the restricted audible alarm on the Automatic Warning System (AWS) until the action that must be taken is actually performed…
The driver of DW17 stated that they were applying RTCD ‘to some degree’ during the period leading up to the SPAD occurrence on 25 March 2019. They had noted each of the 3 yellow signals prior to reaching Park Road, but they had not verbalised these signals (or the required actions) out aloud.
Further information regarding QR’s implementation of RTCD is provided in ATSB report RO-2018-002.
QR’s electric suburban train business operating models
Electric multiple unit (EMU) business operating model
In 1979, QR introduced electric multiple units (EMUs) to the Brisbane suburban rail network. The EMUs consisted of 3-car units that worked either as 3-car trains or coupled together as 6-car trains. The 6-car configuration with the guard working from the middle compartment of the train was the preferred business operating model (BOM).
Due to the location of the guard in the middle of the train, station platforms were designed with provisions in the middle of the platform to cater for the needs of passengers who required boarding assistance. It was the guards’ role to assist with passenger boarding / alighting arrangements at suburban station platforms as required.
Allright signal procedure for the EMU business operating model
Under the EMU BOM arrangement, there was no requirement for station staff at a suburban station platform to provide the allright signal to a train guard. However, due to high patronage at Brisbane central business district (CBD) stations (Roma Street, Central and Fortitude Valley), and at 2 designated suburban stations with bus connections on the Sunshine Coast line (Nambour and Gympie North), station staff were required to provide the allright signal for every suburban passenger train at those stations.
QR procedure MD-10-109 (Observance of signals manual) stated that, prior to giving the allright signal, station staff were required to:
- make sure … staff have completed all duties associated with the rail traffic
- blow whistle or use loudspeaker to warn people to stand clear of the rail traffic
- make sure all people are clear of the rail traffic
- make sure doors on passenger rail vehicles, not operated by the rail traffic driver, are closed...
Station staff communicated the allright signal to the guard during daylight hours by raising one arm at 45° above shoulder height, and in the hours of darkness by a white light held above shoulder height.
There was no official requirement for station staff to check the aspect indication in the platform departure signal prior to giving the train guard the allright signal.
During the course of the investigation, experienced current and former station staff informed the ATSB that there was a long-standing informal practice at Brisbane CBD stations and at Nambour for station staff to check that the departure signal was at proceed prior to giving the allright signal to the train guard. They recognised that checking the signal was not part of the station staff formal duties; however, the informal practice had been in existence over many years and it had been encouraged by more senior station staff as an additional assurance against false rightaways resulting in SPAD occurrences.
An ATSB investigator visited Central Station and observed station staff checking the departure signals prior to issuing the allright signal.
New generation rollingstock (NGR) business operating model
On 27 June 2017, QR adopted a BOM for the NGR. The configuration of the NGR fleet was different to the existing EMU fleet; NGR trains were permanently coupled 6-car units with no guard’s compartment in the middle of the train. Therefore, the BOM for NGR trains involved the guard working from the rear driving compartment of the 6-car train. In December 2017, NGR trains commenced operations on the Brisbane suburban (Citytrain) rail network.
The location of the guard at the rear of the train posed some challenges for operations, as the boarding point for passengers who required assistance with boarding and alighting remained in the middle of the train (and platform). To overcome these challenges, QR required station staff at all Citytrain stations (CBD and suburban station platforms) to meet every NGR service, where practicable, for the purpose of providing passenger assistance as required.
Allright signal changes for the NGR business operating model
At the time of the NGR being introduced into service, a station customer service (SCS) notice to station staff (SCS employees meeting trains – New generation rollingstock) stated that they were required to provide the allright signal to a guard:
at the 3 CBD stations (Roma Street, Central, Fortitude Valley) and 2 nominated suburban stations (Nambour and Gympie North)for all services
at all other suburban stations only when there was an assisted customer activity to complete and the boarding assistance was provided to the customer.
Station staff at suburban stations confirmed that they were trained to provide the allright signal only on the condition that they provided passenger assistance. During training they were told not to check the platform departure signal prior to giving the allright signal as that was not their role. They explained that delivery of the allright signal was an indication to the guard that platform duties were complete, and passengers and staff were clear of the train.
Citytrain’s SCS management also confirmed to the ATSB that, with the introduction of NGR services to the network in December 2017, station staff at suburban stations were only required to give the allright signal for an NGR service and only if they had assisted a passenger on or off the train. There was no requirement to provide the allright signal if passenger assistance was not provided.
Guards stated that initially this change resulted in confusion for them as it was contrary to the allright process at the CBD stations and the other 2 nominated stations, where the allright signal was given for all trains.
A search of train crew training modules (provided by QR) relevant to the NGR BOM identified no documented guidance for train guards relevant to the allright signal from station staff at suburban stations. An important operational notice (ION) (015_01_2018) titled NGR – Arrival/Departure Procedures, was disseminated by Citytrain’s train services delivery (TSD) section to train crew in January 2018. This notice stated that the allright signal would only be given at designated stations; however, it did not nominate the designated stations.
Modification of the NGR business operating model
On 10 January 2019, TSD issued another ION to train crew (drivers and guards) to advise that the NGR BOM had been modified. It stated:
In addition to the introduction of the New Generation Rollingstock (NGR), an NGR Business Operating Model (BOM) was introduced to outline the operational requirements for this class of Rollingstock. An agreement has been reached between Train Service Delivery and Station Customer Service (SCS) that SCS staff members will provide the ‘Allright’ signal, as well as one (1) whistle blow, when attending any NGR revenue service.
The ION also provided answers to frequently asked questions, including:[12]
Are SCS staff required to attend all NGR services at all platforms?
No, there may be circumstances which prevent a member of SCS staff attending to an NGR service. In this instance, the RTG [guard] is responsible for any assisted boarding activities when the platform is unattended and there is an assisted boarding requirement.
Are SCS staff required to give the Allright signal to the RTG, when attending NGR services?
Yes, SCS staff at Suburban stations are required to provide the Allright signal to the RTG when they attend to an NGR service.
Note: This does not affect the requirement for an RTG [guard] to receive the ‘Allright’ signal, for all trains, prior to giving Rightaway at Roma Street (excluding P2, P3 and P10), Central, Fortitude Valley, Nambour and Gympie North…
What information is the SCS staff member providing when they give the ‘Allright’ signal?
When an SCS staff member gives the Allright signal, it advises that they have finished their required platform duties only.
Note: This is not an indication that the departure signal is at proceed. The RTG is responsible for observance of signals prior to giving Rightaway…
On the same day, TSD issued another ION (006_01_2019), which replaced the 2018 notice regarding NGR arrival and departure procedures. It stated that station staff were required to provide the allright signal for an NGR train if they attended the train service.
At the same time, SCS issued an updated communication to station staff, which stated:
SCS employees are required to provide the ‘Allright’ signal to indicate to the RTG that assisted boarding and visual checks have been completed…
- Suburban stations are only required to provide this indication to the RTG for NGR services to indicate platform duties have been completed. - CBD stations are required to provide the ‘Allright’ signal to all services including NGR services...
Station staff at suburban stations confirmed that they were advised of the change.
QR advised that, at the time of the January 2019 change, the NGR deployment was at an advanced stage and the BOM had been continually reviewed. The TSD and SCS sections were trying to clarify the exact requirements for the allright signal to ensure there were no unnecessary delays or impact on on-time running. The notices also updated other aspects of the departure process for personnel.
As a by-product of these changes to the dispatch procedures, from January 2019 onwards there was a significant increase in the frequency that allright signals were provided by station staff to train guards working NGR trains at suburban platforms.
Rightaway signal procedure
QR procedure MD-14-38 (Rail traffic crew manual) outlined the procedures for a guard to follow when a suburban passenger train was departing a station. These included:
- Once the train is stationary, open the cab door and step out onto the platform beyond the yellow line - Walk sufficient distance to view the entire train (last door to first door), and departure signal or Signal Aspect Indicator (where provided) - Ensure Proceed aspect is illuminated in departure signal or Signal Aspect Indicator - Ensure all customers have boarded / alighted safely and provide customer service as required. At specified locations wait until the ‘Allright’ signal is given by station staff… - Ensure all people remaining on the platform are clear of the yellow safety line - Re-check departure signal / Signal Aspect Indicator displays a proceed aspect (where provided) - Return to working cab and give rightaway to rail traffic driver
For NGR trains, the procedures stated:
When a NGR train is arriving at a station, the Rail Traffic Guard (RTG) will observe the external CCTV to confirm that station staff is in attendance and if anyone is waiting in the designated boarding assistance area.
Once stationary, the RTG will ensure that the platform side doors have been released, exit the cab and step onto the platform beyond the yellow line to observe the presence of station staff on the platform - as well as any passengers waiting in the assisted boarding area (In the absence of station staff, the RTG will provide any boarding assistance as required).
- The RTG will walk to view the Departure Signal or Signal Aspect Indicator (where provided) - Ensure Proceed aspect is illuminated in the departure signal or Signal Aspect Indicator - Ensure all customers have boarded / alighted safely and provide customer service as required. - Ensure all people remaining on the platform are clear of the yellow safety line - Re-check Departure Signal / Signal Aspect Indicator to ensure that it continues to display a proceed aspect (where provided)
At designated stations, an Allright signal will be provided by station staff…
As noted above, the circumstances where an allright signal would be provided for NGR trains were advised in IONs.
Regardless of the type of train, if viewing of the departure signal was obstructed, the guard had to ensure the associated signal aspect indicator (SAI) was illuminated (which indicated that the departure signal was not displaying a red aspect).
The guard provided the rightaway signal by bell communication (that is, pressing a button inside the guard’s cab twice, which would annunciate 2 bell sounds in the driver’s cab).
Driver procedure for responding to a rightaway signal
The receipt of ‘two bells’ was a signal to the driver that the guard had given authority to depart the platform. The driver was then required to follow the documented steps in procedure MD-11-282 (TSD professional driving – Train management train units) before moving the train:
- Check the indication of the departure signal - Move the direction controller into the forward position (if not already in the forward position) - Press the door closing button - Sound the city horn - Wait for the ‘doors open’ tile to extinguish - “Scan before you go” [re-check the indication in the departure signal] - Ensure headlight is on (if applicable)
This procedure was the same for EMU and NGR trains. As already noted in The occurrence, the driver of DW17 advised that they could not recall checking or sighting the status of signal DP29 after receiving the rightaway and prior to departing the platform. They recalled that the rightaway signal (2 bells) from the guard was the prompt to depart the platform. The driver stated that there were no distractions present on the platform or in the driving cab at the time.
The driver of DW17 also noted that they were not aware of the other train at the adjacent platform. They received no advice from the NCO that another train was going to be run ahead of them out of Park Road Station and that they would therefore be stopped at the station for longer than normal. The driver also noted that NCOs were inconsistent in advising drivers of such delays; some NCOs provided the advice whereas others did not.
Start against signal occurrences
Background information
A signal passed at danger (SPAD) is a relatively rare event. For example, during the period from July 2016 to June 2020, there were 119 SPADs on QR’s Citytrain rail network (about 30 SPADs per year). This equated to about 1.91 SPADs per million train km, and a rate of 34,900 red signals approached per SPAD[13] over the 4 years.
The 119 SPADs included:
70 (59%) driver misjudged SPADs (that is, the driver attempted to stop the train but failed to stop before passing the signal)
37 (31%) completely missed SPADs (that is, no attempt was made to bring the train to a stop before the signal)
6 (5%) start against signal SPADs (that is, a stationary train started at and proceeded beyond the signal)
6 (5%) other SPADs (that is, any authority exceeded that is not classifiable under one of the above subcategories).
QR considers ‘completely missed’ and ‘start against signal’ as the most significant SPADs, as generally the drivers involved have continued to operate the train unaware it had exceeded its limit of authority. Such occurrences are problematic on the Citytrain network as, currently, the controls designed to detect such an event have limitations.
QR’s universal train control (UTC) system provided a SPAD alarm at the network control officer’s (NCO’s) workstation if a train passed a ‘controlled’ signal.[14] Therefore, the system had the potential to mitigate the consequences of a SPAD by the NCO transmitting an emergency stop command via radio to the driver (as was the case with the 25 March 2019 SPAD at Park Road Station). However, there can be a significant delay between an NCO detecting a SPAD alarm, the NCO providing the stop command to the driver, the driver responding to the stop command and the train coming to a stop. In addition, a small proportion of station departure signals are non-controlled, and therefore will not be associated with a SPAD alarm if there is a start against signal SPAD.
