Accredited representative to NTSC investigation of collision with terrain involving Boeing 737 MAX 8, registration PK-LQP, on 29 October 2018

Final report

On 29 October 2018, Lion Air Flight JT610, a scheduled domestic service from Jakarta to Pangkal Pinang, Indonesia, collided with water in the Java Sea, north of Jakarta, about 13 minutes after take-off. The aircraft, a Boeing 737 MAX 8, registered PK-LQP, was destroyed and all 189 passengers and crew on board were fatally injured.

As the accident occurred in Indonesia, the Indonesian National Transportation Safety Committee (NTSC) was responsible for investigating this occurrence. In accordance with Annex 13 to the Convention on International Civil Aviation, the ATSB appointed an accredited representative to the NTSC investigation. The ATSB provided specialist expertise to support the NTSC in downloading and analysing the flight data recorder (FDR) and cockpit voice recorder (CVR) from the aircraft.

The ATSB has concluded its support of this investigation. On 25 October 2019, the NTSC released the final investigation report into this occurrence and it is available at http://knkt.dephub.go.id/knkt

Any enquiries regarding the investigation and report should, in the first instance, be directed to the NTSC.

Occurrence summary

Investigation number AE-2018-074
Occurrence date 29/10/2018
Location Java Sea, north of Jakarta
State International
Report release date 31/10/2019
Report status Final
Investigation level Defined
Investigation type External Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Manufacturer The Boeing Company
Model 737 MAX 8
Registration PK-LQP
Aircraft operator Lion Air
Sector Jet
Operation type Air Transport High Capacity
Departure point Jakarta, Indonesia
Destination Pangkal Pinang, Indonesia
Damage Destroyed

Runaway and derailment of loaded ore train M02712, near the 211 km mark south of Port Hedland, Western Australia, on 5 November 2018

Final report

Report release date: 17/03/2022

Safety summary

What happened

On 5 November 2018, train M02712, loaded with iron ore, was being operated by BHP on its Newman to Port Hedland railway, Western Australia. The train consisted of 2 locomotives, a rake of 134 wagons, 2 remote locomotives and a second rake of 134 wagons. It was fitted with an electronically controlled pneumatic braking (ECPB) overlay system.

At about 0337, M02712 was travelling at 60 km/h on a downhill grade on the west track, approaching the BHP access road level crossing at the 211.6 km mark. Shortly after, trainline communication between the lead locomotive and the combined end of train monitor was lost, triggering an automated 120% ECPB emergency brake command, stopping the train as it approached Garden South.

Following confirmation with train control of the location of the train and receiving instruction on the number of handbrakes required to secure the loaded train on the falling track grade at Garden, the driver left the locomotive cab to commence applying the brakes from the front of the train. The controller also tasked a support team to attend M02712 and help the driver with applying the handbrakes.

About 60 minutes after the loss of trainline communication, as the driver continued to apply handbrakes to the first rake of ore cars, the train began to move forward. Shortly after, train control received an emergency call from the driver of M02712 alerting that the brakes had ‘bled off’ and the train was now a ‘runaway’.

Train M02712 continued, reaching a speed of 162 km/h before slowing on the rising grades toward Woodstock. After Woodstock, the track grade again began to fall toward Port Hedland and M02712 gained speed to about 130 km/h approaching Abydos.

At about 0520, Hedland control set the crossovers at Turner South and Turner North to switch train M02712 between adjacent tracks to derail the train as it traversed the crossover at speed. About 6 minutes later, the head end locomotives travelling at 144 km/h traversed the crossover at the 119.4 km mark at Turner South.

The locomotives and the first ore car separated from the rest of the train but remained coupled, travelling about 1.6 km further before stopping. The derailment destroyed the 2 remote locomotives, 245 ore cars and 2 km of track infrastructure at Turner South. There was no injury to any person from the runaway or derailment.

What the ATSB found

Between 2011 and 2015, BHP implemented an ECPB system as an overlay to the conventional pneumatic train braking system and undertook an associated modification to the automatic train protection (ATP) system. It predominantly managed the implementation of these changes at an individual system level rather than through the application of a structured engineering approach. BHP did not subsequently identify and manage significant characteristics of how the ECPB, ATP and conventional pneumatic braking systems interacted in response to certain fault conditions. As a result, BHP’s trains configured for ECPB operation were potentially vulnerable to a runaway event should a unique combination of events and conditions occur.

The BHP risk assessment associated with a rail-mounted equipment interaction incident was broad in scope and had limited focus on the causes and critical controls of a train runaway event. In addition, the risk assessment did not include the procedure for responding to brake pipe emergencies and penalties as a critical control. BHP’s material risk control assessments (MRCAs) did not then test the effectiveness of this procedural control for preventing an uncommanded movement of a train during main line operations.

The procedure for responding to brake pipe emergencies and penalties relied extensively on a driver’s memory, with limited processes in place to facilitate or cross-check a driver’s performance to ensure all safety-critical actions were completed. Although the procedure contained a safety-critical action (to apply the automatic brake handle to the pneumatic emergency position), BHP did not clearly communicate the importance and reasons for this action to drivers, reducing the potential for the drivers to correctly recall this action

As M02712 approached Garden on 5 November 2018, one of the 12 trial inter-car connectors disconnected. This caused a loss of ECPB trainline communication and power supply continuity affecting most of the train and triggering an automatic emergency ECP brake application. The driver responded to the ECPB system’s emergency brake application by commencing the brake pipe and penalties and emergencies procedure, but exited the locomotive cab to apply handbrakes to the ore cars without placing the automatic brake handle in the pneumatic emergency position. Without this safety-critical action being done, the brake pipe air pressure was not vented to atmosphere to hold the ore cars brake application via the pneumatic system.

The car control devices (CCDs) on the disconnected ore cars and the end of train monitor continued to run using the internal battery power of each device to hold the brake application. Consistent with how they were designed however, the CCDs released their ECP brake application on shut down after 60 minutes. At this time, while the driver was applying handbrakes, M02712 began to roll away.

The ATP system detected the rollaway and other events, with each generating a penalty brake request to the ECPB system. However, the requests had no effect as the ATP and ECPB systems could not interface to dump brake pipe pressure if an ECPB application became ineffective in arresting an uncommanded train movement.

The ATSB also identified that the response crew tasked to aid the driver did not confirm whether the driver had implemented the BHP three-step protection process prior to approaching a train to begin the application of handbrakes. This increased the risk of injury to personnel working on the rolling stock. Additionally, following becoming aware of the runaway, the BHP emergency response procedures did not ensure rail infrastructure managers that interfaced with the BHP rail network were alerted to an emergency event that could affect safety at the interface.

Given that the train stopped at 0340 and the driver was conducting a series of 7 night shifts, the ATSB examined BHP’s processes for managing train driver fatigue. The ATSB found that the BHP roster patterns for fly-in fly-out train drivers were conducive to result in cumulative sleep restriction and levels of fatigue likely to adversely influence performance on a significant proportion of occasions, and BHP had limited processes in place to ensure that drivers actually obtained sufficient sleep when working these roster patterns. Due to cumulative sleep restriction over several days of night shifts, the time of day (0340) and other factors, the driver of M02712 was probably experiencing a level of fatigue known to adversely influence performance. However, based on the available evidence, the ATSB did not conclude that fatigue contributed to the runaway of M02712.

What has been done as a result

Following the runaway and derailment accident involving M02712, BHP reviewed the risk management framework associated with rail-mounted equipment interaction, updated the risk assessment, and added additional controls related to potential train runaway events. Additionally, BHP implemented a systems engineering and assurance framework to manage the future integration of systems utilised within the BHP rail system.

With regard to procedural controls, BHP revised its operating instruction for responding to brake pipe emergencies and procedures by requiring the driver to complete a form confirming the actions undertaken in response to an emergency ECPB application and confirming these actions with train control prior to leaving the locomotive cab. In addition, the operating instruction was amended to clearly advise the importance and rationale for drivers to place the automatic brake handle in the pneumatic emergency position in response to an emergency ECP brake application with the end of train monitor displaying ‘off’ or ‘?’.

BHP also revised the work instruction associated with handbrake application and release during main line recovery to require that a work group supervisor be appointed to communicate directly between the driver and the work group tasked to render assistance.

BHP has commissioned external fatigue subject matter experts to undertake a range of evaluation and development activities. BHP has recognised that its roster design was not conducive to minimising fatigue and has formed a working group to optimise rosters. It has also undertaken additional work to improve fatigue training and fatigue monitoring of drivers.

Safety message

A train runaway can cause injury or loss of life, substantial damage to rolling stock and infrastructure, and disrupt rail operations for an extended period. Rail transport operators should therefore ensure that they conduct thorough risk assessments to ensure that relevant causes and hazards associated with runaway events are identified and managed.

In addition, rail transport operators considering changes involving the integration of complex systems should utilise a systems engineering approach to identify hazards and then manage risk to ensure that the railway’s operations remain safe, so far as is reasonably practicable. Rail transport operators must then ensure the preventative controls mitigating the hazards will be effective in managing the risk. They also need to place adequate emphasis on critical controls to signify their importance and ensure that the rail safety workers who are required to implement procedural controls clearly understand why the specified actions are required.

Emergency procedures communicate critical tasks that must be fully actioned by rail safety workers responding to atypical or unexpected situations. Rail safety workers must therefore ensure they take sufficient time to methodically perform and verify the effectiveness of each required action.

 

The occurrence

Overview

On 5 November 2018, train M02712, loaded with iron ore, was being operated by BHP on its Newman to Port Hedland railway, Western Australia, from Mining Area C to Nelson Point (Figure 1).

At about 0340,[1] the train stopped at the 210.7 km mark near Garden South due to a loss of trainline communications. As part of the response to this fault, and in discussion with network control, the driver exited the locomotive and commenced applying the handbrake on each ore car. At approximately 0440, with the driver still applying handbrakes, the train rolled away. There was no driver on board the train at the time.

The train travelled uncontrolled on the west track for about 91 km before Hedland train control derailed the train by routing it from the west track to the east track at a crossover located at Turner South. At about 0526, the head end locomotives traversed the crossover. Shortly after, 245 ore cars and the 2 remote locomotives, positioned mid train, derailed while travelling at 144 km/h.

Figure 1: Map of BHP’s Newman to Port Hedland railway

Figure 1: Map of BHP’s Newman to Port Hedland railway

Source: BHP, annotated by the ATSB

Events prior to loss of trainline communications

At about 2300 on 4 November 2018, train M02712 departed Mining Area C (Figure 1) for the driver exchange point, M308 (308 km mark). It consisted of 2 locomotives leading, a unit rake of 134 ore cars, 2 remotely-operated locomotives located mid train, and a second unit rake of 134 ore cars. The trains brake control system was set to enable electrically controlled pneumatic brake (ECPB) operation.

Following arrival at M308, the next rostered driver for the train boarded and took over control of M02712. The train departed the driver exchange point at about 0115, crewed in a driver-only configuration.

At about 0337 on 5 November 2018, M02712 was travelling at 60 km/h on a downhill grade on the west track, approaching the BHP access road level crossing at the 211.6 km mark. The driver had set the throttle control for maximum dynamic braking to control train speed for descending the grade and began moving the automatic brake handle toward a 39% train brake command (TBC).

At about 0338, electrical communication via the trainline between the lead locomotive (4420) and the end of train monitor (EOTM) was lost, triggering an automated emergency brake application (120% TBC), stopping the train at about 0340 as it approached Garden South.

Response to loss of trainline communications

In response to the loss of trainline communications, the driver fully applied the locomotive independent brake. The driver made an emergency radio call to Hedland train control to report the occurrence, the location (at the 210.737 km mark between Shaw and Garden), and the detail of the alert messages displayed on the locomotive onboard systems.

The train controller placed blocks to the trackside signals on the adjacent east track between Garden South and Shaw North[2] to protect the train from other rail movements, and contacted personnel from the Redmont[3] maintenance gang to assist the driver. The controller told the driver that help was on the way and requested the driver to confirm the train’s location from a kilometre mark on the ground closest to the lead locomotive. The driver advised the controller that the FIRE[4] system displayed 210 km but they would detrain and check the kilometre mark to confirm.

At about 0350, the driver confirmed to the controller that the train was stopped at the 210.7 km mark. The controller then instructed the driver to apply 101% handbrakes[5] to secure the loaded train on the falling track grade at Garden. The controller asked if the driver wanted to start applying them now or wait in the locomotive for the arrival of personnel from the Redmont gang (who had been tasked by the controller to check the rear of the train before starting to apply the handbrakes from that end). The driver advised that they would start applying the handbrakes to the first rake of 134 ore cars rather than wait for the Redmont gang to arrive.  

At about 0351, the driver placed the reverser[6] control to the centre (neutral) position and turned the generator field[7] off before preparing to exit the cab of locomotive 4420. The 120% emergency TBC was still active and the automatic brake handle remained set at the position equating to a 39% ECPB TBC.[8] The driver was aware the emergency ECPB interlock[9] would maintain the ECPB application and had applied the independent brake to secure the train. Additionally, by placing the reverser to the centre position and turning the generator field off, the driver had set up the locomotive rollaway protection provided by the on-board automatic train protection (ATP) system.

However, the driver did not place the automatic brake handle in the pneumatic emergency position to vent the train brake pipe pressure to atmosphere. This meant an additional braking control via the conventional pneumatic train brake system was not activated, and the emergency brake application was maintained by the ECPB system only.

Application of handbrakes

At about 0353, the driver exited the locomotive and commenced applying handbrakes to the ore cars, starting from the front of the train.

Soon after starting to apply the handbrakes, the driver identified that one of the inter-car trainline cable connectors near the front of the train had detached. The trainline was located on the opposite side of the train to the handbrake controls. As required by the operator’s procedures, the driver continued applying handbrakes to the remaining ore cars. The driver recalled that the process of applying handbrakes was relatively slow due to the difficulty climbing up and down the steep-sided ballast formation next to each ore car in the dark.

Train control continued to keep in contact with the driver of M02712 via the driver’s handheld radio at 10-minute intervals. During the first of these scheduled calls, the driver advised of finding the disconnection in the trainline cable.

At about 0422, personnel from the Redmont gang informed Hedland train control of their arrival at the 210 km mark to aid the driver of M02712 with applying handbrakes. The controller tasked the gang to start applying handbrakes from the rear of the train and continue toward the driver, who was working from the front. The controller also requested that, when the Redmont gang reached the rear of the train, they provide a report on the integrity of the rear of the train.

During a subsequent scheduled 10-minute call with train control, the driver reported to the controller that the application of handbrakes was progressing well, despite having trouble walking along the elevated ballast shoulder next to the stationary train. The driver stated they were about ‘three quarters’ of the way toward the remote locomotives in the middle of the train. They also reported being aware that the Redmont gang would check the integrity of the rear of the train and start applying handbrakes from there. The driver advised the controller that they intended to continue working toward the remote locomotives in the middle of the train, report to train control, and then return to reinstate the break in the trainline cable. The controller stated that, as the driver and maintenance gang were now ‘both on the ground’, they could communicate with each other.

The driver later advised they had formulated their plan to apply handbrakes on the first rake and then go fix the connector on the assumption that the personnel in Redmont gang, sharing the task of applying handbrakes, would be able to move at a faster rate; meaning that they would arrive at the remote locomotives at about the same time as the driver.

The runaway

At 0438, 60 minutes after the loss of trainline communications, the brakes released on most of the ore cars in the train. At this time, the driver was still applying handbrakes to the first rake of ore cars, and they recalled that they were about 20–30 ore cars from the rear of the first rake. The driver initially heard air venting from the ore car brakes and shortly after noticed the train lurch forward and start to roll away. The driver recalled that they tried to radio the Redmond gang and alert them that the brakes had ‘bled off’ but there was no response.

Shortly after train M02712 began to roll away, the ATP system detected the movement and requested a penalty brake application, but it was ineffective in stopping the train.

Previously, at about 0355, an empty ore train (M02727), travelling on the adjacent east track toward Yandi Junction, stopped at Garden South due to the blocking protections set up previously. At about 0444, the driver of this empty ore train contacted Hedland train control to advise that M02712 was moving and had passed Garden South at an estimated speed of about 50 km/h with brakes dragging.[10]

At 0446, train control received an emergency call from the driver of M02712, stating that the brakes had bled off and the train was now a ‘runaway’. The driver of M02712 had lost their footing when the train began to move, slipping on the ballast formation and knocking their radio off channel. After resetting the radio, the driver contacted the train controller, declaring an emergency and notifying of the runaway. Train control acknowledged the emergency call and advised that signal GNN4 at Garden North was set to red, in order to stop the train by triggering the locomotive onboard ATP system.

Train M02712 passed signal GNN4 at about 80 km/h and continued to increase speed. Although the ATP system requested a penalty brake application in response to signal GNN4 at red and to an overspeed condition, these penalty requests were also ineffective in stopping the train.

About 80 km ahead, another train (M02728) travelling on the eastern track was approaching Abydos North. Hedland train control contacted its driver, instructing the driver to stop, detrain and move to a safe place. Train control also contacted the drivers of the 2 other trains (M02729 and M02710) working between Garden North and Port Hedland, instructing them to also stop, detrain and move to a safe place. Trains M02729 and M02710 stopped at locations north of Turner (Figure 1).

At about 0502, the driver of the empty ore train stopped at Garden South (M02727) contacted train control to advise that the Redmont gang had mistakenly started applying handbrakes to their train rather than to M02712.

Train M02712 continued through Spring and Coonarie. It reached a speed of 162 km/h before slowing on the rising grades toward Woodstock (Figure 1).

At about 0509, M02712, travelling at about 128 km/h, passed over the active level crossing at the 154.3 km mark before Woodstock South. After Woodstock, the track grade again began to fall toward Port Hedland and M02712 gained speed to about 130 km/h as it passed M02728 stopped at the 130.5 km mark on the eastern track north of Abydos.

The derailment

At about 0520, Hedland train control set the crossovers at Turner South and Turner North to switch the runaway train M02712 between adjacent tracks to derail it as the train traversed the crossovers at speed.

About 6 minutes later, the head end locomotives, travelling at 144 km/h, traversed the crossover at the 119.4 km mark at Turner South. Locomotives 4420, 4434 and the first ore car separated from the rest of the train but remained coupled, travelling about 1.6 km further before stopping (Figure 3). The first ore car had derailed.

Ore cars in position 2 to 134 of the first unit rake, the remote locomotives 4472 and 4440 and ore cars one to 112 from the second unit rake derailed near the crossover (Figure 3). The last 22 ore cars of the second unit rake remained coupled and on track.

The derailment destroyed the 2 remote locomotives, 245 ore cars and about 2 km of track infrastructure at Turner South (Figure 4). There was no injury to any person from the runaway or derailment.

Figure 2: Locomotives 4420, 4434 and first ore car at Turner South

Figure 2: Locomotives 4420, 4434 and first ore car at Turner South

Image viewed in a southerly direction of locomotives and ore car at Turner South. The lead locomotives 4420 and 4434 and one ore car remained upright, however the ore-car had derailed.

Source: BHP, annotated by the ATSB

Figure 3: Train M02712 wreckage near the crossover at Turner South

Image viewed in a southerly direction of locomotives and ore car at Turner South. The lead locomotives 4420 and 4434 and one ore car remained upright, however the ore-car had derailed.  Source: BHP, annotated by the ATSB Figure 3: Train M02712 wreckage near the crossover at Turner South

Aerial image viewed in a southerly direction of train wreckage and track damage at Turner South. The lead locomotives 4420 and 4434 remained on track and were coupled with one ore car that had derailed (out of frame in the foreground).

Source: BHP, annotated by the ATSB

Figure 4: Ore cars and remote locomotive 4427 wreckage at Turner South

Figure 4: Ore cars and remote locomotive 4427 wreckage at Turner South

Wreckage of remote locomotive 4472 and ore cars from rakes A and B viewed in a south-westerly direction at Turner South.

Source: BHP, annotated by the ATSB

  1. All time references in this report are local time (Western Standard Time).
  2. The trackside signals displayed a red (stop) indication.
  3. Redmont was a remote maintenance camp accommodating track workers. It was located near Garden South.
  4. Functionally integrated railroad electronics (FIRE) system: forms the interface between the operating crew and locomotive computer systems.
  5. The controller used a handbrake calculator tool to determine the number of handbrakes required based on track grade and loaded/empty state of the train.
  6. Reverser control: lever in locomotive cab to select ‘forward’ ‘centred/handle-out’ or ‘reverse’ for the direction of operation.
  7. Power source for generator field excitation.
  8. An automated ECP penalty brake application overrides manual setting of the automatic brake handle.
  9. For a system initiated emergency brake application, the 120% TBC brake interlock feature maintained a full air brake application to the train, but the brake pipe air pressure remained fully charged at 600 kPa (see ECPB codes of practice and standard)
  10. Brakes applied on head end locomotives and a number of ore cars from the first rake.

Context

Track information

BHP was the rail infrastructure manager for the Newman to Port Hedland railway, which it used to transport iron ore. The railway was a standard gauge track structure constructed with continuously welded 68 kg/m rail, fastened with resilient clips to concrete sleepers bedded in crushed rock ballast. The track structure configuration enabled the operation of rolling stock with a 40-t axle load.

In the direction of travel, the track gradient from Mining Area C was primarily a rising grade approaching Shaw in the Chichester Range, before transitioning to a mainly falling grade toward Nelson Point (Figure 1). The M02712 runaway started between Shaw North and Garden South where the track gradient was -1.5%, the steepest track gradient of the track section between Yandi Junction and Nelson Point.

An automatic train protection (ATP) system governed the maximum permissible track speed for the various sections dependent on the mode of operation (loaded or unloaded), with the target speed displayed to a driver via the FIRE system. The maximum track speeds for the Newman to Port Hedland railway were 60 km/h for a loaded and 75 km/h for an unloaded ore train.

Train control information

BHP managed train movements remotely from a train control centre located in its integrated remote operations centre in Perth. The train control centre had 5 operational control areas (desks): Hedland, Newman, 6PG, Hub control and Yard control. All communications between the Perth control centre, train movements, control systems and wayside equipment was via a dedicated VHF radio system.

The runaway occurred within the operational area managed by Hedland train control, which extended from the 67 km mark south of Walla to the 260 km mark south of Cowra (Figure 1).

Train crew information

Qualifications and experience

The driver of train M02712 began employment with BHP in 2008, operating ore trains from Port Hedland and later the Yandi depot. The driver had recently completed the BHP driver reaccreditation in driver safeworking, locomotive system theory and in-field training courses, and held the required competencies for the tasks performed (see also Driver competency assessment related to rules and procedures).

Medical information

The driver underwent their last medical assessment (category 1) on 9 May 2018 and was assessed as fit for duty as per the requirements of the National Standard for the Health Assessment of Rail Safety Workers.

Following the occurrence, BHP initiated screening tests on the driver for the presence of an illicit drug or alcohol, which provided a negative result (that is, no alcohol or drugs were detected).

Recent history

The driver was employed under a fly-in fly-out (FIFO) arrangement. BHP’s train drivers working on a FIFO arrangement typically worked a roll-over roster pattern or ‘swing’ that included 7 12-hour shifts (each starting at the same time of day), a 24-hour recovery break, 7 12-hour shifts (each starting at the same time of day), and 12 days off duty.

The driver commenced a roll-over swing on 31 October 2018, as outlined in Table 1. This involved commuting to Adelaide on 29 October, staying overnight in Adelaide, then commuting during the day from Adelaide to Yandi on 30 October. The driver recalled waking at about 0230 Western Standard Time[11]to make an early flight to Perth, then catching an afternoon flight to Newman (during which they had a short nap) and arriving at the Yandi depot at about 1700. They had 4–5 hours after arriving at Yandi to allow for unpacking, getting a meal, going back to their accommodation, checking in with family and obtaining some rest prior to preparing for work.

The driver then commenced the series of 12-hour night shifts, each starting at 2200. Each shift generally involved taking a loaded train from Yandi to Port Hedland or taking an empty train from Port Hedland to Yandi.

Table 1: Scheduled and actual duty times for the driver of M02712

DateWork activityDuty startDuty endDuty timeTime free (of duty)
28 Oct 2018Day off (11th day free of duty)    
29 Oct 2018

Day off

Commute to Adelaide (1600–2000)

    
30 Oct 2018

Commute Adelaide – Yandi depot (0230–1700)

Yandi–Port Hedland

 

 

2200

 

 

1000

 

 

12 hours

 

 

12 hours

31 Oct 2018Port Hedland–Yandi2200100012 hours12 hours
1 Nov 2018Yandi–Port Hedland2200100012 hours12 hours
2 Nov 2018Port Hedland–Yandi2200100012 hours12 hours
3 Nov 2018Yandi train load out2200100012 hours12 hours
4 Nov 2018Yandi–Port Hedland (train stopped at 0340)2200100012 hours12 hours
5 Nov 2018Night shift (planned, not worked)2200100012 hours24 hours
6 Nov 2018(Finish duty at 1000)    
7 Nov 2018Day shift (planned, not worked)1000220012 hours12 hours
8 Nov 2018Day shift (planned, not worked)1000220012 hours12 hours
9 Nov 2018Day shift (planned, not worked)1000220012 hours12 hours
10 Nov 2018Day shift (planned, not worked)1000220012 hours12 hours
11 Nov 2018Day shift (planned, not worked)1000220012 hours12 hours
12 Nov 2018Day shift (planned, not worked)1000220012 hours12 hours
13 Nov 2018Day shift (planned, not worked)1000220012 hours12 hours

All times in the table are in Western Standard Time (UTC + 8 hours). The driver commenced commuting on 30 October from Adelaide, which was 2.5 hours ahead of WST.

The driver signed on for their sixth night shift on 4 November at about 2200 after a short (10–15 minutes) commute. The driver recalled that there was a delay in their loaded train being ready for departure. They eventually departed the driver exchange point, M308, at about 0115. They were running behind another train and experienced some yellow signals and reduced speeds, but had no stoppages until the train stopped near Garden at 0340.

Drivers were entitled to a 30-minute ‘crib’ break (or meal break) each shift, and the driver expected to get their break at about 0430–0500 due to the late departure (and breaks normally being taken with a train on a flat gradient). The driver reported that, in the period leading up to the train stopping, the workload and complexity were both moderate (which was normal for that location). 

The driver stated that, after stopping work at 1000 following a night shift, they would go back to their accommodation and normally slept for about 4–5 hours. They then had a meal when the kitchen opened at about 1700, watched television, made a call home and then dozed or napped (if sleep occurred). Overall, they would normally get about 5–6 hours sleep each break following a 2200–1000 shift, with some of this being broken sleep and sometimes sleep being difficult to obtain. This contrasted with 7 plus hours of good quality sleep from about 2200 to 0630–0700 when they were at home.[12]

The driver reported that they found swings commencing at 2200 the most difficult for obtaining sleep. The first few days were particularly difficult, and they would get more sleep later in the week. However, they would continue to get less sleep each rest period than they would at home.

The driver self-rated their fatigue level at the time of the occurrence as 4 out of 7 (‘a little tired’) [13]but also noted that a person usually feels better than they actually are. The driver also commented that, after the train stopped, they felt ‘deflated’ when they realised they had to walk alongside the train to secure the handbrakes.

In terms of strategies to maintain alertness, the driver stated they drank some coffee each day during a swing, mainly while waiting for their train to be ready rather than on the train. They would also listen to music when in the train. They did not take any medications to maintain alertness or drink alcohol during a swing.

Further information regarding BHP’s fatigue management procedures are provided in Fatigue management.

Train information

General information

BHP’s ore trains ran as unit trains.[14] Train M02712 consisted of 2 SD70ACe type locomotives (4420, 4434) leading, a unit rake of 134 ore cars, 2 remotely-operated SD70ACe type locomotives (4472, 4440) located mid train, and a second unit rake of 134 ore cars. It weighed approximately 42,500 t and was 2,860 m long.

The ore train was working between the loading facility at Mining Area C, situated on the spur line extension from Yandi, and the unloading facility at Nelson Point, Port Hedland (Figure 1).

SD70ACe type locomotive

BHP’s SD70ACe diesel electric locomotives were equipped with a microprocessor-based computer control system (EM2000). This control system monitored and controlled locomotive traction power, braking and other interfacing systems. The control system detected fault conditions and allowed diagnostic testing of associated systems. The interface between the locomotive control system and driver was through the functionally integrated railroad electronics system (FIRE).

The FIRE display panel (or integrated functional display) was located in the driver console. The FIRE system replaced most of the driver control switches, gauges and indicators with a display panel graphic user interface. The display screens provided an interactive system that allowed viewing of pertinent data and provided input signals to the locomotive control and air brake systems for set-up and diagnostic tasks. The system also displayed information on an event basis, such as alarms and operator crew messages. ECPB set-up and other functions were performed using various ECPB menus on the display panel.

Some locomotive control functions that previously operated independently through their own display screens were integrated into the FIRE display console. Such functions included those associated with the:

  • EP-60 brake controller
  • ATP system
  • locomotive microprocessor control system
  • ECPB system.
Overview of BHP ore car braking system

The braking application on a conventional pneumatically-braked ore car relied on the driver operating the automatic brake handle in the locomotive to generate a reduction in brake pipe pressure (pressure wave) within the brake pipe. The pressure wave propagated along the brake pipe (through each ore car) for the length of the train. This pressure wave actuated a pneumatic brake control valve in each ore car, applying the ore car’s brakes. The ore car brake applications occurred sequentially along the train, with the magnitude of the brake effort determined by the reduction in brake pipe pressure made by the driver.

Conventional pneumatic braking systems therefore allowed the driver to graduate the application of braking effort on the train. These systems required the brake pipe to be fully charged before the pneumatic valves in each ore car would release the brake application. This meant that the driver could not graduate the release of a brake application.

In contrast to conventional pneumatic-braking systems, an electronically controlled pneumatic braking (ECPB) system used electronic signals that made it possible to activate the air-powered brakes on each ore car. To facilitate this, the ore cars were equipped with a trainline cable that ran parallel to the brake pipe along the length of the train. The cable supplied power to the electronic components installed on each ore car. The cable also served as a communication medium that allowed the locomotive control system to send commands and receive feedback from the ore cars and the end of train monitor (EOTM).

ECPB provided benefits over the conventional pneumatic braking system. For example:

  • Since all the ore cars received the brake command at the same time, the brakes were applied uniformly and instantaneously. This minimised in-train forces and provided better train control, shortened the stopping distance, and reduced risk of derailment or of coupling breakage.
  • The brake pipe remained charged during a brake application. This allowed the reservoirs on the ore cars to continuously charge with air.
  • As the ore cars could send their status to the locomotive at the front, ECPB provided better diagnostic capabilities and enabled the train crew to better monitor the state of the train and its braking capabilities.

ECPB trains could take 2 forms: stand-alone or overlay. With a stand-alone system, braking controls on the ore cars would only operate electrically and there was no pneumatically-operated valve installed on the ore car. An overlay system essentially retained the pneumatic valve and added the electronic car control device (CCD), electronically-controlled valve and adapter air manifold (Figure 5).

Figure 5: Typical ore car air brake system with ECP brake overlay

Figure 5: Typical ore car air brake system with ECP brake overlay

ECPB system highlighted in green.

Source: BHP, annotated by the ATSB

BHP selected an overlay option to provide operational flexibility in mitigating delays to production should an ECPB train experience a fault that could not be recovered in a timely manner. The overlay system allowed BHP to operate trains as either a conventional pneumatically-braked train or as an ECPB train.

In 2011, BHP commenced a management of change process for the introduction of the ECPB system to its mainline operations (Management of change). It then progressively implemented the ECPB system throughout its fleet.

Braking and distributed power systems on train M02712

Train M02712 was equipped with an EP-60 New York Air Brake (NYAB) ECPB system. The system consisted of locomotive equipment, ore car braking control equipment, an EOTM, and a power and communications distribution system.

Locomotive equipment included a trainline communications controller, power supply and identification module. The head end unit (HEU) locomotive communicated with each of the 268 CCDs and remote locomotives via embedded transmissions in the trainline cable, comprised of a single pair of wires forming the intra-train power and communications network. The trainline cable between each rail vehicle (locomotive or ore car) was joined using a connector (see also Trial trainline inter-car connectors). Each CCD unit used 230 V direct current power from the trainline cable to charge its batteries and supply power to its electronics.

The EOTM installed on the last ore car coupler marked the end of the train. It also provided a termination point for the trainline cable and a transducer for end of train information, such as brake pipe pressure, back to the HEU to establish the integrity of the trainline and train consist. The EOTM used 230 V direct current power from the trainline cable to charge its batteries and supply power to its electronics.

If the power from the trainline cable was lost, the CCDs and EOTM each continued to operate on battery power until a 60-minute time period elapsed (shut-down mode or battery conservation mode – refer to ECPB codes of practice and standards) or the battery charge ran low and the CCD cut out. The CCDs and EOTM then respectively entered the shut-down mode or cut out. When a CCD shut down or cut out, it released its ECPB application and relinquished control of brake cylinder pressure to the conventional pneumatic braking system of the ore cars. If the brake pipe was charged and a pneumatic application was not in effect, the brake cylinder pressure released.

BHP was not able to advise on the average battery life of a CCD or EOTM battery, but it was understood to be substantially longer than 60 minutes.

The BHP locomotive fleet was equipped to enable control of multiple distributed power units within the train. Communication of synchronous control and indication signals between the HEU, trailing and remote locomotives also occurred via the trainline system.

As a contingency, the ECPB overlay system and trainline could be shut down and the HEU configured to communicate power and brake commands via UHF radio communications to the remote locomotives. This configuration disabled ECPB, and train braking reverted to conventional pneumatic operation via the train brake pipe. The HEU configuration also set up communication with the EOTM by radio.

The FIRE system displayed braking parameters related to the ECPB system mode, alarms, diagnostic messages, and brake command input (Figure 6). The system displayed the level of train brake command (TBC) input as a percentage, typically between 0% and 100% or as 120%. Various values meant:

  • 0% = release
  • 10% = minimum service
  • 100% = full service / penalty application
  • 120% = emergency.

Figure 6: Typical FIRE system display

Figure 6: Typical FIRE system display

Typical parameters displayed on FIRE system display monitor. Details shown were not those present on locomotive 4420 at the time of the M02712 runaway.

Source: BHP

Driver electronic brake control unit

The driver could manually control braking applications through the electronic brake control unit located on the driver’s console. The control unit included the automatic and independent brake handles. Each of these handles provided independent electrical signals to the EP-60 brake controller (Figure 7).

Figure 7: Drivers electronic brake control unit

Figure 7: Drivers electronic brake control unit

Position of the automatic brake handle equates to a 39% TBC brake application.

Source: BHP, annotated by the ATSB

The automatic brake handle had the following detent positions for driver control:

  • REL (release) – charged air brake and releases locomotive and train brakes
  • MS (minimum [service] reduction) – first detent in service zone to apply minimum braking
  • Service zone – between MS and FS applying graduated service braking effort
  • FS (full service) – position in service zone to apply full-service braking effort
  • SUP (suppression) – second detent position applying full-service braking effort and suppression to safety control applications
  • HO (handle off) – third detent position used when driving station is not active (handle is not removable) or 120% TBC when driving station is occupied and operating in ECPB mode
  • EMER (emergency) – fourth detent position, brake pipe pressure reduced to 0 kPa at a rapid rate and when configured to ECPB mode applied 120% TBC.

In addition to the driver controlling braking to the train (locomotives and ore cars) via operating the automatic train brake handle, the driver could control braking to the locomotives via operating the independent brake handle. The independent brake handle was directly below the automatic brake handle and controlled the HEU locomotive’s braking independently of the automatic train brake (Figure 7). It also applied the brakes on other locomotives in the train (lead and trail) but it did not apply brakes on the ore cars or remote locomotives. The independent brake control applied brakes pneumatically, irrespective of the HEU configuration.

The independent brake control handle could be positioned to:

  • REL (release) – released the locomotive brakes, if the automatic brake handle was also in the REL position
  • SERVICE – moving the handle through the service zone increased locomotive braking effort
  • FULL – applied full braking effort on the locomotive(s)
  • bail off function – depressing the handle in either the REL position or SERVICE zone suppressed any automatic train brake application in progress on the locomotive(s).

Figure 7 shows the position of the brake handles at the time of the runaway and derailment. The driver positioned the automatic brake handle in the service zone to the position equating to a 39% ECPB TBC at 0337, prior to the loss of trainline communications at 0338. The independent brake handle was moved to the FULL position at 0353.

ECPB codes of practice and standards

The Rail Industry Safety and Standards Board (RISSB) Code of Practice for ECP braking (released in 2017) described the configuration and operation of trains fitted with ECPB for use in the Australian rail industry. The practices described in the code were recommendations to the rail industry but excluded captive unit train operations[15]or situations where rolling stock operators, vehicles or locomotives did not interchange across functional boundaries.

The code referred to content from the suite of documents published by the Association of American Railroads (AAR) under Section E-II - Manual of Standards and Recommended Practices - Electronically Controlled Brake Systems. The AAR adopted the S-4200 standard in 1999 with later revisions in 2002, 2004, 2008 and 2014. The standard defined the requirements to ensure the functionality, performance and interoperability for an approved freight train power brake using ECPB systems.

The standard specified the normal operation functions of an ECPB system (including an overlay system) and addressed the effect of the CCDs or EOTM entering the shut-down mode following loss of trainline power. Section 4.3.17 stated:

Shutdown mode (or “battery conservation” mode) shuts off the CCD or EOT to minimize battery drain. When shut down, the CCD or EOT is turned off. When a CCD shuts down, it releases its ECP brake application and relinquishes control of brake cylinder pressure to the pneumatic backup. If the brake pipe is charged and a pneumatic application is not in effect, brake cylinder pressure will release; otherwise it will remain at the level commanded by the pneumatic backup. When an EOT shuts down, it stops transmitting EOT beacons.

Once train line power is lost, the CCD or EOT either continues to operate off of battery power until its battery runs low or enters into a timed shutdown mode. The intent of this logic is to allow the train to operate as long as possible after a loss of train line power and to conserve batteries if the device is disconnected from the train line, the train is parked, or the ECP brake system is CUTOUT.

The CCD or EOT shall shutdown 1 hour after both train line power is lost and no HEU beacon has been received. The CCD or EOT shall shut down after the train line power is lost and the train operating mode is set to CUTOUT.

The standard detailed conditions that triggered the designed shut-down mode of operation. Although the functionality supplied flexibility in operation and protected battery condition under certain circumstances, such as shunting operations utilising switch mode,[16] the conditions also existed following an interruption to the trainline during main line operations.

The standard stated that the CCD on each ore car downstream from a trainline interruption would release the ECP brake application and relinquish control to the pneumatic backup system 60 minutes after a loss of trainline continuity. If the CCDs were shut down with the brake pipe air pressure charged, the brake cylinder pressure on the affected ore cars would release and the braking effort would be lost.

In summary, the operation of the ECPB system outlined in the S–4200 standard included a 60-minute shut-down feature of the CCDs in certain conditions, which introduced a potential risk exposure for a runaway event that needed to be managed. The ECPB system on BHP’s trains was designed consistent with the standard.

ECPB emergency brake conditions

In the ECPB mode of operation, the initiation of an emergency braking application could occur:

  • automatically in response to various system-detected conditions
  • manually by the driver moving the automatic brake handle to the ‘handle-out’ or pneumatic ‘emergency’ positions.

If the system detected an emergency brake condition, such as a critical loss of trainline communications, the EP-60 manual described the system response as:

Emergency (120%) brake command, an emergency brake (120%) brake interlock, locomotive power knock-down (PCS) and corresponding crew message(s). The 120% emergency brake interlock will remain in effect for a minimum of 2 minutes since the emergency condition occurred. The interlock can then be reset once the condition that caused the emergency has been corrected.

If a driver triggered the emergency application by moving the automatic brake handle to the pneumatic ‘emergency’ position, the EP-60 manual described the functionality:

In this position brake pipe is vented to zero and a 120% TBC train brake command is provided.

If the driver moved the automatic brake handle to the ‘handle-out’ position, the braking response would be the same as for the system-initiated emergency (120%) brake command. As stated in the EP-60 manual:

If the automatic handle is moved to the “handle-out/continuous service” position, the brake pipe will continue to charge but a 120% TBC train brake command is provided.

In ECPB mode, for a system-initiated emergency brake application or when a driver moved the automatic brake handle to the ‘handle-out’ position, the 120% TBC brake interlock feature maintained a full air brake application to the train, but the brake pipe air pressure remained fully charged at 600 kPa. For a driver-initiated emergency application where the driver moved the automatic brake handle to the pneumatic emergency position, both the 120% TBC brake interlock and the discharged brake pipe maintained a full air brake application on the train.

Emergency brake application on train M02712

In the case of M02712 approaching Garden on 5 November 2018, the driver had positioned the automatic brake handle for a 39% train brake call to the EP-60 brake controller, prior to the emergency (Figure 7).

About 30 seconds later, at 0338, the interruption in trainline continuity caused several critical alarm conditions in the HEU locomotive’s onboard systems. The loss of trainline communications between the EOTM and HEU beacon triggered a system-initiated emergency application of 120% TBC to lead locomotives and operative CCDs that remained in communication with the HEU (Figure 8).

Figure 8: Event logger extract from locomotives 4420 and 4472, locomotive 4420 (HEU) brake control applications

Figure 8: Event logger extract from locomotives 4420 and 4472, locomotive 4420 (HEU) brake control applications

Source ATSB

The CCDs, remote locomotives and EOTM beacon that could not detect the HEU beacon via the trainline cable subsequently broadcasted an exception message, which was received by the other devices along that portion of the trainline. As each device received more than one exception message within 5 seconds, all operative CCDs and remote locomotives self-initiated an emergency ECPB brake application to stop that part of the train. As this was a system-initiated application and only the trainline communication was interrupted, the brake pipe remained intact and fully charged (Figure 9).

Figure 9: Event logger extract from locomotives 4420 and 4472, locomotive 4472 (remote) and ore car CCD brake application

Figure 9: Event logger extract from locomotives 4420 and 4472, locomotive 4472 (remote) and ore car CCD brake application

Source ATSB

Following the triggering of the 120% TBC application, the brake interlock feature held the brake application on the lead locomotives and CCDs in communication with the HEU. The interlock remained active, maintaining this brake application, as the driver had not reset the ECPB emergency condition.

The self-initiated emergency applications on the remote locomotives and associated ore car CCDs maintained brake application on the respective vehicles. Communication with the HEU was interrupted, so power and control commands (reset) were not available. Consequently, the CCDs relied on sufficient battery charge, and the 60-minute shut-down feature, to keep the brakes applied.

As indicated in Figure 8, the independent brake was fully applied at 0353.

For train M02712 the operative CCDs, remote locomotives and EOTM that were not in contact with the HEU beacon shut down about 60 minutes after the loss of power supplied by the trainline cable (that is, at about 0438). As the brake pipe remained charged, the air brakes released on these ore cars and the remote locomotives. The release of these air brakes and the incomplete application of handbrakes on train M02712 resulted in the train commencing to roll away at about 0440 (Figure 10).

Figure 10: Event logger extract locomotives 4420 and 4472, locomotive 4472 (remote) and ore car CCD brake release

Figure 10: Event logger extract locomotives 4420 and 4472, locomotive 4472 (remote) and ore car CCD brake release

Automatic train protection system

The 4 locomotives on train M02712 were each equipped with an Alstom Ultra-Cab II (UCII) microprocessor-controlled automatic train protection (ATP) system. The UCII system was not a standalone system; it interfaced electronically with other onboard equipment including the FIRE system, ECPB system, wayside transponders and other control systems that combined to provide for the safe operation of the train within the parameters defined in BHP’s rules and procedures.

The ATP functions included checking the locomotive speed and supervising its operation within the limits imposed for the track section. If the locomotive exceeded the target speed limit, alarms would sound to prompt the driver to reduce speed.

The locomotives carried a radio transmitter, transponder reader and antenna. The equipment relayed transmissions between the locomotive and transponders fastened to the track crossties (sleepers) at key locations, such as ATP entry and exit points and interlocked wayside signals along the railway. Track-mounted transponders relayed unique location identification and target speed data to the locomotive UCII microprocessor.

The driver had to reduce speed to the target limit within a predetermined time. If this did not occur, the ATP system automatically communicated with the braking system to request a brake application to stop the train. The type of brake application depended on the setup of the locomotive at the time of the command:

  • If the locomotive was configured for conventional pneumatic braking, the ATP triggered a service braking application. If this was ineffective in slowing the train, the ATP then triggered a penalty braking application.
  • If the locomotive was configured for ECPB, the ATP requested a penalty braking application only.

Additionally, when the locomotive was stationary with its reverser in the neutral (centre) position and the ATP detected a train movement of more than 0.5 m, the ATP requested a penalty braking application to prevent a potential locomotive runaway.

Each locomotive’s ATP system automatically configured to mirror the ECPB brake setup for that locomotive, either as a HEU, trail unit or remote unit. The ATP would not enforce target speed limits or runaway protection on locomotives configured as either a trail or remote unit.

The way the brake controller actioned the ATP’s request for a braking differed depending on whether the train was configured for conventional pneumatic mode or ECPB mode:

  • In conventional pneumatic mode, braking signals from the HEU brake controller were propagated to the remote locomotives and ore car pneumatic valves via a reduction in brake pipe pressure. A penalty brake request by the ATP system caused the brake controller to vent the brake pipe pressure to apply and hold the brake application on the locomotives and ore cars, until actioned by the driver.
  • In ECPB mode, braking signals from the HEU brake controller propagated to the remote locomotives and ore cars electrically via the trainline. The brake pipe remained charged with air. A penalty brake request by the ATP system caused the HEU brake controller to apply the brakes on the lead locomotives. The controller also transmitted an electric signal via the trainline to the remote locomotives and CCDs in each ore car to apply the brakes. An interlock feature in the brake controller then maintained the brake application until actioned by the driver.

In other words, the ATP did not directly integrate with the pneumatic braking system and could not operate a valve to dump brake pipe pressure. Accordingly, if a train was being operated in ECPB mode and there was an ECPB emergency/penalty braking application, and the train then commenced rolling away, subsequent penalty requests by the ATP system would be ineffective when the brake pipe remained charged.

BHP advised the ATSB that implementation of the ATP system in this configuration was historical and done to manage other operational issues such as derailment and ATP override.

The ATP in each of the 4 locomotives in train M02712 functioned respectively as a HEU (4420), trail unit (4434) and 2 remote units (4472 and 4440). When train M02712 started to roll away, and when later passing signals set to red or attaining an overspeed condition, the ATP system in the HEU triggered a penalty command (100% TBC) to the brake controller. In each instance, the ATP system penalty commands to the ECPB system were ineffective in stopping the train.

The brakes on the lead locomotives and the ore cars in communication with the HEU had already applied in response to the first 120% TBC (due to loss of trainline communications) and remained applied due to the brake interlock feature. Later ATP system calls to the EP-60 brake controller and responding ore cars had no material effect in mitigating the runaway of train M02712.

Vigilance control

The train’s vigilance control system checked for driver activity and automatically stopped the locomotive/train when there was no driver-initiated control input or response from the driver to aural and visual warnings displayed via the FIRE system. The vigilance system used random timing and task linking to check for driver activity.

The vigilance system was active when the locomotive air brake was set as the HEU and the locomotive air brake cylinder pressure was less than a predetermined level (independent brake released). The vigilance system was suppressed when any of the following occurred:

  • the locomotive air brake cylinder pressure was greater than a predetermined level (independent brake applied)
  • the locomotive’s braking system was set to trail or remote
  • the reverser was in the neutral (centre) position
  • the locomotive configuration was set for operation at a defined slow speed.

Prior to exiting the locomotive cab to apply handbrakes, the driver of M02712 applied the independent brake fully (increasing the air brake cylinder pressure above the predetermined level) and placed the reverser in the neutral (centre) position. These actions formed part of the ‘three-step process’ that the driver was to action when securing a locomotive (see Rules and procedures for securing trains before conducting work). The implementation of these actions had the effect of supressing the vigilance system, so the system had no effect during the runaway.

Risk management

Risk assessments for material risks

BHP’s Rail Safety Management Plan stated that the risk profile of BHP’s rail operations was determined by its risk management procedures. Different procedures were used for ‘material’ and ‘non-material’ risks. Material risks typically related to fatal accidents and significant operational or catastrophic events. Non-material risks related to task-based hazards and events with less severe consequences, and such risks were typically managed through BHP’s health, safety and environment (HSE) risk management processes.

BHP’s Risk Management Procedure provided guidance to the managers (risk owners) responsible for managing material risks in their area of responsibility. It outlined a series of phases, which included establishing the context, risk assessment (including risk identification, analysis and evaluation), risk treatment, and monitoring and review.

The procedure stated:

A formal risk assessment is a team-based, risk assessment process which provides an efficient and effective method of risk identification, risk analysis, assigning controls and developing risk remediation plans...

It involved relevant subject matter experts and the potential control owners identifying and agreeing on (material) risk events, and then:

For each risk event, identify potential causes and impacts. When assessing risk, normal operating conditions, abnormal operating conditions, start-up and shutdown activities and potential emergency situations shall be considered…

Based on the causes and consequences, the team must identify credible controls that will prevent, detect or mitigate the risk event and associated causes and consequences. The controls identified must be based on the hierarchy of controls[17]… The controls will be either preventive or mitigating controls.

A bowtie was used as the data capture tool for material risk controls. The procedure stated that:

…A bowtie is developed in a workshop with the relevant subject matter experts, risk owner and potential control owners.

Once the risk event, causes and impacts have been agreed, the critical controls are identified. A critical control is a control that significantly reduces the likelihood and / or impact of a material risk. The number of risk controls must be appropriate to the risk event and must play a key role in achieving the business objective…

A material risk required a control design assessment (CDA) occur to ensure the critical control were suitable following their creation and when changed. The assessment test varied dependent on whether the critical control was a procedural (administrative) or an engineering solution. Additionally, critical controls underwent a unique control effectiveness test (CET) to give assurance that each control was in place and effective in managing the material risk to an acceptable level.

In other words, the identification of a material risk event supplied a method for focusing management oversight on the critical controls preventing or mitigating the risk from such events.

Rail-mounted equipment interaction incident

BHP had identified a material risk event titled ‘Rail Mounted Equipment (RME)[18]Interaction Incident’, which referred to events involving an uncontrolled interaction between RME and people and RME and RME. The risk assessment was initially developed circa 2013, with numerous changes made in July 2016.

A range of scenarios were included, which considered the likelihood and consequence of interactions between RME/RME, RME/road vehicles and RME/track worker(s) resulting in the potential for single or multiple fatalities. The maximum foreseeable loss scenario involved a hi-rail vehicle (not covered by ATP) striking maintenance workers. Other worst plausible scenarios included shunting activities, driver walking around the locomotive at night, track workers working on an adjacent line, workers within the 3 m zone.  

The bowtie identified the following 12 ‘causes’ that could lead to such an event:

  • at risk behaviour of personnel, working outside rules/procedures/instructions
  • failure of or poor communications, radio protocols not followed or equipment failure
  • ATP system failure or overridden
  • ineffective track protection applied
  • limit of authority terminals / operator error for road-rail vehicles or track machines
  • uncontrolled or uncommanded movement of RME (workshops and main line)
  • exceed limit of authority (or no authority)
  • non-compliant track design
  • signal system ineffective
  • ineffective train control management
  • operator ignores derailer at active car dumper or train load out
  • derailment resulting in fouling of adjacent line.

The uncontrolled or uncommanded cause included the following types or examples:

  • brake isolation / failure
  • failure of tower control in non-safe state (J-Hub facility)
  • malicious damage (vandalism)
  • failure to secure vehicle against movement (braking and chocks).

It is not clear if the ‘failure to secure vehicle against movement (braking and chocks)’ related only to RME/trackworker(s) situations where maintenance personnel required access to work on rolling stock, or it was also intended to include securing a train against a runaway event on the main line involving a service train.

A matrix within the bowtie then linked each of the 12 causes to one or more preventative critical risk controls. The following 7 critical preventative risk controls were identified for an RME interaction incident caused by the uncontrolled or uncommanded RME movement:

  • radio communication - the protocols to enable clear verbal communication between train control and/or workgroups to confirm and acknowledge authorities to proceed with the related activity
  • rolling stock (excluding ore cars) maintenance - the asset management plans for RME to prevent derailment from equipment failure
  • signalling systems - the systems and procedures to positively locate and provide safe separation between RME
  • isolation protection - the procedures for the isolation and protection of RME against unintended movement (hand brakes and roll away protection)
  • trained and competent - requirement for the engineering and operational personnel to have the correct competencies for the rail-related tasks being carried out
  • three-step protection - the rules and procedures applicable to all personnel entering the profile of an RME to protect against the unauthorised movement of rolling stock
  • interface coordination - the agreements to clearly delineate the responsibilities of each party or functional area to facilitate the interaction between those parties and rail operations at each interface point.

