On the morning of 22 January 2019, a British Aerospace (BAe) 146-300, registered VH-NJZ, landed in Sydney, New South Wales, en route from Melbourne, Victoria, to Brisbane, Queensland on a scheduled freight operation.
Before commencing the cargo-unloading process, a tail strut was attached to the rear of the aircraft. After completion of the cargo-unloading and loading process, the aircraft was taxied for departure to Brisbane with the tail strut still attached. During the take-off roll, the tail strut detached, resulting in the runway being contaminated with foreign object debris.
The complete tail strut was recovered from the runway and the aircraft continued to Brisbane, where it landed without further incident.
What the ATSB found
The ATSB found that pre-departure checklist items, required to be performed by the captain and engineer in a challenge-and-response manner, were not completed. This negated the value of the checklist as a risk control, and resulted in a missed opportunity to detect the tail strut’s presence prior to departure.
The ATSB also found that the engineer performing the aircraft turn-around had no effective means or procedure to contact the aircraft while it was taxiing. As a result, and despite attempting various methods, the engineer was unable to alert the flight crew that the tail strut was still attached to the aircraft.
What's been done as a result
Following the occurrence, the operator disseminated Safety Alerts to relevant staff highlighting the despatch procedure, including the challenge-and-response requirement for the relevant cockpit to ground checklist.
The operator also provided appropriate control tower telephone numbers to engineering staff at all operating bases, allowing them to contact the tower immediately if required.
Finally, the operator emailed all company pilots, further highlighting the despatch procedure. This included the requirement that when the aircraft’s tail strut was not used, the local ground support equipment tail strut was to be visible to the flight crew prior to aircraft despatch.
Safety message
Checklists are an essential tool for overcoming limitations with memory, and ensuring that action items are completed in sequence and without omission. While their value may not be obvious for routinely performed tasks, the incomplete use of checklists has been cited as a factor in previous aircraft accidents.
The occurrence
What happened
On 22 January 2019, a British Aerospace 146-300, registered VH-NJZ (NJZ), was being operated by National Jet Express on a scheduled freight service between Melbourne, Victoria and Brisbane, Queensland via Sydney, New South Wales. At about 0415 Eastern Daylight-saving Time,[1] NJZ landed in Sydney and exited the runway for freight-loading operations.
A licenced aircraft maintenance engineer employed by Cobham Aviation Services reported marshalling NJZ in, and the flight crew subsequently shut down the aircraft’s engines. The engineer placed chocks at the nose wheels and instructed the flight crew to release the parking brake. The engineer positioned boarding stairs at the forward left cabin door and attached a tail strut[2] to the rear of the aircraft (Figure 1). The tail strut was part of the Sydney Airport ground support equipment. The engineer also had the option of using a tail strut that was carried on board the aircraft.
The engineer reported opening the aft lower cargo hold door, on the rear right side of the aircraft to retrieve the sill protectors.[3] The engineer waited for the aircraft freight door to be opened remotely by the captain, installed the sill protectors, and conducted an external visual inspection of NJZ. After the inspection, the engineer engaged in a brief conversation with the flight crew, and returned to the line hut to await completion of loading by the loading team.
The captain reported completing an external visual inspection of the aircraft then returned to the cockpit to plan the next sector to Brisbane with the first officer. Upon completion of loading by the loading team, the captain positioned himself at the top of the boarding stairs and the engineer returned to the aircraft. The engineer removed the freight door sill protectors and signalled the captain to commence lowering the freight door. After the freight door was closed, the engineer visually checked that it was flush with the aircraft skin and that the locks had correctly engaged. The engineer then signalled the captain that the freight door had locked correctly. The captain replied with a thumbs-up, entered the aircraft and closed the cabin door behind him.
The engineer proceeded to the aft lower cargo hold door on the right side of the aircraft, stowed the sill protectors, closed and locked the cargo hold door. The engineer then walked back around towards the front of the aircraft and positioned the boarding stairs clear. The engineer connected a headset to the nose of the aircraft for communications with the flight crew and removed chocks from the nose landing gear wheels. The engineer then took up a position at the nose of the aircraft to commence communications with the flight crew for engine start.
The captain confirmed communications with the engineer, and the engineer responded ‘stowed and closed, you are clear all four’. The flight crew proceeded to start all four engines. After the engines were all started successfully, the engineer disconnected the headset, closed the communications panel, and proceeded into the line hut to put away the headset and torch. At 0451, NJZ taxied forward out of the bay and then toward holding point Golf for take-off on runway 16R.[4]
Figure 1: Example of a tail strut fitted to NJZ and showing opened freight door
Source: Cobham Aviation Services Australia
At that time, a ground staff member from a different company arrived at the line hut on a tug and informed the engineer that NJZ had commenced taxiing with the tail strut still in place. Leaving the line hut, the engineer proceeded outside and saw that NJZ had commenced taxiing towards the runway. The engineer began pursuing the aircraft on foot, and attempted to attract the captain’s attention by waving his arms and shouting. The engineer, realising he wouldn’t be able to get the pilots’ attention, joined the ground staff member on the tug and proceeded after NJZ.
The engineer did not have a contact number for the Sydney Control Tower and was therefore unable to inform them of the situation quickly. Instead, he telephoned National Jet Express Maintenance Watch[5] and asked them to contact the flight crew to inform them of the situation. National Jet Express Maintenance Watch relayed the message to National Jet Express Operations,[6] who in turn attempted unsuccessfully to contact both pilots by mobile phone.
The engineer, realising that he was not going to catch NJZ prior to it entering the runway, approached a nearby works safety officer. As the engineer was asking the safety officer to immediately contact the tower via radio, to prevent NJZ from taking off, the aircraft turned onto runway 16R, powered up and departed.
The captain reported that during the take-off roll, he felt his phone vibrating in his pocket but did not answer as he was concentrating on the departure.
Following the aircraft’s departure, Sydney Tower closed Taxiway Bravo and runway 16R to allow a visual inspection to take place. A Sydney Airport ground safety worker subsequently located the tail strut, took photographs, and recovered the multiple components (Figure 2). The photographs of the recovered tail strut components were sent to the engineer’s mobile phone and the engineer confirmed that the entirety of the tail strut had been recovered. The engineer relayed this information to National Jet Express Maintenance Watch, who passed it on to the captain. The captain, satisfied that the entire tail strut had departed the aircraft, continued the flight to Brisbane.
On arrival at Brisbane, air traffic control requested that NJZ land on a secondary runway in case there was any residual part of the tail strut still attached to the aircraft. The aircraft landed and stopped on the runway without incident, and the rear of the aircraft was inspected by a Brisbane Airport ground safety officer. NJZ was then permitted to taxi to its bay. Engineers subsequently inspected the rear of the aircraft and no damage was evident.
Figure 2: Tail strut as found on Sydney runway 16R post NJZ departure
Source: Sydney Airport
Operator despatch procedure
The operator’s Bae146 Aircraft Ground Operations manual detailed the cockpit to ground communication requirement as listed in Table 1.
Table 1: Stand-Off Bay Despatch Using Intercom Checklist
Captain
Ground Crew
“Cockpit to Ground”
“Ground”
“Confirm all doors and access panels closed and locked, (and where applicable) tail strut removed and sill protectors stowed”
“All doors and panels closed and locked, (and where applicable) tail strut removed and sill protectors stowed”
“Brakes parked, clear to remove chocks”
“Chocks removed”
“Ready to start all engines or Engines 3 & 4, 1 & 2 “ as appropriate”
“Clear to start” as appropriate
“Start completed clear to disconnect”
“Disconnecting”
The engineer stated that during the turnaround of NJZ, prior to stowing the sill protectors, he walked past the tail strut and did not remove it. The captain and engineer commenced the required checklist prior to engine start. During this verbal exchange the challenge-and-response checklist was shortened to ‘We are stowed and closed you are clear for all four’. Immediately after the engineer disconnected communications from the aircraft the engineer proceeded into the line hut. He reported that this did not allow him an opportunity to view the tail strut as the aircraft taxied past.
Safety analysis
During pre-departure checks, the verbal exchange between the captain and engineer was not performed in accordance with the Stand‑Off Bay Despatch Using Intercom challenge-and-response checklist. While that was possibly the result of it being a routinely performed task, it negated the value of the checklist as a risk control, and presented a missed opportunity to detect the tail strut prior to departure.
The engineer had no effective means or procedure to contact the aircraft while it was taxiing. Despite that, he attempted various methods to contact the flight crew but was unable to alert them to the tail strut still being attached to the aircraft prior to take‑off.
Findings
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
During pre-departure checks, the full checklist between the captain and engineer was not completed. This negated the value of the checklist as a risk control and resulted in a missed opportunity to identify that the tail strut was still attached to the aircraft prior to it departing the bay.
The engineer had no effective means or procedure to contact the flight crew while the aircraft was taxiing. As a result, the flight crew were not alerted to the error prior to take‑off.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Following this occurrence, on 23 January 2019, Cobham Aviation Services issued a Safety Alert to relevant staff that highlighted the despatch procedure including the cockpit to ground checklist requirements.
Cobham also provided appropriate control tower telephone numbers to engineering staff at all operating bases. This allows staff to immediately contact the tower if a need arises.
Cobham also emailed all company pilots, further highlighting the despatch procedure. This included the requirement that when the aircraft’s tail strut was not used, the local ground support equipment tail strut was to be visible to the flight crew prior to aircraft despatch.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the morning of 19 January 2019, a Eurocopter EC130 helicopter, registered VH-YHS, conducted a private flight from Moorabbin Airport to an authorised landing area (ALA) near Mansfield, Victoria with the pilot and two passengers on board. A return flight to Moorabbin was planned for later that afternoon.
At about 1500 (Australian Eastern Daylight Time - AEDT), the pilot and passengers boarded the helicopter at the ALA for the return flight. The pilot prepared for take-off and lifted off the helicopter more rapidly than he normally did. As the helicopter became airborne, it began to rotate counter-clockwise (yaw to the left). The pilot tried to control the yaw but the helicopter quickly turned through 360° and, unable to control it, he made a decision to land the helicopter.
The left skid of the descending helicopter subsequently contacted the ground, resulting in a rolling movement that led to the main rotor blades striking the ground. The collision destroyed the aircraft, the pilot sustained minor injuries however the passengers were uninjured.
What the ATSB found
The investigation did not identify any airworthiness issues with the helicopter and it was considered that the loss of control was not attributable to a mechanical issue. It was also determined that the prevailing light winds did not contribute to the loss of control.
The pilot reported that he did not lift the helicopter into a balanced hover, and tried controlling its yaw mainly with the cyclic control instead of through the full application of opposing right, tail rotor pedal. Management of unanticipated yaw in helicopters with shrouded tail rotors (Fenestron) is the subject of the manufacturer’s guidance and learnings from similar accidents.
Safety message
This accident demonstrates the criticality of helicopter pilots understanding the aircraft’s characteristics so that they can anticipate its response when becoming airborne, and are not surprised by events. Controlling yaw in helicopters with a Fenestron tail rotor, as in this case, is an important consideration. Airbus Helicopters and the European Union Aviation Safety Agency (EASA) provide specific guidance relating to this issue to assist pilots.
The occurrence
What happened
At 1033 Eastern Daylight‑saving Time[1] on 19 January 2019, a Eurocopter EC130 helicopter, registered VH-YHS (YHS), departed Moorabbin Airport for a private authorised landing area (ALA), 19 km south-south‑east of Mansfield, Victoria. The pilot and two passengers were on board for the private flight to a rural property and intended to conduct a return flight that afternoon. The pilot’s pre-flight inspection had not identified any defects or outstanding maintenance issues for the helicopter.
At 1115, after an uneventful flight, YHS landed at the rural property. Over the next few hours, the pilot attended to various matters there as planned, and had lunch with the passengers.
Shortly before 1500, the pilot and passengers returned to the helicopter. The helicopter was parked in an open area, facing south with a 0.5 m-high earth mound to its left (Figure 1). The mound prevented water entering the nearby shed and ran the length of the area, which had clusters of trees around it in different directions. The pilot had undertaken five previous flights to the property in the helicopter in the previous 5 months.
After assisting the passengers to board the helicopter, the pilot conducted a walk-around and did not identify anything unusual. He then boarded and, following a normal engine start, carried out his take-off checks. As was his usual practice, he set the friction settings for both the cyclic[2] and collective[3] controls to minimum resistance.[4] The wind was about 10 kt from the south-west (about 45° to the right of the helicopter), the sky was clear and it was approximately 30º C.
As the pilot increased to full power for take-off, he observed that the front right passenger had not put on her headset and signalled for her to do so. While he waited for her to put the headset on, keeping YHS on the ground, he noticed the cabin temperature was 32 ºC and turned on the air‑conditioning.
Shortly after 1500, the pilot was again ready to take-off. He raised the helicopter off the ground, more rapidly than he normally did without getting the usual ‘fine balance’[5]. At a height of about 3 m above the ground, the helicopter began to yaw to the left (turning counter-clockwise), seemingly pivoting about the tail and its attitude became progressively unstable (Figure 1, Top).
The pilot applied inputs, mainly cyclic, to control the helicopter’s movement but the yaw increased. The aircraft now seemed to be pivoting about the main rotor, moving closer to the trees and shed (Figure 1, Middle). The pilot recalled that the helicopter felt ‘unstable’ and moved the cyclic but did not get the response he expected. In seconds, the helicopter had turned through 360° (Figure 1, Bottom). Unable to control the helicopter, the pilot decided to land and lowered the collective.
As the helicopter descended, its left skid contacted the mound, resulting in the helicopter pivoting around that skid and the main rotor blades striking the ground. The helicopter came to rest on its left side, facing the shed (Figure 2). The sequence, from lift-off to ground contact, occurred over about 5 seconds.
The pilot turned off the engine and battery, exited through the shattered left windscreen and assisted the passengers from the helicopter. The pilot sustained minor injuries while the passengers were uninjured.
Figure 1: Accident sequence
Source: ATSB analysis of information from pilot and witness video (partial) superimposed on Google Earth image
Figure 2: Accident site
Source: Seven News Melbourne, annotated by ATSB
Pilot
The pilot completed his helicopter flight training in a Hughes 300 helicopter in 2010. He completed EC130 type training in November 2011 and had accumulated 227 flight hours in that aircraft (from a total of 315 flight hours). Since his last flight review in November 2017, he had flown YHS for 13.5 hours of which 4 hours had been in the 90 days preceding the accident – the last flight being 46 days prior.
The pilot commented that he had:
not heard or seen anything unusual with the helicopter before the accident
tried controlling the yaw mainly with the cyclic, did not know how much right pedal he had used and assessed that he should have used more pedal to control yaw
not flown regularly since his last flight review and noted that during his EC130 type training he had needed more pedal input than in the Hughes 300.
Aircraft information
The EC130 is a single-turbine engine helicopter with a clockwise-turning main rotor and a shrouded Fenestron tail rotor (Figure 2). The helicopter has a maximum take-off weight of about 2,427 kg and can carry seven occupants. The EC130 is a high-performance helicopter compared to the Hughes 300 (in which the pilot first trained). The Hughes 300 has a counterclockwise turning main rotor and a conventional unshrouded tail rotor.
The EC130 with its Fenestron anti‑torque system[6] requires greater right pedal[7] input to overcome torque from the main rotor during lift off than a helicopter with a conventional tail rotor. The pedal control inputs are also not linear with respect to the effect on helicopter yaw.
The helicopter’s manufacturer (Airbus Helicopters) published service letter 1673-67-04 in February 2005 with guidance for managing yaw. The letter reminded pilots that the Fenestron anti‑torque system requires more right pedal travel than a conventional tail rotor to counter left rotation (yaw). The letter stated that if sufficient pedal is not applied quickly to correct yaw, its rate will increase. Further, insufficient pedal input to stop yaw combined with pilot input to decrease altitude could result in the helicopter rolling to the side and contacting the ground.
Post-accident activities
There was no recorded data to determine the flight control inputs and their effect on the motion of YHS during the accident. The pilot’s account, a partially obscured witness video, and photographs of the wreckage were the main sources of evidence.
The maintenance organisation for YHS carried out an examination at the accident site before moving the wreckage to its maintenance facility. This examination found no evidence of airworthiness issues that could have resulted in the accident. It was also determined that the helicopter was within its performance envelope and had sufficient fuel for the planned flight.
The ATSB sought the manufacturer’s input for this accident and was advised that as no technical (mechanical or control) issues with YHS had been identified by the maintenance organisation, the accident was probably the result of a handling error.
In July 2019, about 6 months after the accident, Airbus Helicopters published safety information notice 3297-S-00 to highlight unanticipated yaw. The notice warned that an unanticipated yaw can be rapid and is most often toward the left (where the main rotor rotates clockwise). It further noted that even if the pilot’s response was prompt, the yaw might not immediately subside and lead to the pilot thinking that the input was ineffective.
Similar accident
In October 2015, an EC130 helicopter was departing Megève altiport, France, for a sightseeing flight when the pilot lost control of the aircraft, which collided with the ground (BEA2015-0647 report). The helicopter was destroyed, and the seven occupants were injured.
The pilot had 300 flight hours in helicopters, including 9.5 hours in an EC130 and 74 in the similar AS350 helicopter. The investigation found that while stabilised in the hover, the pilot initiated a left turn to face the climb out direction. However, the pilot was unable to stop or slow the yaw and decided to land, lowering the collective. The helicopter yawed through several more revolutions before colliding with the ground. No technical issues to explain the accident were identified.
As part of the investigation, a flight in a helicopter of the same type in similar conditions was undertaken, and it was found that pushing the right pedal to 70 per cent of its travel stopped a yaw rate of 100° per second to the left in 3 seconds.
Safety analysis
The earlier flight made by VH-YHS (YHS) that day indicated the helicopter was operating normally with no defects. The high-performance helicopter was also operating well below its maximum capacity with only three occupants.
In preparing to take-off, the pilot lifted YHS more rapidly than he normally did without first letting it rest lightly on the skids and applying control inputs to lift it gently into a balanced, controlled hover for the climb out. The higher-than-normal application of control inputs resulted in the torque from the main rotor not being balanced by the anti-torque from the Fenestron tail rotor. Consequently, once the helicopter was off the ground it yawed significantly to the left. The wind from the right may also have initially increased the yaw rate.
The pilot’s pre-take-off checks did not confirm that everyone and everything was ready for the flight. As a result, he had to delay the take-off while a passenger put on her headset. He then noticed the elevated temperature and turned on the air-conditioning. These interruptions may have influenced his actions in lifting off more rapidly than he normally did.
The rate of left yaw offered limited time to regain control. The pilot reported that he principally applied cyclic control rather than the required full application and maintenance of opposing right, tail rotor pedal input. When his applied inputs did not arrest the yaw rate, the pilot assessed that the best option was to land the helicopter.
Similar accidents in the same or comparable helicopters, together with manufacturer’s guidance, provide information for pilots to manage unanticipated yaw and avoid accidents. These show that the outcome of YHS’s attempted landing with a significant yaw rate was somewhat predictable - a skid contacting the ground, the helicopter rolling over and the main rotor blades striking the ground. The rapid development of the accident sequence (about 5 seconds) also illustrates the limited time for pilot actions/decisions in such hazardous situations, which fortunately did not result in serious injury in this case.
The maintenance organisation’s examination found no evidence of airworthiness issues with YHS to explain the accident. The pilot’s account and the manufacturer’s comments also support a conclusion that a mechanical issue and the light wind did not contribute to the accident.
Findings
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
The pilot was unable to control VH-YHS yawing to the left after lifting off and decided to land. When the left skid of the descending helicopter contacted the ground, it rolled over and the main rotor blades struck the ground, destroying the aircraft with the pilot sustaining minor injury.
No mechanical issue with the helicopter was identified and the prevailing light wind did not contribute to the loss of control and subsequent collision.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
At about 0825 Eastern Standard Time on 9 January 2019, an Insitu ScanEagle X200 (X200) unmanned aircraft system was launched to conduct ‘beyond visual line of sight’ aerial survey work in the Woleebee Creek area of Queensland. The flight crew consisted of two pilots and two ground crew.
Shortly after launch, one of the ground crew observed the X200 pitch up and then enter an aerodynamic stall. The flying pilot commenced the emergency procedures for a stall-spin, however the X200 self-recovered before the checklist was completed. At about the same time the pilots received an alert indicating an airspeed sensor failure and initiated the associated emergency procedure checklist.
Before visual sight was lost, the ground crew observed the X200 oscillating in pitch as it continued to fly to the programmed first waypoint. While the flying pilot was executing the emergency procedures checklist, the X200 entered a second aerodynamic stall. Following self‑recovery from a low height above terrain, the X200 commenced a climbing orbit. Shortly after, the X200 entered a third aerodynamic stall, this time from a height that was insufficient for recovery, and collided with terrain. There was no post-impact fire and the X200 was destroyed. There were no reported injuries to people or damage to infrastructure. A post-incident inspection of the X200 identified a partial blockage in the pitot system.
What the ATSB found
The investigation found that the blockage in the pitot-static system resulted in unreliable airspeed data being supplied to the autopilot. Unreliable airspeed data led to the X200 entering an aerodynamic stall at a height that was insufficient for recovery.
