Aircraft preparation occurrence involving BAe 146-300, VH-NJZ, Sydney Airport, New South Wales, on 22 January 2019

Final report

Report release date: 23/06/2020

Safety summary

What happened

On the morning of 22 January 2019, a British Aerospace (BAe) 146-300, registered VH-NJZ, landed in Sydney, New South Wales, en route from Melbourne, Victoria, to Brisbane, Queensland on a scheduled freight operation.

Before commencing the cargo-unloading process, a tail strut was attached to the rear of the aircraft. After completion of the cargo-unloading and loading process, the aircraft was taxied for departure to Brisbane with the tail strut still attached. During the take-off roll, the tail strut detached, resulting in the runway being contaminated with foreign object debris.

The complete tail strut was recovered from the runway and the aircraft continued to Brisbane, where it landed without further incident.

What the ATSB found

The ATSB found that pre-departure checklist items, required to be performed by the captain and engineer in a challenge-and-response manner, were not completed. This negated the value of the checklist as a risk control, and resulted in a missed opportunity to detect the tail strut’s presence prior to departure.

The ATSB also found that the engineer performing the aircraft turn-around had no effective means or procedure to contact the aircraft while it was taxiing. As a result, and despite attempting various methods, the engineer was unable to alert the flight crew that the tail strut was still attached to the aircraft.

What's been done as a result

Following the occurrence, the operator disseminated Safety Alerts to relevant staff highlighting the despatch procedure, including the challenge-and-response requirement for the relevant cockpit to ground checklist.

The operator also provided appropriate control tower telephone numbers to engineering staff at all operating bases, allowing them to contact the tower immediately if required.

Finally, the operator emailed all company pilots, further highlighting the despatch procedure. This included the requirement that when the aircraft’s tail strut was not used, the local ground support equipment tail strut was to be visible to the flight crew prior to aircraft despatch.

Safety message

Checklists are an essential tool for overcoming limitations with memory, and ensuring that action items are completed in sequence and without omission. While their value may not be obvious for routinely performed tasks, the incomplete use of checklists has been cited as a factor in previous aircraft accidents.

 

The occurrence

What happened

On 22 January 2019, a British Aerospace 146-300, registered VH-NJZ (NJZ), was being operated by National Jet Express on a scheduled freight service between Melbourne, Victoria and Brisbane, Queensland via Sydney, New South Wales. At about 0415 Eastern Daylight-saving Time,[1] NJZ landed in Sydney and exited the runway for freight-loading operations.

A licenced aircraft maintenance engineer employed by Cobham Aviation Services reported marshalling NJZ in, and the flight crew subsequently shut down the aircraft’s engines. The engineer placed chocks at the nose wheels and instructed the flight crew to release the parking brake. The engineer positioned boarding stairs at the forward left cabin door and attached a tail strut[2] to the rear of the aircraft (Figure 1). The tail strut was part of the Sydney Airport ground support equipment. The engineer also had the option of using a tail strut that was carried on board the aircraft.

The engineer reported opening the aft lower cargo hold door, on the rear right side of the aircraft to retrieve the sill protectors.[3] The engineer waited for the aircraft freight door to be opened remotely by the captain, installed the sill protectors, and conducted an external visual inspection of NJZ. After the inspection, the engineer engaged in a brief conversation with the flight crew, and returned to the line hut to await completion of loading by the loading team.

The captain reported completing an external visual inspection of the aircraft then returned to the cockpit to plan the next sector to Brisbane with the first officer. Upon completion of loading by the loading team, the captain positioned himself at the top of the boarding stairs and the engineer returned to the aircraft. The engineer removed the freight door sill protectors and signalled the captain to commence lowering the freight door. After the freight door was closed, the engineer visually checked that it was flush with the aircraft skin and that the locks had correctly engaged. The engineer then signalled the captain that the freight door had locked correctly. The captain replied with a thumbs-up, entered the aircraft and closed the cabin door behind him.

The engineer proceeded to the aft lower cargo hold door on the right side of the aircraft, stowed the sill protectors, closed and locked the cargo hold door. The engineer then walked back around towards the front of the aircraft and positioned the boarding stairs clear. The engineer connected a headset to the nose of the aircraft for communications with the flight crew and removed chocks from the nose landing gear wheels. The engineer then took up a position at the nose of the aircraft to commence communications with the flight crew for engine start.

The captain confirmed communications with the engineer, and the engineer responded ‘stowed and closed, you are clear all four’. The flight crew proceeded to start all four engines. After the engines were all started successfully, the engineer disconnected the headset, closed the communications panel, and proceeded into the line hut to put away the headset and torch. At 0451, NJZ taxied forward out of the bay and then toward holding point Golf for take-off on runway 16R.[4]

Figure 1: Example of a tail strut fitted to NJZ and showing opened freight door

Figure 1: Example of a tail strut fitted to NJZ and showing opened freight door.
Source: Cobham Aviation Services Australia

Source: Cobham Aviation Services Australia

At that time, a ground staff member from a different company arrived at the line hut on a tug and informed the engineer that NJZ had commenced taxiing with the tail strut still in place. Leaving the line hut, the engineer proceeded outside and saw that NJZ had commenced taxiing towards the runway. The engineer began pursuing the aircraft on foot, and attempted to attract the captain’s attention by waving his arms and shouting. The engineer, realising he wouldn’t be able to get the pilots’ attention, joined the ground staff member on the tug and proceeded after NJZ.

The engineer did not have a contact number for the Sydney Control Tower and was therefore unable to inform them of the situation quickly. Instead, he telephoned National Jet Express Maintenance Watch[5] and asked them to contact the flight crew to inform them of the situation. National Jet Express Maintenance Watch relayed the message to National Jet Express Operations,[6] who in turn attempted unsuccessfully to contact both pilots by mobile phone.

The engineer, realising that he was not going to catch NJZ prior to it entering the runway, approached a nearby works safety officer. As the engineer was asking the safety officer to immediately contact the tower via radio, to prevent NJZ from taking off, the aircraft turned onto runway 16R, powered up and departed.

The captain reported that during the take-off roll, he felt his phone vibrating in his pocket but did not answer as he was concentrating on the departure.

Following the aircraft’s departure, Sydney Tower closed Taxiway Bravo and runway 16R to allow a visual inspection to take place. A Sydney Airport ground safety worker subsequently located the tail strut, took photographs, and recovered the multiple components (Figure 2). The photographs of the recovered tail strut components were sent to the engineer’s mobile phone and the engineer confirmed that the entirety of the tail strut had been recovered. The engineer relayed this information to National Jet Express Maintenance Watch, who passed it on to the captain. The captain, satisfied that the entire tail strut had departed the aircraft, continued the flight to Brisbane.

On arrival at Brisbane, air traffic control requested that NJZ land on a secondary runway in case there was any residual part of the tail strut still attached to the aircraft. The aircraft landed and stopped on the runway without incident, and the rear of the aircraft was inspected by a Brisbane Airport ground safety officer. NJZ was then permitted to taxi to its bay. Engineers subsequently inspected the rear of the aircraft and no damage was evident.

Figure 2: Tail strut as found on Sydney runway 16R post NJZ departure

Figure 2: Tail strut as found on Sydney runway 16R post NJZ departure.
Source: Sydney Airport

Source: Sydney Airport

Operator despatch procedure

The operator’s Bae146 Aircraft Ground Operations manual detailed the cockpit to ground communication requirement as listed in Table 1.

Table 1: Stand-Off Bay Despatch Using Intercom Checklist

CaptainGround Crew
“Cockpit to Ground”“Ground”
“Confirm all doors and access panels closed and locked, (and where applicable) tail strut removed and sill protectors stowed”“All doors and panels closed and locked, (and where applicable) tail strut removed and sill protectors stowed”
“Brakes parked, clear to remove chocks”“Chocks removed”
“Ready to start all engines or Engines 3 & 4, 1 & 2 “ as appropriate”“Clear to start” as appropriate
“Start completed clear to disconnect”“Disconnecting”

The engineer stated that during the turnaround of NJZ, prior to stowing the sill protectors, he walked past the tail strut and did not remove it. The captain and engineer commenced the required checklist prior to engine start. During this verbal exchange the challenge-and-response checklist was shortened to ‘We are stowed and closed you are clear for all four’. Immediately after the engineer disconnected communications from the aircraft the engineer proceeded into the line hut. He reported that this did not allow him an opportunity to view the tail strut as the aircraft taxied past.

Safety analysis

During pre-departure checks, the verbal exchange between the captain and engineer was not performed in accordance with the Stand‑Off Bay Despatch Using Intercom challenge-and-response checklist. While that was possibly the result of it being a routinely performed task, it negated the value of the checklist as a risk control, and presented a missed opportunity to detect the tail strut prior to departure.

The engineer had no effective means or procedure to contact the aircraft while it was taxiing. Despite that, he attempted various methods to contact the flight crew but was unable to alert them to the tail strut still being attached to the aircraft prior to take‑off.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • During pre-departure checks, the full checklist between the captain and engineer was not completed. This negated the value of the checklist as a risk control and resulted in a missed opportunity to identify that the tail strut was still attached to the aircraft prior to it departing the bay.
  • The engineer had no effective means or procedure to contact the flight crew while the aircraft was taxiing. As a result, the flight crew were not alerted to the error prior to take‑off.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Following this occurrence, on 23 January 2019, Cobham Aviation Services issued a Safety Alert to relevant staff that highlighted the despatch procedure including the cockpit to ground checklist requirements.

Cobham also provided appropriate control tower telephone numbers to engineering staff at all operating bases. This allows staff to immediately contact the tower if a need arises.

Cobham also emailed all company pilots, further highlighting the despatch procedure. This included the requirement that when the aircraft’s tail strut was not used, the local ground support equipment tail strut was to be visible to the flight crew prior to aircraft despatch.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. A tail strut supports the rear of an aircraft while cargo is loaded and unloaded.
  3. The sill protectors are metal guards to protect the sill of the freight door area from damage during loading and unloading.
  4. Runway name: the number represents the magnetic heading of the runway. The letter designates the qualifier for multiple runways (left/right) if necessary.
  5. National Jet Express Maintenance Watch is an internal company department that provides engineering advice to the operating fleet.
  6. National Jet Express Operations is an internal company department that monitors the operating fleet.

Occurrence summary

Investigation number AO-2019-006
Occurrence date 22/01/2019
Location Sydney Airport
State New South Wales
Report release date 23/06/2020
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Aircraft preparation
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer British Aerospace
Model BAe 146-300
Registration VH-NJZ
Serial number E3126
Aircraft operator National Jet Express
Sector Jet
Operation type Air Transport High Capacity
Departure point Sydney Airport, New South Wales
Destination Brisbane Airport, Queensland
Damage Nil

Loss of control and collision with terrain involving EC130 helicopter, VH-YHS, 19 km south-south-east of Mansfield, Victoria, on 19 January 2019

Final report

Report release date: 29/05/2020

Safety summary

What happened

On the morning of 19 January 2019, a Eurocopter EC130 helicopter, registered VH-YHS, conducted a private flight from Moorabbin Airport to an authorised landing area (ALA) near Mansfield, Victoria with the pilot and two passengers on board. A return flight to Moorabbin was planned for later that afternoon.

At about 1500 (Australian Eastern Daylight Time - AEDT), the pilot and passengers boarded the helicopter at the ALA for the return flight. The pilot prepared for take-off and lifted off the helicopter more rapidly than he normally did. As the helicopter became airborne, it began to rotate counter-clockwise (yaw to the left). The pilot tried to control the yaw but the helicopter quickly turned through 360° and, unable to control it, he made a decision to land the helicopter.

The left skid of the descending helicopter subsequently contacted the ground, resulting in a rolling movement that led to the main rotor blades striking the ground. The collision destroyed the aircraft, the pilot sustained minor injuries however the passengers were uninjured.

What the ATSB found

The investigation did not identify any airworthiness issues with the helicopter and it was considered that the loss of control was not attributable to a mechanical issue. It was also determined that the prevailing light winds did not contribute to the loss of control.

The pilot reported that he did not lift the helicopter into a balanced hover, and tried controlling its yaw mainly with the cyclic control instead of through the full application of opposing right, tail rotor pedal. Management of unanticipated yaw in helicopters with shrouded tail rotors (Fenestron) is the subject of the manufacturer’s guidance and learnings from similar accidents.

Safety message

This accident demonstrates the criticality of helicopter pilots understanding the aircraft’s characteristics so that they can anticipate its response when becoming airborne, and are not surprised by events. Controlling yaw in helicopters with a Fenestron tail rotor, as in this case, is an important consideration. Airbus Helicopters and the European Union Aviation Safety Agency (EASA) provide specific guidance relating to this issue to assist pilots.

 

The occurrence

What happened

At 1033 Eastern Daylight‑saving Time[1] on 19 January 2019, a Eurocopter EC130 helicopter, registered VH-YHS (YHS), departed Moorabbin Airport for a private authorised landing area (ALA), 19 km south-south‑east of Mansfield, Victoria. The pilot and two passengers were on board for the private flight to a rural property and intended to conduct a return flight that afternoon. The pilot’s pre-flight inspection had not identified any defects or outstanding maintenance issues for the helicopter.

At 1115, after an uneventful flight, YHS landed at the rural property. Over the next few hours, the pilot attended to various matters there as planned, and had lunch with the passengers.

Shortly before 1500, the pilot and passengers returned to the helicopter. The helicopter was parked in an open area, facing south with a 0.5 m-high earth mound to its left (Figure 1). The mound prevented water entering the nearby shed and ran the length of the area, which had clusters of trees around it in different directions. The pilot had undertaken five previous flights to the property in the helicopter in the previous 5 months.

After assisting the passengers to board the helicopter, the pilot conducted a walk-around and did not identify anything unusual. He then boarded and, following a normal engine start, carried out his take-off checks. As was his usual practice, he set the friction settings for both the cyclic[2] and collective[3] controls to minimum resistance.[4] The wind was about 10 kt from the south-west (about 45° to the right of the helicopter), the sky was clear and it was approximately 30º C.

As the pilot increased to full power for take-off, he observed that the front right passenger had not put on her headset and signalled for her to do so. While he waited for her to put the headset on, keeping YHS on the ground, he noticed the cabin temperature was 32 ºC and turned on the air‑conditioning.

Shortly after 1500, the pilot was again ready to take-off. He raised the helicopter off the ground, more rapidly than he normally did without getting the usual ‘fine balance’[5]. At a height of about 3 m above the ground, the helicopter began to yaw to the left (turning counter-clockwise), seemingly pivoting about the tail and its attitude became progressively unstable (Figure 1, Top).

The pilot applied inputs, mainly cyclic, to control the helicopter’s movement but the yaw increased. The aircraft now seemed to be pivoting about the main rotor, moving closer to the trees and shed (Figure 1, Middle). The pilot recalled that the helicopter felt ‘unstable’ and moved the cyclic but did not get the response he expected. In seconds, the helicopter had turned through 360° (Figure 1, Bottom). Unable to control the helicopter, the pilot decided to land and lowered the collective.

As the helicopter descended, its left skid contacted the mound, resulting in the helicopter pivoting around that skid and the main rotor blades striking the ground. The helicopter came to rest on its left side, facing the shed (Figure 2). The sequence, from lift-off to ground contact, occurred over about 5 seconds.

The pilot turned off the engine and battery, exited through the shattered left windscreen and assisted the passengers from the helicopter. The pilot sustained minor injuries while the passengers were uninjured.

Figure 1: Accident sequence

Figure 1a: Accident sequence.
Source: ATSB analysis of information from pilot and witness video (partial) superimposed on Google Earth image
Figure 1b: Accident sequence
Figure 1c: Accident sequence

Source: ATSB analysis of information from pilot and witness video (partial) superimposed on Google Earth image

Figure 2: Accident site

Figure 2: Accident site

Source: Seven News Melbourne, annotated by ATSB

Pilot

The pilot completed his helicopter flight training in a Hughes 300 helicopter in 2010. He completed EC130 type training in November 2011 and had accumulated 227 flight hours in that aircraft (from a total of 315 flight hours). Since his last flight review in November 2017, he had flown YHS for 13.5 hours of which 4 hours had been in the 90 days preceding the accident – the last flight being 46 days prior.

The pilot commented that he had:

  • not heard or seen anything unusual with the helicopter before the accident
  • tried controlling the yaw mainly with the cyclic, did not know how much right pedal he had used and assessed that he should have used more pedal to control yaw
  • not flown regularly since his last flight review and noted that during his EC130 type training he had needed more pedal input than in the Hughes 300.

Aircraft information

The EC130 is a single-turbine engine helicopter with a clockwise-turning main rotor and a shrouded Fenestron tail rotor (Figure 2). The helicopter has a maximum take-off weight of about 2,427 kg and can carry seven occupants. The EC130 is a high-performance helicopter compared to the Hughes 300 (in which the pilot first trained). The Hughes 300 has a counterclockwise turning main rotor and a conventional unshrouded tail rotor.

The EC130 with its Fenestron anti‑torque system[6] requires greater right pedal[7] input to overcome torque from the main rotor during lift off than a helicopter with a conventional tail rotor. The pedal control inputs are also not linear with respect to the effect on helicopter yaw.

The helicopter’s manufacturer (Airbus Helicopters) published service letter 1673-67-04 in February 2005 with guidance for managing yaw. The letter reminded pilots that the Fenestron anti‑torque system requires more right pedal travel than a conventional tail rotor to counter left rotation (yaw). The letter stated that if sufficient pedal is not applied quickly to correct yaw, its rate will increase. Further, insufficient pedal input to stop yaw combined with pilot input to decrease altitude could result in the helicopter rolling to the side and contacting the ground.

Post-accident activities

There was no recorded data to determine the flight control inputs and their effect on the motion of YHS during the accident. The pilot’s account, a partially obscured witness video, and photographs of the wreckage were the main sources of evidence.

The maintenance organisation for YHS carried out an examination at the accident site before moving the wreckage to its maintenance facility. This examination found no evidence of airworthiness issues that could have resulted in the accident. It was also determined that the helicopter was within its performance envelope and had sufficient fuel for the planned flight.

The ATSB sought the manufacturer’s input for this accident and was advised that as no technical (mechanical or control) issues with YHS had been identified by the maintenance organisation, the accident was probably the result of a handling error.

In July 2019, about 6 months after the accident, Airbus Helicopters published safety information notice 3297-S-00 to highlight unanticipated yaw. The notice warned that an unanticipated yaw can be rapid and is most often toward the left (where the main rotor rotates clockwise). It further noted that even if the pilot’s response was prompt, the yaw might not immediately subside and lead to the pilot thinking that the input was ineffective.

Similar accident

In October 2015, an EC130 helicopter was departing Megève altiport, France, for a sightseeing flight when the pilot lost control of the aircraft, which collided with the ground (BEA2015-0647 report). The helicopter was destroyed, and the seven occupants were injured.

The pilot had 300 flight hours in helicopters, including 9.5 hours in an EC130 and 74 in the similar AS350 helicopter. The investigation found that while stabilised in the hover, the pilot initiated a left turn to face the climb out direction. However, the pilot was unable to stop or slow the yaw and decided to land, lowering the collective. The helicopter yawed through several more revolutions before colliding with the ground. No technical issues to explain the accident were identified.

As part of the investigation, a flight in a helicopter of the same type in similar conditions was undertaken, and it was found that pushing the right pedal to 70 per cent of its travel stopped a yaw rate of 100° per second to the left in 3 seconds.

Safety analysis

The earlier flight made by VH-YHS (YHS) that day indicated the helicopter was operating normally with no defects. The high-performance helicopter was also operating well below its maximum capacity with only three occupants.

In preparing to take-off, the pilot lifted YHS more rapidly than he normally did without first letting it rest lightly on the skids and applying control inputs to lift it gently into a balanced, controlled hover for the climb out. The higher-than-normal application of control inputs resulted in the torque from the main rotor not being balanced by the anti-torque from the Fenestron tail rotor. Consequently, once the helicopter was off the ground it yawed significantly to the left. The wind from the right may also have initially increased the yaw rate.

The pilot’s pre-take-off checks did not confirm that everyone and everything was ready for the flight. As a result, he had to delay the take-off while a passenger put on her headset. He then noticed the elevated temperature and turned on the air-conditioning. These interruptions may have influenced his actions in lifting off more rapidly than he normally did.

The rate of left yaw offered limited time to regain control. The pilot reported that he principally applied cyclic control rather than the required full application and maintenance of opposing right, tail rotor pedal input. When his applied inputs did not arrest the yaw rate, the pilot assessed that the best option was to land the helicopter.

Similar accidents in the same or comparable helicopters, together with manufacturer’s guidance, provide information for pilots to manage unanticipated yaw and avoid accidents. These show that the outcome of YHS’s attempted landing with a significant yaw rate was somewhat predictable - a skid contacting the ground, the helicopter rolling over and the main rotor blades striking the ground. The rapid development of the accident sequence (about 5 seconds) also illustrates the limited time for pilot actions/decisions in such hazardous situations, which fortunately did not result in serious injury in this case.

The maintenance organisation’s examination found no evidence of airworthiness issues with YHS to explain the accident. The pilot’s account and the manufacturer’s comments also support a conclusion that a mechanical issue and the light wind did not contribute to the accident.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The pilot was unable to control VH-YHS yawing to the left after lifting off and decided to land. When the left skid of the descending helicopter contacted the ground, it rolled over and the main rotor blades struck the ground, destroying the aircraft with the pilot sustaining minor injury.
  • No mechanical issue with the helicopter was identified and the prevailing light wind did not contribute to the loss of control and subsequent collision.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Daylightsaving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. Cyclic: a primary helicopter flight control that is similar to an aircraft control column. Cyclic input tilts the main rotor disc, varying the attitude of the helicopter and hence the lateral direction.
  3. Collective: a primary helicopter flight control that simultaneously affects the pitch of all blades of a lifting rotor. Collective input is the main control for vertical velocity.
  4. The helicopter flight manual suggests adjusting flight control friction settings to the preferred resistance.
  5. The fine balance is a two-step lift-off where the pilot lifts the helicopter slightly to be light on the skids, while making control inputs to balance the helicopter, before gently lifting into the hover.
  6. The function of the helicopter tail rotor/Fenestron is to counteract the torque produced by the main rotor to maintain directional control.
  7. Pedals: a primary helicopter flight control. Left and right pedal input moves the helicopter in the corresponding direction to maintain control for directional flight (yaw).

Occurrence summary

Investigation number AO-2019-005
Occurrence date 19/01/2019
Location ALA 19 km south-south-east of Mansfield
State Victoria
Report release date 29/05/2020
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Eurocopter
Model EC130
Registration VH-YHS
Serial number 4080
Sector Helicopter
Operation type Private
Departure point Authorised landing area 19 km south-south-east of Mansfield, Victoria
Destination Moorabbin Airport, Victoria
Damage Substantial

Collision with terrain involving an Insitu ScanEagle X200 unmanned aircraft system (UAS), near Woleebee Creek, Queensland, on 9 January 2019

Final report

Report release date: 15/08/2019

Safety summary

What happened

At about 0825 Eastern Standard Time on 9 January 2019, an Insitu ScanEagle X200 (X200) unmanned aircraft system was launched to conduct ‘beyond visual line of sight’ aerial survey work in the Woleebee Creek area of Queensland. The flight crew consisted of two pilots and two ground crew.

Shortly after launch, one of the ground crew observed the X200 pitch up and then enter an aerodynamic stall. The flying pilot commenced the emergency procedures for a stall-spin, however the X200 self-recovered before the checklist was completed. At about the same time the pilots received an alert indicating an airspeed sensor failure and initiated the associated emergency procedure checklist.

Before visual sight was lost, the ground crew observed the X200 oscillating in pitch as it continued to fly to the programmed first waypoint. While the flying pilot was executing the emergency procedures checklist, the X200 entered a second aerodynamic stall. Following self‑recovery from a low height above terrain, the X200 commenced a climbing orbit. Shortly after, the X200 entered a third aerodynamic stall, this time from a height that was insufficient for recovery, and collided with terrain. There was no post-impact fire and the X200 was destroyed. There were no reported injuries to people or damage to infrastructure. A post-incident inspection of the X200 identified a partial blockage in the pitot system.