Most start against signal SPADs (such as the 25 March 2019 SPAD) occur when starting from a station platform. Start against signal SPADs occurring at platforms have commonly involved guards providing a false rightaway to a driver (that is, they have provided the rightaway when there was a red aspect in the departure signal). Such SPADs have often been called ‘ding-ding-and-away’ SPADs, referring to the sound of the rightaway signal (2 bells) and an automatic, habitual action of the driver to start departing a station upon hearing the bells.
Start against signal occurrences on non-NGR trains
During the 9-year period from July 2012 to June 2021, Citytrain had 7 start against signal SPADs on non-NGR trains. These occurred from September 2012 to January 2018, with only one since June 2016 (in January 2018).
Database records provided by QR indicated that, for 6 of these SPADs, the guard provided a false rightaway to the driver, and details for the other SPAD did not include details regarding the guard’s action.
The database records also indicated that in some cases the driver did not check the signal after receiving the rightaway and prior to departing the platform, whereas in other cases the driver stated they had checked the signal and thought it was indicating a proceed aspect. In 2 of the cases, the database records indicated that the driver did not follow the stopped at a red procedure, whereas in another case it was noted that the driver did follow the procedure.
Start against signal occurrences on NGR trains
As previously noted, the first NGR train entered service in December 2017, but the procedure of providing an allright signal for each NGR train at each suburban station only commenced in January 2019. Between December 2017 and December 2018, Citytrain had no start against signal SPADs involving NGR trains. In the 18 months after the January 2019 procedure change, there were 5 start against signal SPADs on NGR trains, with another SPAD the following year. These included:
signal DP29 (Park Road) – 25 March 2019
signal SE16 (Shorncliffe) – 1 October 2019
signal EJ38 (Eagle Junction) – 20 November 2019
signal BH4 (Beenleigh) – 18 March 2020
signal AP12 (International Airport) – 25 March 2020
signal SL23 (Springfield Central) – 23 April 2021.
By the time of the first of the 6 SPADs (March 2019), 51 of the 75 NGR trains had entered service, and for the other 5 SPADs most or all of the NGR trains had entered service. However, throughout the period from January 2019 to June 2021, there were still more non-NGR train services on the network than NGR train services. QR advised that during the period from January 2019 to June 2021, non-NGR trains travelled 16.0 million track km per year whereas NGR trains travelled 8.6 million track km per year (35% of the total). In addition, non-NGR trains approached 554,000 red signals per year and NGR trains approached 430,000 red signals per year (44% of the total).
In summary, there was a substantial increase in the rate of start against signal SPADs in the 18-month period following the change of NGR dispatch procedures in January 2019 and all 5 of the SPADs involved NGR trains, which had less operations than non-NGR trains. The rate of start against signal SPADs decreased in the following 12 months with only one occurrence, which involved an NGR train.
Overall, the difference between the rate of start against signal SPADs (per red signals faced) for NGR trains during January 2019 to June 2021 was significantly higher than the rate for non-NGR trains.[15] In addition, the rate of start against signal SPADs was statistically higher for NGR trains from January 2019 to June 2021 when compared to all suburban trains during the period 2016 to 2018.[16]
In each of the 6 start against signal SPADs involving NGR trains:
they occurred on a suburban station platform (where station staff did not routinely provide an allright signal for non-NGR trains)
station staff provided the allright signal to the guard without checking the status of the departure signal (consistent with the required procedures for station staff at a suburban platform for an NGR train)
the departure signal was not visible from the rear of the train and therefore the guard was required to check an SAI (rather than the departure signal) prior to giving the rightaway to the driver
the SAI was not illuminated (because the departure signal was displaying a red aspect)
the guard provided a false rightaway to the driver
the driver promptly responded to the rightaway signal (2 bells) and departed when the departure signal was indicating a red aspect.
In some cases, the guard could recall receiving the allright signal from station staff, but could not recall checking the SAI, and in one case the guard had seen the station staff look at the SAI then give the allright signal, which influenced their decision to give the rightaway. In the other cases (including at Park Road), the guard stated they checked the SAI and thought it was illuminated. In 2 cases (including at Park Road), the guard did not leave the train (rear driving compartment) to conduct their tasks. Some of the guards noted that the SPADs occurred in the context of a late departure or waiting for the station staff to attend the train, and that after getting the allright signal they wanted to give the rightaway without delay.
In addition to the Park Road SPAD (where the driver could not recall checking the signal prior to departing the station), 3 of the drivers reported they did not check the signal after receiving the rightaway and prior to departing. One of these drivers stated that they had been distracted by dropping something in the cab, and another stated there was an unusually long dwell time at the station prior to them receiving the rightaway. In the other 2 cases, drivers reported they had looked at the departure signal and believed it was green when they departed.
In 3 of the 6 cases (including at Park Road), the driver did not completely follow QR’s stopped at a red procedure; in particular, they did not apply the park brake after stopping at the signal. In another case, the driver had applied the procedure, but then got distracted by dropping something in the cab (as noted above). In the other 2 cases, the drivers were taking over a train from another driver at a station platform.
Detection and response
In all of the 13 start against signal SPADs from 2012 to 2021, the UTC system detected the train had exceeded its authority, and the NCO issued an emergency call to the driver to stop (although in at least one case, the guard had alerted the driver to the problem and the driver had already started stopping). In 4 cases, the distance passed the signal was estimated to be 200–305 m and in another 6 cases the distance was 100–200 m.
In the case of the Shorncliffe SPAD, the time interval between the train passing the signal and coming to a complete stop was about 30 seconds, and the train stopped 275 m past the signal. In the case of the Park Road SPAD, the time interval was about 34 seconds and the train stopped 305 m past the signal.
False rightaway signals
As far as could be determined, all of the 13 start against signal SPADs on the Citytrain network from July 2012 to June 2021, including the 6 SPADs involving NGR trains since March 2019, were associated with the guard providing a false rightaway to the driver.
One driver involved in a start against signal SPAD on an NGR train advised the ATSB that, in a period of 2 months, they had received 4 or 5 false rightaways from guards on NGR trains, and they noted that the allright signal being provided by station staff had contributed to this situation. In addition, a tutor driver advised the ATSB in 2019 that they and other drivers had noticed a large number of false rightaways being given by guards on NGR trains while the departure signal was at stop, and some of these false rightaways involved very experienced guards.
QR did not specifically require that false rightaway events be reported by train crew under its safety management system (SMS). It advised that guards or drivers could report such an event by email to its SPAD email address or by lodging a worker hazard / incident reporting form. It also advised that it had no reports of a false rightaway being provided since January 2018.
Signal aspect indicators
General information
Within QR’s Citytrain network, signal aspect indicators (SAIs) were provided at station platforms where the train itself or an obstruction blocked the guard’s view of a platform departure signal.
An SAI consisted of multiple light emitting diodes (LEDs), which produced a white light (diagonal line)[17] on a black background when the platform departure signal was at proceed (that is, displaying a green aspect, double yellow aspect, single yellow aspect or a flashing yellow aspect). When the platform departure signal was displaying a red aspect (stop indication), the SAI was not illuminated (that is, the indicator was blank) (Figure 7). When illuminated, the white diagonal line in the SAI was about 18 cm long.
QR advised that the aspect design of an SAI matched the design principle of colour light signals when there was no signal aspect displayed in the signal head. That is, when the colour light signal is at blackout or blank it signifies the signal is at stop.
If a guard could not directly view the platform departure signal, they were required to check the SAI during platform dispatch to confirm that the departure signal was at proceed prior to giving the rightaway to the driver.
Figure 7: SAI on platform 2 at Park Road Station in its 2 states – proceed (left) and stop (right)
The image on the left shows the SAI illuminated, therefore the departure signal is at proceed. The image on the right shows no indication in the SAI, therefore the departure signal is at stop.
Source: ATSB
Location of SAIs at station platforms
The placement of signals on the QR network were governed by standard MD-10-95 (Signalling positioning principles). This standard stated that:
- signals will be positioned to provide optimum sighting and visibility - signals will be positioned to provide some measure of commonality of placement - signals will be positioned to minimise the distraction to the rail traffic crew by objects or structures in the foreground or background of the rail traffic crew’s line of sight to the signal...
The standard also included a detailed list of requirements for the positioning of signals. The standard did not include any specific guidance regarding the positioning of SAIs.
The standard also stated:
The officer who is responsible for the works requiring the review of signal sighting shall convene a signal sighting committee. The signal sighting committee shall consider operational issues relating to optimal location and visibility and assess sighting and visibility risks associated with the placement of the signal and its proposed positioning using the approved Signal Sighting Checklist.
The Signal sighting checklist (MD-12-349) included a detailed list of questions to consider, which expanded on the requirements in the standard. The questions were applicable to signals, with limited applicability to SAIs.
QR procedure MD-12-252 (Signal sighting committee) provided guidance for a committee to ‘ensure that all signals, indicators and safeworking signs and boards were positioned so that they afford Rail Traffic Crew adequate sighting and convey a clear and unambiguous indication’.
It was a requirement for the committee to consider issues arising from the position or sighting of signals, indicators, signs and boards when new or altered infrastructure was being designed, after infrastructure changes had been made, after a SPAD had occurred (if sighting was identified as a potential factor), or following a report of sighting issues. The procedure stated:
The position and structure of all signals, indicators, signs and boards shall be considered by a Signal Sighting Committee … which shall consider and decide the safest and most suitable position and structure of each signal and associated equipment.
The Rail Traffic Crew’s sighting distance and viewing distance on the approach to the signal shall be the prime consideration, but regard shall also be given to the signalling arrangements shown on the signalling plan and the present and proposed permissible speed. Signal Sighting Committee decisions shall conform to MD-10-95 Signalling Positioning Principles as a minimum and shall also consider other issues that impact signal sighting/viewing at the location.
The Signal Sighting Committee shall agree on the position of Guards Signal Aspect Indicators and 6 and 3 Car Stopping marks.
In terms of the location of the stopping marks, the procedure stated that the stopping mark signal sighting committee shall ‘ensure the guard can see the departure signal or the Signal Aspect Indicator’.
The procedure stated that the signal sighting committee were required to use the signal sighting checklist to record its considerations. Following the assessment, the committee was required to complete a signal sighting recommendation form identifying any required mitigating actions or recommendations.
SAIs had been installed at some suburban station platforms for a number of years. In preparation for the introduction of the NGR fleet and the changed location of the guard at the rear of the new trains, additional SAIs were installed at numerous locations within the Citytrain network, mainly due to curved platforms.
During interviews, some guards advised the ATSB that SAIs were not installed in consistent positions on suburban station platforms and that this inconsistency in the placement of SAIs, particularly when working NGR trains, made it more difficult to sight the indicators during station dispatch.
Visits to suburban stations by ATSB investigators also identified inconsistency in the location of SAIs at platforms. They were installed on the side of station buildings, platform shelters or on standalone posts that varied in distance from a guard’s location at the rear of an NGR train. At some locations, SAIs that were not illuminated were hard to sight as the black object (the extinguished lamp plus its mounting board) merged into the background.
Guards reported that the LEDs on an SAI were bright and easy to see. However, some guards also noted that on occasions at some platforms they could be potentially confused with station building lights or reflections, particularly if a guard was not sure of an SAI’s exact location.
Location of the SAI on platform 2 at Park Road
In March 2017, as part of the NGR business operating model, a signal sighting committee convened at Park Road Station and recommended the installation of SAIs on platform 1 and platform 2 (applicable to signal DP29), as well as relocating the SAI on platform 3 and lowering the position of the SAIs on platform 4.
The committee determined that the recommended location of the SAI on platform 2 was consistent with guidelines from MD-10-95. This was recorded in the recommendation form. Subsequently, the recommended location of the SAI was approved.
In August 2017, the SAI was installed on platform 2 at Park Road Station. The SAI was positioned on a passenger shelter under an awning, adjacent to a platform sign. The location was about 57 m away from the guard’s location at the rear of an NGR train.