During the pre-flight checks, there were opportunities for the erroneous airspeed indications to be identified. However, they were not recognised by the crew or flagged by the ground control station.
What's been done as a result
Following the occurrence, the manufacturer revised their procedures to reduce the risk of aircraft being affected by a pitot blockage. Additionally, all of the operator’s pilots underwent refresher training. This included emergency procedures simulator experience.
The X200 manufacturer revised their procedures to provide support to pilots and ground crew in correct assembly of the articulated turret, identifying anomalies (on the ground and in-flight), and steps for aircraft recovery in the event of a departure from normal flight. In addition, updates to the operational software would ensure any spurious on‑ground anomalies were alarmed, to prevent the X200 being launched with an unidentified issue.
Safety message
This occurrence highlights the importance of confirming the significance of any unexpected observations during the pre-flight checks, to minimise the risk of the aircraft departing with an unserviceability. In addition, providing pilots and ground crew with the reasoning behind specific checks and procedures can enhance their ability to identify anomalies and perform the appropriate corrective actions in a timely manner.
Insitu ScanEagle X200
Source: Insitu Pacific
The occurrence
What happened
On the morning of 9 January 2019, the Insitu Pacific (the operator) crew prepared to conduct a 4‑hour ‘beyond visual line of sight’ survey flight, in the Woleebee Creek area, about 350 km west‑north‑west of Brisbane, Queensland. The flight was being conducted by an Insitu ScanEagle X200 (X200).
The crew consisted of two remote pilots[1] (one acting as mission controller/pilot in command and one acting as pilot flying) and two ground crew (who were also qualified remote pilots).[2] The two pilots for this flight were located in the ground control station (GCS).[3] Headsets were worn by all crew members, to enable effective communication. All crew reported to being ‘refreshed’ and looking forward to the day’s flight.
The X200 was launched at 0825 Eastern Standard Time.[4] The crew described the launch as ‘textbook’. The secondary ground crew member maintained visual contact with the X200, typically done until advised by the pilots that they had video feedback from the on-board camera.[5] He reported that, about one minute after launch, the X200 pitched up ‘quite high’, before entering an aerodynamic stall.[6] He immediately advised the pilot flying (PF) with the standard phrase ‘wings level, wings level, you’re stalling’. At this time, the primary ground crew member also observed the X200 in a ‘left-hand spin’ and advised the PF ‘you’ve stalled, wings level, wings level’.
At the same time, the GCS identified the stall condition and projected the ‘stall-spin’ emergency procedures checklist to the display. The PF commenced the checklist items, however the X200 self‑recovered before the checklist was completed. The ground crew reported the X200 recovered ‘low to the ground’ and then commenced a climb to return to the programmed flight altitude.
At about the time of the recovery from the first stall, the GCS initiated the warnings and emergency procedures checklist for an ‘airspeed failure’. Upon the mission controller’s direction, the PF commenced the airspeed failure checklist. The ground crew reported that following a ‘steep’ climb, the X200 was then observed to be ‘porpoising’ (oscillating in pitch) while it continued to the first programmed waypoint. Shortly after this, the X200 flew beyond visual sight of the ground crew.
Telemetry data showed that, about 90 seconds after the first stall, the X200 entered a second stall. The X200 self-recovered again, at about 150 ft above the ground, and commenced a climbing orbit. After about 30 seconds, the X200 entered a third stall and impacted the ground eight seconds later. The mission controller advised the ground crew that the X200 had been lost. Total flight time was less than four minutes and distance from the launch site to the collision with terrain location was about 4.75 km (Figures 1 and 2).
Figure 1: X200 flight path
Source: Insitu Pacific and Google Earth, modified by the ATSB
Figure 2: X200 flight profile
Source: Insitu Pacific and Google Earth, modified by the ATSB
Post-accident recovery and inspection
The aircraft impacted the ground near vertically, there was no post-impact fire and the X200 was destroyed. There was no evidence of in-flight break-up or collision with vegetation or infrastructure prior to the impact. In addition, there were no reported injuries. The operator conducted an examination of the occurrence X200 and identified a partial blockage in the pitot system, which was subsequently confirmed by the manufacturer. The blockage appeared to be a combination of a section of O-ring debris and grease.
Flight operations
The Civil Aviation Safety Authority (CASA) issued the operator with an authorisation to operate the X200 beyond visual line of sight, within a defined area. Some of the authorisation’s requirements included:
all remote pilots were to hold a CASA authorisation
a mode C transponder[7] was to be operational, and transmitting accurate barometric altitude, on all flights
a primary and secondary ‘fail safe’ mode to ensure that, in the event of data-link loss, the X200 did not depart the area of operation and would land at a pre-determined location
air traffic control at Brisbane was to be advised of the intended operation 15 minutes prior to launch, and the crew were to maintain standard airspace radio procedures for the duration of the flight
the operator was to ensure a current Notice to Airmen (NOTAM)[8] was active for each operation
the X200 was only to be operated in visual meteorological conditions.
In addition to the CASA authorisation, the operator’s procedures included:
no flight over populous areas
operations were conducted at altitudes intended to avoid agricultural and passenger aircraft.
Remote pilots underwent a 10-week course prior to being endorsed to operate the X200. This course included a theory component and time in the simulator. The pilots recalled that ‘airspeed failure’ was included in the course, however they felt that particular emergency procedure wasn’t focussed on as ‘heavily’ as others.
The accident site was located within the defined operational area, which was in accordance with the authorised requirements.
Aircraft information
The ScanEagle is a small, long-endurance, low-altitude unmanned aerial system (UAS) built by Insitu, a subsidiary of Boeing, and is used for defence and civilian applications (the X200 variant). The X200 (Figure 3) has a wingspan of 3.1 m, a length of 1.6 m, maximum take‑off weight of about 23 kg and a typical cruise speed of 50-60 kt.
The nose module (payload) on the X200 is interchangeable, depending on the type of mission being flown, and was supplied by the payload manufacturer. The payload fitted to the X200 at the time of the occurrence consisted of a camera assembly located in an articulated turret (turret). The camera could be directed through a defined fore/aft arc and the turret rotated through 360˚.
The pilot controls the X200 entirely through the aircraft autopilot from launch until recovery. The aircraft’s flight path is controlled by position, altitude and airspeed commands through the remote pilot station computer (part of the ground control station), which is then sent to the aircraft autopilot. The pilot does not have a control yoke, or equivalent, that links directly or indirectly to the aircraft control surfaces.
Typically, once the X200 has launched, the pilot commands it through a pre-planned sequence of locations and orbits around each location of interest. At the completion of the flight’s activities, the pilot would position the aircraft in preparation for the recovery phase using the same method of control. In this instance, the emergency procedure checklist actions involved the pilot utilising additional X200 autopilot control laws in order to negate the erroneous airspeed information.
Figure 3: X200 with articulated turret
Source: Insitu Pacific, modified by the ATSB
Pitot-static system
The pitot-static system senses ram air pressure through the pitot probe (on the forward face of the payload) and static air pressure through the static ports (on each side of the payload). The two pressures are used to calculate true airspeed (TAS) and barometric altitude (Alt). The autopilot uses this data to calculate the minimum and maximum airspeed in relation to the weight of the X200 and to maintain controlled flight.
The pitot and static tubes for the X200 were routed from the pitot probe and static port through the turret and connected to the pitot-static tubing in the fuselage. If not correctly oriented during assembly, the tubes could become pinched, blocked or damaged with turret operation. Obstructed pitot-static tubes have the potential to cause incorrect TAS and Alt calculations, affecting autopilot operation.[9] In addition, the TAS and Alt indications to the pilots would also be unreliable. The manufacturer alerted X200 operators to this potential condition in November 2017, via both a service advisory and an operational advisory. Damage sustained to the X200 during this occurrence prevented testing for possible turret interference.
The service advisory (SA) provided expanded procedures for pitot and static tube routing and connection, and inspection procedures if an anomaly was identified during pre-flight checks. A review of the X200 maintenance records showed the turret had been installed as per the SA in July 2018. Since then, it had been operated for about 80 hours, without indication of turret interference.
The operational advisory (OA) included:
information about how to identify and troubleshoot different types of incorrect TAS and Alt indications on the ground and in-flight
a pre-flight function test to identify incorrect TAS and Alt indications shown on the ground control station (GCS) program
in-flight emergency procedures to normalise the incorrect TAS and Alt indications and avoid loss of controlled flight.
The function test was to be completed before every flight and the OA provided examples of how anomalies with the pitot-static tubing may appear on the GCS display. Where inspection and routing of the pitot-static tubes did not rectify the anomaly, the turret was to be replaced prior to next flight. The OA procedures had been incorporated into the GCS program at the time of the occurrence.
In addition, the payload manufacturer identified a quality issue with the turret assembly procedures that had the potential to induce a blockage in the pitot system. The operator identified that the occurrence X200 was affected by this quality issue, consisting of excess grease and O‑ring debris forming the pitot-system partial blockage. The X200 manufacturer published procedures to inspect (and, if required, clean) turrets that were in-service and prior to fitment. The operator examined the remainder of their fleet with these revised procedures, with no further occurrences identified.
Pre-flight checks
As part of the pre-flight procedures, the primary ground crew conducted an inspection of the X200 while the secondary ground crew readied the launcher and recovery systems. At the same time the pilots, located in the GCS, conducted their pre-flight systems checks, which included a function test of the pitot-static system (Figure 4). This test included the primary ground crew fitting a sealed clear tube to the pitot probe, which increased pressure in the system and simulated an airspeed indication associated with forward flight (equivalent to TAS). The procedure stated that any reduction in pressure (TAS) indicated on the GCS during the test, equal to or greater than the specified limits, was indicative of a system leak that required rectification prior to flight.
During the test, a slow rise of about 10 kt TAS occurred, while the indicated altitude remained steady. The OA detailed that if the TAS ‘increases slowly without turret movement or pressurisation of the pitot-static system’, this was an indication of a blockage in the pitot-static system. As per the OA, turret movement had the potential to induce a restriction in the pitot system tubing, which could ‘clear’ with subsequent movement. The pitot system was pressurised and the turret was being operated for part of this test and as such, the rise in TAS as a possible indication of a blockage may have been difficult to identify. Following this occurrence, a revised OA amended the criteria for the slow increase in TAS to show ‘at any time’ during the procedure, removing any ambiguity surrounding pitot pressurisation and turret movement during the tests.
With no pitot system leak identified by the pilots, the tooling was removed. At this time, the pilot flying (PF) commented that the TAS was ‘slow to release’ (return to pre-check indication). The primary ground crew member reported that he heard this comment however, he took no action as he wasn’t aware of the significance of this indication. The pilot pre-flight checklist identified that slow to release pressure was indicative of a blockage in the pitot system.
Following completion of the crew’s pre-flight checks, the GCS continued with the system self‑checks, while the crew met outside for a pre-mission brief, as per their standard procedure. During the time the crew were outside, the GCS self-check indicated an anomaly within the pitot‑static system. In this instance, there was an increase over time in TAS, while the Alt decreased. For this indication, the procedures required an inspection of the pitot-static system prior to launch. However, this indication was not flagged or latched.[10] Therefore, when the pilots returned to the GCS, there was nothing to alert them to this additional indication of a pitot system anomaly.
Figure 4: Pitot pressure test indications
Source: Insitu Pacific, modified by the ATSB
All subsequent pre-flight checks were described as normal. Weather conditions at the time were recorded as overcast conditions, 22˚C, a wind speed of about 6 kt and were described by the crew as ‘ideal’.
Autopilot and the occurrence flight
The X200 autopilot control loops rely on airspeed to control altitude. The target airspeed for the occurrence flight was 53 kt. Recorded data shows that following launch, the TAS reached 70 kt. This resulted in the autopilot commanding a rapid pitch up to try to arrest the perceived high TAS. The pitch attitude was too great for the actual airspeed, which resulted in the X200 entering an aerodynamic stall. Stall recovery took 12 seconds, with an altitude loss of 579 ft (at a rate of 48 ft/s), before the X200 began to climb back to the programmed flight altitude.
Erratic TAS is one of the parameters that can lead to a stall-spin in the X200. Flight data showed that erratic TAS was present from launch, before the turret was unlocked and operated. This was consistent with a blockage of the pitot system, rather than turret interference.
The erratic TAS also resulted in the porpoising flight profile following the first stall and recovery. Following about 80 seconds of porpoising flight, the data showed another rapid increase in TAS. The autopilot likely commanded the X200 to increase pitch attitude, which again resulted in an aerodynamic stall and rapid reduction in height. Within 12 seconds, the X200 had again self‑recovered from the stall, but at a much lower altitude than the first recovery. The second stall required 778 ft for self-recovery (at 64.83 ft/s rate of altitude loss).
This was followed by another extreme increase in TAS, leading to the third stall. This stall was at a similar rate to the second stall. Recovery was again initiated but only 591 ft was available and the X200 collided with terrain, about 9 seconds later (Figure 5).
Figure 5: Flight data showing erratic indicated airspeed and altitude
Source: Insitu Pacific, modified by the ATSB
Safety analysis
Following launch, the Insitu ScanEagle X200 (X200) twice entered an aerodynamic stall and self‑recovered. The X200 entered a third stall, this time at a lower height, and did not recover prior to collision with terrain. The analysis will examine the pre-flight indications of the pitot system blockage and its effect on the flight.
Pre-flight checks
The pre-flight checks provided three opportunities for anomalies in the pitot static system to be detected. There was a slow rise in TAS, which was indicative of an anomaly in the pitot system. The pressurisation of the pitot system and movement in the turret during the pitot-static function test, however, may have meant that the slow rise in TAS and the physical blockage was not obvious. The slow reduction in TAS after the pressure test was an indication of a pitot system blockage. This was noted by some of the crew, however the significance of this indication was not recognised.
The ground control station (GCS) system self-checks showed an additional indication of a pitot system anomaly, however it was not observed by the crew, as they were carrying out other duties at the time. At the completion of the self-checks, there was no ‘flag’ or other indication on the GCS that the pitot system irregularity had occurred. This resulted in the indications of pitot system anomaly not being identified by the crew or flagged by the GCS, resulting the X200 being launched with a blockage in the pitot system.
Unreliable airspeed data
The X200 autopilot uses true airspeed (TAS) and altitude (Alt) data to maintain controlled flight. The blockage in the pitot system resulted in unreliable airspeed data being provided to the autopilot, affecting calculation of TAS. While there remained the possibility that the turret interference may also have been present, it could not be determined as contributory in this occurrence. Flight data showed that erratic (TAS) data was present from launch, before the turret was unlocked and operated. Subsequent movement of the turret may have alleviated any turret‑induced restriction in the pitot system but due to the presence of the identified blockage, the airspeed data was unreliable even without any turret interference.
Following launch, the autopilot interpreted the TAS as increasing and increased the pitch (nose up) to maintain target airspeed. This resulted in the X200 nose-up attitude being too great for the actual airspeed and led to an aerodynamic stall. The X200 self-recovered and recommenced the climb to operating altitude.
Following recovery from the first stall, flight data showed the TAS was oscillating by up to 30 kt, resulting in the ‘porpoising’ flight profile, indicative of the autopilot trying to maintain controlled flight using unreliable airspeed data. A rapid 30 kt increase in TAS likely led to the autopilot increasing pitch attitude, resulting in the second aerodynamic stall. Again, the X200 self-recovered, however at a much lower altitude. A third rapid TAS increase followed shortly after, leading to the final stall, with insufficient height available for recovery.
Findings
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Erroneous airspeed system indications during the pre-flight checks were not identified by the crew or flagged by the ground control station, resulting in the X200 being launched with an unserviceable pitot-static system.
A blockage in the pitot-static system resulted in unreliable airspeed data being supplied to the autopilot.
Unreliable airspeed data led to the X200 entering an aerodynamic stall at a height that was insufficient for recovery.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
The operator
As a result of this occurrence, the operator advised the ATSB that the following safety actions, in cooperation with the X200 and payload manufacturers, have been undertaken:
Pilot training
Following the occurrence, all of the operator’s remote pilots underwent refresher training with a focus on identification and emergency procedures regarding incorrect true airspeed (TAS) and/or barometric altitude (Alt) indications. The training consisted of theory (including ‘how’ the system works and symptoms of pitot-static blockage) and several hours’ simulator experience of failures and use of emergency procedures. Feedback from the pilots following this training was positive. In addition, the ATSB was advised that the X200 manufacturer will amend the ab-initio pilot training to highlight pitot-static system anomalies and associated pre- and in-flight procedures.
Training and enhanced procedures can provide ‘reasoning’ behind the steps. This can assist pilots and maintainers in their understanding of indications and events, prompting effective actions and timely resolution.
The manufacturer
Documentation and procedures
The X200 manufacturer published a revised Operational Advisory (OA) on 18 February 2019. One amendment in this revised publication was the inclusion of an image from the occurrence X200, showing the Ground Control Station indication for ‘slow to release’ pitot pressure. The criteria for the slow increase in TAS was also amended to ‘at any time’ during the procedure, removing any ambiguity surrounding pitot pressurisation and turret movement during the tests.
In addition, the revised OA included an additional caution (in red text) warning that the ‘TAS error exceeds launch limit alarm is disabled for pre-flight pitot-static system checks. Therefore, it is critical to monitor the TAS-ALT-Tachometer plot throughout the on ground phase for any abnormal TAS or Alt signatures’. The operator reported that the X200 manufacturer advised a ‘latching system alarm’ would be incorporated into the next software release (scheduled for mid-2019) to alert the crew where the TAS has exceeded a threshold during on-ground checks.
Further, the manufacturer revised their procedures for assembly of the turret and provided a reworked procedure to X200 operators to reduce the risk of in‑service aircraft being affected by a pitot blockage.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 6 January 2019, SCT Logistics freight train 6MP9 derailed near Cook, South Australia, while travelling from Melbourne, Victoria to Perth, Western Australia. The number 36 vehicle on the consist, wagon ARFY 2198T, experienced a ruptured wheel, resulting in the derailment. No other wagons derailed in the occurrence and there were no injuries.
What the ATSB found
Thermal damage to the wheel resulted in the initiation of a fatigue crack in the flange which propagated into the plate. Cracking then continued propagating around the plate, branching out to the rim, resulting in the wheel failure and ultimate derailment of the wagon.
At the last inspection, the flange fatigue crack was likely observable but was either not detected, or was deemed acceptable under the work instruction provided. This work instruction provided guidance that was less conservative than the Australian Standard, but it was not possible to establish whether compliance with the standard would have prevented the occurrence.
What's been done as a result
SCT Logistics has worked with their primary maintenance provider to develop an improved inspection process for wheels exhibiting issues with brakes (e.g. sticking brakes), as these issues can lead to heat-related fatigue cracks.
SCT Logistics also plans to phase out the type of wheelsets that ruptured in the occurrence, in favour of a type that is less prone to the development of fatigue cracks due to thermal issues.
Safety message
Vigilant field inspections are a useful tool for the detection and monitoring of fatigue cracks. However, they are not infallible, and should be utilised with an understanding of their limitations.
Further, selection of the appropriate materials can assist in reducing the occurrence of fatigue cracks and subsequent wheel failures.
The occurrence
What happened
On the evening of 4 January 2019, SCT Logistics freight train 6MP9 departed Melbourne, Victoria for Perth, Western Australia. At 0635 Central Daylight‑saving Time[1] on 6 January 2019, the train derailed at 869.700 km in the Fisher-Thomiar section, near Cook, South Australia. The derailment involved the number 36 vehicle on the consist, wagon ARFY 2198T. One of the wheelsets on the ‘B’ end of the wagon experienced a ruptured wheel, resulting in the derailment (Figure 1). No other wagons derailed as a result of the rupture, however gouges in the rail were found, as well as some broken sleepers and missing clips.
Prior to the derailment, the train passed over two wayside detectors designed to alert the operator of abnormalities that might indicate wheel or bearing damage. There was no record of any alerts received from these detectors.
Figure 1: The ruptured and derailed wheel in situ
Source: SCT Logistics
Context
Wheelset examination
The majority of the failed wheelset pieces were recovered from the accident site. These pieces and the adjacent wheelset were sent to SCT Logistics’ primary maintenance provider, Gemco Rail (Gemco), for a preliminary inspection. This examination was attended by the ATSB, the Office of the National Rail Safety Regulator, and independent consultants, Bureau Veritas.
A visual examination of the wheel found two potential fatigue regions on the ruptured wheel. One of these was within the flange of the wheel, while the other was within the plate (Figure 2). The wheelset and fragments were then provided to Bureau Veritas for an independent metallurgical examination, in order to determine the nature of, and possible reasons for, the failure.
Figure 2: Two fatigue regions in the flange (left) and the plate (right)
Source: ATSB
Metallurgical examination
Bureau Veritas found that the wheelset met the chemical and hardness requirements for Class C wheel material, as specified by the Association of American Railroads (AAR). The second wheelset on the derailed bogie was recorded as Class B. Both wheel-types were permitted, but Class C wheels were harder with less ductility.
The examination confirmed that two regions of fatigue cracking were present in the wheel. The wheel failed as a result of cracking that initiated at the wheel flange. The fatigue crack on the flange propagated into the rim, and the mode of cracking changed from fatigue to brittle fracture. The crack then propagated into and around the wheel plate, connecting to the second fatigue crack within the plate. The propagation continued through the plate, branching out into the rim at various locations and resulting in the wheel rupturing into multiple pieces when it finally failed. This fracture sequence is illustrated in Figure 3, where blue arrows indicate the direction of crack propagation.