What the ATSB found

The investigation found that the blockage in the pitot-static system resulted in unreliable airspeed data being supplied to the autopilot. Unreliable airspeed data led to the X200 entering an aerodynamic stall at a height that was insufficient for recovery.

During the pre-flight checks, there were opportunities for the erroneous airspeed indications to be identified. However, they were not recognised by the crew or flagged by the ground control station.

What's been done as a result

Following the occurrence, the manufacturer revised their procedures to reduce the risk of aircraft being affected by a pitot blockage. Additionally, all of the operator’s pilots underwent refresher training. This included emergency procedures simulator experience.

The X200 manufacturer revised their procedures to provide support to pilots and ground crew in correct assembly of the articulated turret, identifying anomalies (on the ground and in-flight), and steps for aircraft recovery in the event of a departure from normal flight. In addition, updates to the operational software would ensure any spurious on‑ground anomalies were alarmed, to prevent the X200 being launched with an unidentified issue.

Safety message

This occurrence highlights the importance of confirming the significance of any unexpected observations during the pre-flight checks, to minimise the risk of the aircraft departing with an unserviceability. In addition, providing pilots and ground crew with the reasoning behind specific checks and procedures can enhance their ability to identify anomalies and perform the appropriate corrective actions in a timely manner.

Insitu ScanEagle X200

Insitu ScanEagle X200. Source: Insitu Pacific

Source: Insitu Pacific

 

The occurrence

What happened

On the morning of 9 January 2019, the Insitu Pacific (the operator) crew prepared to conduct a 4‑hour ‘beyond visual line of sight’ survey flight, in the Woleebee Creek area, about 350 km west‑north‑west of Brisbane, Queensland. The flight was being conducted by an Insitu ScanEagle X200 (X200).

The crew consisted of two remote pilots[1] (one acting as mission controller/pilot in command and one acting as pilot flying) and two ground crew (who were also qualified remote pilots).[2] The two pilots for this flight were located in the ground control station (GCS).[3] Headsets were worn by all crew members, to enable effective communication. All crew reported to being ‘refreshed’ and looking forward to the day’s flight.

The X200 was launched at 0825 Eastern Standard Time.[4] The crew described the launch as ‘textbook’. The secondary ground crew member maintained visual contact with the X200, typically done until advised by the pilots that they had video feedback from the on-board camera.[5] He reported that, about one minute after launch, the X200 pitched up ‘quite high’, before entering an aerodynamic stall.[6] He immediately advised the pilot flying (PF) with the standard phrase ‘wings level, wings level, you’re stalling’. At this time, the primary ground crew member also observed the X200 in a ‘left-hand spin’ and advised the PF ‘you’ve stalled, wings level, wings level’.

At the same time, the GCS identified the stall condition and projected the ‘stall-spin’ emergency procedures checklist to the display. The PF commenced the checklist items, however the X200 self‑recovered before the checklist was completed. The ground crew reported the X200 recovered ‘low to the ground’ and then commenced a climb to return to the programmed flight altitude.

At about the time of the recovery from the first stall, the GCS initiated the warnings and emergency procedures checklist for an ‘airspeed failure’. Upon the mission controller’s direction, the PF commenced the airspeed failure checklist. The ground crew reported that following a ‘steep’ climb, the X200 was then observed to be ‘porpoising’ (oscillating in pitch) while it continued to the first programmed waypoint. Shortly after this, the X200 flew beyond visual sight of the ground crew.

Telemetry data showed that, about 90 seconds after the first stall, the X200 entered a second stall. The X200 self-recovered again, at about 150 ft above the ground, and commenced a climbing orbit. After about 30 seconds, the X200 entered a third stall and impacted the ground eight seconds later. The mission controller advised the ground crew that the X200 had been lost. Total flight time was less than four minutes and distance from the launch site to the collision with terrain location was about 4.75 km (Figures 1 and 2).

Figure 1: X200 flight path

Figure 1: X200 flight path. Source: Insitu Pacific and Google Earth, modified by the ATSB

Source: Insitu Pacific and Google Earth, modified by the ATSB

Figure 2: X200 flight profile

Figure 2: X200 flight profile. Source: Insitu Pacific and Google Earth, modified by the ATSB

Source: Insitu Pacific and Google Earth, modified by the ATSB

Post-accident recovery and inspection

The aircraft impacted the ground near vertically, there was no post-impact fire and the X200 was destroyed. There was no evidence of in-flight break-up or collision with vegetation or infrastructure prior to the impact. In addition, there were no reported injuries. The operator conducted an examination of the occurrence X200 and identified a partial blockage in the pitot system, which was subsequently confirmed by the manufacturer. The blockage appeared to be a combination of a section of O-ring debris and grease.

Flight operations

The Civil Aviation Safety Authority (CASA) issued the operator with an authorisation to operate the X200 beyond visual line of sight, within a defined area. Some of the authorisation’s requirements included:

  • all remote pilots were to hold a CASA authorisation
  • a mode C transponder[7] was to be operational, and transmitting accurate barometric altitude, on all flights
  • a primary and secondary ‘fail safe’ mode to ensure that, in the event of data-link loss, the X200 did not depart the area of operation and would land at a pre-determined location
  • air traffic control at Brisbane was to be advised of the intended operation 15 minutes prior to launch, and the crew were to maintain standard airspace radio procedures for the duration of the flight
  • the operator was to ensure a current Notice to Airmen (NOTAM)[8] was active for each operation
  • the X200 was only to be operated in visual meteorological conditions.

In addition to the CASA authorisation, the operator’s procedures included:

  • no flight over populous areas
  • operations were conducted at altitudes intended to avoid agricultural and passenger aircraft.

Remote pilots underwent a 10-week course prior to being endorsed to operate the X200. This course included a theory component and time in the simulator. The pilots recalled that ‘airspeed failure’ was included in the course, however they felt that particular emergency procedure wasn’t focussed on as ‘heavily’ as others.

The accident site was located within the defined operational area, which was in accordance with the authorised requirements.

Aircraft information

The ScanEagle is a small, long-endurance, low-altitude unmanned aerial system (UAS) built by Insitu, a subsidiary of Boeing, and is used for defence and civilian applications (the X200 variant). The X200 (Figure 3) has a wingspan of 3.1 m, a length of 1.6 m, maximum take‑off weight of about 23 kg and a typical cruise speed of 50-60 kt.

The nose module (payload) on the X200 is interchangeable, depending on the type of mission being flown, and was supplied by the payload manufacturer. The payload fitted to the X200 at the time of the occurrence consisted of a camera assembly located in an articulated turret (turret). The camera could be directed through a defined fore/aft arc and the turret rotated through 360˚.

The pilot controls the X200 entirely through the aircraft autopilot from launch until recovery. The aircraft’s flight path is controlled by position, altitude and airspeed commands through the remote pilot station computer (part of the ground control station), which is then sent to the aircraft autopilot. The pilot does not have a control yoke, or equivalent, that links directly or indirectly to the aircraft control surfaces.

Typically, once the X200 has launched, the pilot commands it through a pre-planned sequence of locations and orbits around each location of interest. At the completion of the flight’s activities, the pilot would position the aircraft in preparation for the recovery phase using the same method of control. In this instance, the emergency procedure checklist actions involved the pilot utilising additional X200 autopilot control laws in order to negate the erroneous airspeed information.

Figure 3: X200 with articulated turret

Figure 3: X200 with articulated turret. Source: Insitu Pacific, modified by the ATSB

Source: Insitu Pacific, modified by the ATSB

Pitot-static system

The pitot-static system senses ram air pressure through the pitot probe (on the forward face of the payload) and static air pressure through the static ports (on each side of the payload). The two pressures are used to calculate true airspeed (TAS) and barometric altitude (Alt). The autopilot uses this data to calculate the minimum and maximum airspeed in relation to the weight of the X200 and to maintain controlled flight.

The pitot and static tubes for the X200 were routed from the pitot probe and static port through the turret and connected to the pitot-static tubing in the fuselage. If not correctly oriented during assembly, the tubes could become pinched, blocked or damaged with turret operation. Obstructed pitot-static tubes have the potential to cause incorrect TAS and Alt calculations, affecting autopilot operation.[9] In addition, the TAS and Alt indications to the pilots would also be unreliable. The manufacturer alerted X200 operators to this potential condition in November 2017, via both a service advisory and an operational advisory. Damage sustained to the X200 during this occurrence prevented testing for possible turret interference.

The service advisory (SA) provided expanded procedures for pitot and static tube routing and connection, and inspection procedures if an anomaly was identified during pre-flight checks. A review of the X200 maintenance records showed the turret had been installed as per the SA in July 2018. Since then, it had been operated for about 80 hours, without indication of turret interference.

The operational advisory (OA) included:

  • information about how to identify and troubleshoot different types of incorrect TAS and Alt indications on the ground and in-flight
  • a pre-flight function test to identify incorrect TAS and Alt indications shown on the ground control station (GCS) program
  • in-flight emergency procedures to normalise the incorrect TAS and Alt indications and avoid loss of controlled flight.

The function test was to be completed before every flight and the OA provided examples of how anomalies with the pitot-static tubing may appear on the GCS display. Where inspection and routing of the pitot-static tubes did not rectify the anomaly, the turret was to be replaced prior to next flight. The OA procedures had been incorporated into the GCS program at the time of the occurrence.

In addition, the payload manufacturer identified a quality issue with the turret assembly procedures that had the potential to induce a blockage in the pitot system. The operator identified that the occurrence X200 was affected by this quality issue, consisting of excess grease and O‑ring debris forming the pitot-system partial blockage. The X200 manufacturer published procedures to inspect (and, if required, clean) turrets that were in-service and prior to fitment. The operator examined the remainder of their fleet with these revised procedures, with no further occurrences identified.

Pre-flight checks

As part of the pre-flight procedures, the primary ground crew conducted an inspection of the X200 while the secondary ground crew readied the launcher and recovery systems. At the same time the pilots, located in the GCS, conducted their pre-flight systems checks, which included a function test of the pitot-static system (Figure 4). This test included the primary ground crew fitting a sealed clear tube to the pitot probe, which increased pressure in the system and simulated an airspeed indication associated with forward flight (equivalent to TAS). The procedure stated that any reduction in pressure (TAS) indicated on the GCS during the test, equal to or greater than the specified limits, was indicative of a system leak that required rectification prior to flight.

During the test, a slow rise of about 10 kt TAS occurred, while the indicated altitude remained steady. The OA detailed that if the TAS ‘increases slowly without turret movement or pressurisation of the pitot-static system’, this was an indication of a blockage in the pitot-static system. As per the OA, turret movement had the potential to induce a restriction in the pitot system tubing, which could ‘clear’ with subsequent movement. The pitot system was pressurised and the turret was being operated for part of this test and as such, the rise in TAS as a possible indication of a blockage may have been difficult to identify. Following this occurrence, a revised OA amended the criteria for the slow increase in TAS to show ‘at any time’ during the procedure, removing any ambiguity surrounding pitot pressurisation and turret movement during the tests.

With no pitot system leak identified by the pilots, the tooling was removed. At this time, the pilot flying (PF) commented that the TAS was ‘slow to release’ (return to pre-check indication). The primary ground crew member reported that he heard this comment however, he took no action as he wasn’t aware of the significance of this indication. The pilot pre-flight checklist identified that slow to release pressure was indicative of a blockage in the pitot system.

Following completion of the crew’s pre-flight checks, the GCS continued with the system self‑checks, while the crew met outside for a pre-mission brief, as per their standard procedure. During the time the crew were outside, the GCS self-check indicated an anomaly within the pitot‑static system. In this instance, there was an increase over time in TAS, while the Alt decreased. For this indication, the procedures required an inspection of the pitot-static system prior to launch. However, this indication was not flagged or latched.[10] Therefore, when the pilots returned to the GCS, there was nothing to alert them to this additional indication of a pitot system anomaly.

Figure 4: Pitot pressure test indications

Figure 4: Pitot pressure test indications. Source: Insitu Pacific, modified by the ATSB

Source: Insitu Pacific, modified by the ATSB

All subsequent pre-flight checks were described as normal. Weather conditions at the time were recorded as overcast conditions, 22˚C, a wind speed of about 6 kt and were described by the crew as ‘ideal’.

Autopilot and the occurrence flight

The X200 autopilot control loops rely on airspeed to control altitude. The target airspeed for the occurrence flight was 53 kt. Recorded data shows that following launch, the TAS reached 70 kt. This resulted in the autopilot commanding a rapid pitch up to try to arrest the perceived high TAS. The pitch attitude was too great for the actual airspeed, which resulted in the X200 entering an aerodynamic stall. Stall recovery took 12 seconds, with an altitude loss of 579 ft (at a rate of 48 ft/s), before the X200 began to climb back to the programmed flight altitude.

Erratic TAS is one of the parameters that can lead to a stall-spin in the X200. Flight data showed that erratic TAS was present from launch, before the turret was unlocked and operated. This was consistent with a blockage of the pitot system, rather than turret interference.

The erratic TAS also resulted in the porpoising flight profile following the first stall and recovery. Following about 80 seconds of porpoising flight, the data showed another rapid increase in TAS. The autopilot likely commanded the X200 to increase pitch attitude, which again resulted in an aerodynamic stall and rapid reduction in height. Within 12 seconds, the X200 had again self‑recovered from the stall, but at a much lower altitude than the first recovery. The second stall required 778 ft for self-recovery (at 64.83 ft/s rate of altitude loss).

This was followed by another extreme increase in TAS, leading to the third stall. This stall was at a similar rate to the second stall. Recovery was again initiated but only 591 ft was available and the X200 collided with terrain, about 9 seconds later (Figure 5).

Figure 5: Flight data showing erratic indicated airspeed and altitude

Figure 5: Flight data showing erratic indicated airspeed and altitude. Source: Insitu Pacific, modified by the ATSB

Source: Insitu Pacific, modified by the ATSB

Safety analysis

Following launch, the Insitu ScanEagle X200 (X200) twice entered an aerodynamic stall and self‑recovered. The X200 entered a third stall, this time at a lower height, and did not recover prior to collision with terrain. The analysis will examine the pre-flight indications of the pitot system blockage and its effect on the flight.

Pre-flight checks

The pre-flight checks provided three opportunities for anomalies in the pitot static system to be detected. There was a slow rise in TAS, which was indicative of an anomaly in the pitot system. The pressurisation of the pitot system and movement in the turret during the pitot-static function test, however, may have meant that the slow rise in TAS and the physical blockage was not obvious. The slow reduction in TAS after the pressure test was an indication of a pitot system blockage. This was noted by some of the crew, however the significance of this indication was not recognised.

The ground control station (GCS) system self-checks showed an additional indication of a pitot system anomaly, however it was not observed by the crew, as they were carrying out other duties at the time. At the completion of the self-checks, there was no ‘flag’ or other indication on the GCS that the pitot system irregularity had occurred. This resulted in the indications of pitot system anomaly not being identified by the crew or flagged by the GCS, resulting the X200 being launched with a blockage in the pitot system.

Unreliable airspeed data

The X200 autopilot uses true airspeed (TAS) and altitude (Alt) data to maintain controlled flight. The blockage in the pitot system resulted in unreliable airspeed data being provided to the autopilot, affecting calculation of TAS. While there remained the possibility that the turret interference may also have been present, it could not be determined as contributory in this occurrence. Flight data showed that erratic (TAS) data was present from launch, before the turret was unlocked and operated. Subsequent movement of the turret may have alleviated any turret‑induced restriction in the pitot system but due to the presence of the identified blockage, the airspeed data was unreliable even without any turret interference.

Following launch, the autopilot interpreted the TAS as increasing and increased the pitch (nose up) to maintain target airspeed. This resulted in the X200 nose-up attitude being too great for the actual airspeed and led to an aerodynamic stall. The X200 self-recovered and recommenced the climb to operating altitude.

Following recovery from the first stall, flight data showed the TAS was oscillating by up to 30 kt, resulting in the ‘porpoising’ flight profile, indicative of the autopilot trying to maintain controlled flight using unreliable airspeed data. A rapid 30 kt increase in TAS likely led to the autopilot increasing pitch attitude, resulting in the second aerodynamic stall. Again, the X200 self-recovered, however at a much lower altitude. A third rapid TAS increase followed shortly after, leading to the final stall, with insufficient height available for recovery.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • Erroneous airspeed system indications during the pre-flight checks were not identified by the crew or flagged by the ground control station, resulting in the X200 being launched with an unserviceable pitot-static system.
  • A blockage in the pitot-static system resulted in unreliable airspeed data being supplied to the autopilot.
  • Unreliable airspeed data led to the X200 entering an aerodynamic stall at a height that was insufficient for recovery.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

The operator

As a result of this occurrence, the operator advised the ATSB that the following safety actions, in cooperation with the X200 and payload manufacturers, have been undertaken:

Pilot training

Following the occurrence, all of the operator’s remote pilots underwent refresher training with a focus on identification and emergency procedures regarding incorrect true airspeed (TAS) and/or barometric altitude (Alt) indications. The training consisted of theory (including ‘how’ the system works and symptoms of pitot-static blockage) and several hours’ simulator experience of failures and use of emergency procedures. Feedback from the pilots following this training was positive. In addition, the ATSB was advised that the X200 manufacturer will amend the ab-initio pilot training to highlight pitot-static system anomalies and associated pre- and in-flight procedures.

Training and enhanced procedures can provide ‘reasoning’ behind the steps. This can assist pilots and maintainers in their understanding of indications and events, prompting effective actions and timely resolution.

The manufacturer

Documentation and procedures

The X200 manufacturer published a revised Operational Advisory (OA) on 18 February 2019. One amendment in this revised publication was the inclusion of an image from the occurrence X200, showing the Ground Control Station indication for ‘slow to release’ pitot pressure. The criteria for the slow increase in TAS was also amended to ‘at any time’ during the procedure, removing any ambiguity surrounding pitot pressurisation and turret movement during the tests.

In addition, the revised OA included an additional caution (in red text) warning that the ‘TAS error exceeds launch limit alarm is disabled for pre-flight pitot-static system checks. Therefore, it is critical to monitor the TAS-ALT-Tachometer plot throughout the on ground phase for any abnormal TAS or Alt signatures’. The operator reported that the X200 manufacturer advised a ‘latching system alarm’ would be incorporated into the next software release (scheduled for mid-2019) to alert the crew where the TAS has exceeded a threshold during on-ground checks.

Further, the manufacturer revised their procedures for assembly of the turret and provided a reworked procedure to X200 operators to reduce the risk of in‑service aircraft being affected by a pitot blockage.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. A remote pilot licence (RePL) is required for commercial operations involving remotely piloted aircraft systems (RPAS) that are greater than 2kg maximum take-off weight.
  2. Minimum crew for a deployment consisted of two pilots and one ground crew. When teams consisted of two ground crew, they were identified as primary and secondary. The secondary crew member assisting the primary as directed.
  3. The computers and associated equipment required for flight operations were located in a converted climate-controlled shipping container and collectively known as the GCS. The pilots were located in the GCS for the entire flight, including launch and recovery. The launch and recovery sites were determined each mission and located to best suit the weather and intended flight, which could be some distance from the GCS.
  4. Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours.
  5. The GCS provided location information via GPS and maps. The video feedback provided additional situational awareness for the pilots.
  6. Aerodynamic stall: occurs when the airflow separates from the wing’s upper surface and becomes turbulent. A stall occurs at high angles of attack, typically 16˚ to 18˚, and results in reduced lift.
  7. A mode C transponder transmits both aircraft identification and altitude.
  8. A NOTAM advises personnel concerned with flight operations of information concerning the establishment, condition or change in any aeronautical facility, service, procedure, or hazard, the timely knowledge of which is essential to safe flight.
  9. ‘TAS’ terminology in the remainder of the report refers to the TAS calculated from the unreliable pitot pressure (airspeed) data.
  10. A flag, or latch, is a special mark indicating that a piece of data is unusual. This alert will remain, even if the event has passed, until a clearing action has been conducted by a member of the crew.

Occurrence summary

Investigation number AO-2019-004
Occurrence date 09/01/2019
Location Near Woleebee Creek
State Queensland
Report release date 15/08/2019
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level None

Aircraft details

Model Insitu ScanEagle X200 unmanned aircraft system (UAS)
Registration Call sign AV616
Serial number 08-616
Aircraft operator Insitu Pacific
Sector Remotely piloted aircraft
Operation type Aerial Work
Departure point Woleebee Creek area, Queensland
Destination Woleebee Creek area, Queensland
Damage Destroyed

Derailment of SCT Logistics freight train 6MP9, near Cook, South Australia, on 6 January 2019

Final report

Report release date: 29/06/2020

Safety summary

What happened

On 6 January 2019, SCT Logistics freight train 6MP9 derailed near Cook, South Australia, while travelling from Melbourne, Victoria to Perth, Western Australia. The number 36 vehicle on the consist, wagon ARFY 2198T, experienced a ruptured wheel, resulting in the derailment. No other wagons derailed in the occurrence and there were no injuries.

What the ATSB found

Thermal damage to the wheel resulted in the initiation of a fatigue crack in the flange which propagated into the plate. Cracking then continued propagating around the plate, branching out to the rim, resulting in the wheel failure and ultimate derailment of the wagon.

At the last inspection, the flange fatigue crack was likely observable but was either not detected, or was deemed acceptable under the work instruction provided. This work instruction provided guidance that was less conservative than the Australian Standard, but it was not possible to establish whether compliance with the standard would have prevented the occurrence.

What's been done as a result

SCT Logistics has worked with their primary maintenance provider to develop an improved inspection process for wheels exhibiting issues with brakes (e.g. sticking brakes), as these issues can lead to heat-related fatigue cracks.

SCT Logistics also plans to phase out the type of wheelsets that ruptured in the occurrence, in favour of a type that is less prone to the development of fatigue cracks due to thermal issues.

Safety message

Vigilant field inspections are a useful tool for the detection and monitoring of fatigue cracks. However, they are not infallible, and should be utilised with an understanding of their limitations.

Further, selection of the appropriate materials can assist in reducing the occurrence of fatigue cracks and subsequent wheel failures.

 

The occurrence

What happened

On the evening of 4 January 2019, SCT Logistics freight train 6MP9 departed Melbourne, Victoria for Perth, Western Australia. At 0635 Central Daylight‑saving Time[1] on 6 January 2019, the train derailed at 869.700 km in the Fisher-Thomiar section, near Cook, South Australia. The derailment involved the number 36 vehicle on the consist, wagon ARFY 2198T. One of the wheelsets on the ‘B’ end of the wagon experienced a ruptured wheel, resulting in the derailment (Figure 1). No other wagons derailed as a result of the rupture, however gouges in the rail were found, as well as some broken sleepers and missing clips.

Prior to the derailment, the train passed over two wayside detectors designed to alert the operator of abnormalities that might indicate wheel or bearing damage. There was no record of any alerts received from these detectors.

Figure 1: The ruptured and derailed wheel in situ

Figure 1: The ruptured and derailed wheel in situ.
Source: SCT Logistics

Source: SCT Logistics

Context

Wheelset examination

The majority of the failed wheelset pieces were recovered from the accident site. These pieces and the adjacent wheelset were sent to SCT Logistics’ primary maintenance provider, Gemco Rail (Gemco), for a preliminary inspection. This examination was attended by the ATSB, the Office of the National Rail Safety Regulator, and independent consultants, Bureau Veritas.

A visual examination of the wheel found two potential fatigue regions on the ruptured wheel. One of these was within the flange of the wheel, while the other was within the plate (Figure 2). The wheelset and fragments were then provided to Bureau Veritas for an independent metallurgical examination, in order to determine the nature of, and possible reasons for, the failure.

Figure 2: Two fatigue regions in the flange (left) and the plate (right)

Figure 2: Two fatigue regions in the flange (left) and the plate (right).
Source: ATSB

Source: ATSB

Metallurgical examination

Bureau Veritas found that the wheelset met the chemical and hardness requirements for Class C wheel material, as specified by the Association of American Railroads (AAR). The second wheelset on the derailed bogie was recorded as Class B. Both wheel-types were permitted, but Class C wheels were harder with less ductility.

