On 17 August 2016, at about 0926 Central Standard Time (CST), an Alliance Airlines Fokker F27 MK 50 aircraft (Fokker 50), registered VH-FKV (FKV), and operating with callsign ‘Unity 3201’, landed on runway 12 at Adelaide Airport, South Australia (SA) after a flight from Olympic Dam, SA. The flight crew consisted of a captain seated in the left seat and a check captain seated in the right seat acting as the first officer. Also on board were two cabin crewmembers and 49 passengers.
Air traffic control (ATC) audio recordings showed that at 0926:53, after FKV had rolled through the intersection with runway 23, the aerodrome controller (ADC) cleared an aircraft for take-off on runway 23 (Figure 1).
Figure 1: Adelaide Airport
Source: Airservices Australia – annotated by ATSB
At the end of runway 12, FKV then exited runway 12 onto taxiway D2. After vacating the runway, the check captain switched the aircraft radio from the ATC Tower frequency to Ground frequency and reconfigured the aircraft in accordance with standard operating procedures after landing. The check captain was unable to immediately contact the surface movement controller (SMC) due to congestion on the Ground frequency. The SMC position had combined SMC and airways clearance[1] delivery responsibility.
At 0927:46, the ADC cleared a Jetstar Airbus A320 aircraft, registered VH-VGI (VGI), to land on runway 23. At that stage, the ADC sighted the A320 about 3 NM away on final approach. The flight crew of FKV did not hear that clearance.
Shortly after entering taxiway D2, the check captain, seated on the right of FKV looked outside and sighted an aircraft in the take-off roll on runway 23 and also sighted the A320 on final approach. They estimated that the A320 was 5 to 6 NM away. Based on that estimate, the check captain assessed that they would probably be cleared to cross runway 23 behind the departing aircraft and in front of the landing A320, and then turned their attention inside the cockpit to complete their after-landing checks.
As FKV approached holding point D2, the flight crew had not received an ATC clearance to cross runway 23, and the flight crew therefore assumed they were going to stop at the holding point. The check captain was still waiting for a break in transmissions to make their initial contact with the SMC to advise ‘Adelaide Ground, Unity 3201 for bay 50 golf’.
The SMC was issuing a clearance to another aircraft when they sighted FKV taxiing on taxiway D2 towards the direction the controller was facing. At 0927:49, the SMC told the flight crew of an aircraft awaiting an airways clearance to standby, then immediately said ‘Unity 3201 hold short of runway 23, I’ve got you going to 50 golf’.
The check captain of FKV reported that the start of the transmission from the SMC was over-transmitted and what they heard was ‘runway 23 and I’ve got you for bay 50 golf’. As the instruction included the parking bay, the check captain thought the SMC had instructed them to ‘cross runway 23…’ and read back ‘cross runway 23 to 50 golf, Unity 3201’. The SMC thought the pilot read back ‘short runway 23...’ and assumed that the word ‘hold’ had been ‘clipped’. Both flight crewmembers of FKV thought they had received a clearance to cross runway 23.
The ADC sighted FKV on taxiway D2 and heard the SMC say ‘hold short’, but did not hear the response from the flight crew. The ADC scanned runway 23 to check it was still clear for the landing A320, which was then over buildings and less than 30 seconds from touchdown, and then commenced a handover of the ADC position to another controller.
At 0928:10, the SMC coordinated[2] with the ADC and cleared a vehicle to cross runway 12.
The captain (in the left seat) of FKV then looked to their left and stated ‘clear left’ and taxied the aircraft onto runway 23 to cross. The check captain then looked to their right and sighted the A320 and reported that it was a lot closer than they had expected.
The SMC had looked down at their screen to check the flight strip for the aircraft awaiting a clearance. As the controller looked up, they saw FKV crossing the holding point.
At 0928:21, the SMC called ‘hold short’ and immediately realising that was not the correct instruction, said ‘Unity expedite expedite Unity’. The SMC could then see the A320 in the go-around. The ADC heard the SMC call ‘expedite’ and looked up to see the A320 about 100 ft above the runway – already in the go-around. At 0928:25, the ADC directed the A320 crew to go around.
The captain of FKV continued to taxi the aircraft across the runway and onto taxiway D1 and did not sight the A320 at any time. The A320 (VGI) returned to land without further incident.