ATSB investigators visited Park Road Station to observe the SAI indicator on platform 2. They noted that, when the SAI was illuminated, the white light was reasonably distinct from its background. However, when not illuminated (as shown in Figure 8), the SAI was not distinct from its background as the black indicator face had little contrast with the awning on the platform shelter. In addition, depending on exactly where the train stopped, some thin building posts could partially obstruct the sighting of the SAI. It could also be obstructed by passengers on the platform.
Figure 8: Location of the SAI relative to the location of the guard at Park Road platform 2
The image shows the location of the SAI at platform 2 Park Road Station. Its location on the platform limited the viewing of the indicator from a guard’s perspective, particularly when the indicator was not illuminated (as in this image).
Source: ATSB
Communication of information about the location of the SAIs at Park Road
In August 2017, Citytrain TSD issued an important operational notice (ION) to train crew to disseminate information relating to the new SAIs (including for DP29) and relocated SAIs at Park Road Station. The notice included a map showing the location of the SAIs at the station. Train crew were not required to verify that they had read and understood the information. Similar notices were sent regarding SAIs at other stations that were introduced or modified as a result of the introduction of the NGR fleet.
The ION regarding the Park Road SAIs was emailed to drivers and guards about 4 months prior to the first NGR train in service.
As noted in Guard qualifications and experience, the guard of DW17 had not operated an NGR train via platform 2 at Park Road Station prior to 25 March 2019 (the day of the SPAD). They also noted that they had had not been provided with any specific route familiarisation training regarding the location of the SAI for DP29 at Park Road Station before operating their first NGR train via that platform. However, the guard stated that they had worked traditional type trains (such as EMU trains) through platform 2 and had noted the position of the SAI during those occasions. However, they had never had to use the SAI before because EMU trains stopped with the guard’s compartment in advance of the SAI.
The guard of DW17 stated that when illuminated, the LED lamps of SAIs were quite bright and distinct. They also said that the SAI at Park Road platform 2 was hard to see. As noted in The occurrence, the guard stated that they checked the SAI and noted that it was illuminated (indicating that DP29 was displaying a proceed indication). The guard also stated that they were not aware of the status of the previous signals immediately prior to arriving at Park Road, and were not expecting to be stopped at Park Road (that is, they would have expected the SAI to have been illuminated).
Departure signal indicators used in New South Wales
The New South Wales (NSW) train network uses guards’ indicators, which are equivalent in function to SAIs. The indicators provide a circular LED light, which illuminates when the applicable departure signal is at proceed and are not illuminated when the signal is at stop.
When the indicators were rolled out across the NSW rail system in the late 1990s, they comprised white LED lights. However, the white LEDs were replaced with blue LEDs as fluorescent station lighting had been installed around the same time, and the blue LEDs provided clearer, easier distinction of the guards’ indicators from the fluorescent lights.
Risk management and change management processes
Overview of risk management processes
QR had a policy (MD-11-1337), standard (MD-11-1338), a general risk management procedure (MD-11-1340) and a safety risk management procedure (MD-11-1339), with the 2 procedures being merged in January 2019. It also had developed tools for risk assessments (for both simple and more complex assessments) and requirements for related processes such as change management, assurance and the communication of safety-relevant information.
The QR standard and procedures outlined a risk management process that was consistent with AS/NZS ISO 31000:2009 Risk management – Principles and guidelines. It included the following processes:
communication and consultation
establishing the context
risk assessment (including risk identification, risk analysis and risk evaluation)
risk treatment
monitoring and review.
QR’s risk management standard stated:
Before any significant change, project or event occurs or when a significant external change or event is detected, a suitable risk assessment will be conducted in order to ensure all potential risks can, and will, be managed effectively.
Overview of change management processes
The Office of the National Rail Safety Regular (ONRSR) guidance document Preparation of a rail safety management system (January 2013) provided guidance for management of change processes.[18] It stated:
Different types of change introduce varying degrees of potential risk. The degree of scrutiny required, and the resulting level of detail at each step, should be proportionate to the degree of risk potentially introduced by the change, or the process of implementing the change…
Change within systems frequently has flow on effects to other parts of the system and can have unintended consequences if the effects are not fully identified. The management of change process is expressly intended to ensure that the effects and influences of change are identified and managed…
Accredited operators should have a range of management of change processes that require an increasing level of scrutiny as the potential level of risk associated with the change increases. The safety management system must include procedures for ensuring that changes that may affect the safety of railway operations are identified and managed…
AS 7472:2018 Railway operations – Management of change stated:
For the purpose of rail safety management, change includes anything that has the potential to alter existing risks or introduce new hazards.
As the rail industry implements innovative ideas or new technologies that improve efficiency and safety, it is important the industry demonstrates how it is managing risk with any change including the option of a trial and the transition to permanent application. Change is fundamental to continual improvement. Without change there can be no improvement.
Changes can be made to management, systems, processes, or assets for both new or modified applications. Change should include any change with a potential impact on the organisations safety management system (SMS) or conditions of accreditation…
The Australian standard listed a variety of examples of change, including changes to rolling stock, infrastructure, equipment, work practices, policies or procedures. It also stated:
On becoming aware of a change, the MOC [management of change] methodology detailed in section 3 of this Standard should be followed. The MOC methodology has a number of actions which form a systematic and structured process…
It is important to note all specific actions may not be necessary for simple, low risk changes. RTOs [rail transport operators] shall explore the impact of the change and should scale the MOC process to suit the agreed impact. A change can vary dramatically, from very simple to very complex and the degree of scrutiny required, and the resulting level of detail required at each action should be proportionate to the degree of risk introduced by the change. A change that is assessed as high risk will require more careful planning and risk analysis than a routine change. A simple, low risk change may not require all actions outlined in section 3 to be implemented. The process should stop once the assessment of risks has been undertaken and the change deemed sufficiently low risk to not require further action…
QR’s standard MD-12-219 (Safety change management) set out the organisation’s requirements for managing changes. The scope section stated:
The change management process will provide systems and procedures for ensuring changes that may affect safety are identified and managed, including any risks identified to other internal and external interfaces that may be impacted by the change…
This Standard shall be implemented for change activities undertaken by or on behalf of Queensland Rail with the potential to impact the safety of Queensland Rail’s operations, workers, customers or stakeholders...
Listed examples of changes included changes to physical assets, operating procedures and operating processes. In terms of the change management process, the QR standard stated:
Change management is a complex process that can be undertaken in various ways depending on the type of change, the size of the change and the relevant change theory implemented.
In general, the safety change management process shall:
- identify if the proposed change has any existing safety implications - identify if the change will introduce any new safety and/or human factors risks…
The QR standard outlined the following activities that needed to be completed as part of a change management process:
assess the change (in terms of the type and nature of the change and its impacts)
identify stakeholders
assess the risks
consult with relevant parties
review the safety and environment management system (to determine if any changes to the system’s documentation where required)
identify how the change process will be reviewed
determine systems assurance requirements (including whether an assurance plan is required and the systems and procedures for ensuring affected workers are fully informed and trained)
identify resources available to implement and monitor the change
obtain document approval
implement the change in accordance with the change plan.
For complex changes with high risk and medium to high business impact, the standard required a documented safety change management plan. For simple low risk changes with low business impact, the standard required the completion of a safety change management checklist.
For some types of infrastructure changes, QR had additional change management standards or procedures. There were no specific change management procedures within train services delivery (TSD) or station customer service (SCS).
Risk process to evaluate NGR business operating models
As noted in previous sections, the first NGR train entered service in December 2017. For the overall implementation of the NGR fleet, QR developed safety change management plans.
As part of these activities, QR utilised its risk management process to identify the most safety-effective business operating model (BOM) for its rail operations. This involved undertaking a risk assessment during June–July 2016.
The objective of the risk assessment was to document and evaluate the risks associated with 2 proposed NGR BOMs – the ‘roaming guard model’ and the ‘guard at rear model’ – and compare them to the current EMU BOM (guard working from the middle of the train). In addition, the process evaluated the effectiveness of the existing risk controls and proposed treatments and provided an informed recommendation on the preferred NGR BOM.
QR’s risk management procedure stated:
Multidisciplinary teams of people that possess subject matter expertise and technical knowledge of the process or system under assessment will participate in the risk assessment. Individuals with the appropriate level of experience, skill and aptitude will facilitate the risk workshops.
A review of the individuals (and their substantive roles at the time) who participated in the NGR BOM risk assessments identified limited personnel with subject matter expertise in the field of train operations. For example, there were no train operations inspectors, tutor drivers or tutor guards involved in the risk assessment process.
Results of assessment of NGR business operating models
In all, the 2016 risk assessment identified 16 operational safety risks (as well as additional customer-related and workplace health and safety risks) to compare the 3 BOMs. One of the identified operational safety risks was:
RTC [rail traffic crew] leaving platform without proceed authority resulting in [start against signal] SPAD.
The risk assessment team identified 5 potential ‘causes’ that could generate the risk of a start against signal SPAD:
the guard unable to sight signal / SAI
the guard not verifying signal aspect
the driver not following safe driving procedures
a train crew distraction
an altered workload.
A series of existing controls were then identified, which included:
guards following procedures for giving the rightaway signal (as well as giving the emergency stop bell and using the emergency brake if required)
drivers following procedures (such as stopped on a red procedure and observance of signals procedures)
train crew maintenance of competency (MOC) processes
route competency (awareness of signal location).
The risk assessments determined that the risk of a SPAD occurrence when departing from a platform under the roaming guard model was high. In contrast, the existing EMU model and guard at rear model was regarded as medium risk. That is, the guard at rear model presented no additional level of risk than the existing EMU BOM for this specific risk.
A series of proposed treatments was also identified for each of the models and for each of the risks. In addition to the existing controls for a start against signal SPAD, these included:
review location and upgrade of current SAIs and identification of future SAIs
traincrew notices and safety bulletins (reflect changes to network)
revision of MOC processes
introduction of the European Train Control System (ETCS)[19] or similar system
workload assessment.
Overall, across all of the identified operational risks, the guard at rear model was evaluated as providing a lower risk level than the roaming guard model, and the guard at rear model was subsequently adopted.
Assessments relating to the allright signal at suburban platforms
Some other identified risks in the 2016 risk assessment were associated with the boarding / alighting of passengers who required assistance. The assessment identified that station staff would need to be actively involved in managing passengers who required assistance for the guard at rear BOM. It was identified that there would be the potential for confusion regarding who was providing assistance (station staff or the guard) and a need for clear delineation of roles, responsibilities and procedures for station staff and guards. The need to develop communication protocols between station staff and guards was also identified as a treatment.
At the time the 2016 risk assessment was completed, the exact nature of the tasks required of station staff and the guard had not been finalised. Nevertheless, it was determined that, under the guard at rear BOM, station staff at suburban platforms would be assisting passengers as, with the guard at the rear of the train, there would be significant delays to on-time running if station staff were not involved in the boarding / alighting process.
Based on the risk assessment documentation, the 2016 NGR risk assessment team did not consider the informal signal checking practices by station staff at Brisbane CBD stations, where the allright signal was not given to the guard unless the departure signal was at proceed. Therefore, the potential risk (or required treatments) associated with the station staff at suburban platforms giving the allright signal while the departure signal was displaying a stop indication were not documented.
As noted in the January 2019 ION, the NGR BOM was modified with the requirement for station staff to provide the allright signal for all NGR trains at suburban stations, significantly increasing the provision of allright signals at station platforms. No risk assessment or safety change management checklist were completed for this change. QR advised that the application of the safety change management standard (MD-12-219) was not considered to be required because the change was minor in nature.
Assessments of signal sighting issues on station platforms
As noted above, one of the proposed risk controls in the 2016 risk assessment was to review the sighting of signals and/or SAIs at station platforms due to possible signal sighting issues with the guard positioned at the rear of the train. As a result, QR conducted a signal sighting review at each station platform within the Brisbane suburban rail network as part of the introduction of the NGR (see Signal aspect indicators).