The examination confirmed that two regions of fatigue cracking were present in the wheel. The wheel failed as a result of cracking that initiated at the wheel flange. The fatigue crack on the flange propagated into the rim, and the mode of cracking changed from fatigue to brittle fracture. The crack then propagated into and around the wheel plate, connecting to the second fatigue crack within the plate. The propagation continued through the plate, branching out into the rim at various locations and resulting in the wheel rupturing into multiple pieces when it finally failed. This fracture sequence is illustrated in Figure 3, where blue arrows indicate the direction of crack propagation.

Figure 3: Recovered wheel fragments with direction of crack propagation

Figure 3: Recovered wheel fragments with direction of crack propagation. 
The blue arrows indicate the direction of crack propagation. The letters and numbers were used in the Bureau Veritas examination report to identify the different fragments and cracks, respectively. 
Source: Bureau Veritas, modified by ATSB

The blue arrows indicate the direction of crack propagation. The letters and numbers were used in the Bureau Veritas examination report to identify the different fragments and cracks, respectively.

Source: Bureau Veritas, modified by ATSB

The fatigue crack on the flange (crack 4 in Figure 3) was determined to be a thermal crack, 20 mm in length at the surface, formed in a white etching layer. Thermal cracks are caused by rapid changes in the temperature at the surface of the wheel. The presence of a white etching layer confirms a rapid temperature change occurred, as these layers are regions where the steel has transformed into martensite. Martensite is a brittle form of the metal created by heating and rapid cooling, and is more susceptible to cracking than the original flange material.

Bureau Veritas reported that the fatigue crack in the plate region may have initiated at non‑metallic inclusions found in that part of the wheel. However, this could not be confirmed due to damage at the fracture region because of the wheel failure.

Additional thermal cracks were identified near the crack on the flange (crack 4), although these did not propagate into the rim or the plate. The two largest additional cracks measured 12 mm and 15 mm in surface length (Figure 4). Bureau Veritas reported that the cracks in Figure 4, including the one that propagated into the plate, occurred in a region with evidence of sliding, rather than rolling, contact. Sliding contact can lead to rapid temperature changes in the flange, and the resultant formation of a white etching layer.

Figure 4: Thermal cracks adjacent to the flange fatigue fracture region

Figure 4: Thermal cracks adjacent to the flange fatigue fracture region.
The surface has been cleaned and prepared for examination. Coloured dye has been used to highlight the cracks. 
Source: Bureau Veritas, annotated by ATSB

The surface has been cleaned and prepared for examination. Coloured dye has been used to highlight the cracks.

Source: Bureau Veritas, annotated by ATSB

Comments from the wheel manufacturer

Following the release of Bureau Veritas’ examination report, the wheel manufacturer reviewed and provided comment on the included observations/findings. The manufacturer assessed that the inclusions observed near the plate fatigue cracking were innocuous, and unlikely to provide a suitable site for the initiation of a fatigue crack. They also asserted that the size of the inclusions was within the acceptable range under AAR standards. The manufacturer believed that the fatigue crack likely initiated after the flange crack propagated into the plate, and the wheel lost its rigidity.

The manufacturer also noted that class C wheels were relatively hard, and that:

Class C material being high carbon, high hardness and lower ductility is not generally recommended for tread breaking applications with high thermal load and potential thermal issues.

Wheel maintenance history

Wheelset 39867 was originally fitted with Class C forged wheels on 22 February 2015. It was inspected and reprofiled on 12 October 2016 and again on 19 September 2018. The wheelset was installed on the occurrence wagon (ARFY 2198T) on 28 September 2018. A field inspection, known as an A2 inspection, was performed on the wagon on 10 December 2018, which included an examination of the wheelset. The wagon passed the inspection and returned to service. No wheel cracking or other damage was noted prior to the derailment on 6 January 2019.

The A2 inspection was performed with the wagon on rails, so a small part of the wheel would have been obscured. The inspection involved various checks, which included:

  • ensuring the wheel dimensions were within limits
  • looking for defects or damage on the tread
  • looking for signs of overheating
  • inspecting any visible cracks.

Inspection standards for thermal cracks

Gemco provided a work instruction to personnel performing A2 inspections, which instructed them to classify thermal cracks based on their size and location. A Class 4 thermal crack was defined as one longer than 10 mm within the flange or edge of the rim, or any crack longer than 40 mm. This definition was based on the Rail Industry Safety and Standards Board (RISSB) Wheel Defects Code of Practice. The Code of Practice, which was referenced by the Australian Standard for rolling stock wheels, defined Class 4 thermal cracks as any crack visible on the flange, cracks longer than 10 mm on the edge of the rim, or any crack longer than 40 mm. The presence of a Class 4 crack required the train speed to be limited to 40 km/h until the wheel could be replaced.

Figure 5 compares the definition provided by Gemco’s document with the one from the RISSB Code of Practice. The only difference between the two definitions was that Gemco permitted flange cracks up to 10 mm long, while RISSB did not permit flange cracks of any size. Under Gemco’s work instruction, flange cracks below 10 mm did not fit under any classification and therefore did not need to be recorded.

Figure 5: Definition of Class 4 thermal cracks provided by Gemco (left) and RISSB (right)

Figure 5: Definition of Class 4 thermal cracks provided by Gemco (left) and RISSB (right).
Source: Gemco, RISSB

Source: Gemco, RISSB

Safety analysis

The white etching layer observed on the flange fatigue crack indicated that the wheel was exposed to abnormally high temperatures at some point, probably due to sliding contact with the rail. Exposure to such temperature altered the material property of the steel and facilitated initiation of a fatigue crack, which propagated from the flange into the rim and then the plate. The Class C wheel type may have increased the wheel’s susceptibility to fatigue cracking compared with the softer Class B wheels on the adjacent wheelset.

The crack progressed through the plate and joined with a second fatigue crack. The reason for this second crack’s initiation could not be determined, nor could it be determined whether it initiated as a result of the flange crack or if it was already present in the wheel. However, given the extent of cracking at this point, it did not appear to have a significant effect on this wheel failure. Cracking then continued propagating around the plate, branching out to the rim, resulting in the wheel failure and ultimate derailment of the wagon.

Examinations following the derailment found that the flange fatigue crack and the adjacent thermal cracks were longer than the 10 mm stated in the work instruction. As an inspection for thermal cracks was carried out 27 days prior to the wheel failure and derailment, it is likely that one or more of these cracks were present at the inspection, but they may have been missed, or obstructed by the rail.

It is also possible that the cracks were observed by the inspector, but were visually assessed as smaller than 10 mm long. If the cracks had a surface length below 10 mm, then under Gemco’s work instruction they would not have required any action, and their presence would not need to be recorded.

Without further details from the thermal crack inspection, it was not possible to determine whether or not the derailment would have been prevented if the work instruction prohibited all thermal cracks on the flange, as described in the more conservative RISSB Code of Practice.

Findings

From the evidence available, the following findings are made with respect to the derailment of SCT Logistics freight train 6MP9, near Cook, South Australia on 6 January 2019. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • Thermal damage led to the initiation and propagation of a fatigue crack through the wheel flange. This may have been exacerbated by the wheel type, which was more susceptible to thermal cracking. The crack progressed through the wheel plate, and ultimately resulted in the wheel failing.
  • The flange crack that led to the wheel failure was likely present at the last inspection, but was either not detected, or was an allowable length based on the maintenance provider’s work instruction.
  • The maintenance provider’s work instruction for classifying thermal cracks on the wheel flange was not as restrictive as the Australian Standard.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

The operator and maintenance provider

As a result of this occurrence, SCT Logistics worked with Gemco to develop an improved inspection process for wheels exhibiting issues with brakes (e.g. sticking brakes) – as these issues can lead to the development of thermal cracks.

SCT Logistics has also instructed Gemco to only install Class B wheelsets when replacements are needed, so that Class C wheelsets are phased out of the fleet through attrition.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Central Daylightsaving (CDT) Time: Coordinated Universal Time (UTC) +10.5 hours.

Occurrence summary

Investigation number RO-2019-001
Occurrence date 06/01/2019
Location Near Cook (Fisher-Thomair section)
State South Australia
Report release date 29/06/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Accident
Highest injury level None

Train details

Train operator SCT Logistics
Train number 6MP9
Type of operation Bulk Freight
Rail vehicle sector Freight
Departure point Melbourne, Victoria
Destination Perth, Western Australia
Train damage Substantial

Level crossing irregularity involving passenger train 3MA8, North Geelong, Victoria, on 8 January 2019

Final report

Report release date: 22/09/2020

Safety summary

What happened

On 8 January 2019, as The Overland passenger train, 3MA8, approached the Thompson Road level crossing at North Geelong, Victoria, the train crew noticed that the flashing lights had not activated and the boom gate had not lowered as expected. While the crew noticed the irregularity, it was too late to take substantive action and the train passed through the level crossing unprotected. The crew reported that several road vehicles were in the vicinity of the level crossing at that time, but none were in the danger zone.

What the ATSB found

The ATSB found that, in preparation for stage one track work, the Thompson Road level crossing was to be isolated for the broad and dual-gauge tracks only. The level crossing protections for the adjacent standard-gauge track, which was to continue operating as normal until stage two works at a later date, were to remain active. However, the signalling tester, following the isolation plans provided, mistakenly isolated the level crossing for the stage two work, in addition to stage one. While the stage one and stage two works were to be conducted separately, the signalling tester‑in-charge provided the signalling tester with the isolation plans for both stages in one package.

VicTrack, through their contractor UGL Engineering Limited, did not provide the tester-in-charge or signalling testers with specific instructions detailing the scope of work to be conducted at each stage of the project, but rather, only provided packaged isolation plans for the entire project. The absence of these instructions increased the risk of the works being incorrectly implemented.

What has been done as a result

As a result of this occurrence, VicTrack has advised that improvements had been made at the task‑based level by including specific work instructions for each task associated with each isolation plan.

Safety message

A work instruction is a step-by-step guide on how to perform a specific task or activity, in support of a process or procedure. They are an important defence within a safety system for ensuring the work is performed safely and as intended. This occurrence highlights the importance of providing clear, concise, and detailed work instructions to reduce the risk of errors during critical safety work.

 

The occurrence

Preparation for planned track work

On the morning of 8 January 2019, planned track work was to commence at the North Geelong, Victoria ‘C’ signal box. The work, managed by VicTrack, involved the removal, modification, and installation of signalling equipment and was to be performed in several stages over January 2019. Stage one affected the two broad-gauge and single dual-gauge tracks (managed by V/Line) and would temporarily impact the operation of several level crossings including those at Thompson and Anakie Roads. Stage two involved works on the adjacent Australian Rail Track Corporation (ARTC) standard-gauge track, to be performed at a later date (see Planned work).

At about 0734 Eastern Daylight-saving Time,[1] a track warrant possession (TW2)[2] was issued to exclude rail traffic and allow the work to proceed safely. The exclusion applied to trains operating on the two broad-gauge and single dual-gauge tracks (stage one). The ARTC standard‑gauge track would be protected between train services,[3] but remain operational, as specified in the project planning documents and ARTC Train Notice 2668,[4] until stage two.

Prior to commencing the work, several briefings were conducted involving the various project work teams. The signalling tester-in-charge (TIC) also conducted a separate pre-work briefing with the signal test teams (see Personnel involved). Specifically, the TIC reported mentioning that the standard-gauge track would remain open for normal traffic, but would be protected. The ARTC certified signalling tester (signalling tester) also attended the briefings, but could not recall any discussions regarding train movements.

The TIC, that morning, provided the signalling tester a package of isolation plans (wiring drawings) for the work (see Isolation plans and package), which included the plans for both the stage one and stage two works. Following this, a test team (test team 1), consisting of the signalling tester and an assistant, made their way to the equipment relay room[5] near the Thompson Road level crossing at North Geelong.

For the work, some of the signalling infrastructure at the Thompson and Anakie Road active level crossings needed to be electrically isolated for the broad-gauge and dual‑gauge tracks. In preparation for this, the signalling tester assembled the electrical jumpers needed to isolate each circuit identified on the isolation plans.

Level crossing isolation

At 0954, the TIC contacted the network control officer (NCO) to arrange an infrastructure booking advice[6] for Thompson Road. Shortly after, the TIC notified the signalling tester at the equipment relay room to commence work. The tester began applying the jumper cables[7] to the relay contacts of all four tracks to isolate the Thompson Road level crossing, as detailed within the packaged isolation plans provided (see Isolation plans and package).

At about 1048, after applying the jumper cables, the tester verified that the level crossing was functioning by activating the local push-button.[8] Upon verification, the team left and made their way to the next crossing at Anakie Road. The test triggered an alarm on the Phoenix control system[9] display in the ARTC train control centre in Adelaide, South Australia. The NCO received a level crossing fault alarm, and the ‘Thompson Road’ text changed colour to red to indicate it had been activated (Figure 1). The NCO immediately contacted the operations coordinator[10] and asked if the crossing was okay, and not affected, and would operate as normal. The operations coordinator advised the NCO that the crossing should operate as normal.

Figure 1: Phoenix replay of the Thompson Road level crossing alarm

Figure 1: Phoenix replay of the Thompson Road level crossing alarm.
Note: The level crossing fault alarm is a pop-up dialog box, not shown in this image. Time is Central Daylight-saving Time (CDT), Coordinated Universal Time (UTC) +10.5 hours.
Source: ARTC, annotated by the ATSB

Note: The level crossing fault alarm is a pop-up dialog box, not shown in this image. Time is Central Daylight-saving Time (CDT), Coordinated Universal Time (UTC) +10.5 hours.

Source: ARTC, annotated by the ATSB

Once at Anakie Road, the tester began applying the isolations, similar to the process followed at Thompson Road.

Train 3MA8 approaching Thompson Road

Soon after, The Overland passenger train 3MA8 was nearing the Thompson Road level crossing, operating on the ARTC standard-gauge track. The train crew had been previously made aware by the NCO that track workers were operating at the North Geelong ‘C’ signal box. As the train approached, the crew noticed that the level crossing lights had not activated and the boom gates had not lowered. In response, they commenced braking, reduced the throttle, and sounded the horn to alert approaching road traffic. At about 1054, the train passed through Thompson Road at a reported speed of about 50 km/h, with the level crossing protections inactive. Although there was road traffic in the vicinity of the crossing, no vehicles were in the danger zone[11] at the time the train passed through. The Phoenix replay (Figure 2) showed the ‘Thompson Road’ text white, indicating the crossing was not active as 3MA8 passed (represented by the red line).

The crew contacted the NCO and advised of the occurrence. The train continued its journey as normal. The Anakie Road level crossing, about 650 m further along from the Thompson Road level crossing, operated normally for train 3MA8.

Figure 2: Phoenix replay of the occurrence

Figure 2: Phoenix replay of the occurrence.
Note: Time is Central Daylight-saving Time (CDT), Coordinated Universal Time (UTC) +10.5 hours.
Source: ARTC, annotated by the ATSB

Note: Time is Central Daylight-saving Time (CDT), Coordinated Universal Time (UTC) +10.5 hours.

Source: ARTC, annotated by the ATSB

The NCO immediately called a project representative in the site office near Separation Street who spoke with the TIC about the occurrence. The TIC then contacted the tester, now located at Anakie Road. The tester, who was in the process of applying the jumper cables (but had not yet isolated the level crossing), stopped work and returned to Thompson Road. The TIC also proceeded to Thompson Road.

From about 1120, the TIC reinstated and tested the affected level crossings. During this process, it was determined that the tester had applied jumper cables to all tracks, consistent with stage two implementation. All further work was suspended until further notice. Later that day, an ARTC representative validated the reinstatement actions and normal working resumed through the Thompson Road level crossing.

__________

  1. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. Authority for exclusive occupancy of track by track workers and equipment within specified limits.
  3. Authority for non-exclusive occupancy of track by track workers and equipment within specified limits.
  4. The train notice was issued on 27 December 2018 and detailed the works to be performed at North Geelong between 8–22 January 2019.
  5. An enclosure encompassing racks and their mounted equipment (signalling and control equipment, power supplies and communications equipment).
  6. Infrastructure booking advices (IBAs) are used to tell network control officers that infrastructure is: temporarily or permanently removed from service (‘booked out-of-use’), or installed or returned to service (‘booked into-use’).
  7. The jumper cables are used to isolate (bridge) the electrical contacts on relays or any device to remove the functionality normally provided by the relay or device within the associated electrical circuit.
  8. Following the implementation of both isolation stages, the tester verified the correct function of the crossing via the local push-button.
  9. The Phoenix control system is a non-vital centralised traffic control system that provides real-time monitoring of train movements, and the controls of signals and points. Signalling equipment and circuits are considered non-vital where failure to function correctly would not cause an unsafe outcome of the signalling system.
  10. The operations coordinator is the interface between the project, and the ARTC and V/Line operations.
  11. Everywhere within 3 m horizontally from the nearest rail and any distance above or below this 3m, unless a safe place exists or has been created.

Context

Thompson Road level crossing

The Thompson Road level crossing at North Geelong is located about 72 track kilometres south‑west from Melbourne, on the main line between Melbourne and Adelaide. The level crossing had active protections, which included physical barriers, warning signs, line markings, lights, and audible devices to alert vehicular or pedestrian traffic that a train was approaching or crossing.

The level crossing consisted of four railway tracks and a dual carriageway road, including a pedestrian pathway. All tracks ran adjacent to each other within the rail corridor.

V/Line managed both the broad-gauge and single dual-gauge tracks (yellow shading in Figure 3), and Australian Rail Track Corporation (ARTC) managed the single standard-gauge track (red shading in Figure 3). ARTC had primary maintenance responsibility for the level crossing infrastructure.

Figure 3: Aerial view of ARTC and V/Line responsibility boundaries

Figure 3: Aerial view of ARTC and V/Line responsibility boundaries.
Source: VicTrack, annotated by the ATSB

Source: VicTrack, annotated by the ATSB

Planned work

The North Geelong ‘C’ signal box allowed the management of rail traffic at Thompson Road, Separation Street, the Geelong grain loop, and the Corio independent goods line. The Victorian Government engaged VicTrack to undertake works to replace the current mechanical interlocking and signal control systems to allow the remote operation of the signal box from V/Line’s Centralised Train Control (Centrol). VicTrack engaged UGL Engineering Limited (UGL) as the principal contractor for the works, who in turn sourced suitably qualified staff from other third party providers as required. VicTrack retained oversight and responsibility for the project.

The scope of works undertaken were the disarrangement of track circuits and infrastructure to enable signal upgrades in the V/Line leased area only (Figure 3). The work was to be undertaken during the month of January 2019 in several stages as part of Train Notice 2668:

  • Stage one (yellow shading in Figure 3): 8‑22 January 2019, isolation of the dual-gauge, broad‑gauge, arrival, and departure tracks at Thompson Road; and south line at Anakie Road.
  • Stage two (yellow and red shading in Figure 3): 13 January 2019, isolation of all tracks at Thompson and Anakie Roads.
  • Stage three: 21 January 2019, testing.
  • Stage four: 22 January 2019, commissioning.

Regular planning meetings were held detailing the scope of work required, including the staged track possession of the ARTC standard-gauge track.

Personnel involved

As part of the broader project, an electrical work group was tasked with the electrical isolations of the signalling system. The group consisted of a signalling tester-in-charge (TIC) supervising two test teams, test team 1 and test team 2. Each team consisted of a signalling tester and assistant, who were appropriately qualified.

The TIC had the responsibility to ensure that the new and altered works were planned, installed, inspected and tested to design, standard and schedule. The signalling testers carried out testing activities as directed by the TIC and in accordance with relevant V/Line and ARTC procedures. Assistant signalling testers assisted with testing activities as directed by the TIC or a signalling tester.

Isolation plans and package

A work instruction is a step-by-step guide on how to perform a specific task or activity, in support of a process or procedure. They are an important defence within a safety system for ensuring the work is performed safely and as intended.

The isolation plan for each location was designed by UGL, then reviewed, and approved by all stakeholders[12] before the work commenced. The plans (Figure 4) contained critical information on what circuits were to be isolated, and identified each isolation jumper cable for each circuit. While each plan was associated with a certain stage of the project (see Planned work above), there was no supporting instructions provided in the package specifically detailing the scope of work to be conducted at each stage, nor were the plans marked to clearly identify at which stage that plan applied to.

The package was provided to the TIC by UGL prior to the commencement of the work. The package included the train notices, project planning documents, and isolation plans for the project.

Figure 4: One of the isolation plans for the North Geelong works stage 1

Figure 4: One of the isolation plans for the North Geelong works stage 1.
Source: VicTrack

Source: VicTrack

__________

  1. V/Line, VicTrack, UGL, ARTC.

Safety analysis

Introduction

In preparation for planned track work for the upgrade of the North Geelong, Victoria, ‘C’ signal box, the Thompson Road level crossing was to be isolated for the broad and dual-gauge tracks only (V/Line tracks). The level crossing protections for the adjacent standard-gauge track (Australian Rail Track Corporation (ARTC) track), which was to continue operating as normal, were to remain active as trains would continue to use this track during stage one of the works. However, as The Overland passenger train (3MA8) approached the crossing on the ARTC track, the train crew noticed that the level crossing protections had not activated as expected. While the crew noticed the irregularity, it was too late to take substantive action and the train passed through the level crossing unprotected. The crew reported that several road vehicles were in the vicinity of the level crossing at that time, but none were in the danger zone. The ARTC Phoenix train control system replay confirmed the non-operation of the Thompson Road level crossing.

This analysis will examine why the level crossing protections did not activate as expected and review the documentation provided to signalling testers for isolating the Thompson Road level crossing.

Level crossing isolation

Following the packaged isolation plans provided by the tester‑in‑charge (TIC), the signalling tester applied the jumper cables to the V/Line track in preparation for the stage one works. Additionally, the tester also mistakenly applied the cables to the ARTC track, which should have been performed at a later time as part of the stage two works. The implementation of both stages isolated the V/Line tracks as well as the ARTC track, which was still operational for scheduled train movements. This resulted in the Thompson Road level crossing not operating for the approach and passage of train 3MA8.

While a pre-work brief had been conducted, the tester could not recall the specific details of that briefing. This was a missed opportunity for knowing that the level crossing for the ARTC track was to remain active.

The tester was notified about the occurrence before there was an opportunity to isolate the next level crossing at Anakie Road. However, it was possible that, had the tester applied the jumper cables for the Anakie Road level crossing, it too would have been incorrectly implemented, resulting in the isolation of the crossing protections for all tracks.

Packaged isolation plans

The TIC was provided the isolation package for the entire project by the principal contractor for the works, UGL Engineering Limited (UGL). This package contained the isolation plans for each location, including those for the stage one and stage two works, which were to be conducted separately. The TIC subsequently conducted a verbal pre-work brief with the signalling testers and assistants. During this brief, the TIC reiterated that the ARTC track would remain operational (stage one) and the level crossings active, distinguishing between the two stages. Despite this, the TIC provided the signalling tester with the entire isolation package, without modification, prior to the work commencing. Consequently, the tester had the plans for both stages, although the plans for stage one were only to be applied on the day of the occurrence.

No specific instructions provided

The principal contractor employed by VicTrack for the works, UGL, led the project planning, including the development and approval of the isolation plans. During this process, specific instructions detailing the scope of work to be conducted at each stage of the project had not been developed to support the isolation plans. Consequently, the absence of these instructions increased the risk of the works being incorrectly implemented.

In this case, UGL provided the TIC with a package containing the isolation plans for the entire project including the work to be conducted at Thompson Road, which in turn was provided to the signalling tester. However, without specific written instructions for each plan (at each stage), the tester mistakenly applied the isolation plans both stage one and two at the same time.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the Thompson Road level crossing failed to operate for the passage of passenger train 3MA8 on 8 January 2019.