Flight crew (FKV) comments
Check captain acting as first officer
The check captain commented that a crossing instruction fitted with their judgment of the situation when they first sighted the A320 while taxiing on D2. They were close to the holding point when they received the initial (hold short) instruction from ATC, and assessed that there was a level of urgency in the SMC’s voice which indicated to them that it was a crossing instruction.
The sun was behind the A320 on final approach to runway 23, which may have affected the check captain’s initial estimate, when they first entered taxiway D2, of how far away the A320 was. However, it was not a factor when FKV taxied onto the runway. At that time, the check captain estimated that the A320 was about 1.5 NM away at about 200 ft above the runway. The check captain decided not to advise the left-seat captain then of the A320 as they had already entered the runway.
There was no confusion in the flight deck over whether they had been instructed to cross the runway or not, they both thought that was the clearance.
The clearance was clipped or over-transmitted and led them to believe it was ‘cross’ not ‘hold short’. In hindsight, the pilot commented that maybe they should have reconfirmed the clearance to cross because the words were clipped, but they expected the readback would give the SMC confirmation that what they understood was correct and the opportunity to detect any misunderstanding. They did not hear anything that sounded like ‘hold short’. It was possible that the check captain had pushed their transmit (push-to-talk (PTT)) button which had momentarily over-transmitted the SMC’s call.
If the check captain had sighted the A320 later in the taxi and closer to the holding point, they would probably have expected to hold short rather than cross in front of it.
The controller’s addition of the bay information to the instruction was not consistent with a hold short instruction. The standard clearance is either hold short (with no further instructions), or cross and taxi to your bay or with additional taxiing instructions.
It was possibly a professional courtesy so the pilot did not have to respond with their bay number, but it added to their expectation that it was a crossing instruction. The flight crew had contacted their company personnel about 100 NM prior to their arrival and were issued with parking bay 50G. It was standard procedure to advise the SMC of their bay number on first contact with the SMC. The SMC presumably gets the bay allocation from the airport ground personnel, and provided that information to the flight crew to save a radio transmission. However, its addition to the end of the hold short instruction misled the pilots.
In the absence of any communication with the SMC prior to reaching the holding point, they would have stopped at the holding point rather than enter the runway.
When discussing the incident afterwards, the captain told the check captain that they had not been aware of or sighted the A320 at any time. The check captain commented that maybe they should have told the captain ‘there is one rolling and one on final’ when they first saw the two aircraft to increase the captain’s situational awareness.
Captain
The captain was normally based in New Zealand and commented that to cross an active runway there, pilots are required to contact the ADC on the Tower frequency for a clearance.
The captain was intending to stop at the holding point, but proceeded to cross when they thought they got the clearance to do so. They had to increase power to accelerate, having slowed ready to stop.
The bay number was a non-normal addition to a taxi instruction, possibly provided as the check captain had not yet been able to give the normal transmission with their bay allocation after exiting the runway.
Controller comments
The air traffic controllers provided the following comments.
Aerodrome controller
It was a quiet and routine traffic sequence and the weather at the time was benign.
The voice equipment was fitted in 2013 to Adelaide Tower. The Tower was a ‘quiet tower’, which means that the controllers can only hear the transmissions on the frequency they are controlling, in their own headsets. Although the ADC could hear the SMC give the instruction to hold short, they could not hear any response from flight crew on the Ground frequency.
Prior to the implementation of the quiet tower, controllers could hear transmissions on the other frequencies on speakers in the Tower. The ADC commented that this improved their situational awareness, particularly from a coordination perspective.
The ADC commented that since the incident, in a similar situation, they would wait for the aircraft to land before commencing a handover.
The ADC commented that following the incident there would be a greater focus among the controllers, not just on the instructions controllers give, but that it is not complete until you get adequate readback that responds to all the components of the clearance. In addition, there should be no taxi instruction beyond a hold short instruction.
Controller taking over from aerodrome controller
The controller in the process of a handover/takeover with the ADC was looking at the weather display and listening to the ADC handing over, when they heard the SMC say ‘hold short’ and then ‘expedite’. The controller looked across and sighted FKV half way across the runway and the A320 in the go-around.
The controller commented that before the ‘quiet tower’ they could all hear each other’s radio, which improved their situational awareness.
The controller also commented that when they receive a call from a pilot, they sometimes miss the first part of the transmission. The controller reported that this is a known fault that the controllers have reported via the Airways systems issues reporting scheme (see below). They also advised that they have become desensitised to hearing only part of the readback, which negates the effectiveness of the readback.