Figure 3: Recovered wheel fragments with direction of crack propagation
The blue arrows indicate the direction of crack propagation. The letters and numbers were used in the Bureau Veritas examination report to identify the different fragments and cracks, respectively.
Source: Bureau Veritas, modified by ATSB
The fatigue crack on the flange (crack 4 in Figure 3) was determined to be a thermal crack, 20 mm in length at the surface, formed in a white etching layer. Thermal cracks are caused by rapid changes in the temperature at the surface of the wheel. The presence of a white etching layer confirms a rapid temperature change occurred, as these layers are regions where the steel has transformed into martensite. Martensite is a brittle form of the metal created by heating and rapid cooling, and is more susceptible to cracking than the original flange material.
Bureau Veritas reported that the fatigue crack in the plate region may have initiated at non‑metallic inclusions found in that part of the wheel. However, this could not be confirmed due to damage at the fracture region because of the wheel failure.
Additional thermal cracks were identified near the crack on the flange (crack 4), although these did not propagate into the rim or the plate. The two largest additional cracks measured 12 mm and 15 mm in surface length (Figure 4). Bureau Veritas reported that the cracks in Figure 4, including the one that propagated into the plate, occurred in a region with evidence of sliding, rather than rolling, contact. Sliding contact can lead to rapid temperature changes in the flange, and the resultant formation of a white etching layer.
Figure 4: Thermal cracks adjacent to the flange fatigue fracture region
The surface has been cleaned and prepared for examination. Coloured dye has been used to highlight the cracks.
Source: Bureau Veritas, annotated by ATSB
Comments from the wheel manufacturer
Following the release of Bureau Veritas’ examination report, the wheel manufacturer reviewed and provided comment on the included observations/findings. The manufacturer assessed that the inclusions observed near the plate fatigue cracking were innocuous, and unlikely to provide a suitable site for the initiation of a fatigue crack. They also asserted that the size of the inclusions was within the acceptable range under AAR standards. The manufacturer believed that the fatigue crack likely initiated after the flange crack propagated into the plate, and the wheel lost its rigidity.
The manufacturer also noted that class C wheels were relatively hard, and that:
Class C material being high carbon, high hardness and lower ductility is not generally recommended for tread breaking applications with high thermal load and potential thermal issues.
Wheel maintenance history
Wheelset 39867 was originally fitted with Class C forged wheels on 22 February 2015. It was inspected and reprofiled on 12 October 2016 and again on 19 September 2018. The wheelset was installed on the occurrence wagon (ARFY 2198T) on 28 September 2018. A field inspection, known as an A2 inspection, was performed on the wagon on 10 December 2018, which included an examination of the wheelset. The wagon passed the inspection and returned to service. No wheel cracking or other damage was noted prior to the derailment on 6 January 2019.
The A2 inspection was performed with the wagon on rails, so a small part of the wheel would have been obscured. The inspection involved various checks, which included:
ensuring the wheel dimensions were within limits
looking for defects or damage on the tread
looking for signs of overheating
inspecting any visible cracks.
Inspection standards for thermal cracks
Gemco provided a work instruction to personnel performing A2 inspections, which instructed them to classify thermal cracks based on their size and location. A Class 4 thermal crack was defined as one longer than 10 mm within the flange or edge of the rim, or any crack longer than 40 mm. This definition was based on the Rail Industry Safety and Standards Board (RISSB) Wheel Defects Code of Practice. The Code of Practice, which was referenced by the Australian Standard for rolling stock wheels, defined Class 4 thermal cracks as any crack visible on the flange, cracks longer than 10 mm on the edge of the rim, or any crack longer than 40 mm. The presence of a Class 4 crack required the train speed to be limited to 40 km/h until the wheel could be replaced.
Figure 5 compares the definition provided by Gemco’s document with the one from the RISSB Code of Practice. The only difference between the two definitions was that Gemco permitted flange cracks up to 10 mm long, while RISSB did not permit flange cracks of any size. Under Gemco’s work instruction, flange cracks below 10 mm did not fit under any classification and therefore did not need to be recorded.
Figure 5: Definition of Class 4 thermal cracks provided by Gemco (left) and RISSB (right)
Source: Gemco, RISSB
Safety analysis
The white etching layer observed on the flange fatigue crack indicated that the wheel was exposed to abnormally high temperatures at some point, probably due to sliding contact with the rail. Exposure to such temperature altered the material property of the steel and facilitated initiation of a fatigue crack, which propagated from the flange into the rim and then the plate. The Class C wheel type may have increased the wheel’s susceptibility to fatigue cracking compared with the softer Class B wheels on the adjacent wheelset.
The crack progressed through the plate and joined with a second fatigue crack. The reason for this second crack’s initiation could not be determined, nor could it be determined whether it initiated as a result of the flange crack or if it was already present in the wheel. However, given the extent of cracking at this point, it did not appear to have a significant effect on this wheel failure. Cracking then continued propagating around the plate, branching out to the rim, resulting in the wheel failure and ultimate derailment of the wagon.
Examinations following the derailment found that the flange fatigue crack and the adjacent thermal cracks were longer than the 10 mm stated in the work instruction. As an inspection for thermal cracks was carried out 27 days prior to the wheel failure and derailment, it is likely that one or more of these cracks were present at the inspection, but they may have been missed, or obstructed by the rail.
It is also possible that the cracks were observed by the inspector, but were visually assessed as smaller than 10 mm long. If the cracks had a surface length below 10 mm, then under Gemco’s work instruction they would not have required any action, and their presence would not need to be recorded.
Without further details from the thermal crack inspection, it was not possible to determine whether or not the derailment would have been prevented if the work instruction prohibited all thermal cracks on the flange, as described in the more conservative RISSB Code of Practice.
Findings
From the evidence available, the following findings are made with respect to the derailment of SCT Logistics freight train 6MP9, near Cook, South Australia on 6 January 2019. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Thermal damage led to the initiation and propagation of a fatigue crack through the wheel flange. This may have been exacerbated by the wheel type, which was more susceptible to thermal cracking. The crack progressed through the wheel plate, and ultimately resulted in the wheel failing.
The flange crack that led to the wheel failure was likely present at the last inspection, but was either not detected, or was an allowable length based on the maintenance provider’s work instruction.
The maintenance provider’s work instruction for classifying thermal cracks on the wheel flange was not as restrictive as the Australian Standard.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
The operator and maintenance provider
As a result of this occurrence, SCT Logistics worked with Gemco to develop an improved inspection process for wheels exhibiting issues with brakes (e.g. sticking brakes) – as these issues can lead to the development of thermal cracks.
SCT Logistics has also instructed Gemco to only install Class B wheelsets when replacements are needed, so that Class C wheelsets are phased out of the fleet through attrition.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 8 January 2019, as The Overland passenger train, 3MA8, approached the Thompson Road level crossing at North Geelong, Victoria, the train crew noticed that the flashing lights had not activated and the boom gate had not lowered as expected. While the crew noticed the irregularity, it was too late to take substantive action and the train passed through the level crossing unprotected. The crew reported that several road vehicles were in the vicinity of the level crossing at that time, but none were in the danger zone.
What the ATSB found
The ATSB found that, in preparation for stage one track work, the Thompson Road level crossing was to be isolated for the broad and dual-gauge tracks only. The level crossing protections for the adjacent standard-gauge track, which was to continue operating as normal until stage two works at a later date, were to remain active. However, the signalling tester, following the isolation plans provided, mistakenly isolated the level crossing for the stage two work, in addition to stage one. While the stage one and stage two works were to be conducted separately, the signalling tester‑in-charge provided the signalling tester with the isolation plans for both stages in one package.
VicTrack, through their contractor UGL Engineering Limited, did not provide the tester-in-charge or signalling testers with specific instructions detailing the scope of work to be conducted at each stage of the project, but rather, only provided packaged isolation plans for the entire project. The absence of these instructions increased the risk of the works being incorrectly implemented.
What has been done as a result
As a result of this occurrence, VicTrack has advised that improvements had been made at the task‑based level by including specific work instructions for each task associated with each isolation plan.
Safety message
A work instruction is a step-by-step guide on how to perform a specific task or activity, in support of a process or procedure. They are an important defence within a safety system for ensuring the work is performed safely and as intended. This occurrence highlights the importance of providing clear, concise, and detailed work instructions to reduce the risk of errors during critical safety work.
The occurrence
Preparation for planned track work
On the morning of 8 January 2019, planned track work was to commence at the North Geelong, Victoria ‘C’ signal box. The work, managed by VicTrack, involved the removal, modification, and installation of signalling equipment and was to be performed in several stages over January 2019. Stage one affected the two broad-gauge and single dual-gauge tracks (managed by V/Line) and would temporarily impact the operation of several level crossings including those at Thompson and Anakie Roads. Stage two involved works on the adjacent Australian Rail Track Corporation (ARTC) standard-gauge track, to be performed at a later date (see Planned work).
At about 0734 Eastern Daylight-saving Time,[1] a track warrant possession (TW2)[2] was issued to exclude rail traffic and allow the work to proceed safely. The exclusion applied to trains operating on the two broad-gauge and single dual-gauge tracks (stage one). The ARTC standard‑gauge track would be protected between train services,[3] but remain operational, as specified in the project planning documents and ARTC Train Notice 2668,[4] until stage two.
Prior to commencing the work, several briefings were conducted involving the various project work teams. The signalling tester-in-charge (TIC) also conducted a separate pre-work briefing with the signal test teams (see Personnel involved). Specifically, the TIC reported mentioning that the standard-gauge track would remain open for normal traffic, but would be protected. The ARTC certified signalling tester (signalling tester) also attended the briefings, but could not recall any discussions regarding train movements.
The TIC, that morning, provided the signalling tester a package of isolation plans (wiring drawings) for the work (see Isolation plans and package), which included the plans for both the stage one and stage two works. Following this, a test team (test team 1), consisting of the signalling tester and an assistant, made their way to the equipment relay room[5] near the Thompson Road level crossing at North Geelong.
For the work, some of the signalling infrastructure at the Thompson and Anakie Road active level crossings needed to be electrically isolated for the broad-gauge and dual‑gauge tracks. In preparation for this, the signalling tester assembled the electrical jumpers needed to isolate each circuit identified on the isolation plans.
Level crossing isolation
At 0954, the TIC contacted the network control officer (NCO) to arrange an infrastructure booking advice[6] for Thompson Road. Shortly after, the TIC notified the signalling tester at the equipment relay room to commence work. The tester began applying the jumper cables[7] to the relay contacts of all four tracks to isolate the Thompson Road level crossing, as detailed within the packaged isolation plans provided (see Isolation plans and package).
At about 1048, after applying the jumper cables, the tester verified that the level crossing was functioning by activating the local push-button.[8] Upon verification, the team left and made their way to the next crossing at Anakie Road. The test triggered an alarm on the Phoenix control system[9] display in the ARTC train control centre in Adelaide, South Australia. The NCO received a level crossing fault alarm, and the ‘Thompson Road’ text changed colour to red to indicate it had been activated (Figure 1). The NCO immediately contacted the operations coordinator[10] and asked if the crossing was okay, and not affected, and would operate as normal. The operations coordinator advised the NCO that the crossing should operate as normal.
Figure 1: Phoenix replay of the Thompson Road level crossing alarm
Note: The level crossing fault alarm is a pop-up dialog box, not shown in this image. Time is Central Daylight-saving Time (CDT), Coordinated Universal Time (UTC) +10.5 hours.
Source: ARTC, annotated by the ATSB
Once at Anakie Road, the tester began applying the isolations, similar to the process followed at Thompson Road.
Train 3MA8 approaching Thompson Road
Soon after, The Overland passenger train 3MA8 was nearing the Thompson Road level crossing, operating on the ARTC standard-gauge track. The train crew had been previously made aware by the NCO that track workers were operating at the North Geelong ‘C’ signal box. As the train approached, the crew noticed that the level crossing lights had not activated and the boom gates had not lowered. In response, they commenced braking, reduced the throttle, and sounded the horn to alert approaching road traffic. At about 1054, the train passed through Thompson Road at a reported speed of about 50 km/h, with the level crossing protections inactive. Although there was road traffic in the vicinity of the crossing, no vehicles were in the danger zone[11] at the time the train passed through. The Phoenix replay (Figure 2) showed the ‘Thompson Road’ text white, indicating the crossing was not active as 3MA8 passed (represented by the red line).
The crew contacted the NCO and advised of the occurrence. The train continued its journey as normal. The Anakie Road level crossing, about 650 m further along from the Thompson Road level crossing, operated normally for train 3MA8.
Figure 2: Phoenix replay of the occurrence
Note: Time is Central Daylight-saving Time (CDT), Coordinated Universal Time (UTC) +10.5 hours.
Source: ARTC, annotated by the ATSB
The NCO immediately called a project representative in the site office near Separation Street who spoke with the TIC about the occurrence. The TIC then contacted the tester, now located at Anakie Road. The tester, who was in the process of applying the jumper cables (but had not yet isolated the level crossing), stopped work and returned to Thompson Road. The TIC also proceeded to Thompson Road.
From about 1120, the TIC reinstated and tested the affected level crossings. During this process, it was determined that the tester had applied jumper cables to all tracks, consistent with stage two implementation. All further work was suspended until further notice. Later that day, an ARTC representative validated the reinstatement actions and normal working resumed through the Thompson Road level crossing.
The Thompson Road level crossing at North Geelong is located about 72 track kilometres south‑west from Melbourne, on the main line between Melbourne and Adelaide. The level crossing had active protections, which included physical barriers, warning signs, line markings, lights, and audible devices to alert vehicular or pedestrian traffic that a train was approaching or crossing.
The level crossing consisted of four railway tracks and a dual carriageway road, including a pedestrian pathway. All tracks ran adjacent to each other within the rail corridor.
V/Line managed both the broad-gauge and single dual-gauge tracks (yellow shading in Figure 3), and Australian Rail Track Corporation (ARTC) managed the single standard-gauge track (red shading in Figure 3). ARTC had primary maintenance responsibility for the level crossing infrastructure.
Figure 3: Aerial view of ARTC and V/Line responsibility boundaries
Source: VicTrack, annotated by the ATSB
Planned work
The North Geelong ‘C’ signal box allowed the management of rail traffic at Thompson Road, Separation Street, the Geelong grain loop, and the Corio independent goods line. The Victorian Government engaged VicTrack to undertake works to replace the current mechanical interlocking and signal control systems to allow the remote operation of the signal box from V/Line’s Centralised Train Control (Centrol). VicTrack engaged UGL Engineering Limited (UGL) as the principal contractor for the works, who in turn sourced suitably qualified staff from other third party providers as required. VicTrack retained oversight and responsibility for the project.
The scope of works undertaken were the disarrangement of track circuits and infrastructure to enable signal upgrades in the V/Line leased area only (Figure 3). The work was to be undertaken during the month of January 2019 in several stages as part of Train Notice 2668:
Stage one (yellow shading in Figure 3): 8‑22 January 2019, isolation of the dual-gauge, broad‑gauge, arrival, and departure tracks at Thompson Road; and south line at Anakie Road.
Stage two (yellow and red shading in Figure 3): 13 January 2019, isolation of all tracks at Thompson and Anakie Roads.
Stage three: 21 January 2019, testing.
Stage four: 22 January 2019, commissioning.
Regular planning meetings were held detailing the scope of work required, including the staged track possession of the ARTC standard-gauge track.
Personnel involved
As part of the broader project, an electrical work group was tasked with the electrical isolations of the signalling system. The group consisted of a signalling tester-in-charge (TIC) supervising two test teams, test team 1 and test team 2. Each team consisted of a signalling tester and assistant, who were appropriately qualified.
The TIC had the responsibility to ensure that the new and altered works were planned, installed, inspected and tested to design, standard and schedule. The signalling testers carried out testing activities as directed by the TIC and in accordance with relevant V/Line and ARTC procedures. Assistant signalling testers assisted with testing activities as directed by the TIC or a signalling tester.
Isolation plans and package
A work instruction is a step-by-step guide on how to perform a specific task or activity, in support of a process or procedure. They are an important defence within a safety system for ensuring the work is performed safely and as intended.
The isolation plan for each location was designed by UGL, then reviewed, and approved by all stakeholders[12] before the work commenced. The plans (Figure 4) contained critical information on what circuits were to be isolated, and identified each isolation jumper cable for each circuit. While each plan was associated with a certain stage of the project (see Planned work above), there was no supporting instructions provided in the package specifically detailing the scope of work to be conducted at each stage, nor were the plans marked to clearly identify at which stage that plan applied to.
The package was provided to the TIC by UGL prior to the commencement of the work. The package included the train notices, project planning documents, and isolation plans for the project.
Figure 4: One of the isolation plans for the North Geelong works stage 1
In preparation for planned track work for the upgrade of the North Geelong, Victoria, ‘C’ signal box, the Thompson Road level crossing was to be isolated for the broad and dual-gauge tracks only (V/Line tracks). The level crossing protections for the adjacent standard-gauge track (Australian Rail Track Corporation (ARTC) track), which was to continue operating as normal, were to remain active as trains would continue to use this track during stage one of the works. However, as The Overland passenger train (3MA8) approached the crossing on the ARTC track, the train crew noticed that the level crossing protections had not activated as expected. While the crew noticed the irregularity, it was too late to take substantive action and the train passed through the level crossing unprotected. The crew reported that several road vehicles were in the vicinity of the level crossing at that time, but none were in the danger zone. The ARTC Phoenix train control system replay confirmed the non-operation of the Thompson Road level crossing.
This analysis will examine why the level crossing protections did not activate as expected and review the documentation provided to signalling testers for isolating the Thompson Road level crossing.
Level crossing isolation
Following the packaged isolation plans provided by the tester‑in‑charge (TIC), the signalling tester applied the jumper cables to the V/Line track in preparation for the stage one works. Additionally, the tester also mistakenly applied the cables to the ARTC track, which should have been performed at a later time as part of the stage two works. The implementation of both stages isolated the V/Line tracks as well as the ARTC track, which was still operational for scheduled train movements. This resulted in the Thompson Road level crossing not operating for the approach and passage of train 3MA8.
While a pre-work brief had been conducted, the tester could not recall the specific details of that briefing. This was a missed opportunity for knowing that the level crossing for the ARTC track was to remain active.
The tester was notified about the occurrence before there was an opportunity to isolate the next level crossing at Anakie Road. However, it was possible that, had the tester applied the jumper cables for the Anakie Road level crossing, it too would have been incorrectly implemented, resulting in the isolation of the crossing protections for all tracks.
Packaged isolation plans
The TIC was provided the isolation package for the entire project by the principal contractor for the works, UGL Engineering Limited (UGL). This package contained the isolation plans for each location, including those for the stage one and stage two works, which were to be conducted separately. The TIC subsequently conducted a verbal pre-work brief with the signalling testers and assistants. During this brief, the TIC reiterated that the ARTC track would remain operational (stage one) and the level crossings active, distinguishing between the two stages. Despite this, the TIC provided the signalling tester with the entire isolation package, without modification, prior to the work commencing. Consequently, the tester had the plans for both stages, although the plans for stage one were only to be applied on the day of the occurrence.
No specific instructions provided
The principal contractor employed by VicTrack for the works, UGL, led the project planning, including the development and approval of the isolation plans. During this process, specific instructions detailing the scope of work to be conducted at each stage of the project had not been developed to support the isolation plans. Consequently, the absence of these instructions increased the risk of the works being incorrectly implemented.
In this case, UGL provided the TIC with a package containing the isolation plans for the entire project including the work to be conducted at Thompson Road, which in turn was provided to the signalling tester. However, without specific written instructions for each plan (at each stage), the tester mistakenly applied the isolation plans both stage one and two at the same time.
Findings
ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.
Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
From the evidence available, the following findings are made with respect to the Thompson Road level crossing failed to operate for the passage of passenger train 3MA8 on 8 January 2019.
Contributing factors
The Thompson Road active level crossing at North Geelong failed to operate as train 3MA8 approached and passed through the level crossing.
In preparation for stage one track work (broad and dual gauge-tracks) the signalling tester, following the isolation plans provided, isolated the level crossing for the stage two work (standard-gauge track), which was still operating trains.
The signalling tester-in-charge provided the signalling tester with the packaged isolation plans for both stage one and stage two works, which were intended to be conducted separately.
VicTrack’s contractor,UGL Engineering Limited, did not provide signalling testers with specific instructions detailing the scope of work to be conducted at each stage of a project, but rather, only provided packaged isolation plans for the entire project. The absence of these instructions increased the risk of the works being incorrectly implemented. (Safety issue)
Safety issues and actions
Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.
Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
The initial public version of these safety issues and actions are provided separately on the ATSB website, to facilitate monitoring by interested parties. Where relevant, the safety issues and actions will be updated on the ATSB website as further information about safety action comes to hand.
Safety issue description: VicTrack’s contractor, UGL Engineering Limited, did not provide signalling testers with specific instructions detailing the scope of work to be conducted at each stage of a project, but rather, only provided packaged isolation plans for the entire project. The absence of these instructions increased the risk of the works being incorrectly implemented.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
The Office of the National Rail Safety Regulator
VicTrack
Australian Rail Track Corporation
Pacific National.