The mitigating (or recovery) control listed for this cause was ‘corporate affairs and legal support’.

The preventative controls that were identified within the bowtie for other causes also included the ATP system. The documented aim of the ATP system control was to ensure trains did not exceed permitted speeds and/or levels of authority (that is, passing a signal at stop). The ATP system was stated as meeting the objective through monitoring target speeds and location information to provide warning to the driver if they were likely to exceed a defined speed profile or a braking curve profile for a limit of authority. The control specified that the ATP system would apply the brakes (penalty) if the driver did not respond to the warnings.

The matrix within the bowtie linked ATP as a preventative control measure to the causes on:

-    ATP system failure or overridden - poor maintenance of onboard or way side system

-    Limit of authority (LOA) terminals - failure or operator error for road rails vehicles/or trackside machines; GPS failure in non ATP RME (equipped with back box) or not displaying correct location

-    Non-compliant track design - construction, renewals and/or maintenance, RME operating outside of safe envelope (out of gauge), incorrect placement of Insulated rail joints (or misalignment to ATP map), parking of RME beyond fouling points, out of gauge vehicle

The bowtie risk assessment did not link ATP as a preventative control against the uncontrolled or uncommanded movement of RME and it did not link ATP as a mitigating control for any of the causes of an RME interaction incident.

Evaluation of critical controls

Each critical control listed in a bow tie linked to various design and operating standards, together with the criteria used to verify the control’s overall effectiveness. The design and operating standards for the controls relevant to securing a vehicle (train) against an uncontrolled or uncommanded movement linked to the content of relevant modules within the rail rule book, procedures, worker competency programs, asset management plans, interface coordination plans and emergency response plans. Their effective implementation was dependent on the qualified workers undertaking the related task described within the documents.

The scope and design standards for each critical control primarily addressed material risk associated with personnel accessing the profile of rolling stock to undertake maintenance or recovery tasks. Apart from a reference to drivers keeping an awareness of current operating instructions, the critical controls contained no reference to the risk of a significant or catastrophic event arising from an RME main line runaway, such as M02712. 

The methods used in a critical control verification (CCV) included the scheduled inspection of records, auditing and observation of behaviours targeting representative samples of the workforce. Results from the CCVs and review of the CDA additionally fed into a test plan used to review periodically the significance of key changes to associated procedures, standards and permits or those triggered by significant events or audit findings since the last CDA and CET if applicable.

The outcome from the review processes (CCV, CDA and CET) formed the material risk control assessment (MRCA), where a rating was assigned to the material risk event’s critical controls of either ‘well controlled’, ‘requires some improvement’, ‘requires significant improvement’ or uncontrolled’.

The MRCA of the RME interaction incident risk event undertaken in September 2017 found that, although the majority of critical controls were ‘acceptable’, the risk of an RME interaction with people rated overall as ‘requires some improvement’. The bowtie version date recorded another review and update occurred on the 14 February 2018. Records of tracked changes for the MRCA’s indicated changes occurred in the bowtie on 16 November 2017 and 8 January 2018 respectively to the preventative controls trained and competent and rolling stock [excluding ore cars] maintenance. There was no record of the changes to the bowtie associated with the update conducted on the 14 February 2018.

CCD shutdown event in March 2017

On 27 March 2017, the driver of a loaded ore train reported an ECPB 120% penalty brake application that occurred at Garden (205 km). The driver reported the condition of ‘EOT off’, ‘power off’ and ‘communication loss’ to remote locomotives. The driver also reported placing the automatic brake handle in the full ECPB service position before disembarking to apply handbrakes to the train. The brake pipe remained charged at 600 kPa.

On returning to the locomotive cab, the driver reported noticing a ‘?’ symbol displayed for the remote locomotives on the FIRE screen. After consulting with the maintenance centre staff about the symbol, the driver reverted the configuration of the train from ECPB to pneumatic operation and then continued the journey to Port Hedland without further incident.

On the 28 March 2017, BHP maintenance centre staff conducted tests to repeat the conditions of the reported event while watching the ECPB system response. The testing found that, after a disconnection of the trainline cable interrupting power to the CCDs and EOTM, the ECPB application released when the CCD batteries started to fail. They also noted that they now required drivers to ‘dump their trains’ (vent train brake pipe to atmosphere) in the case that there was a loss of trainline communications and there was no EOTM brake pipe reading. 

BHP’s enquiries with the ECPB vendor (NYAB) later that day confirmed that, after a break in the trainline cable, the trainline power would shut down for the entire train. In addition, the vendor advised:

  • Ore car CCDs to the rear of the point of break, with brake pipe charged and no HEU beacon detected, would cut out and shut down after 60 minutes.
  • Ore car CCDs in front of the point of break, with brake pipe charged and HEU beacon detected, would maintain ECPB brake application until the internal battery charge depleted. The CCDs would then release the brake application, regardless of the detection of the HEU beacon.

The vendor agreed with BHP staff that the above conditions meant that dumping the brake pipe pressure through a driver-initiated application of the automatic brake handle to the pneumatic emergency position, together with applying handbrakes (the number dependent on track grade), was necessary to avoid the possibility of a train roll away.

The operating instruction containing procedures for responding brake pipe emergencies was amended on 5 April 2017 (see Operating instruction 17-11). No addition was made to the RME interaction incident risk assessment to include a brake pipe emergency as a cause of an uncommanded train movement, and the procedure for responding to a brake pipe emergency was not included as a critical control. In addition, the effectiveness of the control was not examined by an MRCA or related processes.

Management of change

BHP management of change process

BHP’s Rail Safety Management Plan stated:

BHPIO Rail employs a management of change process which deals with permanent, temporary or incremental changes, to organisation, plant, equipment, materials, standards or procedures, and changes associated with laws and regulations in relation to BHPIO rail activities.

The process is used to manage the changes which may have a health and safety impact to identify and control potential risks associated with the change. Activities requiring change management are identified via the BHPIO Management of Change procedure where actions are assigned to the relevant departments and managed in 1SAP.[19]

BHP’s Management of Change Procedure stated the overall purpose of the procedure was:

… define the process for managing risk associated with change by ensuring the appropriate process steps are followed and recorded.

Change could be an engineering or non-engineering change. This includes alterations to plant, infrastructure, equipment, products, materials, process systems, management systems, standards, procedures, removal or introduction of people or a change to the environment.

The scope of the procedure included changes of either a permanent, temporary, or emergency nature, or where the untreated risk score exceeded a defined value.

The 5 steps forming the management of change process comprised of:

  • initiate / design - document the reason / basis for the change, engage stakeholders and prepare the proposed change with sufficient detail for the formal review process (including identify subject matter experts, conduct a risk assessment, identify impacted areas and associated actions to manage the risk)
  • review - assess and accept risks and controls associated with the proposed change
  • approve - approve risk assessments, check the right people and reviewers have been engaged and accept accountability for the change
  • implement - confirm / validate the controls to manage risk are in place
  • closeout - verify changes implemented.

BHP’s introduction of the ECPB system to main line operations

On the 3 June 2011, BHP Iron Ore started a management of change process for the introduction of the ECPB system to main line operations, including the Yarrie line.[20] The change was part of a broader project to increase rail capacity.

The management of change assessment presented a series of questions guiding the change originator through the process steps and various topics for consideration. Fields enabled the recording of relevant responses, comments, supporting documentation and details of the risk ranking before and after the change. The risk assessment linked to the HSE risk management procedure used to assess non-material risk related to task-based hazards and events. The assessment had no entry detailing the risk scenarios assessed or their resultant ranking.

The assessment listed supporting documentation that recorded processes undertaken by BHP when introducing ECPB. The documentation included risk assessments, change plans and communication plans. BHP was unable to retrieve and supply any of the listed documents for review by the ATSB.

In April 2012, BHP engaged an external provider to undertake a study[21]verifying the benefits of converting the existing fleet of conventional pneumatically-braked rolling stock to ECPB operation, and the potential for increasing train length. The study utilised instrumented ore cars in rakes with both ECPB and standard pneumatic brake capability and compared the braking performance of each configuration with an emphasis on coupler forces and stopping distances. The study identified key observations related to in train forces, stopping distances and section running times, concluding that although some problems and delays associated with brake equipment failure occurred during the study, the actual performance of the ECP brakes was assessed as very good.

In December 2013, BHP completed a report on the selection phase, which built on the previous work that investigated avenues to increase rail capacity through initiatives such as operating longer and heavier trains. The report identified that the BHP fleet now operated a mixture of ECPB capable and non-ECPB capable locomotives and ore cars. The report quantified the scope of rolling stock that needed to be converted together with a project proposal for the conversion of the ore-cars and locomotives as part of the ECPB project, in order to complete the transition and commence ECPB operation across the fleet.

The report noted that operational trials conducted in 2013 placed greater emphasis on quantifying the benefits of ECPB in terms of cost savings, mitigation of production losses and sectional cycle time improvements. The report then detailed further work required, which included:

  • retrofit all non-ECPB ore cars and locomotives with ECPB
  • train and certify all locomotive drivers in ECPB
  • ATP analysis and updates, focusing on amended braking distances for ECPB-equipped trains.
  • signalling updates (if required) based on revised braking curve analysis.

At that stage it was intended to complete the training of drivers and commissioning of the ore cars and locomotives by mid 2015.

In May 2014, BHP completed a report on the definition phase of the project. The scope included the retro fitment and/or commissioning of ECPB to all mainline rolling stock with the following specific objectives:

  • retrofit ECPB equipment to locomotives and ore cars
  • train locomotive drivers in the operation of ECPB rolling stock
  • train rail workshop and yard maintenance personnel in the repair, replacement and troubleshooting of ECPB and ECPB related systems
  • commission existing ECPB locomotives and ore cars
  • update network ATP maps to ensure safe operating conditions in operating 40 t axle loads
  • upgrade relevant train-load outs to high accuracy track scales to reduce loading variability to prevent exceedance of bridge overloading parameters at 40 t axle loads.

The report included detailed explanation of the planning and processes implemented to modify the rolling stock for installation of the ECPB equipment and the arrangements to ensure the reliability and integrity of the ECPB system within the BHP rail network.

To facilitate the latter, BHP proposed the ECPB operations team design a validation program in consultation with the rail operations group considering:

  • identification of potential issues (including starting testing and validation activities in the definition phase rather than wait until the commissioning period)
  • industry knowledge and learnings from other sources who were using ECPB
  • operational engagement.

The validation scope also documented the testing of a range of functions, including:

  • emergency and penalty recovery – testing procedures using the ECPB interlock feature to recover trains (as existing recovery procedures only related to conventional pneumatic braked trains)
  • securing of trains – following the failure of either the pneumatic or ECPB systems, securing trains by the application of handbrakes (with procedures to be reviewed in conjunction with the ECPB interlock functionality trials)
  • ECPB interlock – using the interlock to secure the train instead of applying handbrakes
  • handbrake tables – undertaking static and dynamic handbrake trials to demonstrate the potential of reducing the amount and times that handbrakes needed to be applied and updating the handbrake chart accordingly.

With respect to the identification of potential issues, the definition phase report noted that twice during the main line trials, it was observed that a percentage of operable brakes in a train decreased for no apparent reason. This observation was reported to the supplier, and it was concluded that the low percent of operable CCDs was due to the large number of ore cars with low batteries. The events related to situations where the driver turned off the trainline power, but left the ECPB active, forcing the CCDs to run on battery power to maintain the ECP brake application. It was observed that after around 11 hours, the CCDs gradually started to cut out due to low battery. The system was left in this state for about 23 hours before the operator turned the trainline power back on. This left all CCDs in the train with depleted batteries.

The conditions present in the train for the above 2 events differed from those observed in the March 2017 event (that is, the CCDs maintained communication with the HEU). However, these events demonstrated that, in the absence of trainline power, the CCDs battery charge could be depleted to a level where the CCD would cut out and either not apply or maintain an ECP brake application.  As a result of these events during trials, BHP required that, for main line operations, the number of operable brakes in an ECPB-configured train must be above 93%. If this level could not be achieved, the driver was to revert the train to conventional pneumatic braking, after informing train control.

The report summarised other actions undertaken by BHP, including risk assessments for the transition to 40 t axle loads and the ECPB conversion process for the introduction of longer and heavier trains, and an FMEA for the transition to 40 t axle loads. BHP was unable to retrieve and supply these documents for review by the ATSB.

Overall, the definition phase report noted that the project was expected to be completed in the third quarter of 2015.

Systems engineering processes

Risk management and management of change are closely-related functions and processes within a safety management system, and they both interact with many other organisational processes. When developing and implementing a new physical system or product, there are also a range of engineering processes that can be applied.

Systems engineering is a way to manage complexity in the development of a product or engineered system. It is a concept that began to form in the 1940s and was later given impetus by the United States National Aeronautics and Space Administration as well as the United States military as a way to manage system complexity through control of the development process (Leveson, 2016). The process can be applied to the development of any product.

As noted by Kusumo (2019):

Given the increasing complexity of railway systems, the integration of a system with new or legacy systems may cause unintended behaviour of any of the systems, as well as the whole integrated system. As such, the traditional approach to delivering major rail projects where each railway system is designed, implemented and tested in isolation of other interconnected systems is no longer sufficient to ensure that the rail network can be operated safely.

A systems approach to implementing change in the railways, especially in integrating multiple new or legacy rail systems is required to ensure that the railway’s operations remain safe, so far as is reasonably practicable. This approach needs to cover the system life cycle: including requirements analysis, system design, system implementation, testing and commissioning, service operation and maintenance, as well as decommissioning.

The V-model is commonly used to describe the systems engineering process (for example, see Figure 11). In this model, the product’s user defines a concept of operations or broad set of requirements that describe what the product should do. This description is broken down into a progression of increasingly detailed sets of sub-requirements. The higher-level requirements describe all aspects of what a product should do and how well it should do them, and the lower-level requirements describe the product’s architecture and other detailed elements of design. The requirements drive the design; that is, design elements are chosen based on the best way to meet the requirements. The designers also need to devise ways to prove that the requirements have been met, which forces them to make the requirements verifiable. Safety can be, and often is, among the design objectives.

Figure 11: Systems engineering lifecycle V-model

Figure 11: Systems engineering lifecycle V-model

Source: Systems Safety Assurance Guideline – RISSB, 18 September 2018

Once a design is finalised, the design and product passes through increasingly broader sets of verification and validation activities (such as testing) to show that the design does meet the requirements. Verification is the process of showing the final product meets the requirements (that is, the product was built correctly). Validation is the process of showing that the requirements met the user’s needs (that is, the right product was built). If the requirements definition and design process are conducted well, there should be few or no ‘unpleasant surprises’ throughout the verification and validation process.

System integration refers to the progressive assembling of subsystems so that the broader system, as an integrated whole, is able to deliver the overarching functionality. A key component of system integration is defining system interfaces and assessing identified hazards associated with those interfaces. More specifically, as stated by Kusumu (2019):

To ensure safe integration, the SRS [system requirements specification] for a system needs to consider the interface requirements between it and any subsystems and between it and any existing or legacy systems. In addition, these interface requirements for the new system need to include any Safety Related Application Conditions (SRACs) on the existing railway systems that will impact the new system…

A system approach to designing railway systems that will ensure safe system integration involves a systematic analysis of the following:

  • Interface compatibility between connected railways systems (data, power and signal, etc.);
  • Risks associated with failures of interface between interconnected systems;
  • Risks of system failure which may compromise the overall safety of the railway operations;
  • Compliance with …SRACs from any existing or legacy systems; and
  • Verification that the identified risk controls have been incorporated in the system design.

Hazard identification and risk analysis is an ongoing and iterative process that is relevant to multiple phases of the lifecycle model. A range of safety assessment techniques can be used to identify problems with the product design, such as interface hazard analysis, functional hazard assessment, fault tree analysis and failure mode effects analysis (FMEA).

A wide variety of standards and guidance documents on systems engineering processes have been published in recent decades, both generic and tailored for specific industries. In 2013, system safety guidance material specific to the rail industry was collated into an International Engineering Safety Management Handbook,[22] which was aimed at ‘clearly outlining the activities involved in making a system or product safe and providing the evidence that it is safe.’ The extent to which this and other guidance reached the Australian rail industry is unclear. A paper published in February 2021 concluded that the Australian transport sector lacked national direction in the application of systems engineering compared to the defence sector or that provided in other countries (Welschen and others 2021). Nevertheless, the application of systems engineering principles has gradually increased through ONRSR safety messaging and publication of guidance material by RISSB.

BHP application of system engineering processes

BHP’s internal investigation into the runaway and derailment of M02712 included a range of internal rail operations and engineering specialists. The investigation report defined a ‘systems engineering framework’ as:

A structured engineering process which applies, in alignment with ISO 15288,[23] a systems engineering approach to the management of risks associated with the introduction of changes to complex systems over their life cycle.

The report concluded that BHP’s WAIO rail network did not have a systems engineering framework in place for the introduction of ECPB into its existing braking systems. It also noted that:

  • there was no formal system assurance process in place to identify and address safety-related matters that were an outcome of system integration activities.
  • when ECPB was introduced and modifications were made to the existing ATP system, they were largely managed on an individual system level, rather than giving full consideration to the aggregate function required to be performed by the braking system as a whole
  • there was insufficient focus on system integration in the risk assessment phase of the ECPB project, particularly on critical controls that were reliant on system integration for safety functions (such as the ability of ATP to effectively intervene).

In 2013, the vendor modifying the ATP system software to facilitate yard auto mode of a loaded consist, controlled by the dumper automated spotting of locomotives (DASL) system, identified 13 safety-related application conditions (SRACs).[24]The vendor communicated to BHP that the conditions listed were outside the scope of work and therefore required BHP to evaluate and mitigate the conditions to a risk level acceptable to BHP. The SRACs included several system conditions that, if present, could result in an unintended train movement that could result in derailment, collision, or runaway event.

Another vendor undertaking later modifications to the ATP software in 2015 and 2016 again raised the SRACs with BHP.

BHP provided no record to the ATSB of its review of the information provided by the vendors or its assessment of the identified risk associated with each SRAC, or of subsequent changes to procedures or systems to address the safety-related information provided by the vendors. There was no indication in the BHP risk assessment for an RME interaction incident risk event that information from the SRACs was included in consideration of reasons for (or controls for) an unintended train movement. In addition, BHP’s internal investigation into the runaway and derailment of M02712 found that        there was no formal system assurance process for addressing safety-related information provided by vendors (including SRACs).

Trial trainline inter-car connectors

A trainline interconnection between rail vehicles (that is, locomotives or ore cars) was via an inter-car cable assembly. The assemblies terminated at a junction box located at the end of each rail vehicle and were joined using a connector. BHP’s ore trains used polarised NYAB Freight Mate connectors (also known as Tri Star connectors) (Figure 12).

Figure 12: NYAB Freight Mate inter-car connector

Figure 12: NYAB Freight Mate inter-car connector

Image showing typical plug-type device connecting the trainline cable between ore cars.

Source: BHP, annotated by the ATSB

In mid-2018, BHP initiated a trial of a Wabtec type connector (Figure 13) to address repeated service delays associated with trains receiving a 120% TBC brake application due to a loss of trainline power and communications from continuity faults within the existing connector. Associated with the service delays, BHP also noted that, depending on the track location, the failure required the application of handbrakes to secure the train. Undertaking this task increased exposure of the train crew and support personnel to a potential injury.

BHP managed the trial through the implementation of its management of change (MoC) process and supplied advice of the change to the ONRSR through a notification of change to railway operations (associated with a ‘change to a safety critical element of existing rolling stock’). The proposed commencement date was 12 September 2018.

The risk assessment undertaken in conjunction with the MoC process primarily targeted the identification and management of work health and safety considerations that could arise during the initial installation or follow-up monitoring work on the connectors. In addition, one operational risk related to the failure of a Wabtec connector causing a communication loss through the trainline cable. The consequence assessed was a potential financial loss due to service disruptions of main line operations when responding to and recovering from the fault.

The trial involved installing 12 Wabtec inter-car connectors to a combination of 7 recently overhauled Brakden QRRS and Golyns type ore cars. Train M02712 was the only train fitted for the trial, with the 7 ore cars found from positions 2 to 8 inclusive in the first rake.

Rail operations personnel received an operations notice that the trial would begin on 1 November 2018. During the 3-month trial period, BHP planned to check the performance of the inter-car connector at 2-weekly intervals to find potential faults related to the performance of the connector. BHP stipulated criteria whereby any failures related to a loss of EOT communications resulting from the assembly failing, connector pulling apart or premature wear under normal operations would result in the immediate termination of the trial and reinstatement of the NYAB inter-car connectors.

The driver of M02712 recalled that the loss of trainline communications occurred as the train was passing over a level crossing. They also stated that, while applying handbrakes to the ore cars, they saw a detached or disconnected inter-car connector. The driver recalled the position was at about ore car 10 in the first rake and the connector did not appear damaged, just disconnected with both ends hanging down. The driver recounted that it was a larger new type of twist connector of a type that the driver was not familiar, rather than the rectangular type of connector with which they were familiar.

During the runaway occurrence involving M02712, dragging equipment detectors placed on the track next to signals GNN3, 202W and 199W recorded strikes from dragging equipment. It is likely the strikes were from the trailing ends of the disconnected inter-car connector.

BHP recovered only one of the 12 trial Wabtec type inter-car connectors from the wreckage of train M02712. The exact position where the break in trainline communications occurred or the location of the recovered connector in the trial ore cars was unknown. 

The management of change records confirm that on the 28 December 2018, BHP ceased the trial of the Wabtec connectors because of the runaway of train M02712 on 5 November 2018. BHP cited the reason as:

Trial was aborted due to an alleged cable striking a crossing and having an emergency brake application. When the cables were installed the car was empty however when loaded the cable may have been hanging low. Trial will have to be repeated with checks conducted to ensure cables on all types of ore cars are not hanging too low allowing them to make contact with infrastructure. 

Figure 13: Wabtec inter-car connector

Figure 13: Wabtec inter-car connector

Image showing the trial plug type device connecting the trainline cable between ore cars.

Source: BHP, annotated by the ATSB

Rules and procedures for brake pipe emergencies and penalties

Overview of manuals and instructions

The BHP Rail Rule Book included 16 modules outlining procedures related to rail operations. BHP sent a revised version of the rule book to the Western Australia Office for Rail Safety[25] (ORS) for endorsement on 15 April 2013. References to ECPB operations were not included at that time, as BHP did not anticipate introducing ECPB into service in the current hard-wired format prior to the release of the revised rule book.

Delays from the ORS in assessing the rule book resulted in the final endorsement not occurring until 22 August 2014. Following receipt of the ORS endorsement, BHP developed training and awareness packages, publishing the rule book ‘as endorsed’ in February 2015.

During the endorsement period, BHP also began arrangements to modify the ore train fleet from pneumatic braking to an ECPB overlay system. Although the recently published rules and procedures addressed conventional pneumatic operation only, BHP managed the changes to the operational rules for the implementation of ECPB through the issue of a series of operating instructions to rail workers.

The rule book Module 1: General rail rules and procedures, sections R1-1.2 and R1-1.3, defined the compliance responsibilities of all workers/persons in relation to the rules and procedures as:

R1-1.2 Application of rules

The compliance with the BHP Billiton Iron Ore Rail rules and procedures is mandatory for:

-    all workers engaged in the operation of the rail;

-    all workers working within the Danger Zone; and

-    all persons entering on to the rail premises other than any areas to which public have unrestricted access.

All persons to whom these rules and procedures apply are responsible for ensuring that they remain familiar with these rules and procedures, including any amendments issued.

R1-1.3 Operating Instructions, Notices and General Alerts

All persons to whom these rules and procedures apply shall familiarise themselves with all current applicable Operating Instructions, Operating Notices, Safety Notices and General Alerts upon commencing duty.

BHP confirmed these statements meant an issued operating instruction was effectively an update/amendment to the applicable rule. All persons associated with rail operations were then responsible for ensuring they remained familiar with the rules and procedures, including any amendments (operating instructions) issued.

Process for issuing and receiving operating instructions

BHP’s procedure 0119630 (Issuing and receiving operating instructions) stated:

Operating Instructions are a notification to rail personnel of relevant information about changes to safeworking procedures, work instructions and safeworking infrastructure changes which alter their work duties and responsibilities. They are not a means of facilitating operational or temporary change that would in the daily course of business be distributed by the issuing of memorandums from the various supervisors or line managers within BHP Iron Ore Rail.

The procedure stipulated that the following processes were applicable for issuing an operating instruction related to changes to safeworking procedures, work instructions or the rule book:

-    review session involving key stakeholders / representatives affected by proposed changes are to be held, minutes taken and documented attendance records completed;

-    a risk assessment by representatives of key stakeholders impacted by the change is to be conducted and incorporated as part of the Change Management Process;

-    Change Management Process is to be applied in line with BHP Iron Ore Change Management Procedure…;

-    Rail Operations Safeworking team is to be supplied with a signed copy of the Change Management and Risk Assessment; and

-    an information package for all complex changes to rail rules, work instructions and safe working procedures to be presented to relevant stakeholders prior to implementation.

BHP confirmed that, although a new rule implemented via an operating instruction should be subject to the processes detailed above, the adoption of the processes could vary when an operating instruction was re-issued following minor changes, such as rewording based on feedback from end users or when updated. This practice was accepted so long as the intent of the rule remained unchanged. When a change or amendment occurred to a rule contained in the rule book, the procedure also triggered the submission of a notification of change to the rail safety regulator.

An amendment to alter an operating instruction related to the rule book did not have an expiry date or period specified where it could remain in circulation before incorporation into the relevant module of the rule book. Instead, an amendment required the issue of a new operating instruction, which rescinded the original instruction. This was in contrast to instructions unrelated to the rule book, which required a review to occur before the end of a 6-month period to decide if the content was still applicable and required on an ongoing basis. If considered required, the operating instruction would transition into an amendment to the rule book or a work instruction document.

However, BHP confirmed there was a program underway to review published operating instructions and incorporate relevant changes into the associated modules in the rule book. The safety specialists undertaking the review prioritised their work by focusing on the modules that had the most operating instructions published. At the time of the runaway of M02712, safety specialists had reissued 11 modules of the rule book. The review of module 6, relevant to brake pipe emergencies and penalties, had not begun at that time.

There was no requirement or guidance in the procedure for issuing operating instructions to require that the reason for a change (or consequences of not following the amended procedure) be provided. In addition, there was no stated requirement for new or important information to be presented in any particular format (see also Formatting of rules and instructions). In contrast, the equivalent procedure for issuing operating notices required that when replacing an operating notice the content changes were to be ‘highlighted’.

BHP publicised changes to operating instructions through safe start rail briefings conducted for drivers each day. Operating instructions and other notices were also available on the BHP intranet for review by drivers.

Rule book procedures for responding to brake pipe emergencies and penalties

The rule book Module 6: Rail operations, section R6-3.0, supplied instructions to drivers responding to brake pipe emergencies and penalties[26]on trains with conventional pneumatic braking systems. It stated:

When an emergency brake application (dump) has occurred either initiated or uninitiated by the driver:

a) Duplicated lines [such as at Garden]

Driver

-    carry out emergency radio procedures;

-    check if adjacent track/s is fouled; and

-    where necessary, provide train protection.

b) Single line

-    advise the train controller.

For calculating the number of handbrakes to be applied to a train, the train controller shall utilise the Handbrake Calculator (electronic)…

Section P6-4.0 supplied added procedural instruction for drivers to follow dependent on the conditions present when an emergency pneumatic brake application occurred. More specifically, separate instructions were provided for:

  • emergency brake application when train moving initiated by the driver
  • emergency brake application when train moving not initiated by the driver
  • emergency brake application when at a stand (not moving)
  • penalty brake application on empty train travelling more than 5 km/h
  • penalty brake application on loaded train traversing specific locations
  • penalty brake application on loaded train traversing other locations.

For the condition where the driver did not initiate the emergency application on a moving train, the procedures stated:

Driver:

-    carry out emergency radio procedures (duplicated lines or where deemed necessary);

-    advise train control;

-    check if adjacent track/s is fouled;

-    where necessary, provide train protection;

-    employ train walk procedures during inspections;

-    secure all portions of the train by application of the independent brake and handbrakes (as per handbrake chart);

-    check for the cause of the air loss, or other indications;

-    maintain radio contact with the train controller during inspections...

The procedures did not refer to the application of the automatic brake. For trains with a conventional pneumatic braking system, an uninitiated emergency brake application (brake pipe dump), whether initiated by the ATP system or a break in the brake pipe continuity, reduced the brake pipe pressure to atmosphere level, subsequently applying full braking effort to the locomotives (unless bailed off) and the trailing ore cars. If the brake pipe remained discharged, air pressure in the auxiliary reservoir on each ore car kept the brake application on that ore car while the reservoir kept sufficient pressure.

In other words, for a train with a pneumatic braking system, with the brake pipe discharged, the driver did not need to place the automatic brake handle to the emergency position to keep an emergency brake application.

With the train held by the emergency brake application, the rule book procedure required drivers to secure all portions of the train by fully applying the locomotive independent brake and the handbrakes on the ore cars[27]in accordance with instructions from the train controller (or in accordance with the handbrake chart if the driver could not contact the train controller). For the Garden location, where the track grade was around -1.5%, a loaded train with locomotive independent brakes applied required the application of the handbrakes to 100% of the ore cars.

Although the procedures referred to the application of handbrakes to secure the train, they did not refer to the associated three-step protection process (see Rules and procedures for securing trains before conducting work).

Operating instructions related to ECPB brake pipe emergencies and penalties

To facilitate the trial and introduction into service of the ECPB overlay system, BHP issued a series of operating instructions to supplement or modify the requirements of module 6 of the rail rule book related to brake pipe emergencies and penalties (Table 2).

Table 2: List of operating instructions related to brake pipe emergencies and penalties

NumberTitle / purposeEffective date
OI 14-14Brake pipe dumps and penalties21 February 2014
OI 14-18Brake pipe dumps and penalties14 March 2014
OI 15-35Trial recovery process for ECPB trains after brake pipe dump or penalty29 July 2015
OI 15-41Brake applications – Mainline loaded trains3 September 2015
OI 15-42Reverting from ECPB to conventional pneumatic mode4 September 2015
OI 15-43Penalty brake application – Empty train7 September 2015
OI 15-45Penalty brake application – Empty train8 September 2015
OI 15-46Penalty brake application – Empty train9 September 2015
OI 15-49ECPB recovery process30 September 2015
OI 15-53Trial recovery process for ECPB trains after brake pipe dump or penalty4 November 2015
OI 16-16Brake pipe emergencies and penalties17 March 2016
OI 17-09Brake pipe emergencies and penalties28 February 2017
OI 17-11Brake pipe emergencies and penalties5 April 2017
OI 18-72Brake pipe emergencies and penalties3 November 2018

Early versions of the operating instruction related to trial recovery processes following a brake pipe dump or penalty on ECPB trains. The trial categorised trains into the following 2 groups:

-    Trains operating as conventional pneumatic only trains or trains operating in ECPB mode with EOT brake pipe displaying ‘off’

-    Trains Operating in ECPB mode with EOT brake pipe displaying 0 kpa or above.

For ECPB trains with EOT brake pipe displaying ‘off’, the response from drivers to an uninitiated emergency brake application (referred to as ‘dump’) remained as per a train with a conventional pneumatic braking system (that is, rule book sections R6-3.0 and P6-4.0). The early versions of the operating instruction did not differentiate the required driver response between an emergency resulting in a dump of brake pipe pressure and the ECPB emergency brake application with EOT displaying ‘off’, where the brake pipe remained charged.

For trains in the second category, drivers were able to secure the train against unintended movement using the ECPB interlock feature.[28] In both cases, the driver had access to an ECPB support team via radio to assist in stepping the driver through the recovery process.

Operating instruction 16-16

The publishing of operating instruction (OI) 16-16, dated 17 March 2016, rescinded a series of earlier instructions related to brake pipe emergencies and penalties and replaced, in total, section P6-4.0 of the rule book. Although the operating instruction replaced a module in the rule book, BHP were unable to retrieve records of the consideration or implementation of procedures for issuing and receiving operating instructions, or a notification of change to the ONRSR.

In contrast to the rule book, procedures were now organised with separate instructions provided for:

  • emergency brake applications – ECPB trains
    • when train moving or not initiated by the driver with EOT displaying ‘off’
    • when train moving or not initiated by the driver with EOT displaying ‘0’ or above
    • when train at a stand initiated by the driver with EOT displaying ‘0’ or above
  • emergency brake applications – conventional pneumatic trains
    • when train moving or not initiated by the driver
    • when train at a stand initiated by the driver
  • penalty brake applications – ECPB trains
    • empty train travelling less than 50 km/h
    • empty train travelling 50 km/h or more
    • loaded train and EOTM displaying ‘0’ or above within specific locations
    • loaded train and EOTM displaying ‘off’
  • penalty brake application – pneumatic trains
    • empty train travelling less than 50 km/h
    • empty train travelling 50 km/h or more
    • loaded train within specific locations
    • loaded train in other locations.

Requirements in the instruction for drivers to secure an ECPB train following an emergency application with EOT brake pipe displaying ‘off’ were the same as previously for a conventional pneumatic train; that is, they still required the driver to:

-    secure all portions of the train by application of the independent brake and handbrakes (as per handbrake chart)

OI 16-16 removed reference to the ECPB support team but included additional instruction to the driver on the procedure to recover from the emergency brake application. If the driver was unable to rectify the ECPB problem, these additional processes required a driver to place the automatic brake handle in the emergency position and reduce the brake pipe pressure to zero before conditioning the train for pneumatic operation.

A note at the end the procedure specified that drivers could not use the ECPB interlock to secure any train when reverting from ECPB to conventional pneumatic operation.

OI 16-16 included an expiry date of 17 September 2016. The reason for inclusion of an expiry date on an operating instruction related to a rule change was unknown and the instruction remained applicable until the issue of the next instruction on 28 February 2017.

Operating instruction 17-09

On 28 February 2017, BHP published OI 17-19, rescinding OI 16-16. To prepare for the changes, BHP implemented the processes detailed in the procedure for issuing and receiving operating instructions. BHP developed a management of change proposal that encompassed evidence of stakeholder consultation, risk assessments and testing of train dynamics under penalty and emergency braking conditions, and the proposal was submitted to ONRSR. 

The objective of the change was to reduce complexity of the processes contained within the instruction, and the mitigation of work health and safety risk to drivers arising from exposure to various environmental hazards while undertaking a walk/inspection of their train. More specifically, the changes removed the requirement to inspect (walk) an ECPB train to confirm it was intact following certain types of penalty or emergency brake applications.

Overall, the structure of the operating instruction now included separate instructions for:

  • emergency brake applications – ECPB trains (TBC = 120%)
    • when train moving with EOT displaying ‘off’
    • when train moving with EOT displaying ‘0’ or above
    • when train at a stand with EOT displaying ‘0’ or above
  • emergency brake applications – conventional pneumatic trains
    • when train moving
    • when train at a stand
  • penalty brake applications – ECPB trains (empty or loaded)
  • penalty brake application – pneumatic trains
    • loaded train within loss of brake pipe below 425 kPa at specific locations
    • empty train travelling 50 km/h or more
    • all other cases of pneumatic train penalty brake applications.

In addition, a flow chart was included at the back of the document to help drivers select the appropriate procedure.

OI 17-09 also included several changes to address misunderstandings or misinterpretations that had arisen between operations personnel on the meaning of some steps. The requirement to secure all portions of the train with the independent brake and manually apply handbrakes following an emergency brake application with EOT brake pipe displaying ‘off’ remained unchanged.

The publication of OI 17-09 featured in the safe start rail briefing on 1 March 2017. The advice to drivers contained in the briefing stated:

Please familiarise yourselves with OI 17-09 Brake Pipe Emergencies and Penalties, as there has been some changes.

No information was available of the details provided in the associated briefing undertaken by the supervisor and co-ordinator team as part of the safe start briefing. However, the requirement of the rule book module 1 still placed responsibility on persons to whom the rules and procedures applied (drivers) to ensure they were familiar with the instruction upon starting duty.

Operating instruction 17-11

Following an event on 27 March 2017, BHP identified a condition where the ore car brakes would release and, if not otherwise secured against movement, could introduce the potential for a train to roll away (see CCD shutdown event in March 2017).

On 5 April 2017, OI 17-11 became effective, rescinding OI 17-09. The new instruction changed the rule for securing an ECPB train with an emergency brake application (TBC = 120%) with the EOTM displaying ‘off’ (section P6-4.1.1) to include placing the automatic brake handle in the pneumatic emergency position (Figure 14). The instruction, presented in a red font, required drivers to:

Secure all portions of the train by placing the Automatic Brake Handle in the full Emergency Position (dump BP [brake pipe] air), fully applying independent brakes and manually applying handbrakes as confirmed by Train Control.

BHP were unable to retrieve records of the consideration or implementation of procedures for issuing and receiving operating instructions, or a notification of change to ONRSR.

The publication of OI 17-11 may have featured in a safe start rail briefing following the publication of the instruction. However, BHP was unable to retrieve records of the briefing detailing the information provided to drivers following the release of the operating instruction. BHP provided the ATSB a Rail Operations Personnel Signing Sheet that showed that the driver of M02712 had signed for the receipt of OI 17-11 on 4 April 2017.

Figure 14: Extract from BHP OI 17-11

Figure 14: Extract from BHP OI 17-11

Extract illustrating formats used to highlight key sections of instruction. Highlighted text in the original. This extract does not include all of the content of P6-4.1.1.

Source: BHP

Operating instruction 18-72

On 3 November 2018, OI 18-72 (see) became effective, rescinding OI 17-11. A full copy of OI 18-72 is provided in Appendix A.

The rule applicable to an ECPB emergency brake application (TBC = 120%) with the EOTM displaying ‘off’ (section P6-4.1.1) was unchanged. The step for securing the train was still presented in a red font and it still included the requirement to place the automatic brake handle in the pneumatic emergency position to dump the brake pipe pressure.

The primary change in content of the new operating instruction related to the communication of information to train control. In particular, the rule applicable to an ECPB emergency brake application (TBC = 120%) with the EOTM displaying ‘0’ or above (section P6-4.1.2) was modified to include a new requirement for the driver to ‘Call EMERGENCY on duplicated lines or where deemed necessary’, before advising train control of other relevant details. This change was highlighted in yellow. There was no requirement for the driver to place the automatic brake handle in the pneumatic emergency position for this fault condition, unless the ECPB fault was unable to be rectified and the driver intended to condition the train for conventional pneumatic brake operation.

The notification of OI 18-72 to operational personnel was via the safe start rail briefings. The safe start rail briefing dated 4 November 2018 referenced OI 18-72, and it stated:

28/10/18 - Can all drivers please re-familiarise themselves with ON 18-72 Brake Pipe Emergencies and Penalties. Please ensure you are providing the correct information to Train Control 120% Emergency, 100% Penalty. This is essential to ensure Train Control employ the right level of protection to the train – 120% - no trains can cross or pass the location, whereas with a Penalty - trains can continue past.[29]

On the morning of 4 November 2018, prior to the completion of their night shift, the driver of M02712 became aware of the recent publication of OI 18-72 through a briefing conducted by a supervisor at the Yandi depot office. The driver recalled the supervisor approached them and a small group of other drivers in the office at about 0800 that morning. The supervisor had a printed copy of the operating instruction and took the opportunity to discuss the content and various ‘pick points’ with the drivers present. The supervisor encouraged drivers to get an individual copy of the instruction to read.

The driver of M02712 recollected discussion on the requirement for drivers to contact train control and call an ‘EMERGENCY’ in the case of a brake penalty (section P6-4.1.2). The emphasis placed on the emergency call resonated with the driver, as previously (OI 17-11) there had not been a requirement to call an emergency in response to that ECPB condition; they just needed to advise train control of the penalty and provide pertinent details. The driver recalled no discussion or reminders regarding the automatic brake handle position.

The driver of M02712 did not receive or download a copy of OI 18-72 before starting their next night shift during the evening of 4 November 2018.

Formatting of rules and instructions

With regard to the presentation of the procedural steps and other information, the rule book included a small number of notes throughout. Some were surrounded by a box with a thin red line, some surrounded by a box with a thick red line, and some surrounded by a box with a thick red line together with a yellow caution symbol. Caution and warning symbols were commonly used in other BHP manuals and instructions (see also Procedures for handbrake application and release).

With regard to the operating instructions relating to brake pipe emergencies:

  • OI 16-16 included some notes in boxes with a thin red line. One of the notes stated that it was ‘essential that the train is secured against movement before repairs are carried out’, and none of the other notes specifically related to the circumstances of the M02712 runaway. A small number of the procedural steps throughout were presented in bold text.
  • OI 17-09 included some notes in boxes with a thick red line. These boxes contained some additional content relative to the notes in OI 16-16, and they were now all highlighted in yellow. A small number of the procedural steps, and parts of some other procedural steps, were presented in bold text. This included the requirement for a driver to ‘call emergency’ in the case of an ECPB train following an emergency application with EOT brake pipe displaying ‘off’. Red text was now used throughout to refer to TBC values of 120% (consistent with how that information was displayed on the FIRE screen).
  • OI 17-11 was in a similar format to OI 17-09, with the only change associated with the procedural step in P6-4.1.1 relating to securing all portions of the train. This step was presented in red font, including the parts that were new (automatic brake handle position) and the parts that were unchanged relative to the previous instruction (locomotive brake and handbrakes). The context of the red boxes was unchanged, and they were no longer highlighted in yellow. Underlining was now used for one phrase in one of the boxes.
  • OI 18-72 was in a similar format to OI 18-72, although section headings were now in dark blue text (as opposed to black) and had slightly different wording. Most of the red boxes were again highlighted in yellow, although the content had not effectively changed (other than changing some words to capitals in some cases). As previously noted, the primary change of content was in P6-4.1.2, where the first step was changed from advising train control to calling emergency. This step was highlighted in yellow. In addition, the equivalent steps in P6-4.1.1 and in a later section relating to pneumatic trains, which were unchanged, were also now highlighted in yellow. A procedural step in P6-4.1.2 relating to positioning of the automatic brake handle to the pneumatic emergency position (if the ECPB was unable to be rectified) was now presented in red text. This was not a new requirement, but the wording had been changed to make it consistent with the wording in P6-4.1.1. Some other minor changes in the text of procedural steps throughout were not highlighted in any manner.
  • No caution or warning symbols were used in any of the operating instructions. The nature of the changes in each instruction were not summarised within the instruction (like a version history), and no standard symbology, such as a line down the side of an instruction, was used to indicated changes to a previous version.

Operator manuals and instructions

In addition to the rule book and operating instructions, BHP published a suite of operator manuals and instruction sheets for wired distributed power (WDP) operation and the WABTEC/NYAB type ECPB systems. The documentation contained information on the setup/shutdown parameters and trouble-shooting guides for drivers to action in response to various fault conditions.

The ECPB – WDP – Leader Operator’s Manual provided detailed information and flowcharts describing the required actions by a driver in response to an uncommanded ECPB emergency brake application with EOT brake pipe displaying ‘off’. The manual instructed a driver responding to this condition to ‘secure all portions of the train with the independent brake and manually apply handbrakes as confirmed by train control’.

Although the ECPB – WDP – Leader Operator’s Manual was provided by BHP as the latest version, the general information, flowcharts and clauses relevant to brake pipe emergencies and penalties extracted from the rule book did not consistently reflect the amendments detailed in later versions of the operating instruction (that is, OI 17-11 and OI 18-72). 

Driver competency assessment related to rules and procedures

According to BHP records, the driver of M02712 underwent training and assessment for ECPB and WDP systems in January 2015, and also subsequently underwent an on-the-job assessment in June 2016.

BHP managed train driver competencies for rail operations through training and assessment processes aligned to the requirements of the Australian Qualification Training Framework unit of competency TLI42615 Certificate IV Train Driving qualification. Any person required to access the rail network received an induction and, where appropriate, additional training in relation to the rail operations safeworking rules, procedures and work instructions. Qualified train drivers underwent scheduled driver reaccreditations (typically at 3-year intervals) to assess their ongoing level of competency related to safeworking and locomotive systems.

The driver of M02712 last underwent the reaccreditation assessment on 25 August 2018 and was assessed as competent. The written (theory) assessment at that time consisted of a number of sections addressing various functions of rail operations, including aspects associated with ECPB. Each section had a series of multiple choice and short answer questions that a driver undergoing accreditation was to complete.

The written assessment included questions associated with the position of controls to set up rollaway protection in the ATP system and the positioning of the automatic brake handle in response to an ECPB-related emergency condition. In relation to these questions:

  • The ATP rollaway question tested the driver’s knowledge of how they set up the rollaway protection on a locomotive. The driver’s response was to turn the generator field off and centre the reverser. A following question tested the driver’s understanding of when the ATP rollaway penalty would occur, and the driver answered that it would occur if the locomotive unintentionally moved more than 0.5 m. Both of the driver’s responses were assessed as correct.
  • In relation to the ECPB system, under the section related to rail operations, a question asked the driver ‘In what position does the Automatic Brake handle need to be placed in when performing a walking inspection of an ECPB train with the EOT BP [brake pipe] showing “OFF”?’ The driver’s response stated ‘emergency’, which was assessed as correct.
  • The next question asked the driver ‘When an ECPB train is required to be secured after an Emergency brake application and the EOT BP is showing 0 or above, the train shall be secured by…?’ The driver’s response stated ‘interlock’ and ‘independent’, which was assessed as correct.
  • Later in the assessment, in a section related to ECPB and WDP, a series of questions were included that related to a case study involving ECPB where a driver’s loaded train had come to a stand ‘on a grade due to a loss of EOT Beacon Emergency’ with the EOTM displaying ‘off’ on the FIRE screen. In contrast to the emergency involving M02712, the context of the case study was that the driver could not restore ECPB and decided to convert the train to conventional pneumatic braking mode to continue the journey. One question asked what position the automatic brake handle should be placed in before walking the train, and the driver stated ‘emergency’. A follow-up question asked what event this action was to prevent, and the driver stated a ‘runaway’. Both of the driver’s responses were assessed as correct.

Driver experience of brake pipe emergencies and penalties

The driver of M02712 recalled experiencing penalty brake applications on other train services that brought the train to a stand. On those occasions, the fault conditions were different to that involving M02712, and the driver was able to readily recover the penalty application and continue the journey.

The driver could not recall having previously experienced a brake penalty with a complete loss of trainline communications or having to implement the procedures related to a 120% TBC and EOT ‘off’ condition. BHP kept records of reported ECPB-related failures and the associated BHP investigations. For the period October 2014 to 4 November 2018, there was no record of the driver of M02712 previously experiencing an ECPB-related occurrence.[30]

During interview, the driver stated:

  • Their understanding was that ECPB set to 120% TBC with the interlock on would hold the train in position.
  • In addition to the interlock, the driver’s understanding was that, by placing the reverser to the centre position and turning the generator field off, they had set up the locomotive rollaway protection provided by the on-board ATP system.
  • BHP had provided drivers with numerous new operating instructions related to brake pipe emergencies and penalties in recent years, many with only minor or subtle wording changes.
  • With the change to the operating instructions to require the automatic brake handle to be set in the pneumatic emergency position, there was no explanation provided regarding the reason for the change or why this action was important. They recalled becoming aware of the reason for, and importance of, this action after the occurrence.
  • There was also no information provided to drivers regarding the ECPB system’s 60-minute shutdown feature.

In relation to the events involving M02712 on 5 November 2018, the driver also stated:

  • When conducting the tasks associated with the operating instruction, the driver relied on their memory of the required tasks. They did not have a copy of the operating instruction, and there was no process in place for another person to verify that the required actions were conducted.
  • Due to the nature of the brake pipe emergency and the location, the driver knew before talking to train control that they would need to secure the train and apply handbrakes to the whole train. They also knew that this would take a significant amount of time to achieve.
  • The driver wanted to expedite the rectification of the loss of trainline communications problem as soon as possible. After reboarding the train to give the train controller the train’s exact position and waiting for their advice regarding handbrakes, the driver was putting on their gloves and getting ready to exit the train to start applying the handbrakes. Accordingly, they did not spend much time checking that they had completed all their required tasks. However, given their knowledge of the ECPB system at the time, the driver believed that taking more time would probably not have resulted in changing their actions to include moving the automatic brake handle to the pneumatic emergency position.

Related occurrences involving brake pipe emergencies and penalties

Following the runaway occurrence involving M02712, BHP audited records of ECPB emergency and penalty events reported between June 2017 and November 2018, finding events where a 120% TBC occurred with a loss of EOT beacon and EOTM displaying ‘off’. The audit selected 63 events (including the occurrence involving M02712) for further analysis.

From those 63 events, BHP focused on occasions when the reported duration to recover the fault exceeded 60 minutes. Of those events, BHP reviewed the degree of compliance with the operating instruction requirement to place the automatic brake handle in the pneumatic emergency position.

Of the 14 events selected, BHP found that for 5 events the driver had applied the emergency brake as per the operating instruction (by placing the automatic brake handle to the pneumatic emergency position). For the remaining 9 events, the driver had not placed the automatic brake handle in the emergency position. Six of these 9 events (including that involving M02712) occurred at a location where the potential for a runaway was present and the risk of a derailment of the train increased.

The BHP database entries against the 6 ECPB emergency and penalty events included details of the follow-up investigation/enquiries that occurred following each event. Other than for the M02712 occurrence, each entry documented a check of the locomotive event recorder logs, finding that a loss of EOT occurred and noting no further action (NFA). The database field for documenting the findings from the investigation/enquiries had no information entered. There was no indication that the extent to which the driver complied with the relevant procedure was examined during the investigations.  

BHP’s internal investigation report into the M02712 runway occurrence concluded that there was ‘a perception [in the organisation] that the ECPB interlock will hold the train secure’. The report also noted that the importance and criticality of placing the automatic brake handle into the pneumatic emergency position when responding to a 120% TBC with EOT displaying ‘off’ was not understood as a safety-critical task by all relevant employees.

At the time of the occurrence, the event recorders on BHP’s locomotives recorded parameters related to brake operation and the position of the automatic brake handle. However, information from the recorded data was not being extracted and examined in a systemic way to monitor compliance with the requirements of the braking procedures on OI 17-11 or OI 18-72.

Rules and procedures for securing trains before conducting work

Three-step protection process

In addition to the procedures for responding to brake pipe emergencies and penalties, BHP also had other procedures for securing a train prior to commencing work on the train.

In particular, the Rail Rule Book module 1 contained rules and procedures for a three-step protection process. This process was designed to minimise the risk of injury to workers conducting work on a train or rail vehicle by conditioning the train/vehicle to prevent any unintended movement.

The general rule stipulated:

Before any worker/s enter the profile of stationary rolling stock to perform a task (e.g. handbrake application, inspection, adjustment etc.) except in controlled workshop conditions, the worker/s shall ensure that Three Step Protection has been applied.

The general procedure provided additional information detailing the respective responsibilities of drivers in conditioning the locomotive, and a worker or work team when entering the profile of the rolling stock. The procedure stipulated that the driver was required to:

-    apply independent brakes and where required apply the train [automatic] brakes to ensure rolling stock remains stationary;

-    place the reverser lever in the neutral position;

-    open the generator field switch;

-    where the gradient of the track and/or weight of the train may allow the vehicles to move, the train [automatic] brake shall be applied.

The first 3 dot points represented the 3 steps, with the last dot point being an additional action required in some cases.[31]As previously stated, centring the reverser and opening the generator field switch (or turning it off) applied the ATP system’s rollaway protection.

A single worker intending to enter the profile was required to:

-    contact driver and verbally request Three Step Protection to be applied; and

-    do not enter the profile of the rolling stock until receiving verbal confirmation from the driver that Three Step Protection has been applied.

Where 2 or more workers were required to access the rolling stock profile, the worker responsible for the workgroup needed to perform the above tasks before allowing other members of the group to enter the rolling stock profile.

Application of three-step protection for M02712

After M02712 stopped at Garden, the train controller instructed the driver to apply 101% handbrakes to secure the train against the grade. They also advised the driver that the Redmont maintenance gang would attend to aid the driver. The application of handbrakes by the driver and the group of workers from the Redmont gang required them to enter the rolling stock profile, and therefore apply three-step protection.

After the Redmont gang arrived at the 210 km mark, communications between train control and the gang centred on formulating a plan for the gang to commence at the rear of the train to confirm its integrity, and then commence applying handbrakes from the rear. Subsequent communications between the train controller and driver indicated that the driver was aware the gang had arrived and that the driver agreed with the plan. The train controller instructed the gang and driver to liaise directly with each other.

There was no radio contact made between the driver of M02712 and the gang to confirm the application of the protection. The driver later stated that they had applied the protection anyway, by applying the independent brakes, placing the reverser in the neutral position, and opening the generator field switch. In addition, they also had an automatic brake application due to the ECPB 120% TBC.