Processes for communicating safety-relevant information
QR procedure MD-12-826 (TSD communication of notices to rail traffic crew and rail operators) described the methods for communicating operational information to train crew (drivers and guards). The procedure outlined 3 methods of communicating information:
a critical operational alert (COA), which addressed a hazard / risk that required immediate behavioural change (such as ‘significant changes to the network signalling / signage’)
an important operational notice (ION), which addressed a hazard risk that required behavioural change though not necessarily immediate change (such as ‘minor network signalling / signage changes’)
a general operational advice (GOA) for informational purposes (for example, ‘car parking issues’).
After receiving advice of a change or information that could impact TSD, the first step in the process was to undertake (‘when required’) a risk assessment to determine if the operational information to be communicated was critical, important, or general in nature. A subject matter expert was then assigned to draft the notice, which then was reviewed by other personnel and management before being distributed.
If a COA was issued, it was emailed to all train crew and the drivers and guards were required to read and understand the alert, then sign and date it, prior to performing duties relevant to the requirements of the COA. It was also posted to a portal for review by all personnel for 6 months. IONs and GOAs were also distributed by email and posted on the relevant portal, but did not require a process to verify that the drivers and guards had read and understood the contents (although a verification process could be initiated for an ION if required).
As noted in Communication of information about the location of the SAIs at Park Road, an ION regarding the location of SAIs at Park Road Station was distributed to train crew in August 2017. In addition, a January 2019 ION was disseminated to all TSD train crew advising that the allright signal would be administered by station staff for all NGR services. The ATSB requested documentation associated with any risk assessments used to determine this method of communication (that is, the use of an ION). QR advised that risk assessments were not undertaken.
Monitor and review
QR’s risk management standard stated:
Continuous monitoring and review are vital components of an effective risk management process. They may be undertaken as part of a formal periodic process, or performed on an adhoc basis, (e.g. change in policy or change in requirement).
The primary purpose of monitoring and review is to determine whether risks still exist, whether new risks have arisen, whether the likelihood or impact of risks have changed, and to reassess the risk priorities within Queensland Rail’s internal and external context.
Monitoring and review provides important feedback with regard to assurance over the efficiency and effectiveness of controls implemented to treat risks. It enables Queensland Rail to analyse and learn lessons from event successes, failures and near-misses.
QR’s risk management procedures provided additional requirements, including stating that each risk needed to be reviewed at least annually. The January 2019 version of the procedure also stated:
Safety Risks should be reviewed regularly when something occurs that could affect the outcome of the risk, such as:
- The occurrence of an incident or discovery of a hazard - Change to the way things are done (Change Management) - Change in legislation or standard that is relevant to the context of the risk
QR’s safety change management standard also noted that:
Monitoring and review arrangements must be introduced immediately following the implementation of the change to ensure all risk controls, including training, have been and remain effective, and the documentation has been updated.
The review of the change shall consider:
- any new risks that may have eventuated, or pre-existing risks that have changed, after implementation - the effectiveness of pre-existing risk controls and additional risk controls added as part of the change.
The level of assurance required for the change shall be assessed in accordance with the requirements of the Assurance Standard MD-12-24 and Assurance Procedure MD-12-27.
QR’s standard (MD-16-24) and procedure (MD-12-27) provided more detailed requirements regarding the planning and conduct of assurance processes to ensure that risk controls and treatments were operating effectively. The extent of the assurance activities was dependent on the level of risk involved.
During the period following the introduction of NGR services, QR conducted various assurance activities associated with managing SPAD risk. However, none of these activities focussed specifically on NGR operations. In addition, the new process for dispatching NGR services from suburban station platforms, which involved a material change where station staff were providing the allright signal to train guards on NGR services, was not examined during an assurance activity.
Following the 25 March 2019 SPAD, QR’s investigation into the SPAD recommended that a second line[20] assurance activity be undertaken to determine guards’ compliance with rightaway procedures. The assurance activity was undertaken in the first quarter of 2020 and involved conducting 90 observations of SCS staff providing allright signals and guards providing rightaway signals. Results included:
About half of the observations were conducted at the 3 CBD stations, and most of the observations (53) involved NGR trains.
The assessment of each guard’s performance was limited to observing whether they exited the cab after arriving at the station and whether they walked beyond the yellow line on the platform before providing the rightaway.
The proportion of guard observations assessed as being non-compliant was higher for non-NGR trains (13 out of 37) than NGR trains (9 out of 53).
No problems were noted with the provision of the allright signal by station staff.
Further examination by the ATSB of the figures contained in the assurance report noted that, for non-NGR trains, all of the observed guard non-compliances occurred at CBD stations (13 out of 28 observations), where station staff always provided the allright signal for all trains and checked the status of the departure signal before doing so (Allright signal procedure for the EMU business operating model). For NGR trains, the rate of observed non compliances was similar for CBD stations (3 out of 16) and suburban stations (6 out of 37).
Incident reporting
QR standard MD-12-210 (Incident, accident and hazard reporting, recording and notification) stated:
All Incidents, Accidents and Hazards are to be reported to enable controls to be identified and implemented to prevent any further occurrence. Workers must be instructed to report all Incidents, Accidents and Hazards to their supervisor for action as soon as possible or prior to the end of the shift.
The standard and associated procedures outlined more specifically the types of events or hazards that were required to be reported. SPADs were required to be reported. However, false rightaway events were not required to be reported.
Drivers and guards directly involved in NGR SPAD occurrences stated that they were unaware of any safety campaign encouraging staff to report incidents associated with the introduction of the new NGR BOM, such as false rightaway events.
Various documentation provided to train crew and SCS personnel with the introduction of the NGR were reviewed by the ATSB. None of these communications specifically required or requested that any particular types of events be reported following the introduction of the NGR fleet.
Maintenance of competency processes
Overview of assessment processes
QR as a rail transport operator was required to ensure that rail safety workers such as drivers and guards were competent. To evaluate competency, drivers and guards on the Citytrain network were required to complete a maintenance of competency (MOC) assessment every 18 months. The MOC included a written assessment and a practical on-track assessment.
The MOC process for a driver involved the driver completing a written assessment (over 1 day) then a practical assessment (over 1 day) with a nominated assessor. The MOC process was undertaken one-on-one; the driver undertook the assessment while the assessor (tutor driver or train operations inspector) administered the activities. The written assessment typically involved nearly 300 questions.
The participant had to achieve 100% on the written assessment before advancing to the on-track practical component. If the driver was unsuccessful in more than 10% of the questions, they would be entitled to one retest (of the whole written assessment), which had to be completed on another day. If they were unsuccessful in some questions (but less than 10%), the participant was required to research the correct answers and then make corrections.
The MOC assessments for a guard followed the same basic process.
In 2018, QR used the MOC process for existing drivers to upgrade their train driving qualifications from Certificate III in train driving to Certificate IV. In all, 252 Citytrain drivers gained the higher level certificate as a result of the successful completion of their written and practical MOC assessments.
Assessors who administered training and assessment for QR had to have vocational competencies at least to the level being delivered and assessed and hold current industry skills relevant to the training and assessment being provided. In accordance with QR’s Registered training organisation specification (MD-13-591), only accredited assessors were permitted to conduct assessments. Assessors were to ensure they followed the principles of assessment and the rules of evidence when conducting assessments.
Previous ATSB investigation
During a recent investigation into a SPAD at Bowen Hills, the ATSB investigated QR’s MOC process for Citytrain drivers in detail.[21] The investigation identified that, in many cases, drivers achieved perfect or near perfect results in their written MOC assessments. However, it was also identified that in numerous cases answers requiring a detailed response in the written MOC assessment matched word-for-word the answers from the assessor’s marking guide.
Based on this and a range of additional evidence, the ATSB concluded that the following 2 safety issues existed:
Queensland Rail’s administration of the maintenance of competency (MOC) assessment process provided limited assurance that its Citytrain train drivers met relevant competency requirements. (Safety issue RO-2018-002-SI-01)
Queensland Rail’s management oversight of the Citytrain driver maintenance of competency (MOC) process did not include planned assurance activities or regular and effective auditing of how the MOC assessments were being conducted, even after there were multiple indications that the process was not being conducted as designed. (Safety issue RO-2018-002-SI-02)
Similar problems were noted in the ATSB report regarding the MOC assessments for guards.
DW17 driver’s maintenance of competency assessments
The driver of DW17’s last 2 MOC assessments were conducted in January 2016 and November 2018. The driver’s MOC assessment in January 2016 recorded 100% on the written component (on their first attempt) and a perfect result on the practical on-track assessment. The written assessment required the driver to respond to 273 questions that varied in complexity from marking the correct answer from a list to writing lengthy responses to technical questions.
The driver’s MOC assessment in November 2018, administered by a different tutor driver, showed similar results to that of their 2016 assessment. On the first attempt of the written assessment, the driver achieved 98.7% (100% after corrections), and the practical on-track assessment resulted in a perfect performance. By successfully completing the MOC assessment in 2018, the driver gained a Certificate IV in Train Driving.
The ATSB compared responses from the driver’s written MOC assessments against answers to questions in the assessor’s MOC marking guides. The results showed that the driver’s written responses in each MOC, for questions requiring a detailed response, were mostly identical or near identical to those in the assessor’s marking guide. In one of the written MOC assessments, an obviously incorrect answer in the marking guide was mirrored in the driver’s response.
The irregularities identified with the driver’s MOC assessments were similar to the findings identified in the ATSB’s previous investigation for other drivers, and indicated that the driver either had access to the assessor’s marking guide or had other assistance during the completion of the MOC assessments.
Following the SPAD occurrence at DP29 in March 2019, the driver participated in a post-incident on-track evaluation,[22] and a subsequent non-technical skill[23] (NTS) assessment. These occurred on 8 May 2019. The on-track evaluation found the driver ‘not yet competent’, while the NTS assessment identified deficiencies and recommended areas for improvement in the driver’s use of RTCD and observance of signals, particularly when departing from station platforms. The outcome of the driver’s evaluation and NTS assessment resulted in an operational improvement plan (OIP) that involved coaching and mentoring sessions administered by train operations inspectors (TOIs).[24]
Records provided by QR showed the driver participated in 17 coaching and mentoring sessions. On 14 occasions, the driver was assessed as ‘not yet competent’. On 28 June 2019, an on-track assessment successfully recorded the driver as competent. In addition, the NTS assessment, based on information collated from the coaching and mentoring session, also considered the driver competent. On 1 July 2019, the driver returned to normal duties.
DW17 guard’s maintenance of competency assessments
QR records showed that the guard of DW17 participated in a MOC process on 11 and 15 October 2018. Prior to the commencement of the written MOC component, the guard had a discussion with an assessor (not the assessor undertaking the MOC assessment) regarding possible language and literacy issues, which could affect their ability to complete the assessment successfully. This assessor recorded:
[the guard] … advised me [their] spelling was not accurate and reading capabilities is of a slow pace with not able to understand the questions correctly nor can [they] pronounce certain words and misunderstands the questions and [they] felt under pressure and stressed…
This information was conveyed to the MOC assessor and relevant training staff, and there was agreement to grant the guard an additional day to complete the written assessment as reasonable adjustment. The guard successfully completed the 207-question written assessment with a result of 96% on their first attempt (100% after corrections).
The assessor who the guard confided in prior to the MOC assessment submitted a ‘Language, literacy and numeracy (LLN) identification checklist’ (MD-14-829) recording the guard’s LLN issues. In addition, the assessor corresponded with the QR training and development section to advise them of the issue. The assessor considered that the guard:
was unable to successfully complete the training and assessment required for their job
was unable to read and understand work instruction procedures, or other relevant documentation
had difficulty reading and/or interpreting diagrams, graphs, plans, flowcharts and similar documents.
On 15 October 2018, while participating in the on-track MOC component, the guard was assessed as ‘not yet competent’ due to a procedural error. A complete retest was scheduled for a later date.
Since the introduction of the MOC process in 2008, there was no previous evidence of recorded disclosure from the guard or assessors relating to the guard having LLN issues. However, records of assessments during that period indicated that the guard had successfully completed the MOC process without special needs assistance. On 24 October 2018, the guard resat the written MOC assessment and achieved 99% on their first attempt, and 100% after corrections. The written assessment showed no evidence that the guard was provided assistance in completing the assessment as a result of having LLN issues. Further review of the assessment identified very few spelling mistakes and there was no additional time required to complete the assessment.