Submissions
Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the following directly involved parties:
Australian Rail Track Corporation
Office of the Rail Safety Regulator
Pacific National
UGL Engineering Limited
VicTrack
V/Line
Submissions were received from:
Australian Rail Track Corporation
Office of the Rail Safety Regulator
Pacific National
UGL Engineering Limited
VicTrack
The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the 10 January 2019, a Bell Helicopter 205A-1, registered VH-HUE (HUE), was being used for external sling loading operations near Talbingo, New South Wales with the pilot as the sole occupant. As the helicopter approached the drop‑off site, the load unexpectedly disconnected from the remote cargo hook. One of two ground personnel was struck and seriously injured by the falling load.
What the ATSB found
Despite examination of the involved components, the reason why the load disconnected unexpectedly from the remote cargo hook could not be determined. However, the ATSB found that the loadmasters were not maintaining a safe distance from the load. Their positioning, in combination with the significant movement of the load as it contacted the ground, resulted in one of them being struck and seriously injured.
What's been done as a result
As a result of this accident, all contractors involved reviewed the procedures being used for helicopter lifting operations during this project. They have reviewed the risk controls for receipt and positioning of loads, based on the positioning precision required.
The operator who supplied the loadmasters has reviewed and updated their procedures. They have identified a ‘dynamic exclusion zone’ as a position above a person’s head height that is in the pathway of a potential uncontrolled load that may drop and impact onto a person. In recognition that the zone may vary due to a number of variables, specific guidance will be provided as part of pre‑activity briefings.
The lead contractor is overseeing a range of initiatives, including a behavioural safety review of the project with the intention to implement an appropriately designed program to positively influence behaviours across their projects.
Safety message
This incident highlights the dangers associated with external sling load operations. Unexpected events can occur and ground personnel should ensure they maintain their separation from external slung loads that are above head height. Each sling load operation can be unique, with different locations, load shape and environmental conditions creating different safety considerations. As a consequence, clear written procedures and detailed discussions prior to commencement of each operation are essential to ensure all participants are aware of the unique dangers of the operation.
Transport Canada commissioned a video titled ‘Keep your eyes on the hook’, which shows some of the dangers for ground crew when working around helicopters and longline loads.
The occurrence
What happened
On the 10 January 2019, a Bell Helicopter 205A-1, registered VH-HUE (HUE), was being used for external sling loading operations near Talbingo, New South Wales with the pilot as the sole occupant. As the helicopter approached the receiving site, the load unexpectedly disconnected from the remote cargo hook. One of two loadmasters assisting on the ground, was struck and seriously injured by the falling load.
Preparation for the operation
There were a number of different organisations involved in lifting operations on the day. The lead contractor had sub‑contracted two helicopter operators to move the equipment from a staging area near Tantangara Dam to a drilling site about 3 km away. The three organisations had conducted this type of work together a number of times. One helicopter operator (operator A) supplied an AS350B3 helicopter, long line, remote cargo hook, lifting equipment and three experienced loadmasters. The second operator (operator B) supplied HUE, a long line and remote cargo hook.
At around 0800 Eastern Daylight Time,[1] two of the loadmasters arrived at the staging site to begin preparations for the day. Both helicopters and the third loadmaster were delayed due to fog. The loadmasters checked all the lifting equipment, including the slings and shackles, for integrity and ensured they had been checked during the last routine equipment inspection. They then began working with the drilling crew to organise, weigh and rig the loads to be moved by the helicopters. The third loadmaster arrived after the fog had lifted, and they all worked together to finish rigging the loads.
Among the loads were three lots of drill rods on drill racks (Figure 1). The loadmasters decided not to use the lift points on the drill racks, as the lift points were not rated or stamped. Working together, the loadmasters ensured the weight of the loads were equal, secured the drill rods to the rack and rigged the slings, so the loads would be balanced during flight. To do this, they used two 6 m round slings, rated to carry 2,000 kg, choked at either end of the rod rack. The slings were then attached to a shackle, which connected directly to the remote cargo hook. A 5.6 m tag line was attached to the load, to assist with manoeuvring the load into the required position at the receiving site. The loadmasters rigged the loads a number of times before they were happy with the rigging.
Figure 1: Drill rods ratcheted to the rack and slings attached
The figure shows the drill rods ratcheted to the drill rod rack and the slings which are choked at the ends of the drill rack.
Source: NSW police, annotated by ATSB
After all the loads were rigged to their satisfaction, the pilots and loadmasters then held an aviation briefing where they discussed a helicopter lift plan. One of the loadmasters then led a toolbox talk, with all people involved in the day’s operations. They discussed every item on their company’s safe work method statement, which included known hazards. It was reported that the discussion clearly identified:
safe sites for people not involved in the helicopter lifting operations
the routes the helicopters would be taking
being mindful of avoiding the ‘crush zone’.
Inside the ‘crush zone’ there was an injury risk from contact with the external loads. There was no definition for the extent of the crush zone.
The loadmaster also highlighted that:
as taglines were being used, people should not become fixated on getting hold of them
ground personnel should not put themselves in a dangerous position and were to remain within the view of the pilot at all times.
The lead contractor then conducted a third briefing, which discussed their company’s expectations including radio communications, transfer of crew between the loading and receiving zone, staff resourcing of both the loading and receiving areas, and emergency procedures. It was reported that all three briefings were done methodically, with clear instructions and time for all involved to ask questions and understand their role.
The people who were being flown to the drill site were then given a helicopter induction. While this was occurring, inspections of the helicopter's cargo hook on the underside of the helicopter, long lines and remote cargo hook connections were conducted. This involved a number of release and reattachments of the long line to the cargo hook on the underside of the helicopter and a number of pilot-operated releases and manual releases by the loadmasters of the remote cargo hook. After the loadmasters had checked the shackles to ensure they fitted in the cargo hook throat (Figure 2), the group split up and went to their designated areas. One loadmaster went to the loading site and two went to the drill site, which was receiving the equipment. At the drill site, the supervisor identified the designated safe zone ensuring all personnel not involved in the lifting operations were within this zone and placed the emergency equipment to ensure easy access if required.
Figure 2: Cargo hook
Source: ATSB
Lifting operations
Operations commenced after lunch with a check of the radios. The loadmasters had VHF radios in their helmets, which they used to communicate with each other at the drill site and with the helicopter pilots. The pilot of HUE conducted the first lift and, having requested to start with a light load, moved an 800 kg load to the drill site with no issues. Loadmaster 1 conducted all radio communications with the pilot at the drill site. He reported that when the helicopter was clear of all obstacles along the approach path, he advised the pilot and then gave directions to position the load where it was required, with clear advice of the height of the load above the ground.
It was reported that one load carried by the AS350B3 was spinning on arrival at the drill site. In response, the pilot touched the load to the ground away from the loadmasters to stop the spin. The helicopter then lifted the load off the ground to about knee height and the loadmasters manoeuvred the load to its position on the site while directing the pilot.
Accident load
After moving two lighter loads, the pilot of HUE requested a heavier load be connected. The loadmaster selected one of the drill rod racks, weighing about 1,200 kg, and connected the shackle to the hook. As the load lifted, it was slightly uneven and the loadmaster instructed the pilot to return the load to the ground, so he could re-adjust the slings. The pilot lowered the load and placed the hook on the load. After adjustment to the sling, the load lifted evenly and was flown to the drill site (Figure 3).
Figure 3: Images showing the occurrence load during departure from loading site
The image on the left shows that on departure the load was slightly uneven, the image on the right shows the load after loadmaster had adjusted the slings.
Source: Helicopter Operator A, annotated by the ATSB
As the helicopter approached the drill site, the pilot contacted the loadmasters and advised them that he was carrying the drill rods. Loadmaster 1 told him that the load was to go to a different area of the site and advised that the wind had dropped to around 3–5 km/h (0.5–1.5 kt). Loadmaster 1 subsequently told the pilot that they could see the helicopter and gave him advice on directions and distance to run to the drill site. He then advised the pilot he could descend, calling out the load’s height above the ground. The loadmasters began to approach the load when it was at about 7 m above the ground. Loadmaster 1 later advised that the plan was to lower the load to touch the ground and then raise it to knee level before moving it to its final resting position. Both loadmasters were reportedly careful to maintain clearance with the area under the load and stood at 45° to the load. They were both on the same side of the load. It was reported that the load was steady as it was flown in to the drill site.
The load was moved very slowly down to an area having an estimated 10˚ slope, with loadmaster 1 being downhill of loadmaster 2. Loadmaster 1 observed loadmaster 2 step toward the load, reach up, take hold of the tagline and immediately step back out to regain their 45˚ spacing. Loadmaster 1 reported that the load was about 5 m above the ground at this stage and the pilot reported that the end of tagline appeared to be near the ground.
Loadmaster 1 reported that as loadmaster 2 returned to their position, the slight forward motion of the load stopped and the load moved back slightly towards the rising ground. As the load moved back, the load detached unexpectedly from the hook.
It was reported that as the load fell, it seemed like one end of the load fell faster than the other and after it struck the ground, the load either bounced or pivoted around. Both loadmasters had to scramble backwards away from the load but the movement resulted in loadmaster 2 being struck by the drill rods and knocked to the ground under the load.
The pilot reported that he felt the helicopter ‘pop up a bit’ and thought that a sling had snapped as he had not released the load. Loadmaster 1 advised that he did not hear the ‘clack’ sound associated with the solenoid release of the hook (see the section titled RemoteCargo hook). He advised that the sound of the solenoid activation was audible over the helicopter noise and while wearing a helmet.
Loadmaster 1 spoke to the helicopter pilot on the radio and advised him that the sling had not separated, the hook was useable and to bring the helicopter back to lift the load. The pilot re‑positioned the helicopter and loadmaster 1 re‑connected the load, which was then lifted off the seriously injured loadmaster.
Remote cargo hook
The remote cargo hook used by the operator of HUE was a TALON 6K half-cage cargo hook (Figure 2). This was the first operational use of this hook following a recent overhaul and was also the first time the helicopter (HUE) was used with this long line and remote hook combination.
The load beam on the remote cargo hook can be made to release by two methods:
a pilot-activated switch on the cyclic, which activated a solenoid in the hook to release the load beam
a manual release on the hook itself.
The hook and long line inspections conducted prior to the flight, included a number of activations of both of these release systems.
The pilot advised that, due to a previous injury to his hand, he had to deliberately move his hand to the top of the cyclic and move the switch sideways to activate the hook. As such, unintended load release by that mechanism was considered very unlikely. The ATSB viewed video footage of the helicopter pilot operating the switch at the top of the cyclic, which supported that conclusion.
The keeper was designed to allow items to enter the hook throat but not return. It opened toward the inside of the load beam and had a spring-loaded automatic return to the closed position.
Loading equipment examination
The slings, shackle and hook were examined by the ATSB. The inspection of the slings determined they were intact. To check that the load had not released through dynamic rollout,[2] the ATSB ensured that the hook and shackle combination did not allow the shackle to pass the end of the load beam. The cargo hook owner’s manual specified that the shackle used with this hook should have an inside diameter less than 11.4 cm. The internal diameter of the shackle used was 5.5 cm. A physical examination of the hook was conducted and it was determined that the manual release and the keeper worked as expected. The ATSB did not dismantle the hook or connect the hook to an electrical supply.
The ATSB examined video footage of the helicopter lifting the load from the loading site. It showed that the ‘D’ shackle was behind the keeper (Figure 4) when the helicopter departed and that the load was evenly balanced as the helicopter flew towards the drill site (Figure 3).
Figure 4: Image shows that the ‘D’ shackle was behind the keeper
The image shows that on departure after the load had been adjusted, the ‘D’ shackle was behind the keeper.
Source: Helicopter operator A, annotated by the ATSB
Electromagnetic interference
The ATSB also considered whether electromagnetic interference (EMI) could have resulted in the inadvertent release of the load. While this accident occurred in an area which has high voltage power lines from the Tumut 3 power station, the aircraft was about 35 km from the power station and 10 km from the closest high voltage power lines. Research suggests that magnetic radiation returns to normal levels at about 150 m from power lines.
A licenced aircraft maintenance engineer inspected the electrical system used on the helicopter to control the hook release mechanism and they reported that the system was working as expected. It was reported that there were no exposed wires within the system that could have resulted in a short circuit if exposed to electromagnetic interference from equipment in the aircraft. The helicopter operator also reported that the system has not had any issues with the hook release system since the accident.
Procedures used for this operation
The ATSB reviewed the procedures used by the different operators involved on the project on the day. The lead contractor had conducted a risk assessment of the overall project, which involved all of the contractors involved.
Operator A had completed a helicopter lift plan for the day and a safe work method statement that identified hazards and the mitigations for lifting operations. There were a number of areas in the procedures indicating that no one should be located below the suspended load. The procedures also specified that people should not be within the ‘crush zone’ but did not identify where the crush zone was. The operator advised that the crush zone was dependent on a number of job-specific variables, including the load shape and size, and the length of sling required. While there was no specific section in the safe work method statement to prompt this discussion, the loadmasters worked together to rig the loads, adding tag lines where required, and so were aware of the individual load’s size, shape and aerodynamic stability.
Safety analysis
The ATSB considered a number of inadvertent load release mechanisms, including:
the pilot release system
dynamic rollout
failure of the manual load release
electromagnetic radiation
failure of the hook mechanism.
A previous injury meant that accidental release by the pilot was unlikely and the loadmaster did not hear the audible ‘clack’ of the solenoid, associated with operation of the pilot‑activated release.
The shackle was the appropriate size, to ensure a dynamic rollout would not occur. The video footage shows that the ‘D’ shackle was securely behind the keeper as the helicopter departed from the loading area.
While flying in an area of electricity production, the helicopter was 35 km from the closest power station and around 10 km from the closest power lines. The wiring was also checked and there were no bare or loose wires in the system. If the load had released through EMF activation of the release system, the loadmasters would have heard the ‘clack’ of the solenoid releasing.
There were no indications that the remote hook release mechanism was faulty after the previous overhaul and the pilot and loadmasters conducted an operational check of the mechanism before operations began on the day. It also successfully lifted the two previous loads and lifted the load off the loadmaster after the incident. In addition, the manual release mechanism operated correctly at the ATSB facility and an examination of the hook release electrical system in the helicopter did not reveal any faults. Despite this, a transient hook fault that resulted in an inadvertent release of the load could not be ruled out.
In summary, based on the available evidence, the mechanism that led to the release of the load could not be determined.
Immediately prior to the accident, the load was being positioned without needing to be adjusted. The plan was that it would touch the ground and then be lifted to knee height before being moved to its final position. Therefore, being in the vicinity of the load when it was above head height was an unnecessary risk.
When the load released, one end fell first and there was likely a movement back toward the rising ground. The loadmasters were reportedly standing to the side and at 45˚ angles from the load, but they were still close enough for one of them to be struck when the load pivoted.
The procedures and briefings for the operation contained several references for individuals not to place themselves in a dangerous position with respect to the load. While the extent of the crush zone was not defined in general, there were a number of variables unique to each job that made this difficult. The opportunity to discuss these aspects was during the briefing, although there was no discussion on the specific loads in this instance. Despite this, the loadmasters did discuss and adjust the different loads, adding tag lines where required. This would imply they were aware of the load size, weights and aerodynamics of specific loads for this job.
ATSB comment
In response to a previous accident, CASA released Airworthiness Bulletin, AWB 25-006 Issue 2, which provided advice to operators involved in sling load operations. While not directly relevant to this occurrence, it details important information relating to external sling load operations. This included information related to the inadvertent release of the load through the use of the incorrect shackle size and electromagnetic radiation (EMI).
Findings
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
The load released from the hook unexpectedly for reasons that were not determined.
The loadmasters were not maintaining a safe distance from the load. Their positioning, in combination with the significant movement of the load as it contacted the ground, resulted in the loadmaster being struck and seriously injured.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
As a result of this accident, all the contractors jointly reviewed the processes used on this project. They determined that the existing documentation contained sufficient warning for personnel to not enter the ‘crush zone’ or ‘work under loads’, but also identified enhancements to the existing processes. This included a control that removed all people (including loadmasters) from the receiving area where there was no requirement for precision in the placing of the load and increased controls where a precision placement of the load was required.
Helicopter operator who supplied the loadmasters
Operator A advised the ATSB that they have reviewed their own safe work method statement and made changes including identifying a ‘dynamic exclusion zone’[3] under the moving helicopter. Recognising that the zone may vary due to a number of variables, the intention is that specific guidance will be provided as part of pre‑activity briefings.
Lead contractor
The lead contractor is overseeing a range of initiatives, including a behavioural safety review of the project with the intention to implement an appropriately designed program to positively influence behaviours across their projects.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the morning of 6 January 2019, a Cessna 182G, registered VH-DGF, took off from Tooradin Airfield to conduct parachuting operations. The pilot reported that soon after take-off, at about 400 ft above the ground, the engine sustained a sudden power loss. After being unable to resolve the problem, the pilot conducted a forced landing in a nearby paddock.
During the forced landing, the aircraft collided with trees and a fence, which resulted in substantial damage. There were no injuries.
What the ATSB found
The ATSB found that the carburettor contained aluminium oxide corrosion deposits which, when loosened, likely blocked fuel flow within the carburettor, resulting in the aircraft engine losing power. Periodic inspections (every 100 hours or 12 months) play a vital role in ensuring the serviceability of an aircraft’s engine, and these inspections had a requirement to drain and flush the carburettor. However, the extent to which this action was actually conducted during the six inspections since the engine and carburettor were overhauled could not be determined.
The engine had periods of inactivity over the preceding years, and maintenance on the engine had not always been conducted at the appropriate time intervals. However, it was not possible to determine exactly when the corrosion started and propagated.
After the engine lost power, the decision by the pilot to conduct a forced landing rather than turn back to the departure runway minimised the risk of loss of control during the forced landing.
The pilot was not wearing an upper torso restraint (UTR), but fortunately was not injured on this occasion. However, by not wearing his UTR, he significantly exposed himself to unnecessary injury risk.
What's been done as a result
The operator advised that it intends to direct pilots to wear upper torso restraints and that this requirement will be incorporated into its training and induction schedule.
Safety message
Corrosion was able to form within the carburettor that was not prevented or detected. This occurrence highlights the importance of following the maintenance program for the aircraft. Particularly in this case, this included draining and flushing the carburettor at its periodic inspection.
When available, upper torso restraints should be worn. While the pilot was uninjured during the accident, a substantial amount of research has shown that wearing an upper torso restraint significantly reduces the risk of injury compared to lap belts only.
The occurrence
Pre-flight preparation
On the morning of 6 January 2019, the pilot of a Cessna 182G, registered VH-DGF, prepared the aircraft for parachuting operations for Skydive south-east Melbourne at Tooradin Airfield, Victoria. The single-engine aircraft had been refuelled from the bowser at the airfield on the previous day.
The pilot reported that, on the morning of the flight, he checked the quantity of fuel on board by dipping the aircraft’s fuel tanks with a calibrated dipstick. He also conducted a normal pre-flight inspection of the aircraft, which included conducting a water drain check of each of the aircraft’s three fuel drains.
After conducting the pre-flight inspection, the pilot started the aircraft’s engine and taxied to the apron area. He allowed the engine to warm and carried out further operational checks. When complete, he repositioned the aircraft to pick up parachutists for the first sortie of the day. However, the flight was then delayed for about 90 minutes by unsuitable weather.
The passenger load consisted of a tandem master, a tandem passenger and two sport parachutists.
Take-off and engine power loss
The pilot conducted the take-off at about 1045 Eastern Daylight-saving Time,[1] toward the south-west. As the aircraft passed over the end of the runway, he raised the flaps and continued to climb.
The pilot reported that, at about 400 ft above ground level, there was a sudden loss of power and aircraft climb performance, and he observed the propeller was windmilling[2] without sound. He later described the power loss as being similar to the mixture control being pulled back. A witness at Tooradin Airfield recalled that the power loss sounded like a sudden closing of the throttle and there was no rough running.
The pilot lowered the aircraft nose and identified a suitable area to make a forced landing which required a heading change of about 45º to the west. He checked the engine controls and fuel selector were correctly configured and had not been disturbed by parachutists entering the aircraft.
The pilot recalled that he conducted a flapless approach at about 70 kt to the identified landing area. During the descent, he instructed the passengers to prepare for a forced landing.
The aircraft touched down in a relatively flat, open paddock. It initially bounced on the unprepared surface before settling on the ground and passing through two boundary fences. The pilot attempted to slow the aircraft and manoeuvre to avoid trees. As the aircraft passed through a gap in the trees, the left-wing strut collided with a tree, which resulted in the left wing folding over on top of the right wing and fuel leaking from it onto the fuselage. The aircraft further collided with a third fence, crossed a private road, and collided with a fourth fence, which collapsed the nose landing gear (Figure 1).
Figure 1: Accident site of Cessna 182, registered VH-DGF
Source: Victoria Police.
Egress from the aircraft
The pilot ordered the passengers to evacuate. Both doors were displaced open during the accident sequence and an interior panel from the rear of the cabin had propelled forward onto the parachutists. The panel obstructed emergency egress and was removed by the pilot.