The event logger extract for locomotives 4420 and 4472 (Figure 8) recorded the driver’s operation of the independent brake handle at 0340 and positioning the reverser lever into neutral on locomotive 4420 at 0351, prior to the driver starting to apply handbrakes.

The three-step protection process also included the requirement to apply the train (automatic) brake where the gradient of the track and/or weight of the train may allow the vehicles to move. The application of the automatic brake would typically involve the driver moving the handle to a location within the service brake zone. With the train configured in ECPB mode, the operation of the automatic brake handle would result in a 10 to 100% TBC being applied. The level of brake application would likely be determined by the driver dependent on the track grade at that location. For any service brake application with the train configured for ECPB operation, the brake pipe would remain charged.

In the context of M02712, the driver had positioned the automatic brake handle to provide a 39% TBC braking effort along the train. The subsequent disconnection of the trainline cable and resultant emergency 120% TBC response essentially applied full (100%) ECPB effort along the train. With the 120% TBC and emergency interlock active, the driver moving the handle further within the service zone would have had no effect on the braking effort applied to M02712 at the time the driver started applying the handbrakes.

Audits of three-step protection

BHP audited its workers’ implementation of the three-step protection process on rolling stock at various sidings and yards. Auditors recorded findings against requirements detailed in the related audit form. An audit tested workers’ compliance with wearing appropriate personal protective equipment and their fitness for work, and posed a series of questions to workers directly involved in a task to determine their understanding of the process. The audit could also involve a review of downloaded train control radio voice recordings and locomotive event logger data to show the correct application of processes.

In conjunction with the review process for BHP material risks, such as the RME interaction with people, auditors (usually front-line supervisors) also undertook critical control observations to assess workers’ understanding of the hazard present and the effectiveness of the associated critical control, such as the three-step protection process.

BHP provided records of various audits and critical control observations undertaken in 2017 and 2018. Each audit and observation recorded that the associated workers had complied with the requirements of the three-step protection process.

Procedures for handbrake application and release

The BHP work instruction 0105931 (Handbrake application and release mainline recovery) provided information for the safe application or release of handbrakes on trains working on the main line. The instruction cross-referenced critical controls contained in related rules in the rule book, together with information published in operating notices and operating instructions, as well as other work instructions.

The work instruction included the mandatory requirement for the person responsible for the worksite to contact the driver to obtain three-step protection before approaching rolling stock to commence work.

Version 2.0 of the instruction, issued in August 2018, also included a caution for the driver of an ECPB train with the EOTM displaying ‘off’ that, before implementing the three-step process, the automatic brake handle was to be set to the emergency position. The warning, highlighted in yellow and marked by a caution sign symbol, stated:

If the train is conditioned for ECPB operations and the EOTM is ‘off’ or has to be returned to pneumatic brake operations the train driver shall place the automatic brake handle to ‘emergency’ prior to the application of the three step process.

The caution reflected the requirement published in OI 17-11 when responding to brake pipe emergencies and penalties.

Prior to the runaway of M02712 on 5 November 2018, the Redmont gang attended at Garden to aid its driver in applying handbrakes to secure the train. The Redmont gang communicated with train control on arrival but not directly communicate with the drivers of either train M02712 or M02727 to confirm that the driver of the train they were meant to be attending (that is, M02712) had applied three-step protection.

Responders from the Redmont gang consequently entered the rolling stock profile and commenced applying handbrakes to M02727 without confirming the correct application of the three-step protection, potentially exposing themselves to an increased risk of injury.

The M02712 loss of trainline communications occurred at 0338 and the Redmont gang advised train control at 0422 that they had arrived at the (incorrect) train. BHP personnel advised that, even if the Redmont gang had attended the correct train and started applying handbrakes soon after, they would not have had time to apply sufficient handbrakes to secure the train within the ECPB system’s 60-minute shut-down period for the ore cars rear of the point of break in the trainline (that is, prior to 0438).   

Emergency management of a runaway train or rail vehicle

Procedures for notifying a runaway

The rule book module 6, section P6-7.0, detailed the actions required from workers and the train controller in response to a runaway of a train or rail vehicle. The worker noticing the runaway was required to:

-    transmit an emergency radio message;

-    inform the following staff,

-    train controller

-    any train in the area

-    workers working in the area

-    take any action necessary to protect trains, other workers and members of the public provided it can be done without further increasing risk to self and / or others.

The procedure for a runaway addressed an event associated with an uncontrolled or uncommanded movement. Although pertinent to a critical control for emergency response following such an event, the procedure was not referenced within the mitigating controls linked to the material risk of rail mounted equipment interaction or other material risk identified within the BHP risk management system.

When train M02712 commenced to roll away at 0440, the train controller became aware of the movement through observing track occupancy indications displayed on the train control monitor, as well as radio communication with the driver of the empty east-bound train M02727 at 0444.

As noted in The occurrence, the driver of M02712 notified the controller of the runaway at 0446. The driver had lost their footing when the train began to move, slipping on the ballast formation and knocking their radio off channel. After resetting the radio, the driver contacted the train controller, declaring an emergency and notifying of the runaway.

Train control response to emergencies

Following receipt of an emergency radio message from a worker alerting a train controller of a runaway involving a train or other rail vehicle, the rule book module 6 procedure required the train controller to take any necessary action to protect trains, other workers and members of the public. 

The train control incident and emergency response procedure[32] further outlined the role and responsibility of the train controller in undertaking the initial response and management of an incident or emergency that occurred on or in the proximity of the BHP rail network.

The procedure addressed responses to an incident or emergency involving injury to a person on the BHP rail network, at an interface point with a third party such as a level crossing, or between BHP and another rail transport operator’s network. For incidents or emergencies involving BHP rail operations, the procedure required the train controller to implement a multi-step process involving the:

  • exclusion of rail traffic
  • gathering of relevant information
  • recording of details on the Train Control Graph
  • implementing processes to protect the sites and assist field staff
  • completion of the rail safe working notification form.

For defined types of events, the procedure included an escalation protocol matrix for notifying supervisors or superintendents as required. An escalation event included:

  • any event that was classified as Category A reportable incident to ONRSR
  • any accidents, incidents or near misses that occurred at a rail interface with a third party, or the area within 5 m either side of the applicable railway tracks and associated track structures, irrespective of whether injury to a person or damage to property or equipment resulted.

An event such as the runaway of train M02712 therefore required immediate escalation to a superintendent level.

The emergency response procedure also linked to the two-part emergency management plan,[33] which described the arrangements BHP iron ore operations put in place to prepare, respond and recover from an emergency event. These plans defined the arrangements for various field response and corporate support teams based on the location and type of event.

In responding to the notification of the runaway of train M02712, the train controller excluded trains approaching the location of M02712 on the adjacent track, gathered relevant details of the event and arranged for resources to assist the driver. The train controller also placed trackside signals immediately in front of M02712’s movement at stop in an attempt to trigger ATP and stop the train.

The train controller based the initial response on the principle that the ATP system would stop the movement of M02712. When this did not occur, train control formed an understanding (in conjunction with advice from other drivers) that M02712 would slow and come to a stand on the rising grades approaching Woodstock (approximately 154 km from Port Hedland). The controller continued to manage the safety of the affected train on the adjacent track and the welfare of the driver of M02712.

About 30 minutes later, when it became evident to train control that M02712 was not stopping, the train controller contacted the drivers of the other trains operating ahead of M02712, instructing them to also stop, secure their trains and move to a position of safety.

Interface coordination plans

The Newman to Port Hedland railway was located predominately within pastoral leases, local government and BHP property. A number of interfaces existed between BHP and adjoining rail infrastructure managers (RIMs), pastoralists/local government and road managers of public and private roads crossing the railway. The interface agreements defined the respective roles and responsibilities of each party and the provisions put in place to manage risks to safety identified at the various infrastructure or operational interfaces. 

The section of the railway between the Garden (211 km) and Turner South (119 km) contained the following infrastructure interface points:[34]

  • rail/rail interfaces
    • Fortescue Metals Group 148.8 km, Cloudbreak rail overpass
    • Fortescue Metals Group 186.75 km, Solomon rail overpass.
  • rail/road interfaces
    • 2 km, passive level crossing
    • 4 km, active level crossing – Roy Hill to Munjina Road, public access
    • 45 km, passive level crossing (wide load bypass, BHP-controlled locked gates)
    • 5 km, passive level crossing (wide load bypass, BHP-controlled locked gates)
    • 9 km, active level crossing – Roy Hill access.

The interface agreement for the overpasses at Cloudbreak and Solomon involved 2 other RIMs. The agreement detailed the parties’ responsibilities and the agreed arrangements for notification and management of risk associated with inspection or maintenance activity and in response to an incident or emergency.

The risk assessments identified the potential for damage to the rail overpass abutments (and potentially the integrity of the track above) arising from various factors, including derailment of a BHP train due to an overspeed. The risk assessments also identified various BHP controls to mitigate the risk, with the residual risk assessed as high.

The interface agreement stipulated that parties immediately report to each other any accident, incident or a near miss that occurred at the interface, irrespective of whether injury to a person or damage to property or equipment resulted. Similarly, following the receipt of an emergency notification from operational staff, the respective train control personnel were to advise the other parties train control personnel immediately in accordance with an activity and notifications table included in the agreement. The notification table identified a life threatening or operational disruption event, such as train derailment, track obstruction, level crossing or infrastructure damage. The description did not define the notification required in response to an emergency involving an uncontrolled train movement (or runaway).

With regard to the occurrence involving M02712, BHP staff at the integrated remote operations centre in Perth communicated with affected BHP staff to manage the event. Although relevant contact details were included in the train control and emergency response procedure, BHP staff did not contact representatives of the RIMs that had interfaces with BHP to warn of the potential risk at the interfaces from the runaway of M02712.

Fatigue management

Regulatory requirements and guidance

Given that the train stopped at 0340 and the driver was conducting a series of 7 night shifts, the ATSB examined BHP’s processes for managing train driver fatigue.

BHP developed its fatigue management procedures to be consistent with the Code of practice: Working hours, issued by the Western Australia Commission of Occupational Safety and Health and its Mining Industry Advisory Committee in 2006.[35]The code stated that it addressed:

… issues that might potentially arise in some working hours arrangements, for example extended hours, shiftwork and on call work. It brings together a range of recognised workplace hazard factors that must already be addressed, as far as practicable, where there are occupational safety and health risks…

As individual workplaces and industries have different working hours arrangements, this code of practice provides high level general guidance and recommendations on risk management. It is suggested that the risk management approach is tailored specific to the unique demands of each workplace and/or industry.

The code provided guidance for employers to identify fatigue-related hazards, assess their risk and implement risk control measures. It outlined a significant number of potential hazard factors to consider. The guidance indicated that factors associated with higher risk for shiftwork, such as fly-in fly-out (FIFO) working arrangements, included 12-hour shifts, night shifts, backwards rotation, slower rotation (such as weekly), 7 sequential 12-hour night shifts and extended travel prior to starting a FIFO shift pattern. There were no specific requirements or minimum standards for roster arrangements.

From November 2015, the Office of the National Rail Safety Regulator (ONRSR) administered the Rail Safety National Law (WA) Act (2015). The Act stated that a duty of a rail transport operator included ensuring that:

…rail safety workers who perform rail safety work in relation to the operator’s railway operations do not carry out rail safety work while impaired by fatigue or if they may become so impaired

Operators were also required to have a safety management system that included a fatigue risk management program. The Rail Safety National Law (WA) regulation 29 stated a range of things an operator had to take into account when preparing a fatigue risk management program. These included (but were not limited to) the scheduling of work and non-work periods, the time when work was undertaken, the length and frequency of rest breaks, circadian effects, chronic sleep loss effects, the types of rail safety work being performed, the suitability of rest environments, the physical environment, and relevant developments in research related to fatigue. There were no specific requirements or guidance regarding the design of shifts and rosters.

ONRSR advised that, for the period from November 2015 until November 2018, it had no records of any notifications of change, variation to accreditation or any regulatory oversight activity conducted in relation to train driver rostering practices for the operator.

Overview of operator’s procedures

The BHP Western Australia Iron Ore (WAIO) fatigue management procedure (SPR-IHS-SAFOH-004) outlined BHP’s approach to controlling the risks associated with fatigue. It applied to all BHP iron ore employees and contractors, including train drivers.

The scope section of the procedure stated:

Fatigue presents a material risk in Iron Ore. This procedure is founded on the WA Code of Practice and Working Hours, which itself is based on extensive studies in the field of fatigue risk management and control. As a result there is a significant base of science underpinning BHPBIO fatigue risk management requirements.

Causes of fatigue include but are not limited to:

-    Roster design and working hours

-    Work tasks and environment

-    Amount and Quality of sleep

-    Sleeping environment

-    Sleep disorders and other health issues….

Fatigue should be managed at the following levels and in the following order:

-    Self-Management

-    Peer Management

-    Supervisor Management

It must be recognised that the individual has the greatest amount of control over their own fatigue and as such the primary accountability for managing personal fatigue risk resides with the employee.

In addition to the fatigue management procedure, additional requirements and guidelines were outlined in related documents. In particular, the WAIO approved rosters procedure provided requirements for planned rosters. It also noted that fatigue could occur due to:

-    Too little or poor quality sleep;

-    Working during normal ‘sleep’ times;

-    Carrying out mentally or physically demanding activities; or

-    Other health factors.

Rostering rules/principles

The WAIO fatigue management procedure stated:

The following key fatigue risk factors are relevant to day to day operations and represent the threshold conditions, beyond which additional controls may be required to manage fatigue risks.

3.2.1 Maximum working time per 24 hours will not exceed 14 hours, inclusive of travel time.

3.2.2 Maximum of 14 consecutive dayshifts

3.2.3 Minimum time between shifts to not be less than 10 hours.

3.2.4 When rotating shifts, they are to rotate from day to night.

3.2.5 When rotating from day shift to night shift, the minimum time between shifts is not less than 23 hours. For avoidance of doubt, the transport time to and from the point where work commences can be within the 23-hour period

3.2.6 Maximum of 7 consecutive nightshifts for FIFO, 4 consecutive nightshifts for residential.

3.2.7 Where a roster starts on nightshift, flight arrangements will ensure that individuals have the opportunity for 4 hours sleep at their site accommodation before the start of their first night shift.

The WAIO approved rosters procedure also specified a set of ‘fatigue rules’, against which planned rosters were required to be assessed prior to approval. For FIFO operations, these rules included:

  • maximum normal shift length – 12 hours (excluding shift handover)
  • maximum shift handover – 30 minutes
  • maximum number of consecutive shifts – 14
  • maximum consecutive night shifts – 7
  • rotation of roster – forwards (day shift followed by night shift)
  • minimum rest period between shifts – 10 hours
  • break between day and night shift (or night and day shift) – at least 23 hours.

A night shift for rail operations (with continuous rolling roster patterns) was defined as working more than 3 hours between the hours of 2300 and 0600 (that is, any 12-hour shift starting between 1500 to 0200).

Specific management approval was required for rosters that exceeded any of the ‘threshold conditions’ or ‘rostering rules’. With regard to FIFO train drivers, an approved exemption had been in place since August 2013 that allowed for roster patterns or ‘swings’ to start with night shifts followed by day shifts.

The operator’s FIFO train drivers typically worked swings that consisted of 7 12-hour shifts (each starting at the same time), a 24-hour recovery break, 7 12-hour shifts (each starting at the same time) and then 12 days off duty. The start time of the first shift would vary for each swing. For example, for the driver of M02712 during 2018, the first shift of their swings started at the following times: 0300, 0600, 0200, 2200, 0500, 0200, 0600 (training), 2100, 0400, 0000 and 2200. The swings commencing at 2100 to 0200 were classified as starting with night shifts, whereas the swings commencing at 0300 to 0600 were classified as starting with day shifts.

Fatigue monitoring

BHP provided operational staff and their managers with a ‘fatigue assessment tool’. The tool asked a worker to provide answers to a series of 8 questions related to sleep and alertness, including: hours sleep in the last 24 hours, hours sleep in the last 48 hours, hours awake at the end of the shift, perceived level of alertness, use of alcohol or medications that could cause drowsiness, and health or personal problems that could influence concentration or sleep.[36]

The answer to each question could be assessed as low (0 points), medium (1 point) or high (2 points) risk, and the overall score across the 8 questions could be then assessed as low risk (0–2 points), medium risk (3–7 points) or high risk (8 or more points). For example, low-risk scores for sleep included at least 7 hours sleep in the last 24 hours and at least 14 hours sleep in the last 48 hours, and high-risk scores included less than 5 hours sleep in the last 24 hours and less than 12 hours sleep in the last 48 hours.

In the case of an overall medium-risk score, the recommended actions for supervisors included rotating tasks, encouraging the use of alertness strategies, providing opportunity for short breaks, having personnel work together, or removing the person from safety-sensitive work. In the case of an overall high-risk score, recommended actions included immediately preventing the person from working and determining if the individual could be placed on alternative duties.

The fatigue assessment tool was required to be used when a worker reported they were ‘fatigued’, a supervisor or peers observed signs of fatigue, or other situations ‘where there may be fatigue risk’. FIFO train drivers were also required to complete the tool prior to their second shift and their ninth shift on each roll-over swing.

An independent review of fatigue management at BHP WAIO rail operations completed in February 2020 (see also Sleep studies, surveys and other assessments) noted that the way BHP’s tool derived an overall risk score could underestimate the level of risk because a high score on multiple questions could still result in only a medium-risk score overall.

In addition, the review noted that a number of people interviewed had stated workers were reluctant to self report fatigue, and few workers were willing to complete the fatigue assessment tool accurately or provide responses that would raise a supervisor’s concern about their fitness for work. Concerns were also raised about how workers who self reported fatigue were managed.

BHP advised that, during 2018, 12,860 fatigue assessments were completed. The vast majority (97.6%) resulted in low-risk scores, with 297 (2.3%) resulting in a medium-risk score and 6 (0.04%) resulting in a high-risk score.   

The driver of M02712 completed a fatigue assessment tool prior to commencing their second night shift on 31 October 2018. Only summarised information from completed forms was stored by BHP, and the result for 31 October indicated a low risk. BHP reported that the driver’s other assessments for 2018 also produced low-risk scores.

The driver stated that they had never self reported being fatigued while working at BHP. They also noted that when a driver did not pass the fatigue assessment tool they were not allowed to drive a train; instead they were generally kept around the office to do administrative tasks (including driving other drivers to their trains), which was perceived negatively by the drivers.

Fatigue management training

BHP’s fatigue management procedure stated that ‘Appropriate education and training shall be provided to assist in the prevention and management of fatigue.’

The independent review of fatigue management completed in February 2020 stated areas of concern regarding fatigue management training. It noted that individuals who had recently conducted induction training reported that the content on fatigue was basic in nature. The review also noted that, according to a BHP manager, courses on ‘fatigue education’ and ‘night shift and fatigue management’ were available on the BHP’s learning management system: however, a sample of employees and supervisors appeared to be unaware of these courses or whether they were mandatory, and none had undertaken such a course recently.

The driver of M02712 completed fatigue awareness training course in May 2009. They also completed an on-line recurrent training course in February 2017 that covered fatigue awareness aspects (amongst other safety topics). The content of the 2017 training including advice on techniques to minimise fatigue and assist with sleep. It also stated that ‘you have to rest for at least 10 hours between shifts, so you have a chance of sleep’. The training did not provide advice on the minimum amount of sleep required between shifts, but noted that if a worker was worried about their level of fatigue they could use the fatigue assessment tool to determine their level of fatigue.  

Accommodation on site

FIFO train drivers were provided with airconditioned accommodation in a unit having its own bathroom. The rooms were described as providing good control over noise, light and temperature.

The driver of M02712 reported the sleeping accommodation was suitable. The driver also noted that the set meal times and meals at the depot were not conducive to a night shift roster, with options available at 1730–1800 being more traditional dinners rather than being the sort of meals people would normally eat for breakfast.

Additional fatigue risk controls and mitigators

As part of its risk management process, BHP had first level supervisors conduct critical control observations (CCOs) related to fitness for work and fatigue management. These involved a front-line supervisor asking a worker 3 questions about fatigue management aspects (including the process for reporting fatigued and the tool available for assessing fatigue). Overall, 4 CCOs were conducted in 2018 on BHP’s train drivers. No problems were noted in the drivers’ understanding of the matters assessed.

BHP also conducted one internal audit of fatigue management aspects within its rail operations in 2018. The audit primarily assessed workers’ awareness of (and compliance with) requirements related to not exceeding 14 hours work a day.

With regard to FIFO travel, as noted in the rostering rules, a worker was required to have a 4-hour sleep opportunity after arriving at camp and prior to commencing their first night shift. The fatigue management procedure also stated that:

It is an individual’s responsibility and duty of care to manage their own fatigue and their commute arrangements to the airport in order to safely work their full first shift…

Reasonable flight arrangements will be scheduled to enable individuals to manage fatigue.

The fatigue management procedure and the fatigue rules did not specify any minimum requirements regarding rest breaks within a rostered work period. FIFO train drivers were permitted to stop for a 30–minute ‘crib’ break (or meal break) between 4 to 7 hours into each shift. A review of the train control diagram for the morning of the accident noted that drivers departing from Yandi typically took a 30-minute rest break at Coonarie or Woodstock after conducting about 6.5 hours duty (ranging from 5.5 to 7.3 hours prior to the break).  

The driver of M02712 stated that, during a crib break, they either sat inside the locomotive and opened up the window for fresh air or stood on the nose or side of the locomotive, had a meal, then grabbed a fresh bottle of water when resuming driving duties.

BHP procedures and practices included a range of additional process to help minimise the risk of fatigue. These included monitoring of fatigue effectiveness management by supervisors, employee assistance programs, drug and alcohol testing, and inclusion of sleep-related items on annual medical examinations (in accordance with the National Standard for Health Assessment for Rail Safety Workers).

Use of biomathematical models of fatigue

A biomathematical model of fatigue (BMMF) uses mathematical algorithms to predict the effect of different patterns of work on measures such as subjective fatigue, sleep or the effectiveness of performing work. Each model uses different types of inputs and produces different types of outputs, and each model is based on many assumptions and has limitations.

In particular, the models are based on group-averaged data, and it is widely agreed that the models are not well suited for predicting a specific individual’s level of fatigue. In addition, none of the models consider all of the factors that can influence fatigue. The models are designed to be one element of a system for evaluating and comparing work rosters (see Civil Aviation Safety Authority 2014, Dawson and others 2011, Gander and others 2011, Independent Transport Safety Regulator 2010).

BHP used the BMMF known as ‘FAID’[37] to conduct assessments of some of its rosters. FAID has been widely used in the Australian rail and aviation industries since the early 2000s. It uses hours of work (start time and end time) as its inputs, and it produces a score based on an algorithm that considers the effects of the length of the duty periods, time of day of the duty periods and the amount of work over the previous 7 days (Roach and others 2004). The more recent the duty period, the more effect the duty period has on the resulting score. The higher the FAID score, the higher the potential for fatigue.

FAID documentation stated scores of 40–80 were broadly consistent with a safe system of work. However, the threshold for deciding the acceptability of a roster needed to be set by the operator based on a fatigue hazard assessment, taking into account the fatigue-related hazards specific to the role or task, and determining the acceptable level of fatigue tolerance for that role or task. Without this assessment, the FAID program defaulted to a fatigue tolerance level (FTL) of 80.

The ATSB requested BHP to provide any fatigue modelling assessments of FIFO train driver rosters. It provided documents that summarised various assessments conducted in 2011–2013. Key points stated in these documents included:

  • BHP set the FAID FTL at 90 due to ‘the use of WAIO fatigue procedures and controls’.
  • FAID was not a ‘yes/no’ tool and scores greater than the FTL did not prevent work from occurring. Rather, FAID was a risk predictive tool and when high scores were identified then suitable controls needed to be established and monitored.
  • FAID identified night shifts as a significant risk and the greater the number of consecutive night shifts then the higher the scores. In comparison, afternoon shifts had lower scores (particularly for shifts ending before or about 0000).
  • The WA Code of Practice noted a key risk with night shift, specifically during 0200–0600, and ‘any use of targeted or strategic risk controls during this period is recommended’.

The documents included assessments of actual or proposed FIFO swings (with 7 12-hour shifts, 24-hour break and 7 12-hour shifts) with various start times. Results included:

  • For a typical series of 4 swings with different start times, 23% of the duty time exceeded a FAID score of 90.
  • All of the swings had multiple shifts with peak FAID scores exceeding 100, and many had multiple shifts with peak scores exceeding 120 (usually on night shifts).
  • Many of the swings had peak FAID scores in the range of 140–149, with the peak score occurring towards the end of the seventh night shift. Shift start times associated with peak FAID scores of 148–149 included 2000, 2130 and 2200.
  • Most of the swings were evaluated as meeting the current requirements of the fatigue management procedure and the fatigue rules. Some of the proposed swings, with night shifts followed by day shifts, were identified as not meeting BHP’s procedural requirements and therefore needed a risk assessment and approval before implementation (see next section).

A review of the fatigue modelling documents provided by BHP to the ATSB noted that:

  • When evaluating new proposed shift times, the documents normally stated that the scores were similar to those found for previous FIFO rosters (rather than state their overall level of risk).
  • Travel times for FIFO workers prior to their first shift were not included in the modelling. Including travel time would increase the scores in the first few shifts by a small amount.
  • The shift patterns being modelled had no work hours for at least 7 days prior to the first shift. A key feature of FAID is that it only considers the duty periods over the previous 7 days, with the influence of a duty period decaying over the 7 days. If there were no duty periods in the previous 7 days, then there was a lag as the score in the next duty periods accumulated. Accordingly, FAID scores for the first few shifts after 7 or more days of no duty time will underestimate fatigue levels.[38]

The ATSB notes that FAID scores (and the scores from any BMMF) need to be interpreted with caution. The Independent Transport Safety Regulator of New South Wales (2010) stated that, due to various factors associated with the model, ‘a FAID score of less than 80 does not mean that a work schedule is acceptable or that a person is not impaired at a level that could affect safety’. In addition, the US Federal Railroad Administration (2010) concluded that in some situations FAID scores between 70 and 80 can be associated with ‘extreme fatigue’.

Fatigue risk assessments

A risk assessment was conducted in August 2013 by BHP for the exemption to the threshold conditions and rostering rules that allowed FIFO train drivers to work a roll-over swing with 7 12-hour night shifts followed by 7 12-hour day shifts. The list of ‘current controls’ for this arrangement included:

  • vigilance control and ATP (on board a train)
  • fatigue management procedure
  • fatigue assessments (as per the fatigue assessment tool)
  • fatigue management training for drivers and supervisors
  • medical assessments
  • drug and alcohol testing
  • employee assistance program
  • airconditioned accommodation
  • fatigue breaks
  • FIFO travel commute plans.

These controls reduced the level of raw risk from ‘extreme’ to a residual risk of ‘high’. No additional risk controls were added to reduce the risk, other than to ensure the roster was approved.

Sleep studies, surveys and other assessments

BHP was asked to provide evidence of any sleep studies, surveys, expert reviews or other reviews conducted for the FIFO train driving rosters (prior to 4 November 2018). No evidence of any sleep studies or surveys associated with the FIFO train drivers was provided.[39]

In August 2018, at the request of BHP, an independent organisation completed a review of WAIO train driver rosters. The review used different criteria to assess residential versus FIFO rosters, noting that FIFO workers generally had a more controlled sleeping environment, reduced domestic and family demands, less competition for sleep times from leisure and domestic pursuits, and reduced daily commute times.

The report concluded that, while 7 consecutive night shifts and 14 consecutive shifts was still very common in the Western Australian mining industry, BHP’s roll-over roster patterns for FIFO train drivers had several significant additional risk factors. High-risk aspects included day shift early start times of between 0000–0300, night shift finish times between 0800–1400, the change from nights to days within a roster pattern (compared to the reverse direction), and the short length of the recovery break (24 hours) between night shifts and day shifts.

Early start times were considered problematic because many employees would find it difficult to get 8 hours sleep due to 1600–2000 being a period of high natural alertness. The late night shift finish times were considered problematic due to environmental and bodily conditions making it difficult for employees to fall asleep and stay asleep during the day. The review also stated that other aspects, such as 7 consecutive night shifts, were considered a medium risk. The report noted that, in combination with the high-risk factors, ‘many individuals are likely to build up a significant sleep debt over these 7 night shifts’.

The August 2018 review outlined several recommendations. These included ensuring that BHP provided recent and comprehensive education to drivers and supervisors and to review whether the additional risks posed by working night shifts prior to day shifts was adequately mitigated by the stated control measures.

The same organisation completed a review of fatigue management at BHP WAIO rail operations in February 2020. That review noted that the exemption which permitted swings with night shifts followed by day shifts did not appear to include the involvement of a fatigue subject matter expert. The review stated that the roster pattern contained ‘a very high risk of fatigue’ and that most of the controls specified in the exemption were administrative in nature and were already in place for approved rosters.

The February 2020 review further stated that commencing with night shifts was problematic as the fatigue accumulated over 7 night shifts was carried over into the day shifts. It was also problematic as it could lead to workers travelling in on the day prior to their first shift and not getting any sleep in the afternoon or evening prior to that first shift, resulting in them being awake for an extended period (more than 24 hours) prior to the end of their first shift. In addition, the review acknowledged that drivers preferred the roster patterns with nights followed by days as it meant that they ended up with an additional day at home.

Information about research into the effects of night shifts and roll-over roster patterns on sleep is provided in Appendix B.

Additional fatigue modelling

The ATSB applied 3 different BMMFs used in the rail industry to a roll-over roster pattern with 7 12-hour night shifts starting at 2200 followed by 7 12-hour day shifts starting at 1000, with no work in the previous 7 days. The purpose of the applications was to understand the nature of the results such models would provide if they had been used by an operator to examine such a roster pattern. More specifically:

  • FAID was applied using the BHP FAID score threshold of 90. It resulted in 22% of scores above 90 and a peak score of 148. All of the scores above 90 occurred on the night shifts, with the amount of time above 90 increasing from 0.8 hours on the third shift, 7.9 hours on the fifth shift, 9.8 hours on the sixth shift and all of the seventh shift. The highest scores each shift occurred between 0300–0800, and particularly between 0500–0700. The scores between 0300 and after 0800 on the sixth shift exceeded 115, and for the same period on the seventh shift they exceeded 120.
  • FAID Quantum (available since 2016) was applied using the default threshold Karolinska sleepiness scale (KSS) score of 7 (out of 9).[40] It resulted in 24% of KSS scores above 7 and a peak KSS score of 8.2. All the scores over 7 occurred on the night shifts, with the amount of time above 7 increasing from 6.5 hours on the third shift to 7.5 hours on the fifth shift and 7.8 hours on the seventh shift. The scores passed 7 at about 0300 on each of these shifts and reached a peak shortly after 0600. The model also predicted 4.5 hours sleep following each night shift. This is broadly consistent with available research on the average amount of sleep workers obtain with multiple 12-hour shifts starting at 2200 (Roach and others 2003, Paech and others 2014; see Appendix B).
  • The fatigue avoidance scheduling tool (FAST) was applied using a no-sleep zone of 1600–1900 (recommended for regular night shift workers) and a commute time of 60 minutes, resulting in 5-hour sleep periods following each night shift. This resulted in performance effectiveness scores[41] that gradually decreased over the 7 night shifts, with the lowest scores in each shift occurring at about 0600. Significant portions of the night shifts were below the criterion line (77.5% effectiveness) and notable amounts were in the red zone (below 65% effectiveness). The percentage of time below the criterion line increased from 66% for the first night shift to 79 % for the last 3 night shifts. The average effectiveness score decreased from 77 for the first night shift to about 64% for the last 3 night shifts.

As indicated previously, BMMFs are not well suited for predicting a specific individual’s level of fatigue at a specific point in time. For the purposes of comparison with the other results above, the score from the various models (using default inputs) for 0345 on the sixth night shift were a FAID score of 120, a FAID Quantum KSS score of about 7.5, and a FAST performance effectiveness score of about 60.

In January 2021, a consultancy organisation provided a report to BHP regarding its rail operations rosters. The review used FAST to conduct modelling of BHP’s current FIFO rosters and some proposed alternatives. With regard to the type of swings being used at the time of the 18 November 2018 accident, the report noted that each swing, regardless of the initial sign-on time, would produce an overall average score (across the 14 shifts) that could be considered ‘extreme risk’ or ‘high risk’. Initial sign-on times associated with the worst average scores were from 2100–0300, with the highest scores being from 0000–0100.

  1. At the time of the accident, Adelaide was on Central Daylight-savings Time (CST), which was 2.5 hours ahead of Western Australia.
  2. A No sleep-related problems were noted on the driver’s last medical assessment. The driver also stated that they had previously undertaken a sleep apnoea test administered by BHP and this test did not identify that they had a sleep disorder.
  3. A The Samn-Perelli scale for self evaluating fatigue ranges from 1 (fully alert) to 7 (completely exhausted). A rating of 4 indicates ‘a little tired; less than fresh’.
  4. Unit train: freight train composed of cars carrying a single type of commodity
  5. Captive unit train operations: train operations where rakes of wagons do multiple return trips as a complete unit. These rakes of wagons are shunted infrequently and rarely travel outside a defined area of operation.
  6. Switch mode is used during shunting operations where use of the EOT device is not practical.
  7. The hierarchy of controls is an industry wide accepted practice used when evaluating ways to reduce risk to a level so far as is reasonably practical. An associated BHP procedure stated that the following hierarchy should be used when risk reduction measures were being considered: elimination, substitution, engineering control, separation, administration (including procedures and training) and personal protective equipment.
  8. Rail-mounted equipment (RME) was defined as including locomotives, ore cars, track mobile machines, fuel trains, hi-rail vehicles, ballast wagons, tamper trains, track geometry recording vehicles, flat bed (wagons), steel trains, flashbutt welders, excavators, pettitbones and grinders.
  9. The 1SAP system was the key database used by BHP for hazard and event management and reporting.
  10. BHP Iron Ore management of change assessment, form #TFAAEBN1106002562, dated 03 June 2011.
  11. Testing of ECP brakes for BHPB-IO, Report 2012/657, April 2012
  12. Available at https://www.intesm.org/.
  13. International Organization for Standardization (ISO) 15288, Systems and software engineering ¬ System life cycle processes. Versions were published in 2002, 2008 and, 2015.
  14. The SRACs communicated conditions to BHP that were identified by the vendor during a safety analysis performed on an earlier version of the ATP executive software.
  15. Western Australia Office of Rail Safety administered the Western Australia Rail Safety Act until 2 November 2015.
  16. On pneumatically braked trains the brake pipe pressure is dumped to atmosphere or alternatively reduced by an amount equating to a full-service brake application in response to an emergency or penalty condition respectively.
  17. This procedure is undertaken to back up the pneumatic brake application to secure the stationary train against a potential loss of brake cylinder air pressure.
  18. An emergency brake interlock will remain in effect for a minimum of 120 seconds following detection of an emergency condition. The brake interlock reset can occur following correction of the condition that caused the emergency.
  19. The same information was included in the rail safe start briefings on previous days, but with OI 17-11 referred to instead of OI 18-72.
  20. The data field related to driver name was blank or recorded as ‘unknown’ for a number of recorded occurrences.
  21. In the driver’s last reaccreditation assessment (conducted in August 2018), a question asked a driver to list the 3 steps required for three-step protection. The correct answer was applying the locomotive brake, centring the reverser and opening the generator field switch.
  22. BHP Train Control Incident and Emergency Response Procedure, 0090625, version 8, dated August 2018.
  23. BHP Emergency Management Plan - Part 1, Procedure
  24. BHP interfaces with pastoralists and local government parties not detailed.
  25. The code was issued under the provisions of the Western Australian Occupational Safety and Health Act 1984 and Mines Safety and Inspection Act 1994.
  26. Such a tool is sometimes called a ‘fatigue calculator’ or ‘fatigue likelihood scale’ and they are used by many organisations in Australia, with each organisation generally customising it to its own context and having different triggers for requiring it to be completed. The basic concept behind the criteria used for recent sleep and hours awake were derived from the prior sleep wake model (Dawson and McCullough 2005).
  27. FAID was initially known as ‘Fatigue Audit InterDyne’. It was subsequently renamed the Fatigue Analysis Tool by InterDynamics.
  28. In October 2017, following the release of ATSB investigation AO-2019-072 (reopened), InterDynamics issued a ‘BMM Warning’ advising users that a weakness of FAID was that work periods immediately following a long break will have a low score.
  29. In this report, a sleep study refers to an activity to measure the quantity (and potentially the quality) of sleep obtained by a sample of workers, using techniques such as sleep diaries, surveys or preferably actigraphs or similar devices. It may also involve obtaining self ratings of fatigue or alertness at different times. This type of study is distinct from an evaluation of a specific individual’s sleep for the purposes of evaluating whether that person has a sleep disorder or medical condition. A survey of workers could examine their estimated sleep patterns and alertness levels in different situations or a range of other topics related to fatigue and fatigue management.
  30. The KSS scale uses subjective ratings of fatigue, ranging from 1 (extremely alert) to 9 (extremely sleepy, fighting sleep). A score of 7 corresponds to a rating of ‘sleepy, but no difficulty remaining awake’.
  31. An effectiveness score of 90 corresponds to a person getting normal sleep periods of 2300–0700 being awake at 2300 (awake for 16 hours). The criterion line (77.5) corresponds to the person being awake at 0700 (awake for 24 hours). The start of the red zone (65) corresponds to being still awake at 2300 (awake for 40 hours).

Safety analysis

Introduction

On 5 November 2018, a BHP loaded ore train M02712 was approaching an access road level crossing near Garden South. Shortly after, there was an unplanned interruption of trainline communications, which triggered an emergency brake command to the electronically controlled pneumatic braking (ECPB) system.

The train came to a stop on the -1.5% falling track grade approaching Garden South. The train was subsequently not effectively secured on the falling grade and, about 60 minutes after the ECPB’s system-initiated brake command, the train started rolling away without the driver on board. M02712 travelled for about 91 km before Hedland train control purposely derailed the train at Turner South. The derailment destroyed the 2 remote locomotives, 245 ore cars and 2 km of track infrastructure. There was no injury to any person from the runaway or derailment.

A train runaway can cause injury or loss of life, substantial damage to rolling stock and infrastructure, and disrupt rail operations for an extended period. Accordingly, rolling stock operators and rail infrastructure managers need to implement sufficient preventative and mitigating controls to manage this hazard. 

In this case, a number of safety factors contributed to train M02712 not being effectively secured. This analysis will initially discuss some limitations in BHP’s initial integration of the ECPB system with related systems and its subsequent risk assessment of the potential for a runaway event to occur. It will then discuss limitations with the design and introduction of the emergency procedure for responding to a loss of trainline communications, before discussing the loss of trainline communications involving M02712, the driver’s response to the emergency, and the inability of the automatic train protection (ATP) system to stop a runaway train in this situation. The analysis will then discuss a number of other factors that increased safety risk identified during the investigation, including the use of three-step protection, emergency response arrangements and fatigue management. 

ECPB system integration

In 2011, BHP commenced the process to implement ECPB on its main line operations due to its many advantages over conventional pneumatically-braked trains, and it elected to implement it as an overlay system in order to provide operational flexibility. The implementation involved integrating the ECPB system with other onboard systems, including the pneumatic braking system and the ATP system.

BHP’s introduction of ECPB involved numerous assessments, trials and other activities over an extended period prior to commencing main line operations with ECPB overlay trains in 2015. However, during this period it did not identify and manage 2 significant characteristics that affected how the ECPB system integrated with these other systems. More specifically, when a train was in service, operating in ECPB mode, and there was a break in the trainline resulting in the end of train monitor (EOTM) displaying ‘off’:

  • The car control devices (CCDs) rear of the point of break in the trainline would shut down and release their brake application 60 minutes after the loss of communications with the head end unit (HEU) locomotive.
  • In the event the CCDs shut down, and the train was not effectively secured against unintended movement, any subsequent automatic train protection (ATP) penalty requests to the ECPB system would be ineffective in stopping the uncommanded movement. In ECPB mode, the ATP system detecting the on-going movement could not then cause a dump of brake pipe pressure to initiate a brake application to the train via the brake pipe.

Consequently, BHP’s trains configured for ECPB operation were potentially vulnerable to a runaway event should the following combination of events and conditions occur:

  • The train was on a descending or ascending grade (which existed at various locations within the BHP Pilbara iron ore rail network).
  • There was a loss of trainline communications, resulting in the EOTM displaying ‘off’.
  • The loss of trainline communications occurred towards the front of the train, meaning a greater proportion of the CCDs in the train would shut down after 60 minutes.
  • The train pneumatic brake pipe remained intact and charged.
  • The driver did not place the automatic brake handle in the pneumatic emergency position (to dump the brake pipe air).
  • There was insufficient time for the driver and other personnel to apply the required number of handbrakes to secure the train.
  • The driver (or other rail safety worker) was not on board the train and able to apply emergency braking pneumatically when the train started rolling away.

This scenario was effectively what occurred on 5 November involving M02712, as will be outlined in more detail below in later sections.

The only control preventing this scenario resulting in a runaway was if the driver, in response to the emergency, placed the automatic brake handle in the pneumatic emergency position. However, up until April 2017 (see next section), this action was not a required part of BHP’s procedure for responding to this type of emergency. Even after the procedure was amended to include this action, the system was still vulnerable as it relied on the effectiveness of a single administrative (procedural) control, and a simple omission by a driver of one action in the procedure could still result in a runaway event.

The specific reasons why the 2 significant characteristics were not effectively identified and/or managed during BHP’s implementation of ECPB were not able to be determined. However, as recognised by BHP itself, the rolling stock operator did not have a systems engineering framework in place during the introduction of ECPB and the integration of ECPB with other related systems. Instead, BHP predominately managed the implementation of its electrically controlled pneumatic brake (ECPB) overlay and modification of automatic train protection (ATP) systems at an individual system level. The use of a systems engineering framework provides a structured approach to manage the risk of designing and implementing complex systems, and increases the likelihood that hazards associated with the integration of a new system with other systems will be effectively identified and managed.

Application of risk management processes

Risk assessment of train runaway events

Although BHP did not effectively use a systems engineering framework during the implementation of the ECPB overlay system to manage the potential risks associated with using that system, it did have established risk management and associated management of change procedures in place as part of its safety management system. These processes involved identifying, assessing and managing ‘material’ (or significant) risks in its operations. As part of this process, critical preventative and mitigating controls for each risk event were identified, which then enabled management to focus oversight on these controls to prevent or mitigate the potential consequences from the risk event.

BHP had identified a rail-mounted equipment (RME) interaction incident as a risk event, and the associated risk assessment (presented in a bow-tie format) showed that one of the potential causes of such an incident was an uncontrolled or uncommanded movement of a train or other RME. Although this risk assessment process provided the opportunity to identify a loss of trainline communications and its response to be a cause of an RME interaction incident, this did not occur. Overall, there were several limitations with the overall nature of the resulting risk assessment. More specifically:

  • The range of events covered by an RME interaction incident was very broad, including events associated with shunting in yards, conducting maintenance on rolling stock, and operation of hi-rail and maintenance vehicles as well as main line train operations. Such a broad scope increased the potential that insufficient focus would be placed on some specific types of events (such as a train runaway event).
  • The risk assessment (and the risk assessment process) generally focused on health and safety considerations. Although preventing fatalities is paramount, this focus likely biased the identification and assessment of preventative controls toward addressing the risk of a worker fatality during rolling stock maintenance and repair activities, and limited the focus on a range of other operational circumstances that could give rise to the potential for a train runaway event on the main line.
  • The range of failures and events that could lead to an uncontrolled or uncommanded train movement was not articulated in any meaningful detail. Although ‘brake failure’ and ‘failure to secure vehicle against movement’ were listed, a wide range of scenarios could result in either, many of which would require different sets of critical controls.
  • A set of critical controls was identified for the uncontrolled or uncommanded movement of a rail vehicle, and these focussed on the competence of the workers involved, the three-step protection process and rolling stock maintenance. However, there was no reference to the procedures associated with responding to a brake pipe emergency or penalty. In addition, none of the controls appeared to specifically focus on preventing a train runaway on the main line.
  • None of the causes or critical controls focussed on the ECPB system or the integration of this system with other related systems, such as the ATP system.
  • The ATP system failing or being overridden was listed as one of the potential causes of an RME interaction incident, but there was no reference to potential conditions where the ATP would operate as designed but be ineffective. ATP was also included as a critical preventative control, but not for the prevention or mitigation of an uncontrolled or uncommanded rail movement. Overall, ATP appeared to be treated as an individual system, and potential limitations in its interaction with other systems were not articulated.
  • Vendors modifying the ATP system for the dumper automated spotting of locomotives (DASL) system project submitted a series of safety-related application conditions (SRACs) to BHP in 2013, 2015 and 2016, which included reference to various conditions that could potentially lead to unintentional train movement. There was no indication that this safety-related information was integrated into the risk assessment.

Ultimately, the risk assessment served an important role in identifying important critical controls and ensuring appropriate management attention was focussed on verifying the integrity of these controls. However, the broad scope and general nature of the risk assessment in this case was not well suited for identifying and managing risk associated with the integration of complex systems, and it was not well suited for managing the risk of an ECPB train runaway.

Management of critical controls for responding to brake pipe emergencies

On 27 March 2017, the driver of another loaded ore train reported an ECPB 120% penalty brake application at Garden with the EOTM displaying ‘off’. The driver responded to the event by generally following the procedure for responding to brake pipe emergencies and penalties that was applicable at that time, contained in operations instruction OI 17-09.

Although a runaway did not occur on that occasion, later investigation by BHP maintenance personnel found that ore car CCDs would release their brake application under certain conditions. Information about the 60-minute shut-down feature of the CCDs, and the need to either secure the train or cut out the ECPB system during this period, had been available in sources such as the applicable Association of American Railroad (AAR) standard (S-4200). However, BHP personnel only appeared to recognise the potential significance of this designed characteristic following the March 2017 event.

After consultation with the equipment supplier, BHP personnel concluded that an added procedural control was essential in such situations to prevent the potential for a runaway to occur (that is, moving the automatic brake handle to the pneumatic emergency position to dump the brake pipe air). This learning resulted in BHP publishing OI 17-11 on 5 April 2017. The instruction contained the new requirement for drivers to secure all portions of the train by placing the automatic brake handle in the pneumatic emergency position, in conjunction with fully applying the independent brake and then manually applying handbrakes.

In effect, BHP was now aware of another ‘cause’ that could lead to an uncontrolled or uncommanded train movement, and it had also identified a critical preventative control to reduce the risk. Although published in OI 17-11 however, this critical control was not subsequently incorporated into the risk assessment for an RME interaction incident. Consequently, the effectiveness of the control was not evaluated as part of BHP’s normal risk management processes, including a control design assessment (CDA) and the verification activities associated with a material risk control assessment (MRCA).

Following OI 17-11 being published (5 April 2017), 2 scheduled MRCAs for the RME interaction incident risk event occurred in September 2017 and February 2018. Although records showed the assessment of various factors, there was no record showing consideration of the effectiveness of OI 17-11 in managing the associated risk during these activities.

A systematic assessment of the critical control associated with the procedure in OI 17-11 would have provided an opportunity to review relevant ECPB-related failures, and the associated BHP investigations and/or event recorder data, to determine the degree of driver compliance and overall understanding of the criticality of complying with the procedural controls in the instruction. However, such an assessment was not done at the time.

Following the runaway of M02712, BHP selected and reviewed 14 related events (including that involving M02712), finding 9 occasions where the driver had not followed the procedure and placed the automatic brake handle in the pneumatic emergency position. This included 6 events at locations with the potential for a runaway. By not examining these previous 13 events in a systematic manner at the time, a significant opportunity was missed to identify problems with the application of the critical control and take action to ensure it was being implemented more effectively prior to the 5 November 2018 runaway occurrence.  

Summary

Although BHP’s risk assessment for an RME interaction incident identified numerous causes and critical controls for such an incident, it was broad in scope and had limited focus on the causes and critical controls for a train runaway event. In addition, it did not include the procedure for responding to brake pipe emergencies and penalties as a critical control, and its MRCAs did not test the effectiveness of this procedural control for preventing an uncommanded movement of a train on the main line.

The March 2017 event provided a valuable opportunity for BHP to identify the vulnerability to a runaway event associated with the ECPB overlay system’s integration with other systems. BHP used this opportunity to identify a missing critical (procedural) control and implement that control. However, it had not ensured that the control was effectively implemented (see also next section).

In addition, BHP did not effectively use the opportunity from the March 2017 to revisit the ECPB system’s integration with related systems to assure itself that it had effectively controlled the risk of a runaway event involving an ECPB train. The use of conventional risk assessment processes to identify problems in the integration between complex systems would probably been of limited effectiveness for this purpose. However, using a systems engineering approach (and methods) at this point would have increased the likelihood for identifying situations where the ATP system would be an ineffective control for stopping a train that had commenced rolling away following an ECPB emergency braking application.

Prior to the March 2017 event, the potential of a risk assessment using a conventional risk assessment approach to identify problems with the integration between complex systems would probably also have been limited, particularly when the risk assessment for RME interaction incident was so broad in nature. The use of a systems engineering approach (and methods) as part of the risk assessment process, particularly if the risk assessment was more focussed on the conditions or sequence of conditions that may cause runaway events, may have increased the potential to identify system limitations during that period.

Design and introduction of procedures for responding to brake pipe emergencies

Overview

In addition to the procedure for responding to brake pipe emergencies and penalties not being included in the risk assessment for an RME interaction incident, there were other problems with the way OI 17-11 was designed and introduced in April 2017. These included the application of processes for making the change, the resulting format of the change or design of the instruction, and the way the change was communicated to drivers. In addition, there were problems with the frequency of procedural changes and the design of the overall task of responding to brake pipe emergencies and penalties.

Application of processes for changing operating instructions

When issuing an operating instruction that made changes related to BHP’s rail rule book, the initiator was required to involve stakeholders, undertake a risk assessment and apply the management of change (MoC) procedure. For complex changes, relevant stakeholders were also required to be provided with an information package about the change.

BHP acknowledged a new rule implemented via an operating instruction would typically involve these processes, but it had allowed flexibility in the adoption of the processes, dependent on the extent or intent of the change. A determination not to implement the required processes would probably be reasonable when undertaking minor wording changes to an existing process to improve clarity.

As noted in the previous section, OI 17-11 introduced a new action requiring drivers of an ECPB train who experienced a loss of trainline communications with the EOTM displaying ‘off’ to move the automatic brake handle to the pneumatic emergency position. Although the change involved amending a single procedural step (or dot point), it introduced a safety-critical action, and therefore should not have been considered as a minor change.

However, BHP were unable to provide documentation that showed a risk assessment or change management process. Similarly, BHP were unable to provide a record of a determination of the extent or intent of the change that led to a decision not to adopt the required processes. A similar situation had also occurred with the introduction of OI 16-16, which replaced the applicable rule book procedure in full to include ECPB trains.

Design or format of the operating instruction

With regard to the resulting format of the change introduced in OI 17-11, and the way the change was communicated within the instruction:

  • No note with warning or caution information (using an appropriate symbol) was included in the instruction to indicate the importance of the new action, or the criticality of the consequences if the action was not completed. Such information can help focus attention on, and ensure better recall of, a procedural change.
  • No information was provided in the instruction regarding the reason for the change. Explaining why a change has been made is widely regarded as an essential part of implementing procedural changes (Barshi and others 2016, Degani and Weiner 1994). In addition, having a detailed mental model or understanding of a system facilitates better performance in a range of situations (Wickens and others 2015), including better recall of procedures (Kieras and Bovair 1984). For example, including information about the CCDs’ 60-minute shut-down feature would have highlighted the feature and enabled drivers to incorporate this information into their mental model of how the system worked and needed to be managed when responding to emergency situations.
  • The amended procedural step was presented in a red font. Although this colour increased the text’s potential salience relative to other procedural steps, the use of red font in this way was not consistent with how changes were indicated in previous operating instructions (normally in yellow highlight), and it was not consistent with how important procedural steps were indicated in previous operating instructions (normally in bold). Red font was also used elsewhere in the instruction for other purposes.
  • The amended procedural step included 3 actions: moving the automatic brake handle to the pneumatic emergency position, fully applying the independent brake, and manually applying the required handbrakes. The second 2 actions had not changed from previous versions of the instruction, yet they were also presented in red font; this reduced the potential salience of the new required action.
  • Although all 3 actions were associated with securing a train, they were distinct actions and could have been more usefully presented as separate procedural steps (or dot points). Guidelines for writing procedures include keeping sentences short and presenting each action on a separate line (for example, Barshi and others 2016).

In summary, although the new action in the procedure was presented in red font, it was not necessarily salient, and the instruction did not clearly state the importance of the new action and the reasons why it was introduced or important.