The controller advised that there were a number of things that could have prevented the incident:
if the SMC had heard the readback correctly
better scanning by air traffic controllers and pilots of aircraft approaching and crossing runways
stop bars[3] could have been an effective risk control even without hearing the readback or effective scanning.
The controller commended the actions of the A320 flight crew.
Surface movement controller
The SMC was confident they had given the hold short instruction clearly.
The SMC thought that the Unity flight crew would be expecting to hold short because there was no way they were going to be cleared to cross in front of the landing A320. The SMC commented that if they had not contacted Unity 3201 as they were approaching the holding point, they would have stopped. Because the aircraft was taxiing towards the runway and it is difficult to tell if the aircraft is slowing down, the SMC issued the hold short instruction to be sure they would stop.
They commented that they added the bay number to the hold short instruction to save a transmission, as another aircraft was waiting for their clearance. They were not sure why they did not pick up the incorrect readback, but they did not hear the first word.
The SMC asserted that in most of the transmissions in Adelaide, the initial second of a readback is clipped, for example they only hear ‘short’ instead of ‘hold short’. The controller thought the readback was ‘short runway 23’ not ‘cross runway 23’. As they thought the pilot would be expecting to hold short, the controller was expecting the readback to be ‘hold short’ and that expectation affected what the controller heard.
In Adelaide Tower, it is difficult to tell when a controller’s PTT button is released and whether the frequency is open or closed. Normally for a ‘hold short’ readback, you would be expecting two words but they get used to looking for one word. If you are not certain of a readback, you are meant to ask again, but if they don’t get the first word every time, it can lead to a lot of additional transmissions. Maybe if radio operators push the PTT button and then wait two heartbeats before they start talking, that technique may prevent transmissions being clipped.
The pilots may not hear the controllers’ instructions clearly either as they are also not listening in a perfect environment.
The airport ground staff provide the ADC with bay allocations, which the ADC then put on the flight strip. When the pilots first make contact with the SMC, they state the bay allocated by their company and the SMC checks that matches the bay number on the strip.
The SMC did not hear the ADC clear the A320 to land (or the other aircraft to take off) because they were issuing a clearance at the time.
If the A320 had landed and FKV had crossed the runway, they may have just got across in front of it but it would have been close.
If the airport had stop bar lights, the incident would more than likely not have occurred.
Manual of air traffic services
In the Manual of air traffic services (MATS), under section 12.3.1.11 Taxiing across runways, section 12.3.1.11.1 Intermediate holding points, stated: ‘Do not include positions beyond required intermediate holding points in taxi instructions.’
Airways systems issues database report
Airservices Australia provided the ATSB with a copy of the relevant Airways systems issues database (ASID) report. In June 2013, the ASID report from Adelaide ATC stated that inbound calls from pilots were clipped at the beginning of calls. This could be heard on recorded audio from the tower transmissions and was compared with transmissions recorded prior to the implementation of the new radio system. Following ATC transmissions, when the controller releases the PTT, the voice communications control system switch remains in the transmit state for 200 milliseconds, known as the guard period. During this period, receive audio is blocked, therefore the audio from pilots is dropped.
In August 2014, the report was updated to state that the clipping issue had been incorporated into the voice system training manual. On 17 December 2015, the comment added was ‘Vendor has advised that this defect will be addressed in the next software release which is currently scheduled for delivery in June 2016’. There was no indication what, if anything, was delivered in that release to address the issue.
On 25 August 2016, a comment was added to the report indicating that rather than a system defect, the cut-off responses could be ‘mostly attributed to poor radio technique by pilots or ATC’. Furthermore, ‘it is also important that controllers release PTT as soon as possible to ensure that the receiver is unmuted’.
The ASID entry dated 17 December 2015 was based on information received from the vendor. Airservices sought input from the vendor on whether they believed the reported issue was a defect and whether the guard period could be adjusted.
Airservices received a response from the vendor with a list of issues which the vendor aimed to address in the next release and the guard period issue was included in this list. Airservices has investigated this issue and has determined it is not a system issue, given that the guard period of 200 milliseconds is less than other voice communication systems used by Airservices and the same as used in other Integrated Tower Automation Suite (INTAS) towers where there has been no observed replication of this issue. It was instead concluded that this issue was due to controller actions related to extended engagement of the foot PTT beyond the end of their transmissions. Airservices considers that the issue was not prevalent in the occurrence as was communicated by the interviewees.