The sport parachutist located at the right[3] rear position attempted to egress the aircraft but had not released his single-point restraint. After doing so, he was first to egress. The sport parachutist located at the right forward position also had not released his restraint prior to attempting egress. After doing so, he was next to egress. The tandem passenger was assisted out of the aircraft, followed by the tandem master and the pilot. Video footage showed that, after the aircraft came to rest, it took about 20 seconds for the occupants to egress.
The pilot returned to the aircraft to confirm the master switch and magnetos were off. The passengers and pilot moved away from the aircraft and waited for emergency services to arrive.
The aircraft was substantially damaged and there were no injuries.
The Cessna 182G is a high-wing, all-metal, unpressurised aircraft with a fixed landing gear. It has a single, reciprocating piston engine driving a constant speed propeller.
VH-DGF was manufactured in 1964 and was first registered in Australia in 1965. The aircraft was reconfigured for parachuting operations in 2017.
The Cessna 182G has two fuel tanks, one in each wing. Fuel from each tank is gravity-fed to the fuel selector valve. Depending on the setting of the valve, fuel from the left tank, right tank or both tanks flows through a fuel strainer (also known as a ‘gascolator’), then the carburettor and the engine.
The Cessna 182G Owner’s Manual stated that pilots should take off with the fuel selector in the BOTH position. The pilot reported that the fuel selector was in the BOTH position during the take-off. Video footage taken during part of the accident flight confirmed that the fuel selector was in the BOTH position, and the fuel tanks indicated that sufficient fuel was on board.
A review of the video footage identified that the mixture was full rich and the carburettor heat was off during take-off. However, a review of the meteorological conditions and other information at the time of the occurrence indicated that the risk of carburettor icing was low.
The aircraft was within the required weight and balance limitations.
Examination of the aircraft and components
The ATSB did not attend the accident site or conduct a detailed examination of the engine. Examination by other parties did not identify any problems with the aircraft’s fuel system or the engine itself. However, a significant amount of debris was recovered from the fuel strainer, the carburettor float bowl and directly below the carburettor nozzle and main jet assembly. The debris in the fuel strainer appeared to include a range of different foreign materials.
The carburettor and the recovered material were examined by the ATSB. Most of the recovered material had a white, chalky appearance and ranged in size up to 5 mm. Inside the carburettor bowl, a significant amount of the material had accumulated at the drain area, and a 'tide' line was visible on the sides of the drain area. The inside surface of the bowl exhibited pitting corrosion where the material had dislodged (Figure 2).
A small amount of similar white chalky material was also observed on a ‘dip’ in the carburettor bowl, slightly above the drain. Other than the areas described, the internal surfaces of the bowl appeared to be relatively clean and in good condition, although some other foreign material was observed in the bowl.
ATSB analysis of the debris found in the carburettor showed that it was primarily comprised of aluminium and oxygen. It was considered likely that the particles were aluminium oxide, a corrosion product from the aluminium carburettor bowl.
Figure 2: Material inside the carburettor bowl of VH-DGF
Source: ATSB.
Engine history
The engine fitted to VH-DGF at the time of the accident was originally fitted to another Cessna 182, registered VH-EIZ. In December 2011 the engine (serial number 67386-7-R) and carburettor (serial number H-11-5085) were removed, overhauled and refitted to VH-EIZ.
In October 2016, the engine and carburettor were removed from VH-EIZ for fitment to VH-DGF. At that time the engine had accumulated 328.1 hours since overhaul. VH-DGF was rebuilt over a 2-month period, and a maintenance release was issued in early January 2017.
No flights were documented on the maintenance release during:
the 4-month period from early January to early May 2017
the 3-month period from mid-May to mid-August 2017
the 7 weeks up until the end of January 2018.
Other than these periods of inactivity between October 2016 and August 2017, the lowest utilisation of the engine since last overhaul was 44.5 hours over an 18-month period between 2013 and 2014.[4]
The last periodic (100-hourly) inspection was carried out on 30 May 2018 at 7,730.1 airframe hours and 393.9 engine hours since overhaul. At the time of the accident, the engine had accumulated 438.4 hours since overhaul.
Between the overhauled engine commencing service in 2011 and the accident, six periodic inspections were conducted which examined the engine (four inspections when it was fitted to VH‑EIZ and two when fitted to VH-DGF).
Periodic maintenance requirements
The aircraft was being maintained in accordance with Civil Aviation Safety Authority (CASA) maintenance schedule 5 and all airworthiness directives applicable to the aircraft.[5] Maintenance schedule 5 outlined requirements for daily inspections (conducted prior to the first flight of each day) and periodic inspections (conducted every 100 hours or 12 months, whichever came first).
The periodic inspection requirements included a requirement to ‘drain and flush the carburettor fuel bowl and refit the plug and lockwire’. This requirement was reiterated in a number of advisory publications.[6]
The six periodic inspections carried out after the engine was overhauled were conducted by four different maintenance organisations. Maintenance records from these periodic inspections indicated that the task of draining and flushing the carburettor had been conducted. During interviews, personnel from three of these maintenance organisations noted that, although this task was required for every periodic inspection, they were aware that it was not always carried out.
A review of the recent maintenance releases for VH-DGF identified a number of anomalies:
The second last periodic inspection and maintenance release were certified for on the 3 and 4 January 2017. The aircraft was ferried to Queensland on 11 December 2017 to be used by another parachuting operation. The maintenance release expired on 3 January 2018, after which the aircraft was used for numerous flights (totalling 4.2 hours flight time) during the period from 27 January until 25 March 2018. As the maintenance release was expired, a special flight permit[7] was issued and the aircraft ferried from Seventeen Seventy to Caboolture on 18 April 2018 (2.1 hours flight time). A second special flight permit was issued and the aircraft was ferried to Tyabb, Victoria, on 26 May 2018 which involved approximately 6.5 hours flying. In summary, based on documented records, the aircraft was operated for 12.8 hours over a period of 4 months without a valid maintenance release (and without a periodic inspection having being conducted within the previous 12 months).
Between periodic inspections, oil and oil filter changes were required. The requirement for the engine fitted to VH-DGF was for an oil and oil filter change after 50 hours flight time or 4 months (whichever came first), and any such change had to be certified on the maintenance release. The second last maintenance release showed two oil and oil filter changes. The first was on 11 December 2017, 11 months since the last periodic inspection. The second occurred on 22 May 2018, 5 months after the previous oil and oil filter change.
The last periodic inspection occurred on 30 May 2018, with a maintenance release issued on the same day. The maintenance release included a requirement to test the pitot static system as per Civil Aviation Order 100.5 (required every 24 months) by 4 January 2019. There was no annotation on the maintenance release to indicate that the inspection was conducted prior to the accident flight (6 January 2019).
On the last maintenance release there was a requirement to carry out an oil and oil filter change on 30 September 2018, however there was no record of this being done.
It is widely acknowledged that piston engines that are not flown frequently are susceptible to damage from corrosion and contamination, which may adversely affect their expected service life.
Susceptibility to corrosion is influenced by a number of factors, including but not limited to, geographical location, season, usage and storage.
When a piston engine is exposed to adverse environmental conditions such as coastal areas and areas of high relative humidity, corrosion attack can occur within a few days. Conversely, engines under more favourable environmental conditions can remain inactive for several weeks without evidence of damage by corrosion.
Experience has shown that the best course of action to reduce the likelihood of corrosion attack on engine internal surfaces is to fly the aircraft regularly. In circumstances where this action is not possible engine preservation procedures have been promulgated within engine manufacturer’s instructions for continuing airworthiness to combat and minimise the corrosion condition a direct result of engine inactivity…
In general, manufacturers recommend that for engines which won’t be flown for 30 days or more, a preservation regime should be instigated.
The need for engine preservation should be evaluated by the aircraft operator having regard to the prevailing environmental conditions and period of aircraft inactivity.
The aircraft manufacturer (Cessna) specified various maintenance actions if an engine was not being utilised for various periods of time. For periods up to 30 days (flyable storage) and 90 days (temporary storage), there was no required actions for preserving the carburettor, whereas there were such requirements for indefinite storage periods.
The engine manufacturer (Continental Motors) advised[8] operators to inject corrosion preventative oil into the carburettor while the engine is running for:
an engine, which has been in operation, is to be stored much longer than a week under normal climatic conditions…
There was no indication in the aircraft’s maintenance records regarding whether any storage or preservation measures were applied to the aircraft’s engine during the periods of inactivity from October 2017 until January 2018.
Related occurrence
On the 14 February 2017, a Yakovlev 52 experienced a loss of engine power en route to its destination. While conducting a forced landing, the aircraft collided with a tree, pitched down and collided with the ground. The pilot was seriously injured and the aircraft was substantially damaged.
The Belgian Federal Public Service Air Accident Investigation Unit investigated the accident[9] and found:
The engine loss of power was most probably caused by the internal corrosion of the carburettor which partially blocked the fuel flow at the pressure regulator valve. The corrosion of the magnesium alloy casing of the carburettor was likely caused by water contamination.
Occupant restraint
Pilot seat
Civil Aviation Safety Regulations 1998 (CASR) 90.105 required that the seats in the front row of an aircraft must be fitted with an approved safety harness. For small aeroplanes (with maximum take-off weight less than 5,700 kg) and helicopters, the safety harness needed to consist of a lap belt and at least one shoulder strap.
The pilot’s seat of VH-DGF was fitted with a lap belt and upper torso restraint (UTR),[10] consistent with the regulatory requirements. Given the age of the aircraft, the UTR did not have an inertia reel (that is, when fitted correctly it was fixed in position and the person’s movement was somewhat restricted). On the accident flight, the pilot wore the lap belt but the UTR was stowed in the seat pocket. The pilot noted that he was 165 cm tall and, when the UTR was worn and correctly adjusted, he could not reach the fuel selector or cowl flaps.
Previous ATSB investigations have found that pilots or passengers in the front seats of small aeroplanes and helicopters have not always worn the available UTRs, exacerbating the severity of their injuries in many accidents (for example, ATSB investigations 199800442, 200605133, AO-2010-053, AO-2012-083, AO-2012-142 and AO-2016-074).
A substantial amount of research has consistently shown that seat belts in small aircraft that include a UTR significantly reduce the risk of injury compared to lap belts only. UTRs minimise the flailing of the upper body and reduce the risk of impacts involving the head and upper body.
For example, a safety study by the United States’ National Transportation Safety Board (NTSB) in 1985[11] examined 535 accidents involving small aircraft in 1982.[12] The NTSB estimated that 20 per cent of the 800 fatally injured occupants would have had only serious injuries or minor injuries if they had been wearing a UTR. In addition, 88 per cent of 229 seriously injured occupants would probably have had less severe head or upper body injuries, only minor injuries or no injuries if they had been wearing a UTR.
A 2011 safety study by the NTSB[13] examined the rate of serious and fatal injuries of pilots in single-engine aeroplanes during the period 1983–2008. It found that pilots wearing only a lap belt had a 49 per cent greater likelihood of a serious or fatal injury compared with pilots wearing a lap belt and a UTR. Another study which examined take-off and landing accidents involving an engine power loss during 1983–1992 found that pilots wearing only a lap belt were 70 per cent more likely to be fatally injured than pilots wearing a seat belt and a UTR.[14]
Parachutists
Civil Aviation Regulation (CAR) 251 (Seat belts and safety harnesses) required seat belts to be worn during take-off and landing, during instrument approaches, when the aircraft was flying less than 1,000 ft above terrain and at all times when in turbulent conditions. CAR 251 had provision to change the type of restraint. In the case of aircraft used for parachuting operations, this was usually a single-point restraint.
Civil Aviation Order (CAO) 20.16.3 (Air service operations – carriage of persons) stated:
Where a parachutist is not provided with a seat of an approved type, he or she shall be provided with a position where he or she can be safely seated.
Except when about to jump, parachutists were required to wear a seat belt, safety harness or parachute that was connected to an approved single-point restraint.
Additionally, the Australian Parachute Federation (APF) Operational Regulations, section 5.2.4, required an aircraft used for parachuting to be fitted with sufficient parachutist restraints that are manufactured to a standard approved by CASA and the APF, labelled accordingly, or have sufficient aircraft seats and seatbelts.
The ATSB and other investigation agencies have previously expressed concern about the suitability of single-point restraints for parachuting operations, with research showing that dual-point restraints offer occupants better protection in the event of an accident. In addition, in some previous take-off accidents, parachutists were not wearing the single-point restraints.[15]
The requirements of CAR 251, CAO 20.16.3 and APF regulation 5.2.4 were met by the operator of VH-DGF by using an approved single-point restraint for each parachutist. The parachutists on board the accident flight were wearing the approved single-point restraints during the accident flight.
The available evidence indicates that there was sufficient fuel on board the aircraft for the flight, the risk of carburettor icing was low and there appeared to be no mechanical defects with the engine.
The Cessna 182 fuel system was designed to provide gravity-fed fuel, free from contamination, to the carburettor. There are multiple components that remove contamination, such as filters and drain points. After the fuel has entered the carburettor bowl, there are no further defences in place prior the fuel being atomised for combustion.
The carburettor fitted to VH-DGF contained aluminium oxide corrosion deposits. These were of sufficient size such that, when loosened, they probably blocked fuel flow within the carburettor, resulting in the aircraft engine suddenly losing power shortly after take-off.
As the carburettor bowl is on the ‘downstream’ side of the defences to prevent contamination, there are maintenance and storage processes to ensure its serviceability. The corrosion was probably able to form in the carburettor bowl during periods of inactivity. However, it was not possible to determine exactly when the corrosion started and propagated.
Periodic inspections (every 100 hours or 12 months) play a vital role in ensuring the serviceability of an aircraft’s engine, and these inspections had a requirement to drain and flush the carburettor. However, the extent to which this action was actually conducted during the six inspections since the engine and carburettor were overhauled could not be determined.
Maintenance overrun
It was also noted that a periodic inspection was not conducted at the required interval. A periodic inspection was required by 3 January 2018, but was not conducted until 30 May 2018. During the period from 27 January 2018 to 25 March 2018, the aircraft was flown without a valid maintenance release, and a further two flights conducted under special flight permits. However, given the last periodic inspection was done 7 months prior to the accident, the extent to which this previous omission contributed to problems with the carburettor was unclear.
There was also no indication on the last maintenance release that oil and oil filter changes were being conducted every 4 months. However, these omissions (if they occurred) should not have had an impact on the condition of the carburettor.
Use of occupant restraints
In general, the forces transmitted to occupants in light aircraft involved in an accident are higher than those transmitted in large transport aircraft involved in an accident. This is primarily due to the lack of protection from a crushable fuselage structure and therefore reduced energy absorption in a small aircraft.
A substantial body of research has shown that the risk of serious and fatal injuries can be significantly reduced if the occupants of small aircraft wear upper torso restraints (UTRs). In this case, the pilot was wearing a lap belt but not wearing the UTR.
It was fortunate that the pilot was not injured on this occasion. However, by not wearing his UTR, he significantly exposed himself to unnecessary injury risk. Noting that a UTR without an inertial reel can be restrictive, this should not prohibit the use of UTRs during critical phases of flight, such as take-off and landing.
Preparation for an emergency landing
During the accident flight, the parachutists were wearing the single-point restraints and given the relatively low impact forces, the restraints were sufficient to minimise injury risk during the forced landing.
However, after being ordered to evacuate by the pilot, the parachutists adjacent to the right door attempted to exit the aircraft without releasing their single-point restraints, delaying the egress of all on board. Fuel leaking from the damaged left wing of the aircraft increased the likelihood of a post-accident fire, and therefore the importance of rapid evacuation.
In this case, the parachutists knew how to undo their restraints, and would have been aware of the required actions for exiting the aircraft in the case of an emergency during take-off. However, this investigation highlights the additional benefits of mentally rehearsing the required actions immediately prior to or during take-off. According to the Civil Aviation Safety Authority’s Cabin safety bulletin 12 – General aviation passenger briefings (October 2018):
Survivors of aircraft accidents have provided anecdotal evidence as to the importance of their recollection of information… Adequately briefed passengers, who understand how to help themselves, will assist in the quick and successful evacuation of an aircraft.
Pilot response to the engine power loss
Airborne emergencies can be dynamic, fast-paced, and place a high cognitive workload on the pilot. When confronted with an airborne emergency, a pilot’s hierarchical priorities are to ensure the aircraft remains in controlled flight, navigate (in this case to a suitable landing area) and, if time permits, communicate the nature of the emergency to authorities enabling them to respond appropriately.[16]
Standard flight training and guidance for pilots is to land straight ahead, or within 30º either side of straight ahead, following an engine failure or power loss at a low height. Pilots are also taught to only consider a turnback manoeuvre once they have achieved a minimum height, which may vary depending on the aircraft type and other factors.
A substantial amount of guidance material has been published about managing engine failures after take-off, and such guidance material continually emphasises the importance of not considering a turnback until a pre-determined safe altitude has been reached. For example, a recent article in CASA’s Flight Safety Australia publication[17] (Stobie 2019) provided the following guidance:
Something that should have stuck from basic training was that you should never turn back following engine failure immediately after take-off. There’s good reason for this lesson—countless fatal accidents have involved pilots unsuccessfully attempting to turn back to the airport following an engine failure on upwind at low level. It’s often labelled the impossible turn, and it’s a procedure fraught with risk.
In this case, when the power loss occurred at about 400 ft, the pilot correctly assessed there was insufficient height to conduct a turnback to the departure runway. He selected a suitable landing area off the airfield 45º to the right of his current heading which, given the height of the aircraft, was able to be reached safely. The pilot automatically lowered the nose of the aircraft to maintain controlled flight and attain best glide speed, and he then focussed on navigating the aircraft to the suitable landing area.
With the limited time and height available, the pilot displayed sound airmanship and decision-making by conducting a forced landing and accepting the risk of a minor accident, rather than turning back and risking a loss of control and an accident involving much more serious consequences.
From the evidence available, the following findings are made with respect to the loss of power on take-off and forced landing involving a Cessna 182, registered VH-DGF at Tooradin Airfield, Victoria on 6 January 2019. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Contributing factors
The carburettor contained aluminium oxide corrosion deposits which, when loosened, likely blocked fuel flow within the carburettor, resulting in the engine losing power shortly after take-off.
The engine had periods of inactivity over the preceding years, and corrosion was able to form within the carburettor that was not prevented or detected by maintenance providers during periodic inspections (every 12 months or 100 hours flight time).
Other factors that increased risk
During the period from 27 January 2018 to 25 March 2018, the aircraft was flown without a valid maintenance release, and a further two flights conducted under special flight permits, without a periodic inspection having been conducted in the previous 12 months.
The pilot was not wearing an upper torso restraint during the accident flight, thereby increasing the likelihood of serious injury during the forced landing.
The parachutists adjacent to the door attempted to exit the aircraft without releasing their single-point restraints, delaying the egress of all on board.
Other findings
After the engine lost power, the decision by the pilot to conduct a forced landing rather than turn back to the departure runway minimised the risk of loss of control during the forced landing.
Safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Aircraft operator
The operator advised that it intends to direct pilots to wear upper torso restraints and that this requirement will be incorporated into its training and induction schedule.
Australian Parachute Federation
As a result of a separate occurrence prior to the accident involving VH-DGF, the Australian Parachute Federation has advised the ATSB that in February 2019 it distributed ‘Continuing Improvement Package 4 – Aircraft Emergency and Evacuation Procedures’ to 60 parachuting clubs to incorporate into their operations and to prompt discussion on the subject.
The aims of the package were to:
reduce the risk and resultant injuries in the event of an aircraft emergency
discuss procedures in the event of aircraft emergency and/or evacuation
discuss multiple aircraft emergency and evacuation scenarios
implement aircraft evacuation training/drills.
Additionally, the Australian Parachute Federation advised in January 2020 that it was in the process of conceptualising a dual point, single release restraint.
Sources and submissions
Sources of information
The sources of information during the investigation included:
the pilot of VH-DGF
the parachuting school that was operating the aircraft (Skydive South East Melbourne)
various maintenance providers
Civil Aviation Safety Authority
the carburettor manufacturer (Marvel).
Submissions
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the pilot, the aircraft operator / parachuting school (Skydive South East Melbourne), the maintenance organisation that conducted the last periodic inspection on the aircraft, the carburettor manufacturer (Marvel, via the United States National Transportation Safety Board (NTSB)), the engine manufacturer (Continental, via the NTSB), the aircraft manufacturer (Cessna, via the NTSB), Civil Aviation Safety Authority and the Australian Parachute Federation (APF).
Submissions were received from the pilot, aircraft operator / parachuting school and APF. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 26 December 2018, a Kavanagh B-350 hot air balloon, registration VH-ZYO, operated as a scenic charter flight by Go Wild Ballooning, departed from Wandin, Victoria with the pilot and 15 passengers on board.
After 20 minutes in flight, and while operating at an altitude of about 800 ft, the pilot recalled hearing a small explosion from the front left burner and observed that a small fire had started on the outside of the burner. The pilot switched off the vapour valve at the fuel tanks to the front two burners and disconnected the hoses.
About a minute later, the pilot attempted to put out the fire using one of two on-board extinguishers, but the fire re-ignited almost immediately. After a further minute, the pilot discharged the second fire extinguisher, but again the fire re-ignited.