Other communication processes

In addition to the dissemination of the operating instruction itself, BHP communicated information about changes to procedures or instructions through supervisors providing safe start briefings. The extent to which the change introduced with OI 17-11 was discussed in safe start briefings was not able to be determined as BHP was unable to provide a copy of the relevant briefing sheet. However, based on the nature of the information in the safe start briefing sheets following other changes to the operating instruction (such as OI 17-09 or OI 18-72), it is unlikely there was any information provided to drivers that was not contained in the instruction itself.

Although it was a supervisor’s responsibility to ensure drivers receiving the information in a safe start briefing understood its content, the practice of disseminating information through the briefings did not address how the supervisor would satisfy themselves of the drivers’ level of understanding of the information, other than obtaining a signature from the recipients acknowledging receipt of the information.

As well as safe start briefings, BHP also conducted driver reaccreditation training and assessment at regular intervals. This provided an opportunity to undertake structured training and assessment of drivers’ understanding of operational rules and procedures that had changed during the accreditation period. The most recent reaccreditation assessment undertaken by the driver of M02712 (in August 2018) included questions related to ECPB operation and the required response to various fault conditions, including that associated with the EOT ‘off’. Although the driver answered that question correctly, it is noted that the question did not refer specifically to an emergency brake application or securing the train, and the nature of any associated classroom discussion on the topic prior to the assessment could not be determined.

Overall, it is unclear to what extent BHP’s drivers were provided with information about the procedural change introduced in OI 17-11 other than what was in the instruction itself. However, the fact that 9 of 14 drivers who were required to use the procedure did not move the automatic brake handle to the pneumatic emergency position is consistent with many drivers not being provided with clear and relevant information about the importance and reasons for the change.

Frequency of procedural changes

BHP used operating instructions to communicate new and amended procedures to drivers during and following the commencement of ECPB operations rather than update the relevant module in the rail rule book. Overall, 13 separate instructions relating to brake pipe emergencies and penalties were issued in the 3 years between February 2014 and April 2017, with a further revision issued with OI 18-72 just prior to the 5 November 2018 occurrence. The only operating instruction that was subjected to assessment under the BHP management of change procedures was OI 17-09.

Frequent procedural changes can increase memory demands when trying to correctly recall the latest version and not confuse some of the steps with previous versions. When under stress, people can also revert to previously learned skills or versions of a procedure (Barshi and others 2016). In addition, frequent changes to procedures can lead to personnel believing their operator’s system is unstable, which may diminish the importance they attribute to any changes (Degani and Weiner 1994).

Design of the task for responding to brake pipe emergencies

The overall design of the task of responding to brake pipe emergencies and penalties also placed significant memory demands on a driver and increased the likelihood of them not correctly remembering all of the required procedural steps. More specifically:

  • The task required drivers to remember a different set of procedural steps for several different situations – depending on whether it was an ECPB or pneumatic train, whether it was a brake pipe emergency or a penalty, the extent of the train brake command (TBC), and whether the train was moving or at a stand. Although drivers were required to familiarise themselves with the procedure (and any changes as they were issued), they were not required to carry a copy with them and a copy was not provided on each train.[42] Referring to a procedure, checklist or job aid is a very well-known and reliable method for minimising errors of omission, particularly for rarely-performed tasks that do not need an immediate response (Wisher and others 1999, Sanli and Carnahan 2018, Barshi and others 2016).
  • Drivers were rarely required to conduct the task while operating a train and they were not provided with opportunities to practice the task. The term ‘skill decay’ (or skill fade) refers to the loss of trained or acquired skills or knowledge following periods of non-use (Arthur and others 1998). Skill decay increases as the retention interval (or time since learning) increases, and it also increases depending on the quantity and quality of the initial and recurrent training and the amount of on-the-job exposure (Arthur and others 1998, Sanli and others 2018, Vlasblom and others 2020).
  • The procedure required a set of discrete actions, many of which did not provide meaningful cues or feedback to prompt the next action in the procedure (including the application of the automatic brake). This type of procedural task is more likely to be associated with skill decay than many other types of tasks (Goodwin 2006, Sothard and Nicholson 2001, Wisher and others 1999).
  • There was no process in place to cross-check the performance of a driver who was conducting the task. Research has shown that errors of omission are often difficult to detect by the people who make them (Sarter and Harrison 2000). In safety-critical systems, human error will occur and such systems need processes in place to not only reduce the likelihood of errors but also detect and recover from them. This would ideally involve some form of engineered risk control providing feedback to indicate that an important action had not been completed. Alternatively, the task could have been designed to require another person to cross-check a driver’s performance. In the case of responding to a brake pipe emergency, the train controller was the person best placed to ensure specific actions were completed, as they were already involved in communications with the driver and determining the number of handbrakes required.

Summary

OI 17-11 introduced a simple yet safety-critical action for drivers to complete in the event of a loss of trainline communications resulting in the EOTM displaying ‘off’. However, BHP did not follow its defined processes for making the procedural change, and the extent to which the resulting OI 17-11 was reviewed or assessed prior to being issued was not able to be determined.

Overall, the task of responding to brake pipe emergencies and penalties relied extensively on a driver’s memory, with limited processes in place to facilitate or cross-check a driver’s performance to ensure all safety-critical actions were completed. In addition, although OI 17-11 (and subsequently OI 18-72) contained a safety-critical action (to apply the automatic brake handle to the pneumatic emergency position), BHP did not clearly communicate the importance and reasons for this action to drivers, reducing the potential for drivers to correctly recall the action, particularly given the context of many previous changes to operating instructions and the low frequency with which the task was required to be conducted.

Loss of trainline communications on M02712

As previously noted, a loss of trainline communications resulting in the EOTM displaying ‘off’ was a fault condition (in combination with other events and conditions) that could result in a runaway event involving an ECPB train. A break in the trainline could occur due to a variety of reasons at any connection point along the train and at any time.

In the case of M02712, recorded information showed that the loss of trainline communications occurred at 0338 as the train was approaching Garden. The communications loss was due to a problem with one of the inter-car connectors towards the front of the train. The driver recalled seeing a disconnected inter-car connector at about ore car 10 in the first rake. Train M02712 had primarily NYAB (square type) connectors installed but it also had 12 WABTEC (round type) connectors installed, which were under trial on ore cars 2 to 8 in the first rake. The driver’s description of the connector, and its relative location in the first rake of ore cars, was consistent with the disconnection involving a WABTEC type connector.

Based on the available information, the exact mechanism that led to the disconnection could not be determined. The driver’s description was consistent with the connector simply disconnecting. The event occurred as the train passed over an access road level crossing, and it is possible that the connector was hanging too low after the ore car was loaded, and it contacted infrastructure at the level crossing, resulting in the disconnection.

Consistent with the ECPB system’s design, the loss of trainline communications triggered a 120% train brake command (TBC) emergency brake application, applied the emergency brake interlock, and disconnected the trainline power feed. The automatic brake was then held by the interlock but only for a limited time period. For the ore cars rear of the point of break (in this case most of the train), the CCDs shut down after 60 minutes and released their brake application.

The loss of trainline communications occurred at Garden South and the track gradient was -1.5%, the steepest gradient of the section between Yandi Junction and Nelson Point. This meant that to secure the train using handbrakes, which was required before commencing work to repair the train, the handbrakes on all 268 ore cars had to be applied, which would take much longer than 60 minutes. Consequently, unless the driver moved the automatic brake handle to the pneumatic emergency position, the train would commence rolling away.

In summary, while train M02712 was approaching Garden and on a descending grade, one of 12 inter-car connectors undergoing a trial near the front of the train disconnected. This caused a loss of trainline communications and an emergency brake application. It also resulted in the CCD on each of the ore cars rear of the break in the trainline initiating an in-built 60-minute shut-down feature.

In addition to limitations related to the introduction of ECPB overall, there were also related limitations with the introduction of the trial connectors. BHP managed the introduction of the WABTEC type connectors in 2018 through its management of change process, with the trial commencing on 1 November 2018. The management of change process included a risk assessment, which considered the potential for adverse operational outcomes from the failure of a trial connector. This was likely in recognition of the unknown performance characteristics of the connector when fitted to the BHP ore cars at that time. The forecast consequence from the assessment was principally a financial loss arising from main line service interruptions while recovering from the failure.

The risk assessment for the trial did not consider other potential operational risk factors, such as an RME interaction incident (or train runaway), that could potentially arise from a loss of trainline communications. It also did not consider the relative risk of a failed connector at the front of the train compared to at the rear of the train.

It is likely that locating the ore cars with the trial connectors toward the front of the train was either to provide ready access for the driver to repair a connector fault if it occurred (after securing the train), or as a consequence of shunting the 7 ore cars into a 134 ore car rake and then marshalling the rake for introduction into the train service. Regardless of the reason, the location of the trial inter-car connectors at the front of train M02712 introduced an unrecognised hazard, as it meant that if there was a problem with one of the connectors almost all of the train would not be in communication with the HEU and the CCDs would shut down after 60 minutes. Overall, the absence of a documented consideration of this issue in the trial’s risk assessment was consistent with BHP personnel still not fully understanding the limitations and constraints associated with the integration of the ECPB system with other systems.

Driver response to the loss of trainline communications

In response to an ECPB emergency brake application when moving, with the EOTM displaying ‘off’, the applicable operating instruction required a driver to follow a number of procedural steps prior to commencing an inspection to identify and rectify the fault condition. From April 2017 (in OI 17-11 and subsequently in OI 18-82), these steps included:

  • declare an emergency
  • advise train control of relevant details (including location)
  • request protection of adjacent tracks
  • secure all portions of the train by placing the automatic brake handle in the pneumatic emergency position, applying the independent (locomotive) brakes, and manually applying handbrakes as confirmed by train control.

On the 5 November 2018, the driver of M02712 contacted train control to declare an emergency and provided relevant details. The driver also applied the locomotive independent brake. The controller placed blocks of the adjacent track for protection, and the controller and driver then had discussions to determine the exact location of the train and therefore the amount of handbrakes required, after which the driver centred the reverser and turned the generator field off before leaving the locomotive to commence applying the handbrakes to the first rake of ore cars.

As already noted, a critically-important action for responding to this type of fault condition was to move the automatic brake handle to the pneumatic emergency position (to dump the brake pipe air). As evidenced by the recorded data, the driver omitted this action, and therefore the critical control in the procedure was not implemented. Accordingly, following the CCDs on most of the ore cars shutting down after 60 minutes (consistent with the way they were designed) and insufficient handbrakes having been applied at that time, the train commenced rolling away on the descending grade.

In effect, the driver omitted one action in one step in the procedure. Omitting a step or an action is one of the most common forms of human error (Reason 2002), and it can occur due to a wide variety of reasons. In this case the omission was likely associated with the inherent limitations of long-term memory, the driver’s understanding of the relevant systems and the way the procedural change introduced in OI 17-11 was communicated to drivers.

More specifically, although the driver had received OI 17-11 and OI 18-72, and was required to familiarise themselves with the contents, the driver had not had to apply the procedure for this type of emergency fault condition before and had no previous opportunity to practice the required response, increasing the likelihood of skill (or knowledge) decay. The driver also did not have a copy of the procedure to refer to when doing the task, and the instruction itself did not clearly indicate the importance of the action or the reasons why it was introduced, reducing the potential for correct recall. In addition, the driver stated they were not made aware of the ECPB system’s 60-minute shut-down feature. As previously discussed, the frequency of procedural changes and the overall design of the task also placed significant memory demands on a driver.

The ATSB considered a range of other explanations for the driver’s omission, including fatigue (see Driver fatigue), time pressure and distraction. Applying the automatic brake at the same time as the locomotive brake would be consistent with the design of the procedure (that is, both actions were contained in the same procedural step). At that time, it is unlikely that time pressure or distraction was a factor. However, the driver also had subsequent opportunities to place the automatic brake handle into the pneumatic emergency position when waiting for advice from train control and when completing the tasks within the three-step protection process. During that period, the driver’s attention may have been distracted by communications with train control and the additional task of obtaining an exact marker for the train’s position. It is also possible the driver was experiencing a degree of perceived time pressure to start resolving the situation. However, without having the appropriate knowledge of the 60-minute shut-down feature, it is unclear whether the driver spending additional time reviewing the situation and their actions would have led to them identifying the need to move the automatic brake handle to the emergency position.

In summary, when applying the emergency procedure for responding to a loss of trainline communications with the end of train monitor displaying ‘off’, the driver did not place the automatic brake handle into the pneumatic emergency position, which would have vented the brake pipe pressure to zero and applied the train brakes via the pneumatic system in addition to the system-initiated ECPB application.

The driver was conducting the procedure from memory, and their memory of the procedure could have decayed or been affected due to a range of factors associated with the way the overall task was designed and the way the change in the operating instruction was designed and introduced. As noted in Design of the task for responding to brake pipe emergencies, for rarely-performed tasks that do not need an immediate response, being provided with a copy of the procedure or a checklist and being required to use it, or having another person review their actions, would have been effective ways of ensuring that the driver did not omit any critical actions when performing the procedure.

Recovery controls – integration between ATP and ECPB

After M02712 commenced rolling away at 0440, without the driver on board, there was no recovery control available to stop the train in this specific situation, other than forcing a derailment.

As already noted, BHP’s trains were fitted with an automatic train protection (ATP) system. This system was designed to apply penalty braking to a train in certain conditions, such as if there was an uncontrolled / uncommanded roll away of the train. More specifically, when a locomotive was stationary with its reverser in the neutral (centre) position and the ATP detected a movement of more than 0.5 m, the ATP requested a penalty braking application to stop the rollaway. In addition, If the locomotive exceeded the target speed limit, alarms would sound to prompt the driver to reduce speed. If this did not occur (such as if there was no driver on board), the ATP system automatically communicated with the braking system to request a penalty brake application to stop the train.

For train M02712, the ATP system functioned as designed, and it made the appropriate requests for penalty braking after it started rolling away and then when it exceeded the relevant speed limits. However, given the situation that existed for M02712 on 5 November 2018, these requests from the ATP system were ineffective in initiating any braking.

As discussed earlier, this was associated with the way the ECPB system was integrated with the ATP system. In the event the CCDs shut down, and a train was not effectively secured against unintended movement, any subsequent ATP penalty commands to the ECPB system would be ineffective in stopping the uncommanded movement. In other words, the ATP system and the ECPB system on BHP’s trains could not interface to dump brake pipe pressure if an ECPB emergency or penalty brake application became ineffective in arresting an uncommanded train movement.

BHP had likely weighted the ATP system heavily as an engineered control that would prevent or recover events where a train moved uncommanded, travelled at excessive speed or outside the limit of authority. However, as discussed in earlier sections, BHP had not identified the limitation with the integration between the ATP and ECPB systems during its implementation of the ECPB overlay system, and its investigation into similar events involving drivers response to a 120% brake pipe emergency with EOT off, or in association with subsequent risk assessments for an RME interaction incident. 

Three-step process for accessing rail-mounted equipment

BHP’s three-step protection process was required to be applied before conducting work on any train, and it provided another control against an uncommanded or uncontrolled train movement. The driver of M02712 applied the three-step protection tasks shortly after the train stopped at Garden, initially applying the independent brake, then later placing the reverser to the neutral position and opening the generator switch.

The instructions in the Rail Rule Book module 1 included an additional requirement for the driver to apply the train brake (automatic brake) where the gradient of the track and/or weight of the train may allow the vehicles to move. However, this requirement likely related to the context of securing the train when undertaking tasks such as train crew changeover or rolling stock inspection, and not specifically in response to a brake pipe emergency and penalty (where the applicable procedure was published separately in a series of operating instructions). In addition, in the case of M02712, the driver was aware that the ECPB interlock was already applying a 120% TBC or maximum braking effort.

The three-step protection process not only involved the driver, but also placed responsibilities on the workers seeking to access the rolling stock profile. In this case, the responsible person for the worksite was required to contact the train driver to request and confirm the application of three-step protection before entering the rolling stock profile to apply handbrakes. The Redmont maintenance gang arrived at the 210 km mark and the driver of M02712 was some distance away, already applying handbrakes near the front of the train. There were radio communications between the controller and the maintenance gang, and communications between the controller and the driver, and the controller had advised the gang and the driver to contact each other. However, at no stage did the gang directly communicate with the driver to confirm the application of three-step protection.

On arrival, the gang mistook the rear of an unloaded train (M02727), which was stopped on the eastern track at Garden South, to be the loaded train M02712, which was stopped further south on the western track, and the gang started applying the handbrakes on the wrong train. Ultimately, this error did not contribute to the runaway of M02712, as the gang would not have had time to apply sufficient handbrakes prior to the end of the 60-minute period after the loss of trainline communications. Nevertheless, applying handbrakes to the incorrect train increased the risk of injury to personnel working on the rolling stock.

The train controller tasked the Redmont gang to attend M02712 at Garden South. There is no record of the train controller advising the gang of the later arrival of the second train at Garden south (M02727), which was coincidentally stopped at that location due to the protections placed by the controller. Therefore, it is likely the gang were unaware that a second train was at Garden south. However, direct communication between the gang and driver in relation to the application of three-step protection and arrangements for the application of handbrakes would have provided an opportunity to identify the error made by the gang.

Emergency response – interface coordination

Following the notification by the driver of M02712 of the emergency braking event, the train controller coordinated the internal arrangements for protecting the train, dispatching other support personnel and communicating with the driver at 10-minute intervals. After notification by drivers that M02712 had run away, the controller continued to monitor the welfare of the driver and support personnel. In addition, the controller applied additional protections in an attempt to stop the movement of train M02712, and alerted the drivers of other trains ahead of the evolving situation before instructing them to stop and move to a position of safety.

In general, the train controller’s actions were consistent with the requirements of the rules and procedures for responding to an emergency of this type. The ensuing internal communications between the controller and field personnel supported the safety of BHP operational personnel who were or had the potential to be affected. 

In addition to communicating internally within BHP’s operations, there was also a requirement to communicate with external parties. The Newman to Port Hedland railway had several locations where an interface occurred between BHP and an adjoining rail infrastructure manager (RIM), pastoralist/local government, or a manager of a public or private road. The associated interface agreement with each party detailed the responsibilities for the notification of accidents, incidents or near misses that occurred which had the potential to increase risk to either party at the interface. However, the agreements did not include requirements related to notifying the other parties, including other RIMs’ train control, of an event in progress on the network that had the potential to increase risk at an interface, such as a runaway.

Train M02712 travelled uncontrolled and at speed for about 91 km, traversing several locations where BHP’s railway interfaced with other parties. Two of these locations interfaced with another RIM, where a similar heavy-haul railway passed over the BHP’s railway via bridge infrastructure. BHP risk assessments identified the potential for damage to rail overpasses arising from the derailment of a BHP train due to an overspeed. Neither the train controller or a BHP supervisor or superintendent contacted the parties that interfaced with the section of the railway affected by the runaway of train M02712. Had they been informed, the other RIMs’ train control could have ensured that ensured that rail vehicles and personnel on their networks were positioned away from potential risk associated with the runaway train.

Fatigue and fatigue management

Driver fatigue

Determining whether a person is experiencing a level of fatigue that is likely to adversely influence performance involves considering the amount of recent sleep and work and a range of other factors. With regard to M02712:

  • The driver was conducting the sixth of 7 12-hour night shifts from 2200–1000. They recalled getting about 4–5 hours sleep following each night shift, and overall about 5–6 hours sleep in total during each break between night shifts. This appeared to be consistent with, or slightly more than, what would be expected based on the available research for this type of shift (see Appendix B). Most people need at least 7–8 hours of sleep each day to achieve maximum levels of alertness and performance, and research has shown that restricting sleep to 6 hours or less a night over several nights will result in significant performance decrements (Banks and Dinges 2007, Watson and others 2015).
  • The train stopped at Garden at about 0340 in the morning, which is during the window of circadian low (0200–0600) for a person with a normal sleep-wake cycle. Although the driver was completing their sixth night shift, it is unlikely that their sleep-wake cycle had significantly adapted during this period. People exposed to a significant amount of sunlight each morning are unlikely to shift their sleep-wake cycle (Smith and Eastman 2012), and in this case sunrise in the Yandi to Port Hedland area was occurring at about 0715 in the morning and the driver was probably getting to bed at about 1100 following each night shift.
  • The driver had risen early (about 0230 in their established sleep-wake cycle) to travel from Adelaide to the Yandi camp prior to their first night shift. Although they were provided with 5 hours opportunity to settle in upon arrival at the camp, it is unlikely that they would have obtained sufficient sleep to overcome their initial sleep debt prior to the first night shift.
  • The driver reported that they found a roster pattern with night shifts commencing at about 2200 the most difficult for obtaining sleep. This pattern equated to a start time of 2330–0030 in their established sleep-wake cycle when they first arrived at the camp.
  • The driver reported that they were ‘a little bit tired’, but research indicates that people will generally underestimate their level of fatigue (Battelle Memorial Institute 1998). In addition, people underestimate the impact of several days of sleep restriction (Banks and Dinges 2007, Watson and others 2015).
  • The driver was conducting a single-driver operation, and would normally expect to have a 30-minute rest break after about 6 hours. On the day of the accident, the rest break had not yet occurred and would not have occurred until about 0500 as there was a delay before train M02712 became available.
  • Biomathematical modelling, using 3 different models, indicated that an average person working the driver’s roster pattern would have a significant level of fatigue during the last 3 of the 7 night shifts. All models have assumptions and limitations and use different inputs, and they do not consider all the factors that can influence fatigue. However, in this case it is noteworthy that the indicated levels of fatigue were significant and consistent across the 3 models.
  • In a FIFO work environment, workers generally have less domestic demands and distractions and need to conduct fewer non-work tasks. In this case, it is also unlikely the driver’s sleep was disrupted by the quality of the accommodation or other local factors. In addition, the driver only had short commute times between the accommodation and signing on for work. Although these contextual factors will have facilitated the driver’s ability to utilise their available sleep opportunities, they will not have been sufficient for most people to overcome the fundamental problems associated with restricted sleep and related factors, such as the time of day.

In summary, due to cumulative sleep restriction over several days of night shifts, the time of day (0340) and other factors, the driver was probably experiencing a level of fatigue known to adversely influence performance when the train came to a stop at Garden. 

Fatigue can have a wide range of impacts on human performance, and the driver’s level of fatigue would have increased the likelihood of making errors when performing many types of tasks, including those involving the use of working memory (Goel and others 2009). However, although some research has shown that fatigue can increase errors associated with retrieval from long-term memory, the results are inconsistent (Alhoha and Polo-Kantola 2007).

Overall, the extent to which fatigue contributed to the driver’s error of not moving the automatic brake handle to the pneumatic emergency position could not be determined. As previously discussed, that error was likely related to the driver’s understanding of the relevant systems and the manner in which the operating instructions were presented. It is also noted that a number of other drivers had made a similar error, and the extent to which they may have been experiencing fatigue was unknown. In other words, although fatigue increased the likelihood of making an error, it is unclear from the evidence available whether the driver’s error would still have occurred on this occasion if the driver had been experiencing a lower level of fatigue.

Management of rosters and fatigue risk

BHP's fatigue management processes required its train drivers to be rostered on 7 12-hour shifts, followed by a 24-hour break and then 7 12-hour shifts, with the roster pattern commencing at all times of the day. As previously noted, research has shown that roll-over roster patterns or swings that include 7 consecutive 12-hour night shifts present an elevated risk of fatigue, particularly in environments where it is unlikely that workers will adapt their sleep-wake cycles. This risk is further exacerbated depending on the timing of the shifts, with night shifts ending in the late morning likely to lead to the least amount of sleep.

Given this fatigue risk potential, BHP needed to have processes in place to provide assurance that its drivers could actually obtain sufficient sleep between shifts (as well as obtain sufficient rest during shifts) to maintain adequate levels of alertness when carrying out their safety-critical tasks. BHP had recognised that its roll-over roster patterns for WAIO train drivers were problematic and, even with a set of control measures, assessed the associated risk level was ‘high’ (compared to a raw risk level before treatment of ‘extreme’).

Some of the specified control measures were clearly important for minimising potential fatigue-related problems (such as providing suitable air-conditioned accommodation and a 4-hour sleep opportunity prior to commencing the first night shift, as well as ensuring trains were fitted with ATP for single-driver operations). However, given the realistic potential for many drivers to not be able to obtain sufficient sleep on some of their roster patterns (depending on their start time), there needed to be robust processes in place to ensure that sufficient sleep was actually being obtained.

The primary control in place to assess the amount of sleep being obtained by drivers was the fatigue assessment tool. This short questionnaire was required to be completed by a driver twice each swing, and as required if a driver felt fatigued. However:

  • Although this tool contained relevant questions, there were limitations with how the overall score was derived. A driver could have an overall low-risk score yet one of the sleep criteria (such as sleep in the last 24 hours or sleep in the last 48 hours) could have been significantly affected; they could also have an overall medium-risk score but have high risk associated with multiple criteria.
  • Drivers were required to complete the tool prior to the second shift and prior to the ninth shift of each swing. Completing it prior to the second shift would include the last sleep prior to commuting to the camp, sleep after arriving at the camp and sleep after the first shift, and completing it after the ninth shift would include the sleep during the 24-hour recovery break at the end of the first week and sleep after the next shift. Depending on the initial sign-on time, such scores would often be better than if they were completed after multiple night shifts.
  • Concerns about self-reporting fatigue are commonly perceived amongst train crew in the rail industry (for example, Fitness and Naweed 2017), and anecdotal evidence indicated that BHP’s drivers may also have been unlikely to complete the fatigue assessment tool accurately or report being fatigued. In addition, the overall proportion of BHP’s completed fatigue assessments that resulted in low-risk scores (97.6%) was unrealistic, and much higher than would be expected given the results of research associated with night shifts and roll-over roster patterns.
  • One of the key questions on the tool was a self-rating of alertness; as already noted, people will generally underestimate their level of fatigue or the influence of cumulative sleep restriction.
  • The importance of providing realistic answers for each of the questions could have been reinforced through detailed fatigue awareness training. However, recent training material did not emphasise the amount of sleep required each day to maximise alertness and performance.
  • BHP had not conducted any sleep studies, surveys or similar research to determine how much sleep its train drivers were actually obtaining during swings starting at different times of day.
  • BHP had applied the FAID biomathematical model of fatigue (BMMF) to some of its FIFO train driver swings. Although these applications had indicated the swings had very high scores (related to most normal work rosters), and scores that significantly exceeded the nominated fatigue tolerance threshold, this did not appear to generate any additional controls or treatments. The results were compared relative to other swings that had very high scores rather than treated as potential problems that needed further assessment.
  • BHP had conducted a limited number of critical control observations and audits, but these were very limited in scope. It had not conducted any independent or detailed reviews of its train driver rosters or fatigue management system until August 2018. That review, and a related review in February 2020, outlined a range of potential concerns and recommendations.

In summary, BHP's fatigue management processes required its train drivers to be rostered on 7 12-hour shifts, followed by a 24-hour break and then 7 12-hour shifts, with the roster pattern commencing at a wide variety of times of day. Such roster patterns were conducive to result in cumulative sleep restriction and levels of fatigue likely to adversely influence performance on a significant proportion of occasions, and BHP had limited processes in place to ensure that drivers actually obtained sufficient sleep when working these roster patterns.

  1. BHP advised drivers could access all instructions relevant to their role and specific tasks through the BHP Rail operations portal via their personal electronic device (that is a mobile telephone, subject to mobile coverage)

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors. 

Safety issues are highlighted in bold to emphasise their importance. A safety issue is a safety factor that (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the runaway and derailment of loaded ore train M02712 that occurred on the 5 November 2018 near the 211 km mark south of Port Hedland, Western Australia.

Contributing factors

  • BHP predominately managed the implementation of its electrically controlled pneumatic brake (ECPB) overlay and modification of automatic train protection (ATP) systems in 2011–2015 at an individual system level rather than through the application of a structured engineering approach. In the absence of a systems engineering framework, BHP did not identify and manage significant characteristics of how the ECPB, ATP and conventional pneumatic braking systems interacted in response to certain fault conditions.
  • Although BHP’s risk assessment for a rail-mounted equipment interaction incident identified numerous causes and critical controls for such an incident, it was broad in scope and had limited focus on the causes and critical controls for a train runaway event. In addition, the risk assessment did not include the procedure for responding to brake pipe emergencies and penalties as a critical control and BHP’s material risk control assessments (MRCAs) did not test the effectiveness of this procedural control for preventing an uncommanded movement of a train during main line operations. (Safety issue)
  • The task of responding to brake pipe emergencies or penalties relied extensively on a driver’s memory, with limited processes in place to facilitate or cross-check a driver’s performance to ensure all safety-critical actions were completed. (Safety issue)
  • Although operating instructions OI 17-11 (5 April 2017) and then OI 18-72 (3 November 2018) contained a safety-critical action (to apply the automatic brake handle to the pneumatic emergency position), BHP did not clearly communicate the importance and reasons for the safety-critical action to drivers, reducing the potential for the drivers to correctly recall this procedural action. (Safety issue)
  • Approaching Garden and on a descending grade, one of 12 inter-car connectors undergoing a trial near the front of the train disconnected. This caused a loss of trainline communications, resulting in the car control device (CCD) on each of the ore cars rear of the break in the trainline initiating an in-built 60-minute shut-down feature.
  • During implementation of the emergency procedure for responding to a loss of trainline communications with the end of train monitor displaying ‘off’, the driver did not place the automatic brake handle into the pneumatic emergency position, which would have vented the brake pipe pressure to zero and applied the train brakes via the pneumatic system.
  • The automatic train protection (ATP) and electronically controlled pneumatic braking (ECPB) systems on BHP’s trains could not interface to dump brake pipe pressure if an ECPB emergency or penalty brake application became ineffective in arresting an uncommanded train movement. (Safety issue)

Other factors that increased risk

  • On arrival at the 210 km mark, the Redmont maintenance gang did not directly communicate with the driver of M02712 and did not confirm the driver had implemented the BHP three-step process. The gang subsequently started applying handbrakes to another train (M02727), without three-step protection being applied on that train, which increased the risk of injury to personnel working on the rolling stock.
  • BHP’s emergency response procedures did not ensure rail infrastructure managers that interfaced with BHP's rail network were alerted to the emergency that could affect safety at the interface.
  • Due to cumulative sleep restriction over several days of night shifts, the time of day (0340) and other factors, the driver of MO2712 was probably experiencing a level of fatigue known to adversely influence performance.
  • BHP's fatigue management processes required its train drivers to be rostered on 7 12‑hour shifts, followed by a 24-hour break and then 7 12-hour shifts, with the roster pattern commencing at a wide variety of times of day. Such roster patterns were conducive to result in cumulative sleep restriction and levels of fatigue likely to adversely influence performance on a significant proportion of occasions, and BHP had limited processes in place to ensure that drivers actually obtained sufficient sleep when working these roster patterns. (Safety issue)

Safety issues and actions

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Risk assessment for a rail-mounted equipment interaction incident

Safety issue number: RO-2018-018-SI-01 

Safety issue description: Although BHP’s risk assessment for a rail-mounted equipment interaction incident identified numerous causes and critical controls for such an incident, it was broad in scope and had limited focus on the causes and critical controls for a train runaway event. In addition, the risk assessment did not include the procedure for responding to brake pipe emergencies and penalties as a critical control and BHP’s material risk control assessments (MRCAs) did not test the effectiveness of this procedural control for preventing an uncommanded movement of a train during main line operations.

Task design – brake pipe emergencies and penalties

Safety issue number: RO-2018-018-SI-02

Safety issue description: The task of responding to brake pipe emergencies or penalties relied extensively on a driver’s memory, with limited processes in place to facilitate or cross-check a driver’s performance to ensure all safety-critical actions were completed.

Operating instructions – brake pipe emergencies and penalties

Safety issue number: RO-2018-018-SI-03

Safety issue description: Although operating instructions OI 17-11 (5 April 2017) and then OI 18-72 (3 November 2018) contained a safety-critical action (to apply the automatic brake handle to the pneumatic emergency position), BHP did not clearly communicate the importance and reasons for the safety-critical action to drivers, reducing the potential for the drivers to correctly recall this procedural action.

Recovery controls – ATP/ECPB interaction

Safety issue number: RO-2018-018-SI-04

Safety issue description: The automatic train protection (ATP) and electronically controlled pneumatic braking (ECPB) systems on BHP’s trains could not interface to dump brake pipe pressure if an ECPB emergency or penalty brake application became ineffective in arresting an uncommanded train movement.

Fatigue management of train drivers

Safety issue number: RO-2018-018-SI-05

Safety issue description: BHP's fatigue management processes required its train drivers to be rostered on 7 12-hour shifts, followed by a 24-hour break and then 7 12-hour shifts, with the roster pattern commencing at a wide variety of times of day. Such roster patterns were conducive to result in cumulative sleep restriction and levels of fatigue likely to adversely influence performance on a significant proportion of occasions, and BHP had limited processes in place to ensure that drivers actually obtained sufficient sleep when working these roster patterns.

Safety action not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Additional safety action by BHP

Following the runaway and derailment accident involving of M02712, BHP leadership teams of the involved parties met to find the ‘root cause’ of the process noncompliance. BHP subsequently implemented additional controls via the issue of operating notice 18-216[43] requiring that any person responding to an event was to meet the driver of the affected train in person upon arrival. The following day BHP published operating notice 18-219[44] superseding notice 18-216.

Operating notice 18-219 included added detail on the requirement for support personnel to liaise with both the train control and the locomotive driver to:

  • determine the location and lead locomotive of the train requiring assistance
  • establish communication with the train driver
  • confirm lead locomotive and location
  • meet the train driver at an agreed location
  • confirm three step protection is applied
  • work under the direction of the train driver.

The notice reinforced that accessing rolling stock had to be conducted per Rail Rule Book Module 1: General Rail Rules and Procedures (section P1-5.0 regarding three step protection).

Operating notice 18-219 expired on 11 April 2019.

On 31 January 2022, BHP updated the above proactive action, advising:

The requirement for a work group to meet with the lead locomotive was included in work instruction 0105931 from version 3.0 (Oct 2019).

In 2021, as part of BHP’s work instruction uplift project (which was aimed at simplifying content) this requirement was reviewed and deemed to not be practical because the driver would not always be at the lead locomotive of the train. The requirement was also obscure to all potential stakeholders that could render assistance in similar scenarios. Accordingly, the requirement was removed from work instruction 0105931, and a new requirement was inserted for a work group supervisor to be appointed to communicate directly with the driver and the work group.

BHP is currently updating and simplifying our Rail rule book to further improve on the safe operation of our rail network. This will include a new digital portal that is designed to make documentation relevant to the task more easily accessible to the end user.

Additional safety action by the Office of the National Rail Safety Regulator

On 20 November 2018, post the runaway of M02712, the Office of the National Rail Safety Regulator (ONRSR) issued safety alert number RSA-2018-002 to rail transport operators in relation to the use of electronically controlled pneumatic braking (ECPB) and automatic train protection (ATP) systems (Appendix C). The alert encouraged operators to:

  • conduct an assessment of the interaction between the ECP braking system and the mechanical pneumatic braking system following an unexpected (penalty) braking intervention on a train configured for ECP braking.
  • determine whether the ECP braking system is designed to the AAR S-4200 standard
  • determine whether the 60-minute release has been programmed within the ECP braking software
  • conduct a risk assessment on the use of ECP braking for the prevention of the event of a rollaway incident
  • conduct a risk assessment on the effectiveness of the ATP system in the event of an ECP braking system failure.

Following the issue of the safety alert, ONRSR identified rail transport operators that may use ECPB in their railway operations. The regulator liaised with identified operators and ensured those that were affected undertook the actions as outlined in the safety alert. ONRSR also liaised with industry vendors of ECPB systems to obtain assurance of corrective actions following the accident.

In March 2019, ONRSR published a safety message titled Importance of a System Engineering Approach, which stated:

Following recent incidents and observations the Office of the National Rail Safety Regulator (ONRSR) is reminding all operators of the importance of a system engineering approach.

With various subsystems - such as track, signalling, rolling stock, electrification, stations, depots, and control centres - closely interlinked, any change in one may affect the operation of another. As such, it is important to carefully consider the interfaces and how the subsystems interact with each other (including how these systems work together with people).

It is essential to understand the hazards when making system changes or introducing new products into a system and the effect such a change will have on the overall risk profile of the railway.

One particular area operators should pay attention to is the acceptance of products or systems based on cross-acceptance. That is, where a product or system is deemed safe because it has been applied safely on another railway or because it is compliant with appropriate standards.

Whilst cross acceptance can be an indication of performance, it cannot be taken as evidence that a product will perform safely in the particular railway system it is introduced to. As part of a robust engineering change process it is, therefore, important to understand the potential hazards a product or system may present in the environment it is introduced to - and the effects it might have on the overall safety risk of the railway.

Operators should demonstrate that they use appropriate systems engineering processes and safety assurance processes (e.g. EN50126/8/9 for complex systems) in their design and procurement approach. This can be achieved through the creation of a systems engineering management plan which specifies the procedures to identify and record stakeholders, system requirements and safety needs.

On 3 August 2020 ONRSR published two related fact sheets:

The Safety Critical Software Assurance fact sheet is designed to help rail transport operators ensure their safety management systems address the complexity of software systems along with its compliance and safety risk. It features a series of international lessons learned to illustrate key points.

The Systems Integration fact sheet focuses on the importance of a robust approach to systems integration in the context of major projects and other initiatives that are delivering complex and/or multifaceted safety systems. The aim of the resource being to ensure new technologies work together safely with existing railway infrastructure and rolling stock.

Additional safety action by the Rail Industry Safety and Standards Board

In January 2019, the Rail Industry Safety and Standards Board (RISSB) issued the Rolling Stock Safety Assessment Guideline as ‘an aid to rail industry describing common practice for the safety assessment of rolling stock and approvals.’ It set guidance for:

  • providing rolling stock safety assessment awareness in rolling stock lifecycle,
  • preparing and undertaking a safety assessment and safety assurance case toward regulatory compliance,
  • addressing stakeholder responsibilities for safety in the rolling stock lifecycle.

The Rolling Stock Safety Assessment Guideline listed several systems and safety engineering standards, including EN 50126-1, as normative references.

In June 2020, the RISSB-developed Australian Standard (AS) 7473 Complex system integration in railways was issued. The standard is freely available to RISSB member organisations. It stated:

The objective of this Standard is to establish an industry approach for managing:

a. the risks associated with integrating complex systems;

b. the design and implementation of complex system interfaces; and,

c. the planning, conducting and reporting on system integration testing (SIT).

This Standard defines an approach to support the preparation and execution of system integration for rail projects in Australia. It provides processes to support the definition, control and optimization of integration processes used within an organization or project that can be applied by the adopter when delivering railway systems.

This Standard is targeted at railway systems integrators such as operators, delivery authorities, prime contractors and alliances, or other bodies involved in integrating systems for or into a railway environment. Specifically, activities that result in changes or creation of railway configuration or operation.

AS 7473 listed two systems and safety standards as normative references: British Standard (BS) EN 50126 and ISO/IEC 15288.

  1. BHP Operating Notice 18-216, Assisting and Applying or Releasing Train Handbrakes, 10 November 2018
  2. BHP Operating Notice 18-219, Assisting and Applying or Releasing Train Handbrakes, 11 November 2018

Glossary

AAR  Association of American Railroads
ATP   Automatic train protection
ATSB  Australian Transport Safety Bureau
BMMF Bio-mathematical model of fatigue
BHP   Broken Hill Proprietary Ltd.
CASACivil Aviation Safety Authority
CCDCar control device
CCV  Critical control verification
CDA   Control design assessment
CET   Control effectiveness test
ECP  Electronically controlled pneumatic
ECPBElectronically controlled pneumatic braking
EOTM End of train monitor
EOT End of train
FAID    Fatigue Audit InterDyne
FIREFunctionally integrated railroad electronics
FIFO  Fly-in fly-out
FAST   Fatigue avoidance scheduling tool
FRA Federal Railroad Association
FTL Fatigue tolerance level
GPS  Global position satellite
HEUHead end unit
KSS Karolinska sleepiness scale
LOA Limit of authority
MRCA Material risk control assessment
NYABNew York Air Brake
ORS Western Australia Office of Rail Safety
ONRSR   The Office of the National Rail Safety Regulator
OI  Operating instruction
ONOperating notice
RME  Rail mounted equipment
SARC Safety-related application condition
TBC Train brake command
UCIIAlston Ultra-Cab II
WAIO West Australian Iron Ore
WA Western Australia
VHF  Very high frequency

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the driver of M02712
  • BHP Iron Ore Pty Ltd
  • recorded data from the event loggers of locomotives 4420, 4440 and 4472
  • recorded data from BHP’s train control centre.

References

Association of American Railroads, S-4200, Electronically Controlled Pneumatic (ECP) Cable-Based Brake Systems - Performance Requirements, 2014.

BHP Billiton Iron Ore Railroad Operations 3-Step Protection Audit Form, 0057320, version 2.0.

BHP Driver Safeworking and Locomotive System Theory and In Field Training, RALSWSDACC, Version 7.0.

BHP Rail Safety Management Plan, PRC-RRO-PLN-023, Version 6.0, June 2019.

BHP Operating Notice 18-208, 31 October 2018.

BHP Iron Ore, Rail Rule Book, Rail Operations Rules and Procedures, Module 6, Rail Operations, Document 0119119, Version 1.1, January 2015.

BHP Handbrake Application and Release Mainline Recovery 0105931, version 2.0, August 2018.

BHP Issuing and Receiving Operating Instructions Procedure, Document number 0119630, Version 2.0, reviewed August 2018.

BHP Emergency Management Plan – Part 1, Procedure, Document 0095982, Version 9.0, September 2018.

BHP Iron Ore Railroad Incident and Emergency Response, Train Controller, Document 00996525, Version 8.0.

BHP Operating Notice 18-216, Assisting and Applying or Releasing Train Handbrakes, 10 November 2018 (superseded).

BHP Operating Notice 18-219, Assisting and Applying or Releasing Train Handbrakes, 11 November 2018.

BHP Iron Ore, Management of change procedure, SPR-IHS_SAF-028, October 2019.

BHP ECPB-WDP-Leader Operators manual, Document 0117864, V3.0_01_16, reviewed 11 February 2016.

BHP Train Control Incident and Emergency Response Procedure, 0090625, version 8, August 2018.

BHP Electronically Controlled Pneumatic Braking (ECPB) Project, Definition Phase Study Report, Version 1.0, May 2014.

BHP Electronically controlled pneumatic braking (ECPB) project, Selection phase to definition phase IPR version 1.2, 6 December 2013.

BHP - Testing of ECP brakes for BHPB-IO, Report 2012/657, April 2012.

Minerals Australia, Western Australia Iron Ore, Risk Management Procedure, Document 0126027, Version 4.0, February 2018.

New York Air Brake, Maintenance and Repair, EP-60 Freight Car Integrated Brake Control System, IP – 234 Rev (3/17/17) – en.

Vlasblom JID, Pennings HJM, Van der Pal J and Oprins EAPB (2020) ‘Competence retention in safety-critical professions: A systematic literature review’, Educational Research Review, 30:10.1016.

Watson NF, Badr MS, Belenky G, Bliwise DL, Buxton OM, Buysse D, Dinges DF, Gangwisch J, Grandner MA, Kushida C, Malhotra RK, Martin JL, Patel SR, Quan SF, Tasali E (2015) ‘Joint consensus statement of the American Academy of Sleep Medicine and Sleep Research Society on the recommended amount of sleep for a healthy adult: methodology and discussion’, Journal of Clinical Sleep Medicine, 11:931-952.

Welschen R, Bellon E, Brown C, Fullalove R, Kennedy G, Irvine K, Mumford N, Nadeem M, Nasr J, Tildesley E, Patel H, Roodt D (2021) An overview of systems engineering in the Australian transport sector, Systems Engineering Society of Australia, version 5.0.

Wickens CD, Hollands JG, Banbury S and Parasuraman R (2013) Engineering psychology and human performance, 4th edition, Pearson Boston, MA.

Wisher RA, Sabol MA and Ellis JA (1999) Staying sharp: Retention of military knowledge and skills, US Army Research Institute, Special Report 39.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • BHP Billiton Iron Ore Pty Ltd
  • Office of the National Rail Safety Regulator
  • the driver of M02712.

Submissions were received from:

  • BHP Billiton Iron Ore Pty Ltd
  • the Office of the National Rail Safety Regulator.

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Appendices

Appendix A – Operating Instruction 18-72

appendix-a-image-1.png
appendix-a-image-2.png
appendix-a-image-3.png
appendix-a-image-4.png
appendix-a-image-5.png
appendix-a-image-6.png

Appendix B – Research associated with various roster patterns

Research associated with night shifts

Shift work is an inevitable part of commercial transport. However, night shifts will generally have a negative effect on a person’s amount of sleep, sleepiness and performance (Akerstedt and others 2009, Sallinen and Kecklund 2010). The primary reason is that people are generally adapted to a normal sleep-wake cycle (with sleep at night), and a night shift forces people to work and sleep at the physiologically least suitable times of day.

A range of factors can influence the severity of problems associated with night shifts. Although some concern has been expressed about the length of shifts (such as 12-hour shifts versus shorter shifts), research has shown that the length of a shift itself is not necessarily as problematic as other features of roster patterns, the nature of the work and the frequency of rest breaks (Ferguson and Dawson 2012). Tucker and Folkard (2012) stated:

Work schedules that conflict with the normal sleep-wake cycle can result in considerable cumulative fatigue that can only be dissipated if the timing of rest periods allows adequate sleep… although it is clearly possible to make recommendations for each specific feature, the impact of the features of any given work schedule really need to be considered in combination with one another. For example, a span of five successive 12-hour shifts might be perfectly acceptable if there are frequent rest breaks and they are worked during the day, but totally unacceptable if there are no rest breaks and they are worked at night.

One significant feature is the number of consecutive night shifts. Research has shown that most people will generally not adapt their sleep-wake cycle while on night shifts, and therefore, as the number of consecutive night shifts increases, the more problematic the effects associated with the reduced amount of sleep each day (Tucker and Folkard 2012). Ferguson and Dawson (2012) cited studies showing people on 12-hour night shifts get between 5 and 6.5 hours sleep.

Another significant feature is the timing of the recovery break between consecutive night shifts. As noted by Tucker and Folkard (2012):

…night-shift workers experience greater sleep problems when they go to bed in the relatively "late" morning, after returning home from the night shift... Sleep propensity falls rapidly from its peak between 4 and 6 a.m. until about 1 p.m., implying that the later nightworkers go to bed following a night shift, the more difficulty they may have in falling asleep. They may also find it difficult to stay asleep long enough to recover adequately.

Roach and others (2003) found that train drivers with a 12-hour break between 2 shifts had an average of 5.2 hours sleep, but the amount of sleep significantly varied depending on the start time of the break. Breaks beginning at 0800–1000 had the lowest amount of sleep (3.1 hours), and breaks starting from 0400–1400 had less than 5 hours sleep. Other research has also noted a similar relationship between the time of a recovery period and the amount of sleep obtained (Spencer and others 2006).

Shifts that begin in the early morning can also be problematic as people generally go to bed at (or cannot get to sleep until) their normal bedtime and they get less than their normal amount of sleep (Tucker and Folkard 2012). Research has shown that early morning shifts are associated with elevated levels of fatigue risk and higher self-ratings of fatigue compared to day shifts (Sallinen and Hublin 2015).

Some researchers have stated that the number of consecutive night shifts or early shifts be limited to a maximum of 3 in a row (Tucker and Folkard 2012). Others have recommended that rosters with several consecutive early morning starts be avoided where possible (Roach and others 2011).

Research associated with roll-over roster patterns

A significant amount of research has been conducted on the effects of roll-over roster patterns in FIFO work in the offshore oil and gas industry, primarily in the North Sea (Fossum and others 2013, Parkes 2012, Parkes 2015). For these environments:

  • Shifts generally started at about 1800–1900 (night shift) or 0600–0700 (day shift).
  • Roll-over patterns starting with night shifts typically resulted in an average of 6.5 hours sleep after each night shift.
  • Many workers started adapting their sleep-wake cycle to the night shift after 5–6 nights. The adaptation generally occurred in these environments because much of the work was indoors and there was limited exposure to sunlight. After rolling over to the day shifts the workers then had to re-adapt to day shifts, which led to further sleep restrictions.
  • Roll-over patterns starting with night shifts were found to lead to less sleep over the fortnight than roll-over patterns starting with day shifts or roster patterns with 14 night shifts. However, workers generally preferred roll-over patterns commencing with night shifts because they were adapted to a normal sleep-wake cycle when they went home.

A recent guidance document on FIFO work for the oil and gas industry (IPIECA 2015) discussed a number of risk factors. It recommended avoiding rotating from nights to days during the middle of a 14-day roster pattern. It also stated that ‘Long tours of night shifts are associated with cumulative fatigue due to a lack of restorative sleep.’ Recommended control measures included ‘adequate and regular breaks’ within each shift, and to avoid scheduling safety-critical work during 0200-0600.

There has been less research conducted into roll-over roster patterns in onshore environments. Ferguson and others (2010, 2012) examined FIFO roll-over roster patterns in a Western Australia mining environment with day shifts 0545–1800 followed by night shifts 1745–0600. The average amount of sleep following a day shift (6.1 hours) was less than following a night shift (5.7 hours).[45]The amount of sleep did not increase over the week of night shifts, and various measures indicated that the workers’ sleep-wake cycles did not adapt during the week of night shifts. Performance on reaction time tasks also decreased over the week of night shifts. The authors noted that the workers were exposed to a significant amount of sunlight after completing their night shifts and before getting to bed, whereas workers in the North Sea environment would have less exposure to sunlight.

Very little research has examined the influence of different start times for roll-over roster patterns. Paech and others (2014) examined the influence of start times for FIFO train drivers at a Western Australia mining site. All the swings started with morning shifts (that is, starting from 0100–1200) followed by afternoon shifts (starting from 1300 to 0000). Workers obtained an average of 6.1 hours sleep each break between shifts, with the amount of sleep varying depending on the start time of the break. Breaks beginning from 1000 to 1200 were associated with 4.4 hours sleep and breaks starting from 0100 to 0300 were associated with 6.8 hours sleep. Overall, breaks starting from 0400 to 1200 were associated with less than 6 hours sleep whereas breaks starting from 1300 to 0300 were associated with more than 6 hours sleep.

Summary

In summary, roll-over roster patterns that include 7 consecutive 12-hour night shifts present an elevated risk of fatigue, particularly in environments such as Australian mining sites where it is unlikely that workers will adapt their sleep-wake cycles during a week of night shifts due to exposure to sunlight. This risk is further exacerbated depending on the start and end time of the shifts, with night shifts ending in the late morning likely to lead to the least amount of sleep.

Appendix C – ONRSR Safety Alert

appendix-c-image-1.png
appendix-c-image-2.png

__________

  1. The researchers noted that at this mining site the workers had to arise early to catch a bus at 0445 prior to a day shift, and such early starts would have restricted the amount of sleep prior to a day shift.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2022

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Preliminary report

Report release date: 12/03/2019

This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

The occurrence

Overview

At approximately 0440[1] on 5 November 2018, loaded BHP ore train M02712 rolled away from the 210.7 km mark located near Garden South on the Nelson Point to Newman railway, Western Australia. There was no driver on board the train at the time. The train travelled uncontrolled on the west track for about 91 km before Hedland train control decided to derail the train by routing it from the west track to the east track at a crossover located at Turner South.

At about 0526, the head end locomotives traversed the crossover. Shortly after, 245-ore cars and the two remote locomotives, located mid consist, derailed. There was significant damage to rolling stock and track infrastructure at Turner South (Figure 1). There was no injury to any person from the derailment.

Figure 1: Train M02712 wreckage at Turner South

Figure 1: Train M02712 wreckage at Turner South. Aerial image viewed in a southerly direction of train wreckage and track damage at Turner South. The lead locomotives 4420 and 4434 and one ore car (out of frame in the foreground) remained on track Source: BHP, annotated ATSB

Aerial image viewed in a southerly direction of train wreckage and track damage at Turner South. The lead locomotives 4420 and 4434 and one ore car (out of frame in the foreground) remained on track.

Source: BHP, annotated ATSB

Sequence of events

At about 0337 on 5 November 2018, train M02712 was travelling at 60 km/h on the west track approaching the BHP access road level crossing at the 211.6 km mark. The driver had set the throttle control for maximum dynamic braking and commenced moving the Electrically Controlled Pneumatic (ECP) braking control toward a 39 per cent application.

At about 0339, communication between the lead locomotive and the combined end of train monitor (CEOT) was lost, triggering an automated 120 per cent ECP emergency brake application, stopping the train as it approached Garden South. Shortly after, the driver made an emergency radio call to Hedland train control reporting the occurrence, his location (at the 210.737 km mark between Shaw and Garden), and the details of alert messages displayed to him by the locomotive on-board systems.