Contributing factors

  • The Thompson Road active level crossing at North Geelong failed to operate as train 3MA8 approached and passed through the level crossing.
  • In preparation for stage one track work (broad and dual gauge-tracks) the signalling tester, following the isolation plans provided, isolated the level crossing for the stage two work (standard-gauge track), which was still operating trains.
  • The signalling tester-in-charge provided the signalling tester with the packaged isolation plans for both stage one and stage two works, which were intended to be conducted separately.
  • VicTrack’s contractor, UGL Engineering Limited, did not provide signalling testers with specific instructions detailing the scope of work to be conducted at each stage of a project, but rather, only provided packaged isolation plans for the entire project. The absence of these instructions increased the risk of the works being incorrectly implemented. (Safety issue)

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

The initial public version of these safety issues and actions are provided separately on the ATSB website, to facilitate monitoring by interested parties. Where relevant, the safety issues and actions will be updated on the ATSB website as further information about safety action comes to hand.

No specific instructions provided

Safety issue number: RO-2019-002-SI-01

Safety issue description: VicTrack’s contractor, UGL Engineering Limited, did not provide signalling testers with specific instructions detailing the scope of work to be conducted at each stage of a project, but rather, only provided packaged isolation plans for the entire project. The absence of these instructions increased the risk of the works being incorrectly implemented.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • The Office of the National Rail Safety Regulator
  • VicTrack
  • Australian Rail Track Corporation
  • Pacific National.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • Australian Rail Track Corporation
  • Office of the Rail Safety Regulator
  • Pacific National
  • UGL Engineering Limited
  • VicTrack
  • V/Line

Submissions were received from:

  • Australian Rail Track Corporation
  • Office of the Rail Safety Regulator
  • Pacific National
  • UGL Engineering Limited
  • VicTrack

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2019-002
Occurrence date 08/01/2019
Location North Geelong
State Victoria
Report release date 22/09/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Signal Irregularity
Occurrence class Incident
Highest injury level None

Train details

Train operator Journey Beyond/Pacific National
Train number 3MA8
Type of operation Passenger
Departure point Melbourne, Victoria
Destination Adelaide, South Australia
Train damage Nil

External sling loading accident involving Bell 205, VH-HUE, 39 km south-east of Talbingo, New South Wales, on 10 January 2019

Final report

Report release date: 10/03/2020

Safety summary

What happened

On the 10 January 2019, a Bell Helicopter 205A-1, registered VH-HUE (HUE), was being used for external sling loading operations near Talbingo, New South Wales with the pilot as the sole occupant. As the helicopter approached the drop‑off site, the load unexpectedly disconnected from the remote cargo hook. One of two ground personnel was struck and seriously injured by the falling load.

What the ATSB found

Despite examination of the involved components, the reason why the load disconnected unexpectedly from the remote cargo hook could not be determined. However, the ATSB found that the loadmasters were not maintaining a safe distance from the load. Their positioning, in combination with the significant movement of the load as it contacted the ground, resulted in one of them being struck and seriously injured.

What's been done as a result

As a result of this accident, all contractors involved reviewed the procedures being used for helicopter lifting operations during this project. They have reviewed the risk controls for receipt and positioning of loads, based on the positioning precision required.

The operator who supplied the loadmasters has reviewed and updated their procedures. They have identified a ‘dynamic exclusion zone’ as a position above a person’s head height that is in the pathway of a potential uncontrolled load that may drop and impact onto a person. In recognition that the zone may vary due to a number of variables, specific guidance will be provided as part of pre‑activity briefings.

The lead contractor is overseeing a range of initiatives, including a behavioural safety review of the project with the intention to implement an appropriately designed program to positively influence behaviours across their projects.

Safety message

This incident highlights the dangers associated with external sling load operations. Unexpected events can occur and ground personnel should ensure they maintain their separation from external slung loads that are above head height. Each sling load operation can be unique, with different locations, load shape and environmental conditions creating different safety considerations. As a consequence, clear written procedures and detailed discussions prior to commencement of each operation are essential to ensure all participants are aware of the unique dangers of the operation.

Transport Canada commissioned a video titled ‘Keep your eyes on the hook’, which shows some of the dangers for ground crew when working around helicopters and longline loads.

 

The occurrence

What happened

On the 10 January 2019, a Bell Helicopter 205A-1, registered VH-HUE (HUE), was being used for external sling loading operations near Talbingo, New South Wales with the pilot as the sole occupant. As the helicopter approached the receiving site, the load unexpectedly disconnected from the remote cargo hook. One of two loadmasters assisting on the ground, was struck and seriously injured by the falling load.

Preparation for the operation

There were a number of different organisations involved in lifting operations on the day. The lead contractor had sub‑contracted two helicopter operators to move the equipment from a staging area near Tantangara Dam to a drilling site about 3 km away. The three organisations had conducted this type of work together a number of times. One helicopter operator (operator A) supplied an AS350B3 helicopter, long line, remote cargo hook, lifting equipment and three experienced loadmasters. The second operator (operator B) supplied HUE, a long line and remote cargo hook.

At around 0800 Eastern Daylight Time,[1] two of the loadmasters arrived at the staging site to begin preparations for the day. Both helicopters and the third loadmaster were delayed due to fog. The loadmasters checked all the lifting equipment, including the slings and shackles, for integrity and ensured they had been checked during the last routine equipment inspection. They then began working with the drilling crew to organise, weigh and rig the loads to be moved by the helicopters. The third loadmaster arrived after the fog had lifted, and they all worked together to finish rigging the loads.

Among the loads were three lots of drill rods on drill racks (Figure 1). The loadmasters decided not to use the lift points on the drill racks, as the lift points were not rated or stamped. Working together, the loadmasters ensured the weight of the loads were equal, secured the drill rods to the rack and rigged the slings, so the loads would be balanced during flight. To do this, they used two 6 m round slings, rated to carry 2,000 kg, choked at either end of the rod rack. The slings were then attached to a shackle, which connected directly to the remote cargo hook. A 5.6 m tag line was attached to the load, to assist with manoeuvring the load into the required position at the receiving site. The loadmasters rigged the loads a number of times before they were happy with the rigging.

Figure 1: Drill rods ratcheted to the rack and slings attached

Figure 1: Drill rods ratcheted to the rack and slings attached.
The figure shows the drill rods ratcheted to the drill rod rack and the slings which are choked at the ends of the drill rack. 
Source: NSW police, annotated by ATSB

The figure shows the drill rods ratcheted to the drill rod rack and the slings which are choked at the ends of the drill rack.

Source: NSW police, annotated by ATSB

After all the loads were rigged to their satisfaction, the pilots and loadmasters then held an aviation briefing where they discussed a helicopter lift plan. One of the loadmasters then led a toolbox talk, with all people involved in the day’s operations. They discussed every item on their company’s safe work method statement, which included known hazards. It was reported that the discussion clearly identified:

  • safe sites for people not involved in the helicopter lifting operations
  • the routes the helicopters would be taking
  • being mindful of avoiding the ‘crush zone’.

Inside the ‘crush zone’ there was an injury risk from contact with the external loads. There was no definition for the extent of the crush zone.

The loadmaster also highlighted that:

  • as taglines were being used, people should not become fixated on getting hold of them
  • ground personnel should not put themselves in a dangerous position and were to remain within the view of the pilot at all times.

The lead contractor then conducted a third briefing, which discussed their company’s expectations including radio communications, transfer of crew between the loading and receiving zone, staff resourcing of both the loading and receiving areas, and emergency procedures. It was reported that all three briefings were done methodically, with clear instructions and time for all involved to ask questions and understand their role.

The people who were being flown to the drill site were then given a helicopter induction. While this was occurring, inspections of the helicopter's cargo hook on the underside of the helicopter, long lines and remote cargo hook connections were conducted. This involved a number of release and reattachments of the long line to the cargo hook on the underside of the helicopter and a number of pilot-operated releases and manual releases by the loadmasters of the remote cargo hook. After the loadmasters had checked the shackles to ensure they fitted in the cargo hook throat (Figure 2), the group split up and went to their designated areas. One loadmaster went to the loading site and two went to the drill site, which was receiving the equipment. At the drill site, the supervisor identified the designated safe zone ensuring all personnel not involved in the lifting operations were within this zone and placed the emergency equipment to ensure easy access if required.

Figure 2: Cargo hook

Figure 2: Cargo hook.
Source: ATSB

Source: ATSB

Lifting operations

Operations commenced after lunch with a check of the radios. The loadmasters had VHF radios in their helmets, which they used to communicate with each other at the drill site and with the helicopter pilots. The pilot of HUE conducted the first lift and, having requested to start with a light load, moved an 800 kg load to the drill site with no issues. Loadmaster 1 conducted all radio communications with the pilot at the drill site. He reported that when the helicopter was clear of all obstacles along the approach path, he advised the pilot and then gave directions to position the load where it was required, with clear advice of the height of the load above the ground.

It was reported that one load carried by the AS350B3 was spinning on arrival at the drill site. In response, the pilot touched the load to the ground away from the loadmasters to stop the spin. The helicopter then lifted the load off the ground to about knee height and the loadmasters manoeuvred the load to its position on the site while directing the pilot.

Accident load

After moving two lighter loads, the pilot of HUE requested a heavier load be connected. The loadmaster selected one of the drill rod racks, weighing about 1,200 kg, and connected the shackle to the hook. As the load lifted, it was slightly uneven and the loadmaster instructed the pilot to return the load to the ground, so he could re-adjust the slings. The pilot lowered the load and placed the hook on the load. After adjustment to the sling, the load lifted evenly and was flown to the drill site (Figure 3).

Figure 3: Images showing the occurrence load during departure from loading site

ao2019003_figure-3_final.png

The image on the left shows that on departure the load was slightly uneven, the image on the right shows the load after loadmaster had adjusted the slings.

Source: Helicopter Operator A, annotated by the ATSB

As the helicopter approached the drill site, the pilot contacted the loadmasters and advised them that he was carrying the drill rods. Loadmaster 1 told him that the load was to go to a different area of the site and advised that the wind had dropped to around 3–5 km/h (0.5–1.5 kt). Loadmaster 1 subsequently told the pilot that they could see the helicopter and gave him advice on directions and distance to run to the drill site. He then advised the pilot he could descend, calling out the load’s height above the ground. The loadmasters began to approach the load when it was at about 7 m above the ground. Loadmaster 1 later advised that the plan was to lower the load to touch the ground and then raise it to knee level before moving it to its final resting position. Both loadmasters were reportedly careful to maintain clearance with the area under the load and stood at 45° to the load. They were both on the same side of the load. It was reported that the load was steady as it was flown in to the drill site.

The load was moved very slowly down to an area having an estimated 10˚ slope, with loadmaster 1 being downhill of loadmaster 2. Loadmaster 1 observed loadmaster 2 step toward the load, reach up, take hold of the tagline and immediately step back out to regain their 45˚ spacing. Loadmaster 1 reported that the load was about 5 m above the ground at this stage and the pilot reported that the end of tagline appeared to be near the ground.

Loadmaster 1 reported that as loadmaster 2 returned to their position, the slight forward motion of the load stopped and the load moved back slightly towards the rising ground. As the load moved back, the load detached unexpectedly from the hook.

It was reported that as the load fell, it seemed like one end of the load fell faster than the other and after it struck the ground, the load either bounced or pivoted around. Both loadmasters had to scramble backwards away from the load but the movement resulted in loadmaster 2 being struck by the drill rods and knocked to the ground under the load.

The pilot reported that he felt the helicopter ‘pop up a bit’ and thought that a sling had snapped as he had not released the load. Loadmaster 1 advised that he did not hear the ‘clack’ sound associated with the solenoid release of the hook (see the section titled Remote Cargo hook). He advised that the sound of the solenoid activation was audible over the helicopter noise and while wearing a helmet.

Loadmaster 1 spoke to the helicopter pilot on the radio and advised him that the sling had not separated, the hook was useable and to bring the helicopter back to lift the load. The pilot re‑positioned the helicopter and loadmaster 1 re‑connected the load, which was then lifted off the seriously injured loadmaster.

Remote cargo hook

The remote cargo hook used by the operator of HUE was a TALON 6K half-cage cargo hook (Figure 2). This was the first operational use of this hook following a recent overhaul and was also the first time the helicopter (HUE) was used with this long line and remote hook combination.

The load beam on the remote cargo hook can be made to release by two methods:

  • a pilot-activated switch on the cyclic, which activated a solenoid in the hook to release the load beam
  • a manual release on the hook itself.

The hook and long line inspections conducted prior to the flight, included a number of activations of both of these release systems.

The pilot advised that, due to a previous injury to his hand, he had to deliberately move his hand to the top of the cyclic and move the switch sideways to activate the hook. As such, unintended load release by that mechanism was considered very unlikely. The ATSB viewed video footage of the helicopter pilot operating the switch at the top of the cyclic, which supported that conclusion.

The keeper was designed to allow items to enter the hook throat but not return. It opened toward the inside of the load beam and had a spring-loaded automatic return to the closed position.

Loading equipment examination

The slings, shackle and hook were examined by the ATSB. The inspection of the slings determined they were intact. To check that the load had not released through dynamic rollout,[2] the ATSB ensured that the hook and shackle combination did not allow the shackle to pass the end of the load beam. The cargo hook owner’s manual specified that the shackle used with this hook should have an inside diameter less than 11.4 cm. The internal diameter of the shackle used was 5.5 cm. A physical examination of the hook was conducted and it was determined that the manual release and the keeper worked as expected. The ATSB did not dismantle the hook or connect the hook to an electrical supply.

The ATSB examined video footage of the helicopter lifting the load from the loading site. It showed that the ‘D’ shackle was behind the keeper (Figure 4) when the helicopter departed and that the load was evenly balanced as the helicopter flew towards the drill site (Figure 3).

Figure 4: Image shows that the ‘D’ shackle was behind the keeper

Figure 4: Image shows that the ‘D’ shackle was behind the keeper.
The image shows that on departure after the load had been adjusted, the ‘D’ shackle was behind the keeper.
Source: Helicopter operator A, annotated by the ATSB

The image shows that on departure after the load had been adjusted, the ‘D’ shackle was behind the keeper.

Source: Helicopter operator A, annotated by the ATSB

Electromagnetic interference

The ATSB also considered whether electromagnetic interference (EMI) could have resulted in the inadvertent release of the load. While this accident occurred in an area which has high voltage power lines from the Tumut 3 power station, the aircraft was about 35 km from the power station and 10 km from the closest high voltage power lines. Research suggests that magnetic radiation returns to normal levels at about 150 m from power lines.

A licenced aircraft maintenance engineer inspected the electrical system used on the helicopter to control the hook release mechanism and they reported that the system was working as expected. It was reported that there were no exposed wires within the system that could have resulted in a short circuit if exposed to electromagnetic interference from equipment in the aircraft. The helicopter operator also reported that the system has not had any issues with the hook release system since the accident.

Procedures used for this operation

The ATSB reviewed the procedures used by the different operators involved on the project on the day. The lead contractor had conducted a risk assessment of the overall project, which involved all of the contractors involved.

Operator A had completed a helicopter lift plan for the day and a safe work method statement that identified hazards and the mitigations for lifting operations. There were a number of areas in the procedures indicating that no one should be located below the suspended load. The procedures also specified that people should not be within the ‘crush zone’ but did not identify where the crush zone was. The operator advised that the crush zone was dependent on a number of job-specific variables, including the load shape and size, and the length of sling required. While there was no specific section in the safe work method statement to prompt this discussion, the loadmasters worked together to rig the loads, adding tag lines where required, and so were aware of the individual load’s size, shape and aerodynamic stability.

Safety analysis

The ATSB considered a number of inadvertent load release mechanisms, including:

  • the pilot release system
  • dynamic rollout
  • failure of the manual load release
  • electromagnetic radiation
  • failure of the hook mechanism.

A previous injury meant that accidental release by the pilot was unlikely and the loadmaster did not hear the audible ‘clack’ of the solenoid, associated with operation of the pilot‑activated release.

The shackle was the appropriate size, to ensure a dynamic rollout would not occur. The video footage shows that the ‘D’ shackle was securely behind the keeper as the helicopter departed from the loading area.

While flying in an area of electricity production, the helicopter was 35 km from the closest power station and around 10 km from the closest power lines. The wiring was also checked and there were no bare or loose wires in the system. If the load had released through EMF activation of the release system, the loadmasters would have heard the ‘clack’ of the solenoid releasing.

There were no indications that the remote hook release mechanism was faulty after the previous overhaul and the pilot and loadmasters conducted an operational check of the mechanism before operations began on the day. It also successfully lifted the two previous loads and lifted the load off the loadmaster after the incident. In addition, the manual release mechanism operated correctly at the ATSB facility and an examination of the hook release electrical system in the helicopter did not reveal any faults. Despite this, a transient hook fault that resulted in an inadvertent release of the load could not be ruled out.

In summary, based on the available evidence, the mechanism that led to the release of the load could not be determined.

Immediately prior to the accident, the load was being positioned without needing to be adjusted. The plan was that it would touch the ground and then be lifted to knee height before being moved to its final position. Therefore, being in the vicinity of the load when it was above head height was an unnecessary risk.

When the load released, one end fell first and there was likely a movement back toward the rising ground. The loadmasters were reportedly standing to the side and at 45˚ angles from the load, but they were still close enough for one of them to be struck when the load pivoted.

The procedures and briefings for the operation contained several references for individuals not to place themselves in a dangerous position with respect to the load. While the extent of the crush zone was not defined in general, there were a number of variables unique to each job that made this difficult. The opportunity to discuss these aspects was during the briefing, although there was no discussion on the specific loads in this instance. Despite this, the loadmasters did discuss and adjust the different loads, adding tag lines where required. This would imply they were aware of the load size, weights and aerodynamics of specific loads for this job.

ATSB comment

In response to a previous accident, CASA released Airworthiness Bulletin, AWB 25-006 Issue 2, which provided advice to operators involved in sling load operations. While not directly relevant to this occurrence, it details important information relating to external sling load operations. This included information related to the inadvertent release of the load through the use of the incorrect shackle size and electromagnetic radiation (EMI).

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The load released from the hook unexpectedly for reasons that were not determined.
  • The loadmasters were not maintaining a safe distance from the load. Their positioning, in combination with the significant movement of the load as it contacted the ground, resulted in the loadmaster being struck and seriously injured.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

As a result of this accident, all the contractors jointly reviewed the processes used on this project. They determined that the existing documentation contained sufficient warning for personnel to not enter the ‘crush zone’ or ‘work under loads’, but also identified enhancements to the existing processes. This included a control that removed all people (including loadmasters) from the receiving area where there was no requirement for precision in the placing of the load and increased controls where a precision placement of the load was required.

Helicopter operator who supplied the loadmasters

Operator A advised the ATSB that they have reviewed their own safe work method statement and made changes including identifying a ‘dynamic exclusion zone’[3] under the moving helicopter. Recognising that the zone may vary due to a number of variables, the intention is that specific guidance will be provided as part of pre‑activity briefings.

Lead contractor

The lead contractor is overseeing a range of initiatives, including a behavioural safety review of the project with the intention to implement an appropriately designed program to positively influence behaviours across their projects.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Daylight Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. Dynamic rollout: An uncommanded release of the load can occur when the internal diameter of the shackle is big enough to pass over the tip of load beam, opening the keeper and releasing the shackle.
  3. Dynamic exclusion zone: A dynamic exclusion zone is a position above a person’s head height that is in the pathway of a potential uncontrolled load that may drop and impact onto a person.

Occurrence summary

Investigation number AO-2019-003
Occurrence date 10/01/2019
Location 39 km south-east of Talbingo
State New South Wales
Report release date 10/03/2020
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Loading related
Occurrence class Accident
Highest injury level Serious

Aircraft details

Manufacturer Bell Helicopter Co
Model Textron 205A-1A
Registration VH-HUE
Serial number 30290
Aircraft operator O'Driscoll Aviation
Sector Helicopter
Operation type Aerial Work
Departure point Near Tantangara Dam, New South Wales
Destination Near Tantangara Dam, New South Wales
Damage Nil

Loss of power on take-off and forced landing involving Cessna 182, VH-DGF, Tooradin, Victoria, on 6 January 2019

Final report

Report release date: 31/01/2020

Safety summary

What happened

On the morning of 6 January 2019, a Cessna 182G, registered VH-DGF, took off from Tooradin Airfield to conduct parachuting operations. The pilot reported that soon after take-off, at about 400 ft above the ground, the engine sustained a sudden power loss. After being unable to resolve the problem, the pilot conducted a forced landing in a nearby paddock.

During the forced landing, the aircraft collided with trees and a fence, which resulted in substantial damage. There were no injuries.

What the ATSB found

The ATSB found that the carburettor contained aluminium oxide corrosion deposits which, when loosened, likely blocked fuel flow within the carburettor, resulting in the aircraft engine losing power. Periodic inspections (every 100 hours or 12 months) play a vital role in ensuring the serviceability of an aircraft’s engine, and these inspections had a requirement to drain and flush the carburettor. However, the extent to which this action was actually conducted during the six inspections since the engine and carburettor were overhauled could not be determined.

The engine had periods of inactivity over the preceding years, and maintenance on the engine had not always been conducted at the appropriate time intervals. However, it was not possible to determine exactly when the corrosion started and propagated.

After the engine lost power, the decision by the pilot to conduct a forced landing rather than turn back to the departure runway minimised the risk of loss of control during the forced landing.

The pilot was not wearing an upper torso restraint (UTR), but fortunately was not injured on this occasion. However, by not wearing his UTR, he significantly exposed himself to unnecessary injury risk.

What's been done as a result

The operator advised that it intends to direct pilots to wear upper torso restraints and that this requirement will be incorporated into its training and induction schedule.

Safety message

Corrosion was able to form within the carburettor that was not prevented or detected. This occurrence highlights the importance of following the maintenance program for the aircraft. Particularly in this case, this included draining and flushing the carburettor at its periodic inspection.

When available, upper torso restraints should be worn. While the pilot was uninjured during the accident, a substantial amount of research has shown that wearing an upper torso restraint significantly reduces the risk of injury compared to lap belts only.

 

The occurrence

Pre-flight preparation

On the morning of 6 January 2019, the pilot of a Cessna 182G, registered VH-DGF, prepared the aircraft for parachuting operations for Skydive south-east Melbourne at Tooradin Airfield, Victoria. The single-engine aircraft had been refuelled from the bowser at the airfield on the previous day.

The pilot reported that, on the morning of the flight, he checked the quantity of fuel on board by dipping the aircraft’s fuel tanks with a calibrated dipstick. He also conducted a normal pre-flight inspection of the aircraft, which included conducting a water drain check of each of the aircraft’s three fuel drains.

After conducting the pre-flight inspection, the pilot started the aircraft’s engine and taxied to the apron area. He allowed the engine to warm and carried out further operational checks. When complete, he repositioned the aircraft to pick up parachutists for the first sortie of the day. However, the flight was then delayed for about 90 minutes by unsuitable weather.

The passenger load consisted of a tandem master, a tandem passenger and two sport parachutists.

Take-off and engine power loss

The pilot conducted the take-off at about 1045 Eastern Daylight-saving Time,[1] toward the south-west. As the aircraft passed over the end of the runway, he raised the flaps and continued to climb.

The pilot reported that, at about 400 ft above ground level, there was a sudden loss of power and aircraft climb performance, and he observed the propeller was windmilling[2] without sound. He later described the power loss as being similar to the mixture control being pulled back. A witness at Tooradin Airfield recalled that the power loss sounded like a sudden closing of the throttle and there was no rough running.

The pilot lowered the aircraft nose and identified a suitable area to make a forced landing which required a heading change of about 45º to the west. He checked the engine controls and fuel selector were correctly configured and had not been disturbed by parachutists entering the aircraft.

The pilot recalled that he conducted a flapless approach at about 70 kt to the identified landing area. During the descent, he instructed the passengers to prepare for a forced landing.

The aircraft touched down in a relatively flat, open paddock. It initially bounced on the unprepared surface before settling on the ground and passing through two boundary fences. The pilot attempted to slow the aircraft and manoeuvre to avoid trees. As the aircraft passed through a gap in the trees, the left-wing strut collided with a tree, which resulted in the left wing folding over on top of the right wing and fuel leaking from it onto the fuselage. The aircraft further collided with a third fence, crossed a private road, and collided with a fourth fence, which collapsed the nose landing gear (Figure 1).