Following the SPAD occurrence at DP29 in March 2019, the guard chose (supported by QR management) to relinquish the position of guard and subsequently took up another position within QR.
Fatigue management
Introduction
During the investigation, the ATSB noted that in the 8 days leading up to the occurrence, the driver had conducted seven shifts that commenced between 0300 and 0537 (see Driver medical information and recent work history). In addition, the ATSB noted that the guard was assigned an early shift on the day of the occurrence, commencing at 0412, with limited advance notice (see Guard medical information and recent work history). Accordingly, the ATSB examined QR’s processes for managing fatigue risk related to these aspects.
Rostering principles and guidelines
QR standard MD-10-178 (Fatigue risk management) prescribed hours-of-work principles for a master (long-term forecast) roster and day-of-operations (actual) roster for different types of rail safety workers. For suburban rail traffic crew, these principles included:
maximum shift length of 9 hours
minimum break between shifts of 12 hours
maximum number of 12 shifts in any 14-day period.
With regard to roster design, the standard also stated:
For a robust hierarchical risk based approach the following should be considered and applied in this order unless not reasonably practicable.
1) Apply the good roster practice guidelines in Appendix 2 to roster development;
2) Where the good roster practice guidelines are not reasonably practicable in the business context, apply a risk based approach determined as SFAIRP [so far as is reasonably practicable] in the specific context that manages risk to a higher level than minimum requirements of this Standard;
3) Apply minimum requirements of this Standard, including checks against FAID [see below], hours of work principles and Enterprise Agreements.
The good roster practice guidelines included (but were not limited to):
shifts with sign-on-times before 0500 limited to no more than 8 hours
maximum of 4 consecutive night shifts in a row (defined as starting between 1800–0359)
maximum of 5 consecutive early shifts (defined as starting between 0400–0600)
minimum rest period between night shifts of 14 hours
2 days rest between a night shift and starting an early shift (that is, minimum 54 hours rest)
1 day rest between an early shift and starting a night shift
avoiding significant adjustments in required sleep (such as transitioning from an early start to a night shift).
In the case of the driver and guard of DW17, their master and day-of-operations rosters for the period leading up to the occurrence complied with the mandatory hours-of-work principles.
With regard to the good roster practice guidelines, the driver had 6 consecutive shifts between 17–23 March that commenced between 0300 and 0537; 4 were classified as early shifts and 2 were classified as night shifts. These shifts did not meet the guidelines associated with rest breaks when transitioning between early shifts and night shifts. If these shifts were all considered to be early shifts, they would not have met the guideline regarding a maximum of 5 early shifts in a row.
In addition, both the driver and the guard conducted shifts of over 8 hours starting before 0500 on multiple occasions in the 14 days prior to the occurrence, including on the day of the occurrence (the driver on 3 shifts and the guard on 4 shifts).
Use of biomathematical models of fatigue
A biomathematical model of fatigue (BMMF) uses algorithms to predict the effect of different patterns of work on measures such as subjective fatigue, sleep or the effectiveness of performing work. Each model uses different types of inputs and produces different types of outputs, and each model is based on many assumptions and has limitations.
In particular, the models are based on group-averaged data, and it is widely agreed that the models are not well suited for predicting a specific individual’s level of fatigue. In addition, none of the models consider all of the factors that can influence fatigue. The models are designed to be only one element of a system for evaluating and comparing work rosters (see Civil Aviation Safety Authority 2014, Dawson and others 2011, Gander and others 2011, Independent Transport Safety Regulator 2010).
QR used the BMMF known as ‘FAID’[25] to conduct assessments of rosters. FAID has been widely used in the Australian rail and aviation industries since the early 2000s. It uses hours of work (start time and end time) as its inputs, and it produces a score based on an algorithm that considers the effects of the length of the duty periods, time of day of the duty periods, and the amount of work over the previous 7 days (Roach and others 2004). The higher the FAID score, the higher the potential for fatigue.
QR’s fatigue risk management standard stated:
All master and day of operations rosters for Queensland Rail workers performing shift work (including volunteers), must be analysed using … FAID … to ascertain if the rosters provide adequate sleep opportunity. This includes shift changes, shift swaps, extended and unplanned shifts.
The QR standard stated that FAID scores between 0-79 (green zone) were considered broadly acceptable and ‘all reasonable steps should be taken to ensure all rosters fall within this range’. Scores greater than 100 (red zone) were considered to provide an unacceptable sleep opportunity. Scores between 80–100 (yellow zone) were considered ‘acceptable with demonstrable risk assessment’. This meant that:
A documented risk assessment, undertaken in accordance with the Risk Management Framework, must be completed and approved as per the risk management matrix before workers can operate in this zone.
QR advised the ATSB that this did not mean that a specific risk assessment had to be conducted prior to any specific worker being assigned a shift with a FAID score of 80–100. Rather, for train crew, train services delivery (TSD) had conducted a risk assessment covering all fatigue-related hazards.
In terms of the risk of ‘worker fatigue’, one of the listed causes in the risk assessment was rosters with a FAID score in the yellow zone or outside of the hours of work principles. A number of controls and treatments were listed. These were mostly general in nature, such as MD-10-178 being implemented as the higher safety control, managers and rostering personnel completing fatigue management training, and conducting regular assurance activities on a sample of rosters. There was no requirement for any specific worker with a FAID score in the yellow zone to undergo an assessment prior to commencing work unless the worker had self-identified that they were fatigued or they had been observed to be experiencing signs of fatigue (see also next section).
For the 7 days leading up the occurrence, the guard’s FAID scores were below 80 and on the day of the occurrence the peak score was 40. For the driver, the peak FAID score on the day of the occurrence was 65. However, on both the 22 and 23 March, the driver’s peak scores were above 80 (and for 23 March the score was above 80 for about half of the duty period).
Self assessments of fatigue
QR’s procedures and code of conduct stated that fatigue risk management was a shared responsibility between the operator and rail traffic crew. The fatigue risk management standard stated that rail traffic crew were responsible for taking reasonable steps to ensure they did not present to work fatigued and that they managed non-work factors that could contribute to fatigue.
QR’s standard also required that workers ‘report instances of fatigue to their leader so additional controls can be implemented to manage the risk’. Such reports were required to use QR’s fatigue assessment form.
A critical operational alert issued to train crew in October 2017 advised train crew about a new version of the self-assessment form for train crew. It also stated that train crew were required to:
Using the new self-assessment form, assess whether you are fit to go prior to every shift as is current practice. If you are not fit to go for your entire shift and duties, contact the roster office to discuss your fatigue assessment result. If alternative duties are located and agreed to, or you are booked off, you are required to submit the completed fatigue self-assessment form as per the form instructions on your next shift.
The form included questions regarding the amount of sleep in the previous 24 hours and 48 hours, and the worker’s self-assessment of their level of alertness. If any of these parameters exceeded predetermined thresholds, then either personal risk mitigation strategies were required (if one of the scores was in the yellow zone), the result needed to be discussed with a supervisor, roster officer or train operations inspector and additional controls be specified (if one of the scores was in the red zone) or the worker was deemed not fit for duty (if one of the scores was in the black zone).
In terms of sleep in the previous 24 hours, the form stated that 5 hours or more sleep was in the green risk band, 4 hours was in the yellow band, 3 hours was in the red band and 2 hours was in the black band. In terms of sleep in the previous 48 hours, the form stated values of 12 or more hours, 11 hours, 10 hours and 9 or less hours for the 4 bands respectively.
There was no specific requirement for the driver or guard of DW17 to complete and submit a risk assessment form in the period leading up to the occurrence, and there was no evidence to indicate any forms were completed.
Fatigue management training
Citytrain train crew were required to undertake fatigue awareness training on a regular basis. The contents of the training provided an overview of sources and effects of fatigue, QR’s processes for managing fatigue and some individual fatigue alertness strategies.
In terms of hours of sleep, the course materials noted that less than 6 hours sleep was high risk and 6–8 hours’ sleep was moderate risk. This information was not fully consistent with the latest version of the fatigue assessment form (see previous section).
The course material also provided some information regarding FAID and how it was used by QR. The material noted that all master roster scores had to be below 80 (that is, in the green zone) whereas day-of-operations roster scores could be in the yellow zone.
Late-notice changes to a roster
According to the QR’s fatigue risk management standard, deviations from the mandatory hours-of-work principles could only occur for a day-of-operations roster or for an ‘emergency or unplanned event’. Similarly, rosters with FAID scores of 100 or more could only occur for an emergency or unplanned event. In such events, a fatigue assessment form for the worker was required to be completed and all reasonable steps taken to relieve the worker as soon as possible.
The guard was called at 2208 on the 24 March and asked if they were able to commence their shift on 25 March at 0412 (rather than the previously assigned time of 0900). QR rostering personnel stated that this was not considered an emergency or unplanned event; rather it was a shift vacancy caused by illness to another rail traffic crewmember.
QR rostering personnel noted that they managed the rosters of 2,800 employees (including train crew) and that the need to replace a rostered person at short notice was not unusual. In such cases, their systems would indicate which personnel were available to take the required shift (in terms of personnel who met the hours of work principles) and then they would ensure the selected personnel had a suitable FAID score (that is, 100 or less). If the selected personnel met the requirements, they would be offered the shift change or additional shift. It was not compulsory for the personnel to accept the change, and it was up to the personnel to assess their fitness to undertake the changed duty.
The ATSB requested information relating to any other risk controls used by QR to manage the fatigue risks associated with late-notice roster changes for rail traffic crew. There were no additional procedures for managing such changes. There was no requirement for a worker to complete a fatigue assessment form, unless they perceived themselves to be fatigued, and there was no requirement for rostering personnel to ask the worker about their level of alertness or hours of sleep when arranging a change.
On 25 March 2019, a Queensland Rail (QR) Citytrain suburban passenger train (DW17) exceeded its limit of authority by passing signal DP29 at Park Road Station while the signal displayed a red aspect (stop indication). This resulted in a near collision with another QR suburban passenger train (1E65), which had been scheduled to run in advance of DW17 from Park Road Station.
There were no problems associated with the serviceability of the train, and the signalling system functioned as designed. The immediate reason for the signal passed at danger (SPAD) was that the driver did not effectively confirm the signal’s status prior to departing Park Road Station.
Such a ‘start against signal’ SPAD could have had very serious consequences as there were limited risk controls or defences in place on the QR Citytrain rail network to recover from the situation. In this case, the actions of a tutor driver in the driving cab of train 1E65 and a network control officer (NCO) likely prevented a train-to-train collision. Although a collision between 2 trains merging at a set of points would be less serious than some other collision scenarios, it would still have probably led to significant adverse consequences.
The safety analysis will initially discuss the actions of the driver and guard of DW17 and the context of those actions. It will also discuss the process associated with the placement of signal aspect indicators (SAIs) on station platforms with the introduction of the new generation rollingstock (NGR) business operating mode (BOM). In addition, it will consider QR’s risk management and change management processes relevant to the implementation of the NGR BOM and the risk of start against signal SPADs. The analysis will also discuss train crew maintenance of competency (MOC) processes and fatigue management in relation to late-notice roster changes.
Train crew performance
Checking the departure signal
Train driving is a specialised task that is acquired through comprehensive training and significant experience; it involves conducting routine, frequently-practiced tasks in a largely automatic manner (at a skill-based level) with occasional conscious checks on performance. Accordingly, most of the driver errors associated with SPADs occur at the skill-based level of performance (Gibson 2016), and such errors are generally known as slips or lapses (Reason 1990).
A common factor involved in most start against signal SPADs is expectancy. Expectations based on past experience strongly influence where a person will search for information and what they will search for (Wickens and McCarley 2008), and they also influence the perception of information (Wickens and others 2013). In simple terms, people are more likely to see what they expect to see, and less likely to see what they do not expect to see.
Prior to departing a station platform, a driver is required to check the status of the departure signal after receiving the rightaway signal (2 bells) from the guard. Citytrain train drivers receive more than 100 rightaways a day, and in almost all cases the rightaway is provided when the departure signal is displaying a proceed indication. Accordingly, drivers develop a very strong association between the sound of the rightaway signal and the presence of a proceed indication, and they therefore develop a very high level of expectancy that 2 bells (rightaway) is associated with departing from the platform.