Moments later, the pilot’s compartment caught fire. The pilot was wearing a cotton shirt, synthetic vest, rolled-up pants, and rubber slip-on shoes and began to feel uncomfortable with his proximity to the fire. He then moved from the pilot’s compartment to the back left compartment of the basket.
About 8 minutes after the fire started, the pilot identified a suitable landing position and began the approach. During the descent, the basket struck some treetops and the ropes became tangled in the branches. Passengers reported that the branches whipped around and into the basket, with one passenger sustaining cuts to his hand. The pilot freed the ropes from the tree and brought the balloon to rest in the paddock below. As the basket touched the ground, the passengers jumped out and ran to safety.
The fire continued to burn as the pilot secured the balloon. When emergency services arrived on site, flames had engulfed the balloon. By the time firefighters extinguished the flames, the fire had destroyed the balloon.
What the ATSB found
The ATSB found that the in-flight fire was the result of a fuel leak at the front left burner. Due to severe fire damage, the source of the leak could not be determined conclusively, but it was considered most likely to be the main ball valve, liquid fire valve or liquid fire valve connection to the main valve block.
The hand-wheel valve on the liquid outlet of the fuel tank and the pilot burners were not shut-off, which resulted in the pilot being unable to control the fire. Installation of a 90-degree valve on the liquid fuel outlet may have assisted the pilot to recognise that the liquid fuel valve was not shut-off.
In addition, the pilot's clothing did not meet the recommended industry standards for personal protective equipment, which increased the risk to his personal safety.
What's been done as a result
As a result of this occurrence, the Civil Aviation Safety Authority released an Airworthiness Bulletin (AWB 02-063) to address some of the pertinent issues surrounding this occurrence. The AWB included:
a recommendation to inspect critical componentry
the use of 90-degree shut-off valves for the fuel tank liquid outlets
a reminder to close off liquid and vapour valves in the event of a fire
a reminder to wear appropriate personal protective equipment.
In addition, Go Wild Ballooning has advised the ATSB that they have replaced all hand-wheel valves with 90-degree valves on all fuel tanks and reviewed the company policy on protective clothing.
Safety message
In the event of an in-flight balloon fire, the first priority is isolation of the fuel supply at the fuel tank. It is good practice to rehearse emergency procedures by standing in the basket to run through the checklist steps.
Further ways to reduce risk to individuals and improve survivability outcomes include:
wearing appropriate protective clothing that includes cotton long‑sleeved shirts and long trousers, leather gloves, and enclosed footwear
utilising componentry that provides a visual indication of the system status, for example, 90‑degree valves on liquid outlets.
On-board view of in-flight fire involving VH-ZYO
Source: Passenger photo
The occurrence
What happened
On 26 December 2018, at about 0500 Eastern Daylight-saving Time,[1] a Kavanagh B-350 hot-air balloon, registration VH-ZYO, operated as a scenic charter flight by Go Wild Ballooning, was being prepared for departure from Wandin, Victoria.
Prior to take-off, the pilot, together with another ground crew member, conducted the pre-flight check on the balloon, while a ground crew member conducted a safety briefing with the passengers. Neither person inspecting the balloon observed any defects during the pre-flight check.
At 0537, the balloon lifted off with the pilot and 15 passengers on board. After about 15 minutes in flight, the balloon reached an altitude of 4000 ft. The pilot maintained level flight for a few minutes and then began to descend. At about 800 ft, the pilot recalled hearing a small ‘explosion’ from the front left burner (Figure 1) and observed that a small fire had started on the outside of the burner. The passengers observed that the fire was concentrated around the base of the burner, shooting outwards to the front of the basket.
The pilot switched off the vapour valve (see the section titled Aircraft information) at the fuel tanks to the front two burners and disconnected the hoses. Shortly after, the vapour hose connected to the front left burner burnt through and fell away from the burner.
About a minute later, the pilot attempted to put out the fire using one of two on-board extinguishers, but the fire re-ignited almost immediately. After a further minute, the pilot discharged the second fire extinguisher, but again the fire re-ignited. The first flames appeared in the vicinity of the burner can base, towards the front side of the basket, with the flames directed outwards.
Moments later, the pilot’s compartment caught on fire. The pilot was wearing a cotton shirt, synthetic vest, rolled-up pants and rubber slip-on shoes and began to feel uncomfortable with the proximity of the fire. As a result, the pilot moved from the pilot’s compartment to the back left compartment of the basket. The pilot made a call over the radio, repeating MAYDAY[2] three times followed by the balloon registration. Air traffic control acknowledged the call and initiated the appropriate emergency procedures in response.
About 8 minutes after the fire started, the pilot identified a suitable landing position and began the approach. During the descent, the basket struck treetops in the landing area undershoot and the ropes became tangled in the branches. Passengers reported that the branches whipped around and into the basket, with one passenger sustaining cuts to his hand. The pilot freed the ropes from the tree and brought the balloon to rest in the paddock below. As the basket touched the ground, the passengers on the right hand side of the basket jumped out causing the right side of the basket to lift off the ground again. In response, the pilot quickly pulled the red line[3] to evacuate the hot air from the envelope and brought the basket back down to the ground. The remaining passengers then jumped out and ran to safety.
The fire continued to burn as the pilot secured the balloon. When emergency services arrived on site, flames had engulfed the balloon. By the time firefighters extinguished the flames, the fire had destroyed the balloon.
Pilot's comments
The pilot later commented that:
he was carrying a long woollen coat in the basket as additional protective clothing, however, it was not accessible
he had not been wearing protective gloves, as they had been burnt earlier in the flight, when he had put them aside to adjust the radio
during the incident, he followed the priority of, ‘aviate, navigate, communicate’.
Aircraft information
VH-ZYO was a Kavanagh B-350 balloon. The balloon consisted of an envelope, a 16-person basket, a quad burner system and four propane fuel tanks.
Kavanagh Balloons series 3 burner and fuel system
A Kavanagh series 3, quad burner system was installed on the aircraft. The burner unit consisted of four high-pressure propane burners. Each of the burner units had two connections to the fuel tank: a vapour hose (connected to the pilot burner) and a liquid hose, which connected into the burner coil (Figure 1). A standard feature of the system included a secondary burner, known as ‘liquid fire’. This system bypassed the heat exchanger coil and fed liquid propane directly into the burner. The vapour hose drew gaseous propane from the top of the fuel tank and the liquid hose drew liquid propane from the bottom of the fuel tank. The fuel tanks on VH-ZYO had hand-wheel shut-off valves installed at the connections for both the liquid and vapour hoses. The alternative certified configuration was a 90-degree valve. Both valve configurations are shown in Figure 3.
Figure 1: Basket and burner arrangement similar to VH-ZYO
Source: Kavanagh Balloons, annotated by ATSB
An illustrated diagram of a burner unit is shown in Figure 2 below.
Figure 2: Illustrated diagram of the burner system on VH-ZYO
Source: Kavanagh Balloons, annotated by ATSB
Figure 3: Valve types on propane tank
Source: Kavanagh Balloons, annotated by the ATSB
The European Aviation Safety Authority (EASA) has previously published a safety information bulletin (SIB 2018-14) highlighting the advantages of using 90-degree valves over the hand‑wheel valves. EASA recommends operators of hot air balloons use the 90‑degree valves for propane fuel cylinders as they had been found to improve the survivability outcome in the event of fire due to their easy and quick actuation.
Liquid and vapour hoses
The Kavanagh Balloon’s maintenance manual mandates that the liquid fuel hoses have a 10-year life from the date of manufacture. The liquid hoses on VH-ZYO were last replaced in October 2018. Leak checks were conducted as part of the standard replacement procedure and the aircraft had been used multiple times since the replacement.
The liquid hoses were constructed from three layers of material: an inner rubber tubing, an encasing metal braid, and a rubber outer casing. Vapour hoses have a similar construction but do not have a time-limited life.
Main valve block
The main valve block (Figure 2) was an assembly of two solid pieces of aluminium, fastened either side of the main ball valve with four bolt and nut combinations. The liquid fire valve, liquid fuel hose, pressure gauge and cross flow plug each screw into a threaded hole in the main valve block.
Pressure gauge
The manufacturer rated the pressure gauge to a maximum operating pressure of 230 psi,[4] with design testing conducted to around 345 psi. The normal operating range for the series 3 burner (the same burner installed on VH-ZYO) is 50 – 218 psi. The pilot indicated that the system was generally operated at around 180 psi.
Liquid fire valve and main ball valve
The liquid fire valve was a small ball valve, housed in a steel casing, with no replaceable parts. The maintenance manual specified that the valve was to be replaced as a full unit (based on the valve’s condition). Conditions indicating replacement was necessary included seizing of the valve, the valve not shutting off, or signs of leaking.
The main ball valve was a 90-degree, quick shut-off valve, designed to stop the flow of fuel into the burner can.
Kavanagh Balloons flight manual
Mandatory equipment
The flight manual specified that at least one dry powder (1 kg capacity) fire extinguisher must be carried during each flight.
In-flight fire
The manufacturer’s required actions for managing an in-flight fire were:
turn off fuel at main tank valves and turn off pilot burners
put out fire with the fire extinguisher
if it is safe, re-light pilot burner, proceed as normal and make a landing as soon as possible
if it is unsafe to re-light the burner, prepare to make an emergency hard landing.
Clothing recommendations
The regulatory bodies in Europe and America have developed guidelines for balloon operators, including the following recommended protective clothing:
long sleeves and trousers, preferably made of natural fibres
protective footwear
leather gloves.
Component examination
The ATSB conducted an examination of a number of balloon components. The examination was severely hindered by the extensive fire damage but the following observations were possible:
the burner from which the fire was emanating still had the liquid fire valve, the mini ball valve (vapour pilot burner) and the burner coil attached (Figure 4)
the main ball valve was not attached to the coil (Figure 4)
in-flight photographs showed that the main ball valve was shut during the fire
all of the main valve block assembly bolts (with nuts attached) and cross-flow plugs were found intact in the wreckage
examination of the components did not identify any possible sources of a leak or failure that may have contributed to the in-flight fire
determination of the integrity of the main ball valve and liquid fire valve could not be established as the internal structures were completely disrupted by the fire.
Figure 4: Underside of burner and main ball valve – fire location
Source: ATSB
Previous occurrences
A review of the ATSB occurrence database for similar occurrences identified that in the last 10 years there had been 10 instances of a hot air balloon catching fire. Of these, two incidents were the result of a fuel leak. In the first instance, the leak occurred at the main ball valve and in the other at the liquid fire valve. The pilots of the balloons controlled the fires by shutting off the fuel at the tank and then extinguishing the flames.
Safety analysis
The pilot first observed the fire coming from the front left burner. Physical examination of the components did not identify any possible sources of a leak or failure that may have contributed to the in-flight fire. However, the location of the fire (front left burner) eliminated any of the connections at the fuel tanks as a source of the leak. With the main valve switched off and the liquid fuel remaining on at the tank, only the pressurised components in between could have been the source of the initial leak. The most likely were considered to be the:
threaded connection between the liquid fire valve and main valve block
liquid fire valve
main ball valve.
The direction of the flame (towards the front of the balloon) was in line with the connection of the liquid fire valve into the main valve block. On installation, over-torquing or cross-threading the connection could result in damage to the aluminium valve block. Stresses from pressurisation and thermal cycling over time can cause the damage to develop into a crack, resulting in a fuel leak. However, as this joint did not require frequent adjustment, the likelihood of damage due to installation error or handling was reduced.
The flames emanated from a location near the main ball valve and the liquid fire valve. The valves (moving components) were prone to wear and therefore at higher risk of leaking than static components. The valves were oriented vertically with a handle on the base. It can be expected that any leaking fluid would spray downwards, into the handle, making it unlikely to see the directional flame pointing outwards from the basket. However, given the fire continued for an extended length of time, it is likely that the initial fire heated the surrounding structure causing failure of seals and joint sealant in other components, leading to further leaks and a larger fire. In that context, images and accounts of the flames directed outwards from the basket may be the result of subsequent failures.
As the pilot did not shut the liquid fire valve on the fuel tanks or the pilot burners, the situation escalated rapidly and increased the pilot’s workload in managing the situation. The leaking fuel near to the pilot flames on the adjacent burners caused the fire to re‑ignite immediately after the removal of the fire extinguishers. Use of a 90-degree valve on the liquid fuel outlet may have better assisted the pilot to recognise that he had not shut off the liquid fuel valve, enabling him to control the fire.
The pilot’s clothing did not provide adequate protection from burns, increasing the risk of personal injury. The pilot was carrying additional protective clothing, however, it was not kept in a readily accessible location, and therefore could not be used.
Finally, the MAYDAY broadcast did not provide air traffic control with a current or last known location of the aircraft. In this instance, the lack of information did not result in a delayed response from emergency services. It is important, however, for pilots to follow standard broadcast procedures when declaring an emergency.
Findings
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
A fuel leak at the front left burner resulted in an in-flight fire. Due to severe fire damage, the source of the leak could not be determined conclusively, but it was considered most likely to be the main ball valve, liquid fire valve or liquid fire valve connection to the main valve block.
The hand-wheel valve on the liquid outlet of the fuel tank and the pilot burners were not shut off, which resulted in the pilot being unable to control the fire.
The pilot's clothing did not meet the recommended industry standards for personal protective equipment, which increased the risk to his personal safety.
Installation of a 90-degree valve on the liquid fuel outlet increases survivability in the event of fire and, may have assisted the pilot to recognise that the liquid fuel valve was not shut off.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Civil Aviation Safety Authority
As a result of this occurrence, the Civil Aviation Safety Authority released an Airworthiness Bulletin (AWB 02-063) to address some of the pertinent issues surrounding this occurrence. The AWB included the following recommendations:
Inspect the condition and operation of the fuel pressure gauge, stem seal and liquid fire valve.
Review the fuel system pressurisation limitations. Pressurisation of the fuel gauge beyond the maximum reading may cause catastrophic failure of the pressure gauge.
Use 90-degree (quick shut-off) valves for the fuel tank liquid outlets.
Review and rehearse all emergency procedures including in-flight fire and burner malfunctions.
Both the liquid and vapour valves must be closed on any tanks connected to the burner with a leak or malfunction before any effective firefighting methods can be performed.
Minimum industry standard protective clothing should be worn, which includes fire-resistant gloves, long-sleeved cotton shirt and sturdy, enclosed footwear
Carry fire blankets of a size of at least 1.5 m x 2 m.
In addition, CASA conducted a surveillance audit on Go Wild Ballooning. The audit returned a number of findings that the company will be required to rectify.
Go Wild Ballooning
As a result of this occurrence, Go Wild Ballooning has advised the ATSB it has taken the following actions:
upgraded one basket to the new Kavanagh Quad Burner system and is considering phasing out the older Kavanagh series 3 systems
replaced hand-wheel valves with 90-degree valves on all fuel tanks
reviewed the company policy on protective clothing, and are researching new fire-proof gloves.
Safety message
Pilots experience a high workload during in-flight emergencies. However, in the event of an in‑flight balloon fire, the first priority must be isolation of the fuel supply at the fuel tank.
The complex nature of emergencies highlights the importance of rehearsing response procedures. It is also good practice to do this standing in the basket. Further ways to reduce risk to individuals and improve survivability outcomes include:
wearing appropriate protective clothing, which includes cotton long-sleeved shirts and long trousers, leather gloves and enclosed footwear.
utilising componentry which provides a visual indication of the system status and is easy to use, for example, 90‑degree valves on liquid outlets.
Civil Aviation Order 201.11, Appendix IV and Civil Aviation Regulation 5.143 provide requirements for pilots to maintain currency of skills. It is important to remember, however, that it is up to individuals to ensure that they maintain a good working knowledge of how to deal with the full range of abnormal indications. Civil Aviation Advisory Publication 5.81-1(1) provides a clear interpretation of the requirements.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 13 December 2018, a GIE Avions De Transport Regional ATR72-212A registered VH-FVN was operated by Virgin Australia Airlines on a scheduled passenger flight from Sydney to Canberra. The aircraft encountered icing, turbulence and rain associated with thunderstorm activity in the area, so the crew diverted and held as required in order to avoid the adverse weather. Shortly after commencing descent into Canberra, passing 11,000 ft, the No.2 engine flamed out. The engine’s automatic ignition system engaged and the engine recovered within five seconds without pilot input. Approximately one minute later, passing 10,000 ft, the No.1 engine flamed out and automatically recovered within five seconds, again without pilot input.
Because of the quick nature of the automatic recovery, the crew did not action any checklists. The crew selected manual ignition as a preventative measure and continued to Canberra without further incident.
What the ATSB found
The ATSB found no evidence to suggest a mechanical fault or failure caused the engines to flameout and that the flameouts were likely to have been caused by the environmental conditions during the flight, most likely either icing or moderate/heavy rain, or a combination of both.
Aircraft systems and procedures for protection and recovery from flameouts in these conditions were reliable and effective in relighting the engines. However, the decision to select manual ignition following the flameouts potentially reduced the recovery and protection of the engines in the event of any potential further flameout.
What's been done as a result
The operator has conducted an internal investigation, released internal communications for awareness of the occurrence and ensured its pilots are aware of the appropriate use of manual ignition.
The manufacturer is ensuring all operators of the ATR72-212A are aware of the appropriate use of manual ignition. They are also reviewing operational documentation as to whether this requirement could be explicitly included.
Safety message
An engine flameout event is not common in today’s modern turbo propeller engines, but it is still possible. Reliable and effective systems and procedures exist to protect and recover from such events and it is important that pilots follow manufacturer procedures for these systems. In the case of the ATR72-212A, the automatic ignition system worked as designed, correctly identifying the loss of engine power, initiating ignition and successfully relighting the engines without pilot input. The selection of manual ignition potentially reduces the recovery mechanism effectiveness against flameouts, and should only be used when directed by checklist or a minimum equipment list.
The occurrence
On 13 December 2018, a GIE Avions De Transport Regional (ATR) ATR72-212A 600 series (ATR72), registered VH-FVN, was operated by Virgin Australia Airlines (Virgin) on scheduled passenger flight VA660 from Sydney, New South Wales (NSW) to Canberra, Australian Capital Territory (ACT). Two pilots, two cabin crew and 42 passengers were on board. The captain was the pilot monitoring (PM) and the first officer (FO) was pilot flying (PF).
During planning for the flight, the crew were aware of significant weather en route, with a line of thunderstorms approaching Canberra. A second line of thunderstorms was approaching and the crew assessed that the aircraft would arrive in Canberra at about the same time as the second line of storms. Sufficient fuel was loaded to enable the duration of the flight to Canberra, to hold for one hour, return to Sydney and hold for another hour.
Following departure at about 1741, the crew were able to observe the weather ahead and formulated plans to avoid the storms. About 10 minutes after departure, the crew requested a diversion 5 NM left of track to avoid weather. About 15 minutes after departure, air traffic control (ATC) cleared the aircraft to climb to flight level 160 (FL160[1]) and to increase their diversion left of track up to 10 NM.
Shortly thereafter, the clearance to divert left of track was cancelled by ATC and the crew were requested to provide a heading which would keep them clear of weather. ATC then directed the aircraft to maintain FL130 due to passing traffic, later clearing a further climb to FL140.
After being cleared for the standard arrival route (STAR) BUNGO 3A into Canberra, the crew accepted direct tracking to waypoint HIPPO. En route to HIPPO, the aircraft entered visible moisture with a total air temperature (TAT) below 7 °C, which were icing conditions as defined by the aircraft manufacturer (ATR). The crew acknowledged this and turned on anti-icing systems in accordance with the aircraft procedure for entering such conditions.
The crew requested an update on the weather at Canberra. ATC advised there was significant showers in the area with greatly reduced visibility. The crew commenced descent in accordance with their arrival clearance and ATC directed them to stop descent at FL120. ATC asked the crew if they would like to attempt an approach but the crew elected to hold at HIPPO at FL120 until the weather passed. Shortly thereafter, icing was visible on the aircraft and the crew selected de-icing systems ON as required by ATR FCOM procedures.
After holding at HIPPO for about 7 minutes, the crew requested to track south then west to fly around the weather and then back to Canberra. ATC cleared the aircraft to do so with headings at crew discretion.
The aircraft tracked south until about 1830 when it turned back north to assess the weather at Canberra (utilising radar). The crew decide to track to waypoint POLLI for the POLLI 7 STAR and advised ATC accordingly. ATC advised the crew that a STAR clearance was available, but the crew advised ATC to standby as they were busy avoiding weather. Shortly after, ATC advised that an approach was now viable (a previous aircraft had landed) but the crew continued to POLLI and assessed the weather for themselves.
The crew elected to hold at POLLI and held there until about 1849 when ATC vectored them to the north to commence the STAR. At 1853, the aircraft was cleared by ATC to resume its own navigation direct to waypoint HUNNI, descend to 9,000 ft to commence the STAR.
At about 1854, shortly after descent had commenced, the aircraft passed FL110 with both power levers close to flight idle when No.2 engine lost power and flamed out. The master warning and ENG 2 OUT annunciators displayed, and No.2 engine torque reduced to zero. In the time it took the crew to acknowledge the warning and confirm what it was, No.2 engine self-recovered, torque returned to normal and the warnings ceased. The crew discussed that they likely encountered icing, confirmed engine power had returned to normal and confirmed that anti-icing and de-icing systems were on. Due to the automatic recovery, the crew were not required to action any checklist or procedures associated with an engine flameout in flight.