Figure 1: Accident site of Cessna 182, registered VH-DGF

Figure 1: Accident site of Cessna 182, registered VH-DGF. Source: Victoria Police.

Source: Victoria Police.

Egress from the aircraft

The pilot ordered the passengers to evacuate. Both doors were displaced open during the accident sequence and an interior panel from the rear of the cabin had propelled forward onto the parachutists. The panel obstructed emergency egress and was removed by the pilot.

The sport parachutist located at the right[3] rear position attempted to egress the aircraft but had not released his single-point restraint. After doing so, he was first to egress. The sport parachutist located at the right forward position also had not released his restraint prior to attempting egress. After doing so, he was next to egress. The tandem passenger was assisted out of the aircraft, followed by the tandem master and the pilot. Video footage showed that, after the aircraft came to rest, it took about 20 seconds for the occupants to egress.

The pilot returned to the aircraft to confirm the master switch and magnetos were off. The passengers and pilot moved away from the aircraft and waited for emergency services to arrive.

The aircraft was substantially damaged and there were no injuries.

__________

  1. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. Windmilling: a rotating propeller being driven by the airflow rather than by engine power, and results in increased drag at normal propeller blade angles.
  3. As viewed looking forward.

Context

General aircraft information

The Cessna 182G is a high-wing, all-metal, unpressurised aircraft with a fixed landing gear. It has a single, reciprocating piston engine driving a constant speed propeller.

VH-DGF was manufactured in 1964 and was first registered in Australia in 1965. The aircraft was reconfigured for parachuting operations in 2017.

The Cessna 182G has two fuel tanks, one in each wing. Fuel from each tank is gravity-fed to the fuel selector valve. Depending on the setting of the valve, fuel from the left tank, right tank or both tanks flows through a fuel strainer (also known as a ‘gascolator’), then the carburettor and the engine.

The Cessna 182G Owner’s Manual stated that pilots should take off with the fuel selector in the BOTH position. The pilot reported that the fuel selector was in the BOTH position during the take-off. Video footage taken during part of the accident flight confirmed that the fuel selector was in the BOTH position, and the fuel tanks indicated that sufficient fuel was on board.

A review of the video footage identified that the mixture was full rich and the carburettor heat was off during take-off. However, a review of the meteorological conditions and other information at the time of the occurrence indicated that the risk of carburettor icing was low.

The aircraft was within the required weight and balance limitations.

Examination of the aircraft and components

The ATSB did not attend the accident site or conduct a detailed examination of the engine. Examination by other parties did not identify any problems with the aircraft’s fuel system or the engine itself. However, a significant amount of debris was recovered from the fuel strainer, the carburettor float bowl and directly below the carburettor nozzle and main jet assembly. The debris in the fuel strainer appeared to include a range of different foreign materials.

The carburettor and the recovered material were examined by the ATSB. Most of the recovered material had a white, chalky appearance and ranged in size up to 5 mm. Inside the carburettor bowl, a significant amount of the material had accumulated at the drain area, and a 'tide' line was visible on the sides of the drain area. The inside surface of the bowl exhibited pitting corrosion where the material had dislodged (Figure 2).

A small amount of similar white chalky material was also observed on a ‘dip’ in the carburettor bowl, slightly above the drain. Other than the areas described, the internal surfaces of the bowl appeared to be relatively clean and in good condition, although some other foreign material was observed in the bowl.

ATSB analysis of the debris found in the carburettor showed that it was primarily comprised of aluminium and oxygen. It was considered likely that the particles were aluminium oxide, a corrosion product from the aluminium carburettor bowl.

Figure 2: Material inside the carburettor bowl of VH-DGF

Figure 2: Material inside the carburettor bowl of VH-DGF. Source: ATSB.

Source: ATSB.

Engine history

The engine fitted to VH-DGF at the time of the accident was originally fitted to another Cessna 182, registered VH-EIZ. In December 2011 the engine (serial number 67386-7-R) and carburettor (serial number H-11-5085) were removed, overhauled and refitted to VH-EIZ.

In October 2016, the engine and carburettor were removed from VH-EIZ for fitment to VH-DGF. At that time the engine had accumulated 328.1 hours since overhaul. VH-DGF was rebuilt over a 2-month period, and a maintenance release was issued in early January 2017.

No flights were documented on the maintenance release during:

  • the 4-month period from early January to early May 2017
  • the 3-month period from mid-May to mid-August 2017
  • the 7 weeks up until the end of January 2018.

Other than these periods of inactivity between October 2016 and August 2017, the lowest utilisation of the engine since last overhaul was 44.5 hours over an 18-month period between 2013 and 2014.[4]

The last periodic (100-hourly) inspection was carried out on 30 May 2018 at 7,730.1 airframe hours and 393.9 engine hours since overhaul. At the time of the accident, the engine had accumulated 438.4 hours since overhaul.

Between the overhauled engine commencing service in 2011 and the accident, six periodic inspections were conducted which examined the engine (four inspections when it was fitted to VH‑EIZ and two when fitted to VH-DGF).

Periodic maintenance requirements

The aircraft was being maintained in accordance with Civil Aviation Safety Authority (CASA) maintenance schedule 5 and all airworthiness directives applicable to the aircraft.[5] Maintenance schedule 5 outlined requirements for daily inspections (conducted prior to the first flight of each day) and periodic inspections (conducted every 100 hours or 12 months, whichever came first).

The periodic inspection requirements included a requirement to ‘drain and flush the carburettor fuel bowl and refit the plug and lockwire’. This requirement was reiterated in a number of advisory publications.[6]

The six periodic inspections carried out after the engine was overhauled were conducted by four different maintenance organisations. Maintenance records from these periodic inspections indicated that the task of draining and flushing the carburettor had been conducted. During interviews, personnel from three of these maintenance organisations noted that, although this task was required for every periodic inspection, they were aware that it was not always carried out.

A review of the recent maintenance releases for VH-DGF identified a number of anomalies:

  • The second last periodic inspection and maintenance release were certified for on the 3 and 4 January 2017. The aircraft was ferried to Queensland on 11 December 2017 to be used by another parachuting operation. The maintenance release expired on 3 January 2018, after which the aircraft was used for numerous flights (totalling 4.2 hours flight time) during the period from 27 January until 25 March 2018. As the maintenance release was expired, a special flight permit[7] was issued and the aircraft ferried from Seventeen Seventy to Caboolture on 18 April 2018 (2.1 hours flight time). A second special flight permit was issued and the aircraft was ferried to Tyabb, Victoria, on 26 May 2018 which involved approximately 6.5 hours flying. In summary, based on documented records, the aircraft was operated for 12.8 hours over a period of 4 months without a valid maintenance release (and without a periodic inspection having being conducted within the previous 12 months).
  • Between periodic inspections, oil and oil filter changes were required. The requirement for the engine fitted to VH-DGF was for an oil and oil filter change after 50 hours flight time or 4 months (whichever came first), and any such change had to be certified on the maintenance release. The second last maintenance release showed two oil and oil filter changes. The first was on 11 December 2017, 11 months since the last periodic inspection. The second occurred on 22 May 2018, 5 months after the previous oil and oil filter change.
  • The last periodic inspection occurred on 30 May 2018, with a maintenance release issued on the same day. The maintenance release included a requirement to test the pitot static system as per Civil Aviation Order 100.5 (required every 24 months) by 4 January 2019. There was no annotation on the maintenance release to indicate that the inspection was conducted prior to the accident flight (6 January 2019).
  • On the last maintenance release there was a requirement to carry out an oil and oil filter change on 30 September 2018, however there was no record of this being done.

Engine storage requirements

CASA Airworthiness Bulletin AWB 85-021 (Piston engine low utilisation maintenance practices) stated:

It is widely acknowledged that piston engines that are not flown frequently are susceptible to damage from corrosion and contamination, which may adversely affect their expected service life.

Susceptibility to corrosion is influenced by a number of factors, including but not limited to, geographical location, season, usage and storage.

When a piston engine is exposed to adverse environmental conditions such as coastal areas and areas of high relative humidity, corrosion attack can occur within a few days. Conversely, engines under more favourable environmental conditions can remain inactive for several weeks without evidence of damage by corrosion.

Experience has shown that the best course of action to reduce the likelihood of corrosion attack on engine internal surfaces is to fly the aircraft regularly. In circumstances where this action is not possible engine preservation procedures have been promulgated within engine manufacturer’s instructions for continuing airworthiness to combat and minimise the corrosion condition a direct result of engine inactivity…

In general, manufacturers recommend that for engines which won’t be flown for 30 days or more, a preservation regime should be instigated.

The need for engine preservation should be evaluated by the aircraft operator having regard to the prevailing environmental conditions and period of aircraft inactivity.

The aircraft manufacturer (Cessna) specified various maintenance actions if an engine was not being utilised for various periods of time. For periods up to 30 days (flyable storage) and 90 days (temporary storage), there was no required actions for preserving the carburettor, whereas there were such requirements for indefinite storage periods.

The engine manufacturer (Continental Motors) advised[8] operators to inject corrosion preventative oil into the carburettor while the engine is running for:

an engine, which has been in operation, is to be stored much longer than a week under normal climatic conditions…

There was no indication in the aircraft’s maintenance records regarding whether any storage or preservation measures were applied to the aircraft’s engine during the periods of inactivity from October 2017 until January 2018.

Related occurrence

On the 14 February 2017, a Yakovlev 52 experienced a loss of engine power en route to its destination. While conducting a forced landing, the aircraft collided with a tree, pitched down and collided with the ground. The pilot was seriously injured and the aircraft was substantially damaged.

The Belgian Federal Public Service Air Accident Investigation Unit investigated the accident[9] and found:

The engine loss of power was most probably caused by the internal corrosion of the carburettor which partially blocked the fuel flow at the pressure regulator valve. The corrosion of the magnesium alloy casing of the carburettor was likely caused by water contamination.

Occupant restraint

Pilot seat

Civil Aviation Safety Regulations 1998 (CASR) 90.105 required that the seats in the front row of an aircraft must be fitted with an approved safety harness. For small aeroplanes (with maximum take-off weight less than 5,700 kg) and helicopters, the safety harness needed to consist of a lap belt and at least one shoulder strap.

The pilot’s seat of VH-DGF was fitted with a lap belt and upper torso restraint (UTR),[10] consistent with the regulatory requirements. Given the age of the aircraft, the UTR did not have an inertia reel (that is, when fitted correctly it was fixed in position and the person’s movement was somewhat restricted). On the accident flight, the pilot wore the lap belt but the UTR was stowed in the seat pocket. The pilot noted that he was 165 cm tall and, when the UTR was worn and correctly adjusted, he could not reach the fuel selector or cowl flaps.

Previous ATSB investigations have found that pilots or passengers in the front seats of small aeroplanes and helicopters have not always worn the available UTRs, exacerbating the severity of their injuries in many accidents (for example, ATSB investigations 199800442, 200605133, AO-2010-053, AO-2012-083, AO-2012-142 and AO-2016-074).

A substantial amount of research has consistently shown that seat belts in small aircraft that include a UTR significantly reduce the risk of injury compared to lap belts only. UTRs minimise the flailing of the upper body and reduce the risk of impacts involving the head and upper body.

For example, a safety study by the United States’ National Transportation Safety Board (NTSB) in 1985[11] examined 535 accidents involving small aircraft in 1982.[12] The NTSB estimated that 20 per cent of the 800 fatally injured occupants would have had only serious injuries or minor injuries if they had been wearing a UTR. In addition, 88 per cent of 229 seriously injured occupants would probably have had less severe head or upper body injuries, only minor injuries or no injuries if they had been wearing a UTR.

A 2011 safety study by the NTSB[13] examined the rate of serious and fatal injuries of pilots in single-engine aeroplanes during the period 1983–2008. It found that pilots wearing only a lap belt had a 49 per cent greater likelihood of a serious or fatal injury compared with pilots wearing a lap belt and a UTR. Another study which examined take-off and landing accidents involving an engine power loss during 1983–1992 found that pilots wearing only a lap belt were 70 per cent more likely to be fatally injured than pilots wearing a seat belt and a UTR.[14]

Parachutists

Civil Aviation Regulation (CAR) 251 (Seat belts and safety harnesses) required seat belts to be worn during take-off and landing, during instrument approaches, when the aircraft was flying less than 1,000 ft above terrain and at all times when in turbulent conditions. CAR 251 had provision to change the type of restraint. In the case of aircraft used for parachuting operations, this was usually a single-point restraint.

Civil Aviation Order (CAO) 20.16.3 (Air service operations – carriage of persons) stated:

Where a parachutist is not provided with a seat of an approved type, he or she shall be provided with a position where he or she can be safely seated.

Except when about to jump, parachutists were required to wear a seat belt, safety harness or parachute that was connected to an approved single-point restraint.

Additionally, the Australian Parachute Federation (APF) Operational Regulations, section 5.2.4, required an aircraft used for parachuting to be fitted with sufficient parachutist restraints that are manufactured to a standard approved by CASA and the APF, labelled accordingly, or have sufficient aircraft seats and seatbelts.

The ATSB and other investigation agencies have previously expressed concern about the suitability of single-point restraints for parachuting operations, with research showing that dual-point restraints offer occupants better protection in the event of an accident. In addition, in some previous take-off accidents, parachutists were not wearing the single-point restraints.[15]

The requirements of CAR 251, CAO 20.16.3 and APF regulation 5.2.4 were met by the operator of VH-DGF by using an approved single-point restraint for each parachutist. The parachutists on board the accident flight were wearing the approved single-point restraints during the accident flight.

__________

  1. Records for monthly utilisation were not available to be examined when the engine was fitted to VH-EIZ.
  2. Civil Aviation Regulation (CAR) 42B stated that the certificate of registration holder could maintain a class B aeroplane in accordance with CASA’s maintenance schedule. Class B aeroplanes included all aeroplanes except transport category aeroplanes used for regular public transport operations.
  3. These include the United States’ Federal Aviation Administration’s Advisory Circulars AC 20-106 and AC 20-125, Special Airworthiness Information Bulletin SAIB CE-10-40R1, and the Civil Aviation Safety Authority’s Airworthiness Bulletin AWB 28-008 (Water contamination of aviation fuel).
  4. Special flight permits are issued under CASR 21.200 for individual aircraft which for a variety of possible reasons may not meet the airworthiness requirements under the Civil Aviation Act, Civil Aviation Regulations (CASR 1998 and CAR 1988), and Civil Aviation Orders.
  5. Continental O470 Maintenance and Overhaul Manual, 4-12 Preparation for storage.
  6. AAIU-2017-AII-02 Safety Investigation Report – Yakovlev 52 at Couvin, Belgium, on 14 February 2017.
  7. Upper torso restraint: a shoulder strap or harness. A shoulder strap, when paired with a lap belt, effectively makes the occupant’s restraint similar to the seat belt on modern cars.
  8. National Transportation Safety Board 2005, General aviation crashworthiness project: Phase two – Impact severity and potential injury prevention in general aviation accidents, Safety Report NTSB/SR-85/01.
  9. The selected accidents included those where at least one occupant was fatally or seriously injured. The accidents were evaluated to determine the extent to which they were survivable, based on whether one occupant either survived or could have survived if shoulder harnesses or energy-absorbing seats were used. The data suggested that a survivable envelope was defined by impact speeds of 45 kt at 90º angle of impact, 60 kt at 45º angle of impact and 75 kt at 0º angle of impact.
  10. National Transportation Safety Board 2011, Airbag performance in general aviation restraint systems, Safety Study NTSB/SS-11/01.
  11. Rostykus PC, Cummings P & Mueller BA 1998, ‘Risk factors for pilot fatalities in general aviation airplane crash landings’, Journal of the American Medical Association, vol. 280, pp.997-999.
  12. ATSB investigation AO-2014-053, Loss of control involving Cessna Aircraft Company U206G, VH-FRT, Caboolture Airfield, Queensland, 22 March 2014.

Safety analysis

Engine power loss

The available evidence indicates that there was sufficient fuel on board the aircraft for the flight, the risk of carburettor icing was low and there appeared to be no mechanical defects with the engine.

The Cessna 182 fuel system was designed to provide gravity-fed fuel, free from contamination, to the carburettor. There are multiple components that remove contamination, such as filters and drain points. After the fuel has entered the carburettor bowl, there are no further defences in place prior the fuel being atomised for combustion.

The carburettor fitted to VH-DGF contained aluminium oxide corrosion deposits. These were of sufficient size such that, when loosened, they probably blocked fuel flow within the carburettor, resulting in the aircraft engine suddenly losing power shortly after take-off.

As the carburettor bowl is on the ‘downstream’ side of the defences to prevent contamination, there are maintenance and storage processes to ensure its serviceability. The corrosion was probably able to form in the carburettor bowl during periods of inactivity. However, it was not possible to determine exactly when the corrosion started and propagated.

Periodic inspections (every 100 hours or 12 months) play a vital role in ensuring the serviceability of an aircraft’s engine, and these inspections had a requirement to drain and flush the carburettor. However, the extent to which this action was actually conducted during the six inspections since the engine and carburettor were overhauled could not be determined.

Maintenance overrun

It was also noted that a periodic inspection was not conducted at the required interval. A periodic inspection was required by 3 January 2018, but was not conducted until 30 May 2018. During the period from 27 January 2018 to 25 March 2018, the aircraft was flown without a valid maintenance release, and a further two flights conducted under special flight permits. However, given the last periodic inspection was done 7 months prior to the accident, the extent to which this previous omission contributed to problems with the carburettor was unclear.

There was also no indication on the last maintenance release that oil and oil filter changes were being conducted every 4 months. However, these omissions (if they occurred) should not have had an impact on the condition of the carburettor.

Use of occupant restraints

In general, the forces transmitted to occupants in light aircraft involved in an accident are higher than those transmitted in large transport aircraft involved in an accident. This is primarily due to the lack of protection from a crushable fuselage structure and therefore reduced energy absorption in a small aircraft.

A substantial body of research has shown that the risk of serious and fatal injuries can be significantly reduced if the occupants of small aircraft wear upper torso restraints (UTRs). In this case, the pilot was wearing a lap belt but not wearing the UTR.

It was fortunate that the pilot was not injured on this occasion. However, by not wearing his UTR, he significantly exposed himself to unnecessary injury risk. Noting that a UTR without an inertial reel can be restrictive, this should not prohibit the use of UTRs during critical phases of flight, such as take-off and landing.

Preparation for an emergency landing

During the accident flight, the parachutists were wearing the single-point restraints and given the relatively low impact forces, the restraints were sufficient to minimise injury risk during the forced landing.

However, after being ordered to evacuate by the pilot, the parachutists adjacent to the right door attempted to exit the aircraft without releasing their single-point restraints, delaying the egress of all on board. Fuel leaking from the damaged left wing of the aircraft increased the likelihood of a post-accident fire, and therefore the importance of rapid evacuation.

In this case, the parachutists knew how to undo their restraints, and would have been aware of the required actions for exiting the aircraft in the case of an emergency during take-off. However, this investigation highlights the additional benefits of mentally rehearsing the required actions immediately prior to or during take-off. According to the Civil Aviation Safety Authority’s Cabin safety bulletin 12 – General aviation passenger briefings (October 2018):

Survivors of aircraft accidents have provided anecdotal evidence as to the importance of their recollection of information… Adequately briefed passengers, who understand how to help themselves, will assist in the quick and successful evacuation of an aircraft.

Pilot response to the engine power loss

Airborne emergencies can be dynamic, fast-paced, and place a high cognitive workload on the pilot. When confronted with an airborne emergency, a pilot’s hierarchical priorities are to ensure the aircraft remains in controlled flight, navigate (in this case to a suitable landing area) and, if time permits, communicate the nature of the emergency to authorities enabling them to respond appropriately.[16]

Standard flight training and guidance for pilots is to land straight ahead, or within 30º either side of straight ahead, following an engine failure or power loss at a low height. Pilots are also taught to only consider a turnback manoeuvre once they have achieved a minimum height, which may vary depending on the aircraft type and other factors.

A substantial amount of guidance material has been published about managing engine failures after take-off, and such guidance material continually emphasises the importance of not considering a turnback until a pre-determined safe altitude has been reached. For example, a recent article in CASA’s Flight Safety Australia publication[17] (Stobie 2019) provided the following guidance:

Something that should have stuck from basic training was that you should never turn back following engine failure immediately after take-off. There’s good reason for this lesson—countless fatal accidents have involved pilots unsuccessfully attempting to turn back to the airport following an engine failure on upwind at low level. It’s often labelled the impossible turn, and it’s a procedure fraught with risk.

In this case, when the power loss occurred at about 400 ft, the pilot correctly assessed there was insufficient height to conduct a turnback to the departure runway. He selected a suitable landing area off the airfield 45º to the right of his current heading which, given the height of the aircraft, was able to be reached safely. The pilot automatically lowered the nose of the aircraft to maintain controlled flight and attain best glide speed, and he then focussed on navigating the aircraft to the suitable landing area.

With the limited time and height available, the pilot displayed sound airmanship and decision-making by conducting a forced landing and accepting the risk of a minor accident, rather than turning back and risking a loss of control and an accident involving much more serious consequences.

__________

  1. These hierarchical priorities are colloquially known as ‘aviate, navigate, communicate’.
  2. Stobie N 2019, ‘Your one and only: Mitigating the risk of engine failures in singles’, Flight Safety Australia, uploaded March 2019. Available from www.flightsafetyaustralia.com.

Findings

From the evidence available, the following findings are made with respect to the loss of power on take-off and forced landing involving a Cessna 182, registered VH-DGF at Tooradin Airfield, Victoria on 6 January 2019. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • The carburettor contained aluminium oxide corrosion deposits which, when loosened, likely blocked fuel flow within the carburettor, resulting in the engine losing power shortly after take-off.
  • The engine had periods of inactivity over the preceding years, and corrosion was able to form within the carburettor that was not prevented or detected by maintenance providers during periodic inspections (every 12 months or 100 hours flight time).

Other factors that increased risk

  • During the period from 27 January 2018 to 25 March 2018, the aircraft was flown without a valid maintenance release, and a further two flights conducted under special flight permits, without a periodic inspection having been conducted in the previous 12 months.
  • The pilot was not wearing an upper torso restraint during the accident flight, thereby increasing the likelihood of serious injury during the forced landing.
  • The parachutists adjacent to the door attempted to exit the aircraft without releasing their single-point restraints, delaying the egress of all on board.

Other findings

  • After the engine lost power, the decision by the pilot to conduct a forced landing rather than turn back to the departure runway minimised the risk of loss of control during the forced landing.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Aircraft operator

The operator advised that it intends to direct pilots to wear upper torso restraints and that this requirement will be incorporated into its training and induction schedule.

Australian Parachute Federation

As a result of a separate occurrence prior to the accident involving VH-DGF, the Australian Parachute Federation has advised the ATSB that in February 2019 it distributed ‘Continuing Improvement Package 4 – Aircraft Emergency and Evacuation Procedures’ to 60 parachuting clubs to incorporate into their operations and to prompt discussion on the subject.

The aims of the package were to:

  • reduce the risk and resultant injuries in the event of an aircraft emergency
  • discuss procedures in the event of aircraft emergency and/or evacuation
  • discuss multiple aircraft emergency and evacuation scenarios
  • implement aircraft evacuation training/drills.

Additionally, the Australian Parachute Federation advised in January 2020 that it was in the process of conceptualising a dual point, single release restraint.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the pilot of VH-DGF
  • the parachuting school that was operating the aircraft (Skydive South East Melbourne)
  • various maintenance providers
  • Civil Aviation Safety Authority
  • the carburettor manufacturer (Marvel).

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the pilot, the aircraft operator / parachuting school (Skydive South East Melbourne), the maintenance organisation that conducted the last periodic inspection on the aircraft, the carburettor manufacturer (Marvel, via the United States National Transportation Safety Board (NTSB)), the engine manufacturer (Continental, via the NTSB), the aircraft manufacturer (Cessna, via the NTSB), Civil Aviation Safety Authority and the Australian Parachute Federation (APF).