As noted with a number of start against signal SPADs involving Citytrain drivers, this leads to some situations where drivers, performing their tasks at a skill-based level, receive a rightaway and either do not check the departure signal or check the signal but falsely perceive the signal to be displaying a proceed indication. This automatic or habitual tendency is well known in rail operations (for example, Multer and others 2019, Basacik and others 2008) and has also been demonstrated in experimental research (Haga 1984).
In this case, the driver of DW17 promptly departed the station platform after receiving the rightaway from the guard. The driver subsequently reported that they could not recall checking or sighting the status of signal DP29 prior to departing the station, and they were prompted to depart after receiving the rightaway.
The driver also stated they were expecting the departure signal to be red when they approached the station and their driving on approach to the station was consistent with this expectation. However, there was a longer than normal dwell time at the station, and such situations can disengage or dislocate a driver’s attention (Naweed 2013). It is also likely that, as DW17 was running on time, the driver had a low level of expectancy that the train would be delayed at Park Road to accommodate the passage of another train. They had received no advice from the NCO that they would be held at the station for an extended period (nor were they required to be advised).
Although the driver explained the SPAD as being a product of the signal being blocked by the train cab blinds, the ATSB determined this was not plausible. Furthermore, the implication of the driver’s account is that they consciously departed Park Road Station without checking the signal aspect. Sighting and confirming the aspect of a departure signal is a critical activity for safe train driving, and it is highly unlikely that an experienced train driver would intentionally depart a train station if they were consciously looking for but not able to confirm the signal aspect.
The red aspect in the signal had optimum viewing from within the driving cab of the train when it stopped at the platform, and there were no indications that the driver read through to another signal. In addition, there were no indications of distractions either inside or outside the driving cab at the time.
In summary, after receiving the rightaway signal, the driver promptly departed the station platform without effectively checking and confirming the aspect indication in the departure signal (DP29). Based on the available evidence, it is more likely that they did not check the signal rather than they misperceived the aspect indication. In either case, the driver was conducting their tasks at a skill-based (or automatic) level of performance and had a very high level of expectancy that the signal was indicating a proceed aspect, particularly after receiving the rightaway from the guard.
Application of the ‘stopped at a red’ procedure
A driver checking the status of the departure signal is the last risk control in place to prevent a start against signal SPAD. QR had in place other procedural risk controls that provided protection against the unauthorised departure of a train from a station platform. One key risk control involved drivers applying the ‘stopped at a red’ procedure. This required a driver to use operational interlocks (park brake and direction control settings) after stopping at a red signal to reduce the likelihood of an automatic or reflexive driver response to a false rightaway.
Such operational interlocks are used by many experienced drivers in different operators (Naweed and others 2015), and QR had formalised them into a standard procedure for its drivers. Based on QR data, the procedure had a relatively high compliance rate (92%). The procedure also appears to be effective in reducing the likelihood, but not eliminating, start against signal SPADs, as the compliance rate during such events was much lower. However, it is unclear how many drivers applied the start on a red procedure, received a false rightaway from a guard and then detected the red signal prior to departing a platform.
In this case, the driver of DW17 did not fully apply the start on a red procedure. Even though the driver was probably aware that the departure signal was displaying a red aspect during their arrival at the station, it is possible that their awareness of the status of the signal decreased soon after stopping at the platform. The driver said that their habit was to only sometimes use the stopped at a red procedure, depending on whether they felt confident in their ability to drive safely at the time. Inconsistent use of such procedures would degrade their effectiveness, and it is noted that the driver had also previously experienced a start against signal SPAD 10 years previously.
In summary, after DW17 stopped at Park Road Station, with the departure signal displaying a red aspect, the driver did not apply the operator's stopped at a red procedure. This probably contributed to them not detecting that the departure signal was displaying a red aspect after receiving the false rightaway from the guard.
Providing the rightaway signal
Another key risk control to minimise the risk of a start against signal SPAD was for guards to check the status of a platform departure signal, via direct observation of the signal (or as in this case the SAI), before providing the rightaway to the driver. The guard was required to check the departure signal or SAI twice; both before and after checking that all passengers had boarded / alighted (or where required after station staff had provided the allright signal).
Commencing in January 2019, station staff were required to provide the allright signal to the guard for every NGR service (regardless of whether they had to assist a passenger). In line with QR’s platform dispatch procedures, there was no requirement for station staff to check the departure signal prior to issuing the allright signal, and staff at suburban stations were also instructed not to check the departure signal.
In the case of DW17, the guard issued the rightaway to the driver after receiving the allright signal, even though the SAI was not illuminated. The guard stated that they had looked for the SAI after they received the allright signal and they thought that it was illuminated (indicating signal DP29 was at proceed).
The ATSB notes that the guard had significant time prior to receiving the allright signal to sight the SAI. However, after receiving the allright signal they immediately gave the rightaway signal to the driver, which could suggest the allright signal was the guard’s prompt to give rightaway. In addition, the guard did not step onto the platform to perform their tasks. Although the SAI could be sighted from the rear of the train, by not stepping out onto the platform the guard was less likely to be actively engaged in performing their tasks. The extent to which the guard was aware of the location of the SAI to use it effectively was also unclear (see Placement of signal aspect indicators).
Previous research in the UK has identified that guards have reported that they would be less likely to check a departure signal if station staff were involved in the departure process (Basacik and others 2008). In the course of the current investigation, the ATSB identified 5 similar SPAD events involving NGR trains where the guard had issued a false rightaway after receiving the allright signal from station staff. In some of these cases, the guards could not recall checking the SAI whereas in other cases they recalled checking the SAI and perceived it to be illuminated.
Regardless of whether they checked the SAI, it is likely that expectancy had a strong influence on most (if not all) of these guards’ responses. As with drivers, guards are conducting frequently-practised tasks at a skill-based level of performance, and through experience they have developed a very high level of expectancy that, if they are given the allright signal, then a departure signal will be displaying a proceed indication.
This expectancy has developed because:
Before the introduction of the NGR to the Citytrain network, there was no requirement for station staff at suburban station platforms to provide the allright signal to train guards, other than at the 3 Brisbane CBD stations and 2 designated suburban stations (Gympie North and Nambour). At these stations, guards would always receive the allright signal from station staff, but they only receive it when the platform departure signal displayed a proceed indication. This was due to station staff executing the informal (and undocumented) practice of checking the departure signal was at proceed before providing the allright signal.
With the introduction of NGR trains in late 2017, station staff at suburban platforms were only required to provide the allright signal if they assisted passengers. This occurred occasionally but not frequently.
Given the lower levels of intersecting traffic and lower signal density outside of the Brisbane CBD, the likelihood of a red aspect in a departure signal at a suburban station platform was comparatively low.
The change to dispatch procedures in January 2019, which required station staff at suburban stations to issue the allright signal for all NGR trains, significantly increased the number of allright signals guards received each day. Because station staff at suburban platforms did not check the status of the departure signal before issuing an allright signal, this also increased the likelihood that guards would receive an allright signal while the departure signal was displaying a stop indication. As indicated by the SPAD statistics and anecdotal reports, this significantly increased the frequency of false rightaways that led to start against signal SPADs.
Overall, it is unclear whether the guard of DW17 checked the SAI after receiving the allright signal before providing rightaway to the driver. Regardless of whether they checked the SAI or not, the guard probably had a very high level of expectancy that the departure signal was at proceed after being issued the allright signal, as this is what they had previously experienced at Brisbane CBD station platforms. In addition, the guard had no knowledge of the restricted signal sequence encountered by the driver as the train approached and stopped at Park Road. Therefore, they had a low level of expectancy that the train would be delayed at Park Road to accommodate the passage of another train as DW17 was running on time.
Summary
The development of this occurrence required multiple errors by the driver and the guard. Effective safety systems utilise redundant controls to minimise the consequence of individual errors. In the case of start against signal SPADs, the procedural risk controls had redundancy, relying on both the driver and the guard to check the departure signal. In addition, there was a requirement for the driver to use the stopped at a red procedure as another risk control to capture the error of automatically responding to a false rightaway and departing from the platform.
Nevertheless, this start against signal SPAD (and the other 5 NGR start against signal SPADs) have reinforced the point that procedural (or administrative) risk controls will always be fundamentally limited in their effectiveness compared to well-designed engineering controls for detecting potential or actual SPADs and managing their risk (see also ATSB report RO-2018-002 for further discussion of this topic).
Placement of signal aspect indicators
A signal aspect indicator (SAI) plays an essential role in the platform dispatch process. If the guard cannot sight the departure signal, due to the curvature of the track or obstructions, they need some other indication on the status of the departure signal prior to providing the rightaway signal to the driver. Although SAIs were installed at some station platforms prior to the introduction of the NGR fleet, the guards’ location at the rear on NGR trains meant that SAIs were required to be installed or moved at a considerable number of platforms in the Brisbane suburban network.
A number of factors can influence how people search for information such as a signal, including knowledge of the signal’s location and the salience of the signal. In simple terms, if people know the exact location where a signal will be provided, then their performance will be better than if they do not know (Wickens and others 2013).
SAIs on platforms in the Citytrain network were not located in consistent positions; they varied in terms of what they were affixed to, and also their distance from the rear of an NGR train. In addition, QR procedures relevant to signal positioning and sighting principles provided limited guidance on the placement of SAIs, other than to state they should be positioned to provide adequate sighting and convey a clear indication. In contrast, the QR procedures and signal sighting checklist provided detailed guidance regarding the placement of signals.
It is understandable that the placement of SAIs involves considering a range of factors and will at times require compromises to be made. Nevertheless, limited consistency in the placement of SAIs presented difficulties to the guards who had to use them. This situation could be mitigated to some extent if guards knew the exact location of each SAI and were experienced with using them. However, when a considerable number of SAIs were installed or moved in a short period for the NGR fleet, it was probably not practical to give each guard detailed familiarisation training. Although guards were advised by notices about changes to the location of SAIs, they still needed to develop experience with using the SAIs to be able to effectively conduct their tasks.
In terms of salience, warnings and signals are typically designed to present their most conspicuous state when the system is in its most hazardous state, or at least the most hazardous state is presented in a clear and salient manner. As noted by Wickens and others (2013), the absence of something is harder for people to notice than the presence of something.
In the process of dispatching trains at station platforms, an SAI displays a bright light when the departure signal is at proceed (less hazardous state) and nothing when the departure signal displays a stop indication (most hazardous state). In addition, an SAI that is not illuminated often has a low level of contrast relative to its background and can be hard to detect, particularly if a person does not know exactly where it is located. In such situations, it is possible that a guard, with a high level of expectancy that a departure signal is at proceed, may mistake some other form of light or reflection in their visual field to be an illuminated SAI.
SAIs and similar indicators have been in place in the rail system for a long time, and originally their design was consistent with a fail-safe principle, because if the light failed then it would default to a safe (stop) indication. Redesigning such displays would present its own challenges due to the significant changeover and retraining cost. Nevertheless, positioning them close to the guard who is using them, or modifying their design or the design of their surrounding area to better show their location when not illuminated, would increase their salience and improve performance.
The SAI for DP29 was located 57 m from the location of the guard when working an NGR train. The SAI could be seen from the rear of an NGR train and also from the platform, however there were some obstacles (building infrastructure) on the platform that possibly could partially obstruct its sighting. Whether the SAI could be sighted from the train or the platform, its position was not consistent with optimal viewing for a guard.
The extent to which the guard of DW17 was aware of the exact location of the SAI for signal DP29 is unclear. The guard had received an important operations notice (ION) by email in August 2017 prior to the SPAD, but it is unlikely that they would have recalled this information 19 months later. The guard also stated they had never worked an NGR train through platform 2 at Park Road until the day of the SPAD. Although the guard stated they had previously seen the SAI when working other types of trains through that platform, the extent to which the guard could have promptly and reliably identified its location when it was not illuminated from the rear of an NGR train was difficult to determine.
In summary, QR’s process for the installation of SAIs did not provide sufficient detail to ensure consistent and conspicuous placement of SAIs at station platforms. This problem, combined with an SAI’s non-salient indication when the platform departure signal displayed a stop indication, increased the risk that an SAI would not be correctly perceived by a train guard. The extent to which this problem contributed to the SPAD on 25 March 2019 could not be reliably determined as it is unclear to what extent the guard actually checked the SAI (see Providing the rightaway signal).