At about 1855, both power levers were at flight idle when No.1 engine lost power and flamed out. The master warning and ENG 1 OUT annunciators displayed, and No.1 engine torque reduced to zero. In the same way that No.2 engine had recovered, No.1 engine self-recovered by the time the crew had acknowledged and confirmed the flameout. Again, no checklist or associated procedures were required to be actioned.
The captain immediately identified the de-ice mode selector switch in order to ensure the de-ice cycle was in ‘fast’; however, the captain inadvertently selected the slow cycle. The captain then selected ignition to ‘manual’, in order to provide continuous ignition in an attempt to prevent any further flameouts.
Satisfied that power in both engines had been restored to normal, the crew discussed the situation, but were unable to determine the cause of the flameouts. They confirmed manual ignition ON, icing protection ON and observed that the temperature was 12 degrees, prompting further discussion on the use of icing protection. The crew decided that they would not turn any of the icing protection systems off at that stage and would fly at icing speeds[2] if they needed to keep the icing protection on for landing.
The crew stated that the aircraft was in heavy rain at the time of the flameouts but they did not notice any significant icing at the time. Figure 1 depicts the rainfall recorded by radar at about the time of the first flameout.
The crew continued the approach, and at about 1901, the crew confirmed the aircraft was no longer in icing conditions and selected the de-icing OFF but left the anti-icing systems ON.
No further flameouts occurred and the aircraft landed at 1906.
Figure 1: Radar image at time of flameouts
The radar image at 1854, about the time of the first flameout. Areas of yellow depict moderate rainfall with red depicting heavy rainfall.
The captain commenced flying the ATR72 with Virgin in 2013 as a first officer, becoming a captain in April 2018. At the time of the incident, the captain had accumulated 204 hours command on the ATR72. The captain had a total flying time of 6,660 hours with 2,225 hours on ATR72.
Previous flying experience included charter and regular public transport (RPT) operations on aircraft including the Embraer 120 and Cessna 441 (Conquest). The captain had also undertaken flying instructor roles prior to that.
The captain’s most recent line and simulator check records did not highlight any major or ongoing proficiency concerns. Engine malfunctions and adverse weather operations were included in those assessments.
First officer
The first officer (FO) commenced flying the ATR72 with Virgin in 2012 as a first officer. At the time of the incident, the FO had a total flying time of 6,700 hours, with over 3,000 hours on the ATR72.
Previous flying experience included charter and RPT and flying instruction.
The FO’s most recent line and simulator checks did not note any major or ongoing proficiency concerns. Engine malfunctions and adverse weather operations were included.
Aircraft Information
General
VH-FVN was an ATR72-212A 600 series aircraft manufactured in 2012. The aircraft is a twin-engine turboprop regional airliner that seats up to 78 passengers (dependant on configuration) and is crewed by two pilots and two cabin crew.
Engine combustion and flameout
The ATR72 is powered by two Pratt & Whitney Canada (PWC) PW127M turbo propeller engines. The engine operates by continuous internal combustion of a fuel air mix. A flameout is an unintentional extinguishing of the flame in the engine. This may result from interruption of any of the requirements for sustaining combustion, being fuel, air and heat.
The ATR Flight Crew Operating Manual (FCOM) provided information on possible causes of a flameout. Pilots were able to use this to assist in identification of the likely cause in the event of a flameout and to allow appropriate action to take place. The FCOM stated:
The causes of engine flameout can generally be divided into two categories:
- External causes such as icing, very heavy turbulence, fuel mismanagement. These causes, which can affect both engines can generally be easily determined and an immediate relight can be attempted.
- Internal causes such as engine stalls or failures, usually affect a single engine. These causes are not so easily determined. In these cases, the engine is shut down then the cause of the flameout investigated. If the cause of the flameout cannot be determined, the need for engine restart should be evaluated against the risk of further engine damage or fire that may result from a restart attempt.
‘Icing’ is not quantified. However, another section of the FCOM stated that very large ice accretion on the engine intake may generate an engine flameout when the ice breaks free. Rain is not specifically included in the FCOM as an external cause of flameouts.
Fuel system
Fuel management and fuel quality was considered as a possible external contributor. There was no evidence to suggest fuel mismanagement and inspection of the fuel system did not identify any contaminants. Fuel management and fuel quality were not considered contributory to the flameouts.
Ignition system
The PW127M engine has a high-energy ignition system which provides for engine start on ground or in flight. Following a successful engine start, the ignition system is automatically disengaged and no longer providing a spark as combustion is self-sustaining. Under control of the electronic engine control (EEC) unit, the ignition system will activate if NH[3] drops below 60 per cent.
A guarded manual ignition switch is available to allow the crew to manually select continuous ignition. The FCOM referred to manual ignition in situations where an EEC is OFF (fault or malfunction). If one or both EECs are OFF, manual ignition is required for flight in the following cases: icing conditions, engine(s) flame out, emergency descent, severe turbulence and heavy rain, or when operating on a contaminated runway for take-off or landing.
The ATSB noted that there was no FCOM reference that prohibited the use of manual ignition in other situations and there was no explicit direction for ignition to remain in its automatic initiation state.
Prior to the engine flameouts on VH-FVN, the ignition system was in its normal state, being OFF, but primed to be initiated by the EEC as previously described. For both flameouts, the ignition system automatically engaged as designed and successfully relit the engines. Following the automatic recovery, the crew reported that they selected manual ignition as a safety measure to prevent further flameouts. The crew could not recall any specific guidance from ATR for flights in heavy weather.
Following notification of the occurrence, ATR advised Virgin that selection of manual ignition was not appropriate and that use of manual ignition other than as directed lowered the flameout recovery and protection afforded by automatic ignition. ATR explained the difference as follows:
On ATR72-600, each engine is equipped with a high-energy ignition system. Triggering of auto-relight energizes igniter boxes, which deliver sparking rate of 5/6 per sec for 25s.
MAN IGN [manual ignition] is a guarded push button at overhead panel and is to be used in case of EEC Fault or under dispatch minimum equipment list (MEL[4]) with EEC OFF as per ATR procedures.
When selecting MAN IGN, ignition system is activated at a sparking rate of 5/6 per sec for 25s. Then, the sparking rate becomes slower after 25s (changing from 5/6 per sec to 1 per sec).
ATR later clarified their explanation for automatic initiation in that following the initial 25 seconds, the sparking rate also reduces to one spark per second.
The implication is that if manual ignition has been ON for more than 25 seconds at the time of a flameout, it would be steady at one spark per second and not at the high spark rate of automatic ignition, therefore potentially delaying the relight process.
Icing and rain protection system
The ATR72-600 is fitted with various protection systems for operations in various environmental conditions, particularly icing.
The system consists of:
Ice detector, mounted on left wing which electronically monitors ice accretion.
Ice evidence probe (IEP) near captain’s windshield for visible detection of ice accretion.
Electrically heating (anti-ice) of propeller blades, windshields, probes and flight control horns.
Pneumatic boots (de-ice) on wing and horizontal tailplane leading edges and engine air intakes and gas paths.
Windshield wipers for rain removal from front windshields.
An aircraft performance monitoring system works in conjunction with the above components, through alerts to the crew if an aircraft aerodynamic performance degradation is detected due to ice accretion.
The aircraft engines are protected from icing through the de-ice system controlled via two push button switches, one for each engine. Pneumatic boots, located in the engine air intakes and gas paths, inflate on an automatically controlled cycle to dislodge ice accretions.
The selection of engine de-ice is not a recorded parameter. However, it is monitored for faults and any faults triggered are recorded. No engine de-icing faults were recorded for the incident flight. There was no indication of any problems with the engine de-icing system that may have contributed to the flameouts. Similarly, there was no damage to the engine intakes which may indicate impact due to large ice accretions having broken away during the de-ice process.
Water ingestion margin testing
The PW127M engines had been tested and certified for water ingestion requirements, and in addition to this, another water ingestion test was undertaken by PWC in 2016 to identify engine capability in terms of water ingestion. This was on one PW127M engine mounted on a test bed with a non-bypass intake duct. This configuration tested a worst-case scenario with all water entering the engine.
The test concluded that the engine demonstrated significant margin over the certification requirements and a resilience to adverse operational environments. The certification required the engine to maintain steady operation with an ingestion of water at a 4 per cent water to air ratio (WAR). The test engine performed such that a power loss and flameout occurred at 15.8 per cent WAR.
Procedures
Operations in adverse atmospheric conditions
Volume A1 of Virgin’s operations manual suite included a section on adverse atmospheric conditions. Requirements for avoiding thunderstorms and severe weather as well as specific sections on lightning, cyclones and volcanic ash were included. Rain was not specifically mentioned.
The ATR FCOM also provided guidance and procedures for operations in adverse weather conditions. There were several sections with procedural guidance on icing conditions and turbulence and general adverse weather.
Rain was not afforded any specific guidance in the FCOM nor was it mentioned, except with regard to the use of windshield wipers and in the EEC fault procedure.
During the flight, the crew diverted and held as required to maintain the aircraft clear of the weather. On several occasions, the crew requested diversion off track to maintain safe separation from the approaching weather and entered a holding pattern on two occasions to allow for passage of thunderstorms over Canberra. The flight was initially flown at turbulence speed[5] due to moderate the turbulence encountered. From about 1807, the aircraft was flown at icing speeds. Although turbulence continued for the remainder of the flight, icing speeds were flown from that point as the crew assessed that icing was a higher threat than the moderate turbulence.
Engine flameout recovery procedure
An engine flameout procedure was included in the aircraft operational documentation. The initial actions for an engine flameout is to move the power lever on the affected engine to flight idle. If NH drops below 30 per cent (no immediate relight) then the engine is to be shutdown.
For this incident, upon warnings being displayed for the first flameout, the crew acknowledged the master warning and whilst assessing the situation, the engine power restored prior to any action being required. The second flameout occurred in a similar manner and engine power restored whilst the crew were assessing the situation. No checklist procedures were carried out given the timeframe from flameout to automatic recovery.
Recorded flight data
The ATSB downloaded and analysed the data from the aircraft flight data recorder. Figure 2 below presents the key recorded aircraft and engine parameters at the time of the flameouts. During both flameouts, the master warning was active for 5 seconds. This included the time from flameout, initiation of automatic ignition and full recovery.
Figure 2: Recorded flight data
Source: ATSB
Weather information
Weather forecasts provided to the crew included significant meteorological information (SIGMET), forecasting squall line thunderstorms with hail, with tops up to FL400. The weather was forecasted to move to the east-south-east at 15 knots. At the time of planning, operational dispatch notes indicated this weather was within 50 NM to the west of Canberra. A significant weather (SIGWX) chart covering FL100-FL250 forecast moderate turbulence between FL100-FL250 and moderate icing from FL120-FL240 with isolated embedded cumulonimbus clouds.
The Bureau of Meteorology (BOM) graphical area forecast, covering mean sea level to 10,000 ft, indicated a broad area of thunderstorms including reduced visibility down to 2,000 m associated with heavy rain and areas of 4,000 m visibility associated with widespread rain. BOM always assume that severe icing is coincident with the convective activity of forecast thunderstorms and therefore do not forecast icing separately.
The aerodrome forecast (TAF) for Canberra, issued at 1608 and valid from 1700 until 1700 the next day, forecast temporary deterioration periods where thunderstorms, reduced visibility, rain and hail would occur, broadly consistent with the area forecasts and significant weather charts. However, the prevailing conditions at Canberra suggested an approach and landing would be achieved in between the temporary deteriorations.
The crew were well aware of the expected weather for the flight and in conjunction with Virgin operation staff, sufficient fuel was loaded to allow the crew to hold and/or divert as required in order to allow for passage of the weather. Both crew commented that at no stage did they consider that the flight should be cancelled due to the weather.
BOM radar imagery around the time of the incident shows lines of moderate rainfall, which the BOM describe as indicative of thunderstorm activity.
Special observations at Canberra from 1800 confirmed thunderstorm activity and continued to be reported at Canberra until 1900.
The crew observed the actual weather was as expected but commented that turbulence was the prevalent issue. The crew described the turbulence as moderate throughout the flight with a highest recorded G load[6] of +1.76. Icing conditions were encountered, with the crew observing visible moisture and total air temperature (TAT) below 7 °C. Ice accretion was observed shortly thereafter.
The crew recalled that rain was heavier in the POLLI area. The captain described being in heavy rain at the time of the flameouts although BOM radar imager indicates moderate rain at the time. Ice was not evident on the IEP at that time and the captain recalled that the windscreen looked like ‘a bucket of water had been thrown on it’. Consistent with their pre-flight assessment that they could fly, the crew noted that the weather, although significant, was not anything that they had not encountered previously.
Post occurrence maintenance inspection
Following the occurrence, a number of maintenance inspections were undertaken. The inspections that took place included:
Visual inspection of the inlet compressor blades and exhaust outlet (a detailed inspection of the engine core was not undertaken as the visual inspection of outer section did not identify any damage indicative of ingesting foreign objects. This was based on ATR/PWC guidance).
Chip detector inspection.
Severe turbulence inspection.
Low pressure fuel filter and housing inspection.
Fuel tanks checked for water contamination.
Although not exhaustive, there was no indication of any mechanical fault or failure and no indication that further detailed inspections were required.
Related Occurrences
PWC provided information regarding 21 flameout events on PW127M engines on ATR aircraft during bad weather (rain or icing). It included this occurrence and three subsequent events. These events were on ATR72-500 and -600 variants as well as one ATR42-600.
Figure 3 shows breakdown by year:
ten were in icing conditions
seven were in heavy rain
four were in moderate rain.
In all cases, the automatic ignition system initiated successfully, and power was restored without pilot intervention.
The earlier related occurrences prompted a water ingestion test in 2016 by PWC of the PW127M engine. As previously discussed, the engine performed in excess of the certification requirements, satisfying both PWC and ATR that the engines were capable of operating in significant adverse environmental conditions.
ATR concluded that extant guidance and standard operating procedures were sufficient. That is, in the case of a temporary power loss with automatic relight there was nothing specific to do. Should an automatic relight not occur, the checklist provided guidance for securing the engine and any subsequent restart attempt.
Figure 3: Flameout events during bad weather by year
The ATSB considered internal causes such as a mechanical fault or failure. The engines were running smoothly and producing the required power as commanded with no signs of the impending flameout. Post occurrence maintenance was in conjunction with ATR and PWC guidance and did not identify any mechanical fault or failure. There was no evidence to suggest that a mechanical fault or failure contributed to the flameout.
Of possible external causes, fuel management and fuel quality were not considered contributory to the flameouts. However, evidence indicates that the aircraft encountered significant weather during the flight, including rain, icing and turbulence. Despite this, the ATSB considered that the flight crew managed the weather conditions appropriately and there was no evidence to suggest that the flight should have been cancelled due to those conditions.
The flight crew operating manual (FCOM) listed heavy turbulence as a possible cause of flameout. The crew described the turbulence as moderate and the recorded G load of +1.76 is consistent with crew description of the turbulence. The ATSB did not consider turbulence as contributory to the flameouts.
Icing was also included in the FCOM as a possible cause of flameout. There was no evidence of damage to engine inlets (suggesting no ingestion of large ice accretions) and the crew did not note any significant ice accretion during the flight. Engine de-ice had been on for at least 40 minutes prior to the flameouts which indicates that significant ice accretions would have been very unlikely. The aircraft exited icing conditions approximately 1 minute prior to first flameout (TAT had risen above 7 °C) suggesting that the conditions were suitable for dislodging any ice accretion or that they were not suitable for ice to form. There was insufficient evidence to determine if icing did or did not contribute to the flameouts.
The crew recalled that the aircraft was in heavy rain and Bureau of Metrology (BOM) radar imagery indicates moderate rain at the time. Although the engines passed certification requirements for water ingestion, numerous flameout occurrences have previously been associated with moderate or heavy rain conditions. Testing takes place in a controlled environment but does not account for engine installation and other variables of actual flight conditions. There was insufficient evidence to determine if rain did or did not contribute to the flameouts.
In the absence of evidence to the contrary, it is likely the flameouts were the result of the environmental conditions during the flight. Although the exact environmental influence could not be confirmed, it is likely this was either ice or rain, or some combination of the two.
Flameout recovery
The automatic ignition function performed as designed, recognising the drop in NH below specified criteria and automatically engaging the ignition system to relight the engines without pilot input.
The known flameout events on ATR aircraft all involved icing or moderate/heavy rain. The auto ignition system has been proven effective and reliable in providing flameout recovery and in all 21 events, as the engines successfully relit without pilot input.
In the absence of specific guidance against the use of manual ignition, the crew selected manual ignition, which operates continuously at one spark per second after the initial 25 seconds. Given the uncommon situation of two engine flameouts, the crew considered that manual ignition was a safety measure to prevent any further flameouts in that a continuous source of ignition may prevent the flame from being extinguished. This is in contrast to automatic ignition, which in the event of a further flameout, would have initially operated at a higher spark rate.
ATR advice to Virgin and other ATR operators is that in the case of a temporary power loss with automatic relight, there is nothing else to do, the system has worked as designed and restored engine power. ATR advice is that selection of manual ignition potentially lowers the flameout protection of the engine, and that manual ignition should only be used when directed by a checklist. However, ATR documentation does not contain this guidance.
Findings
From the evidence available, the following findings are made with respect to the engine flameouts on descent involving ATR 72-212A, VH-FVN that occurred near Canberra, Australian Capital Territory on 13 December 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Contributing factors
The two engine flameouts were probably the result of the environmental conditions (likely icing and/or heavy/moderate rain) during the flight.
Other factors that increased risk
The crew selected manual ignition as a preventative measure against further flameout. While ATR recommend that manual ignition should not be selected unless directed by checklist or under minimum equipment list, this was not specifically mentioned in the ATR documentation.
Other key finding
The aircraft automatic ignition system performed as designed by automatically relighting both engines without pilot input following flameout.
Safety actions
Additional safety actions
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Action taken by Virgin Australia Airlines Pty Ltd
Virgin has advised the ATSB that the following safety actions have been taken:
Provided a statement of facts of the occurrence to all ATR flight crew.
Provided an update to ATR flight crew with regard to use of manual ignition.
Released a flight crew operational notice formalising previous information on manual ignition use.
Updated internal documentation (Standard OperatingProceduresManual) to include direction on use of manual ignition as well as reference to rain as a possible cause of flameout.
Action taken by GIE Avions De Transport Regional
ATR has prepared communications to be provided to ATR operators (on request), advising details of this occurrence and that manual ignition is only to be selected when directed by checklist or under minimum equipment list.
ATR commenced an internal review of aircraft documentation with the following modifications on going:
The addition of ‘rain’ in the potential external causes of engine flameouts
The addition of detailed differences between manual and automatic ignition, including a description of the role of the manual ignition push button.
Sources and submissions
Sources of information
The sources of information during the investigation included:
Flight crew of VH-FVN
Flight data recorder and cockpit voice recorder from VH-FVN
Virgin Australia Airlines
GIE Avions De Transport Regional
Pratt & Whitney Canada
Bureau of Meteorology
Airservices Australia.
Submissions
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the flight crew, Virgin Australia Airlines, GIE Avions De Transport Regional, Bureau d'Enquêtes et d'Analyses pour la Sécurité de l'Aviation Civile, Pratt & Whitney Canada, the Transportation Safety Board of Canada, Australian Bureau of Meteorology, Airservices Australia and the Civil Aviation Safety Authority.
Submissions were received from Virgin Australia Airlines and GIE Avions De Transport Regional. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 8 December 2018, a Desert-Air Safaris Beech Aircraft Corporation B200, registered VH-ODI operated a charter flight from Adelaide Airport to Mount Gambier Airport, South Australia with a pilot and seven passengers on board. One of the passengers held a commercial pilot licence and acted in an observer role from the right flight deck seat, but was not a member of the flight crew.
During the landing at Mount Gambier, the aircraft touched down with the landing gear retracted, with the propellers contacting the runway twice before the pilot initiated a go‑around. During the go-around, the left engine failed. The aircraft then landed without further incident.
What the ATSB found
The ATSB found that upon reaching the minimum descent altitude for an approach to Runway 18 at Mount Gambier, the pilot had not yet obtained visual reference with the runway. He therefore commenced a go-around and retracted the landing gear. After retracting the landing gear, the pilot sighted the runway and decided to continue the approach, but inadvertently did not re-extend the landing gear.
During the continued approach, the pilot likely did not detect the retracted landing gear due to an expectation that it was already extended. This was possibly also compounded by the now‑increased workload.
Further, the ATSB found that the pilot’s decision to conduct a go-around after the wheels-up landing stemmed from his misunderstanding of the situation, and an assessment that a runway overrun was imminent.
Safety message
This accident highlights the hazards of spontaneous decision-making, particularly during a high‑workload phase of flight in a complex aircraft. The Civil Aviation Safety Authority Resource booklet and video Decision Making provides the following tips to improve the quality of decision making, mitigate the possibility of errors and ensure a considered approach in resolving issues or problems:
You cannot improvise a good decision, you must prepare for it. You will make a better and timelier final decision if you have considered all options in advance. This is why good briefings are important.