Submissions were received from the pilot, aircraft operator / parachuting school and APF. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2019-002
Occurrence date 06/01/2019
Location Near Tooradin Airfield
State Victoria
Report release date 31/01/2020
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Engine failure or malfunction
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model 182G
Registration VH-DGF
Serial number 18255755
Aircraft operator Skydive South East Melbourne
Sector Piston
Operation type Sports Aviation
Departure point Tooradin Airfield, Victoria
Destination Tooradin Airfield, Victoria
Damage Substantial

In-flight fire involving Kavanagh B-350 hot air balloon, VH-ZYO, near Coldstream, Victoria, on 26 December 2018

Final report

Report release date: 28/06/2019

Safety summary

What happened

On 26 December 2018, a Kavanagh B-350 hot air balloon, registration VH-ZYO, operated as a scenic charter flight by Go Wild Ballooning, departed from Wandin, Victoria with the pilot and 15 passengers on board.

After 20 minutes in flight, and while operating at an altitude of about 800 ft, the pilot recalled hearing a small explosion from the front left burner and observed that a small fire had started on the outside of the burner. The pilot switched off the vapour valve at the fuel tanks to the front two burners and disconnected the hoses.

About a minute later, the pilot attempted to put out the fire using one of two on-board extinguishers, but the fire re-ignited almost immediately. After a further minute, the pilot discharged the second fire extinguisher, but again the fire re-ignited.

Moments later, the pilot’s compartment caught fire. The pilot was wearing a cotton shirt, synthetic vest, rolled-up pants, and rubber slip-on shoes and began to feel uncomfortable with his proximity to the fire. He then moved from the pilot’s compartment to the back left compartment of the basket.

About 8 minutes after the fire started, the pilot identified a suitable landing position and began the approach. During the descent, the basket struck some treetops and the ropes became tangled in the branches. Passengers reported that the branches whipped around and into the basket, with one passenger sustaining cuts to his hand. The pilot freed the ropes from the tree and brought the balloon to rest in the paddock below. As the basket touched the ground, the passengers jumped out and ran to safety.

The fire continued to burn as the pilot secured the balloon. When emergency services arrived on site, flames had engulfed the balloon. By the time firefighters extinguished the flames, the fire had destroyed the balloon.

What the ATSB found

  • The ATSB found that the in-flight fire was the result of a fuel leak at the front left burner. Due to severe fire damage, the source of the leak could not be determined conclusively, but it was considered most likely to be the main ball valve, liquid fire valve or liquid fire valve connection to the main valve block.
  • The hand-wheel valve on the liquid outlet of the fuel tank and the pilot burners were not shut-off, which resulted in the pilot being unable to control the fire. Installation of a 90-degree valve on the liquid fuel outlet may have assisted the pilot to recognise that the liquid fuel valve was not shut-off.
  • In addition, the pilot's clothing did not meet the recommended industry standards for personal protective equipment, which increased the risk to his personal safety.

What's been done as a result

As a result of this occurrence, the Civil Aviation Safety Authority released an Airworthiness Bulletin (AWB 02-063) to address some of the pertinent issues surrounding this occurrence. The AWB included:

  • a recommendation to inspect critical componentry
  • the use of 90-degree shut-off valves for the fuel tank liquid outlets
  • a reminder to close off liquid and vapour valves in the event of a fire
  • a reminder to wear appropriate personal protective equipment.

In addition, Go Wild Ballooning has advised the ATSB that they have replaced all hand-wheel valves with 90-degree valves on all fuel tanks and reviewed the company policy on protective clothing.

Safety message

In the event of an in-flight balloon fire, the first priority is isolation of the fuel supply at the fuel tank. It is good practice to rehearse emergency procedures by standing in the basket to run through the checklist steps.

Further ways to reduce risk to individuals and improve survivability outcomes include:

  • wearing appropriate protective clothing that includes cotton long‑sleeved shirts and long trousers, leather gloves, and enclosed footwear
  • utilising componentry that provides a visual indication of the system status, for example, 90‑degree valves on liquid outlets.

On-board view of in-flight fire involving VH-ZYO

On-board view of in-flight fire involving VH-ZYO. Source: Passenger photo

Source: Passenger photo

 

The occurrence

What happened

On 26 December 2018, at about 0500 Eastern Daylight-saving Time,[1] a Kavanagh B-350 hot-air balloon, registration VH-ZYO, operated as a scenic charter flight by Go Wild Ballooning, was being prepared for departure from Wandin, Victoria.

Prior to take-off, the pilot, together with another ground crew member, conducted the pre-flight check on the balloon, while a ground crew member conducted a safety briefing with the passengers. Neither person inspecting the balloon observed any defects during the pre-flight check.

At 0537, the balloon lifted off with the pilot and 15 passengers on board. After about 15 minutes in flight, the balloon reached an altitude of 4000 ft. The pilot maintained level flight for a few minutes and then began to descend. At about 800 ft, the pilot recalled hearing a small ‘explosion’ from the front left burner (Figure 1) and observed that a small fire had started on the outside of the burner. The passengers observed that the fire was concentrated around the base of the burner, shooting outwards to the front of the basket.

The pilot switched off the vapour valve (see the section titled Aircraft information) at the fuel tanks to the front two burners and disconnected the hoses. Shortly after, the vapour hose connected to the front left burner burnt through and fell away from the burner.

About a minute later, the pilot attempted to put out the fire using one of two on-board extinguishers, but the fire re-ignited almost immediately. After a further minute, the pilot discharged the second fire extinguisher, but again the fire re-ignited. The first flames appeared in the vicinity of the burner can base, towards the front side of the basket, with the flames directed outwards.

Moments later, the pilot’s compartment caught on fire. The pilot was wearing a cotton shirt, synthetic vest, rolled-up pants and rubber slip-on shoes and began to feel uncomfortable with the proximity of the fire. As a result, the pilot moved from the pilot’s compartment to the back left compartment of the basket. The pilot made a call over the radio, repeating MAYDAY[2] three times followed by the balloon registration. Air traffic control acknowledged the call and initiated the appropriate emergency procedures in response.

About 8 minutes after the fire started, the pilot identified a suitable landing position and began the approach. During the descent, the basket struck treetops in the landing area undershoot and the ropes became tangled in the branches. Passengers reported that the branches whipped around and into the basket, with one passenger sustaining cuts to his hand. The pilot freed the ropes from the tree and brought the balloon to rest in the paddock below. As the basket touched the ground, the passengers on the right hand side of the basket jumped out causing the right side of the basket to lift off the ground again. In response, the pilot quickly pulled the red line[3] to evacuate the hot air from the envelope and brought the basket back down to the ground. The remaining passengers then jumped out and ran to safety.

The fire continued to burn as the pilot secured the balloon. When emergency services arrived on site, flames had engulfed the balloon. By the time firefighters extinguished the flames, the fire had destroyed the balloon.

Pilot's comments

The pilot later commented that:

  • he was carrying a long woollen coat in the basket as additional protective clothing, however, it was not accessible
  • he had not been wearing protective gloves, as they had been burnt earlier in the flight, when he had put them aside to adjust the radio
  • during the incident, he followed the priority of, ‘aviate, navigate, communicate’.

Aircraft information

VH-ZYO was a Kavanagh B-350 balloon. The balloon consisted of an envelope, a 16-person basket, a quad burner system and four propane fuel tanks.

Kavanagh Balloons series 3 burner and fuel system

A Kavanagh series 3, quad burner system was installed on the aircraft. The burner unit consisted of four high-pressure propane burners. Each of the burner units had two connections to the fuel tank: a vapour hose (connected to the pilot burner) and a liquid hose, which connected into the burner coil (Figure 1). A standard feature of the system included a secondary burner, known as ‘liquid fire’. This system bypassed the heat exchanger coil and fed liquid propane directly into the burner. The vapour hose drew gaseous propane from the top of the fuel tank and the liquid hose drew liquid propane from the bottom of the fuel tank. The fuel tanks on VH-ZYO had hand-wheel shut-off valves installed at the connections for both the liquid and vapour hoses. The alternative certified configuration was a 90-degree valve. Both valve configurations are shown in Figure 3.

Figure 1: Basket and burner arrangement similar to VH-ZYO

Figure 1: Basket and burner arrangement similar to VH-ZYO. Source: Kavanagh Balloons, annotated by ATSB

Source: Kavanagh Balloons, annotated by ATSB

An illustrated diagram of a burner unit is shown in Figure 2 below.

Figure 2: Illustrated diagram of the burner system on VH-ZYO

Figure 2: Illustrated diagram of the burner system on VH-ZYO. Source: Kavanagh Balloons, annotated by ATSB

Source: Kavanagh Balloons, annotated by ATSB

Figure 3: Valve types on propane tank

Figure 3: Valve types on propane tank. Source: Kavanagh Balloons, annotated by the ATSB

Source: Kavanagh Balloons, annotated by the ATSB

The European Aviation Safety Authority (EASA) has previously published a safety information bulletin (SIB 2018-14) highlighting the advantages of using 90-degree valves over the hand‑wheel valves. EASA recommends operators of hot air balloons use the 90‑degree valves for propane fuel cylinders as they had been found to improve the survivability outcome in the event of fire due to their easy and quick actuation.

Liquid and vapour hoses

The Kavanagh Balloon’s maintenance manual mandates that the liquid fuel hoses have a 10-year life from the date of manufacture. The liquid hoses on VH-ZYO were last replaced in October 2018. Leak checks were conducted as part of the standard replacement procedure and the aircraft had been used multiple times since the replacement.

The liquid hoses were constructed from three layers of material: an inner rubber tubing, an encasing metal braid, and a rubber outer casing. Vapour hoses have a similar construction but do not have a time-limited life.

Main valve block

The main valve block (Figure 2) was an assembly of two solid pieces of aluminium, fastened either side of the main ball valve with four bolt and nut combinations. The liquid fire valve, liquid fuel hose, pressure gauge and cross flow plug each screw into a threaded hole in the main valve block.

Pressure gauge

The manufacturer rated the pressure gauge to a maximum operating pressure of 230 psi,[4] with design testing conducted to around 345 psi. The normal operating range for the series 3 burner (the same burner installed on VH-ZYO) is 50 – 218 psi. The pilot indicated that the system was generally operated at around 180 psi.

Liquid fire valve and main ball valve

The liquid fire valve was a small ball valve, housed in a steel casing, with no replaceable parts. The maintenance manual specified that the valve was to be replaced as a full unit (based on the valve’s condition). Conditions indicating replacement was necessary included seizing of the valve, the valve not shutting off, or signs of leaking.

The main ball valve was a 90-degree, quick shut-off valve, designed to stop the flow of fuel into the burner can.

Kavanagh Balloons flight manual

Mandatory equipment

The flight manual specified that at least one dry powder (1 kg capacity) fire extinguisher must be carried during each flight.

In-flight fire

The manufacturer’s required actions for managing an in-flight fire were:

  • turn off fuel at main tank valves and turn off pilot burners
  • put out fire with the fire extinguisher
  • if it is safe, re-light pilot burner, proceed as normal and make a landing as soon as possible
  • if it is unsafe to re-light the burner, prepare to make an emergency hard landing.

Clothing recommendations

The regulatory bodies in Europe and America have developed guidelines for balloon operators, including the following recommended protective clothing:

  • long sleeves and trousers, preferably made of natural fibres
  • protective footwear
  • leather gloves.

Component examination

The ATSB conducted an examination of a number of balloon components. The examination was severely hindered by the extensive fire damage but the following observations were possible:

  • the burner from which the fire was emanating still had the liquid fire valve, the mini ball valve (vapour pilot burner) and the burner coil attached (Figure 4)
  • the main ball valve was not attached to the coil (Figure 4)
  • in-flight photographs showed that the main ball valve was shut during the fire
  • all of the main valve block assembly bolts (with nuts attached) and cross-flow plugs were found intact in the wreckage
  • examination of the components did not identify any possible sources of a leak or failure that may have contributed to the in-flight fire
  • determination of the integrity of the main ball valve and liquid fire valve could not be established as the internal structures were completely disrupted by the fire.

Figure 4: Underside of burner and main ball valve – fire location

Figure 4: Underside of burner and main ball valve – fire location. Source: ATSB

Source: ATSB

Previous occurrences

A review of the ATSB occurrence database for similar occurrences identified that in the last 10 years there had been 10 instances of a hot air balloon catching fire. Of these, two incidents were the result of a fuel leak. In the first instance, the leak occurred at the main ball valve and in the other at the liquid fire valve. The pilots of the balloons controlled the fires by shutting off the fuel at the tank and then extinguishing the flames.

Safety analysis

The pilot first observed the fire coming from the front left burner. Physical examination of the components did not identify any possible sources of a leak or failure that may have contributed to the in-flight fire. However, the location of the fire (front left burner) eliminated any of the connections at the fuel tanks as a source of the leak. With the main valve switched off and the liquid fuel remaining on at the tank, only the pressurised components in between could have been the source of the initial leak. The most likely were considered to be the:

  • threaded connection between the liquid fire valve and main valve block
  • liquid fire valve
  • main ball valve.

The direction of the flame (towards the front of the balloon) was in line with the connection of the liquid fire valve into the main valve block. On installation, over-torquing or cross-threading the connection could result in damage to the aluminium valve block. Stresses from pressurisation and thermal cycling over time can cause the damage to develop into a crack, resulting in a fuel leak. However, as this joint did not require frequent adjustment, the likelihood of damage due to installation error or handling was reduced.

The flames emanated from a location near the main ball valve and the liquid fire valve. The valves (moving components) were prone to wear and therefore at higher risk of leaking than static components. The valves were oriented vertically with a handle on the base. It can be expected that any leaking fluid would spray downwards, into the handle, making it unlikely to see the directional flame pointing outwards from the basket. However, given the fire continued for an extended length of time, it is likely that the initial fire heated the surrounding structure causing failure of seals and joint sealant in other components, leading to further leaks and a larger fire. In that context, images and accounts of the flames directed outwards from the basket may be the result of subsequent failures.

As the pilot did not shut the liquid fire valve on the fuel tanks or the pilot burners, the situation escalated rapidly and increased the pilot’s workload in managing the situation. The leaking fuel near to the pilot flames on the adjacent burners caused the fire to re‑ignite immediately after the removal of the fire extinguishers. Use of a 90-degree valve on the liquid fuel outlet may have better assisted the pilot to recognise that he had not shut off the liquid fuel valve, enabling him to control the fire.

The pilot’s clothing did not provide adequate protection from burns, increasing the risk of personal injury. The pilot was carrying additional protective clothing, however, it was not kept in a readily accessible location, and therefore could not be used.

Finally, the MAYDAY broadcast did not provide air traffic control with a current or last known location of the aircraft. In this instance, the lack of information did not result in a delayed response from emergency services. It is important, however, for pilots to follow standard broadcast procedures when declaring an emergency.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • A fuel leak at the front left burner resulted in an in-flight fire. Due to severe fire damage, the source of the leak could not be determined conclusively, but it was considered most likely to be the main ball valve, liquid fire valve or liquid fire valve connection to the main valve block.
  • The hand-wheel valve on the liquid outlet of the fuel tank and the pilot burners were not shut off, which resulted in the pilot being unable to control the fire.
  • The pilot's clothing did not meet the recommended industry standards for personal protective equipment, which increased the risk to his personal safety.
  • Installation of a 90-degree valve on the liquid fuel outlet increases survivability in the event of fire and, may have assisted the pilot to recognise that the liquid fuel valve was not shut off.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Civil Aviation Safety Authority

As a result of this occurrence, the Civil Aviation Safety Authority released an Airworthiness Bulletin (AWB 02-063) to address some of the pertinent issues surrounding this occurrence. The AWB included the following recommendations:

  • Inspect the condition and operation of the fuel pressure gauge, stem seal and liquid fire valve.
  • Review the fuel system pressurisation limitations. Pressurisation of the fuel gauge beyond the maximum reading may cause catastrophic failure of the pressure gauge.
  • Use 90-degree (quick shut-off) valves for the fuel tank liquid outlets.
  • Review and rehearse all emergency procedures including in-flight fire and burner malfunctions.
  • Both the liquid and vapour valves must be closed on any tanks connected to the burner with a leak or malfunction before any effective firefighting methods can be performed.
  • Minimum industry standard protective clothing should be worn, which includes fire-resistant gloves, long-sleeved cotton shirt and sturdy, enclosed footwear
  • Carry fire blankets of a size of at least 1.5 m x 2 m.

In addition, CASA conducted a surveillance audit on Go Wild Ballooning. The audit returned a number of findings that the company will be required to rectify.

Go Wild Ballooning

As a result of this occurrence, Go Wild Ballooning has advised the ATSB it has taken the following actions:

  • upgraded one basket to the new Kavanagh Quad Burner system and is considering phasing out the older Kavanagh series 3 systems
  • replaced hand-wheel valves with 90-degree valves on all fuel tanks
  • reviewed the company policy on protective clothing, and are researching new fire-proof gloves.

Safety message

Pilots experience a high workload during in-flight emergencies. However, in the event of an in‑flight balloon fire, the first priority must be isolation of the fuel supply at the fuel tank.

The complex nature of emergencies highlights the importance of rehearsing response procedures. It is also good practice to do this standing in the basket. Further ways to reduce risk to individuals and improve survivability outcomes include:

  • wearing appropriate protective clothing, which includes cotton long-sleeved shirts and long trousers, leather gloves and enclosed footwear.
  • utilising componentry which provides a visual indication of the system status and is easy to use, for example, 90‑degree valves on liquid outlets.

Civil Aviation Order 201.11, Appendix IV and Civil Aviation Regulation 5.143 provide requirements for pilots to maintain currency of skills. It is important to remember, however, that it is up to individuals to ensure that they maintain a good working knowledge of how to deal with the full range of abnormal indications. Civil Aviation Advisory Publication 5.81-1(1) provides a clear interpretation of the requirements.

 

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Daylight-saving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. MAYDAY: an internationally recognised radio call announcing a distress condition where an aircraft or its occupants are being threatened by serious and/or imminent danger and the flight crew require immediate assistance.
  3. A rope or nylon strap connected to the top of the envelope, which the pilot uses to vent some or all of the hot air inside the envelope in order to descend or land.
  4. The imperial unit for pressure, pounds per square inch (psi) is equal to 6.895 kPa.

Occurrence summary

Investigation number AO-2019-001
Occurrence date 26/12/2018
Location Near Coldstream (ALA)
State Victoria
Report release date 28/06/2019
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Fire
Occurrence class Accident
Highest injury level Minor

Aircraft details

Manufacturer Kavanagh Balloons
Model B-350
Registration VH-ZYO
Serial number B350-368
Aircraft operator Go Wild Ballooning
Sector Balloon
Operation type Ballooning
Departure point Wandin, Victoria
Destination Coldstream, Victoria
Damage Destroyed

Engine flameouts on descent involving GIE Avions De Transport Regional ATR72-212A, VH-FVN, near Canberra Airport, Australian Capital Territory, on 13 December 2018

Final report

Report release date: 05/05/2020

Safety summary

What happened

On 13 December 2018, a GIE Avions De Transport Regional ATR72-212A registered VH-FVN was operated by Virgin Australia Airlines on a scheduled passenger flight from Sydney to Canberra. The aircraft encountered icing, turbulence and rain associated with thunderstorm activity in the area, so the crew diverted and held as required in order to avoid the adverse weather. Shortly after commencing descent into Canberra, passing 11,000 ft, the No.2 engine flamed out. The engine’s automatic ignition system engaged and the engine recovered within five seconds without pilot input. Approximately one minute later, passing 10,000 ft, the No.1 engine flamed out and automatically recovered within five seconds, again without pilot input.

Because of the quick nature of the automatic recovery, the crew did not action any checklists. The crew selected manual ignition as a preventative measure and continued to Canberra without further incident.

What the ATSB found

The ATSB found no evidence to suggest a mechanical fault or failure caused the engines to flameout and that the flameouts were likely to have been caused by the environmental conditions during the flight, most likely either icing or moderate/heavy rain, or a combination of both.

Aircraft systems and procedures for protection and recovery from flameouts in these conditions were reliable and effective in relighting the engines. However, the decision to select manual ignition following the flameouts potentially reduced the recovery and protection of the engines in the event of any potential further flameout.

What's been done as a result

The operator has conducted an internal investigation, released internal communications for awareness of the occurrence and ensured its pilots are aware of the appropriate use of manual ignition.

The manufacturer is ensuring all operators of the ATR72-212A are aware of the appropriate use of manual ignition. They are also reviewing operational documentation as to whether this requirement could be explicitly included.

Safety message

An engine flameout event is not common in today’s modern turbo propeller engines, but it is still possible. Reliable and effective systems and procedures exist to protect and recover from such events and it is important that pilots follow manufacturer procedures for these systems. In the case of the ATR72-212A, the automatic ignition system worked as designed, correctly identifying the loss of engine power, initiating ignition and successfully relighting the engines without pilot input. The selection of manual ignition potentially reduces the recovery mechanism effectiveness against flameouts, and should only be used when directed by checklist or a minimum equipment list.

 

The occurrence

On 13 December 2018, a GIE Avions De Transport Regional (ATR) ATR72-212A 600 series (ATR72), registered VH-FVN, was operated by Virgin Australia Airlines (Virgin) on scheduled passenger flight VA660 from Sydney, New South Wales (NSW) to Canberra, Australian Capital Territory (ACT). Two pilots, two cabin crew and 42 passengers were on board. The captain was the pilot monitoring (PM) and the first officer (FO) was pilot flying (PF).

During planning for the flight, the crew were aware of significant weather en route, with a line of thunderstorms approaching Canberra. A second line of thunderstorms was approaching and the crew assessed that the aircraft would arrive in Canberra at about the same time as the second line of storms. Sufficient fuel was loaded to enable the duration of the flight to Canberra, to hold for one hour, return to Sydney and hold for another hour.

Following departure at about 1741, the crew were able to observe the weather ahead and formulated plans to avoid the storms. About 10 minutes after departure, the crew requested a diversion 5 NM left of track to avoid weather. About 15 minutes after departure, air traffic control (ATC) cleared the aircraft to climb to flight level 160 (FL160[1]) and to increase their diversion left of track up to 10 NM.

Shortly thereafter, the clearance to divert left of track was cancelled by ATC and the crew were requested to provide a heading which would keep them clear of weather. ATC then directed the aircraft to maintain FL130 due to passing traffic, later clearing a further climb to FL140.

After being cleared for the standard arrival route (STAR) BUNGO 3A into Canberra, the crew accepted direct tracking to waypoint HIPPO. En route to HIPPO, the aircraft entered visible moisture with a total air temperature (TAT) below 7 °C, which were icing conditions as defined by the aircraft manufacturer (ATR). The crew acknowledged this and turned on anti-icing systems in accordance with the aircraft procedure for entering such conditions.

The crew requested an update on the weather at Canberra. ATC advised there was significant showers in the area with greatly reduced visibility. The crew commenced descent in accordance with their arrival clearance and ATC directed them to stop descent at FL120. ATC asked the crew if they would like to attempt an approach but the crew elected to hold at HIPPO at FL120 until the weather passed. Shortly thereafter, icing was visible on the aircraft and the crew selected de-icing systems ON as required by ATR FCOM procedures.

After holding at HIPPO for about 7 minutes, the crew requested to track south then west to fly around the weather and then back to Canberra. ATC cleared the aircraft to do so with headings at crew discretion.

The aircraft tracked south until about 1830 when it turned back north to assess the weather at Canberra (utilising radar). The crew decide to track to waypoint POLLI for the POLLI 7 STAR and advised ATC accordingly. ATC advised the crew that a STAR clearance was available, but the crew advised ATC to standby as they were busy avoiding weather. Shortly after, ATC advised that an approach was now viable (a previous aircraft had landed) but the crew continued to POLLI and assessed the weather for themselves.

The crew elected to hold at POLLI and held there until about 1849 when ATC vectored them to the north to commence the STAR. At 1853, the aircraft was cleared by ATC to resume its own navigation direct to waypoint HUNNI, descend to 9,000 ft to commence the STAR.