Risk management associated with changing the allright signal process
As previously noted, the start of NGR operations in December 2017 resulted in station staff at suburban platforms providing the allright signal more frequently to train guards (that is, when they had assisted a passenger on or off an NGR service). The provision of the allright signal at suburban platforms then significantly increased in January 2019 when the dispatch procedures were changed to require the allright signal to be provided for each NGR service.
The provision of the allright signal played an important role in standardising communications between station staff and train guards of NGR services. However, the increased use of the allright signal at suburban platforms created an unintended hazard due to the way the allright signal was previously provided for all trains at the 3 CBD stations and 2 other designated stations.
More specifically, due to the undocumented practice of station staff providing allright signals at the designated stations only if the departure signal was displaying a proceed indication, guards had a very high level of expectancy that if they received an allright signal the departure signal would be displaying a proceed indication.
Based on the available information, QR did not effectively identify and assess the risk associated with this hazard during the introduction of the NGR, or when it changed the allright signal process in January 2019. Undoubtedly, identifying and assessing risks associated with a change is easier in hindsight during a safety investigation than when the change is occurring. Nevertheless, there were several limitations with processes during the introduction of the NGR BOM and the change to dispatch procedures in January 2019 that reduced QR’s ability to identify and assess the risk. These included:
Although QR conducted a detailed risk assessment to compare 2 NGR BOMs in mid-2016, the team participating in this assessment did not include personnel with subject matter expertise in train operations (such as train operations inspectors, tutor drivers or tutor guards). This limited expertise would have reduced the team’s appreciation of how allright signals were provided at CBD stations and other designated locations, and reduced the potential for them to identify the use of the allright signal at suburban station platforms as a start against signal risk. Accordingly, there were no treatments recorded to specifically manage this risk.
No formal risk assessment or change management process was conducted when the dispatch process at suburban platforms for NGR services was modified in January 2019. QR advised that this was because the change was considered minor in nature. It is understandable that personnel may have perceived that the change was actually helping to improve the clarity of communications between station staff and guards and therefore was reducing risk rather than increasing risk. Nonetheless, any changes to tasks or processes can have unintended consequences, particularly if the full context of the task has not been considered. In this case, the change affected how a large number of train dispatch movements at station platforms would be managed, and a more formal evaluation of the risk would have been justifiable.
Important operational notices (IONs) were issued to train crew at several stages throughout the introduction of the NGR, including before the change to dispatch procedures in January 2019. Although TSD’s procedures required that a risk assessment be done ‘when required’ to establish whether the type of communication was appropriate, no formal assessments were conducted, removing another opportunity to evaluate the situation using a structured approach.
Although a significant number of SAIs were installed or moved prior to the introduction of the NGR, as far as could be determined the changes at each station were managed as individual projects. There was no apparent consideration of the overall risk of the significant number of SAI changes on the ability of guards to effectively locate all the SAIs.
No additional incident or event reporting requirements were introduced with the implementation of the NGR fleet. With any major project, it is foreseeable that the introduction of new systems or processes will present unanticipated risks. Accordingly, it is important for there to be processes in place to gather safety information after the change has commenced. More specifically, the introduction of the NGR presented an opportunity for QR to proactively promote its incident reporting systems at a targeted audience to capture safety information that may not have been identified through other activities. For example, there could have been a formal campaign to promote the reporting of any safety-related events associated with the introduction of the NGR, or it could have been more targeted towards specific types of events. It is likely that this approach would have provided QR with information about a significant increase in the number of false rightaways being provided by guards on NGR trains prior to any (or most) of the 6 start against signal SPADs.
No assurance activities were planned to review SPAD risk or station dispatch procedures associated with the introduction of the NGR fleet. It is understandable that assurance activities need to be planned based on the level of expected risk, but as already noted there is also a need to ensure that unanticipated risks are not present following a change. An integral part of risk management with the introduction of a new system is to continually monitor and review the system’s integrity through the conduct of various assurance activities, such as audits, systematic observations or surveys of involved personnel.
In summary, there were limitations in QR’s application of risk management and change management processes relevant to the introduction of the NGR, which created a vulnerability that increased the risk of a start against signal SPAD. Specifically, multiple processes did not effectively consider the risk of station staff at suburban platforms providing the allright signal for all NGR trains even when the platform departure signal displayed a stop indication, which was in contrast to how allright signals were being applied in practice for all trains at the 3 CBD stations and 2 other designated stations.
Overall, if QR had developed a greater appreciation of the risk associated with increased false rightaways, they could have introduced additional mitigators, particularly prior to the January 2019 change to dispatch procedures. This could have included more extensive communications to guards and drivers, more active monitoring of rightaways (and reporting of false rightaways), and potentially further review of the positioning or salience of SAIs.
Ultimately, it is worth noting that the start against signal SPAD rate on NGR trains decreased within 18 months of the procedure change. This was probably associated with guards becoming more familiar with the differences between allright signal processes at suburban stations compared to the designated stations, guards becoming more familiar with the location of SAIs, and/or drivers becoming more familiar with the increased risk of false rightaways.
Overall, this change process has demonstrated important lessons for all operators about understanding the undocumented or informal risk controls that are in place, and how exactly operational personnel are applying procedures, prior to introducing changes. It has also demonstrated the importance of applying a formal change management process to assess the potential risk of procedural changes before determining that a change is minor in nature.
Application of the maintenance of competency process
Both the driver and guard had undertaken regular maintenance of competency (MOC) assessments, at least every 18 months, in the period leading up to the 25 March 2019. However, irregularities were found with the recent assessments conducted for both the driver and the guard.
In the case of the driver, answers to questions requiring a detailed response matched very closely to answers from the assessor’s marking guide. In addition, no problems were noted with the driver’s performance during practical MOC assessments in 2016 and 2018. However, following the 25 March 2019 SPAD, QR found the driver not competent on 14 occasions while participating in their post-SPAD coaching and mentoring sessions.
Similar, the guard was identified to have language and literacy difficulties in October 2018, which required special assistance in order for them to complete the written MOC assessments. However, there was no record that any special assistance or reasonable adjustment was provided on previous MOC assessments or a subsequent assessment conducted later in the same month, and there was no indication that the guard had any difficulty in completing the written assessments.
Overall, such irregularities were similar to those identified with MOC assessments during a previous ATSB investigation (RO-2018-002), which determined that QR’s administration of the MOC assessment process provided limited assurance that drivers met relevant competency requirements. As outlined in the previous investigation report, QR has taken and is taking steps to address this issue.
As noted in the previous investigation, the ATSB is not suggesting that QR’s Citytrain drivers and guards were not competent; rather, the application of the process for assessing competency had significant limitations in assuring their competency. It is very likely that most of the Citytrain drivers and guards possessed the skills, knowledge and aptitude to demonstrate competency at the time the assessments were conducted.
In this case, with regard to the specific actions of the driver involved in the 25 March SPAD, they knew the requirements of the stopped at a red, start on yellow and other relevant procedures involved in this SPAD. Similarly, the guard knew the requirements of the rightaway procedure. Accordingly, the available evidence indicates that the limitations identified with the application of the MOC process for the driver and guard did not directly contribute to this particular SPAD occurrence.
Train crew fatigue
Both the driver and guard of DW17 commenced duty on the day of the SPAD at 0412. Such early starts are problematic because people generally go to bed at (or cannot get to sleep until) their normal bedtime and they get less than their normal amount of sleep (Tucker and Folkard 2012). Research has shown that early morning shifts are associated with elevated levels of fatigue risk and higher self-ratings of fatigue compared to day shifts (Sallinen and Hublin 2015). Some researchers have stated early shifts be limited to a maximum of 3 in a row (Tucker and Folkard 2012) whereas others have recommended that rosters with several consecutive early morning starts be avoided where possible (Roach and others 2011).
Most people need at least 7–8 hours of sleep each day to achieve optimum levels of alertness and performance (Watson and others 2015), and research has shown that obtaining less than 5 hours sleep in the previous 24 hours is associated with significant performance decrements (Dawson and McCulloch 2005, Dawson and others 2021), with some research noting that 5–6 hours’ sleep in the previous 24 hours is problematic (Dawson and others 2021, Williamson and others 2011).
In the case of DW17, the driver reported having 6 hours sleep during the night before the SPAD. They had also been on duty for just over 8 hours, slightly longer than the maximum recommended by QR’s rostering guidelines for a shift commencing before 0500. However, given the time of the SPAD (1216), the time the driver had been awake (about 9 hours) and the fact that they had 2 rest breaks during their shift, there was insufficient evidence to conclude that the driver was experiencing a level of fatigue that has been demonstrated to adversely influence performance.
The guard was working the same shift as the driver, however they probably had 3.0–3.5 hours’ sleep during the night before the incident. Irrespective of other factors, this amount of sleep within the previous 24 hours, and the fact that little if any of this sleep would have occurred in the guard’s circadian low, was sufficient evidence to conclude that the guard was probably experiencing a level of fatigue that has been demonstrated to adversely influence performance.
The extent to which the guard’s level of fatigue contributed to them providing a false rightaway signal is difficult to determine. As previously discussed, such errors are commonly associated with high levels of expectancy such that, after receiving the allright signal, the rightaway signal can be provided. There was no specific evidence available to indicate that such errors are commonly associated with fatigue.
Management of roster changes
The guard’s restricted sleep the previous night was associated with a late-notice change to their roster. The guard was originally scheduled to commence duty at 0900, but they were asked if they could commence at 0412.
For a suburban passenger rail transport operator, there is a constant requirement to operate trains 7 days a week and most hours of the day. Rail transport operators will always have a need to manage changes to rosters, and on some occasions, there will be limited time available to organise these changes. However, it is still important that any such changes be managed in a way that minimises fatigue risk.
In the case of QR’s Citytrain train crew, there appeared to be 3 main requirements to be met prior to a driver or guard being offered a shift change to modify their day-of-operations roster:
The resulting shift(s) complied with the mandatory hours-of work-principles (such as maximum shift length of 9 hours and minimum break between shifts of 12 hours).
The resulting shift(s) had a FAID score that did not exceed 100.
The driver or guard did not report that they were feeling fatigued when they accepted the revised shift(s) or prior to commencing the shift(s).
Although important and useful, rosters complying with the hours-of-work principles could still present an elevated risk of fatigue. In addition, depending on the roster pattern, FAID scores less than 100 can be associated with significant levels of fatigue. The Independent Transport Safety Regulator (2010) stated ‘a FAID score of less than 80 does not mean that a work schedule is acceptable or that a person is not impaired at a level that could affect safety’, and the US Federal Railroad Administration (2010) concluded that in some cases FAID scores between 70 and 80 can be associated with ‘extreme fatigue’.
Although a biomathematical model of fatigue (BMMF) score can provide a relative indication of a roster’s potential to provide adequate sleep opportunity (Dawson and others 2011), such models have many limitations and other processes need to be in place to help ensure an adequate sleep opportunity is actually provided. There are many types of roster changes that will result in restricted sleep opportunities that will not result in a FAID score that is problematic or significantly elevated. As noted by Gander and others (2011):
The current generation of bio-mathematical models cannot be used in real time, for example to estimate workers fatigue levels when reviewing roster swaps or deciding which staff will be less fatigued when being asked to carry out overtime…
In terms of self assessments, research indicates that people will generally underestimate their level of fatigue (Battelle Memorial Institute 1998), including underestimating the impact of several days of sleep restriction (Banks and Dinges 2007). Some research has also shown that people overestimate the amount of sleep they obtain (Lauderdale and others 2008, Jackson and others 2018). In addition, most rail transport operators have financial incentives in place for train crew if they accept changes or extensions to their planned shift or accept an additional shift. Concerns about self-reporting fatigue are also commonly perceived amongst train crew in the rail industry (for example, Fitness and Naweed 2017).
In the case of the guard of DW17, the revised start time for the guard’s shift met the hours-of-work principles because the guard had the previous 2 days off duty. In addition, because of the 2 days off duty, the guard’s FAID score was relatively low (40) and would have stayed well below a score of 100 (and even a score of 80) regardless of the start time.