The train controller placed blocks to signals on the adjacent east track between Garden South and Shaw North to protect the train (from other rail movements) and contacted personnel from the Redmont[2] maintenance gang to assist the driver. The controller advised the driver that assistance was en route and requested he confirm the train’s location from a kilometre mark[3] closest to the lead locomotive.

The driver stated that the FIRE[4] system displayed 210 km, but would detrain and check the kilometre mark on the ground to confirm. At about 0351, the driver placed the reverser[5] control to the centre (neutral) position, turned the generator field[6] off and fully applied the locomotive independent brake before exiting the locomotive cab. The 120 per cent emergency brake application was active and the automatic brake handle remained set at the position equating to a 39 per cent ECP brake application.[7]

After receiving confirmation of the 210.7 km mark, the controller instructed that 101 per cent handbrakes[8] were required to secure a loaded train on the falling track grade. The controller asked the driver if he wanted to start applying them now or go back up to the locomotive and wait for the arrival of personnel from the Redmont gang. At about 0353, the driver decided to commence applying handbrakes to the 268 ore cars from the front of the train.

At about 0355, an empty ore train (M02727) travelling on the adjacent east track toward Yandi Junction stopped at Garden South due to the blocking protections set up previously. About 30 minutes later, personnel from the Redmont gang advised train control of their arrival at the 210 km mark to assist the driver in applying handbrakes. The train controller suggested the gang start applying handbrakes from the rear of the train and proceed toward the driver who was working from the front.

Hedland control continued to maintain contact with the driver of M02712 at 10-minute intervals during which the driver advised that he had found a disconnection in the train-line cable[9]. The train-line cable was located on the opposite side of the train and not accessible safely, so the driver continued to apply handbrakes to secure the train. During one of the scheduled calls, the driver reported to the controller that the application of handbrakes was progressing well despite having trouble walking along the ballast shoulder next to the stationary train. The driver also reported that he was aware the Redmont gang had arrived to check the integrity of the rear of the train and to apply handbrakes. The driver said that he planned to continue working toward the locomotives mid train, report to train control then return to reinstate the break in the train-line cable.

At about 0440, the driver heard air venting from the ore car brakes and shortly after noticed the train begin to move forward. The driver first attempted a radio call to the Redmond gang alerting that the brakes had ‘bled off’ but there was no response. Shortly after train M02712 began to roll away, the ATP system requested a penalty brake application but it was ineffective in stopping the train.

About four minutes later, the driver of the empty ore train standing at Garden South (M02727) contacted train control advising train M02712 was moving and had passed his location at an estimated speed of about 50 km/h with brakes dragging.[10]

At 0446, train control received an emergency call from the driver of M02712 alerting that the brakes had bled off and the train was now a ‘runaway’. Train control acknowledged the emergency call and advised he had set signal GNN4 at Garden North to red, attempting to stop the train by triggering the locomotive on-board automatic train protection system. Train M02712 passed signal GNN4 at about 80 km/h and continued to increase in speed. Although the ATP system requested a penalty brake application in response to signal GNN4 at red and to an over speed, these penalty applications were also ineffective in stopping the train.

About 80 km ahead, another train (M02728) travelling on the eastern track was approaching Abydos North. Hedland control contacted its driver instructing him to stop, detrain and move to a safe place. Hedland control also contacted the drivers of the two other trains (M02729, M02710) operating between Garden North and Port Hedland, instructing the drivers to stop, detrain and move to a safe place. Trains M02729 and M02710 stopped at locations north of Turner (Figure 2).

At about 0502, the driver of the empty ore train (M02727) stopped at Garden South, contacted Hedland control advising that the Redmont gang had mistakenly applied handbrakes to his train rather than to train M02712.

Train M02712 continued through Spring and Coonarie reaching a speed of 162 km/h before slowing on the rising grades toward Woodstock (Figure 2). At about 0509, train M02712, travelling at about 128 km/h, passed over the level crossing at the 154.3 km mark before Woodstock South. After Woodstock, the track grade again began to fall toward Port Hedland and train M02712 gained speed to about 130 km/h as it passed train M02728 stopped at the 130.5 km mark on the eastern track north of Abydos.

At about 0520, Hedland control set the crossovers at Turner South and Turner North to switch train M02712 between adjacent tracks in an attempt to derail it as the traversed the crossover at speed. About six minutes later, the head end locomotives travelling at 144 km/h traversed the crossover at the 119.4 km mark at Turner South. Locomotives 4420, 4434 and the first ore car remained coupled and on track, travelling about 1.6 km further before stopping. Ore cars in position two to 134 of the first rake, the remote locomotives 4472 and 4440 and ore cars one to 112 from the second unit rake derailed near the crossover. The last 22-ore cars of the second unit rake remained coupled and on track.

The derailment destroyed two locomotives, 245-ore cars and 2 km of track infrastructure at Turner South.

Figure 2: Location map BHP Port Hedland railway

Figure 2: Location map BHP Port Hedland railway. Source: BHP, annotated ATSB

Source: BHP, annotated ATSB

Context

Train information

Train M02712

The ore train operated as a unit train weighing approximately 42,500 t and was 2,860 m long. It consisted of two SD70ACe type locomotives (4420, 4434) leading , a unit rake of 134-ore cars, two remotely operated SD70ACe type locomotives (4472, 4440) located mid-train, and a second unit rake of 134-ore cars. The ore train was operating between the loading facility at Mining Area C situated on the spur line extension from Yandi, and the unloading facility at Nelson Point, Port Hedland (Figure 2).

Locomotive on-board automatic train protection system

The four locomotives on train M02712 were each equipped with an Alstom Ultra-Cab II (UCII) microprocessor controlled automatic train protection (ATP) system. The UCII system was not a standalone system; it interfaced electronically with other on-board equipment including FIRE, Electrically Controlled Pneumatic (ECP) braking systems, wayside transponders[11] and other control systems that combined to provide for the safe operation of the train within the parameters defined in the BHP iron ore rules and regulations.

The ATP functions included monitoring the locomotive speed and supervising its operation within the limits imposed for the track section. If the locomotive was moving faster than the target speed limit, alarms would sound prompting the driver to reduce speed.

The locomotives carry a radio transmitter, transponder reader and antenna. Transmissions are relayed between the locomotive and transponders fastened to the track cross-ties (sleepers) at key locations such as ATP entry and exit points and interlocked wayside signals along the railway. Unique location identification and target speed data is relayed from the track mounted transponders to the locomotive UCII microprocessor.

The driver must reduce speed to the target limit within a predetermined time. If this does not occur, the ATP automatically interfaces with the braking system to initiate a brake application to stop the train. The type of brake application is dependent on the setup of the locomotive at the time of the command. If the locomotive is configured for conventional pneumatic braking, the ATP initiates a service brake application. If this was ineffective in slowing the train, the ATP then initiates a penalty brake application. For an ECP braking configuration, the ATP requests a penalty brake application.

Additionally, when the locomotive was stationary with its reverser in the neutral (centre) position and the ATP detected a train movement of more than 0.5 m, the ATP requested a penalty brake application to prevent a potential locomotive runaway.

Each ATP automatically configures to mirror the ECP brake setup for that locomotive as a head end unit (HEU), trail or remote unit. The ATP would not enforce target speed limits or runaway protection on locomotives configured as either a trail or remote unit. The ATP in each of the four locomotives in train M02712 (4420, 4434, 4472 and 4440) functioned respectively as a HEU, trail and two remote units.

Braking and Distributed Power systems

Train M02712 was equipped with an EP-60 New York Air Brake electrically controlled pneumatic (ECP) braking system. The system consisted of locomotive equipment, ore car braking control equipment, an end of train monitor, and a power and communications distribution system.

Locomotive equipment comprised a train-line communications controller, power supply and identification module. The lead locomotive 4420 functioned as the HEU. The HEU communicated with each of the 268-ore car braking control devices (CCD) and remote locomotives via embedded transmissions in the train-line cable comprised of a single set of wires forming the intra-train power and communications network. The CCD unit used 230 Volt Direct Current power from the train-line to charge its batteries and supply power to its electronics.

In ECP mode, the EP-60 system used the position of the HEU automatic brake handle to control the operation of the locomotive and ore-car brake cylinders. The FIRE system provided the interface to the driver displaying braking parameters related to the ECP system mode, alarms, diagnostic messages and brake command input.

The FIRE system displayed the level of brake command input as a percentage (%TBC)[12], typically a number between 0 and 100 per cent or as 120 per cent:

  • 0% = Release
  • 10% = Minimum Service
  • 100% = Full Service/Penalty application
  • 120% = Emergency.

The Combined ECP end of train monitor (CEOT) installed on the last ore car coupler marked the end of the train, provided a termination point for the train-line and a transducer for end of train information, such as brake pipe pressure, back to the HEU to establish the integrity of the train-line and train consist. The CEOT used 230 Volt Direct Current power from the train-line to charge its batteries and supply power to its electronics.

If the power from the train-line is lost, the CCD and CEOT devices each continue to operate on battery power until the batteries run low or a 60 minute time period elapses. The CCD and CEOT devices will then enter shutdown mode. When a CCD shuts down it releases its ECP brake application and relinquishes control of brake cylinder pressure to the conventional pneumatic braking system. If the brake pipe is charged and a pneumatic application is not in effect, the brake cylinder pressure will release.

The BHP locomotive fleet was equipped to enable control of multiple distributed power units within the train. Communication of synchronous control and indication signals between the HEU, trailing and remote locomotives, located mid consist, also occurred via the train-line system.

As a contingency, the ECP overlay braking system and train-line could be shut down and the HEU configured to communicate power and brake commands via UHF radio communications to the remote locomotives. This configuration disables ECP braking and train braking reverts to conventional pneumatic operation via the train brake pipe. The HEU configuration establishes communication with the CEOT by radio.

The locomotive independent brake handle is located immediately below the automatic brake handle and controls the locomotive braking independently of the automatic train brake. It also applies the brakes on other locomotives in the train. The independent brake control only apples to the locomotives (lead and remote) and not the ore cars in the train. The independent brake control operates pneumatically irrespective of the HEU configuration.

The independent brake control handle can be positioned to:

  • REL (release), releasing the locomotive brakes provided the automatic brake handle is also in the REL position
  • SERVICE, moving the handle through the service zone increases locomotive braking effort
  • APPL position applies full braking effort on the locomotive(s)
  • Bail off function, depressing the handle in either the REL position or SERVICE zone suppresses any automatic train brake application in progress on the locomotive(s).
Vigilance control

The vigilance control system functions to monitor driver activity and stop the locomotive/train when there was no response from the driver to aural and visual warnings displayed via the FIRE system. The vigilance system uses random timing and task linking to monitor driver activity.

The vigilance system is active when the locomotive air brake is set as HEU and the air brake cylinder pressure is less than a predetermined level. Vigilance system suppression occurs when the locomotive air brake cylinder pressure is greater than a predetermined level, when the braking system is set to trail or remote, when the reverser is in the centred position, or when the locomotive configuration is set for operation at a defined slow speed.

Track

The BHP iron ore railway is a standard gauge track structure constructed with continuously welded 68 kg/m rail fastened with resilient clips to concrete sleepers. The sleepers are contained in crushed rock ballast. The track structure configuration enabled the operation of rolling stock with 40 t axle load.

In the direction of travel, the track gradient from Mining Area C was primarily a rising grade approaching Shaw located in the Chichester Range before transitioning to a mainly falling grade toward Nelson Point. The roll away occurred between Shaw North and Garden South where the track gradient was -1.5 per cent—the steepest track gradient of the track section between Yandi Junction and Nelson Point.

The ATP governed the maximum permissible track speed for the various sections dependent on the mode of operation, with the target speed displayed to the driver via the FIRE system. The maximum track speed for the Newman to Port Hedland railway was 75 km/h for loaded ore trains.

Train control

BHP manages train movements remotely from its train control centre located in the Integrated Remote Operations Centre in Perth. The train control centre has five operational control areas (desks) identified as Hedland, Newman, 6PG, Hub control and Yard control. All communications between the Perth control centre, train movements, control systems and wayside equipment is via a dedicated VHF radio system.

The runaway occurred within the operational area managed by Hedland train control that extended from the 67 km mark located south of Walla to the 260 km mark located south of Cowra.

Safety action

The BHP preliminary investigation recommended a series of actions for implementation over the short (prior to recommencing movements of trains), medium (within approximately one year) and long term (over one year).

Short term
  • Issue communications to all train drivers regarding the release of ECP brakes under certain conditions.
  • Amend operating instruction related to Brake Pipe Emergencies and Penalties.
Medium term
  • Investigate improvements to ECP braking system Handbook in relation to any of the short term controls.
  • Review the processes for issuing operating instructions and disseminating information to drivers and assess value in presenting a measure of criticality with each operating instruction to avoid dilution of critical instructions amongst non-critical information.
  • Undertake a review of the ECP braking system timeout function to explore software options to increase timeout period at a sacrifice to ECP braking system battery performance.
  • Investigate a hardware/software solution whereby the on-board control system, FIRE or brake computer automatically dumps the air from the train brake pipe under different conditions.
Long term
  • In conjunction with the BHP existing signalling upgrade project, introduce new automatic train protection system on-board every locomotive, track maintenance machine and Hi-rail in the BHP fleet.

Ongoing investigation

The ATSB investigation has obtained relevant material and conducted interviews with a number of BHP staff. The ATSB is continuing to gather documentation about the design of train braking systems operated by BHP and the procedures contained in the BHP safety management system for the management of risk and the development and dissemination of safety critical information to rail safety workers.

The ongoing ATSB investigation will include consideration of the following:

  • examination of factors associated with train-line cable connectors
  • design, operation and serviceability of the locomotive and ore car electrically controlled pneumatic and pneumatic braking systems, and the interface between them at time of the occurrence
  • effectiveness of critical control management process in identifying and managing operational risk from a runaway occurrence
  • arrangements for the dissemination of safety critical information and associated driver training
  • effectiveness of recovery controls—runaway protection
  • effectiveness of emergency management plan response systems and actions
  • factors influencing the driver’s response to a penalty brake application
  • train handling, driver qualifications, experience and health information
  • Status of BHP short, medium and long term actions following the occurrence.

_____________

The information contained in this interim report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this report. As such, no analysis or findings are included.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. WST, Western Standard Time, UTC plus 8 hours.
  2. Redmont is a remote maintenance camp accommodating track workers. Redmont was located near Garden South.
  3. Kilometre markings on rail.
  4. Functionally Integrated Railroad Electronics (FIRE) system forming the interface between the operating crew and locomotive computer systems.
  5. Lever in locomotive cab to select ‘forward’ ‘centred/handle-out’ or ‘reverse’ for the direction of operation.
  6. Power source for generator field excitation.
  7. Automated ECP penalty brake application overrides manual setting of the automatic brake handle.
  8. Handbrake calculator tool determined number of handbrakes required based on track grade and loaded/empty state of train.
  9. The interruption in the train-line cable was due to a disconnected connector between the tenth and eleventh ore-car in the first unit rake.
  10. Brakes applied on head end locomotives and a number of ore cars from the first rake.
  11. Signalling and other associated equipment located adjacent to the rail track.
  12. Train Brake Command.

Occurrence summary

Investigation number RO-2018-018
Occurrence date 05/11/2018
Location 211 km from Port Hedland (Nelson Point to Newman Railway)
State Western Australia
Report release date 17/03/2022
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Accident
Highest injury level None

Train details

Train operator BHP
Train number M02712
Type of operation Freight
Rail vehicle sector Freight
Departure point Newman Mine, Western Australia
Destination Port Hedland, Western Australia
Train damage Substantial

Technical assistance to Recreational Aviation Australia (RAAus) involving Aeropro 3K, registration 24-7502, collision with terrain, 65 km north of Wentworth, New South Wales, on 31 October 2018

Summary

On 31 October 2018, an Aeropro 3K, registration 24-7502, collided with terrain 65 km north of Wentworth in NSW. The pilot and passenger were fatally injured.

Recreational Aviation Australia (RAAus) commenced an investigation of this accident and requested technical assistance from the Australian Transport Safety Bureau (ATSB) to download the flight data from a Dynon data logging unit.

To protect the information supplied by RAAus to the ATSB and the ATSB's investigative work to assist RAAus, the ATSB has initiated an investigation under the Transport Safety Investigation Act 2003.

Any enquiries relating to the accident investigations should be directed to RAAus at: www.raa.asn.au.


Updated: 26 March 2019

The ATSB has completed its work attempting to download the recorded data from the Dynon SkyView SV‑D1000 unit supplied by RAAus. A report detailing the work undertaken by the ATSB was provided to RAAus on 15 March 2019.

Occurrence summary

Investigation number AE-2018-072
Occurrence date 31/10/2018
Location 65 km north of Wentworth
State New South Wales
Report release date 26/03/2019
Report status Final
Investigation level Short
Investigation type External Investigation
Investigation phase Final report: Dissemination
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Model Aeropro 3K 100 hp
Registration 24-7502
Serial number 32310
Sector Sport and recreational
Operation type Private
Damage Substantial

Engine failure involving Boeing 787, 9V-OJE, Perth Airport, Western Australia, on 11 October 2018

Final report

Report release date: 01/12/2020

Safety summary

What happened

On 11 October 2018, a Boeing 787-9, 9V-OJE, operated by Scoot Tigerair (Scoot), departed Singapore on a scheduled flight to Perth, Western Australia. During descent, the flight crew noticed that the right engine was slow to respond to commands, and its performance continued to decline throughout the descent. While passing through 9,000 ft, severe thrust asymmetry developed, and the engine shut down shortly afterwards. The crew followed appropriate procedures, and due to the proximity of the airport, elected not to attempt a restart. The aircraft landed safely with emergency services in attendance. There were no injuries sustained and no aircraft damage as a result of the incident.

What the ATSB found

The ATSB determined that following a series of engine status and alert messages, 9V-OJE experienced an uncommanded engine shutdown while on descent into Perth, before landing safely using the operational engine.

Based on a review of the flight data and an examination of engine components by Rolls-Royce, the engine shutdown was due to debris from worn journal bearings in the engine’s secondary high-pressure fuel pump blocking an inlet filter for the fuel metering valve servo assembly. This prevented the valve from delivering sufficient fuel to the engine.

Rolls-Royce also determined that, between late 2018 and early 2019, the operator’s fleet of 787 aircraft had been particularly susceptible to low‑life wear in the journal bearings of the secondary high‑pressure fuel pump. It identified a number of potential factors that led to the component wear but, due to the number of variables, a single/dominant reason could not be established.

What has been done as a result

Rolls-Royce updated its Fault Isolation Manual to instruct all operators to remove the fuel pump and hydro-mechanical unit in the event of a maintenance message regarding the fuel metering valve not being in the commanded position. Rolls-Royce is also monitoring maintenance messages and investigating the possibility of using flight data to detect fuel pump journal wear before its effects on valve operation become apparent.

Safety message

This occurrence highlights the importance of flight crew being familiar with emergency procedures, so that the appropriate corrective action can be taken quickly and effectively. In this case, the flight crew worked effectively to assess the situation, and took appropriate action to minimise risk in accordance with the operator’s flight crew operations manual.

This occurrence also shows that positively identifying the factors contributing to technical failures can be difficult and time consuming. However, manufacturers and operators can implement interim risk mitigation measures, as was the case here.

 

The investigation

Decisions regarding whether to conduct an investigation, and the scope of an investigation, are based on many factors, including the level of safety benefit likely to be obtained from an investigation. For this occurrence, a limited-scope investigation was conducted in order to produce a short investigation report, and allow for greater industry awareness of findings that affect safety and potential learning opportunities.

The occurrence

On 11 October 2018, at about 1421 Western Standard Time,[1] a Boeing 787-9, 9V-OJE, operated by Scoot Tigerair (Scoot), departed Changi Airport, Singapore. The aircraft was on a scheduled passenger flight to Perth, Western Australia, with 11 crew members and 356 passengers on board.

Approximately 2 hours into the flight, the crew received two status messages indicating abnormalities within the right engine. Three hours later, during descent, the aircraft was passing through FL 250[2] when the crew noticed that the right engine was slow to respond to commanded inputs. Throughout the descent, the right engine performance continued to decline. Passing through 9,000 ft, severe thrust asymmetry developed, and the captain noticed rudder input from the autopilot. Shortly after, at 1853, the crew received the engine‑indicating and crew‑alerting system (EICAS) message ENG FAIL R, and the right engine shut down.

In response, the flight crew declared a PAN[3] and requested air traffic control clearance to level off at 5,000 feet and be vectored off the approach to allow time for completion of the quick reference handbook (QRH) checklist items. Completion of the QRH checklist required the flight crew to decide whether they should attempt to relight the engine. Due to the proximity of the airport and because the aircraft is capable of landing safely with one engine, the flight crew decided that attempting an engine restart was unnecessary. After the checklist was completed, the flight crew conducted a NITS[4] briefing with the cabin crew.

Subsequently, the flight crew completed the landing performance calculations and advised ATC that they were ready to land. The flight crew also requested that emergency services conduct a visual inspection of the aircraft after landing.

At 1909, the aircraft landed safely at Perth Airport and emergency services carried out a visual inspection. The aircraft was cleared to taxi to the parking bay and disembark passengers normally via the aerobridge.

There were no injuries sustained and no damage to the aircraft as a result of the occurrence.

Context

Subsequent maintenance

Following the occurrence, an engineering team carried out a detailed inspection of the aircraft to address the in‑flight shutdown and status/EICAS warning messages observed by the crew. The technical examination resulted in replacement of the right engine hydro‑mechanical unit (HMU) and a high‑power engine run was then successfully performed.

On 12 October 2018, a non-revenue flight (no passengers or cargo) was conducted to return the aircraft to Singapore for further maintenance, during which time the electronic engine controller (EEC) was replaced. The aircraft then returned to revenue service.

On 15 October 2018, the aircraft was on a flight from Sydney to Singapore when several maintenance messages indicating similar issues to the occurrence flight were generated, but there was no noticeable effect on engine performance. Following the flight, additional components were replaced, including the:

  • HMU (further replacement)
  • fuel pump
  • high‑ and low‑pressure fuel filters
  • left and right variable stator vane actuator.

The aircraft was then declared serviceable and returned to service with no further recurrence of the maintenance messages.

Engine fuel system

The Trent 1000 fuel system includes a three-stage pump that supplies fuel from the aircraft to the engine. Fuel runs through a low pressure (LP) pump followed by two high pressure (HP) pumps, identified as primary and secondary, running in parallel. The primary HP pump operates under all conditions, while the larger secondary HP pump increases fuel flow to the engine at periods of high demand, such as take-off.

The HP pumps supply fuel to the HMU, which controls fuel flow to the engine using its fuel metering valve (FMV) as follows:

  • Fuel enters the FMV servo assembly within the HMU through an inlet filter.
  • To change the flow rate of fuel supplied to the engine, the EEC sends electrical signals to the FMV servo assembly.
  • The signals control the position of a valve, which changes the fuel pressures within the servo assembly.
  • These servo pressures determine the position of the FMV, which ultimately controls the flow rate of fuel to the burners.

Rolls-Royce investigation

Following the occurrence and subsequent non-revenue flight to Singapore, the engine manufacturer, Rolls-Royce, conducted an investigation into the occurrence. This included reviewing flight data from both flights, examining engine components from 9V-OJE, and based on its findings, assessing the Trent 1000 fleet more widely.

Review of flight data

Approximately 2 hours into the flight, during cruise, the right engine’s EEC generated the following message:

Hydro-Mechanical Unit (Right Engine) fuel metering valve (FMV) torque motor current is too low or too high.

This message indicated that the current required to adjust the fuel flow via the FMV was outside the expected range. Eleven minutes later, another message indicated that the current had exceeded an allowable limit:

Hydro-Mechanical Unit (Right Engine) fuel metering valve (FMV) torque motor current is failed too low or too high.

During descent, approximately 3 hours later, two more messages were generated:

Hydro-Mechanical Unit (Right Engine) fuel metering valve (FMV) is not in commanded position.

Right Engine is failed below idle with fuel switch on.

Rolls-Royce determined that the first message was evidence the FMV was taking longer than it should have to reach the position specified by the EEC. It was found that the second message was generated after the EEC had commanded a deceleration. The FMV moved below the idle position as requested, but once deceleration had occurred, it did not move back to the directed idle position. The right engine then ran at sub-idle speed for a short time before shutting down. Data for the entire occurrence flight indicated that the torque motor current required to control the FMV position increased throughout the flight up until the in‑flight shutdown.

Rolls-Royce also identified that the maintenance messages generated during the flight to Singapore on 15 October 2018 indicated that control of the new FMV was still requiring a higher-than-expected torque motor current. However, the engine continued to operate normally, and the flight was completed without incident.

Component examination

Rolls-Royce examined the HMU from the occurrence flight (HMU 1) as well as the one from the subsequent flight (HMU 2). In both units, a build-up of metallic debris was found in various locations, although more debris was found in HMU 1. The inlet filter to the FMV servo assembly was at least partially blocked with debris in both units.

Rolls-Royce concluded that the in-flight shutdown of 9V-OJE’s right engine was the result of the blocked inlet filter on the FMV servo assembly. The blockage restricted the EEC’s ability to control the FMV, and ultimately, the flow of fuel to the engine.

The FMV servo assemblies from each HMU were scanned using CT imaging. The resulting x-ray cross sections are shown with photographs of each servo assembly in Figure 1.

Figure 1: Blocked inlet filters on both FMV servo assemblies

Figure 1: Blocked inlet filters on both FMV servo assemblies.
The build-up of metallic debris was greater on HMU #1. Some deformation can also be observed in the #1 inlet filter x-ray image. Rolls-Royce determined that this was likely due to the high pressure differential caused by the blockage.
Source: Rolls-Royce

The build-up of metallic debris was greater on HMU #1. Some deformation can also be observed in the #1 inlet filter x-ray image. Rolls-Royce determined that this was likely due to the high‑pressure differential caused by the blockage.

Source: Rolls-Royce

Analysis of the metallic debris revealed that it consisted of material from the fuel pump bearings and the casing. All three stages of the pump (the LP pump, and the two HP pumps) were disassembled and examined by Rolls-Royce in the presence of the United Kingdom Air Accidents Investigation Branch.

The examination found that the debris originated from the secondary HP pump. The bearings for the secondary HP pump driven gear were heavily worn, with evidence of scoring and missing material (Figure 2). Rolls-Royce found that the casing for the driven gear had more wear than would be expected during normal operation, likely due to shaft movement resulting from the damaged journal bearings. No damage was found on other bearings within the secondary HP pump or the other two fuel pumps.

Figure 2: Worn journal bearings and casing for the secondary HP pump driven gear

Figure 2: Worn journal bearings and casing for the secondary HP pump driven gear.
Source: Rolls-Royce

Source: Rolls-Royce

Rolls-Royce reviewed the manufacturing records for the secondary HP pump but found that it was typical of the fleet. No abnormalities had been noted, and the pump dimensions were within the accepted tolerances. The material composition of the fuel pump components was checked and found to be similar to the rest of the population. The fuel pump and HMU from the left engine were removed and inspected as a precaution, but there was no evidence of journal wear or debris build-up.

Trent 1000 fleet inspection

On 1 November 2018, another Scoot Boeing 787 generated maintenance messages related to the HMU during start-up, prior to a flight. The engine was inspected, and some wear was also found on the secondary HP pump journal bearings.

To search for similar HMU maintenance messages, Rolls-Royce examined all maintenance data across the fleet of Trent 1000 Package B and Package C engines and continued to monitor ongoing flights. Six other events were found where messages were generated due to fuel pump debris blocking the FMV servo assembly inlet filter. Five of these events were from aircraft operated by Scoot, while one was from a different operator.

Of the events found in the Scoot fleet, the age of the pumps varied between 5,201 and 12,686 hours. The recommended life of the pumps was 22,000 hours. Based on the number of occurrences compared with the greater Trent 1000 fleet, Rolls-Royce determined that the secondary HP pump journal bearings on Scoot aircraft were particularly susceptible to low life journal wear.

In an effort to determine what was increasing wear susceptibility in the Scoot fleet’s bearings, Rolls‑Royce identified a number of potential factors, including the following:

  • Pump manufacture and build: The worn pumps found on Scoot aircraft had been manufactured over a number of years from 2015 to 2017. As such, it was determined that a batch or build issue was unlikely to be a common factor.
  • Fuel quality: Analysis of fuel samples from Singapore Changi Airport found no anomalies within the 12 months prior to the occurrence involving 9V-OJE. There were also no reports of fuel pump bearing wear from other Trent 1000 operators that used the same airport.
  • Operations: Rolls-Royce noted that Scoot generally flew shorter routes than most other Trent 1000 operators, but there were comparable operations with no evidence of fuel pump journal wear. Within the Scoot fleet, aircraft flew to multiple destinations, and there were no specific city pairs associated with the engines with worn bearings.
  • Maintenance: Scoot shared its maintenance facilities with another operator that also used Trent 1000 engines. There was no evidence of fuel pump bearing wear from this operator.

Based on its investigation, Rolls-Royce concluded the following:

It is likely that a combination of factors have led to Scoot bearings being particularly susceptible to significant low life wear, but analysis of data to date has not identified any significant differences between worn and unworn bearings, both within the Scoot fleet and the wider Trent 1000 Pack B & C fleets.

It was further noted that the majority of Scoot events occurred between late 2018 and early 2019. With the exception of the occurrence flight, none resulted in an in-flight shutdown.

The Rolls-Royce investigation also considered factors in addition to those listed above but, due to the number of variables, was unable to identify which might have been dominant with respect to the pump bearing wear. However, it identified and implemented interim measures (mainly related to engine data monitoring) to address the risk from low life wear of bearings.

Safety analysis

While on descent into Perth, the right engine of 9V-OJE shut down. After completing the necessary checklists, the flight crew landed the aircraft safely on one engine. There were no injuries sustained as a result.

The engine manufacturer, Rolls-Royce, concluded that the engine shutdown was the result of a blocked inlet filter on the fuel metering valve (FMV) servo assembly. This blockage restricted the electronic engine controller’s (EEC) ability to adjust fuel pressures within the servo. As a result, the EEC had limited control over the FMV position, and consequently the amount of fuel flowing to the burners. When the EEC commanded the FMV to increase fuel flow from sub‑idle to idle levels, it did not respond in time, and the engine shut down. The blockage was due to debris from worn journal bearings in the secondary HP fuel pump driven gear.

Rolls-Royce’s examination of flight data and maintenance records from its Trent 1000 engines identified that Scoot’s fleet of 787 aircraft had been particularly susceptible to low life wear in their secondary HP pump journal bearings over a period of several months. The Rolls-Royce investigation identified various potential factors that might have contributed to low life journal wear, including the fleet’s operation, maintenance, fuel quality, or pump design and construction. However, it found no evidence that any factors were significantly different to the wider Trent 1000 fleet. Additionally, due to the number of variables associated with operations, maintenance, design and manufacture, it was not possible to determine the relative effect of these factors (and possibly others) when combined.

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition, ‘other findings’ may be included to provide important information about topics other than safety factors.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the uncommanded engine shutdown involving Boeing 787-9, 9V-OJE, on 11 October 2018 near Perth Airport.

Contributing factors

  • Following a series of status and alert messages related to the aircraft’s right engine, the engine shut down during descent. The flight crew followed the appropriate procedures and landed the aircraft safely using the operational engine.
  • The engine shutdown was the result of insufficient fuel delivery due to low pressure in the fuel metering valve servo assembly, as debris from worn fuel pump bearings had blocked its inlet filter.
  • The engine manufacturer, Rolls-Royce, identified that between late 2018 and early 2019 the operator’s fleet of 787 aircraft were particularly susceptible to low life wear in the journal bearings of the secondary high‑pressure fuel pump.

Other finding

  • Rolls‑Royce identified a number of potential factors that led to the component wear but, due to the number of variables, a single/dominant reason could not be established.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Safety action by Rolls-Royce

As part of its investigation into the engine failure, Rolls-Royce instructed Scoot to remove the engine’s fuel pump in the event of debris being found in the ports during removal of a hydro‑mechanical unit. In February 2020, the Fault Isolation Manual was updated to instruct all operators to remove the fuel pump and hydro-mechanical unit in the event of a maintenance message regarding the fuel metering valve not being in the commanded position.

Rolls-Royce is investigating the possibility of detecting potential fuel pump bearing journal wear by using flight data (particularly the fuel metering valve torque motor current) to detect partial filter blockage before maintenance messages are generated. It is also continuing to monitor maintenance messages and the condition of unserviceable fuel pumps ‘to ensure that the risk of an in-flight shutdown caused by fuel pump bearing wear is maintained at an acceptable rate’.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the aircraft captain
  • Scoot Tigerair
  • Rolls-Royce.

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • the aircraft captain
  • the aircraft first officer
  • Scoot Tigerair
  • Rolls-Royce
  • The Boeing Company
  • the Civil Aviation Safety Authority
  • the Transport Safety Investigation Bureau of Singapore
  • the United States National Transportation Safety Board
  • the Air Accidents Investigation Branch (United Kingdom).

Submissions were received from:

  • Rolls-Royce
  • the United States National Transportation Safety Board
  • the Air Accidents Investigation Branch (United Kingdom).

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Western Standard Time (WST): Coordinated Universal Time (UTC) + 8 hours.
  2. Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 250 equates to 25,000 ft.
  3. PAN PAN: an internationally recognised radio call announcing an urgency condition which concerns the safety of an aircraft or its occupants but where the flight crew does not require immediate assistance.
  4. NITS – Acronym encompassing the nature of the emergency, the intentions of the flight crew, the time available before landing, and the need for a special instructions brief.

Occurrence summary

Investigation number AO-2018-069
Occurrence date 11/10/2018
Location Perth Airport
State Western Australia
Report release date 01/12/2020
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Engine failure or malfunction
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer The Boeing Company
Model 787-900
Serial number 37116
Aircraft operator Scoot
Sector Jet
Operation type Air Transport High Capacity
Departure point Singapore
Destination Perth Airport, Western Australia
Damage Nil

Loss of separation involving Boeing 737 aircraft, VH-YFW and VH-VZD, near Amberley, Queensland, on 11 October 2018

Final report

Report release date: 04/12/2019

Safety summary

What happened

On 11 October 2018 a Qantas Airways Boeing 737-800, registered VH-VZD (VZD) was inbound to Brisbane, Queensland from Melbourne, Victoria on a scheduled passenger flight. Another Boeing 737-800 also on a scheduled passenger flight, operated by Virgin Australia Airlines and registered VH-YFW (YFW), departed Brisbane, Queensland for Proserpine, Queensland. The two aircraft were on reciprocal tracks in the Amberley Queensland airspace when a loss of separation occurred. The aircraft inbound to Brisbane, VZD, was being controlled on the Royal Australian Air Force (RAAF) Amberley (military) air traffic control (ATC) frequency and the aircraft outbound from Brisbane, YFW, was being controlled on a Brisbane (civil) ATC frequency.

What the ATSB found

RAAF Amberley and Brisbane ATC operated non-linked air traffic management systems, which did not share a common display. Between ATC jurisdictions without linked systems information was shared using manual coordination between ATC elements.

The departing aircraft from Brisbane (YFW) entered Amberley airspace without a hand‑off from Brisbane ATC and without instructions to the crew to change to the Amberley frequency. This resulted in YFW monitoring an incorrect frequency on entry to Amberley airspace and Amberley ATC initially unable to communicate with the flight crew.

The Brisbane departures air traffic controller did not hand‑off the departing aircraft YFW until after it had entered Amberley airspace. In addition, just prior to this incident, Brisbane terminal control unit did not advise Amberley ATC of a change in configuration to the terminal control unit consoles. This led to Amberley ATC contacting the incorrect console position at Brisbane ATC once the departing aircraft had entered Amberley airspace, and delayed the opportunity for Amberley ATC to resolve the impending conflict.

Once appropriate communication with Amberley and Brisbane ATC was established, the outbound aircraft was transferred to the Amberley frequency, and the aircraft were initially diverted away from each other, before being re-established on their respective tracks.

What’s been done as a result

Following the occurrence both RAAF Amberley and Brisbane ATC have taken corrective actions to improve communication and coordination between the two units. This has included deploying a dedicated communications pathway between Amberley approach and the Brisbane Departures South air traffic control positions, and implementing an airspace release that controls the risk that short notice deviations present across the non-linked systems.

Safety message

This incident highlights the importance of clear communication and coordination between air traffic controllers operating in different, yet immediately adjacent airspace. Air traffic controllers need to maintain a clear understanding of responsibility for separation assurance, especially when operating without a shared traffic picture. This incident also illustrates the effectiveness of the conflict resolution training received by air traffic controllers in loss of separation events.

 

The occurrence

What happened

On 11 October 2018 at about 1413 Eastern Standard Time (EST),[1] there was a loss of vertical and lateral separation standards in military airspace near the Royal Australian Air Force (RAAF) Amberley aerodrome, Queensland, involving two Boeing 737-800 aircraft. Prior to the loss of separation the two aircraft were operating in the same airspace but on different frequencies, with one aircraft controlled by RAAF Amberley (military) air traffic control (ATC) and the other by Brisbane (civil) ATC.

Sequence leading to the incident

At 1406 a Qantas Boeing 737-800, registered VH-VZD (VZD), operating as QF618 on a scheduled passenger flight from Melbourne, Victoria to Brisbane, Queensland, was on descent to Brisbane Airport and passing through RAAF Amberley airspace, which was controlled by military ATC. Weather warnings were in place for Brisbane and Amberley airports as a frontal weather system, including thunderstorms, was approaching from the west and moving east. About that time, a Virgin Australia Airlines Boeing 737-800 aircraft, registered VH-YFW (YFW) operating as VA1117 on a scheduled passenger flight, departed Brisbane Airport from runway 19 on an initial heading of 195, and turned right onto a heading of 230 and was on climb to flight level (FL)[2] 180. Due to the convective weather in the area, YFW was unable to use a procedural standard instrument departure, and was flying assigned radar headings provided by ATC. The flight crew advised the Brisbane departures controller that they were unable to make any further turns to the right at that time due to the convective weather.

At 1410, as YFW was approaching Amberley airspace, the Brisbane departures controller provided the RAAF Amberley approach controller with an identification on the aircraft, as required by the procedures in the Manual of Air Traffic Services (MATS): Supplementary South East Queensland.[3] At this time, the Amberley approach controller advised the Brisbane departures controller of the inbound aircraft on air route Y195 (Figure 1). The Brisbane departures controller replied that YFW would be turning right soon. The Brisbane departures controller then asked the flight crew of YFW to advise when they could turn right (north). The flight crew advised they would like to stay on heading 230 for an additional 70 to 80 NM due to the weather. It was around this time that YFW entered Amberley airspace (Figure 1), while still communicating with the Brisbane departures controller.

At this time, RAAF Amberley approach was being controlled by a trainee approach controller under supervision of a training supervisor.

At 1411:56, the Amberley approach controller attempted to contact the Brisbane departures south controller regarding the inbound aircraft VZD but was advised that they were speaking to the incorrect controller due to an earlier Brisbane terminal airspace configuration change (see Brisbane airspace configuration). The Amberley training officer took over from the trainee controller in the Amberley approach position, and about 17 seconds later established contact with the Brisbane departures controller, advising them of the inbound aircraft (VZD). The Brisbane departures controller questioned the assigned altitude of VZD raising concern over the potential conflict with YFW, which was now within Amberley airspace. At this point, the two aircraft were still on different radio frequencies, with VZD on the Amberley approach frequency, and YFW on the Brisbane departures frequency.

Figure 1: Position and direction of the two aircraft when VH-YFW entered Amberley airspace at 1411:44. The red line indicates the boundary between Brisbane airspace (right) and Amberley (left) airspace. Air route Y195 was assigned to VH-VZD.

Figure 1: Position and direction of the two aircraft when VH-YFW entered Amberley airspace at 1411:44. The red line indicates the boundary between Brisbane airspace (right) and Amberley (left) airspace. Air route Y195 was assigned to VH-VZD. Source: Airservices Australia – modified by the ATSB

Source: Airservices Australia – modified by the ATSB

At 1412:20, the Brisbane departures controller advised the Amberley approach controller that YFW would contact them for separation, and at 1412:29 instructed the flight crew of YFW to contact Amberley approach. Around this time, the Brisbane ATC display presented a short term conflict alert (STCA) to the Brisbane departures controller. At about the same time the Amberley approach controller issued a safety alert[4] to VZD and instructed the crew to turn left (north). Upon contact with YFW at 1413:10, the Amberley approach controller issued a safety alert and instructed them to turn to left (south). After both aircraft had turned and separation recovery actions were complete, VZD resumed its descent into Brisbane and YFW continued its flight to Proserpine.

Both aircraft were fitted with a traffic collision avoidance system[5] (TCAS) which would have assisted in providing separation instructions to the flight crew in the event ATC were unable to resolve the situation.

Airspace information

The red line in Figure 1 shows the delineation between Brisbane and Amberley airspace. The local coordination procedures between Brisbane and Amberley ATC are described in the MATS: Supplementary South East Queensland. This document included the following:

  • the hand-off of (aircraft) must be initiated prior to 5 NM (9.26 km) of the boundary
  • when runway 19 is in use, the standard assignable level is FL 130 for aircraft on approach to Brisbane on the air route Y195, through Amberley airspace
  • Brisbane Terminal Control Unit (TCU) are to advise Amberley of any changes to the position of Brisbane departures south. This includes if it is merged with Brisbane approach south or Brisbane departures north.

Brisbane and Amberley ATC used different air traffic management systems to control their airspace. These systems were not linked and did not display the same information, so the Amberley controllers did not get details of aircraft which were not entering their airspace as the details were not entered by their planning function. The Brisbane controllers were required to contact the Amberley controllers to provide them an aircraft’s identification and basic details if the aircraft was approaching the boundary between Brisbane and Amberley airspace.

Aircraft hand-off

ATC recordings and interviews identified that the Brisbane departures controller originally intended to turn the departing aircraft, YFW, to the north avoiding Amberley airspace. Amberley controllers stated that YFW came further into their airspace than they were expecting, as they were expecting it to turn north based on communications with the Brisbane departures controller. The Brisbane departures controller reported that several previous aircraft had ‘accepted’ turns to the north-northwest.

The Amberley approach controller had not received a hand‑off of YFW when it entered Amberley airspace. The hand-off of YFW occurred after the impending conflict with the inbound aircraft (VZD) was identified by the Brisbane departures controller. The Brisbane departures controller reported that they had expected Amberley to assure separation between the aircraft by assigning VZD to maintain FL 190, however 5 minutes before YFW entered Amberley airspace VZD had been instructed by the Amberley approach controller to descend to FL 130.

Brisbane airspace configuration

Prior to the occurrence, and due to the World Parachuting Championships at Runaway Bay (about 65 km south-south-east of Brisbane Airport), the airspace sectors for the Brisbane TCU were not in the usual configuration. Due to the proximity of the inbound and outbound tracks of aircraft around the parachute operations, one controller was controlling all departures and approaches in the southern area. Due to the weather front approaching, the parachuting championships were put on hold prior to the incident.

About 5 minutes prior to the incident, at about 1407, the Brisbane airspace was returned to a more standard configuration, being that the departures controller controlled all departures to the south and north. The Brisbane approach south controller was controlling all aircraft approaching from the south. It was reported that this change, back to the more standard configuration was not communicated to Amberley ATC.

Amberley to Brisbane communication

Amberley approach and Brisbane TCU controllers used three tele-communication lines. These included direct lines to the following sectors: Brisbane approach north, Brisbane approach south and Brisbane departures north. There was no direct line to Brisbane departures south. Brisbane TCU used combinations of sectors whereby the sector of Brisbane departures south was always combined with one of the other sectors. In accordance with agreed procedures, Brisbane TCU was required to notify Amberley when the position of Brisbane departures south changed.

The Amberley controllers stated that they were not aware that Brisbane departures positions had been combined until they contacted the incorrect controller. The Airservices internal investigation stated that the Brisbane TCU did not advise Amberley of the change of configuration. There was approximately 4 minutes and 30 seconds from the time Brisbane departures was combined and the Amberley approach controller contacting the incorrect Brisbane controller.

Workload

The presence of the rapidly moving weather front, including thunderstorms, around Brisbane meant that many aircraft were unable to operate on standard instrument departures. This resulted in an increase in coordination requirements for the air traffic controllers. The Brisbane departures controller had continuous communications with multiple aircraft for approximately 6 minutes prior to the loss of separation.

Separation

Once the two aircraft were operating on the same frequency, they were instructed to deviate from their flight path away from each other by the Amberley approach controller. The two aircraft passed each other and had a loss of separation,[6] where the required separation was 3 NM horizontally or 1,000 ft vertically, and the minimum recorded distances were 2.1 NM and 650 ft.

Safety analysis

The Brisbane departures controller intended to turn the departing aircraft YFW to the north, avoiding Amberley airspace. When YFW did not accept turns to the north, it was unlikely the situation was effectively reassessed by the Brisbane departures controller resulting in YFW entering Amberley airspace without a hand-off. The presence of the rapidly moving weather front likely increased the workload for the Brisbane departures controller due to the increase in aircraft coordination requirements, and this may have influenced the delay in the hand-off of YFW to the Amberley approach controller.

When YFW entered Amberley airspace without a hand-off from the Brisbane departures controller it was operating on a different frequency to Amberley approach and other aircraft in Amberley airspace. This resulted in the Amberley approach controller being unable to effectively manage the multiple aircraft, specifically YFW, in their airspace and therefore reduced their ability to maintain separation standards.

Amberley ATC were not expecting YFW to enter their airspace due to the Brisbane departures controller stating the aircraft would be turning north soon, which was consistent with their actions for several previous departing aircraft. This, combined with the aircraft operating on a different frequency to Amberley approach, resulted in a delay in the Amberley approach controller being able to resolve the impending conflict. The Brisbane departures controller was expecting the Amberley approach controller to assure separation between the two aircraft, but was unaware that VZD was already on descent and therefore in conflict with YFW.

Due to the World Parachuting Championships, the Brisbane Terminal Control Unit (TCU) were not operating in a standard configuration on the day of the occurrence. When the TCU reverted back to a more standard configuration this was not communicated to Amberley ATC as per the agreed procedure. Consequently, this led to a delay in the Amberley approach controller being able to contact the Brisbane departures south controller due to the incorrect position being contacted. Further, this resulted in a delay in the aircraft being transferred to the Amberley approach controller to effect recovery of the compromised separation scenario. The time from configuration change to the Amberley approach controller contacting the incorrect Brisbane position (4 minutes and 30 seconds) suggests that there was an opportunity for Brisbane TCU to advise Amberley ATC of the new configuration prior to the Amberley approach controller requiring contact with the Brisbane departures south controller.

The Amberley approach controller contacting the incorrect controller resulted in a reduction of potential recovery time of 17 seconds before the correct Brisbane controller was reached. Calculations based on the estimated ground speed of both aircraft obtained from Airservices indicate that this 17-second delay led to a reduction in the lateral separation of the two aircraft by approximately 6 km (3.24 NM). This delay in communication between Amberley and Brisbane ATC reduced the amount of time available to recover the impending loss of separation while the aircraft were closing on reciprocal tracks in opposite directions. If this configuration change was immediately relayed to Amberley ATC, it would have allowed the Amberley approach controller more time to resolve the impending conflict between the two aircraft, and separation requirements may have been maintained.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The departing aircraft was not expected to enter Amberley airspace but did so without hand‑off of control from the Brisbane departures controller, resulting in the aircraft operating on a different frequency to the Amberley approach controller and the other aircraft operating in Amberley airspace.
  • The Brisbane departures controller did not hand‑off the departing aircraft until after it had entered Amberley airspace due to the original intention to turn the aircraft north prior to the airspace boundary.
  • The Brisbane Terminal Control Unit did not advise Amberley of the changed terminal control unit configuration. This led to Amberley approach contacting the incorrect Brisbane controller once the departing aircraft had entered Amberley airspace, and delayed the opportunity for Amberley approach to resolve the impending conflict.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Airservices Australia

As a result of this occurrence, Airservices Australia (civil air traffic control) advised the ATSB that they are taking the following safety actions:

  • Implementing airspace releases that control the risk that short notice deviations present across the non-linked systems.
  • Deployed dedicated communication lines between Amberley ATC and Brisbane departures south.

Royal Australian Air Force (RAAF)

As a result of this occurrence, RAAF (military) air traffic control has advised the ATSB that they have taken the following safety actions:

  • A communications line to Brisbane departures south has been established and commenced operational use.
  • The relevant parties are working together to implement a solution to ensure separation assurance between Brisbane departing aircraft and Amberley traffic during weather diversions.
  • Amberley have submitted a documentation change to Airservices Australia to extend the weather colour coding to include the Brisbane TCU/Amberley approach interface.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours.
  2. Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 180 equates to 18,000 ft.
  3. Manual of Air Traffic Service (MATS): Supplementary South East Queensland is the document agreed to by Air Traffic Controllers (civil and military) and identifies coordination requirements for the region.
  4. The provision of advice to an aircraft when air traffic control becomes aware that an aircraft is in a position which is considered to place it in unsafe proximity to terrain, obstructions, active restricted or prohibited areas, or another aircraft.
  5. An aircraft collision avoidance system monitors the airspace around an aircraft for other aircraft equipped with a corresponding active transponder and gives warning of possible collision risks.
  6. Loss of separation (LOS): an occurrence in which the spacing between two or more aircraft is less than prescribed separation minima in airspace where the aircraft is subject to an air traffic service.

Occurrence summary

Investigation number AO-2018-070
Occurrence date 11/10/2018
Location Near Amberley Airport
State Queensland
Report release date 04/12/2019
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Loss of separation
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer The Boeing Company
Model 737-8FE
Registration VH-YFW
Serial number 41037
Aircraft operator Virgin Australia Airlines
Sector Jet
Operation type Air Transport High Capacity
Departure point Brisbane Airport, Queensland
Destination Proserpine Airport, Queensland
Damage Nil

Aircraft details

Manufacturer The Boeing Company
Model 737-838
Registration VH-VZD
Serial number 34198
Aircraft operator Qantas Airways
Sector Jet
Operation type Air Transport High Capacity
Departure point Melbourne Airport, Victoria
Destination Brisbane Airport, Queensland
Damage Nil

Loss of control and collision with terrain involving BRM Aero S.R.O Bristell LSA aircraft, VH-YVX, at Stawell, Victoria, on 5 October 2018

Final report

Report release date: 29/06/2020

Safety summary

What happened

On 5 October 2018, a BRM Aero Bristell light sport aircraft (LSA), registered VH-YVX, departed Moorabbin Airport, Victoria, with a pilot and passenger on board. The purpose of the flight was a navigation exercise in support of the pilot’s commercial pilot training requirements. Following an overfly of the intended waypoint at Stawell Airport, the aircraft was observed by witnesses to conduct a number of aerobatic‑type manoeuvres before control was lost. The pilot was unable to recover control of the aircraft before it impacted terrain. The occupants sustained significant injuries and the aircraft was destroyed.

What the ATSB found

The ATSB determined that, contrary to the aircraft’s limitations and the pilot’s qualifications, aerobatic manoeuvres were conducted during the flight, and immediately prior to the loss of control. The aircraft experienced an accelerated aerodynamic stall and entered into an upright, fully‑developed spin. Although the pilot did not consistently apply the manufacturer’s recommended spin recovery technique, recovery from a fully‑developed spin may not have been possible in the aircraft type.

The avionics system fitted to the accident aircraft had data storage capability and also backup storage capability by way of a secure digital (SD) card which could be fitted to the avionics system. An SD card was not fitted as standard equipment when Bristell aircraft were delivered to operators from new. Further, the operator was not aware of the additional memory card storage capability and had not installed SD cards in any of their Bristell fleet.

What's been done as a result

Following a number of fatal spin‑related accidents involving BRM Aero Bristell aircraft in Australia and overseas, the Civil Aviation Safety Authority (CASA) reviewed the flight test data supplied by the aircraft manufacturer against the ASTM standard for which the manufacturer self‑certifies compliance. CASA found that there was not enough information in the initial and follow-up test data to provide them with assurance that the aircraft type meets the required standards for spin recovery. At the time of writing the final investigation report, the manufacturer and CASA were still in discussion.

The operator conducted a fleet-wide installation of SD cards to all aircraft capable of storing data.

Safety message

Aerobatic flight should not be undertaken by pilots who have not been adequately trained, as it requires specialist techniques and methods to maintain control of the aircraft during significant manoeuvring. Further, aircraft manufacturers that prohibit aerobatics in certain aircraft types do so because the aircraft has not been designed and/or tested to ensure these manoeuvres can be conducted safely. This accident clearly demonstrates the catastrophic consequences when the hazards of aerobatic flight are not managed.

Aircraft data recording systems can be a readily accessible tool for both flying training, maintenance and safety investigation. Aircraft owners should make themselves aware of the data recording capability of their aircraft and ensure that the systems are fully functioning and backing up information.