At about 1854, shortly after descent had commenced, the aircraft passed FL110 with both power levers close to flight idle when No.2 engine lost power and flamed out. The master warning and ENG 2 OUT annunciators displayed, and No.2 engine torque reduced to zero. In the time it took the crew to acknowledge the warning and confirm what it was, No.2 engine self-recovered, torque returned to normal and the warnings ceased. The crew discussed that they likely encountered icing, confirmed engine power had returned to normal and confirmed that anti-icing and de-icing systems were on. Due to the automatic recovery, the crew were not required to action any checklist or procedures associated with an engine flameout in flight.

At about 1855, both power levers were at flight idle when No.1 engine lost power and flamed out. The master warning and ENG 1 OUT annunciators displayed, and No.1 engine torque reduced to zero. In the same way that No.2 engine had recovered, No.1 engine self-recovered by the time the crew had acknowledged and confirmed the flameout. Again, no checklist or associated procedures were required to be actioned.

The captain immediately identified the de-ice mode selector switch in order to ensure the de-ice cycle was in ‘fast’; however, the captain inadvertently selected the slow cycle. The captain then selected ignition to ‘manual’, in order to provide continuous ignition in an attempt to prevent any further flameouts.

Satisfied that power in both engines had been restored to normal, the crew discussed the situation, but were unable to determine the cause of the flameouts. They confirmed manual ignition ON, icing protection ON and observed that the temperature was 12 degrees, prompting further discussion on the use of icing protection. The crew decided that they would not turn any of the icing protection systems off at that stage and would fly at icing speeds[2] if they needed to keep the icing protection on for landing.

The crew stated that the aircraft was in heavy rain at the time of the flameouts but they did not notice any significant icing at the time. Figure 1 depicts the rainfall recorded by radar at about the time of the first flameout.

The crew continued the approach, and at about 1901, the crew confirmed the aircraft was no longer in icing conditions and selected the de-icing OFF but left the anti-icing systems ON.

No further flameouts occurred and the aircraft landed at 1906.

Figure 1: Radar image at time of flameouts

Figure 1: Radar image at time of flameouts.
The radar image at 1854, about the time of the first flameout. Areas of yellow depict moderate rainfall with red depicting heavy rainfall. 
Source: PWC annotated by ATSB.

The radar image at 1854, about the time of the first flameout. Areas of yellow depict moderate rainfall with red depicting heavy rainfall.

Source: PWC annotated by ATSB.

__________

  1. Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 370 equates to 37,000 ft.
  2. Icing speeds are minimum manoeuvre speeds in icing conditions that must be flown in order to provide sufficient margin against aerodynamic stall.

Context

Pilot Information

Captain

The captain commenced flying the ATR72 with Virgin in 2013 as a first officer, becoming a captain in April 2018. At the time of the incident, the captain had accumulated 204 hours command on the ATR72. The captain had a total flying time of 6,660 hours with 2,225 hours on ATR72.

Previous flying experience included charter and regular public transport (RPT) operations on aircraft including the Embraer 120 and Cessna 441 (Conquest). The captain had also undertaken flying instructor roles prior to that.

The captain’s most recent line and simulator check records did not highlight any major or ongoing proficiency concerns. Engine malfunctions and adverse weather operations were included in those assessments.

First officer

The first officer (FO) commenced flying the ATR72 with Virgin in 2012 as a first officer. At the time of the incident, the FO had a total flying time of 6,700 hours, with over 3,000 hours on the ATR72.

Previous flying experience included charter and RPT and flying instruction.

The FO’s most recent line and simulator checks did not note any major or ongoing proficiency concerns. Engine malfunctions and adverse weather operations were included.

Aircraft Information

General

VH-FVN was an ATR72-212A 600 series aircraft manufactured in 2012. The aircraft is a twin-engine turboprop regional airliner that seats up to 78 passengers (dependant on configuration) and is crewed by two pilots and two cabin crew.

Engine combustion and flameout

The ATR72 is powered by two Pratt & Whitney Canada (PWC) PW127M turbo propeller engines. The engine operates by continuous internal combustion of a fuel air mix. A flameout is an unintentional extinguishing of the flame in the engine. This may result from interruption of any of the requirements for sustaining combustion, being fuel, air and heat.

The ATR Flight Crew Operating Manual (FCOM) provided information on possible causes of a flameout. Pilots were able to use this to assist in identification of the likely cause in the event of a flameout and to allow appropriate action to take place. The FCOM stated:

The causes of engine flameout can generally be divided into two categories:

- External causes such as icing, very heavy turbulence, fuel mismanagement. These causes, which can affect both engines can generally be easily determined and an immediate relight can be attempted.

- Internal causes such as engine stalls or failures, usually affect a single engine. These causes are not so easily determined. In these cases, the engine is shut down then the cause of the flameout investigated. If the cause of the flameout cannot be determined, the need for engine restart should be evaluated against the risk of further engine damage or fire that may result from a restart attempt.

‘Icing’ is not quantified. However, another section of the FCOM stated that very large ice accretion on the engine intake may generate an engine flameout when the ice breaks free. Rain is not specifically included in the FCOM as an external cause of flameouts.

Fuel system

Fuel management and fuel quality was considered as a possible external contributor. There was no evidence to suggest fuel mismanagement and inspection of the fuel system did not identify any contaminants. Fuel management and fuel quality were not considered contributory to the flameouts.

Ignition system

The PW127M engine has a high-energy ignition system which provides for engine start on ground or in flight. Following a successful engine start, the ignition system is automatically disengaged and no longer providing a spark as combustion is self-sustaining. Under control of the electronic engine control (EEC) unit, the ignition system will activate if NH[3] drops below 60 per cent.

A guarded manual ignition switch is available to allow the crew to manually select continuous ignition. The FCOM referred to manual ignition in situations where an EEC is OFF (fault or malfunction). If one or both EECs are OFF, manual ignition is required for flight in the following cases: icing conditions, engine(s) flame out, emergency descent, severe turbulence and heavy rain, or when operating on a contaminated runway for take-off or landing.

The ATSB noted that there was no FCOM reference that prohibited the use of manual ignition in other situations and there was no explicit direction for ignition to remain in its automatic initiation state.

Prior to the engine flameouts on VH-FVN, the ignition system was in its normal state, being OFF, but primed to be initiated by the EEC as previously described. For both flameouts, the ignition system automatically engaged as designed and successfully relit the engines. Following the automatic recovery, the crew reported that they selected manual ignition as a safety measure to prevent further flameouts. The crew could not recall any specific guidance from ATR for flights in heavy weather.

Following notification of the occurrence, ATR advised Virgin that selection of manual ignition was not appropriate and that use of manual ignition other than as directed lowered the flameout recovery and protection afforded by automatic ignition. ATR explained the difference as follows:

On ATR72-600, each engine is equipped with a high-energy ignition system. Triggering of auto-relight energizes igniter boxes, which deliver sparking rate of 5/6 per sec for 25s.

MAN IGN [manual ignition] is a guarded push button at overhead panel and is to be used in case of EEC Fault or under dispatch minimum equipment list (MEL[4]) with EEC OFF as per ATR procedures.

When selecting MAN IGN, ignition system is activated at a sparking rate of 5/6 per sec for 25s. Then, the sparking rate becomes slower after 25s (changing from 5/6 per sec to 1 per sec).

ATR later clarified their explanation for automatic initiation in that following the initial 25 seconds, the sparking rate also reduces to one spark per second.

The implication is that if manual ignition has been ON for more than 25 seconds at the time of a flameout, it would be steady at one spark per second and not at the high spark rate of automatic ignition, therefore potentially delaying the relight process.

Icing and rain protection system

The ATR72-600 is fitted with various protection systems for operations in various environmental conditions, particularly icing.

The system consists of:

  • Ice detector, mounted on left wing which electronically monitors ice accretion.
  • Ice evidence probe (IEP) near captain’s windshield for visible detection of ice accretion.
  • Electrically heating (anti-ice) of propeller blades, windshields, probes and flight control horns.
  • Pneumatic boots (de-ice) on wing and horizontal tailplane leading edges and engine air intakes and gas paths.
  • Windshield wipers for rain removal from front windshields.

An aircraft performance monitoring system works in conjunction with the above components, through alerts to the crew if an aircraft aerodynamic performance degradation is detected due to ice accretion.

The aircraft engines are protected from icing through the de-ice system controlled via two push button switches, one for each engine. Pneumatic boots, located in the engine air intakes and gas paths, inflate on an automatically controlled cycle to dislodge ice accretions.

The selection of engine de-ice is not a recorded parameter. However, it is monitored for faults and any faults triggered are recorded. No engine de-icing faults were recorded for the incident flight. There was no indication of any problems with the engine de-icing system that may have contributed to the flameouts. Similarly, there was no damage to the engine intakes which may indicate impact due to large ice accretions having broken away during the de-ice process.

Water ingestion margin testing

The PW127M engines had been tested and certified for water ingestion requirements, and in addition to this, another water ingestion test was undertaken by PWC in 2016 to identify engine capability in terms of water ingestion. This was on one PW127M engine mounted on a test bed with a non-bypass intake duct. This configuration tested a worst-case scenario with all water entering the engine.

The test concluded that the engine demonstrated significant margin over the certification requirements and a resilience to adverse operational environments. The certification required the engine to maintain steady operation with an ingestion of water at a 4 per cent water to air ratio (WAR). The test engine performed such that a power loss and flameout occurred at 15.8 per cent WAR.

Procedures

Operations in adverse atmospheric conditions

Volume A1 of Virgin’s operations manual suite included a section on adverse atmospheric conditions. Requirements for avoiding thunderstorms and severe weather as well as specific sections on lightning, cyclones and volcanic ash were included. Rain was not specifically mentioned.

The ATR FCOM also provided guidance and procedures for operations in adverse weather conditions. There were several sections with procedural guidance on icing conditions and turbulence and general adverse weather.

Rain was not afforded any specific guidance in the FCOM nor was it mentioned, except with regard to the use of windshield wipers and in the EEC fault procedure.

During the flight, the crew diverted and held as required to maintain the aircraft clear of the weather. On several occasions, the crew requested diversion off track to maintain safe separation from the approaching weather and entered a holding pattern on two occasions to allow for passage of thunderstorms over Canberra. The flight was initially flown at turbulence speed[5] due to moderate the turbulence encountered. From about 1807, the aircraft was flown at icing speeds. Although turbulence continued for the remainder of the flight, icing speeds were flown from that point as the crew assessed that icing was a higher threat than the moderate turbulence.

Engine flameout recovery procedure

An engine flameout procedure was included in the aircraft operational documentation. The initial actions for an engine flameout is to move the power lever on the affected engine to flight idle. If NH drops below 30 per cent (no immediate relight) then the engine is to be shutdown.

For this incident, upon warnings being displayed for the first flameout, the crew acknowledged the master warning and whilst assessing the situation, the engine power restored prior to any action being required. The second flameout occurred in a similar manner and engine power restored whilst the crew were assessing the situation. No checklist procedures were carried out given the timeframe from flameout to automatic recovery.

Recorded flight data

The ATSB downloaded and analysed the data from the aircraft flight data recorder. Figure 2 below presents the key recorded aircraft and engine parameters at the time of the flameouts. During both flameouts, the master warning was active for 5 seconds. This included the time from flameout, initiation of automatic ignition and full recovery.

Figure 2: Recorded flight data

Figure 2: Recorded flight data.
Source: ATSB

Source: ATSB

Weather information

Weather forecasts provided to the crew included significant meteorological information (SIGMET), forecasting squall line thunderstorms with hail, with tops up to FL400. The weather was forecasted to move to the east-south-east at 15 knots. At the time of planning, operational dispatch notes indicated this weather was within 50 NM to the west of Canberra. A significant weather (SIGWX) chart covering FL100-FL250 forecast moderate turbulence between FL100-FL250 and moderate icing from FL120-FL240 with isolated embedded cumulonimbus clouds.

The Bureau of Meteorology (BOM) graphical area forecast, covering mean sea level to 10,000 ft, indicated a broad area of thunderstorms including reduced visibility down to 2,000 m associated with heavy rain and areas of 4,000 m visibility associated with widespread rain. BOM always assume that severe icing is coincident with the convective activity of forecast thunderstorms and therefore do not forecast icing separately.

The aerodrome forecast (TAF) for Canberra, issued at 1608 and valid from 1700 until 1700 the next day, forecast temporary deterioration periods where thunderstorms, reduced visibility, rain and hail would occur, broadly consistent with the area forecasts and significant weather charts. However, the prevailing conditions at Canberra suggested an approach and landing would be achieved in between the temporary deteriorations.

The crew were well aware of the expected weather for the flight and in conjunction with Virgin operation staff, sufficient fuel was loaded to allow the crew to hold and/or divert as required in order to allow for passage of the weather. Both crew commented that at no stage did they consider that the flight should be cancelled due to the weather.

BOM radar imagery around the time of the incident shows lines of moderate rainfall, which the BOM describe as indicative of thunderstorm activity.

Special observations at Canberra from 1800 confirmed thunderstorm activity and continued to be reported at Canberra until 1900.

The crew observed the actual weather was as expected but commented that turbulence was the prevalent issue. The crew described the turbulence as moderate throughout the flight with a highest recorded G load[6] of +1.76. Icing conditions were encountered, with the crew observing visible moisture and total air temperature (TAT) below 7 °C. Ice accretion was observed shortly thereafter.

The crew recalled that rain was heavier in the POLLI area. The captain described being in heavy rain at the time of the flameouts although BOM radar imager indicates moderate rain at the time. Ice was not evident on the IEP at that time and the captain recalled that the windscreen looked like ‘a bucket of water had been thrown on it’. Consistent with their pre-flight assessment that they could fly, the crew noted that the weather, although significant, was not anything that they had not encountered previously.

Post occurrence maintenance inspection

Following the occurrence, a number of maintenance inspections were undertaken. The inspections that took place included:

  • Visual inspection of the inlet compressor blades and exhaust outlet (a detailed inspection of the engine core was not undertaken as the visual inspection of outer section did not identify any damage indicative of ingesting foreign objects. This was based on ATR/PWC guidance).
  • Chip detector inspection.
  • Severe turbulence inspection.
  • Low pressure fuel filter and housing inspection.
  • Fuel tanks checked for water contamination.

Although not exhaustive, there was no indication of any mechanical fault or failure and no indication that further detailed inspections were required.

Related Occurrences

PWC provided information regarding 21 flameout events on PW127M engines on ATR aircraft during bad weather (rain or icing). It included this occurrence and three subsequent events. These events were on ATR72-500 and -600 variants as well as one ATR42-600.

Figure 3 shows breakdown by year:

  • ten were in icing conditions
  • seven were in heavy rain
  • four were in moderate rain.

In all cases, the automatic ignition system initiated successfully, and power was restored without pilot intervention.

The earlier related occurrences prompted a water ingestion test in 2016 by PWC of the PW127M engine. As previously discussed, the engine performed in excess of the certification requirements, satisfying both PWC and ATR that the engines were capable of operating in significant adverse environmental conditions.

ATR concluded that extant guidance and standard operating procedures were sufficient. That is, in the case of a temporary power loss with automatic relight there was nothing specific to do. Should an automatic relight not occur, the checklist provided guidance for securing the engine and any subsequent restart attempt.

Figure 3: Flameout events during bad weather by year

Figure 3: Flameout events during bad weather by year.
Source: PWC

Source: PWC

__________

  1. NH: the rotational speed of the high pressure compressor in the turbo propeller engine.
  2. MEL: a minimum equipment list of items of equipment that may be temporarily inoperative under certain conditions and limitations, while still maintaining the level of safety intended in the design standards.
  3. Turbulence speed is a maximum speed for turbulent conditions in order to provide the best protection against the effect of gust on the aircraft structural limits.
  4. G load: the nominal value for acceleration. In flight, G load represent the combined effects of flight manoeuvring loads and turbulence and can have a positive or negative value.

Safety analysis

Flameout causes

The ATSB considered internal causes such as a mechanical fault or failure. The engines were running smoothly and producing the required power as commanded with no signs of the impending flameout. Post occurrence maintenance was in conjunction with ATR and PWC guidance and did not identify any mechanical fault or failure. There was no evidence to suggest that a mechanical fault or failure contributed to the flameout.

Of possible external causes, fuel management and fuel quality were not considered contributory to the flameouts. However, evidence indicates that the aircraft encountered significant weather during the flight, including rain, icing and turbulence. Despite this, the ATSB considered that the flight crew managed the weather conditions appropriately and there was no evidence to suggest that the flight should have been cancelled due to those conditions.

The flight crew operating manual (FCOM) listed heavy turbulence as a possible cause of flameout. The crew described the turbulence as moderate and the recorded G load of +1.76 is consistent with crew description of the turbulence. The ATSB did not consider turbulence as contributory to the flameouts.

Icing was also included in the FCOM as a possible cause of flameout. There was no evidence of damage to engine inlets (suggesting no ingestion of large ice accretions) and the crew did not note any significant ice accretion during the flight. Engine de-ice had been on for at least 40 minutes prior to the flameouts which indicates that significant ice accretions would have been very unlikely. The aircraft exited icing conditions approximately 1 minute prior to first flameout (TAT had risen above 7 °C) suggesting that the conditions were suitable for dislodging any ice accretion or that they were not suitable for ice to form. There was insufficient evidence to determine if icing did or did not contribute to the flameouts.

The crew recalled that the aircraft was in heavy rain and Bureau of Metrology (BOM) radar imagery indicates moderate rain at the time. Although the engines passed certification requirements for water ingestion, numerous flameout occurrences have previously been associated with moderate or heavy rain conditions. Testing takes place in a controlled environment but does not account for engine installation and other variables of actual flight conditions. There was insufficient evidence to determine if rain did or did not contribute to the flameouts.

In the absence of evidence to the contrary, it is likely the flameouts were the result of the environmental conditions during the flight. Although the exact environmental influence could not be confirmed, it is likely this was either ice or rain, or some combination of the two.

Flameout recovery

The automatic ignition function performed as designed, recognising the drop in NH below specified criteria and automatically engaging the ignition system to relight the engines without pilot input.

The known flameout events on ATR aircraft all involved icing or moderate/heavy rain. The auto ignition system has been proven effective and reliable in providing flameout recovery and in all 21 events, as the engines successfully relit without pilot input.

In the absence of specific guidance against the use of manual ignition, the crew selected manual ignition, which operates continuously at one spark per second after the initial 25 seconds. Given the uncommon situation of two engine flameouts, the crew considered that manual ignition was a safety measure to prevent any further flameouts in that a continuous source of ignition may prevent the flame from being extinguished. This is in contrast to automatic ignition, which in the event of a further flameout, would have initially operated at a higher spark rate.

ATR advice to Virgin and other ATR operators is that in the case of a temporary power loss with automatic relight, there is nothing else to do, the system has worked as designed and restored engine power. ATR advice is that selection of manual ignition potentially lowers the flameout protection of the engine, and that manual ignition should only be used when directed by a checklist. However, ATR documentation does not contain this guidance.

Findings

From the evidence available, the following findings are made with respect to the engine flameouts on descent involving ATR 72-212A, VH-FVN that occurred near Canberra, Australian Capital Territory on 13 December 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • The two engine flameouts were probably the result of the environmental conditions (likely icing and/or heavy/moderate rain) during the flight.

Other factors that increased risk

  • The crew selected manual ignition as a preventative measure against further flameout. While ATR recommend that manual ignition should not be selected unless directed by checklist or under minimum equipment list, this was not specifically mentioned in the ATR documentation.

Other key finding

  • The aircraft automatic ignition system performed as designed by automatically relighting both engines without pilot input following flameout.

Safety actions

Additional safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Action taken by Virgin Australia Airlines Pty Ltd

Virgin has advised the ATSB that the following safety actions have been taken:

  • Provided a statement of facts of the occurrence to all ATR flight crew.
  • Provided an update to ATR flight crew with regard to use of manual ignition.
  • Released a flight crew operational notice formalising previous information on manual ignition use.
  • Updated internal documentation (Standard Operating Procedures Manual) to include direction on use of manual ignition as well as reference to rain as a possible cause of flameout.

Action taken by GIE Avions De Transport Regional

  • ATR has prepared communications to be provided to ATR operators (on request), advising details of this occurrence and that manual ignition is only to be selected when directed by checklist or under minimum equipment list.
  • ATR commenced an internal review of aircraft documentation with the following modifications on going:
    • The addition of ‘rain’ in the potential external causes of engine flameouts
    • The addition of detailed differences between manual and automatic ignition, including a description of the role of the manual ignition push button.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Flight crew of VH-FVN
  • Flight data recorder and cockpit voice recorder from VH-FVN
  • Virgin Australia Airlines
  • GIE Avions De Transport Regional
  • Pratt & Whitney Canada
  • Bureau of Meteorology
  • Airservices Australia.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the flight crew, Virgin Australia Airlines, GIE Avions De Transport Regional, Bureau d'Enquêtes et d'Analyses pour la Sécurité de l'Aviation Civile, Pratt & Whitney Canada, the Transportation Safety Board of Canada, Australian Bureau of Meteorology, Airservices Australia and the Civil Aviation Safety Authority.

Submissions were received from Virgin Australia Airlines and GIE Avions De Transport Regional. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2018-081
Occurrence date 13/12/2018
Location Near Canberra Airport
State Australian Capital Territory
Report release date 05/05/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Engine failure or malfunction
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer ATR-GIE Avions de Transport Régional
Model ATR72-212A
Registration VH-FVN
Serial number 1039
Aircraft operator Virgin Australia
Sector Turboprop
Operation type Air Transport High Capacity
Departure point Sydney Airport, New South Wales
Destination Canberra Airport, Australian Capital Territory
Damage Nil

Wheels-up landing involving Beech Aircraft Corporation B200, VH-ODI, Mount Gambier Airport, South Australia, on 8 December 2018

Final report

Report release date: 20/05/2020

Safety summary

What happened

On 8 December 2018, a Desert-Air Safaris Beech Aircraft Corporation B200, registered VH-ODI operated a charter flight from Adelaide Airport to Mount Gambier Airport, South Australia with a pilot and seven passengers on board. One of the passengers held a commercial pilot licence and acted in an observer role from the right flight deck seat, but was not a member of the flight crew.

During the landing at Mount Gambier, the aircraft touched down with the landing gear retracted, with the propellers contacting the runway twice before the pilot initiated a go‑around. During the go-around, the left engine failed. The aircraft then landed without further incident.

What the ATSB found

The ATSB found that upon reaching the minimum descent altitude for an approach to Runway 18 at Mount Gambier, the pilot had not yet obtained visual reference with the runway. He therefore commenced a go-around and retracted the landing gear. After retracting the landing gear, the pilot sighted the runway and decided to continue the approach, but inadvertently did not re-extend the landing gear.

During the continued approach, the pilot likely did not detect the retracted landing gear due to an expectation that it was already extended. This was possibly also compounded by the now‑increased workload.

Further, the ATSB found that the pilot’s decision to conduct a go-around after the wheels-up landing stemmed from his misunderstanding of the situation, and an assessment that a runway overrun was imminent.

Safety message

This accident highlights the hazards of spontaneous decision-making, particularly during a high‑workload phase of flight in a complex aircraft. The Civil Aviation Safety Authority Resource booklet and video Decision Making provides the following tips to improve the quality of decision making, mitigate the possibility of errors and ensure a considered approach in resolving issues or problems:

  • You cannot improvise a good decision, you must prepare for it. You will make a better and timelier final decision if you have considered all options in advance. This is why good briefings are important.
  • Use decision-making aids—operational checklists—to ensure you have not forgotten anything important.
  • Always have reserve capacity for reacting to unexpected events.
  • Delegate your load to other team members (if multi-crew) when time is critical.
  • Keep the big picture in mind rather than focusing on one aspect of a problem.

 

The occurrence

On the morning of 8 December 2018, the pilot of a Desert-Air Safaris Beech Aircraft Corporation B200, registered VH-ODI (ODI), prepared to conduct a charter flight from Adelaide, South Australia to Mount Gambier, South Australia with seven passengers on board. One of the passengers occupied the right flight deck seat as an observer. This observer held a commercial pilot licence, but was not a member of the flight crew.