Use decision-making aids—operational checklists—to ensure you have not forgotten anything important.
Always have reserve capacity for reacting to unexpected events.
Delegate your load to other team members (if multi-crew) when time is critical.
Keep the big picture in mind rather than focusing on one aspect of a problem.
The occurrence
On the morning of 8 December 2018, the pilot of a Desert-Air Safaris Beech Aircraft Corporation B200, registered VH-ODI (ODI), prepared to conduct a charter flight from Adelaide, South Australia to Mount Gambier, South Australia with seven passengers on board. One of the passengers occupied the right flight deck seat as an observer. This observer held a commercial pilot licence, but was not a member of the flight crew.
At about the scheduled departure time of 1000 Central Daylight‑saving Time,[1] the pilot reviewed the weather forecast for Mount Gambier Airport which provided the following information:
A southerly wind of 10-14 kt throughout the forecast period.
Visibility greater than 10 km for the forecast period, with light rain showers until 1230.
A broken[2] cloud base of 712 ft above mean sea level (AMSL) (500 ft above aerodrome level (AAL)) until 1130.
From 1130, the broken cloud base would remain, but rise to 1,212 ft AMSL (1,000 ft AAL).
From 1230, the cloud coverage was forecast to reduce to scattered and the cloud base rise further to 1,712 ft AMSL (1,500 ft AAL), with an overlying broken layer at 2,212 ft AMSL (2,000 ft AAL).
The pilot also contacted the Mount Gambier Airport aerodrome reporting officer. The aerodrome reporting officer advised that the observed cloud ceiling was about 300 feet above the aerodrome level and that a scheduled flight from Adelaide to Mount Gambier had delayed their departure due to the low cloud. The pilot of ODI noted that the forecast indicated conditions would improve, and he elected to delay the departure, until 1100.
At 1109, the flight departed Adelaide Airport. During the flight to Mount Gambier, the pilot prepared for the arrival. He anticipated conducting an area navigation (RNAV) instrument approach to Runway 18 (see the section titled Operation) (Figure 1). The pilot also determined an estimated time for the commencement of the approach of 1157. Air traffic control advised that another aircraft would be commencing an RNAV approach to Runway 18 at Mount Gambier at 1155. The pilot of ODI therefore elected to slow the aircraft to allow the preceding aircraft to conduct their approach.
Figure 1: Mount Gambier Airport overview
Source: Google Earth, annotated by ATSB.
During the flight, the pilot also received a Special Weather Report (SPECI).[3] This observation reported overcast cloud at 512 ft AMSL, below the approach minimum descent altitude (MDA) of 730 ft AMSL. The SPECI also reported visibility greater than 10 km and a southerly wind of 11 kt.
At 1200, ODI commenced the Runway 18 RNAV approach behind the preceding aircraft. As the preceding aircraft continued the approach, the flight crew of that aircraft received an alert indicating the loss of the Global Navigation Satellite System[4] receiver autonomous integrity monitoring (RAIM)[5] and conducted a go-around.
Despite not receiving a similar alert, the pilot of ODI also elected to conduct a go-around. He climbed the aircraft to an altitude of 5,000 feet and proceeded with the missed approach procedure to waypoint[6] MTGNE to commence another approach. The other aircraft then advised that they would hold at waypoint MTGND while ODI conducted another approach.
At 1215, ODI commenced a second approach to Runway 18 from waypoint MTGNE.
During the flight and approaches, the observer contributed to the operation of the aircraft by:
Monitoring the operation of the aircraft (with autopilot engaged) while the pilot briefed the passengers.
Calculating RAIM availability.
Calling out operational checklists.
Providing details of the instrument approach to the pilot, including the upcoming waypoints, tracks between waypoints and descent altitudes.
Communicating to the pilot the details of external radio broadcasts.
Monitoring the approach and calling out excursions from the target altitude.
The approach chart indicated that a normal descent profile should position the aircraft at 980 ft, 2 NM prior to the missed approach point at MTGNM. As the aircraft crossed this point, the pilot announced that the aircraft was ‘too fast by far’ and ‘high’.
On multiple occasions throughout the approach, the pilot questioned and corrected information provided by the observer and educated her on the operation of the flight.
As the aircraft descended to 730ft, the observer announced that they had reached the MDA. Upon reaching the MDA, the pilot could see the ground directly beneath the aircraft, but could not see the runway ahead. He then announced that he would conduct a go-around and retracted the landing gear, without announcing that he had done so. The observer was unaware that the landing gear had been retracted. After the pilot announced the go-around, the engine power level did not increase.
Nine seconds after the landing gear was retracted, the pilot and observer sighted the runway. The pilot then reduced power and selected full flap to continue the approach. He noted that the required approach profile from that position was ‘very steep’.
At that time, the landing gear warning tone activated. As the approach continued, the ground proximity warning system (GPWS) ‘check gear’ aural alert also activated. In response, the pilot incorrectly announced that the landing gear was extended. The approach continued, and 5 seconds later the GPWS alert ‘pull up’ also activated. The observer announced that the ‘pull up’ warning had activated. The pilot acknowledged this call, announced ‘I’ve got it’ and continued the approach. One second later, the ‘pull up’ and ‘check gear’ alerts ceased, but the landing gear warning tone continued (the pilot and observer both later recalled not hearing the landing gear warning tone or GPWS ‘check gear’ alerts).
At 1222, the aircraft briefly touched down on the propellers and bounced (Figure 2). Two seconds later, the propellers again contacted the runway. The pilot, believing the landing gear was down and the aircraft had landed on the runway, twice attempted unsuccessfully to engage reverse thrust.
Figure 2: Left propeller strike marks
Source: Airport operator, annotated by ATSB.
The aircraft continued flying above the runway at low level and began to drift right toward the runway edge. The pilot, believing the aircraft to be rolling on the landing gear and not responding to brake inputs, assessed that it could not be stopped in the remaining runway and elected to conduct a go-around. He then increased engine power and observed good initial response from both engines followed shortly after by failure of the left engine.
The pilot completed the initial engine failure actions and announced ‘gear up, flap up’ and the landing gear warning tone then ceased operating, consistent with flap retraction (see the section titled Aircraft details). Following the flap retraction, the stall warning activated intermittently for 16 seconds.
The pilot shut down and secured the left engine and assessed that the right engine was performing as expected. He then conducted a visual left circuit at an altitude of about 600‑650 ft AMSL, and at 1224 the aircraft landed on Runway 18 and vacated on to Runway 29 where it was shut down (Figure 1).
The observer assisted with passenger disembarkation onto Runway 29 and escorted them clear of the runway. No persons were injured during the accident however, the aircraft was substantially damaged.
The pilot held an Air Transport Pilot Licence (Aeroplane) and a Class 1 aviation medical certificate. He also held pressurisation system, retractable undercarriage and gas turbine engine ratings along with an instrument rating applicable to multi-engine aircraft and instrument approach procedure ratings for both two-dimensional and three-dimensional approaches.
At the time of the accident flight, the pilot had over 14,200 hours of aeronautical experience, of which about 2,460 hours were on the B200.
The investigation found no indicators that increased the risk of the pilot experiencing a level of fatigue known to have affected performance.
Following the accident, the Civil Aviation Safety Authority (CASA) suspended the pilot’s licence.
Observer
The observer held a Commercial Pilot Licence (Aeroplane), an instructor rating and a Class 1 aviation medical certificate.
The observer had not held a flying role for a number of years and was observing the operation to re‑familiarise herself with flying operations. She had acted in that role on the B200 over the preceding 4 months. At the time of the accident flight, the observer had about 440 hours of aeronautical experience, of which none were on the B200.[7]
The pilot commented that the interactions between himself and the observer did not increase his workload, were not distracting, and reinforced his actions.
Operation
The flight was a passenger charter flight from Adelaide to Mount Gambier and had been arranged the previous day. The company typically operated such flights as single-pilot operations, often with an observer, as was the case for the accident flight.
The observer was not a member of the flight crew and her role was not defined in operational documentation. Typically flight crew roles are defined as ‘Pilot Flying’ and ‘Pilot Monitoring.’ The Pilot Flying does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The Pilot Monitoring carries out support duties and monitors the Pilot Flying’s actions and the aircraft’s flight path.
The pilot was also the Chief Pilot and owner of the company; he defined the observer role as purely an observational role with limited participation in the operation of the flight. He did describe the observer taking on some operational support duties such as recording operating parameters and providing instrument approach information to the pilot. The observer understood the role not to include any flying or radio broadcasts, but to observe the operation of the flight, act as a support to the pilot during flight and to assist with ground duties.
There was no evidence that the observer made radio broadcasts or manipulated the flight controls during the accident flight.
Mount Gambier Runway 18 RNAV-Z approach
Runway 18 at Mount Gambier was provisioned with an area navigation (RNAV) straight-in approach. The approach was flown along a path of GNSS waypoints. The passage of each waypoint allowed a pilot to descend in accordance with segment minimum safe altitudes and, after passing the final approach waypoint (MTGNF), descend to the MDA.
The MDA was 730 ft AMSL,[8] which was 518 ft AAL (Figure 3). Upon descending to the MDA, further descent must not be made unless the pilot is able to proceed visually.
Figure 3: Mount Gambier RNAV-Z Runway 18 approach
Source: Airservices Australia, modified by ATSB
The Airservices Australia publication, Aeronautical Information Publication (AIP) section ENR 1.5, paragraph 1.8.2, provided the following requirements to be met to allow descent below an MDA during a straight-in approach:
Descent below the straight-in MDA may only occur when:
visual reference can be maintained;
all elements of the meteorological minima are equal to or greater than those published for the aircraft performance category; and
the aircraft is continuously in a position from which a descent to a landing on the intended runway can be made at a normal rate of descent using normal flight manoeuvres that will allow touchdown to occur within the touchdown zone of the runway of intended landing.
Section ENR 1.5, paragraph 1.10.1 (relevant sections only), further instructed:
A missed approach must be executed if:
c. visual reference is not established at or before reaching the missed approach point from which the missed approach procedure commences; or
d. a landing cannot be effected from a runway approach
Workload
In the context of aviation, workload has been described as ‘reflecting the interaction between a specific individual and the demands imposed by a particular task. It represents the cost incurred by the human operator in achieving a particular level of performance’ (Orlady & Orlady, 1999). A person experiences workload differently, based on their individual capabilities and the local conditions at the time.
Research on unexpected changes in workload during flight has found that pilots who encounter abnormal or emergency situations experience a higher workload with an increase in the number of errors compared to pilots who do not experience these situations (Johannsen & Rouse, 1983). Additionally, Harris (2011) states that:
‘The underlying concept is that cognitive workload is a product of competition for limited information processing resources.' Wickens and others (2016) add that when workload becomes excessive, ‘people may shed tasks in a non-optimal fashion, abandoning those that should be performed.’
In particular, the task of monitoring the state of important items in the cockpit can be one of the tasks shed by a single pilot. The United Kingdom Civil Aviation Authority publication Monitoring Matters provides the following information regarding monitoring:
…whilst you are ahead of the game, concentrating on the next event, keeping an eye on all the flight parameters, system modes etc everything runs fairly smoothly. But as soon as something draws your attention away and you become out of the loop it becomes difficult to play catch up.
While it is possible to attend to more than one task using selective attention techniques, there is a limit to cognitive capacity. If tasks consume this capacity, task shedding will occur. This publication further advises that under high workload, especially during approach and descent, attention capacity diminishes. This includes the ability to detect when the configuration of the aircraft is not correct, even when there is an aural or visual alert, particularly in the case in single pilot operations as:
…the processes and procedures will be equivalent to multi crew operation except there will only be one person in the cockpit and the systems may be less automated. Hence the need to monitor the flight profile, flight instruments, fuel state, engines, radio, etc. diligently. The instrument scan must be carried out very frequently, especially during departure and approach in order to monitor the aircraft state and planned profile.
Aircraft details
The Beech 200 is a pressurised, twin-engine turboprop aircraft with retractable landing gear and was approved for single-pilot operation. VH-ODI was manufactured in 1980 and was configured with two flight deck and 11 passenger cabin seats (Figure 4). One of the flight deck seats was also available for passenger use.
Figure 4: VH-ODI
Source: Mike Didsbury, modified by ATSB
Operational warning systems
The aircraft was fitted with a landing gear warning system. This system is designed to help prevent a pilot from landing with the landing gear retracted. The system in ODI was designed to activate when the flaps were selected to the ‘full’ position and the landing gear was not down and locked. When activated, the system emitted a warning tone through the flight deck speaker and illuminated red lights within the landing gear position selector handle (Figure 5).
Figure 5: Exemplar landing gear control lever and warning light extinguished (left) and illuminated (right) (see note)
Source: Aircraft maintainer
Note: the image is only intended to illustrate the handle warning light. It is not intended to represent the landing gear configuration at the time of the occurrence.
The aircraft was also equipped with a ground proximity and warning system (GPWS). This system was designed to alert a pilot if an unsafe aircraft terrain closure rate or aircraft configuration was detected. When activated, the system emitted aural spoken word alerts through the pilot and observer’s headsets.
The aircraft was fitted with a stall warning system to provide the pilot with aural warning of an imminent aerodynamic stall. The stall warning system senses angle of attack through a lift transducer actuated by a vane mounted on the leading edge of the left wing. Depending on aircraft configuration and flight condition, the stall warning system will activate between 5‑14 kt prior to a stall occurring.
Damage
The aircraft sustained damage to both propellers, the left engine and the fuselage (Figure 6). The damage resulted in fragments of the left propeller penetrating the left side of the fuselage and a significant oil leak from the left propeller shaft (Figure 7). The damage to the left engine led to the failure of that engine upon the application of power for the go-around.
Figure 6: Forward fuselage damage
Source: Airport operator.
The right propeller sustained less severe damage. The pilot and observer did not detect any deterioration in performance from the right engine and were not aware of the damage to this propeller until after landing.
Figure 7: Propeller and engine damage
Source: Airport operator.
Recorded data
Cockpit voice recorder
The aircraft was equipped with a Fairchild Model A100S cockpit voice recorder (CVR). The recorder captured the final 22 minutes of the flight. The aircraft was not required to be, and was not, fitted with a flight data recorder.
Table 1 is a list of key events captured by the CVR during the accident flight. Events marked with inverted commas (‘’) are automated voice alerts from the ground proximity warning system.
Table 1: Cockpit voice recorder key events
Time
Event
1215:19
Commencement of accident approach
1218:55
Pilot announces commencement of approach descent
1218:59
Sound of landing gear extension
1221:18
Observer announces that the minimum descent altitude has been reached
1221:27
The pilot announces that a go-around will be conducted
1221:31
Sound of landing gear retraction
1221:34
GPWS alert - ‘check gear, check gear, check gear’
1221:40
Both the pilot and observer announce that the runway is in sight
1221:40
Engine power reduces
1221:40 – 1222:17
Landing gear warning tone commences and activates continuously for this period
1221:49
GPWS alert - ‘check gear, check gear, check gear’
1221:50
The pilot announces that the landing gear is down
1221:50
GPWS alert - ‘pull up, pull up’
1222:03
Sound of first propeller contact
1222:05
Sound of second propeller contact
1222:10
Observer announces that an engine has failed
1222:14
Pilot announces landing gear and flap retraction. (No landing gear retraction sound is audible.)
1222:17
Landing gear warning tone ceases activating
1222:19 – 1222:35
Stall warning activates intermittently during this period
1224:05
Sound of landing gear extension
1224:34
Sound of touch-down
Security camera footage
A Mount Gambier Airport security camera overlooking the apron area of the airport captured ODI during the occurrence approach and the subsequent landing approach (Figure 8).
The magnification of the footage led to a reduction in image quality. However, the footage showed the landing gear as dark objects beneath the aircraft during the landing approach. The dark objects were absent in the footage of the occurrence approach, consistent with the retracted landing gear.
Figure 8: Mount Gambier Airport CCTV captures of ODI and representative images of a B200
On 4 July 2016, a Piper PA31-325 aircraft, registered VH-ETW, arrived at Birdsville Airport, Queensland. At the end of the downwind leg of the circuit, the pilot selected the landing gear handle down and noted that the landing gear selector moved out more easily than normal. During the turn onto the base leg, the pilot felt something against his right knee and found that the landing gear selector handle had become partially detached. The pilot inserted the handle back into the landing gear selector lever and retracted and extended the landing gear to ensure that it operated correctly. The landing gear subsequently retracted without the pilot’s knowledge.
The aircraft touched down with the landing gear retracted and the pilot assessed that the safest option was to conduct a go-around. The pilot then conducted a circuit and landed without further incident. The pilot and passengers were uninjured and the aircraft had minor damage to the propellers.
During an approach to Runway 18 at Mount Gambier in poor weather conditions, the aircraft touched down with the landing gear retracted, with the propellers contacting the runway twice before the pilot initiated a go‑around. The following analysis will consider the development of the occurrence and the subsequent decision to conduct a go‑around.
Continued approach and non-detection of retracted landing gear
Upon reaching the minimum descent altitude, the pilot could see ground directly below the aircraft, but could not obtain visual reference with the runway ahead. Therefore, he appropriately elected to conduct a go-around and retracted the landing gear. However, prior to beginning to climb the aircraft, the pilot sighted the runway and elected to continue the approach, but inadvertently did not re-extend the landing gear.
In response to the landing gear configuration, a number of automated aural and visual alerts activated. However, neither the pilot nor observer recognised that the landing gear was retracted.
It has been well-demonstrated that people are more likely to detect targets when they are expected and less likely to detect targets when they are not (Wickens & McCarley, 2008). This lack of detection occurs even when targets are salient, important and in an area to which a person is looking (known as inattentional blindness) (Chabris & Simon 2010).
When considering expectancy, a range of conditions may have influenced the pilot not detecting that the landing gear remained retracted (despite the automated alerts), including:
He retracted the landing gear during a time of high task loading associated with obtaining visual reference with the runway environment, which may have precluded the recollection that it was actually retracted.
The pilot was likely highly focussed on the landing at the time.
Errors of omission are often difficult to detect by the people who make them (Sarter & Alexander 2000).
In summary, the pilot’s ability to detect the retracted landing gear was likely reduced by his expectation that it was extended. In addition, he retracted the landing gear during a high task loading time which could have precluded the recollection that this was its latest state. This, combined with the high task loading during the continued approach in a complex aircraft, possibly meant that the task of confirming the configuration of the aircraft was shed.
Although the observer was also a pilot, she did not have the defined responsibility of monitoring the operation of the aircraft and was not assigned a ‘pilot monitoring’ role as is the norm in a formal multi-crew operation. In addition, the pilot did not announce that the landing gear had been retracted, further reducing her ability to detect the landing gear position.
She later recalled not hearing the landing gear-related aural alerts, although the cockpit voice recorder captured that she did emphasise to the pilot the ‘pull up’ EGPWS alerts. However, when these alerts were emphasised, the pilot announced that he would continue the approach. Therefore, a similar call regarding the landing gear may also have gone unheeded, as evidenced by the pilot’s reaction to the GPWS ‘check gear’ alert.
Go-around after the wheels-up landing
Prior to the wheels-up landing, the pilot understood the landing gear to be extended and stated so in response to the GPWS ‘check gear’ alert. This misperception of the landing gear position persisted through the two touch-downs and go-around.
The pilot, believing that the aircraft had bounced twice on the landing gear, that it was not responding to wheel brake inputs and that he could not engage reverse thrust, assessed that a runway overrun was imminent. This indicated that he was also very likely unaware of the substantial airframe damage sustained and why he assessed a low‑level go-around clear of cloud as the safest option.
Findings
From the evidence available, the following findings are made with respect to the wheels-up landing involving Beech Aircraft Corporation B200, VH-ODI that occurred at Mount Gambier Airport, South Australia on 8 December 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Contributing factors
The pilot elected to continue the approach after initially deciding to conduct a go-around. The pilot's expectation of the landing gear position, possibly coupled with the effects of the now increased workload, probably led to him not detecting the retracted landing gear before the aircraft contacted the runway.
Other findings
After the wheels-up landing, the decision to conduct a go-around resulted from the pilot’s misunderstanding of the situation and assessment that a runway overrun was imminent.
Sources and submissions
Sources of information
The sources of information during the investigation included:
Chabris & Simons, 2010. The invisible gorilla. Random House: New York, USA
Johannsen, G & Rouse, WB, 1983. Studies of planning behaviour of aircraft pilots in normal, abnormal, and emergency situations. IEEE Transactions on Systems, Man and Cybernetics, (3).
Orlady, HW, & Orlady, LM, 1999. Human factors in multi-crew flight operations. Ashgate: Aldershot, UK.
Wickens and others, 2016. Engineering Psychology and Human Performance. Psychology Press: New York, USA.
Harris D, 2011. Human Performance on the flight deck. Ashgate: Aldershot, UK.
Submissions
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the pilot’s next of kin,[9] the observer and the Civil Aviation Safety Authority (CASA).
Submissions were received from the pilot’s next of kin and CASA. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.
Single Engine Aircraft, Multi Engine Aircraft, DC3, Instrument Rating Multi Engine Aircraft, Instrument Approach Procedure 3D, Instrument Approach Procedure 2D
Medical certificate:
Class 1, valid to March 2019
Aeronautical experience:
Approximately 14,200 hours
Last flight review:
November 2018
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.