 

The occurrence

What happened

On 5 October 2018, at about 1220 Eastern Daylight‑saving Time,[1] a Bristell light sport aircraft, registered VH-YVX, departed Moorabbin Airport, Victoria, with a pilot and passenger on board. The purpose of the flight was a navigation exercise in support of the pilot’s commercial pilot training requirements. The passenger held a student pilot licence, however their aviation medical certificate was not current. Photographs taken during the flight indicated that the passenger operated the aircraft for brief periods, but the ATSB assessed that this did not contribute to the development of the accident.

Automatic Dependence Surveillance Broadcast and on-board flight and GPS data recorded the aircraft position and attitude throughout the flight (see the section titled Recorded information). The data showed the take-off and flight over the northern part of Port Phillip Bay, followed by the commencement of significant manoeuvring overhead a built-up area to the west of Melbourne (Figures 1 and 2).

Figure 1: Aircraft’s flight path and accident site location

Figure 1: Aircraft’s flight path and accident site location.
Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB

Figure 1 details the flight path of the aircraft in the area labelled as ‘Detail A’ in Figure 1. The data showed that the pilot conducted significant manoeuvres including steep climbs, descents and turns in excess of 90° angle of bank over a built-up area and at heights between 600‑1,300 ft above ground level (AGL).

In discussing that segment of the flight, the pilot stated that a 360° turn was conducted over the house of someone the pilot knew in the area. The pilot did not recall conducting any aerobatics or significant manoeuvring at that time.

Figure 2: Detail A – Recorded data of the aircraft flight path over a built-up area

Figure 2: Detail A – Recorded data of the aircraft flight path over a built-up area.
Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB

The aircraft then continued to Bacchus Marsh Airport where the pilot conducted a circuit followed by a touch-and-go landing. The aircraft then continued in a north‑west direction until overhead Stawell Airport (Figure 3).

At about 1240, three witnesses at Stawell Airport observed the aircraft overfly the airport before commencing a 180°turn back towards the south‑east. Following that turn, the aircraft was observed to commence a number of significant manoeuvres including steep climbs and turns described as aerobatic in nature. The aircraft was then observed to abruptly enter a flat spin (see the section titled Spins and spin recovery) and descend out of view.

Analysis of the recorded data identified that, after passing overhead the airport, manoeuvres far in excess of the aircraft’s performance limitations were conducted. Based on the magnitude of the recorded pitch and roll values, the manoeuvres were classified as aerobatic. Further data analysis established that while the aircraft was pitching and rolling out from a diving left steep turn, it experienced an accelerated aerodynamic stall[2] while rolling at an indicated airspeed of about 93 kt. The aircraft subsequently flick-rolled and entered a fully developed upright spin at an altitude of about 1,650 ft AGL. The aircraft maintained the spinning descent until it impacted terrain.

The pilot stated that, immediately prior to the accident, a turn of no more than 50° angle of bank was conducted in the process of lining up for a practice circuit and landing at Stawell Airport when ‘the back end of the aircraft slid out’ and control was lost. The pilot also stated that the accident occurred prior to reaching the airport.

When provided with detail of the recorded flight data and other accounts, the pilot was unable to reconcile the difference between their recollection of the event and that of the witnesses and the recorded data. Figure 3 shows the aircraft track, manoeuvring and spin. The red portion of the flight track is the point at which the GPS lost signal and position data was no longer recorded. This was likely due to a combination of the aircraft’s rapid movements and the GPS antenna position. From that point onwards, position data was calculated using groundspeed, bearing and barometric altitude data.

Figure 3: Detail B – Aircraft operation in the vicinity of Stawell Airport

Figure 3: Detail B – Aircraft operation in the vicinity of Stawell Airport.
Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB

A witness at Stawell Airport notified emergency services about the accident. Two other witnesses at the airport used an aircraft to locate the accident site and guided the emergency services to the location by flying overhead. The pilot and passenger sustained serious injuries and were airlifted to hospital. The aircraft was destroyed.

__________

  1. Eastern Daylightsaving Time (EDT): Coordinated Universal Time (UTC) + 11 hours.
  2. An aerodynamic stall occurs when the relative angle of the wings through the air exceeds a critical angle. This can occur at any airspeed and aircraft attitude within the structural limitations of the aircraft. In this case, the term ‘accelerated’ refers to the wings supporting a load greater than the weight of the aircraft due to manoeuvres, resulting in an aerodynamic stall occurring at higher than the published 1 G wings-level indicated airspeed.

Context

Pilot information

General information

The pilot attained a Private Pilot Licence (Aeroplane) on 13 August 2018 and had about 160 hours of flying experience. At the time of the accident the pilot was undergoing training for the issue of a Commercial Pilot Licence (Aeroplane) qualification. The pilot was not trained or endorsed to conduct aerobatics.

Medical information

The pilot held a current Class 1 Aviation Medical Certificate with a requirement to conduct additional assessments as directed by the Civil Aviation Safety Authority. The pilot confirmed being well-rested on the day of the flight, with no medical issues.

Stall and spin recovery training

According to the pilot’s instructor, the pilot had been taught theoretical and practical stall recovery techniques, including recovery from an incipient spin. The pilot’s training records indicated that the pilot had demonstrated the correct incipient spin recovery technique to their instructor and flight examiner on several occasions.

Aircraft information

General

The BRM Aero Bristell is a light sport aircraft (LSA). It is an all-metal, low-wing monoplane of semi-monocoque construction with side-by-side seating and dual flight controls. It is driven by a 4-cylinder, 4-stroke, normally aspirated piston engine, driving a composite three-blade constant-speed propeller. It has a maximum all up weight of 600 kg (Figure 4).

Figure 4: Exemplar BRM Aero Bristell LSA aircraft

Figure 4: Exemplar BRM Aero Bristell LSA aircraft.
Source: Aircraft operator with permission

Source: Aircraft operator with permission

VH-YVX Airworthiness and maintenance

BRM Aero Bristell LSA serial number 284 was manufactured in 2017 and registered in Australia as VH-YVX.

At the time of the accident, the aircraft was:

  • operating on a special Certificate of Airworthiness in the light sport aircraft (LSA) category
  • approved for private operations/flight training
  • maintained in accordance with the manufacturer’s maintenance schedule
  • operating under a current maintenance release with no outstanding defects or maintenance. It indicated that the aircraft had about 928 flight hours since new.
Approved aircraft manoeuvres

The aircraft operating instructions (AOI) section 2.9 had approved manoeuvres listed as follows:

• Steep turns not exceeding 60° bank

• Lazy eights

•Chandelles

• Stalls (except whip stalls).

The section also had the following warning:

Aerobatics and intentional spins are prohibited.

The same warning is also included as a placard on the cockpit instrument panel (Figure 5).

Figure 5: Depiction of placard attached to the instrument panel

Figure 5: Depiction of placard attached to the instrument panel.
Source: Bristell LSA operating instructions

Source: Bristell LSA operating instructions

Section 2.10 of the AOI identified the maximum manoeuvring load factors as +4.0 to -2.0 G.

Integrated instrument and avionics system

The aircraft was fitted with a Garmin G3X avionics system, which was an integrated flight instrumentation, position, navigation and communication system.

Recorded flight data

The G3X unit had a flight data logging feature which automatically stored flight and engine data to its memory module. A secure digital (SD) card can also be fitted as a backup memory storage that can be easily removed from the aircraft so that the flight data can be downloaded for operational and maintenance monitoring purposes. A data file was created each time the system was powered on with an SD card inserted, or each time an SD card was inserted after power on.

A 2 GB SD card can store over 1,000 hours of flight data or up to 1,000 files (whichever comes first). The SD card is normally located in a receptacle on the right upper face of the unit. However, an SD card was not provided with the aircraft when it was first supplied from the manufacturer. It was therefore at the owner’s discretion if they wished to utilise the recording feature. No SD card was installed at the time of the accident.

Stall warning and angle of attack display

When the angle of attack (AOA) system identifies an exceedance in the calibrated caution alert threshold, an intermittent audible warning will be heard. The tone will increase in frequency until it reaches the AOA stall warning threshold, at which point the audible warning will change from intermittent to continuous.

In conjunction with the audible warning, the AOA system will display a change from a solid green to yellow in the caution level. It flashes from yellow to red when it reaches the stall warning threshold (Figure 6).

Figure 6: Angle of attack on the primary flight display

Figure 6: Angle of attack on the primary flight display.
Source: Garmin G3X Pilot’s Guide, modified by the ATSB

Source: Garmin G3X Pilot’s Guide, modified by the ATSB

Regulatory definition and requirements for aerobatic flight

Definition of aerobatic flight

Civil Aviation Safety Regulations 1998 (CASR) Dictionary, Part 1 Definitions defined aerobatic manoeuvres as those that involve:

(a) bank angles that are greater than 60˚; or

(b) pitch angles that are greater than 45˚, or are otherwise abnormal to the aircraft type; or

(c) abrupt changes of speed, direction, angle of bank or angle of pitch.

Regulatory requirements for aerobatic flight

To conduct aerobatic manoeuvres, pilots are required to have an aerobatics flight activity endorsement entered on their pilot’s licence. To obtain this endorsement, a pilot is required to have received training and demonstrated competency in all the course units mentioned in CASR Part 61 Manual of Standards. That training includes recovery from unusual attitudes and spins.

CASR 61.065 prohibits the conduct of any activity for which the licence holder is not authorised. In addition, CASR subpart 61.S Flight activity endorsements stated the requirements for aerobatic endorsements. These included an initial aerobatic endorsement that would authorise the pilot to conduct aerobatic manoeuvres in an aeroplane above 3,000 ft above ground level (AGL). Subsequent endorsements were necessary for aerobatic activities at lower altitudes.

Also, Civil Aviation Advisory Publication (CAAP) 155-1(0) Aerobatics provided pilots with:

information and guidance on safety issues related to aerobatic flight, including in respect of the aircraft, pilot and regulations

an explanation of spin recovery techniques

advice on the importance of ensuring sufficient height to recover from an aerobatic manoeuvre by 3,000 ft AGL (or the lower limit of the pilot’s approval).

In particular, section 7.3.2 of the CAAP stated:

It is highly probable that the consequence of an error or failure during low-level aerobatics will be fatal to the participants.

Finally, Civil Aviation Regulation 1988 (CAR) 155 at section 5.1 (5) stipulated that:

Aerobatics are not permitted over populous areas or public gatherings without the written permission of CASA.

Spins and spin recovery

Overview

An aerodynamic spin is a sustained spiral descent in which one or both an aircraft’s wings are in a stalled condition,[3] with the outside wing producing more lift and less drag than the other wing. The associated forces sustain the rotation and keep the aircraft in the spin. A spinning aircraft will descend more slowly than one in a vertical or spiral dive and it will have a lower airspeed, which may oscillate. The pitch angle can also vary considerably from significant pitch down to a relatively flat attitude.

Intentional spins are normally entered from a stall in straight and level flight, via the application of full back elevator and full rudder in the intended direction of rotation at the moment of the stall. The circumstances of a spin entry during aerobatic manoeuvring can be very different. If for example, aerobatic manoeuvres are incorrectly conducted, an unintentional consequence can be a flick roll[4] and entry into a spin.

Incipient spin

When entering a spin, an aircraft motion through the air is irregular at first. This is a transition phase from the stall and is known as incipient spin. Though the nature of the incipient spin is heavily dependent on the aircraft type and the manner of entry, recovery may be more rapid and require less control input in this stage compared with recovery from a developed spin.

Developed Spin

After a number of rotations and depending on the aircraft loading, type and control inputs, an aircraft in an incipient spin may settle into a regular rotating descent known as a developed spin. A developed spin is typified by reduced oscillations when compared to an incipient spin and the axis of rotation becomes vertical. The spin may steepen (nose down) or flatten (nose more horizontal) as it continues.

Recovery from an unintentional spin

The BRM Aero Bristell LSA AOI, section 3.7 described the recovery from unintentional spins as follows:

There is no[t] an uncontrollable tendency of the airplane to enter into a spin provided the normal piloting techniques are used.

Unintentional spin recovery technique:

1. Throttle - idle

2. Lateral control - ailerons neutralized

3. Rudder pedals - full opposite rudder

4. Rudder pedals - neutralize rudder immediately when rotation stops

5. Longitudinal control - neutralize or push forward and recover dive.

Spinning ceases only when opposing forces and moments overcome auto-rotation. Since yaw coupled with roll powers the spin, the pilot must forcibly uncouple them by applying the recommended spin recovery technique. Due to rotational inertia, spin recovery is not instantaneous. It may take several turns of the applied technique before recovery control forces finally overcome the spin stabilising forces and rotational inertia. Spins are only recoverable when the cumulative effects of the interacting variables favour recovery and there is enough altitude and therefore time to recover. Generally speaking, recovery from an incipient spin will take less time than a recovery from a fully developed spin. It is therefore vital that the correct recovery technique is implemented as soon as possible.

Pilot and passenger recollection of the attempted spin recovery

The pilot stated that the aircraft did not provide him with an aural or visual warning of an impending stall leading up to or during the accident sequence. When asked about the recovery technique following entry into a spin, the pilot confirmed that full opposite rudder was not maintained. Rather, the pilot initially applied opposite rudder to the spin and then reversed the control and noted that the spin rate increased. The pilot then moved the rudder back to the full opposite rudder position.

Analysis of the recorded data showed that the engine power was only slightly reduced following entry into the spin. Power was reapplied and then reduced to idle about 14 seconds after the spin commenced.

The passenger did not have a full recollection of the event but recalled the plane going pitch-up to a vertical position and then one rotation. The passenger remembered then saying ‘opposite rudder power down’ to the pilot before passing out prior to impact.

Although the passenger did not recall an audible warning when interviewed by the ATSB, they did mention hearing a beeping sound when discussing the event with their family a short time after the accident.

Light sport aircraft certification standards for spin recovery

Aircraft in the LSA category are certified to the ASTM International[5] standards. The certification process is conducted and self-certified for compliance by the manufacturer themselves, rather than by the regulating aviation authority from the state of manufacture. The LSA process relies on the manufacturer declaring that the aircraft meets all the construction and flight requirements of the LSA standards identified by them in the statement of compliance.

Aircraft certification standards for spin testing

ASTM F2245 standard specification for design and performance of light sport aeroplanes, section 4.5.9 states:

4.5.9 Spinning:

4.5.9.1 For airplanes placarded “no intentional spins,” the airplane must be able to recover from a one turn spin or a 3-s[econd] spin, whichever takes longer, in not more than one additional turn, with the controls used in the manner normally used for recovery.

In some aircraft not approved for spinning, recovery may not be possible if the spin progresses to the developed stage.

The standard has various requirements, for example the light sport aircraft category for non-aerobatic aircraft requires the aircraft manufacturer to prove the aircraft type can recover from a one-turn spin.

CASA assessment of BRM Aero Bristell LSA spin testing

The LSA category relies solely on the aircraft manufacturer declaring that each individual aircraft meets/complies with the standard(s) that they have indicated within the statement of compliance.  Each individual aircraft must have its own statement of compliance issued and signed by the aircraft manufacturer that the particular aircraft meets the identified standards. Manufacturers are not required to submit test data, or show compliance to those standards, to CASA or any other regulator.

Following a number of fatal accidents involving Bristell aircraft entering into and not recovering from spins in Australia and overseas, CASA assessed the Bristell LSA self-certification testing documentation against the ASTM certification test standards.

CASA found that there was insufficient information in the initial test data to provide assurance that the aircraft type met the ASTM standards for spin recovery. As a result, CASA requested more certification testing data from the manufacturer. The manufacturer conducted further certification flight tests in the Bristell LSA and provided that data, including video recordings of each flight sequence to CASA. CASA’s assessment of the new flight-testing data and further information supplied by the manufacturer was that it still did not confirm that the aircraft met the required ASTM standard for spin recovery.

Post-accident CASA guidance on spin avoidance

Due to an increase in spin‑related accidents across a broad range of light aircraft types in the training environment, CASA produced guidance material in the form of an advisory circular (AC) 61-16 v1.0 titled Spin avoidance and stall recovery training. The AC highlights:

…the risks associated with advanced stalling training when conducted in aircraft that are not certified for intentional spinning. It clarifies the difference between wing drop at the stall and the incipient phase of a spin and provides background for the interpretation of aircraft flight manual manoeuvre limitations with respect to spinning. It also provides guidance on acceptable methods of training and testing stalls with a wing drop and spin avoidance.

The AC provides detailed guidance for pilots, flight instructors, flight examiners and flight training organisations. The AC states that:

The key messages in this AC that are critical for the safe conduct of advanced stalling and spinning exercises, and that all pilots instructors, operators and flight examiners should be aware of are:

• A spin must not be induced in aircraft not certified or approved for intentional spinning

• A spin must not be induced without the pilot in command holding a spinning flight activity endorsement

• Aircraft flight manual limitations and any special procedures before conducting any exercise which may result in a spin

• The need to comply with aeroplane centre of gravity limits

• Wing drop at the stall for the purposes of spin avoidance training must not be induced by application of pro-spin rudder and the induction of a spin

• Training in spin avoidance must include the recognition of symptoms associated with slow flight and approach to the stall through to recovery from stall with a wing drop

• Recognise and manage changes in aircraft energy state

• Spin avoidance training where a wing may drop at the stall should be undertaken through scenario-based in-flight manoeuvres:

- Approach configuration descending turns (base to final turn)

- Go-around from approach configuration (significant change in trim state)

- Climbing turns in departure configuration (trim changes during flap retraction and turns)

- Engine failure after take-off (potential out of trim condition)

- Turns in slow flight.

Site and wreckage examination

The ATSB conducted an examination of the accident site and wreckage (Figure 7). The examination identified that:

  • the aircraft was located in relatively flat and open farmland, about 1.7 km south‑east of Stawell Airport
  • ground impact marks indicated that the aircraft had impacted terrain in a relatively flat, upright, counterclockwise spin
  • the flaps were in the retracted position
  • there was evidence of a significant amount of fuel at the accident site and the airframe fuel filter bowl was full of fuel and free of contaminants
  • the propeller blades showed rotation damage consistent with engine operation at a low power setting at impact
  • elevator trim was in a neutral position
  • no pre-impact defects were identified with the flight controls or aircraft structure
  • all aircraft components were accounted for at the accident site.

A Garmin G3X (G3X) panel‑mounted avionics unit was removed from the aircraft for detailed examination at the ATSB’s technical facility in Canberra.

Figure 7: Aircraft accident site

Figure 7: Aircraft accident site.
Source: ATSB

Source: ATSB

Recorded information

G3X avionics system flight data download

The ATSB inspected the G3X unit and identified that it was visually undamaged. There was no SD card fitted to the unit. On return to Canberra, the unit was powered up with an SD card fitted (Figure 8). Data files associated with the accident flight were successfully downloaded from the memory module to the card.

Figure 8: G3X avionics unit being downloaded, showing memory card position

Figure 8: G3X avionics unit being downloaded, showing memory card position.
Source: ATSB

Source: ATSB

Flight data summary

The downloaded data recorded 86 parameters for the duration of the accident flight, from the initial taxi until impact with terrain. The flight data indicated that the aircraft and engine were operating normally throughout the flight with no anomalies identified within the data or aircraft operating systems.

Position verification

The GPS position was verified to be accurate within 2 metres by utilising the aircraft’s:

  • track on the parking bay, taxi ways and runway at Moorabbin Airport
  • track during the touch-and-go on the runway at Bacchus Marsh Airport
  • final position at the accident site.
Significant aircraft manoeuvres

The data recorded that at about 1230, while the aircraft was overhead the built‑up area shown in Figure 2, it was operated significantly outside of its allowable flight envelope. This included banking to 94° while manoeuvring between 600‑1,300 ft above a populated area.

At 1319, the recording captured a 91° roll to the left followed by a pitch down to 40°. The data also recorded a climbing right turn to 91° angle of bank at 1323, followed by a pitch down to 38° then a rolling left pull out turn. Whilst pulling out, the instrumentation system recorded a peak normal acceleration of 4.4 G. That loading exceeded the aircraft’s positive load limit of 4 G.

From 1340, there was significant variation in the magnitude of pitch, roll and load factor, consistent with additional aerobatic manoeuvring during the final minute of the flight (Figure 9).

At 1340:36, while the aircraft was operating at:

  • about 90 kt indicated airspeed
  • a pitch-down angle of about 50°
  • high angle of attack and positive load factor

it abruptly pitched down to 90° and rolled significantly to the left. That behaviour was consistent with the aircraft experiencing an accelerated aerodynamic stall.[6]

Subsequent variation in the recorded parameters indicated that the aircraft then entered a counter-clockwise upright spin at a rotation rate of about one full turn every 1.5 seconds and a vertical descent rate of over 3,000 ft/min at the time of impact.

The engine power level remained at a constant high setting prior to the spin entry.

Figure 9: Last 60 seconds of recorded flight data parameters prior to the accident

Figure 9: Last 60 seconds of recorded flight data parameters prior to the accident.
Source: ATSB

Source: ATSB

Weight and balance information

The aircraft weight was calculated as being about 17 kg over the maximum allowable limit at take‑off from Moorabbin Airport, but within the balance limits. However, the aircraft was within the weight and balance limits at the time of the accident, when the weight was adjusted for 1 hour 20 minutes of fuel consumption.

Previous accidents

BRM Aero Bristell registered 24-7954, Clyde North, Victoria

This accident was investigated by Recreational Aviation Australia. The accident investigation report is not a publically available document.

On 3 August 2017, during a training flight, a student pilot was conducting stall recovery training under supervision of an instructor at an altitude of 3,500 ft AGL. Following entry into the stall, the right wing dropped and, despite the correct instructed actions, the student pilot mishandled the stall recovery by applying opposite aileron. Although this is an intuitive response to raise the wing, it exacerbated the stall and the aircraft entered a spin.

The instructor took over control of the aircraft from the student and initiated the correct spin recovery technique using ailerons neutral and opposite rudder. Despite having 3,000 ft remaining, the instructor was unable to regain control of the aircraft before it impacted the terrain. The student pilot was fatally injured, and the instructor sustained serious injuries.

BRM Aero NG5 registered G-OJCS, Belan, Co. Kildare Ireland

On 14 June 2019, during a flight with two occupants, recorded data showed that the engine power was reduced as the aircraft maintained about 3,200 ft with reducing airspeed. The aircraft then rapidly lost height and impacted the ground about 30 seconds later. The aircraft was destroyed and the two occupants were fatally injured.

The on-site examination indicated that the aircraft impacted the ground at a high vertical rate, in a nearly level attitude, whilst rotating anticlockwise about the yaw axis.

At the time of writing the accident was still under investigation by the Irish Aircraft Accident Investigation Unit.[7]

__________

  1. Aerodynamic stall: occurs when the airflow separates from the wings upper surface and becomes turbulent. It occurs at high angles of attack, typically 16–18° and results in reduced lift and increased drag.
  2. Flick roll: Essentially a horizontal spin, made by slowing to spinentry speed with engine throttled back and then applying full back stick and full rudder. Result should be a controlled very rapid 360° roll.
  3. ASTM International, formally known as the American Society for Testing and Materials, provide guidance for aircraft manufacturers in design and certification standards.
  4. Accelerated aerodynamic stall: For an aerofoil whose angle of attack is increased rapidly, the onset of the stall can be delayed to angles in excess of the static stall angle. Once an accelerated aerodynamic stall does occur, however, it is usually more severe and more persistent than static stall. The angle of attack must be reduced to well below the static stall angle to reattach the airflow.
  5. AAIU preliminary report 2019-008

Safety analysis

Introduction

Examination of the aircraft and recorded flight data identified that there were no mechanical defects that contributed to the accident. Further, a review of the meteorological conditions as described by witnesses and the pilot indicated that weather was not a factor.

Evaluation of the flight data also established that the pilot engaged in aerobatic manoeuvres during the course of the flight, including just prior to the loss of control in the vicinity of Stawell Airport. This analysis will discuss the development of the accident in that context.

Aerobatic limitations

The Bristell light sport aircraft (LSA) operating instructions prohibit excessive angles of bank, aerobatics and intentional spins. This was clearly defined and the information relating to spin avoidance was also presented by way of a placard in the cockpit.

Civil aviation regulations stipulate the types of manoeuvres that are considered to be aerobatic. It also sets out the pilot training and endorsements requirements before aerobatics are to be conducted. The framework provided by these rules ensures that this hazardous activity can be performed with an acceptable level of safety.

When interviewed, the pilot demonstrated an awareness of the aircraft limitations and the requirements relating to aerobatics. Further, the pilot did not have any training or endorsements in aerobatics and did not apply for or receive permission from CASA to undertake aerobatics over a populous area. Despite that, manoeuvres meeting the definition of aerobatics were carried out during the accident flight in the form of abrupt changes in flight parameters and excessive bank and pitch.

Aerobatic manoeuvring and loss of control

Aerobatics were first conducted above a built-up area at 600‑1,300 ft above ground level (AGL), and with a maximum bank angle of 94°. Had an unrecoverable loss of control occurred over such a populated area, in addition to the likely fatality of the occupants, there was a significantly increased risk of injuries or fatalities to people on the ground.

Additional aerobatics were conducted mid-flight between Bacchus Marsh and Stawell airports, with one exceeding the aircraft’s flight load limitations. The aircraft was then observed by witnesses to overfly Stawell Airport before again commencing significant pitch and bank manoeuvres. During one of these manoeuvres, the aircraft experienced an accelerated aerodynamic stall and entered into an upright spin at an altitude of about 1,650 ft AGL. This progressed into a fully developed spin that continued until the aircraft impacted terrain.

Due to the accelerated nature of the spin entry and the already nose-down and banked attitude, the entry to the spin would probably have been abrupt and disorientating. The pilot reported not maintaining the correct spin recovery technique with respect to rudder input. Despite that, as discussed further below, even with immediate and sustained application of spin recovery control inputs, recovery from the spin may not have been possible.

The pilot’s account of the aircraft manoeuvring during the flight, including immediately before the loss of control, did not align with either the flight data or the witness statements. The passenger only recalled fragments of information about the flight and did not recall what happened before the aircraft entered the spin.

The ATSB assessed that the recorded flight data was accurate. It clearly indicated that the aircraft was operated significantly beyond the allowable limits of both the aircraft and the pilot’s qualifications, with catastrophic consequences.

Aircraft spin certification and characteristics

Non‑aerobatic aircraft in the LSA category, such as the Bristell LSA, are certified to the ASTM International standards. As such, the aircraft is required to demonstrate the ability to recover from a one‑turn or 3‑second spin, whichever was longer, in not more than one additional turn. Recovery from a multiple-turn, fully developed spin is not required to be demonstrated.

As a consequence, there is no assurance that, even if the normal spin recovery technique was applied, that recovery from a fully developed spin is possible in the Bristell LSA aircraft.

In response to a number of fatal accidents involving Bristell aircraft entering and not recovering from spins in Australia and overseas, the Civil Aviation Safety Authority (CASA) assessed the Bristell LSA type certification testing documentation against the ASTM certification test standards. CASA found that there was insufficient information in the initial flight test data to provide assurance that the aircraft type met the ASTM standards for spin recovery. As a result, CASA requested more certification testing data from the manufacturer. The manufacturer conducted further certification flight tests in the Bristell LSA and provided that data, including video recordings of each flight sequence to CASA. CASA’s assessment of the new flight-testing data and other information provided after that point still did not confirm that the aircraft met the required ASTM standard for spin recovery. At the time of writing, CASA and the manufacturer were still in discussion.

In the context of this accident, as the aircraft was operated significantly outside its operating limitations, it was not possible to identify if a safety issue surrounding aircraft spin and recovery characteristics of the Bristell LSA exists.

Avionics memory and data use

There are many advantages to having recording devices installed in aircraft. These include the use of downloaded data to monitor:

  • student pilot performance
  • third party aircraft usage
  • engine health trends and aircraft limitation exceedances.

They also provide a significant source of evidence during the investigation of aircraft accidents.

The avionics system fitted to the accident aircraft had data storage capability and also backup storage capability by way of a secure digital (SD) card which could be fitted to the avionics system. An SD card was not fitted as standard equipment when Bristell aircraft were delivered to operators from new. Further, the operator was not aware of the additional memory card storage capability and had not installed SD cards in of their Bristell fleet. As a result, had the avionics unit memory module been damaged, then important recorded data associated with this accident could have been destroyed.

The ATSB encourages operators and owners of aircraft to, wherever possible, use on board recording capability to capture the available data parameters.

Findings

From the evidence available, the following findings are made with respect to the loss of control and collision with terrain involving a Bristell LSA aircraft, registered VH-YVX, in Stawell Victoria on 5 October 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • While conducting aerobatics, the aircraft experienced an accelerated aerodynamic stall and entered into an upright spin that continued until impacted terrain.
  • The pilot conducted aerobatic manoeuvres without aerobatic training, in an aircraft which prohibited such manoeuvres.

Other factors that increased risk

  • During the accident flight, the pilot conducted aerobatics at low altitude over a built-up area in contravention to safe practices and the regulations. Had an unrecoverable loss of control occurred there was a significantly increased risk of injuries or fatalities to people on the ground.
  • A regulatory review of the aircraft type’s self-certification flight test data and documentation by the Civil Aviation Safety Authority (ongoing at the time of writing) did not provide assurance that the aircraft type met the required standard for spin recovery.

Other findings

  • The aircraft's avionics system, while capable of storing data, was not fitted with a memory card. The memory card serves as a back-up for stored data, which can be a readily accessible tool for both flying training and safety investigation.

Safety issues and actions

Proactive safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Civil Aviation Safety Authority

During the investigation, the ATSB became aware that the Civil Aviation Safety Authority (CASA) was reviewing the BRM Aero Bristell LSA aircraft certification testing against the ASTM standards. At the time of writing, there was insufficient information available to assure CASA that the Bristell LSA aircraft met the required standard for spin recovery. Consequently, CASA has requested further information from the aircraft manufacturer.

The operator

The operator conducted a fleet-wide installation of SD cards to all aircraft capable of storing data.

Pilot details

Pilot details

Licence details:Private Pilot Licence (Aeroplane), issued 13 August 2018
Endorsements:Manual Propeller Pitch Control
Ratings:Single engine aeroplane
Medical certificate:Class 1 and 2, valid to 19 October 2018
Aeronautical experience:about 160 flight hours

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the pilot and passenger
  • witnesses and first responders to the accident
  • the aircraft operator and manufacturer
  • Civil Aviation Safety Authority
  • Airservices Australia
  • Victoria Police.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the pilot and passenger, the aircraft operator and manufacturer and the Civil Aviation Safety Authority.

Submissions were received from the pilot and passenger, the aircraft operator and manufacturer and the Civil Aviation Safety Authority. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Preliminary report

Report release date: 21/11/2018

This preliminary report details factual information established in the investigation’s early evidence collection phase and has been prepared to provide timely information to the industry and public. Preliminary reports contain no analysis or findings, which will be detailed in the investigation’s final report. The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

What happened

On 5 October 2018, at about 1120 Eastern Daylight‑saving Time,[1] a Bristell Light Sport Aircraft, registered VH-YVX, departed Moorabbin Airport, Victoria, with a pilot and passenger onboard. The purpose of the flight was a navigation exercise in support of the pilot’s commercial pilot training requirements. The passenger held a student pilot licence, but his aviation medical certificate was not current.

At about 1240, following an overfly of the intended waypoint at Stawell Airport, the aircraft was observed by witnesses to conduct a 180° turn towards the east at about 1,500 ft above ground level (Figure 1). Following the turn the aircraft was observed to commence a number of manoeuvres before entering a spin. The pilot was unable to recover control of the aircraft before it impacted terrain.

Figure 1: Aircraft’s flight path and accident site location

Figure 1: Aircraft’s flight path and accident site location. Source: Google earth, with Airservices surveillance radar data. Annotated by the ATSB

Source: Google earth, with Airservices surveillance radar data. Modified by the ATSB

A witness at the aerodrome notified emergency services about the accident. Two other witnesses at the aerodrome utilised an aircraft to locate the accident site and guided the emergency services to its location. The pilot and passenger sustained significant injuries and were airlifted to hospital. The aircraft was destroyed.

Site and wreckage examination

The ATSB conducted an examination of the accident site and wreckage (Figure 2). This examination identified that the:

  • aircraft was located in relatively flat and open farmland, which was about 1.7 km south‑east of Stawell Airport
  • ground impact marks indicated that the aircraft had impacted terrain in a relatively flat, upright, counter clockwise spin
  • flaps were in the retracted position
  • elevator trim was in a neutral position.

No pre-impact defects were identified with the flight controls or aircraft structure.

A panel‑mounted avionics unit was removed from the aircraft and taken to the ATSB’s technical facility in Canberra for examination. The stored information was successfully downloaded and included numerous flight and engine parameters recorded during the accident flight.

Figure 2: Accident site of Bristell Light Sport Aircraft, registered VH-YVX

Figure 2: Accident site Bristell Light Sport Aircraft, registered VH-YVX. Source: ATSB

Source: ATSB

Ongoing investigation

The investigation is continuing and will include:

  • interviews with parties involved in the accident
  • analysis of the downloaded data from the avionics unit and other electronic devices
  • examination of the pilot’s qualifications, experience and medical history
  • assessment of the aircraft’s flight performance characteristics
  • examination of aircraft maintenance and operational records
  • examination of the training organisation records and procedures.

___________________

The information contained in this preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the initial investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this update. As such, no analysis or findings are included in this update.

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Daylightsaving Time (AEDT): Coordinated Universal Time (UTC) + 11 hours.

Occurrence summary

Investigation number AO-2018-066
Occurrence date 05/10/2018
Location 1.7 km south-east of Stawell Airport
State Victoria
Report release date 29/06/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Serious

Aircraft details

Manufacturer BRM Aero S.R.O.
Model BRM Aero Bristell LSA
Registration VH-YVX
Serial number 284
Aircraft operator Soar Aviation
Sector Piston
Operation type Flying Training
Departure point Moorabbin Airport, Victoria
Destination Moorabbin Airport, Victoria
Damage Destroyed

Incorrect configuration involving Airbus A320, VH-VFX, Sydney Airport, New South Wales, on 29 September 2018

Final report

Report release date: 24/02/2020

Safety summary

What happened

On 29 September 2018, a Jetstar Airways Airbus A320 aircraft, registered VH-VFK, was operating a scheduled passenger flight from Sydney, New South Wales to Melbourne, Victoria. While preparing for the flight and having difficulties with the electronic system used for calculating take-off performance figures, the flight crew reverted to the back-up procedure of manual calculations.

Shortly after take-off, the maximum flap extended speed was exceeded. As the aircraft climbed through 2,800 ft, the flight crew retracted the landing gear after realising it was still extended, resulting in a landing gear retraction overspeed.

What the ATSB found

In completing the manual calculations for take-off performance, the flight crew inadvertently calculated speeds that were higher than required for the actual aircraft weight and environmental conditions. The incorrect take-off speeds were not identified by independent verification and cross-checking.

During the first segment of the take-off climb period, at maximum engine power settings, the aircraft pitch rate was below the recommended 3° per second, resulting in a higher acceleration rate than anticipated. Due to the incorrect calculated speeds, the aircraft rotated with a margin of only 16 kt to the flap extended limit speed. Five seconds after rotation, the flap extended overspeed event occurred.

The aircraft did not rotate to the correct pitch attitude and the pilot monitoring did not alert the pilot flying of this. However, he called ‘speed, speed’ in an attempt to assist the pilot flying manage the airspeed, to which the pilot flying reduced the engine power in response, rather than increasing the aircraft pitch. The action of reducing the engine power was taken when the aircraft was below the safe altitude above ground.

The landing gear would normally be retracted by the flight crew as soon as the aircraft had a positive rate of climb. In this case, the crew did not retract the landing gear when required. Climbing through 2,800 ft, they identified that the landing gear was still extended while troubleshooting the source of a buffeting noise. They then immediately selected the gear to ‘UP’ without first checking the aircraft speed, resulting in a landing gear retraction overspeed event.

What's been done as a result

Jetstar Airways advised that they undertook several actions to prevent a similar occurrence in the future. A safety summary of the incident was distributed to the wider pilot community, focusing on the importance of having the latest Flysmart software database version on their Electronic Flight Bag. It also highlighted the importance of considering reasonability and accuracy checks, consulting company procedure manuals in the event of Electronic Flight Bag issues, and conducting a normal rotation followed by reference to the Speed Reference System.

Safety message

This incident highlights the importance of independent validation and cross-check by the flight crew, in particular for performance speeds and aircraft weight.

The Airbus magazine Safety First #18 reports on potential problems with using incorrect reference speeds. This highlights the design and operational considerations underlying recommendations that Airbus has issued to flight crews.

 

The occurrence

On 29 September 2018, the flight crew of an Airbus A320 aircraft, registered VH-VFX and operated by Jetstar Airways, prepared to conduct a scheduled passenger flight from Sydney, New South Wales to Melbourne, Victoria. The flight crew had recently completed their third sector for that day in a different aircraft and were required to change aircraft for this flight, which had a scheduled departure time of 2200 Eastern Standard Time (EST).[1]

Take-off performance calculations – Electronic Flight Bag

The first officer, who was the designated pilot monitoring (PM)[2] for this flight, boarded VH-VFX in advance of the captain who was the pilot flying (PF) to begin flight preparations so as to minimise any delay. Jetstar had issued each pilot with their own electronic flight bag (EFB), an electronic information management device that helps the flight crew perform flight management tasks more easily and efficiently. The EFB enables the flight crew to access up-to-date information and contains applications to automate other functions, such as performance take-off calculations. Neither flight crew updated their EFBs before the first flight of the day, as required by Jetstar Airways.

The PM updated his EFB’s Flysmart[3] database shortly before the occurrence flight. When the PF arrived on the flight deck, he and the PM continued their preparations for departure. Both the PF and the PM used their respective EFBs to calculate the take-off performance data. The PF entered the data from his EFB into the flight management system (FMS)[4] performance take-off page. When the PM cross-checked the performance data displayed on his EFB with the information that the PF had entered into the FMS, he identified that the data was inconsistent. The PM and the PF then conducted a series of checks to troubleshoot the problem. During the flight crew’s attempt to identify the discrepancy, they found that the PF had an older software version of the EFB database on his device. The flight crew assessed that the out-of-date database was possibly related to the performance data discrepancy.

The PF attempted to update the database on his EFB, however, the device screen continuously displayed the ‘busy’ symbol and, at that time, the update was unsuccessful. The flight crew then attempted to use the spare EFB[5] on the aircraft. This had an outdated version of the software database.[6] The PF attempted to update the spare EFB. This update was also unsuccessful. Both the spare EFB and the PF’s EFB were effectively inoperative, continuously displaying the ‘busy’ symbol.

Take-off performance calculations – manual calculations

The flight crew resorted to the back-up procedure in which performance speeds were derived from manual calculations. The manual calculations involved reading the performance speeds off the regulated take-off weight (RTOW)[7] tables.

The PM recalled that he performed the calculations and that the PF agreed with the results, but the PM did not recall the PF independently performing that task. However, the PF’s recollection was that he did independently check the performance speed calculations that the PM had achieved. The flight crew agreed on the following performance speeds that were entered into the flight management system:

  • V1[8]: 157 kt
  • VR[9]: 161 kt
  • V2[10]: 164 kt.

Flap overspeed

The flight crew commenced the take-off at 2237 EST (1237 UTC), using the manually-calculated performance data and take-off/go-around (TOGA)[11] thrust. Table 1 shows the quick access recorder (QAR) data at one second intervals, including indicated airspeed (KIAS), aircraft pitch attitude, pitch rate and the pitch and thrust commands by the pilot flying. Aircraft data times below are in UTC. QAR data showed the aircraft rotated at 169 kt with an initial pitch rate of 2.8⁰/sec. After rotation, the pitch rate remained under the desired 3⁰/sec (see Speed Reference System), reducing across the next 7 seconds before increasing.

Table 1: Aircraft data showing pitch attitude and pitch commands

The green highlighted line shows the rotation. The shaded line shows the flap overspeed. The yellow highlighted line shows when the thrust was reduced. The orange highlighted line shows when the master warning has been triggered.

Source: Quick access recorder (QAR) data provided by Jetstar and tabulated by ATSB.

In the normal procedure, following take-off, the PM would call ‘positive climb’ and the PF would call ‘gear up.’ In this case, neither of the calls were heard by the other flight crew member, although they were both reported as having been made.

The PM reported then calling ‘speed, speed’, indicating that the aircraft was nearly at maximum speed for the flap extension configuration. The aircraft exceeded the flap extended limit speed 5 seconds after rotation (Table 1 and Figure 1).[13] By this time, at 1237:40 UTC, the aircraft was about 63 ft above ground level (AGL) and had a pitch attitude of 10.5° (green graph in Figure 1).

The overspeed warning was triggered when the airspeed exceeded the maximum flap extended speed (VFE[14]) by more than 4 kt. This occurred at a time between 1237:42 and 1237:43 UTC (the yellow and orange lines in Table 1). Airbus advised that the aircraft was at 180 ft radio altitude (AGL) at that time. The overspeed warning was displayed on the electronic centralised aircraft monitor, in addition to an aural warning and the master warning light.

Figure 1: Quick access recorder data graph showing take-off period

Figure 1: Quick access recorder data graph showing take-off period.
This graph shows when the master warning was recorded in the QAR data.
Source: Jetstar Airways quick access recorder data – graphed by ATSB

This graph shows when the master warning was recorded in the QAR data.

Source: Jetstar Airways quick access recorder data – graphed by ATSB

The PF retarded the thrust levers from the TOGA position 2 seconds after the flap overspeed, while the aircraft was at 144 ft AGL, which was below the thrust reduction altitude of 800 ft. After a further 7 seconds, the PF increased the thrust by advancing the thrust levers to the climb detent. The PF then retracted the flaps from position 3 to position 1.[15] The autopilot was engaged in climb mode and the aircraft continued climb with subsequent retraction of the flaps from position 1 to 0.[16]

Landing gear retraction overspeed

The take-off standard operating procedure was to retract the landing gear as soon as a positive climb rate was established. Shortly after completely retracting the flaps, the flight crew reported that they heard a ‘buffeting noise’. They commenced trouble-shooting the source of this sound and they identified that the aircraft’s auxiliary power unit (APU) was still on and delivering bleed air to the air-conditioning packs (as required when take-off performance speeds are calculated using the RTOW tables). Thinking that this may have been causing the buffeting noise, they turned the bleed air off, as per the standard operating procedures. This did not resolve the buffeting noise. The flight crew then realised the landing gear was still extended. The PF immediately called ‘gear up’ and the PM responded by retracting the landing gear immediately. The airspeed was then 250 kt,[17] which was above the maximum landing gear retraction speed of 220 kt.

The flight crew discussed the occurrence and, having no known adverse indications, decided to continue the flight to Melbourne.

__________

  1. Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours
  2. Pilot Flying (PF) and Pilot Monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances, such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
  3. Flysmart is the Airbus software installed on electronic portable devices so they function as an EFB.
  4. The flight management system is an on-board multi-purpose navigation, performance and aircraft operations computer. It automates a wide variety of in-flight tasks. It is comprised of the following interrelated functions: navigation, flight planning, performance computations, data communications and optimised route determination and en route guidance.
  5. Spare EFB is how this operator refers to the EFB kept on the aircraft.
  6. As outlined in the Jetstar A320 Company Procedures Manual: ‘The spare iPad may be up to 8 weeks out-of-date and so all required operational apps must be updated IAW normal procedures prior to operational use.’
  7. RTOW is the limiting take-off weight calculated for a particular runway under particular specified conditions.
  8. V1: the critical engine failure speed or decision speed required for take-off. Engine failure below V1 should result in a rejected take off; above this speed the take-off should be continued.
  9. VR: the speed at which the rotation of the aircraft is initiated to take-off attitude. This speed cannot be less than V1 or less than 1.05 times VMCG. With an engine failure, it must also allow for the acceleration to V2 at a height of 35 ft at the end of the runway.
  10. V2: the minimum speed at which a transport category aircraft complies with those handling criteria associated with climb following an engine failure. V2 is the take-off safety speed and is normally obtained by factoring the stalling speed or minimum control (airborne) speed, whichever is the greater, to provide a safe margin.
  11. TOGA: Take-off/go-around is a throttle position (detent) that gives the maximum available engine thrust for the environmental conditions. This throttle position is required when the performance speeds are manually calculated.
  12. Coordinated Universal Time (UTC): the time zone used for aviation. Local time zones around the world can be expressed as positive or negative offsets from UTC. Australian Eastern Standard Time = UTC + 10:00.
  13. The quick access recorder data was recorded once every second.
  14. VFE: maximum speed with flaps extended. VFE = 185 kt for flaps at configuration 3.
  15. The flap lever is marked 0, 1, 2, 3 and FULL. They mark flap stages: 1 = 10 degrees of flaps; 2 = 15 degrees of flaps; 3 = 20 degrees of flaps and FULL = 35 degrees of flaps.
  16. The take-off procedure in the Jetstar A320/A321 Flight Crew Operating Manual had several segments with instructions at each. The instructions to progressively retract the flaps were part of the segment for after the acceleration altitude has been reached. This is the altitude at which the pilot accelerates the aircraft by reducing the aircraft’s pitch, to allow acceleration to a speed safe enough to raise flaps and slats. The acceleration altitude in this case was 800 ft.
  17. This was below the maximum operating speed with the landing gear extended of 280 kt.

Context

Electronic flight bag

The operator’s procedures required the flight crew to verify the Flysmart software database version on their electronic flight bag (EFB), and update it if required prior to their first flight of the day. On this occasion, neither flight crew member updated their Flysmart software prior to their first flight of the day despite an updated version being available. Included in the updated version was the removal of an obstacle relevant to the departure runway. However, Jetstar Airways later reported that the two software versions should have produced identical take-off performance results for this flight. Different performance data could result from a discrepancy in manually entered parameters. For example, if the incorrect aircraft registration was entered into Flysmart, different performance data would likely result.

The standard operating procedures, which the flight crew were required to complete as part of the preparation of the aircraft, included steps for starting the EFB and using it to calculate the take-off performance data. Subsequently, the flight crew were required to complete the flight management and guidance system preparation, which included entering the take-off data from the EFB into the flight management system’s performance take-off page and completing a cross-check of that data.

For dispatch, the EFB’s AIB Take-off application[18] had to be present and functioning on two EFBs (which could include the spare EFB) unless backup provisions were satisfied. The backup provisions, as detailed in the Jetstar A320 Company Procedures Manual, were ‘manual take-off charts available and/or independent calculations on one device.’ Since the flight crew did not have the AIB Take-off application functioning on two EFBs, they chose to use the manual take-off tables. However, in accordance with the backup provisions, they could also have completed independent calculations on the one functioning device.

Manual calculation for performance values

The manual take-off charts (regulated take-off weight (RTOW) tables) served as a backup method for calculation of the performance speeds when Flysmart was not available. The tables and the instructions for using them were contained in the Jetstar A320/A321 Performance Manual. The instructions spanned three pages and the tables were contained in a separate appendix. The manual was stored electronically on the EFBs and the flight crew accessed it on the PM’s EFB.

To use the manual tables (extract shown in Figure 2), the flight crew had to select the row corresponding to the outside air temperature, in this case 15⁰ (shown by the green arrow). They then had to select the column corresponding to the wind, in this case ‘nil wind’ (shown by the green circle). The point where they intersect is the maximum RTOW for these conditions, which was 85.7 t (shown by the red box). The take-off reference speeds used by the crew corresponded to this row.

The next step in the procedure was to move down the wind column to the row with the weight that was nearest to, but greater than the actual take-off weight (TOW) of 64.5t. The instruction to move down the ‘wind column’ appears at the top of the second page of the instructions. In this case, that weight was 68 t. According to this method, 68 t corresponded to the performance speeds of V1 = 120 kt, VR = 128 kt, V2 = 133 kt (shown by the green box).

After the event, the pilot monitoring (PM) stated that, in hindsight, he did not complete the process and move down the wind column until the actual TOW was less than the RTOW, as required by the procedure.

Training to use the tables was included as part of the operator’s initial ground school and line training. Both flight crewmembers had received this training. However, as the EFBs had been very reliable, it was rarely necessary to use the tables. Additionally, there was no recurrent training or practice with the tables.

Prior to the introduction of Flysmart in 2014, the procedures and charts were the normal method of calculation for the take-off performance speeds. The pilot flying (PF) commenced with Jetstar in 2006, so had prior, although not recent, experience with the charts. The PM stated that before commencing with Jetstar 18 months ago, he had used similar charts for calculating performance speeds for a different aircraft type. Those charts, however, did not require the user to use the aircraft weight to go down the wind column.

The operator’s procedures explaining how to use the tables also stated that normally the PM will calculate and record the performance data. The PF will only enter the performance data into the multifunction control display unit (MCDU) once they have checked and confirmed the calculated data is correct. If the PF identifies an error in the PM’s calculations, they may recalculate the recorded data. In any case, both the PF and the PM must agree on any data before entry into the MCDU, which they did in this instance. However, as described above, there was different recollection among the two crewmembers about whether the PF independently checked the speed calculations.

Both the PF and the PM explained that their resulting take-off reference speeds were ‘on the faster side’ but that this was consistent with what they were expecting, because using the charts required using TOGA thrust.

Figure 2: Regulated take-off weight table

Figure 2: Regulated take-off weight table.
Source: Jetstar Airways – annotated by ATSB

The header of the table shows the aircraft type and variant, the airport location and runway to which the table applies. The sub-header gives more details about the airport and the configuration required. The main body of the table contains data provided for various temperature and wind combinations. The data corresponding to the ambient temperature (to the left) and the wind component (above) are RTOW in tonnes/ Performance Limit Code/Take-off speeds (V1, VR and V2). (Note: 100 must be added to VR and V2.). The performance limit code of *D is an obstacle limit weight. The lower sections of the table show corrections required for such things as wet runway, QNH corrections. They were not required in this case.

Source: Jetstar Airways – annotated by ATSB

Speed Reference System

The take-off procedure prescribed in the Jetstar A320/A321 Flight Crew Operating Manual (FCOM) stated:

At VR, initiate the rotation to achieve a continuous rotation with a rate of about 3°/s, towards a pitch attitude of 15°.

The FCOM further stated ‘After lift-off, follow the [speed reference system] SRS[19] pitch command bar.’ The speed reference system (SRS) shows a pitch line on the primary flight display (PFD). After rotation, the PF is required to bring the aircraft symbol on the PFD up to this line by rotating the aircraft at about 3°/s. While the pitch line is above the aircraft symbol, the PF is required to continue with a smooth rotation rate until the aircraft symbol intercepts the pitch line. From then on, the PF should aim to adjust the pitch only as necessary to keep the aircraft symbol on the pitch bar.

This guidance provided by the SRS helps the PF to maintain speed and pitch within defined parameters. With normal engine configuration, the SRS commands a target speed of V2 + 10 kt and contains speed protection limiting the target speed to V2 + 15 kt. In this case, the calculated V2 was 164 kt, giving a target speed of 174 kt. This speed was achieved less than 2 seconds after rotation. Using the correct weight for the manual calculations would have given a V2 of 133 kt, hence a target speed of 143 kt.

In addition to providing the correct pitch to maintain the target speed, the SRS pitch command bar also provides attitude protection to reduce the aircraft nose-up effect during take-off (limited to 18°) and flight path angle protection that ensures a minimum vertical speed of 120 ft/minute.

Airbus conducted a simulation using the data obtained from the Quick Assess Recorder (QAR), but modifying the pitch input to target a 3°/s pitch rate. From this they were able to conclude in this case the airspeed would have remained below 180 kt and that a 3°/s pitch rate would have prevented the flap overspeed. Airbus further advised that the SRS would likely have been indicating a pitch guidance lower than the maximum 18º. This was evidenced by the speed decrease of 3 kt/s when the pitch attitude reached 17º in response to the PF’s pitch-up input.

Thrust management

The Jetstar A320/A321 Performance Manual required the crew to use TOGA thrust when performance speeds calculated from the RTOW tables were used for take-off. TOGA thrust is the take-off/go-around throttle position that provides maximum power. For most take-offs, maximum power is not necessary and the aircraft can take off using less thrust than the engines are capable of producing, which reduces engine wear. This is implemented by assuming that the temperature for performance speed calculations is higher than actual outside air temperature. The ‘assumed temperature’ gives the required thrust for the available runway length.

The PF reported that TOGA take-offs were only used about two to three times a year and the PM said that he had never experienced TOGA thrust setting with the flaps in configuration three. The limit speed for flaps extended has a specific value for each flap setting—the higher the configuration of the flaps, the lower the limit speed.

The take-off procedure prescribed in the Flight Crew Operating Manual (FCOM) dictated that the thrust levers were to remain in the take-off configuration until the thrust reduction altitude was reached. A minimum thrust reduction altitude ensures that the aircraft has reached a safe height above the ground before reducing thrust.

The PM called ‘speed, speed’ to alert the PF to the impending flap overspeed event.