At about the scheduled departure time of 1000 Central Daylight‑saving Time,[1] the pilot reviewed the weather forecast for Mount Gambier Airport which provided the following information:

  • A southerly wind of 10-14 kt throughout the forecast period.
  • Visibility greater than 10 km for the forecast period, with light rain showers until 1230.
  • A broken[2] cloud base of 712 ft above mean sea level (AMSL) (500 ft above aerodrome level (AAL)) until 1130.
  • From 1130, the broken cloud base would remain, but rise to 1,212 ft AMSL (1,000 ft AAL).
  • From 1230, the cloud coverage was forecast to reduce to scattered and the cloud base rise further to 1,712 ft AMSL (1,500 ft AAL), with an overlying broken layer at 2,212 ft AMSL (2,000 ft AAL).

The pilot also contacted the Mount Gambier Airport aerodrome reporting officer. The aerodrome reporting officer advised that the observed cloud ceiling was about 300 feet above the aerodrome level and that a scheduled flight from Adelaide to Mount Gambier had delayed their departure due to the low cloud. The pilot of ODI noted that the forecast indicated conditions would improve, and he elected to delay the departure, until 1100.

At 1109, the flight departed Adelaide Airport. During the flight to Mount Gambier, the pilot prepared for the arrival. He anticipated conducting an area navigation (RNAV) instrument approach to Runway 18 (see the section titled Operation) (Figure 1). The pilot also determined an estimated time for the commencement of the approach of 1157. Air traffic control advised that another aircraft would be commencing an RNAV approach to Runway 18 at Mount Gambier at 1155. The pilot of ODI therefore elected to slow the aircraft to allow the preceding aircraft to conduct their approach.

Figure 1: Mount Gambier Airport overview

Figure 1: Mount Gambier Airport overview.
Source: Google Earth, annotated by ATSB.

Source: Google Earth, annotated by ATSB.

During the flight, the pilot also received a Special Weather Report (SPECI).[3] This observation reported overcast cloud at 512 ft AMSL, below the approach minimum descent altitude (MDA) of 730 ft AMSL. The SPECI also reported visibility greater than 10 km and a southerly wind of 11 kt.

At 1200, ODI commenced the Runway 18 RNAV approach behind the preceding aircraft. As the preceding aircraft continued the approach, the flight crew of that aircraft received an alert indicating the loss of the Global Navigation Satellite System[4] receiver autonomous integrity monitoring (RAIM)[5] and conducted a go-around.

Despite not receiving a similar alert, the pilot of ODI also elected to conduct a go-around. He climbed the aircraft to an altitude of 5,000 feet and proceeded with the missed approach procedure to waypoint[6] MTGNE to commence another approach. The other aircraft then advised that they would hold at waypoint MTGND while ODI conducted another approach.

At 1215, ODI commenced a second approach to Runway 18 from waypoint MTGNE.

During the flight and approaches, the observer contributed to the operation of the aircraft by:

  • Monitoring the operation of the aircraft (with autopilot engaged) while the pilot briefed the passengers.
  • Calculating RAIM availability.
  • Calling out operational checklists.
  • Providing details of the instrument approach to the pilot, including the upcoming waypoints, tracks between waypoints and descent altitudes.
  • Communicating to the pilot the details of external radio broadcasts.
  • Monitoring the approach and calling out excursions from the target altitude.

The approach chart indicated that a normal descent profile should position the aircraft at 980 ft, 2 NM prior to the missed approach point at MTGNM. As the aircraft crossed this point, the pilot announced that the aircraft was ‘too fast by far’ and ‘high’.

On multiple occasions throughout the approach, the pilot questioned and corrected information provided by the observer and educated her on the operation of the flight.

As the aircraft descended to 730ft, the observer announced that they had reached the MDA. Upon reaching the MDA, the pilot could see the ground directly beneath the aircraft, but could not see the runway ahead. He then announced that he would conduct a go-around and retracted the landing gear, without announcing that he had done so. The observer was unaware that the landing gear had been retracted. After the pilot announced the go-around, the engine power level did not increase.

Nine seconds after the landing gear was retracted, the pilot and observer sighted the runway. The pilot then reduced power and selected full flap to continue the approach. He noted that the required approach profile from that position was ‘very steep’.

At that time, the landing gear warning tone activated. As the approach continued, the ground proximity warning system (GPWS) ‘check gear’ aural alert also activated. In response, the pilot incorrectly announced that the landing gear was extended. The approach continued, and 5 seconds later the GPWS alert ‘pull up’ also activated. The observer announced that the ‘pull up’ warning had activated. The pilot acknowledged this call, announced ‘I’ve got it’ and continued the approach. One second later, the ‘pull up’ and ‘check gear’ alerts ceased, but the landing gear warning tone continued (the pilot and observer both later recalled not hearing the landing gear warning tone or GPWS ‘check gear’ alerts).

At 1222, the aircraft briefly touched down on the propellers and bounced (Figure 2). Two seconds later, the propellers again contacted the runway. The pilot, believing the landing gear was down and the aircraft had landed on the runway, twice attempted unsuccessfully to engage reverse thrust.

Figure 2: Left propeller strike marks

Figure 2: Left propeller strike marks.
Source: Airport operator, annotated by ATSB.

Source: Airport operator, annotated by ATSB.

The aircraft continued flying above the runway at low level and began to drift right toward the runway edge. The pilot, believing the aircraft to be rolling on the landing gear and not responding to brake inputs, assessed that it could not be stopped in the remaining runway and elected to conduct a go-around. He then increased engine power and observed good initial response from both engines followed shortly after by failure of the left engine.

The pilot completed the initial engine failure actions and announced ‘gear up, flap up’ and the landing gear warning tone then ceased operating, consistent with flap retraction (see the section titled Aircraft details). Following the flap retraction, the stall warning activated intermittently for 16 seconds.

The pilot shut down and secured the left engine and assessed that the right engine was performing as expected. He then conducted a visual left circuit at an altitude of about 600‑650 ft AMSL, and at 1224 the aircraft landed on Runway 18 and vacated on to Runway 29 where it was shut down (Figure 1).

The observer assisted with passenger disembarkation onto Runway 29 and escorted them clear of the runway. No persons were injured during the accident however, the aircraft was substantially damaged.

  1. Central Daylightsaving Time (CDT): Coordinated Universal Time (UTC) +10.5 hours.
  2. Cloud cover: in aviation, cloud cover is reported using words that denote the extent of the cover – ‘few’ indicates that up to a quarter of the sky is covered, ‘scattered’ indicates that cloud is covering between a quarter and a half of the sky, ‘broken’ indicates that more than half to almost all the sky is covered, and ‘overcast’ indicates that all the sky is covered.
  3. A SPECI is a special report of surface meteorological information at an aerodrome. These are issued when specific criteria are met. At the time of the occurrence, a routine SPECI was being issued for Mount Gambier every 30 minutes due to the low cloud base.
  4. Global Navigation Satellite System: The global navigation service provided by satellites constellations such as GPS.
  5. Receiver Autonomous Integrity Monitoring is a process whereby the GNSS receiver makes use of redundant satellite information as a check on the integrity of the navigation solution, before and during an approach.
  6. Waypoint: A defined position of latitude and longitude coordinates, primarily used for navigation.

Context

Pilot and observer information

Pilot

The pilot held an Air Transport Pilot Licence (Aeroplane) and a Class 1 aviation medical certificate. He also held pressurisation system, retractable undercarriage and gas turbine engine ratings along with an instrument rating applicable to multi-engine aircraft and instrument approach procedure ratings for both two-dimensional and three-dimensional approaches.

At the time of the accident flight, the pilot had over 14,200 hours of aeronautical experience, of which about 2,460 hours were on the B200.

The investigation found no indicators that increased the risk of the pilot experiencing a level of fatigue known to have affected performance.

Following the accident, the Civil Aviation Safety Authority (CASA) suspended the pilot’s licence.

Observer

The observer held a Commercial Pilot Licence (Aeroplane), an instructor rating and a Class 1 aviation medical certificate.

The observer had not held a flying role for a number of years and was observing the operation to re‑familiarise herself with flying operations. She had acted in that role on the B200 over the preceding 4 months. At the time of the accident flight, the observer had about 440 hours of aeronautical experience, of which none were on the B200.[7]

The pilot commented that the interactions between himself and the observer did not increase his workload, were not distracting, and reinforced his actions.

Operation

The flight was a passenger charter flight from Adelaide to Mount Gambier and had been arranged the previous day. The company typically operated such flights as single-pilot operations, often with an observer, as was the case for the accident flight.

The observer was not a member of the flight crew and her role was not defined in operational documentation. Typically flight crew roles are defined as ‘Pilot Flying’ and ‘Pilot Monitoring.’ The Pilot Flying does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The Pilot Monitoring carries out support duties and monitors the Pilot Flying’s actions and the aircraft’s flight path.

The pilot was also the Chief Pilot and owner of the company; he defined the observer role as purely an observational role with limited participation in the operation of the flight. He did describe the observer taking on some operational support duties such as recording operating parameters and providing instrument approach information to the pilot. The observer understood the role not to include any flying or radio broadcasts, but to observe the operation of the flight, act as a support to the pilot during flight and to assist with ground duties.

There was no evidence that the observer made radio broadcasts or manipulated the flight controls during the accident flight.

Mount Gambier Runway 18 RNAV-Z approach

Runway 18 at Mount Gambier was provisioned with an area navigation (RNAV) straight-in approach. The approach was flown along a path of GNSS waypoints. The passage of each waypoint allowed a pilot to descend in accordance with segment minimum safe altitudes and, after passing the final approach waypoint (MTGNF), descend to the MDA.

The MDA was 730 ft AMSL,[8] which was 518 ft AAL (Figure 3). Upon descending to the MDA, further descent must not be made unless the pilot is able to proceed visually.

Figure 3: Mount Gambier RNAV-Z Runway 18 approach

ao2018080_figure-3_final.png

Source: Airservices Australia, modified by ATSB

The Airservices Australia publication, Aeronautical Information Publication (AIP) section ENR 1.5, paragraph 1.8.2, provided the following requirements to be met to allow descent below an MDA during a straight-in approach:

Descent below the straight-in MDA may only occur when:

visual reference can be maintained;

all elements of the meteorological minima are equal to or greater than those published for the aircraft performance category; and

the aircraft is continuously in a position from which a descent to a landing on the intended runway can be made at a normal rate of descent using normal flight manoeuvres that will allow touchdown to occur within the touchdown zone of the runway of intended landing.

Section ENR 1.5, paragraph 1.10.1 (relevant sections only), further instructed:

A missed approach must be executed if:

c. visual reference is not established at or before reaching the missed approach point from which the missed approach procedure commences; or

d. a landing cannot be effected from a runway approach

Workload

In the context of aviation, workload has been described as ‘reflecting the interaction between a specific individual and the demands imposed by a particular task. It represents the cost incurred by the human operator in achieving a particular level of performance’ (Orlady & Orlady, 1999). A person experiences workload differently, based on their individual capabilities and the local conditions at the time.

Research on unexpected changes in workload during flight has found that pilots who encounter abnormal or emergency situations experience a higher workload with an increase in the number of errors compared to pilots who do not experience these situations (Johannsen & Rouse, 1983). Additionally, Harris (2011) states that:

‘The underlying concept is that cognitive workload is a product of competition for limited information processing resources.' Wickens and others (2016) add that when workload becomes excessive, ‘people may shed tasks in a non-optimal fashion, abandoning those that should be performed.’

In particular, the task of monitoring the state of important items in the cockpit can be one of the tasks shed by a single pilot. The United Kingdom Civil Aviation Authority publication Monitoring Matters provides the following information regarding monitoring:

…whilst you are ahead of the game, concentrating on the next event, keeping an eye on all the flight parameters, system modes etc everything runs fairly smoothly. But as soon as something draws your attention away and you become out of the loop it becomes difficult to play catch up.

While it is possible to attend to more than one task using selective attention techniques, there is a limit to cognitive capacity. If tasks consume this capacity, task shedding will occur. This publication further advises that under high workload, especially during approach and descent, attention capacity diminishes. This includes the ability to detect when the configuration of the aircraft is not correct, even when there is an aural or visual alert, particularly in the case in single pilot operations as:

…the processes and procedures will be equivalent to multi crew operation except there will only be one person in the cockpit and the systems may be less automated. Hence the need to monitor the flight profile, flight instruments, fuel state, engines, radio, etc. diligently. The instrument scan must be carried out very frequently, especially during departure and approach in order to monitor the aircraft state and planned profile.

Aircraft details

The Beech 200 is a pressurised, twin-engine turboprop aircraft with retractable landing gear and was approved for single-pilot operation. VH-ODI was manufactured in 1980 and was configured with two flight deck and 11 passenger cabin seats (Figure 4). One of the flight deck seats was also available for passenger use.

Figure 4: VH-ODI

Figure 4: VH-ODI.
Source: Mike Didsbury, modified by ATSB

Source: Mike Didsbury, modified by ATSB

Operational warning systems

The aircraft was fitted with a landing gear warning system. This system is designed to help prevent a pilot from landing with the landing gear retracted. The system in ODI was designed to activate when the flaps were selected to the ‘full’ position and the landing gear was not down and locked. When activated, the system emitted a warning tone through the flight deck speaker and illuminated red lights within the landing gear position selector handle (Figure 5).

Figure 5: Exemplar landing gear control lever and warning light extinguished (left) and illuminated (right) (see note)

Figure 5: Exemplar landing gear control lever and warning light extinguished (left) and illuminated (right) (see note).
Source: Aircraft maintainer Note: the image is only intended to illustrate the handle warning light. It is not intended to represent the landing gear configuration at the time of the occurrence.

Source: Aircraft maintainer

Note: the image is only intended to illustrate the handle warning light. It is not intended to represent the landing gear configuration at the time of the occurrence.

The aircraft was also equipped with a ground proximity and warning system (GPWS). This system was designed to alert a pilot if an unsafe aircraft terrain closure rate or aircraft configuration was detected. When activated, the system emitted aural spoken word alerts through the pilot and observer’s headsets.

The aircraft was fitted with a stall warning system to provide the pilot with aural warning of an imminent aerodynamic stall. The stall warning system senses angle of attack through a lift transducer actuated by a vane mounted on the leading edge of the left wing. Depending on aircraft configuration and flight condition, the stall warning system will activate between 5‑14 kt prior to a stall occurring.

Damage

The aircraft sustained damage to both propellers, the left engine and the fuselage (Figure 6). The damage resulted in fragments of the left propeller penetrating the left side of the fuselage and a significant oil leak from the left propeller shaft (Figure 7). The damage to the left engine led to the failure of that engine upon the application of power for the go-around.

Figure 6: Forward fuselage damage

Figure 6: Forward fuselage damage.
Source: Airport operator.

Source: Airport operator.

The right propeller sustained less severe damage. The pilot and observer did not detect any deterioration in performance from the right engine and were not aware of the damage to this propeller until after landing.

Figure 7: Propeller and engine damage

Figure 7: Propeller and engine damage.
Source: Airport operator.

Source: Airport operator.

Recorded data

Cockpit voice recorder

The aircraft was equipped with a Fairchild Model A100S cockpit voice recorder (CVR). The recorder captured the final 22 minutes of the flight. The aircraft was not required to be, and was not, fitted with a flight data recorder.

Table 1 is a list of key events captured by the CVR during the accident flight. Events marked with inverted commas (‘’) are automated voice alerts from the ground proximity warning system.

Table 1: Cockpit voice recorder key events

TimeEvent
1215:19Commencement of accident approach
1218:55Pilot announces commencement of approach descent
1218:59Sound of landing gear extension
1221:18Observer announces that the minimum descent altitude has been reached
1221:27The pilot announces that a go-around will be conducted
1221:31Sound of landing gear retraction
1221:34GPWS alert - ‘check gear, check gear, check gear’
1221:40Both the pilot and observer announce that the runway is in sight
1221:40Engine power reduces
1221:40 –
1222:17
Landing gear warning tone commences and activates continuously for this period
1221:49GPWS alert - ‘check gear, check gear, check gear’
1221:50The pilot announces that the landing gear is down
1221:50GPWS alert - ‘pull up, pull up’
1222:03Sound of first propeller contact
1222:05Sound of second propeller contact
1222:10Observer announces that an engine has failed
1222:14Pilot announces landing gear and flap retraction. (No landing gear retraction sound is audible.)
1222:17Landing gear warning tone ceases activating
1222:19 –
1222:35
Stall warning activates intermittently during this period
1224:05Sound of landing gear extension
1224:34Sound of touch-down
Security camera footage

A Mount Gambier Airport security camera overlooking the apron area of the airport captured ODI during the occurrence approach and the subsequent landing approach (Figure 8).

The magnification of the footage led to a reduction in image quality. However, the footage showed the landing gear as dark objects beneath the aircraft during the landing approach. The dark objects were absent in the footage of the occurrence approach, consistent with the retracted landing gear.

Figure 8: Mount Gambier Airport CCTV captures of ODI and representative images of a B200

Figure 8: Mount Gambier Airport CCTV captures of ODI and representative images of a B200.
Source: Airport operator and ATSB.

Source: Airport operator and ATSB.

Similar occurrence

ATSB investigation AO-2016-072 (VH-ETW)

On 4 July 2016, a Piper PA31-325 aircraft, registered VH-ETW, arrived at Birdsville Airport, Queensland. At the end of the downwind leg of the circuit, the pilot selected the landing gear handle down and noted that the landing gear selector moved out more easily than normal. During the turn onto the base leg, the pilot felt something against his right knee and found that the landing gear selector handle had become partially detached. The pilot inserted the handle back into the landing gear selector lever and retracted and extended the landing gear to ensure that it operated correctly. The landing gear subsequently retracted without the pilot’s knowledge.

The aircraft touched down with the landing gear retracted and the pilot assessed that the safest option was to conduct a go-around. The pilot then conducted a circuit and landed without further incident. The pilot and passengers were uninjured and the aircraft had minor damage to the propellers.

  1. The B200 observation flights did not meet the requirements of aeronautical experience.
  2. If local atmospheric pressure information (QNH) was available, the MDA could be lowered by 100ft. QNH was available at the time via the Mount Gambier Aerodrome Weather Information Service. However the pilot later reported that the minima used for the accident approach was 730 ft, and this was consistent with the cockpit voice recording.

Safety analysis

During an approach to Runway 18 at Mount Gambier in poor weather conditions, the aircraft touched down with the landing gear retracted, with the propellers contacting the runway twice before the pilot initiated a go‑around. The following analysis will consider the development of the occurrence and the subsequent decision to conduct a go‑around.

Continued approach and non-detection of retracted landing gear

Upon reaching the minimum descent altitude, the pilot could see ground directly below the aircraft, but could not obtain visual reference with the runway ahead. Therefore, he appropriately elected to conduct a go-around and retracted the landing gear. However, prior to beginning to climb the aircraft, the pilot sighted the runway and elected to continue the approach, but inadvertently did not re-extend the landing gear.

In response to the landing gear configuration, a number of automated aural and visual alerts activated. However, neither the pilot nor observer recognised that the landing gear was retracted.

It has been well-demonstrated that people are more likely to detect targets when they are expected and less likely to detect targets when they are not (Wickens & McCarley, 2008). This lack of detection occurs even when targets are salient, important and in an area to which a person is looking (known as inattentional blindness) (Chabris & Simon 2010).

When considering expectancy, a range of conditions may have influenced the pilot not detecting that the landing gear remained retracted (despite the automated alerts), including:

  • He retracted the landing gear during a time of high task loading associated with obtaining visual reference with the runway environment, which may have precluded the recollection that it was actually retracted.
  • The pilot was likely highly focussed on the landing at the time.
  • Errors of omission are often difficult to detect by the people who make them (Sarter & Alexander 2000).

In summary, the pilot’s ability to detect the retracted landing gear was likely reduced by his expectation that it was extended. In addition, he retracted the landing gear during a high task loading time which could have precluded the recollection that this was its latest state. This, combined with the high task loading during the continued approach in a complex aircraft, possibly meant that the task of confirming the configuration of the aircraft was shed.

Although the observer was also a pilot, she did not have the defined responsibility of monitoring the operation of the aircraft and was not assigned a ‘pilot monitoring’ role as is the norm in a formal multi-crew operation. In addition, the pilot did not announce that the landing gear had been retracted, further reducing her ability to detect the landing gear position.

She later recalled not hearing the landing gear-related aural alerts, although the cockpit voice recorder captured that she did emphasise to the pilot the ‘pull up’ EGPWS alerts. However, when these alerts were emphasised, the pilot announced that he would continue the approach. Therefore, a similar call regarding the landing gear may also have gone unheeded, as evidenced by the pilot’s reaction to the GPWS ‘check gear’ alert.

Go-around after the wheels-up landing

Prior to the wheels-up landing, the pilot understood the landing gear to be extended and stated so in response to the GPWS ‘check gear’ alert. This misperception of the landing gear position persisted through the two touch-downs and go-around.

The pilot, believing that the aircraft had bounced twice on the landing gear, that it was not responding to wheel brake inputs and that he could not engage reverse thrust, assessed that a runway overrun was imminent. This indicated that he was also very likely unaware of the substantial airframe damage sustained and why he assessed a low‑level go-around clear of cloud as the safest option.

Findings

From the evidence available, the following findings are made with respect to the wheels-up landing involving Beech Aircraft Corporation B200, VH-ODI that occurred at Mount Gambier Airport, South Australia on 8 December 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • The pilot elected to continue the approach after initially deciding to conduct a go-around. The pilot's expectation of the landing gear position, possibly coupled with the effects of the now increased workload, probably led to him not detecting the retracted landing gear before the aircraft contacted the runway.

Other findings

  • After the wheels-up landing, the decision to conduct a go-around resulted from the pilot’s misunderstanding of the situation and assessment that a runway overrun was imminent.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the aircraft operational documents
  • the pilot/aircraft operator
  • the observer
  • the maintainer
  • the Civil Aviation Safety Authority
  • Airservices Australia
  • the Bureau of Meteorology
  • the air traffic radio recordings
  • the airport operator.

References

Wickens & McCarley, 2008. Applied attention theory. CRC Press: Boca Raton, USA

Chabris & Simons, 2010. The invisible gorilla. Random House: New York, USA

Johannsen, G & Rouse, WB, 1983. Studies of planning behaviour of aircraft pilots in normal, abnormal, and emergency situations. IEEE Transactions on Systems, Man and Cybernetics, (3).

Orlady, HW, & Orlady, LM, 1999. Human factors in multi-crew flight operations. Ashgate: Aldershot, UK.

Wickens and others, 2016. Engineering Psychology and Human Performance. Psychology Press: New York, USA.

Harris D, 2011. Human Performance on the flight deck. Ashgate: Aldershot, UK.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the pilot’s next of kin,[9] the observer and the Civil Aviation Safety Authority (CASA).

Submissions were received from the pilot’s next of kin and CASA. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

  1. The pilot was fatally injured in unrelated circumstances during the course of this investigation.

General details

Pilot details

Licence details:Air Transport Pilot Licence (Aeroplane)
Endorsements:Tail-wheel Undercarriage, Manual Propeller Pitch Control; Retractable Undercarriage; Multi-engine Centreline Thrust, Pressurisation System, Gas Turbine Engine
Ratings:Single Engine Aircraft, Multi Engine Aircraft, DC3, Instrument Rating Multi Engine Aircraft, Instrument Approach Procedure 3D, Instrument Approach Procedure 2D
Medical certificate:Class 1, valid to March 2019
Aeronautical experience:Approximately 14,200 hours
Last flight review:November 2018

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2018-080
Occurrence date 08/12/2018
Location Mount Gambier Airport
State South Australia
Report release date 20/05/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Wheels up landing
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Beech Aircraft Corp
Model 200
Registration VH-ODI
Serial number BB-634
Aircraft operator Desert-Air Safaris
Sector Turboprop
Operation type Charter
Departure point Adelaide Airport, South Australia
Destination Mount Gambier Airport, South Australia
Damage Substantial