Nevertheless, given the late-notice roster change, the guard did not have sufficient sleep opportunity prior to commencing their shift. The rostering personnel were asking the guard after 2200 the night before to undertake a shift at 0412, a situation that would almost certainly have resulted in the guard having a restricted sleep opportunity (and at most 4 hours of sleep before commencing duty). This problem was not able to be captured by either the FAID score or the hours-of-work principles.
To cope with the variable start times common in the rail industry, personnel may adjust their sleep patterns to some extent based on an expected roster. It is quite reasonable that the guard, expecting to start work at 0900, would stay up until after 2200. If they were aware, they would be commencing work at 0412, they may have attempted to go to sleep earlier or had a nap in the afternoon (although such actions may not be successful).
In such situations, with late-notice changes resulting in elevated fatigue risk, there is obvious merit for a rail operator to more actively seek assurance that personnel have obtained sufficient sleep prior to accepting the roster change and/or prior to commencing duty. The application of other mitigators, such as limiting the length of the shift, should also be considered. Passively assuming that personnel have conducted an accurate self assessment of their fatigue or alertness level in such situations does not provide assurance that the risk associated with the late-notice change has been adequately managed.
The ATSB investigation also noted that the driver had undertaken 3 additional shifts (to those originally rostered) during the period from 15–18 March 2019, conducted a series of 6 early start (starting between 0400–0600) or very early start (starting between 0300–0359) shifts in a row between 18–23 March, and had a FAID score exceeding 80 in the last 2 of these shifts. This sequence of shifts included several deviations from the operator’s rostering guidelines. In such situations, there would also be considerable merit in a more active approach to ensuring that the driver was assessed as being fit for duty prior to the last 2 shifts rather than passively relying on self assessments.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the signal passed at danger (SPAD) involving suburban passenger train DW17 and the near collision with another passenger train at Park Road Station on 25 March 2019.
Contributing factors
After train DW17 stopped at Park Road Station, with the departure signal (DP29) displaying a red aspect, the driver did not apply the operator's ‘stopped at a red’ procedure.
After receiving the 'allright' signal indicating station duties were complete, the guard promptly provided the driver with the 'rightaway' signal, even though the platform departure signal (DP29) was displaying a red aspect (stop) indication. This was probably associated with the guard having a very high level of expectancy that the allright signal indicated the departure signal was at proceed.
After receiving the ‘rightaway’ signal from the guard, the driver promptly departed the station platform without effectively checking and confirming the aspect indication in the departure signal (DP29). This was probably associated with the driver having a very high level of expectancy that the rightaway signal indicated that the departure signal was at proceed.
Limitations in Queensland Rail’s application of risk management and change management processes relevant to the introduction of the new generation rollingstock (NGR) increased the risk of a start against signal SPAD (signals passed at danger). Specifically, multiple processes did not effectively consider the risk of station staff at suburban platforms providing the allright signal for all NGR trains even when the platform departure signal displayed a stop indication, which was in contrast to how allright signals were being provided in practice for all trains at the 3 central business district stations and 2 other designated stations. [Safety issue]
Other factors that increased risk
The maintenance of competency (MOC) assessments undertaken on the driver prior to the signal passed at danger (SPAD) occurrence on 25 March 2019 did not provide assurance that the driver met all relevant competency requirements, including competencies associated with minimising the risk of a SPAD. Anomalies were also identified with the MOC assessments undertaken on the guard.
Queensland Rail's process for the installation of signal aspect indicators (SAIs) did not provide sufficient detail to ensure consistent and conspicuous placement of SAIs at station platforms. This problem, combined with an SAI’s non-salient indication when the platform departure signal displayed a stop indication, increased the risk that an SAI would not be correctly perceived by a train guard. [Safety issue]
Due to a late-notice roster change and limited sleep the night before the occurrence, the train guard was probably experiencing a level of fatigue known to adversely influence performance.
Queensland Rail’s fatigue management processes for Citytrain train crew had limited processes in place to actively identify and manage the risk of restricted sleep opportunity resulting from late-notice roster changes. [Safety issue]
Other findings
The tutor driver on 1E65 identified the potential collision risk and took prompt action to stop that train prior to the potential collision point with DW17. In addition, after the universal traffic control system generated a SPAD alarm, the network control officer promptly transmitted an emergency stop command to the driver of DW17 and the crew of 1E65 to stop their trains.
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.
Risk management associated with changing allright signal procedures for the NGR
Safety issue description: Limitations in Queensland Rail’s application of risk management and change management processes relevant to the introduction of the new generation rollingstock (NGR) increased the risk of a start against signal SPAD (signals passed at danger). Specifically, multiple processes did not effectively consider the risk of station staff at suburban platforms providing the allright signal for all NGR trains even when the platform departure signal displayed a stop indication, which was in contrast to how allright signals were being provided in practice for all trains at the 3 central business district stations and 2 other designated stations.
Placement of signal aspect indicators at station platforms
Safety issue description: Queensland Rail's process for the installation of signal aspect indicators (SAIs) did not provide sufficient detail to ensure consistent and conspicuous placement of SAIs at station platforms. This problem, combined with an SAI’s non-salient indication when the platform departure signal displayed a stop indication, increased the risk that an SAI would not be correctly perceived by a train guard.
Safety issue description: Queensland Rail’s fatigue management processes for Citytrain train crew had limited processes in place to actively identify and manage the risk of restricted sleep opportunity resulting from late-notice roster changes.
Safety action not associated with an identified safety issue
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Additional safety action Queensland Rail
The Queensland Rail (QR) internal safety investigation report into the 25 March 2019 SPAD occurrence at signal DP29 noted the following safety actions:
- Train Service Delivery has actioned an Operational Improvement Plan for the Rail Traffic Driver - Train Service Delivery has actioned a Performance Management Plan for the Rail Traffic Guard - Published a lessons learned from the investigation produced by the Investigation Team into the SPAD at DP29 to all Rail Traffic Crew - Assurance team to undertake a 2nd Line Assurance activity to determine Rail Traffic Guard Compliance with Procedure MD-12-38 Rail Traffic Crew Manual (Version 5.0) AEQ 14 Rightaway Procedures – SEQ.
In 2020, QR completed the second line assurance activity. The findings from the investigation were included in the ATSB report (see Monitor and review). Following the assurance activity, an operational notice was sent to train crew regarding compliance with the rightaway procedure.
Glossary
AWS Automatic warning system
BMMF Biomathematical model of fatigue
BOM Business operating model
CBD Central business district
COA Critical operational alert (a type of TSD communication to train crew)
EMU Electric multiple unit (a type of electric suburban train)
FAID Fatigue Audit InterDyne, subsequently named Fatigue Analysis Tool (a type of BMMF)
GOA General operational alert (a type of TSD communication to train crew)
ION Important operational notice (a type of TSD communication to train crew)
LED Light emitting diode
MOC Maintenance of competency
NCO Network control officer
NGR New generation rollingstock (a type of electric suburban train)
QR Queensland Rail
RTC Rail traffic crew
RTCD Risk triggered commentary driving
RTD Rail traffic driver
RTG Rail traffic guard
SAI Signal aspect indicator
SCS Station customer service (a section within QR Citytrain)
SMS Safety management system
SPAD Signal passed at danger
TSD Train services delivery (a section within QR Citytrain)
UTC Universal traffic control (system used by train control)
Sources and submissions
Sources of information
The sources of information during the investigation included:
Queensland Rail
the driver and guard of DW17
the train crew of IE65
other Queensland Rail personnel
event recorders from trains DW17 and 1E65
closed-circuit television from trains DW17, 1E65 and from the station platform at Park Road Station.
References
Banks S and Dinges DF (2007), ‘Behavioral and physiological consequences of sleep restriction’, Journal of Clinical Sleep Medicine, 3:519–528.
Basacik D, Read C, Heavisides J, Jones M and Pollard G (2008) A review of passenger train dispatch from stations, Rail Safety and Standards Board, UK, research report T743.
Battelle Memorial Institute (1998) An overview of the scientific literature concerning fatigue, sleep, and the circadian cycle, Report prepared for the Office of the Chief Scientific and Technical Advisor for Human Factors, United States Federal Aviation Administration.
Civil Aviation Safety Authority (2014) Biomathematical fatigue models. Available from www.casa.gov.au.
Dawson D and McCulloch K (2005) ‘Managing fatigue: It’s about sleep’, Sleep Medicine Reviews, 9:365–380.
Dawson D, Noy YI, Härmäc M, Åkerstedtd T and Belenkye G (2011) ‘Modelling fatigue and the use of fatigue models in work settings’, Accident Analysis and Prevention, 43:549–564.
Dawson D, Sprajcer M and Thomas M (2021) ‘How much sleep do you need? A comprehensive review of fatigue related impairment and the capacity to work or drive safely’, Accident Analysis and Prevention, 151:105955.
Federal Railroad Administration (2010) Procedures for Validation and Calibration of Human Fatigue Models: The Fatigue Audit InterDyne Tool, Department of Transportation Technical Report DOT/FRA/ORD-10/14.
Fitness AJ and Naweed A (2017) ‘Causes, consequences and countermeasures to driver fatigue in the rail industry: The train driver perspective’, Applied Ergonomics, 60:12–21.
Gander P, Hartley L, Powell D, Cabon P, Hitchccok E, Mills A and Poplin S (2011) ‘Fatigue risk management: Organizational factors at the regulatory and industry/company level’, Accident Analysis and Prevention, 43:573–590.
Gibson H (2016) Industry human factors SPAD review: Project summary report, Rail Safety and Standards Board, UK.
Haga S (1984) ‘An experimental study of signal vigilance errors in train driving’, Ergonomics, 27:755-765.
Independent Transport Safety Regulator (2010) Transport Safety Alert 34 - Use of biomathematical models in managing risks of human fatigue in the workplace.
Jackson CL, Patel SR, Jackson WB 2nd, Lutsey PL, and Redline S (2018) ‘Agreement between self-reported and objectively measured sleep duration among white, black, Hispanic, and Chinese adults in the United States: Multi-Ethnic Study of Atherosclerosis’, Sleep, 41(6).
Lauderdale DS, Knutson KL, Yan LL, Liu K, and Rathouz PJ (2008) ‘Self-reported and measured sleep duration: how similar are they?’, Epidemiology, 19:838–845.
Multer J, Safar H, Roth E and France M (2019) Why do passenger trains pass stop signals? A systems view, Federal Railroad Administration, Department of Transportation Technical Report DOT/FRA/ORD-19/19.
Naweed A (2013) ‘Psychological factors for driver distraction and inattention in the Australian and New Zealand rail industry’, Accident Analysis and Prevention, 60:193–204.
Naweed A, Rainbird S and Chapman J (2015) ‘Investigating the formal countermeasures and informal strategies used to mitigate SPAD risk in train driving’, Ergonomics, 58:883–896.
Roach GD, Fletcher A and Dawson D (2004) ‘A model to predict work -related fatigue based on hours of work’, Aviation, Space, and Environmental Medicine, 75:61-69.
Roach GD, Sargent S, Darwent D and Dawson D (2012) ‘Duty periods with early start times restrict the amount of sleep obtained by short-haul pilots’, Accident Analysis and Prevention, 45S:22–26.
Sallinen M and Hublin C (2015) ‘Fatigue-inducing factors in transportation operators’, Reviews of Human Factors and Ergonomics, 10:138–173.
Tucker P and Folkard S (2012) Working time, health and safety: A research synthesis paper, Background Report to the International Labour Office for the ILO Tripartite Meeting of Experts on Working time Arrangements, Geneva: International Labour Office.
Watson NF, Badr MS, Belenky G, Bliwise DL, Buxton OM, Buysse D, Dinges DF, Gangwisch J, Grandner MA, Kushida C, Malhotra RK, Martin JL, Patel SR, Quan SF and Tasali E (2015) ‘Recommended amount of sleep for a healthy adult: A joint consensus statement of the American Academy of Sleep Medicine and Sleep Research Society’, Sleep, 38:843-844.
Wickens CD, Hollands JG, Banbury S and Parasuraman R (2013) Engineering psychology and human performance, 4th edition, Pearson Boston, MA.
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
the driver and guard of DW17
Queensland Rail
the Office of the National Rail Safety Regulator (ONRSR).
Submissions were received from Queensland Rail and ONRSR. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.