__________

  1. AIB Take-off is the application installed on the operator’s EFB used to calculate take-off performance figures for a given aircraft and environmental conditions.
  2. SRS: speed reference system. The SRS pitch command bar provides the correct pitch to maintain the target speed during take-off.

Safety analysis

Electronic flight bag

The flight crew did not have the same database versions on their electronic flight bags (EFB). The standard operating procedures required the version to be checked at sign-on each day. Had this been completed the databases on the flight crew’s EFBs would have been the same and the current database. Although the operator reported that the discrepancy should not have made a difference to the performance results obtained for this flight, had both databases been up to date, it is more likely the crew would have considered the source of the discrepancy between the two EFBs was related to something else, such as a data entry, and resolved the discrepancy.

Manual calculations of performance speeds

Instead of using the one serviceable EFB, the crew reverted to the manual take-off charts to calculate the performance speeds, a procedure rarely practiced by the crew. When using the manual performance tables to derive take-off speeds, it was unlikely the flight crew completed the full procedure for the manual calculation. The instruction to move down the ‘wind column’ appears at the top of the second page of instructions. It was likely that this step, and subsequent steps, were overlooked, resulting in performance speeds for the maximum regulated take-off weight (RTOW) being used.

The ATSB could not establish whether both of the flight crew independently made the same calculation error or if the results were not independently validated by the pilot flying (PF). Either way, the error by the pilot monitoring (PM) was not detected by the PF.

Rotation and flap overspeed

The actual rotation speed of 169 kt was only 16 kt below the maximum flap extended speed (185 kt), 41 kt closer than the correct rotation speed would have been. The PF rotated the aircraft at a rate significantly below the recommended rate of 3°/s. This resulted in the aircraft attitude reaching 10.5° pitch-up, instead of 15°, 5 seconds after rotation when the maximum flap extended speed was exceeded. The pitch attitude reached 15°; 11 seconds after rotation.

It is likely that the SRS was indicating guidance to the PF to increase the pitch, which, had the PF followed, would have reduced the aircraft acceleration. According to the simulation conducted by Airbus, if a 3°/s pitch rate had been achieved, the flap overspeed would not have occurred.

The PM did not bring to the attention of the PF the incorrect pitch attitude at take-off. Had the PM called ‘pitch’ it may have prompted the PF to increase the pitch. Jetstar stated this call was not specifically published, like many calls a PM would need to make to identify an incorrect control input.

Thrust management

When the PM called ‘speed, speed’, the PF reduced the engine power in response, as opposed to increasing the aircraft pitch. The thrust reduction occurred below the thrust reduction altitude and therefore had the potential to affect safety of the flight.

Landing gear retraction overspeed event

The retraction of the landing gear was not performed when positive climb was achieved. While troubleshooting a buffeting sound, the PF found that the landing gear was still extended and called ‘gear up’. The PM immediately retracted the landing gear without checking the aircraft’s actual airspeed relative to the maximum landing gear retraction speed. This resulted in an overspeed event when the landing gear was retracted beyond the maximum landing retraction speed. The correct procedure was to reduce the aircraft’s speed below the maximum landing gear speed before retracting the landing gear. There is no aircraft warning associated with this event.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The flight crew did not follow standard operating procedures to verify and update Flysmart database during sign on for the day.
  • When using manual calculations to obtain performance speeds, the flight crew made an error which was not detected by independent validation. This resulted in a calculated rotation speed based on an aircraft weight significantly heavier than the actual take-off weight.
  • The rotation rate commanded by the pilot flying was too low to prevent a flap overspeed, given the incorrect performance speeds and use of maximum take-off thrust.
  • In an attempt to manage the airspeed, the pilot flying reduced the thrust from the take-off setting, rather than increasing the pitch, but the aircraft was below the safe altitude above the ground to do so.
  • The landing gear was not retracted at the normal phase of the take-off. When the flight crew identified that the landing gear was still extended, they retracted it immediately, even though the aircraft was above the maximum landing gear retraction speed.

Safety action

The ATSB has been advised of the following proactive safety action in response to this occurrence.

Jetstar issued an internal safety summary to all flight crew outlining the occurrence and the learning outcomes from the incident. These included reminders to:

  • have the correct databases at the start of their duty and perform a verbal cross-check of the databases to ensure compliance
  • consider performance figures for reasonability and accuracy
  • carefully and methodically follow any available reference instructions, particularly when an ‘out of the ordinary’ circumstance arises
  • consult the Company Procedures manual in the event of electronic flight bag issues
  • conduct a normal rotation followed by reference to the speed reference system, in particular if it is noted that the aircraft is carrying a lot of energy.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the flight crew and Jetstar Airways.

Submissions were received from flight crew and Jetstar Airways. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2018-067
Occurrence date 29/09/2018
Location Sydney Airport
State New South Wales
Report release date 24/02/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Incorrect configuration
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer Airbus
Model A320-232
Registration VH-VFX
Serial number 5871
Aircraft operator Jetstar Airways
Sector Jet
Operation type Air Transport High Capacity
Departure point Sydney Airport, New South Wales
Destination Melbourne Airport, Victoria
Damage Nil

Collision with water involving Cessna 208B, VH-FAY, 185 km north-east of Tokyo, Japan, on 27 September 2018

Final report

Report release date: 18/03/2020

Safety summary

What happened

The pilot of a Cessna 208B aircraft, registered VH-FAY (FAY), was contracted by the aircraft operator to ferry FAY from Jandakot Airport, Western Australia to Mississippi, United States. On the morning of 27 September 2018 local time, the aircraft departed Saipan International Airport, Northern Mariana Islands, for a planned flight to New Chitose Airport, Hokkaido, Japan. After climbing for about an hour, the aircraft levelled off at flight level (FL) 220.

After 2 hours 20 minutes flight time, the pilot contacted Tokyo Radio flight information service at the first mandatory reporting position. The aircraft passed the next reporting point at the same altitude, 1 hour 20 minutes later, but the pilot did not contact Tokyo Radio as expected. Tokyo Radio made repeated attempts to communicate with the pilot, without success. Having received no communications from the pilot for 4.5 hours, two Japan Air Self‑Defense Force (JASDF) aircraft intercepted FAY. The pilot did not manoeuvre the aircraft in response, in accordance with international intercept protocols.

After about 30 minutes, the JASDF pilots observed FAY descend into cloud. The aircraft descended rapidly and disappeared from radar less than 2 minutes later. Within 2 hours, search and rescue personnel located the aircraft’s rear passenger door. No other aircraft parts were located and the pilot was not found.

What the ATSB found

While the aircraft was in the cruise on autopilot, the pilot almost certainly became incapacitated and did not recover. About 5 hours after the last position report, without pilot intervention to select fuel tanks, the aircraft’s engine stopped, likely due to fuel starvation. This resulted in the aircraft entering an uncontrolled descent into the ocean.

The cause of incapacitation could not be determined. While a medical event could not be ruled out, the pilot was operating alone in an unpressurised aircraft at 22,000 ft and probably using an unsuitable oxygen system, which increased the risk of experiencing hypoxia and being unable to recover.

What's been done as a result

The aircraft operator amended their operations manual to include additional guidance for international ferry flights. They also created an oxygen use guide and a specific risk assessment for positioning (ferry) flights.

Safety message

Operating unpressurised aircraft above 10,000 ft requires careful oxygen management and planning. Where an increased risk of hypoxia exists, good risk management practices should be used for flight planning. Because the effects of hypoxia can be insidious, training in recognition of early symptoms of hypoxia can increase the time available to react, descend and resolve any issues. The Flight Safety Australia (2014) article Do not go gentle: the harsh facts of hypoxia provides further information, including anecdotal experiences of hypoxia.

VH-FAY with full survey equipment installed

ao2018065_summary_final.jpg

Source: Sid Mitchell, Aviation Spotters Online

 

The occurrence

What happened

The pilot of a Cessna 208B aircraft, registered VH-FAY (FAY), was contracted to ferry the aircraft from Jandakot Airport, Western Australia (WA), to Greenwood, Mississippi in the United States (US). The pilot planned to fly via the ‘North Pacific Route’ (Figure 1).

At 0146 Coordinated Universal Time (UTC)[1] on 15 September 2018, the aircraft took off from Jandakot Airport, WA, and landed in Alice Springs, Northern Territory at 0743. After landing, the pilot advised the aircraft operator that the aircraft had a standby alternator fault indication. In response, two company licenced aircraft maintenance engineers went to Alice Springs and changed the alternator control unit, which fixed the problem.

Late the next morning, the aircraft departed Alice Springs for Weipa, Queensland, where the pilot refuelled the aircraft and stayed overnight.

On the morning of 17 September, the pilot conducted a 1-hour flight to Horn Island, Queensland. About an hour later, the aircraft departed Horn Island with the planned destination of Guam, Micronesia. While en route, the pilot sent a message to the aircraft operator advising that he would not land in Guam, but would continue another 218 km (118 NM) to Saipan, Northern Mariana Islands. At 1003, the aircraft landed at Saipan International Airport.

The next morning, the pilot refuelled the aircraft and detected damage to the propeller anti-ice boot. The aircraft was delayed for more than a week while a company engineer travelled to Saipan and replaced the anti-ice boot.

Figure 1: North Pacific Route

Figure 1: North Pacific Route.
Source: Aircraft operator – annotated by ATSB

Source: Aircraft operator – annotated by ATSB

At 2300 UTC on 26 September, the aircraft departed Saipan, bound for New Chitose Airport, Hokkaido, Japan. Once airborne, the pilot sent a message from his Garmin device, indicating that the weather was clear and that he had an expected flight time of 9.5 hours.

About an hour after departure, the aircraft levelled out at flight level (FL) 220.[2] Once in the cruise, the pilot sent a message that he was at 22,000 feet, had a tailwind and the weather was clear. This was followed by a message at 0010 that he was at FL 220, with a true airspeed[3] of 167 kt and fuel flow of 288 lb/hr (163 L/hr).

At 0121, while overhead reporting point TEGOD (Figure 2), the pilot contacted Tokyo Radio flight information service[4] on HF radio. The pilot was next due to report when the aircraft reached reporting point SAGOP, which the pilot estimated would occur at 0244. GPS recorded track showed that the aircraft passed SAGOP at 0241, but the pilot did not contact Tokyo Radio as expected. At 0249, Tokyo Radio made several attempts to communicate with the pilot on two different HF frequencies, but did not receive a response. Tokyo Radio made further attempts to contact the pilot between 0249 and 0251, and at 0341, 0351 and 0405.

Figure 2: VH-FAY GPS recorded track

Figure 2: VH-FAY GPS recorded track.
Source: Aircraft operator, Google Earth – annotated by ATSB

Source: Aircraft operator, Google Earth – annotated by ATSB

About 4.5 hours after the pilot’s last communication, two Japan Air Self-Defense Force (JASDF) aircraft intercepted FAY. The pilot did not respond to the intercept in accordance with international intercept protocols, either by rocking the aircraft wings or turning, and the aircraft continued to track at FL 220 on its planned flight route. The JASDF pilots were unable to see into the cockpit to determine whether the pilot was in his seat or whether there was any indication that he was incapacitated. The JASDF pilots flew around FAY for about 30 minutes, until the aircraft descended into cloud.

At 0626 UTC, the aircraft’s GPS tracker stopped reporting, with the last recorded position at FL 220, about 100 km off the Japanese coast and 589 km (318 NM) short of the destination airport. Radar data showed that the aircraft descended rapidly from this point and collided with water approximately 2 minutes later. The Japanese authorities launched a search and rescue mission and, within 2 hours, searchers found the aircraft’s rear passenger door (Figure 3). The search continued until the next day, when a typhoon passed through the area and the search was suspended for two days. After resuming, the search continued until 27 October with no further parts of the aircraft found. The pilot was not located.

Figure 3: Rear passenger door

Figure 3: Rear passenger door.
Source: Aircraft operator

Source: Aircraft operator

__________

  1. Coordinated Universal Time (UTC): the time zone used for aviation. Local time zones around the world can be expressed as positive or negative offsets from UTC.
  2. Flight level (FL): An aircraft’s height above mean sea level when the pressure at sea level is 1013.2 hPa, called pressure altitude. FL 220 equates to 22,000 ft pressure altitude.
  3. True airspeed (TAS): the speed of the aircraft relative to the air mass in which it is flying.
  4. A flight information service is a form of air traffic service available to aircraft within a flight information region that provides information pertinent to safe and efficient conduct of flight including information on other potentially conflicting traffic.

Context

Pilot information

According to information provided by the aircraft operator, the pilot had accrued over 13,600 hours of aeronautical experience and had conducted more than 200 ferry flights for various companies. The pilot held a valid US First Class Medical Certificate issued on 19 March 2018, with the restriction of vision correction. The 66 year-old pilot was reported by acquaintances to be a non-smoker, in good health for his age, and there was no evidence of any underlying medical conditions. In the nights before FAY departed from Saipan, the pilot had reportedly not slept well, but there was insufficient evidence to determine whether he could have been experiencing a level of fatigue that would affect performance.

The pilot was a Norwegian/American dual citizen with a United States (US) Airline Transport Pilot Licence issued in January 2018. For the ferry flight, a Certificate of Validation was issued by the Civil Aviation Safety Authority (CASA) on 14 September 2018 for a Commercial Pilot Licence (Aeroplane). This included the conditions that the flight ‘must be conducted in accordance with [the aircraft operator’s] operations manual and CASA legislative requirements pertaining to the flight planned route.’ In January 2018, the pilot had ferried another Cessna 208B aircraft, VH-FHY (FHY) from Canada to Perth, WA.

Aircraft information

VH-FAY (FAY) was a Cessna Aircraft Company C208B aircraft manufactured in the US in 2001. At that time, the aircraft was issued with a Certificate of Airworthiness and an associated Airplane Flight Manual.[5]

The aircraft was fitted with a Honeywell TPE331-12JR engine and a Hartzell Propeller Inc. HC-B4TN-5QL/LT10891NK (De-ice) propeller under a Supplemental Type Certificate (STC). Also under an STC, the aircraft had been fitted with an improved landing gear axle. This increased the maximum landing weight from 3,856 to 4,082 kg and the maximum take-off weight (MTOW) from 3,969 to 4,110 kg. Flight Manual Supplements (FMS) to the Airplane Flight Manual had been issued for each of these modifications.

FAY was fitted with a Garmin GTN 750 GPS. Among other options, the aircraft’s autopilot could be selected to ‘Altitude hold’, and lateral navigation mode could be selected to capture a GPS programmed flight plan.

The aircraft’s last Maintenance Release[6] was issued on 7 September 2018 following completion of extensive maintenance in preparation for overseas operations. It was valid for 14 months or 230 hours. At issue, the aircraft had 9,269.8 hours total time in service and was approved in the aerial work category and for flight under the instrument flight rules (IFR).[7]

On the morning of 27 September, prior to departure from Saipan, the aircraft had a total of 9291.7 hours in service.

Survey equipment

The aircraft was usually used for aerial survey work and had been fitted with an electromagnetic (EM) loop system under an Engineering Order[8] (EO) and an associated FMS had been issued. The system consisted of a copper cable loop suspended around the aircraft and supported by nose, wingtip and tail stingers with a transmitter mounted in the cabin. A receiver (bird) could be towed behind the aircraft on a cable, extended and retracted using a winch. The cable, bird and its cradle, and wingtip stingers had been removed in preparation for the ferry, and the tail stinger had been shortened but was still fitted to the aircraft. EM equipment in the cabin had also been removed, except for some fixed cables.

As the equipment was fitted under an EO, the aircraft had a Special Certificate of Airworthiness (CoA) that limited aircraft operation to the restricted category, for the purpose of aerial surveying.

The FMS for the EM loop limited the aircraft to a maximum operating airspeed of 161 kt and a maximum operating altitude of 20,000 ft, however, most of the equipment had been removed from the aircraft for the ferry. The design holder of the EM loop system advised the ATSB that exceeding the altitude limit had no safety implications in that configuration.

Although the aircraft was permitted to operate in IFR conditions, flight into known icing conditions was prohibited.

Ferry fuel tank and special flight permit

An aircraft that is not operated in accordance with its Type Certificate (and approved Supplementary Type Certificates) is not permitted to operate in foreign countries without a Special Flight Permit (SFP) and the approval of all countries the aircraft flies over or into.

For the ferry, FAY had been fitted with a ferry fuel tank under an engineering order with an associated FMS. The ferry fuel tank fitment meant that the aircraft no longer met the design requirements for the aircraft. Therefore, the aircraft was required to operate under an SFP. An SFP was issued on 6 September 2018 by a person authorised by CASA to issue SFPs, but not to issue overweight approvals.

The aircraft Type Certificate Data Sheet (TCDS) stated that the aircraft was structurally satisfactory for ferry flight up to 130 per cent of the TCDS MTOW (which equates to 11,375 lb or 5,160 kg). However, without overweight approval, the aircraft was required to be operated not above the STC MTOW of 9,062 lb (4,110 kg). The ferry tank FMS stated that ‘the ferry tank may only be able to be partially filled to stay within the aircraft 9062 lbs MTOW.’

Weight and balance

The load sheet indicated that on departure from Saipan, the aircraft’s take-off weight was 4,430 kg and it was loaded within the centre of gravity and structural limits.

Journey logs

The pilot completed journey logs for each flight sector, which included a daily inspection certification, take-off, landing and flight times, and fuel information. The pilot had also recorded engine condition trend monitoring information including the exhaust gas temperature (EGT) and RPM percentage. These are depicted in Table 1.

Table 1: Trend exhaust gas temperature (EGT) and engine RPM

DateEGT (°C)RPM (%)
15 September657100.5
16 September658100.4
17 September658100.2

Source: Aircraft operator

Operating the engine at 100.2 to 100.9 per cent was within the normal continuous engine speed allowable range. The FMS for the engine specified the maximum EGT as 650 °C. The engine manufacturer advised that operating at an average EGT of 658 °C relative to 650 °C increased fuel flow by about 5 lb (2.8 L) per hour under the conditions of the accident flight. The aircraft operator’s head of airworthiness and maintenance control advised that no inspection was needed for the recorded temperature exceedances, which could be avoided if the pilot reduced RPM to 100 per cent.

The journey logs were sent to the operator each day, however they were not reviewed during the ferry flight.

Communications

Radio equipment

The aircraft was fitted with the following equipment:

  • two VHF radios
  • one HF radio
  • a Spidertracks GPS connected via a switch on the instrument panel to a hot bus straight to the aircraft battery, so it would continue to operate in case of electrical failure
  • one Artex G406-4 emergency locator transmitter fitted with a G shock and remote panel switch
  • a satellite phone was installed in the aircraft, docked and with Bluetooth connection
  • four personal locator beacons (MT410G) and one Kannad marine sport emergency position indicating radio beacon were on board, all of which needed to be manually activated.

The pilot had a Garmin inReach system from which he could send and receive messages, navigate and track flights and ‘if necessary, trigger an SOS to get emergency help from a 24/7 global monitoring via the 100% global Iridium® satellite network.’

Push to talk

When the company licenced aircraft maintenance engineer (LAME) arrived in Saipan, the pilot advised him that the pilot-side push-to-talk (PTT) button had only been working intermittently and reported that he had been using the co-pilot-side PTT. The LAME cleaned and tested the button, which the pilot then verified was transmitting correctly.

Recorded data

GPS data

The on-board Spidertracks and Garmin GPS devices recorded the aircraft’s position and geometric altitude at 2-minute intervals. The recorded altitude of all sectors flown from Jandakot Airport to the last recorded position is shown in Figure 4. About half of the first leg, from Jandakot to Alice Springs, was flown at FL 210 before descending to FL 130, which was also the cruise altitude on the following sector to Weipa. On the flight from Horn Island to Saipan, having conducted a climb to FL 200, the pilot then made a descent over Papua New Guinea, possibly to avoid weather near Mount Hagen, before climbing and then maintaining FL 200.

The geometric altitude for the occurrence flight from Saipan showed a gradual descent from top of climb at 23,412 ft to the last recorded position at 22,770 ft. This was consistent with the aircraft flying into reducing temperature and barometric pressure. The corresponding radar data recorded pressure altitude at intervals of about 10 seconds and showed a constant altitude at 22,000 ft AMSL.

The pilot sent several messages from the Garmin device after departing Saipan and before the aircraft reached reporting point TEGOD. The last position recorded by the Spidertracks and Garmin devices was at 0626 UTC at FL 220. The aircraft took less than 2 minutes to descend from FL 220 to the ocean and there were no GPS recorded points below that altitude.

Figure 4: Geometric altitude of all flight sectors

Figure 4: Geometric altitude of all flight sectors.
Source: Spidertracks analysed by ATSB

Source: Spidertracks analysed by ATSB

Radar and ADS-B data

Japanese air traffic services recorded mode C radar and automatic dependant surveillance broadcast (ADS-B) data from FAY. Secondary surveillance radar (SSR) returns depend on an aircraft transponder’s reply to an interrogation from the ground. In response to a mode C interrogation, the aircraft transmits an encoded return with the aircraft’s selected SSR code and pressure altitude.

Radar data recorded the aircraft’s position (in X and Y coordinates) from the ground radar site and pressure altitude (referenced to 1013 hPa and quantised to the nearest 100 ft) at approximately 10-second intervals. ADS-B data transmitted from FAY’s GPS included the aircraft’s altitude within about 25 ft.

The aircraft was recorded by radar at 22,000 ft at 0627:36 and there were five valid radar returns after that. The data showed that the aircraft descended from 22,000 to the last recorded position of about 11,500 ft in 62 seconds, with an increasing descent rate of up to 22,000 and 23,000 ft/min. That descent rate was less than the dive speed (VD)[9] for the aircraft (250 kt calibrated airspeed), which corresponded to a vertical descent rate of about 25,300 ft/min.

Recorded audio transmissions

The ATSB obtained recorded audio of the pilot’s transmissions on HF radio to Tokyo Radio and VHF transmissions while tracking across Australia. Comparative analysis of these was carried out with the aim of determining whether the pilot was likely to have been using a nasal cannula and/or affected by hypoxia in the final transmission. Indicators of hypoxia include timing of microphone keying, voice onset time and fundamental frequency range of the pilot’s voice, but these could not be measured due to the noise in the HF channels. The pilot’s communications with Tokyo Radio at TEGOD included some hesitation and a misstated time, but the tempo of the pilot’s next transmission appeared normal and he corrected the time error. The ATSB was unable to make any conclusions based on the recorded audio.

Fuel

The aircraft was fitted with left- and right-wing tanks, which held a combined total of 1,257 L (2,225 lb) of usable fuel. The ferry tank held 924 L (1,635 lb) of usable fuel. The ferry tank was fitted under an engineering order with an associated FMS.

Based on the journey log and fuel dockets, the aircraft ferry and wing tanks were filled in Saipan on 18 September. Although the pilot had taxied the aircraft for maintenance, the fuel was likely close to full on departure. The LAME in Saipan had seen the pilot conduct a pre-flight fuel sample drain from the aircraft and check for contaminants, on the morning prior to departure.

There was no published fuel flow data for flight at FL 220, but the pilot reported an in-flight fuel consumption rate of 163 L/hr (288 lb/hr), which would have been relatively constant for the 6.4 hours in cruise. The aircraft took about 1 hour from taxi to reaching top of climb at 22,000 ft. The operations manual specified a planned fuel burn rate of 450 lb/hr in the climb and the design holder for the engineering orders estimated a taxi and climb fuel consumption of 353 lb. Given the pilot had previously started the aircraft and taxied for maintenance, an estimated fuel consumption for the taxi and climb was 400 lb. Based on these figures, the estimated total fuel used at the last recorded position was 1,241 L (2,196 lb), which was approximately the combined volume of the wing tanks.

Fuel transfer and imbalance

The fuel transfer protocol detailed in the ferry tank FMS was to conduct the take-off and climb to altitude using both aircraft main fuel tanks and, when established in the cruise, turn the left-wing tank selector to off, as fuel in the ferry tank could only be transferred to the right-wing tank. Two electric ferry tank pumps could be selected with different flow rates – 440 lb/hr (low) and 600 lb/hr (high). There was no gauge to indicate fuel quantity remaining in the ferry tank, and the pilot was required to monitor the fuel quantity of the right-wing tank to ensure fuel was transferring as planned and that fuel was not venting overboard.

The FMS specified 200 lb as the maximum permitted fuel imbalance between the left and right tanks. When more severe sideslip is maintained (due to imbalance), the unusable fuel quantity increases. In this occurrence, if the left tank selector was set to off at the top of climb and the right tank was used until empty, it was possible to have a 900 lb imbalance.

In August 1998, the Cessna Aircraft Company conducted flight tests at the request of the US National Transportation Safety Board to determine controllability of the Cessna 208B at various airspeed and lateral fuel imbalance combinations. A Cessna 208B aircraft was flown to a maximum 600 lb imbalance, at airspeeds between 70 and 120 kt at flap settings of 0° and 20°. The maximum control wheel deflection attained was about 28°, of the maximum available 55° control wheel deflection. Control deflection versus lateral imbalance curves were derived from the test. The ATSB extrapolated the data and found that for a 900 lb imbalance, at the aircraft’s likely airspeed, this equated to a control wheel deflection of +14°-17° and right aileron travel of +5-7°.

The aircraft manufacturer (now Textron Aviation) advised the ATSB that the autopilot servo was capable of driving the ailerons to the travel limits of 25° +4°/-0° up and 16° +1°/-0° down in the hangar. This indicated that if the aircraft had a fuel imbalance of 900 lb, there was adequate aileron control to maintain level flight at the aircraft’s likely airspeed, however the autopilot force required to maintain this was not assessed. Photos from the JASDF of FAY in the final 30 minutes of the flight did not show any visible aileron deflection.

Weather

During the last 30 minutes of the flight, the aircraft was observed to be situated between two layers of cloud. The weather conditions that the aircraft likely encountered at FL 220 included strong south-westerly winds averaging about 50 kt, temperature about -15 °C and moderate turbulence. Moderate icing and light rain were present in cloud.

Supplemental oxygen

Because of reduced atmospheric pressure, operation of unpressurised aircraft in Australia above 10,000 ft requires supplemental oxygen.

Flight crew oxygen requirements

Australian Civil Aviation Order (CAO) 20.4 – Provision and use of oxygen and protective breathing equipment, stated:

A flight crew member who is on flight deck duty in an unpressurised aircraft must be provided with, and continuously use, supplemental oxygen at all times during which an aircraft flies above 10 000 feet altitude.

CAO 108.26 – System specification – oxygen systems included that portable oxygen units may be used to meet the crew or passenger breathing requirements and that:

…flight crew members may use nasal cannula manufactured under the name “Oxymizer”, subject to the following conditions… (b) the flight crew members must use the nasal cannula only during private, aerial work, or charter, operations; (c) the aircraft must not operate above 18 000 feet altitude.

Further, it stated that ‘Dispensing units provided in an aircraft operating above flight level 180 must be designed to cover the nose and mouth.’

Aircraft oxygen system

The aircraft was fitted with a 13-port oxygen system with a 3.312 cubic metre (116.95 cubic foot) capacity oxygen cylinder located in the fuselage tail cone. The cylinder had been tested and maintained in accordance with requirements, was within its 15-year life limit and had been filled with aviator breathing oxygen (ABO) prior to the aircraft’s departure from Jandakot.

Oxygen from the cylinder was first reduced to 70 PSI by a pressure regulator and then by two altitude-compensating regulators located between the pressure regulator and oxygen supply lines, which automatically varied the flow of oxygen to the masks with changes in altitude. A remote shut-off valve in the overhead console was used to shut off the supply of oxygen to the system when not in use. A cylinder pressure gauge was located on the overhead console above the pilot’s (and copilot’s) seat.

A microphone-equipped Cessna mask with a vinyl plastic hose and flow indicator was stored under the pilot’s seat. It was observed to be in its packaging (unused) when the aircraft was in Saipan.

On-demand system

The pilot had a battery-operated Mountain High (MH) Pulse-Demand™ Electronic Delivery System (EDS) O2D1 (single-person) model (Figure 5). The EDS unit supplied a measured pulse of oxygen at the beginning of each inhalation and was oxygen-compensating (increasing flow with altitude). The unit had audible and illuminating flow fault and apnoea alarms. A representative from Mountain High advised that although the ceiling of the MH EDS is 25,000 ft, at 22,000 ft it is at the maximum flow rate requirement for oxygen.

Figure 5: Mountain High Pulse-Demand Electronic Delivery System O2D1

Figure 5: Mountain High Pulse-Demand Electronic Delivery System O2D1.
Source: Mountain High

Source: Mountain High

Cannula

The pilot preferred to use a nasal cannula for oxygen delivery and he intended to use it for the ferry flight. This was consistent with the supplied oxygen mask being unused before departing Saipan, despite two previous sectors above 18,000 ft. The pilot had also sent a message on the previous sector, indicating that he was using the cannula at 19,000 ft.

The ATSB could not establish the cannula model used for the ferry, however the MH EDS manual stated ‘Use only the supplied MH EDS cannula, as other cannulas may not work properly with the EDS.’ The standard MH nasal cannula (Figure 6) differed from the Oxymizer specified in CAO 108.26, which had a reservoir that stored oxygen during the exhalation then added it to the delivery during inhalation to increase oxygenation. Mountain High advised that the risks of wearing a cannula are:

  • it is ineffective if the pilot has nasal congestion, is eating, talking or mouth-breathing
  • it can come away from the nose, which would also trigger the apnoea alert.

Figure 6: Mountain High nasal cannula

Figure 6: Mountain High nasal cannula.
Source: Mountain High

Source: Mountain High

In-line regulator

The EDS was required to be operated with an oxygen inlet pressure between 16 and 20 PSI, which could be achieved with an in-line regulator (Figure 7). The MH EDS manual indicated that the flow of oxygen would be unnecessarily high between 20-30 PSI. The manual also included the warning that higher pressure ‘will not only compromise the performance of the EDS, but is likely to damage the internal breathing sensor, rendering your EDS unit inoperable.’ MH advised that pressures above 30 PSI would cause the valve to open up and result in the EDS working like a constant flow system. In this situation, the apnoea alert would sound out constantly until the oxygen supply was nearly depleted.

The pilot did not have an in-line regulator for the flight. At altitudes above 17,000 ft, the aircraft’s system provided oxygen at 21.55 ± 2.5 PSI, which was higher than the EDS inlet pressure range. At 20,000 ft, this increased 24.45 ± 2.5 PSI. There was no data for the output pressure at 22,000 ft.

Figure 7: In-line regulator to connect EDS to aircraft oxygen outlet

Figure 7: In-line regulator to connect EDS to aircraft oxygen outlet.
Source: Mountain High

Source: Mountain High

Mountain High aluminium cylinders

In his briefing before the aircraft departed Jandakot, the chief pilot understood that the pilot intended to plug his EDS directly into the aircraft system without an in-line regulator and was concerned about its effectiveness. Therefore, to ensure the pilot had an independent oxygen supply, the operator provided two MH aluminium (AL682) cylinders fitted with MH regulators, each of which had a maximum volume of 0.68 cubic metres (24.1 cubic feet) and a ‘typical volume’ of 0.63 cubic metres (22.1 cubic feet). The cylinders were filled with ABO and secured behind the copilot’s seat, which the pilot could reach if he slid his seat backwards.

Flight above FL 180

The MH EDS manual advised that pilots operating above 18,000 ft should have a supplementary oxygen cylinder gauge and an emergency backup oxygen system. The manual also provided full cylinder duration figures up to its ceiling of 25,000 ft and cylinder duration graphs from which to calculate usable oxygen for altitudes up to 18,000 ft.

The FAA pilot safety brochure Oxygen equipment: Use in General Aviation Operations stated that the use of cannulas was restricted by US Federal Aviation Regulations to 18,000 ft ‘because of the risk of reducing oxygen-blood saturation levels if one breathes through the mouth or talks too much.’

The aircraft operator’s operations manual approved the use of the MH EDS O2D2 and MH standard aviation nasal cannula up to FL 180, above which pilots were required to use a constant flow mask.

Pulse oximeter

To aid in identifying the symptoms of hypoxia, the pilot had a pulse oximeter, which showed blood oxygen saturation levels based on reading from the finger. On a previous flight the pilot was observed only to use the oximeter intermittently.

The US Federal Aviation Administration (FAA) cautions against relying on pulse oximeters as the sole indicator of hypoxia because by the time the oxygen saturation levels fall, it may result in a level of hypoxia sufficient to cause impairment. Further, the haemoglobin oxygen saturation in blood passing through the finger may not reflect oxygen available to the brain.

Pilot’s oxygen usage

An oxygen management plan from the pilot was not provided to the operator, however there were three sources of oxygen available to the pilot – the aircraft oxygen system and two aluminium cylinders, which were all filled prior to departure from Jandakot. It was not known which source the pilot used and when, but only one cylinder remained behind the copilot’s seat prior to the aircraft departing Saipan. This suggests the pilot had used one cylinder during the flights to Saipan. The pilot had not refilled the aircraft or portable oxygen cylinders since commencing the ferry.

The ATSB estimated whether the pilot had sufficient oxygen to complete the sector. This was based on the time at various altitudes flown for all sectors up to the last recorded aircraft position, and the expected endurance of the available oxygen, filled to typical pressures, according to the manufacturer’s documentation. The estimation was also based on using the available equipment as follows:

  • oxygen was used at all altitudes above 10,000 ft
  • the nasal cannula was used with the MH cylinders at all flight levels
  • the aircraft system was used with a mask or cannula, with or without the EDS.

The pilot’s actual equipment usage may have varied from these assumptions and it is acknowledged that oxygen usage can vary significantly between individuals, especially with on‑demand systems. However, it represented realistic usage scenarios and approximate endurance for the available oxygen. Even when conditions of highest usage were considered, there should have been several hours of oxygen remaining at the completion of the sector to Japan.

Hypoxia

Hypoxia is the absence of an adequate supply of oxygen to the tissues. Hypobaric hypoxia is the most common form in aviation and is associated with breathing air at low barometric pressure. A deficiency in alveolar oxygen exchange due to low oxygen tension (partial pressure) of inspired air leads to inadequate oxygen supply to the blood and reduced oxygen available to the tissues.

Hypoxia can be prevented by pressurising the aircraft cabin or by breathing supplemental oxygen. However, hypoxia can still occur in unpressurised aircraft if, for example, the supply equipment fails and/or does not provide an adequate concentration of oxygen or if the supply is not managed appropriately. In an aviation context, acute hypobaric hypoxia is the ‘most serious single physiological hazard during flight at altitude.’ [10]

Signs and symptoms of hypobaric hypoxia include:

  • darkening and restriction of the visual field and loss of peripheral vision
  • increased heart rate, hyperventilation and light-headedness
  • syncope (fainting/unconsciousness, pallor, sweating, nausea and vomiting)
  • cyanosis (bluish colouration of the skin, nail beds and mucous membranes)
  • impairment of mental performance and neuromuscular control, slowed reaction time
  • muscular spasms.

From 15,000 to 20,000 ft ‘there is a loss of critical judgment and willpower…the subject is usually unaware of any deterioration in performance or indeed of the presence of hypoxia; it is this that makes the condition such a potentially dangerous hazard in aviation.’ Above 20,000 ft these symptoms and signs become more pronounced. Involuntary jerks of the arms, loss of consciousness and convulsions occur, and after several minutes, death.

Physical activity, cold, illness and certain drugs increase the onset speed and severity of hypoxia.

US FAA Advisory Circular AC_61-107B Aircraft operations at altitudes above 25,000 feet mean sea level or Mach numbers greater than .75 indicated that while the signs of hypoxia can be detected in an individual by an observer, signs are not a very effective tool for hypoxic individuals to use to recognize hypoxia in themselves. The circular carried the following warning:

A common misconception among pilots is that it is easy to recognize the symptoms of hypoxia and to take corrective action before becoming seriously impaired. While this concept may be appealing in theory, it is both misleading and dangerous for crewmembers.

The Skybrary Operator’s Guide to Human Factors in Aviation Briefing Note defined the fourth, or critical stage of hypoxia as above 18,000 ft. It stated:

Above this altitude, complete incapacitation can occur with little or no warning. All senses fail, and a pilot will become unconscious within a very short period of time. No stimuli such as the radio will be able to help a pilot suffering from hypoxia, especially [rapid onset] fulminant hypoxia, above 5,500 meters (18,000 feet).

A less common form of hypoxia in an aviation context is anaemic hypoxia, caused by carbon monoxide poisoning. This is most commonly associated with piston engine aircraft, in drawing air for cabin heating over a damaged or defective exhaust system. Turbine engines produce up to two orders of magnitude lower carbon monoxide emissions than piston engines and utilise compressor bleed air as opposed to an exhaust heat exchanger. In addition, in 1984, the US National Transportation Safety Board investigated the possible effect of engine oil bleed air contamination on pilot incapacitation, from Garrett TPE 331 engines. It was concluded that such contamination was not likely to occur.

Time of useful consciousness

The FAA circular referenced above (AC_61-107B) defined the time of useful consciousness (TUC) as ‘the period of time from interruption of the oxygen supply, or exposure to an oxygen-poor environment, to the time when an individual is no longer capable of taking proper corrective and protective action.’ There are significant variations in TUC between individuals, and it does not mean that everyone will be capable of performing complex tasks in a challenging environment for the duration.

The circular included a graph showing decreasing TUC with increasing altitude (Figure 8). At 22,000 ft, the TUC was 10 minutes, or 5-6 minutes following rapid decompression. However, it goes on to caution that slow decompression is as dangerous as, or more dangerous than, a rapid decompression, as the resultant hypoxia may be unrecognized by the pilot. The circular also carried the warning: ‘The TUC does not mean the onset of unconsciousness. Impaired performance may be immediate.

Figure 8: Times of useful consciousness versus altitude

Figure 8: Times of useful consciousness versus altitude.
Source: FAA AC 61-107B

Source: FAA AC 61-107B

Pilot exposure and training for high altitude flying

There was evidence from previous flights that the pilot had some exposure to operating at higher altitudes. The pilot also held a valid US type rating for a Bombardier Challenger aircraft which had a service ceiling above FL 250. Under US Code of Federal Regulations Part 61.31 (g), this required completion of ground theory training including the effects, symptoms and causes of hypoxia and any other high-altitude sickness. The pilot had completed theoretical hypoxia awareness training and reported being aware of his own initial signs of hypoxia.

Altitude-induced decompression sickness

Flying unpressurised aircraft above 18,000 ft can not only induce hypoxia, but also result in altitude-induced decompression sickness (DCS). This is the formation of nitrogen bubbles in different areas of the body due to exposure to reduced barometric pressure. According to the FAA pilot safety brochure on decompression sickness, in most cases of DCS, the bubbles form in the joints, but in 10-15 per cent of cases, neurological manifestations occur. These can include similar symptoms to hypoxia such as confusion, seizures and unconsciousness.

While most cases occur at or above 25,000 ft, the risk of DCS increases with exposure to altitudes above 18,000 ft.

Oversight of the ferry flight

The aircraft operator’s Air Operator Certificate (AOC) was for aerial work and as such, it was not a regulatory requirement to have a formal safety management system. Despite this, the aircraft operator had implemented a health, safety and environmental operating management system (HSE-OMS) that applied to their aviation activities, most of which were low-level survey operations.

FAY was routinely ferried to new surveying locations with its specialised equipment installed. Although ferry flights were classed as private operations, they were normally carried out by company pilots, operating under the AOC. The flights were conducted in accordance with the standard operating procedures and the chief pilot was responsible for operational matters affecting the safety of flying operations. However, following the successful ferry of FHY from Canada to Western Australia by the contract pilot 6 months earlier, the operator elected to re‑engage the contract pilot to ferry FAY to the US.

Risk assessment for the ferry flight

The operator initially conducted a gap analysis to identify any changes that had occurred since the ferry of FHY. It identified several actions, including the need to audit the pilot’s qualifications, conduct a familiarisation flight and briefing on the aircraft and fitments, and for flight monitoring by company staff.

At the planning stage of the FAY ferry, the primary concerns of the operator were around managing:

  • long sectors over water – fatigue, lack of alternate landing areas and distance from search and rescue assistance
  • single-pilot operation – the operator required their own ferry flights to be conducted with two crewmembers, but the contracted ferry pilot preferred to operate alone

routing – including consideration of security in countries to be overflown.

In accordance with the HSE-OMS, the operator then conducted a risk assessment for the ferry flight. The operator’s risk matrix guidelines included:

The Risk Matrix must be used with good judgment, applying the following recommendations:

- Make use of the experience of several people, with a broad range of experience and backgrounds.

- Within the defined context, the relevant hazards should be identified and documented in the hazard libraries.

- For an identified hazard, the potential consequences (severity) are determined first. A hazard can have a consequence in several categories…

- Risk must be assessed in the context of an activity as hazards manifest themselves differently in different environments or conditions…

The aviation manager reported that he had done the risk assessment based on what the company had experienced in previous ferries and general risk assessment from their operations. The quality assurance manager and flight operations administrator were involved in the assessment process. He also obtained input from the company’s aviation specialist in Canada, who had been involved with the risk assessment for the previous ferry (of FHY). The assessment report was then provided through to their HSE manager.

The HSE manager commented that normally they would get flight operations personnel involved; he, the chief pilot, the aviation manager, a ferry pilot, and a couple of other pilots would form a team. However, the HSE manager had been on vacation during the ferry risk assessment and had not been involved in the process.

The risk assessment identified 32 hazards including one relating to hypoxia:

Unconscious pilot due to oxygen starvation [resulting in] uncontrolled flight into terrain.

It was initially rated as moderate and assessed as unlikely to occur. The nominated control to reduce risk was that there was an oxygen system fitted to the aircraft, with no resultant change to the risk rating (or likelihood). Consideration of specific operational or technical factors that could contribute to hypoxia were not included in the risk assessment. Nor was any form of pilot incapacitation other than hypoxia.

Nearly half of the identified hazards nominated the pilot’s experience (having conducted over 200 ferry flights, including multiple recent Pacific crossings) as one of, or the only risk control. The assessment did not detail whether the pilot had considered the hazards or associated risks, or how he proposed to mitigate them. However, the day before FAY departed Jandakot, the ferry pilot reviewed the risk assessment in conjunction with the operator and suggested additional risks, including road transport, ‘poor decision making due client pressure,’ and access to food and medical support. The chief pilot and a senior company pilot later outlined to the ATSB that they assessed the pilot as being ‘quite organised and competent’, albeit with a clear preference for doing things his own way.

Aircraft operator and pilot agreement

The contract between the pilot and aircraft operator for the ferry detailed the responsibilities of each party, and stipulated how the aircraft was to be operated, including the requirement to adhere to standard operating procedures as specified in the operations manual.

The ‘International Operations’ section of the operations manual included requirements for approvals, permits and documentation associated with travelling to foreign countries as well as flight planning, flight following and emergency equipment. In the agreement between the aircraft operator and the contract pilot, most of these responsibilities had been assigned to the pilot to manage. Of significance, the section stated that ‘In general, the Chief Pilot will manage an overseas operation. Close liaison between the aircrew and the Chief Pilot or their delegate is essential.’

The chief pilot had commenced with the operator on 28 August 2018, two weeks before FAY departed Jandakot on the ferry flight. The chief pilot had previously conducted ferry flights for a different operator, but was inexperienced on the C208 aircraft type. Additionally, because the ferry was assigned to a contract pilot, the chief pilot reported having been informed that he was not required to have involvement in the conduct of the operation, other than briefing the ferry pilot prior to departure.

Along with the risks inherent to the type of operation, the aircraft operator had considered the additional threats posed by financial incentive to complete the ferry as expeditiously and cost-effectively as possible. To this end, the contract included that the pilot would be paid for any days delayed on the ground to reduce pressure to continue the flight in adverse conditions. The pilot was responsible for fuel, oil and other en-route costs such as accommodation and food.

Pre-flight briefing and familiarisation flight

The day before the ferry flight departed from Jandakot, the pilot completed an aircraft familiarisation flight with a senior company pilot experienced in ferry flights, and a briefing with the chief pilot. The familiarisation flight focused on aircraft handling and use of the ferry tank fuel. The chief pilot’s briefing was primarily about the aircraft’s minimum equipment list and safety equipment. These measures had been identified in the gap analysis but not included in the risk assessment.

When the chief pilot briefed the ferry pilot, he was concerned about the pilot’s intention to connect his EDS unit to the aircraft oxygen system without the requisite regulator. To address the concern, he provided the pilot with the two portable oxygen cylinders that were appropriate for use with the pilot’s equipment. The risk assessment did not include the pilot’s oxygen management plan and further risk assessment was not done to assess the effect of the additional oxygen sources.

Flight following

The gap analysis indicated that company operations staff would be responsible for flight following. As required by the contract, the pilot sent the flight plan and journey logs to the operator each day, however they were not reviewed by the operator until after the aircraft disappeared from radar. The logs showed the pilot consistently operated the aircraft engine above the exhaust gas temperature (EGT) limit of 650 °C. Additionally, on the first sector to Alice Springs, the aircraft was flown at 21,000 ft and the final sector from Saipan was at 22,000 ft. Operations staff did not contact the pilot about exceeding the 20,000 ft limit.

Flight plan

The flight plan that the aircraft operator obtained, which was submitted for the planned flight from Saipan to New Chitose Airport, showed the flight planned altitude as FL 250, total estimated elapsed time of 10 hours and 15 minutes and (fuel) endurance of 9 hours and 30 minutes. The discrepancy with the planned flight time exceeding the endurance may have been a transposition error by the pilot, however neither this, the lack of alternates, nor the planned altitude in excess of the 20,000 ft limit was identified or amended prior to departure.

The flight plan obtained by Japan Civil Aviation Bureau was sent from Honolulu at 0507 UTC on 26 September, before the aircraft departed Saipan. That flight plan had a planned cruising level of FL 220 and a total estimated elapsed time of 8 hours and 53 minutes.

Summary of operational oversight

The aircraft operator had processes in place to identify and manage the risks associated with the ferry flight. This included conducting a gap analysis and risk assessment, familiarisation flight and pre-flight briefing, which identified the potential issue with pilot’s intended use of the oxygen system.

The operator also relied on the pilot’s extensive ferry experience to bring level of safety to the ferry flight. However, many of the risk controls relied solely on the pilot’s experience and did not provide any detail on the steps the pilot had taken to manage those risks. The flight also took place outside of the company’s standard procedures and without the normal level of oversight from operations personnel, both of which could have provided an additional opportunity to identify and manage the hazards associated with the ferry flight.

Previous occurrences

ATSB research publication Pilot Incapacitation – Analysis of medical conditions affecting pilots involved in accidents and incidents (2007), reviewed occurrences recorded by the ATSB from 1 January 1975 to 31 March 2006. It identified three cases of hypoxia, which was 3 per cent of the medical/incapacitation events. One of those was a Beech Super King Air aircraft (VH-SKC) near Burketown, Queensland on 4 September 2000. The ATSB investigation report (200003771) assessed that the incapacitation of the pilot and seven passengers was probably due to hypobaric hypoxia due to operating at high cabin altitude and not receiving supplemental oxygen. The report also identified that all the fatal accidents where medical conditions or incapacitation occurred were single-pilot operations where there was no second pilot on board who could assume control of the aircraft and prevent an accident.

The ATSB investigated an incapacitation event involving a Raytheon Aircraft Super King Air 200, VH-OYA, which occurred on 21 June 1999 (199902928). As the aircraft climbed through 10,400 ft, the pilot inadvertently selected the ‘bleed air off’, which prevented the aircraft from pressurising. As the aircraft reached the planned cruising altitude of FL 250, the aircraft deviated from the assigned track and the pilot was observed repeatedly attempting to program the GPS. Shortly afterwards, the pilot lost consciousness. The passenger in the co‑pilot seat took control of the aircraft and conducted an emergency descent, during which the pilot regained consciousness. The investigation findings included that hypobaric training did not provide an effective defence to ensure the pilot (or passengers) would identify the onset of hypoxia.

ATSB investigation AO-2014-134: Flight crew incapacitation involving a Reims F406, VH-EYQ near Emerald Airport, Qld on 1 August 2014. The pilot and navigator were planning to conduct a survey operation at FL 240. The aircraft was unpressurised but fitted with an oxygen system. Having selected the oxygen supply on and donned oxygen masks, passing about FL 180, the pilot noticed the blood saturation level reporting on his oxygen pulse meter was 77 per cent instead of above 90 per cent. In a hypoxic state, the pilot worked to rectify a problem with his oxygen system connection with assistance from the navigator and air traffic control. In this case, the pilot subsequently commented that his hypoxia awareness training had aided his appreciation of his symptoms and effects of hypoxia.

On 23 September 2012, a Metro 3 aircraft, VH-SEF, failed to pressurise on climb (ATSB investigation AO-2012-127). Passing FL 140, the captain started to feel the effects of hypoxia, donned an oxygen mask, and the first officer took over flying the aircraft and conducted an emergency descent to 10,000 ft.

__________

  1. The Airplane Flight Manual (AFM) is produced by the aircraft manufacturer and contains detailed information about operation of the aircraft.
  2. Maintenance release: an official document, issued by an authorised person as described in Regulations, which is required to be carried on an aircraft as an ongoing record of its time in service (TIS) and airworthiness status. Subject to conditions, a maintenance release is valid for a set period, nominally 100 hours TIS or 12 months from issue.
  3. Instrument flight rules (IFR): a set of regulations that permit the pilot to operate an aircraft in instrument meteorological conditions (IMC), which have much lower weather minimums than visual flight rules (VFR). Procedures and training are significantly more complex as a pilot must demonstrate competency in IMC conditions while controlling the aircraft solely by reference to instruments. IFR-capable aircraft have greater equipment and maintenance requirements.
  4. CASA defines an engineering order as the implementing document for a repair or modification and it contains all necessary instructions and references to carry out the task.
  5. An aircraft must be designed to be capable of diving to the design dive speed (VD) without flutter, control reversal or buffeting.
  6. Gradwell DP, Rainford DJ 2006, Ernsting’s aviation medicine, Edward Arnold (Publishers) Ltd London, Chapter 3.

Safety analysis

Introduction

After departing Saipan and climbing for about an hour, the aircraft levelled off at flight level (FL) 220. An hour later, the pilot made a mandatory position report on HF radio and then no subsequent communications. About 5 hours after the position report, while maintaining FL 220 and the flight planned route, the aircraft descended to the ocean. No wreckage other than a part of the aircraft door was recovered and the pilot was not found, limiting the evidence available.

The analysis will consider reasons for the pilot’s lack of any further communication and the aircraft’s subsequent descent. The investigation identified some operational factors that increased the pilot’s risk of experiencing hypoxia. These factors are explored in detail below.

Pilot incapacitation

The absence of any communication by the pilot after reporting at position TEGOD was almost certainly a result of pilot incapacitation. He did not make any further mandatory position reports, or respond to repeated attempts by Tokyo Radio to communicate on HF radio. The pilot had several alternative means of communication available in case of HF radio failure or failure of the aircraft’s electrical system. He would have been able to communicate using one of those means if not incapacitated, as demonstrated by having successfully sent messages from his standalone Garmin device prior to reaching TEGOD.

Additionally, the pilot did not respond in accordance with international intercept protocols, either by rocking the aircraft wings or turning, when intercepted by two Japan Air Self-Defence Force (JASDF) aircraft. The JASDF pilots were unable to see into the cockpit to confirm whether the pilot of VH-FAY was visibly incapacitated.

No evidence was available from which to determine the cause of incapacitation. The two most likely mechanisms for incapacitation were due to the pilot experiencing a medical event or hypoxia. Although the pilot had a valid medical certificate and was reportedly in good health, a medical event could not be ruled out. Similarly, the pilot’s last communications with Tokyo Radio were not of adequate sound quality to determine whether the pilot was affected by hypoxia at that time. In any case, there was ample time after TEGOD for the pilot to experience hypoxia and be unable to recover at the cruise altitude, before the aircraft reached the next reporting point.

With the pilot incapacitated, the aircraft continued on autopilot. The aircraft’s track and altitude were consistent with the flight director selected to hold flight level (FL) 220 and to follow the GPS programmed track.

Fuel starvation and uncontrolled descent

About 5 hours after the pilot’s last transmission, the JASDF aircraft radar showed FAY start to descend at an increasing rate, which was indicative of engine power loss. In the absence of pilot intervention, the power loss would have resulted from either engine failure or fuel starvation. An engine failure could not be ruled out, however this would had to have occurred in addition to pilot incapacitation, and the likelihood of both these events occurring in the same flight was considered to be low. The engine power loss was therefore considered more likely to have resulted from fuel starvation.

The estimated fuel used at the commencement of the descent was significantly less than the total fuel carried. However, as the pilot almost certainly became incapacitated relatively early in the flight, he would therefore not have been able to manually alter the fuel state after that point. It was possible to have starved the engine of fuel around the descent point by switching to the right tank and using some or all of the ferry tank (and venting some). However, this would have resulted in a fuel imbalance that was not evident in photos of the aircraft taken shortly before its descent. Given that the estimated fuel used was approximately equal to the usable fuel in the wing tanks, it was more likely that the wing tanks were selected for the duration and this usable fuel was exhausted, leaving the ferry tank full.