Airservices Australia comment
Airservices Australia provided the following comments in response to the ATSB draft report.
Quiet tower
Although some controllers prefer speakers to increase their situational awareness, it may also result in considerable noise when all three positions are open during periods of increased traffic. Such noise is particularly distracting for controllers that have transitioned from an enroute environment where headsets are used and speakers are not permitted.
Additionally, ATC procedures are designed to ensure controllers can perform their duties safely without reliance on speakers. The use of speakers does not always increase situational awareness and should not be relied upon as an effective threat barrier.
Clipped transmissions
The recorded audio leading up to, during and after the occurrence did not contain any clipped transmissions related to the ‘fault’ reported.
Adelaide Tower Line Manager's and Shift Manager's regular monitoring of the controller's air ground communications have observed that pilot transmissions may occasionally be missing the first part of the call (clipped transmissions are less than one second in duration). This typically occurs when the pilot commences their response prior to the controller releasing the press to talk (PTT) button. However, clipping of this nature does not occur frequently and not to a point where controllers would become desensitised to only hearing part of the readback.
Existing ATC procedures require the controller to obtain a correct readback of instructions (in accordance with per AIP GEN 3.4 -12). In the absence of the correct and complete readback, the controller must challenge the readback until they are satisfied it is correct.
Audio sample
Airservices randomly sampled 90 minutes of audio from 1 August 2016 at Adelaide and did not identify any calls which had a clipped the transmission.
On 12 September, Airservices reviewed the radio technique of a controller in the tower using a foot PTT and noted that there was a significant (0.5-1 second) delay from the end of the delivery of the instruction by the controller to the time when the controller disengaged the foot PTT. This anomaly in the controller's technique resulted in a number of clipped pilot transmissions due to them starting the readback whilst the foot PTT was still engaged. The controller's error was rectified by using the in-line PTT which decreased the delay of the controller releasing the foot PTT.
Additionally, the Voice Communications and Control System (VCCS) enables controllers to view the status of the transmitter and receiver.
ATSB comment
The A320 crew are to be commended for their actions in preventing a potentially more serious incident occurring.
The flight crew of FKV thought they were cleared to cross the runway probably because of the bay allocation at the end of the hold short instruction. An effective sighting of the aircraft on final approach may have led them to query their understood instruction to cross the runway.
The SMC heard one word in response and mis-heard it as ‘short’ rather than ‘cross’ and that assumed ‘hold’ had been clipped from the transmission. The SMC did not question the pilots about the missing word as they had some previous experiences of the beginning of transmissions being clipped. As there was a ‘quiet tower’ communications system, there was no opportunity for the ADC to hear this pilot read-back to the SMC and notice the misunderstandings before the runway incursion.
The ADC was in the process of handover/takeover and was not watching the landing A320 or the runway as they assumed FKV would hold short and that the runway was clear.
Safety message
The risk of runway incursions and other separation events can be minimised through good communication. This incident highlights the importance of:
controllers and flight crews using correct phraseology
controllers and pilots challenging instructions which they have not heard or understood fully
pilots looking carefully for aircraft or other hazards before entering an active runway.
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
While en route from Sydney, New South Wales, to Kuala Lumpur, Malaysia, the oil pressure pump for the right engine (engine 2) of an AirAsia X Airbus A330 experienced a shaft failure. That shaft failure resulted in the oil pressure in engine 2 dropping rapidly to 0 psi. The aircraft’s electronic centralised aircraft monitor (ECAM) detected the drop in oil pressure and notified the flight crew through the ENG 2 OIL LO PR failure alert. In response to the alert, the flight crew commenced, but did not complete, the associated procedure. In accordance with the procedure the flight crew reduced the engine’s thrust to idle, but then elected to monitor the engine instead of shutting it down. After about 4 minutes, the flight crew returned engine 2 to normal operations. Shortly thereafter, the engine surged a number of times and eventually failed. The flight crew completed the engine failure procedure, shutting the engine down, and initiated a diversion to Melbourne. During the diversion, the flight crew attempted to relight engine 2 twice, the first shortly after the engine failure, and the second just prior to descending into Melbourne.
What the ATSB found
The ENG 2 OIL LO PR failure, a level 3 alert, was the result of a shaft failure of the right engine oil pressure pump. A level 3 alert required immediate crew action as the failure may be altering the safety of the flight. The ECAM procedure required the flight crew reduce the engine thrust to idle and, ‘if [the] warning persists’, then shut the engine down. The flight crew probably interpreted this as a temporal requirement and not a continuation of the condition, as intended by Airbus. As a result, the flight crew continued to troubleshoot the failure. After monitoring the engine, they established a belief that the warning was the result of a gauge failure. With a stated intent of further trouble shooting, the flight crew then increased the engine’s thrust. This led to the first engine stall and ultimately the engine failure.
Despite available guidance and cumulative evidence to the contrary, the flight crew determined that right engine was not damaged and could be restarted. Consequently, and contrary to the operator’s procedures, the flight crew made two attempts to restart this engine. Both restart attempts failed.
Also contrary to the operator’s procedures, the flight crew elected to divert to Melbourne following the engine failure, bypassing closer suitable aerodromes. This increased the time that the aircraft was operating in an elevated risk environment.
What's been done as a result
The operator restated the operational requirements concerning engine restarts and diversion decision making to flight crew. The operator also used the occurrence as the basis of a training package on response to engine failures, restarting failed engines and diversion decision making.
Safety message
This occurrence demonstrates the importance of crews adhering to standard operating procedures. It also identifies the need for clarity in the construction of procedures, and that where there is not a need for immediate response, to look at the full contextual and available information before deciding on a plan of action.
Context
Operator information
AirAsia X is a Malaysian company based in Kuala Lumpur, Malaysia, operating under an Air Operator’s certificate issued by the Department of Civil Aviation Malaysia. AirAsia X operates long haul air transportation services throughout the Asia-Pacific region and the Middle East.
Personnel information
Captain
The captain held an Air Transport Pilot (Aeroplane) Licence (ATP(A)L), a current Class 1 medical certificate, and was certified in English proficiency at level 5. The captain had accumulated about 8,700 hours of aeronautical experience. Of these, approximately 2,540 hours were on Airbus A330 type aircraft. In the 90 days preceding the occurrence, the captain had logged 244 hours, all of which were on Airbus A330 aircraft.
About 4 months prior to the occurrence, the captain had a recurrent training session in an A330 simulator, and about 10 months prior to the occurrence an annual line check, both of which were completed to a satisfactory standard.
First officer
The first officer held an Air Transport Pilot (Aeroplane) Licence (ATP(A)L), a current Class 1 medical certificate, and was certified in English proficiency at level 5. The first officer had accumulated about 3,265 hours of aeronautical experience. About 4 months prior to the occurrence, the first officer had a recurrent training session in an A330 simulator, and about 7 months prior to the occurrence an annual line check, both of which were completed to a satisfactory standard.
Aircraft information
The A330 is a twin turbofan engine, medium to long range, wide-body passenger aircraft. Manufactured by Airbus, 9M-XXD was fitted with two Rolls-Royce Trent 700 series engines. The following discussion will cover the:
electronic centralised aircraft monitor (ECAM)
Trent 700 engine, including the engine oil system and starter system.
The electronic centralised aircraft monitor
The ECAM monitors the various aircraft systems and displays information about those systems, including the aircraft’s engines, to the flight crew. The components of the ECAM include the:
flight warning computers (FWC)
engine/warning and the system display units (Figure 3).
Figure 3: The cockpit front panels, showing the location and exploded view of the engine/warning display and system display, and the master warning/caution lights
The figure shows the location and exploded view of the engine/warning display and system display, and the master warning/caution lights.
Source: Airbus, modified by ATSB.
When the FWCs detect a system failure, they automatically trigger the appropriate ECAM alert level. That ECAM alert level will result in the display of the ECAM message attached with the condition, the triggering of the alert level’s aural and visual attention-getters, and the display of the required emergency/abnormal procedure as well as the relevant system display.
There were three ECAM alert levels. From a systems perspective:
The most serious, a level 3 red safety priority alert, denoted a system failure that alters flight safety and required immediate flight crew action.
A level 2 amber abnormal priority alert denoted a system failure that does not have a direct consequence on flight safety, but required crew awareness. Action in response to a level 2 alert should be taken without delay, time and situation permitting. The required action is displayed as a procedure on the lower left section of the engine/warning display (Figure 3).
A level 1 amber degradation priority alert required crew awareness and then monitoring.