The aircraft’s last computed descent rate was below the dive speed for the aircraft, and was therefore indicative of an uncontrolled descent, rather than an in-flight breakup. There was no recorded data of the aircraft’s collision with the water, however the descent profile and wreckage indicated that the collision with water was not survivable.

Increased risk of experiencing hypoxia

In exploring the potential reasons for pilot incapacitation, there were several operational factors identified that increased the pilot’s risk of experiencing hypoxia and being unable to recover.

The pilot elected to fly solo at FL 220 where, without adequate oxygen supply, the time of useful consciousness (TUC) was in the order of 5-6 minutes. This was limited compared to FL 180, for example, where the TUC was two to three times longer.

The pilot had undertaken a hypoxia awareness course and reportedly knew the initial symptoms that presented in himself, which would aid in identifying and mitigating against the risk of hypoxia. However, particularly above FL 180, impairment and incapacitation can occur quickly, with little or no warning, rendering a person unable to take action to recover. The pilot also had a pulse oximeter to monitor blood oxygen saturation, but had been observed on a previous flight to use it intermittently rather than continuously. Given the limited TUC, had the pilot followed a similar regime on this flight, it may have resulted in insufficient time to alert the pilot to decreasing saturation levels. The pilot elected not to have a second pilot on board, as offered by the operator, which would have provided an additional risk control in assisting to identify the signs of hypoxia in each other and enable recovery action, as illustrated by previous occurrences. This would be especially pertinent at altitudes where there is limited TUC.

There was adequate oxygen on board for the flight, however the pilot was probably using a nasal cannula connected to the pilot’s electronic pulse-demand system (EDS) at all flight levels, as indicated by the fact that the Cessna mask was unused by the time the aircraft was in Saipan, despite having flown above FL180. This increased the risk of reduced oxygen-blood saturation levels.

The pilot had also indicated his intention to connect the EDS to the aircraft system without the in-line regulator that was required to ensure the EDS operated within its limits. At FL 220, this had the potential for the pilot to receive inadequate oxygen supply or for the EDS to be rendered inoperative, resulting in higher oxygen consumption than anticipated. However, it is noted that the pilot had the Cessna mask available which, if used with the aircraft system, would have mitigated this risk.

Findings

From the evidence available, the following findings are made with respect to the uncontrolled flight into water involving a Cessna Aircraft Company 208B, registered VH-FAY, that occurred 260 km north-east of Narita International Airport, Japan, on 27 September 2018. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • During the cruise between Saipan and New Chitose, the pilot very likely became incapacitated and could no longer operate the aircraft.
  • The aircraft’s engine most likely stopped due to fuel starvation from pilot inaction, which resulted in the aircraft entering an uncontrolled descent into the ocean.

Other factors that increased risk

  • The pilot was operating alone in the unpressurised aircraft at 22,000 ft and probably not using the oxygen system appropriately, which increased the risk of experiencing hypoxia and being unable to recover.

Safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Aircraft operator

As a result of this occurrence, the aircraft operator has advised the ATSB that they are taking the following safety actions:

Risk assessment and standard procedures

The aircraft operator reviewed their risk assessment processes and the standard operating procedures for conduct of ferry flights. As a result, they amended the guidance for international ferry operations in their operations manual including: maximum sector length, fuel planning, mandating two-crew operations, oxygen planning, management and training, operating altitude limitations, and use of contract pilots.

Oxygen use guide

The aircraft operator also created an oxygen use guide and a specific risk assessment for positioning (ferry) flights.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • Aircraft operator and maintainer
  • Aircraft engineer and design holder
  • Japan Transport Safety Board
  • Civil Aviation Safety Authority
  • Bureau of Meteorology
  • Honeywell
  • Textron Aviation
  • United States National Transportation Safety Board.

References

Campbell RD, Bagshaw M 2002, Human performance and limitations in aviation, Blackwell Science Ltd.

Gradwell DP, Rainford DJ 2006, Ernsting’s aviation medicine, Edward Arnold (Publishers) Ltd London, Chapter 3.

Newman, DG 2004, Flying fast jets: Human factors and performance limitations, CRC Pres LLC.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the aircraft operator, aircraft maintainer, aircraft insurance assessor, Civil Aviation Safety Authority, Japan Transport Safety Board, US National Transportation Safety Board, Textron Aviation, Honeywell, Thomson Design and Mountain High.

Submissions were received from the Japan Transport Safety Board, Honeywell, aircraft insurance assessor, aircraft operator, Thomson Design and Mountain High. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2018-065
Occurrence date 27/09/2018
Location 185 km north-east of Narita International, Japan
State International
Report release date 18/03/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Manufacturer Cessna Aircraft Company
Model 208B
Registration VH-FAY
Serial number 208B0884
Aircraft operator CGG Aviation (Australia)
Sector Turboprop
Operation type Private
Departure point Saipan, Federated States of Micronesia
Destination New Chitose Airport, Hokkaido, Japan
Damage Destroyed

Safeworking irregularity involving Track Work Authority, at Blackheath, New South Wales, on 2 September 2018

Final report

Report release date: 25/02/2020

Safety summary

What happened

On 2 September 2018, a Sydney Trains workgroup conducting a track inspection had to move to a safe location beside the track as a NSW Trains’ passenger train, W532, approached. The incident occurred in a worksite protected by a Track Work Authority, in a section of track between Blackheath and Medlow Bath stations on the Main West line.

The maintenance work group began working on a section of line that passenger train W532 was travelling in. The work group were informed that the section was protected. The driver of W532 travelling on the Up[1] main line sounded the horn when he saw workers on the tracks 40 to 60 metres ahead of the train. The work group, evacuated to a safe place beside the Up main line. The workers had cleared the tracks approximately three to four seconds before W532 passed their location.

There were no injuries to people or damage to property.

What the ATSB found

The Australian Transport Safety Bureau found that safety critical communication lacked confirmation between the signaller at Mount Victoria (SMV) and the protection officer[2] (PO) for the work group.

The PO became distracted during the establishment of worksite protection while he was attempting to conduct multiple tasks. The PO was communicating with the SMV, his work group and also the hand signaller at Mount Victoria (HSMV). This resulted in him overlooking information regarding the presence of a passenger train within the limits of the worksite and directing his work group to commence work on track.

What’s been done as a result

As a result of this incident and other recent safe working incidents, Sydney Trains launched the safety initiative “Safety Together: It Starts With Me”. The initiative focussed on ensuring all employees had an adequate understanding of the protection in place prior to the commencement of their work.

Safety message

Rail operators should remind rail safety workers of the importance of effective communications. All safety critical messages should be repeated by the receiver to confirm the detail of the message. If the sender is unsure that the receiver has understood the message, then the sender should challenge the receiver to repeat the message. This confirmation is especially important with regard to providing detail of train movements in the vicinity of the worksite.

__________

  1. Trains travelling on the Up line are usually travelling towards Sydney Central Station; trains travelling on the Down line are travelling away.
  2. The Qualified Worker responsible for protection.

 

The occurrence

What happened

On 2 September 2018, Sydney Trains had pre-scheduled track maintenance work (Welded Track Stability Inspection)[3] for both the Up and Down Main West lines between Mount Victoria and Katoomba (see Figure 1).

To facilitate the work, at 0600[4] the PO briefed the work group and deployed hand signallers, one to Mt Victoria station, the second to Katoomba station. The PO then arranged a Track Work Authority[5] (TWA) with the signaller, Katoomba for the Down line at 0714. At 0720, the PO contacted the SMV to establish the TWA on the Up line, however this could not occur, as there was a train in the section at that time. While the PO waited for the train to clear the section, he conducted a final worksite protection pre-work briefing for the work group.

Following the briefing, the PO then arranged a TWA with the SMV on the Up line at 0756. Both of the TWAs were authorised by the train controller on the Southwest Panel prior to the workers entering the rail corridor.

Figure 1: Location of the Mt Victoria to Katoomba track section.

Figure 1: Location of the Mt Victoria to Katoomba track section.
Source: Geoscience Australia, annotated by the ATSB

Source: Geoscience Australia, annotated by the ATSB

Passenger train W532, an 8-car intercity train known as a V set, was scheduled to depart Mt Victoria station on the Up line at 0802. The PO informed the SMV that he would allow W532 to depart prior to establishing protection. At 0758, the PO radioed the HSMV and communicated the plan to allow W532 to depart prior to implementing the protection. The planned protection consisted of the HSMV clipping and locking 41 points, combined with the SMV blocking signal 78.6 (126.599 km).[6]

At 0802, passenger train W532 departed Mt Victoria on the Up line. At approximately 0803 the HSMV informed the SMV that W532 had passed his location. The SMV then informed the HSMV that he placed the signals to stop and applied a block[7]. The HSMV clipped and locked 41 points, then called the PO on the two way radio informing him that protection was in place and W532 was in the section.

At approximately 0804, the PO received a call from the SMV who communicated the train-running times for the day. This conversation included the information that W532 was currently in the section.

At approximately 0807, the PO advised the work group supervisor that both Up and Down TWA were in place and that both tracks were protected. The PO advised the work group they could commence work and the work group moved on to the tracks.

At 0809, W532 departed Blackheath station (120.622km) on the Up main line towards Sydney. A short while later, the driver of W532 observed a work group on the tracks as the train exited a left hand curve in a cutting between 119.614 km and 119.650 km (see Figures 2 and 3).

Figure 2: Location detail

Figure 2: Location detail.
Source: Sydney Trains, annotated by the ATSB

Source: Sydney Trains, annotated by the ATSB

Figure 3: Line of sight between train and workgroup obscured by cutting

Figure 3: Line of sight between train and workgroup obscured by cutting.
Source: Sydney Trains, annotated by the ATSB

At 0811, the driver of W532 rounded the left hand turn and sounded the train’s horn when he sighted workers on both the Up and Down lines in front of the train. The driver did not apply the brakes and continued on his route as scheduled without reporting the incident. At approximately the same time the PO, who was located closer to the train, ran towards the work group shouting a warning that a train was approaching.

The workers on the Up line, realising that W532 was approaching, moved to a safe location beside the tracks (see Figure 4). The workers on the Down line waited for W532 to pass before joining the rest of the work group at the safe location.

Figure 4: Driver’s view of the incident site

Figure 4: Driver’s view of the incident site.
Source: Sydney Trains, annotated by the ATSB

Source: Sydney Trains, annotated by the ATSB

W532 passed the worksite approximately 3-4 seconds after the workers on the Up main cleared the track and continued on its journey to Sydney. The work group reported no injuries.

The Worksite Supervisor stopped the work and reported the incident to ICON[8] and the PO fulfilled the TWAs on both the Up and Down Main lines. The workgroup then returned to the Lawson network base where they met with the incident rail commander who conducted preliminary interviews and arranged post incident drug and alcohol testing. The results of the testing were negative.

Network rules and procedures

When planning work in a rail corridor, it is a PO’s responsibility to ensure that all work in the danger zone is carried out according to network rules and procedures. The PO must also ensure that work is planned in accordance with NWT 300 Planning work in the Rail Corridor.

NWT 306 Track Work Authority

In order to carry out track work under a TWA, a PO must ensure that the TWA is authorised by the network controller. Prior to a network controller issuing a TWA, they must be satisfied that the PO has complied with network rule NWT 306. NWT 306 prescribes items that must be completed before authorising, issuing and using a TWA. The PO must liaise with the signaller responsible for the section about protection arrangements. The PO must ensure that the workers and worksite are protected against the unauthorised entry of rail traffic.

Before workers can enter a worksite, they must be briefed by the PO about the worksite and planned protection. The briefing must identify safe places, safety measures, the extent of the protected area and any changes to the protection. The PO must also ensure that protection is in place prior to any work commencing.

For the duration of the TWA, the PO must manage rail traffic between the limits of the TWA. The PO does this by establishing and maintaining effective communication with local signal boxes and with inner and outer hand signallers.

NPR 702 Using a Track Work Authority

NPR 702 prescribes the process for obtaining, authorising and establishing a TWA. It also specifies how to manage rail traffic movements through the worksite.

It requires the signaller provide the PO with train running information. Further, the signaller must identify the last rail traffic to enter the worksite and ensure the PO knows its location. The PO is required to confirm understanding of this information.

NPR 702 contains a warning that states:

Workers must be in safe places before rail traffic is allowed to approach beyond the inner Hand signaller or pass through the limits of worksites.

NGE 204 Network communication

NGE 204 prescribes rules for spoken and written communication on the Sydney Trains Network. The general principles of which are that all communication must be brief, clear, relevant to the task at hand and agreed to its meaning before being acted upon. The receiver must confirm the content of a message by repeating the message back to the sender when the communication is about a work on track authority.

NGE 204 contains a warning:

Qualified Workers must not assume that a receiver has understood a message before the receiver confirms that the message has been understood.

The Protection Officer

At the time of the incident, the PO had over five years’ experience as a protection officer. The PO was qualified and worked as a level 2 for almost 5 years and had held his level 3 qualification since February 2018. The level 3 qualification additionally allowed him to implement a TWA and manage rail traffic through worksites.

The PO had worked on the Blue Mountains section of the network for approximately 12 months. Six of these months he had worked as a qualified level 3 PO.

__________

  1. A Welded Track Stability Inspection requires a work group to walk a defined section of track to take detailed geometry measurements at various points.
  2. All times are in Australian Eastern Standard Time (UTS + 10:00) and in 24-hour format.
  3. A Track Work Authority allows track work on running lines between rail traffic movements. Protection Officers manage the approach of rail traffic to worksites. Rail traffic may pass through only under controlled conditions (NPR702).
  4. The kilometre distance is given as the distance from Platform 1, Central Station Sydney, New South Wales.
  5. A block is a mechanism of preventing a signaller from accidently changing a signal. Typically a physical cover is placed over the signal button to prevent it from being pressed.
  6. ICON is a multifunction support complex, whose responsibility includes the management and assurance of worksite safety. It is also responsible for the management and rectification of infrastructure problems.

Safety analysis

A number of safety factors lead to the work group entering the danger zone at the same time as passenger service W532. These factors were found to be related to the implementation of rules and procedures, and serve as a reminder for rail operators and rail safety workers to ensure effective communications when working on the rail network.

Missed W532 in the Section

At the time the PO delivered the final worksite protection briefing and participated in the worksite supervisor’s pre-work briefing, trains W530 and VP02 passed through the worksite. When VP02 exited the worksite, at approximately 0750, the SMV communicated with the train controller and had the TWA on the Up Main authorised at 0756. W532 was scheduled to depart Mt Victoria six minutes later at 0802.

Due to the proximity of W532s scheduled departure, the PO instructed the HSMV to allow W532 to depart Mt Victoria before applying protection. At 0802, W532 departed Mt Victoria station and protection (signal block and clip lock on 41 points) was established. The HSMV then called the PO, at 0803, on the two-way radio and informed him that protection was established and that W532 was in the section.

At 0804, shortly following the radio call, the SMV called the PO to relay expected train schedule times on the Up Main line that day. During this conversation, the SMV informed the PO that W532 was in the section. The PO recorded the up coming train schedule times on the PO log but notably made no record of W532 being in the section (see Figure 5).

Figure 5: Train running schedule from Protection Officer Log

Figure 5: Train running schedule from Protection Officer Log.
Source: Sydney Trains: annotated by the ATSB

Source: Sydney Trains: annotated by the ATSB

At 0807, after receiving and recording the train running schedule the PO informed the work group that protection was established and they could commence work.

The work group moved on to both the Up and Down lines at the agreed location (119.650 km) to commence work. W532 rounded the cutting and approached the work group shortly after at 0811.

At post interview, the PO said that he missed the fact that W532 was in the section.

Network Communication

ATSB reviewed the voice recordings between the PO and SMV during the establishment of the TWA. It was found that the communication of important safety information was informal, conversational and lacked confirmation to ensure messages were understood.

Specifically at 0804, during the communication between the SMV and the PO, train running information was being provided to the PO informing him that W532 was in the section at that time. The PO responded with ‘yep’.

The PO did not repeat back the train running information or that W532 was in the section to confirm his understanding. Additionally, the SMV did not challenge the lack of confirmation by the PO, thus missing an opportunity to confirm that the message was understood.

The lack of confirmation of the message, most likely allowed the PO to overlook the fact that W532 was in the section. This oversight led to the PO instructing the work group to enter the rail corridor with a train in the section.

Management of tasks

The process of implementing worksite protection requires the PO to undertake a number of tasks and consider various factors to ensure the success of the worksite protection plan.

At the time of the incident, the PO was managing a number of tasks that each demanded his attention:

  • His prime responsibility, according to NWT 300 Planning work in the Rail Corridor, was to ensure the safety of the worksite and the workers.
  • He was responsible for managing the movement of rail traffic through the worksite to ensure the safety of his work team prior to allowing work to begin in the danger zone.
  • He was updating paperwork relevant to the protection officer’s diary and log.
  • He was communicating with the SMV by mobile phone receiving safety critical information relevant to the worksite protection on the Up Main line.
  • He was communicating with the HSMV regarding current rail traffic and status of protection.

Research has shown that attempting to carry out multiple tasks at the same time results in distraction, slower task performance and an increase in errors. [9] Baddeley (1986) argues that individuals have a limited pool of working memory resources available to conduct tasks. When an individual attempts to manage multiple tasks, the divided attention draws from the limited pool and results in a reduction of resources to devote to any one task.

Research by Wickens (1992) proposed that an individual’s short term sensory resource is of limited capacity and if overwhelmed by competing stimuli, can become depleted resulting in poor responses or slips of attention.

Staal (2004), argued that this reduction in attentional resources when attempting the management of multiple tasks, ’results in degraded performance on either the primary or secondary task.’

Further Staal argues that:

In such cases when the recall or recognition of information is required, this division often results in a decreased capacity to recall or recognize information.

It is likely that the PO became distracted and missed the information about W532 being in the section, as he attempted to manage the multiple tasks and the high workload.

In establishing the TWA, the PO followed the basic principles of network rules 300 and 306. However, safety critical communication when implementing protection on the Up Main line lacked the feedback and confirmation as required by NGE 204. This lack of confirmation combined with attempts to concurrently carry out multiple tasks led to the PO overlooking that W532 was already in the section when he instructed his work group to commence work.

ATSB comment

When establishing worksite protection, the principles of network communication require communication to be clear, brief, unambiguous, relevant and agreed to its meaning before being acted upon. Clear communication is critical to maintaining safety on the rail network.

__________

  1. C.D.Wickens (1992) Engineering Psychology and Human Performance, New York: Harper Collins.Mark A. Staal (2004) Stress, Cognition, and Human Performance: A Literature Review and Conceptual Framework, Moffett Field, California: Ames Research Centre.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The PO cleared the work group to enter the danger zone and commence work when passenger service W532 was in section.
  • The verbal communications between the PO and the SMV lacked the feedback and confirmation required in network communications.
  • The PO was working through multiple tasks when implementing the TWA on the Up main line which distracted him from understanding safety critical train schedule information.

Safety action

The ATSB has been advised of the following proactive safety action in response to this occurrence.

Sydney Trains

As a result of this occurrence, Sydney Trains has taken the following safety actions:

Safety Initiative

As a result, of this incident and other recent safe working incidents, the safety initiative “Safety Together: It Starts With Me” was launched. The initiative focusses on ensuring all employees have an adequate understanding of the protection in place prior to the commencement of their work.

References

A.D. Baddeley (1986). Working memory, Oxford, England: Oxford University Press.

Sidney W. A. Dekker (2002). The re-invention of human error, Sweden: Lund University School of Aviation.

Anjum Naweed (2013) Psychological factors for driver distraction and inattention in the Australian and New Zealand rail industry, Accident Analysis and Prevention, 60(pp. 193-204).

J. Reason (1990). Human error. New York: Cambridge.

Mark A. Staal (2004). Stress, Cognition, and Human Performance: A Literature Review and Conceptual Framework, Moffett Field, California: Ames Research Center.

David L. Strayer, Jason M. Watson, and Frank A. Drews (2011). Cognitive Distraction While Multitasking in the Automobile, The Psychology of Learning and Motivation, Vol. 54, Burlington: Academic Press.

C.D.Wickens (1992). Engineering Psychology and Human Performance, New York: Harper Collins.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2018-016
Occurrence date 02/09/2018
Location Blackheath
State New South Wales
Report release date 25/02/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Safe Working Irregularity/Breach
Occurrence class Incident
Highest injury level None

Train details

Train operator NSW Trains
Train number W532
Type of operation Passenger
Departure point Mount Victoria, New South Wales
Destination Sydney Terminal, New South Wales
Train damage Nil

Derailment and collision between coal trains, Ravenan (25 km from Muswellbrook), New South Wales, on 26 September 2018

Final report

Report release date: 18/12/2020

Safety summary

What happened

A coal train MR336 departed for Newcastle after being loaded with coal from Moolarben loading terminal. On route the 25th wagon in the train consist derailed at Antiene and then subsequently collided with another coal train WC915 as it passed in the opposing direction at Ravenan. The collision resulted in the locomotives on WC915 being damaged and derailed and several wagons from both trains were also damaged and derailed.

What the ATSB found

A loading sensor malfunctioned during the loading sequence which stopped coal from being loaded into the 25th wagon. The train loading operator (TLO) was pre-occupied when control alarms sounded and missed viewing the wagon pass under the loading bin. The TLO could not confirm if the wagon was loaded or not in the low light conditions, so instigated a verification check. The TLO unknowingly provided misleading information to check the 28th wagon, rather than the 28th vehicle in the sequence. The empty 25th wagon was not detected by the loading terminal before MR336 departed onto the rail network.

An empty wagon positioned between two loaded wagons was allowed onto the rail network and this known risk materialised in a derailment of the empty wagon. The derailed state of the wagon on MR336 caused the collision with WC915.

The controls for managing loading irregularities, were operational in the Moolarben loading system however, it is likely, the reliability of the alarms to indicate a loading irregularity in the loading system contributed to the TLO questioning their accuracy.

What has been done as a result

Moolarben loading terminal corrected the malfunctioning sensor and implemented more detailed verification processes of the train load out summary. They reviewed their risk assessment for train loading and implemented a number of actions resulting from this review process. The details of these actions is presented in this report.

Safety message

Empty or light loaded wagons positioned between loaded wagons running on the rail network is a known risk that can have severe consequences. Coal loading terminals and rolling stock operators should review their processes to prevent this known risk from materialising.

 

The occurrence

Train loading

At 0356 on 26 September 2018, coal train MR336 arrived at Moolarben coal loading terminal to load coal and return to Newcastle, New South Wales.

Shortly after, the train driver of MR336 moved the train up to the loading bin in readiness to commence loading. At 0417, loading coal into the wagons of MR336 commenced.

At 0445, the TLO was alerted to a ‘wagon empty detected’ alarm from the loading system.

When this alarm sounded, the TLO was pre-occupied and could not confirm if the wagon was loaded by viewing it as it passed under the loading bin. The TLO then waited for the weighbridge readings for wagons 28 and 29. The TLO received a ‘wagon empty alert’ from the weighbridge but was unable to visually verify if these wagons were empty as the wagons had moved beyond the lit loading area.

Shortly after, the TLO called the Coal Handling Preparation Plant (CHPP) Supervisor to check wagon 28. The CHPP Supervisor confirmed he would check the wagon. The TLO then continued to load the train with the train driver communicating through a combination of telemetry[1] and radio calls.

The CHPP Supervisor and a technician drove up to the front of the loading train then proceeded to count back from the 1st wagon. When they reached the 28th wagon, they checked wagons 27, 28 and 29 and confirmed that all three wagons were loaded.

The TLO continued to load the train, with another three loading interruptions occurring before it was completed at 0645.

Shortly after, the TLO contacted the train driver by radio to advise loading was complete. MR336 then departed the loading terminal on its path to Newcastle where it would unload.

Derailment

MR336 travelled approximately 160 km after departing Moolarben loading terminal before the train derailed on the up main line[2] at Antiene. The leading wheelset of the trailing bogie of the 25th wagon mounted the rail at kilometre mark 274.396 km.[3] The wheelset dropped off the rail in a derailed state at kilometre mark 274.394 km.

Shortly after derailing, a wheelset ejected from its bogie and came to rest at 271.684 kms. The train continued to travel in a derailed state for approximately nine kilometres.

Figure 1: Location of ejected wheelset

 

Figure 1: Location of ejected wheelset.
Source: ARTC

Source: ARTC

Collision

As MR336 reached Ravenan, another coal train, WC915 travelling in the opposite direction approached on the down main line.

The second person in WC915 was alerted to something dragging along-side MR336. As WC915 got closer, the second person shouted to the train driver of WC915 to apply full emergency brakes. The train driver applied the emergency brakes as the second person got on the radio to tell the train driver of MR336 to stop immediately.

The trailing bogie on the 25th wagon on MR336 was dragging across the down track fouling the down main line. The lead locomotive of WC915 collided with the dragging bogie that had been partly dislodged from the wagon earlier. The collision between the lead locomotive of WC915 and the dragging bogie caused the wagon it was attached to (25th) and the seven following wagons on MR336 to derail and incur damage to varying degrees.

The 25th, 26th and 27th wagons tipped on their side away from the down main line. The 25th wagon was found without coal.

The locomotives and two wagons on WC915 were derailed and damaged as a result of the collision.

Track infrastructure underneath the derailed rollingstock was damaged and approximately nine kilometres of track and infrastructure between Antiene and Ravenan was damaged to varying degree by the dragging bogie on MR336.

There were no injuries to the train drivers from either train.

Figure 2: Curve and gradient diagram indicating point of derailment and point of collision

›3 ‹
Figure 2: Curve and gradient diagram indicating point of derailment and point of collision.
Source: ARTC annotated by OTSI

Source: ARTC annotated by OTSI

Incident response

The train crew on WC915 contacted Network Control and their organisation’s operations control to inform them of the incident. They checked their locomotives for any fluid loss and confirmed with their operations control that the locomotives were intact.

The rail infrastructure manager sent crews to isolate the site and make it safe. Information was communicated to relevant organisations as required and post incident investigations commenced that afternoon.

__________

  1. In train coal loading, a telemetry system is used to monitor train speed to ensure an optimum speed is maintained to facilitate coal loading. The train driver is able to observe the desired speed and adjust the power to ensure that speed is maintained.
  2. In NSW, trains travelling towards Sydney travel in the up direction, trains travelling away from Sydney are travelling in the down direction.
  3. Kilometre mark in New South Wales is the distance a section of rail is from Platform 1 Central Station, Sydney, New South Wales.

Context

Hunter Valley Coal Chain

Spanning over 450 km the Hunter Valley Coal Chain is made up of coal producers (or mines), rail haulage providers, the Australian Rail Track Corporation (ARTC), three export terminals, port managers and the Hunter Valley Coal Chain Coordinator. Collectively the Hunter Valley Coal Chain facilitates more than 20,000 train trips and the loading of 1,600 vessels annually in order to export more than 80 different types of thermal and coking coal to destinations around the world.

The trains involved in this incident were coal trains.

Australian Rail Track Corporation

The ARTC is the rail infrastructure manager for mainline rail in the Hunter Valley. ARTC was accredited by the Office of the National Rail Safety Regulator (ONRSR) to manage the Hunter Valley rail network.

As the accredited organisation, ARTC is responsible for maintaining the condition of the rail infrastructure to relevant standards and for providing network control for the movements of rollingstock over the network.

The rail track where the derailment and subsequent collision occurred was under the management of the ARTC. The system of safeworking was rail vehicle detection using axle counters to detect the presence of rail traffic in a block section.

Moolarben Coal Complex

The Moolarben Coal Complex is located approximately 40 kilometres north of Mudgee in the Western Coalfields of New South Wales.

Moolarben Coal Operations Pty Ltd (MCO) is the operator of the Moolarben Coal Complex on behalf of the Moolarben Joint Venture (Moolarben Coal Mines Pty Ltd, Yancoal Moolarben Pty Ltd and a consortium of Korean power companies). MCO, Moolarben Coal Mines Pty Ltd and Yancoal Moolarben are wholly owned subsidiaries of Yancoal Australia Limited.

Operating 24 hours a day, the Moolarben Coal Complex comprises four approved open cut mining areas, three approved underground mining areas and other mining related infrastructure (including coal processing and transport facilities).

Moolarben loading terminal

The Moolarben loading terminal is a loading facility built for loading coal trains and forms a significant part of the transport facilities of the Moolarben Coal Complex.

Coal loading process

Train information sent to TLO

Prior to the arrival of the coal train at the loading terminal, the rolling stock operator was responsible for sending Moolarben information relating to train loading. The information which was sent includes but is not limited to wagon and locomotive; type, number, position in consist and loading restrictions (i.e. if some wagons are to remain empty or partially filled).

Information uploading

As the train approaches the loading terminal, the TLO uploads the information provided in preparation to load the train. The data is uploaded into the train load point supervisory control and data acquisition system (SCADA). This system monitors the progress of a train and through the use of algorithms loads the train at a speed and rate so as to optimise the volume of coal loaded on each train against certain customer requirements.

Train movement into loading terminal

Once the information is uploaded by the TLO, the TLO provides the train driver a verbal authority to proceed through the loading terminal via 2-way radio. The TLO also advises the train driver to maintain a speed which was advised to be around 0.7-0.8 km/h. Beyond the initial verbal communication, the train speed is communicated from the TLO to the train via the train speed indicator (TSI) panel in the locomotive cabin. The speed of the train is monitored by sensors at the loading terminal and warns the TLO of any over speed or under speed.

Train loading display screen

Prior to the occurrence (wagon not being loaded), the train loading display screen did not display the wagon number column.

Figure 3: Train loading display screen

Figure 3: Train loading display screen.
Source: OTSI

Source: OTSI

There was no clear delineation between the ‘wagon’ position in the train consist and the ‘vehicle’ position in the train consist. That is, vehicle position was the physical count of all vehicles (wagons and/or locos) starting from the first vehicle (in the direction of travel) of the train consist. Whereas wagon position was the physical count from the first wagon in the train consist, not including any locomotives. To be clear, if there were 3 locomotives on the front of a head end powered train, wagon number 25 was the same as vehicle 28. The requirement to distinguish between locomotives and wagons was a recent change as a result of Moolarben’s investigation into this occurrence.

Train loading

Moolarben’s coal loading terminal has a semi-automated coal loading system that uses a number of sensors for wagon detection to start and stop coal loading. The coal loading system is overseen by the TLO. The TLO would normally be seated in the loading cabin which was situated above the wagons so coal loading into the wagons could be easily observed.

How the sensors work

The sensors are known as photo electric (PE) sensors. The sensors work by emitting and receiving electromagnetic radiation. If there is an obstruction, the receiver cannot detect the emitted radiation and hence knows there is an obstruction. If the receiver can receive the emitted radiation, the system knows that there is no obstruction.

Figure 4: PE Sensor operation
 

Figure 4: PE Sensor operation
Source: OTSI

Source: OTSI

The sensors involved in coal loading were P1, P2, N1, N2, N3 and N3A.

Sensors P1 and P2

Sensors P1 and P2 initiate the loading of coal from the coal bin above the wagons. The coal bin has a capacity of 1000 t and it is continuously monitored and filled by conveyor belts during a typical train loading operation. A typical 93 x 120 t train will carry approximately 9021 t of coal.

The sensors detect a gap between the front of the wagon to be loaded and the rear of the wagon which had just been loaded. Once the front of the wagon to be loaded obstructs P1 and P2, there is a delay and the system instructs the bin gates to open to commence loading.

Figure 5: Sensor P1 and P2 instructing system to drop coal

Figure 5: Sensor P1 and P2 instructing system to drop coal.
Source: OTSI

Source: OTSI

Coal loading then continues as the train progresses at 0.7 to 0.8 km/h.

Sensors N1, N2, N3 and N3A

Sensors N1, N2, N3 and N3A work to instruct the system to stop loading coal. As a gap emerges at N1, it warns the system that it is approaching the end of the wagon and begins to slow the loading of coal. Once a gap emerges at N2, the system instructs the loading to stop completely and by the time there is a gap at N3, the system should have stopped loading coal.

It was advised by Moolarben representatives that a redundant sensor N3A also existed at the time of the occurrence which was used to confirm what the N3 sensor was detecting. This redundant sensor has since been removed.

Figure 6: N1, N2 and N3 sensors

Figure 6: N1, N2 and N3 sensors.
Source: OTSI

Source: OTSI

Post wagon loading

After the wagons are loaded, they enter a weigh bridge approximately three wagon lengths from the loading terminal in the direction of travel. The weigh bridge measures the weight of the wagons to confirm the wagon has been loaded within tolerances. This weigh data is used as feedback to the SCADA system so as to load more or less coal in the remaining wagons based upon a number of parameters including the speed of the train, the time the load bin chute is open for, etc).

It was advised that if the wagons fall below or above a threshold weight, an alarm is activated to alert the TLO. In this scenario, the wagon may be reversed to load more coal or adjusted to reduce the amount of coal within it.

Safety Interface Agreements

A safety interface agreement is a written agreement for managing the risks to safety at interfaces.

The Rail Safety National Law (RSNL) requires that rail transport operators (i.e. rail infrastructure managers and rolling stock operators) and road managers must enter into interface agreements to manage the risks to safety at interfaces.

Pacific National Pty Ltd and Moolarben Coal Operations Pty Ltd entered into a safety interface agreement between the two parties from the 14 March 2016.

In part 31.2 of the safety interface agreement;

Moolarben Coal Operations Pty limited is responsible for train (wagon) loading operations to ensure wagons are loaded safely and evenly without causing damage to Pacific national property and notification to Pacific National of any wagon loading irregularity, including overloading, underloading (wagons to be loaded within maximum and minimum gross load limit) empty or part loaded wagons, coal spillages, and will ensure wagon loading is carried out, so far as reasonably practicable, as detailed in Pacific National Procedure NSWC005 – Coal Train Loading Process.

Safety analysis

Introduction

A number of potential contributing factors were considered in this investigation, including the condition and maintenance history of the rolling stock and the rail infrastructure.

Rolling stock maintenance history was provided by the rollingstock operators and the investigation concluded maintenance did not contribute to the incident. Post incident inspections of the damaged wagons, draw gear, bogies and wheelsets found the damage to be consistent with the derailment and collision and therefore unlikely any pre-existing condition in the rollingstock contributed to the incident.

Track measurements (top, gauge and twist)[4] were taken of the Up Main line from the point of mount (274.396 km)[5] to 100 m in the down direction. Track measurements were also taken up to 25 m after the point of mount in the up direction The track measurements were all within the ARTC’s track geometry standards. Maintenance data for the section of track was provided by the ARTC and the investigation concluded track maintenance and the condition of the track did not contribute to the incident.

The focus of the analysis is on the conditions that led to the derailment of the 25th wagon in the train consist and the awareness of this risk in the industry.

Wagon empty and undetected

There were a number of controls in place at the Moolarben loading terminal to detect when a wagon had not been loaded as required. At the time, Moolarben loading terminal was in process of commissioning various parts of the loading system so that it could be a fully automated loading process without the need for intervention by a TLO.

The loading system was set up with sensors to detect wagons and automatically load each wagon as it passed underneath the coal loading chute. As loading progressed on the morning of the incident, there was a fault in the system which stopped coal from being loaded into the 25th wagon. Moolarben’s post incident analysis of the loading system found the stop loading sensor N3A had malfunctioned. Moolarben loading terminal decommissioned the N3A sensor shortly after.

When loading faults such as this occurred there was the ‘wagon empty detected’ alarm which formed part of the check system that was being commissioned and would form part of the system for automatic loading. In the commissioning phase, this alarm had false triggered on a number of occasions and the confidence level of the TLO in the alarm was not high.

The wagon empty detected alarm sounded as required but was reliant on an action from the TLO to intervene and check that the alarm was indicating an actual event and then set the train back so the wagon could be loaded if required.

At the time the alarm sounded, the TLO was pre-occupied with other non-work related activity which kept his attention long enough to miss being able to confirm if the wagon had been loaded by viewing it as it passed under the loading bin.

When the TLO eventually returned his attention to the train loading, he attempted to confirm whether there was coal in the wagon, however the wagon had moved beyond the lit loading area and in the low light of pre sunrise the TLO could not visually confirm whether there was coal in the wagon or not. The TLO was aware the wagon would be passing over the weighbridge which was also fitted with an alarm for detecting empty wagons.

When the weighbridge alarm sounded indicating there was an empty wagon, the TLO waited for the next wagon to go over the weighbridge to confirm whether the weighbridge was reading correctly. When the following wagon passed over without sounding the weighbridge alarm, the TLO contacted the CHPP Supervisor to check the wagon.

Prior to the incident the train loading display screen for the TLO only had the Seq. No. column. When the TLO contacted the CHPP Supervisor to check the wagon, the TLO called the wagon – wagon 28, when it was in fact the 25th wagon, as there were 3 locomotives at the front of the train.

The CHPP Supervisor and a technician drove up to the position of the 28th wagon by counting back from the first wagon after the locomotives. They checked the 27th, 28th and 29th wagons to confirm all were loaded. As the 25th wagon (28th vehicle in the sequence) was the unloaded wagon, it was missed by this check.

The CHPP Supervisor confirmed the 28th wagon was loaded and the TLO continued to load the train.

‘Less than safely loaded’ wagons

In June 2010, the Independent Transport Safety and Reliability Regulator (ITSRR), the then rail safety regulator in New South Wales, released a rail industry safety notice (RISN No.32) on the ‘Operation of less than safely loaded wagons’.

The safety notice was published following instances of one or more wagons in a coal train consist being left unloaded or lightly loaded and positioned between loaded wagons at a coal loading point on a railway balloon loop off the main line.

The safety notice was directed to coal loading operators and rolling stock operators who were responsible for loading coal into wagons of a coal train to a safe level.

In the 20 months leading to the release of the safety notice, a freight operator in NSW had experienced three incidents most likely attributed to an empty or lightly loaded vehicle entering service undetected post loading, within the train consist. In each case, the empty or lightly loaded wagon had been positioned between two fully loaded wagons resulting in the trailing in-train longitudinal forces either lifting the wagon off its bogie(s), lifting the wagon and bogie(s) off the rail or, the precursor, the forces creating a diminished wheel loading on wheelsets of the affected wagon, which heightens the risk of derailment.

On each of the above occasions, the wagon was retained in the train consist by the solid drawbar connection which prevented the train consist from uncoupling, however, two of the incidents resulted in derailments.

As a result ITSRR provided some key points to consider which included:

  • Rolling stock operators to check that suitable and sufficient information has been provided to the loading points regarding appropriate wagon loading configurations (ie. less than safely loaded thresholds) for safe operations.
  • Existing controls for the majority of coal loading facilities are predominantly procedural based ie. reliance on the competency and fitness for duty (ie. drug and alcohol, fatigue management, etc) of their coal load personnel and their vulnerability to human error (or performance variability).
  • Attention of coal load personnel can also be subject to distraction from other train management, mining and stockpile duties.
  • A number of incidents of less than safely loaded wagons have either gone undetected and/or the train crew involved have not been informed prior to completion of the loading activity.

Refer to Appendix A for the full rail industry safety notice.

In July 2019, the ONRSR released a safety message titled; ‘Unsafe Loading of Coal Wagons’. It was an updated safety message with the same safety related content released in response to this occurrence.

Refer to Appendix B for the full safety message.

Derailment

The train travelled approximately 160 km without incident. As the train approached Antiene, it is likely a combination of train handling (train braking was being applied), track geometry (a falling grade of 1:59 and a left hand 690m curve radius[6] into a turnout on tangent track), and the trailing in-train longitudinal forces lifting the 25th wagon and its trailing bogie resulting in the leading wheelset of the trailing bogie mounting the rail at kilometre mark 274.396 km. The wheelset then dismounted the rail in a derailed state at kilometre mark 274.394 km.

The 25th wagon was positioned between two loaded wagons, the front of the wagon was coupled to the 24th wagon and was attached to the 26th wagon by the solid drawbar connection.

Figure 7: Point of Mount (POM) and Point of Dismount (POD) – Antiene Up direction

Figure 7: Point of Mount (POM) and Point of Dismount (POD) – Antiene Up direction.
Source: OTSI

Source: OTSI

Following the derailment the leading wheelset of the trailing bogie was ejected from the bogie and left on the track at kilometre mark 271.684 km. As the driver remained unaware of the derailment, the train continued with the bogie dragging on the down rail of the up main line within the six foot and foul of the down main line.

Figure 8: WC915 front locomotive footage just prior to collision

Figure 8: WC915 front locomotive footage just prior to collision.
Source: Aurizon annotated by OTSI

Source: Aurizon annotated by OTSI

The derailed wagon and dragging bogie caused damage to multiple parts of the rail infrastructure network. As the train travelled in a derailed state, the NCO received information that may have alerted the NCO to a possible problem however it was received and interpreted in the following manner (see Table 1).

Table 1: NCO log of incident events

Table 1: NCO log of incident events.
Source: ARTC annotated by OTSI to de-identify parties

Source: ARTC annotated by OTSI to de-identify parties

The responses by the NCO to the track failures as they occurred are likely standard responses taken by any NCO when faced with track irregularities.

At 1202 when the NCO was alerted to an irregularity on the down main line, the NCO’s response was to make contact with the signals team and request they investigate a possible track failure.

This is an immediate action taken by the NCO that attends to a potential problem and would allow the NCO to continue working on other issues while waiting for further information.

When the second track failure occurred at 1209, the NCO’s response was to reset the axle counters which appeared to rectify the situation, although the original track failure remained. The NCO had already taken action on the original track failure and it is reasonable to see he would continue to wait to hear back from the signal team.

At 1216 when there were multiple track failures, the NCO assumed a possible power issue caused by lightning strike or storm which was occurring further north on the rail network and therefore took action by advising the signals team of these other failures.

Between this time and the emergency call made by the crew on WC915, the NCO had an opportunity to make contact with the train crew on MR336 if he suspected there was a problem. Had the NCO made the enquiry, it is likely the crew of MR336 would not have been able to provide any other information that would help the NCO identify the source of the problem.

As at 1225 when the NCO heard the emergency call from WC915, the NCO made contact with the driver of MR336 and made enquiries. MR336 had come to a stand and the crew reported they were not injured. They were also not aware of any issue other than a minor air issue which they deemed not a problem.

It is possible the air issue was a leak in the trains pneumatic braking system[7] as a result of the derailed 25th wagon however such a situation where air is being lost but not significantly so as to automatically apply the brakes, the train crew would remain unaware of there being a problem with the train.

Management of known risk

The risk associated with releasing an empty or lightly loaded wagon positioned between a loaded wagon onto the rail network was known by the rollingstock operator and the loading terminal. The requirement to load wagons safely and evenly was detailed in the safety interface agreement between the two parties.

Moolarben loading terminal had a number of controls in place to ensure wagons were loaded in accordance with the rollingstock operator’s procedure for loading coal trains. This indicated both parties understood the risk and reasonable mitigating controls had been implemented to prevent the risk from arising.

A summary of the risk controls that were ineffective which lead to the unwanted event of an empty wagon positioned between loaded wagons is depicted below (see Figure 9).

Figure 9: Bow tie risk diagram depicting ineffective risk controls in this incident

Figure 9: Bow tie risk diagram depicting ineffective risk controls in this incident.
Source: OTSI

Source: OTSI

The layers of control (defences) in place failed to prevent and detect the loading irregularity. As a result, the loading terminal reviewed its risk assessment and controls to confirm the systems level of effectiveness. The outcomes from the review included implementation of additional controls, such as extra lighting on the outbound side of the loading chute, two independent mechanisms for detection of empty wagons and a process of verification of the train load out summary between the TLO and the Control Room Operators to ensure each train is loaded within required specification prior to advising the train operator that loading is complete.

__________

  1. Top – is vertical alignment or rail level; Gauge - is the distance between points on the inside face of the rails; Twist - is the difference in level of the two rails over a defined length, short twist (2 m), long twist (14 m).
  2. Kilometre mark in New South Wales is the distance a section of rail is from Platform 1 Central Station, Sydney, New South Wales.
  3. Track curvature is referenced when facing the up direction
  4. The pneumatic braking system or air braking system is a fail-safe train braking system that uses compressed air for the release and application of brakes across the train

Findings

ATSB investigation report findings focus on safety factors (that is, events and conditions that increase risk). Safety factors include ‘contributing factors’ and ‘other factors that increased risk’ (that is, factors that did not meet the definition of a contributing factor for this occurrence but were still considered important to include in the report for the purpose of increasing awareness and enhancing safety). In addition ‘other findings’ may be included to provide important information about topics other than safety factors.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

From the evidence available, the following findings are made with respect to the derailment of MR336 at Antiene and subsequent collision between MR336 and WC915 at Ravenan New South Wales on 26 September 2018.

Contributing factors

  • An empty wagon positioned between two loaded wagons on MR336 was allowed onto the network and this known risk materialised in a derailment of the empty wagon.
  • The derailed state of MR336 caused the collision with WC915.
  • Sensor N3A malfunctioned during the loading sequence which stopped coal from being loaded into the 25th wagon.
  • The TLO was pre-occupied when control alarms sounded and missed viewing the wagon passing under the loading bin.
  • The TLO instigated a verification check however the TLO unknowingly provided misleading information to check the 28th wagon, rather than the 28th vehicle in the sequence.
  • The 25th wagon in the train consist was not loaded and was not detected by the loading terminal.

Other factors that increased risk

  • It is likely, the reliability of the alarms to indicate a loading irregularity in the loading system contributed to the TLO questioning their accuracy.
  • The TLO could not see if the wagon was loaded or not in the low light of pre sunrise when the wagon had already passed through the loading area.

Safety action

Central to the ATSB’s investigation of transport safety matters is the early identification of safety issues. The ATSB expects relevant organisations will address all safety issues an investigation identifies.

Depending on the level of risk of a safety issue, the extent of corrective action taken by the relevant organisation(s), or the desirability of directing a broad safety message to the rail industry, the ATSB may issue a formal safety recommendation or safety advisory notice as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

The initial public version of these safety issues and actions are provided separately on the ATSB website, to facilitate monitoring by interested parties. Where relevant, the safety issues and actions will be updated on the ATSB website as further information about safety action comes to hand.

Safety action not associated with an identified safety issue

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Moolarben loading terminal

Following the occurrence Moolarben conducted an internal investigation and developed a number of safety actions in their corrective action plan. During the DIP process Moolarben provided an update on the status of the actions listed below.

Malfunctioning Sensors

Sensor N3A was determined to be faulty and for this reason has been removed from service.

Empty wagon detection sensors have been re-commissioned and are functional.

Verification of train load out summary

Communicate requirement for verification of train load out summary at end of loading by both the TLO and Control Room Operators to ensure train is loaded within required specification prior to advising train operator that loading is complete. Completed.

Review risk assessment for additional train loading requirements

Review of the train load out risk assessment has been completed. Outcomes of this review included the following items;

  1. Train loading sequence stop and alarms raised if wagon overloaded, underloaded or empty.
  2. Empty wagon detection via two independent methods, being radar profiling and weighbridge.
  3. Sequence number, wagon number and unique wagon identifier to appear on train summary page.
  4. Improve lighting on outbound side of train load out.
  5. Use of radar for train speed detection.
  6. Increased monitoring of weighbridge performance.
  7. Enable recording of train load out CCTV cameras.
  8. Install scraper blade for removal of coal from the top of a wagon if an overload occurs.
  9. Upgrade and reprogram the train loading control system to incorporate all of the above requirements.

Complete change management for additional train loading requirements

Complete Change Management for additional train loading functionality requirements as identified by the risk assessment review. The additional requirements listed above have been implemented since the incident occurred.

Review and update train loading manual and training package

Review and update train loading manual and training package including additional train loading functionality requirements and actions to be taken if a wagon is outside of acceptable loading specifications. Completed.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • Moolarben
  • Australian Rail Track Corporation
  • Aurizon
  • Pacific National
  • Office of the National Rail Safety Regulator (ONRSR)
  • Interviews with directly involved parties
  • Video footage of the incident and other photographs and videos taken on the day of the incident and in the days after

References

ARTC curve and gradient

ITSRR

Safety interface agreement

Rail Safety National Law (RSNL)

Submissions

Under section 26 of the Transport Safety Investigation Act 2003, the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. That section allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the following directly involved parties:

  • Moolarben
  • Australian Rail Track Corporation
  • Aurizon
  • Pacific National
  • ONRSR
  • Transport for NSW

Submissions were received from:

  • Moolarben
  • Australian Rail Track Corporation
  • Pacific National
  • Transport for NSW
  • ONRSR

The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Additional train details

Train 1 details

Track operator:Australian Rail Track Corporation 
Train operator:Pacific National 
Train number:MR336 
Type of operation:Freight 
Consist:Coal 
Departure:Moolarben loading terminal 
Destination:Newcastle 
Persons on board:Crew – 2Passengers – N/A
Injuries:Crew – 0Passengers – N/A
Damage:Substantial [7 wagons damaged] and nine kilometres of track 

Train 2 details

Train operator:Aurizon 
Train number:WC915 
Type of operation:Freight 
Consist:Coal (empty) 
Departure:Newcastle 
Destination:Werris Creek 
Persons on board:Crew – 2Passengers – N/A
Injuries:Crew – 2 (minor)Passengers – N/A
Damage:Substantial [2 locomotives and 2 wagons damaged] 

Appendices

Appendix A – Rail Industry Safety Notice (RISN No. 32)

Appendix A – Rail Industry Safety Notice (RISN No. 32) (Page 1)
Appendix A – Rail Industry Safety Notice (RISN No. 32) (Page 2)
Appendix A – Rail Industry Safety Notice (RISN No. 32) (Page 3)

Appendix B – Safety Message: Unsafe Loading of Coal Wagons

This safety message is directed to coal loading operators and any other rolling stock operators responsible for loading coal into wagons.

Recently a coal train consist at a coal loading point on a railway balloon loop off the main line in New South Wales was allowed to depart with an unloaded wagon. The unloaded wagon subsequently derailed on the main line whilst the train was braking to negotiate a curve.

The empty wagon had been sandwiched between two fully loaded wagons resulting in the trailing in-train longitudinal forces either; lifting the wagon off one of its bogies, lifting the wagon and one of its bogies off the rail or, as a precursor, the forces created a diminished wheel loading on wheelsets of the affected wagon - subsequently heightening the risk of derailment.

Further the wagon was retained in the train consist by a solid drawbar connection which prevented uncoupling and resulted in a derailment. One bogie dislodged from the centre casting and rotated under the vehicle before fouling the adjacent track. The derailed bogie was subsequently struck by another coal train traveling on the adjacent track causing that train to derail.

In view of the above, it is imperative that the actual load in each wagon is ascertained at the loading points prior to the consist entering a rail transport operator’s network.

Points to consider
  • Rolling stock operators should check that suitable and sufficient information has been provided to the loading points regarding appropriate wagon loading configurations (i.e. less than safely loaded thresholds) for safe operations.
  • Existing controls for the majority of coal loading facilities are predominantly procedural based i.e. reliance on the competency and fitness for duty (i.e. drug and alcohol, fatigue management, etc.) of their coal load personnel and their vulnerability to human error (or performance variability).
  • Attention of coal loading personnel can also be subject to distraction from other train management, mining and stockpile duties.
The following actions should be taken by rail transport operators

ONRSR requires coal loading operators and rolling stock operators to carry out their respective railway operations in relation to loading coal into wagons of a coal train in a safe manner, to do so in a way that does not threaten safety. Coal loading operators and rolling stock operators should:

  • Review the risks associated with operations and loading of coal trains, in particular ensuring correct and known loading configurations are met for the subsequent movement of the train away from the coal loading facility.
  • In the context of this safety message review the current standards, procedures, rules and control measures including safety interface agreements to ensure:
    • clear delineation of roles and responsibilities;
    • Ongoing effectiveness of existing controls; and
    • Opportunities to implement additional controls including engineering controls such as ultrasonic load profile detectors, track based load cells, etc.)
This advice is effective immediately

www.onrsr.com.au/documents/resource-centre/publication/safety-data-bulletin/aus-onrsr/safety-bulletins/unsafe-loading-of-coal-wagon.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2018-017
Occurrence date 26/09/2018
Location Ravenan (approx. 98 km from Newcastle)
State New South Wales
Report release date 18/12/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Incident
Highest injury level None

Train details

Train operator Pacific National
Train number MR336
Type of operation Coal freight
Rail vehicle sector Freight
Departure point Moolarben, New South Wales
Destination Kooragang Coal Terminal, New South Wales
Train damage Substantial

Train details

Train operator Aurizon
Train number WC195
Type of operation Coal Freight (empty)
Rail vehicle sector Freight
Departure point Kooragang Coal Terminal, New South Wales
Destination Wilpinjong, New South Wales
Train damage Substantial