The Trent 700 engine
An overview
The Rolls-Royce Trent 700 engine has three compressor/turbine assemblies, identified as the low-pressure, intermediate-pressure and high-pressure assemblies (Figure 4). The measure of the rotation of these assemblies is displayed as the N1, N2 and N3 values respectively (see the engine/warning and system displays at Figure 3). The high-pressure assembly has an accessory gearbox attached. That gearbox includes components used to start the engine. A full authority digital engine control (FADEC) system controls and manages the engine, as well as provides engine parameters to the ECAM system.
Figure 4: Trent 700 cutaway diagram
The cutaway identifies the low-pressure assembly (blue), the intermediate-pressure assembly (yellow), the high-pressure assembly (orange) and the combustion chamber (red).
Source: Rolls-Royce, modified by ATSB.
The engine oil system
The engine’s oil system provides lubrication for engine components. A pressure pump module takes oil from the oil tank and supplies that oil to the engine components at the required pressure. That oil is then returned from the engine components to the oil tank using a scavenge pump module. The oil system uses three sensors to monitor oil pressure, two oil pressure transducers and an oil pressure switch. The transducers provide oil pressure parameters to the ECAM system, which in turn, are displayed as oil system parameters on the relevant engine systems display. Those transducer parameters are also sent to the FWC. The oil pressure switch provides a signal directly to the FWC in the event of loss of oil pressure. The FWC will generate a low oil pressure message in the event that any two of the three oil pressure sensors indicate low oil pressure.
The FCOM contained a section that detailed the limitations contained within the manufacturer’s Aircraft Flight Manual.[16] Limitations attached to the aircraft’s power plant included a minimum oil pressure of 25 psi.
In a Flight Operations Briefing Notes (FOBN) titled Supplementary Techniques – Handling Engine Malfunctions,[17] Airbus provided basic guidelines to identify engine malfunctions and typical operational recommendations in case of engine malfunctions. The FOBN included the following with respect to low oil pressure and low oil level:
In service experience shows that some rejected takeoffs and in-flight shutdowns have been commanded because of a low oil level. However, a low oil level alone is not a symptom of an engine malfunction.
On the other hand, a low oil pressure is the sign of an imminent engine failure. Therefore, the published procedure must be applied.
The engine starter system
The engine starter system comprises an air turbine starter (starter motor), a starter valve to provide high pressure bleed air to the starter motor, and engine start controls on the flight deck panels. The FADEC controls the system components and the start sequence.
For an inflight relight of the engine, the FADEC will identify whether the relight will require the assistance of the starter motor, or whether the flight conditions are sufficient to enable a windmilling relight. Rolls-Royce advised that if airspeed is greater than 280 kt and N3 is greater than 7 per cent, then a windmill relight will be performed. If either of these two parameters are not met, the FADEC will perform a starter assisted relight. During an inflight relight, the FADEC will:
provide fuel to the engine when the high-pressure turbine has achieved greater than 10 per cent rotation
if the starter motor has been engaged, disengage the starter motor when the high-pressure turbine has achieved greater than 50 per cent rotation.
Rolls-Royce also advised that there was no published data on engine indications for a windmilling engine. The expected N1, N2 and N3 indications would depend on the aircraft’s speed and altitude, however, test data for conditions similar to the first relight attempt suggest that these parameters would be about N1 of 18 per cent, N2 of 6 per cent and N3 of 4 per cent.
Emergency and abnormal procedures
The triggering of an ECAM alert will result in the procedure, which the flight crew are required to complete, being presented on the engine/warning display. Some actions required by the procedures may depend on a precondition. These preconditions are identified by a preceding dot. Procedures can also conclude with associated procedures. Associated procedures are additional non-normal procedures required to be completed as a result of a change in the aircraft’s configuration or status.
The procedures discussion will examine the Airbus ECAM procedures for the ENG OIL LO PR, ENG STALL, ENG FAIL, and the related ENG SHUT DOWN messages. This will be followed by discussion on the LAND ASAP message, engine restart in-flight procedures and the ENG START FAULT alert.
The AirAsia X Flight Crew Operating Manual (FCOM) contained explanations on these procedures. The intent was to explain actions for which the reason is not self-evident, and to provide additional background. As far as practicable, the procedural presentation in the FCOM was identical to that presented by ECAM. The following discussion on specific emergency/abnormal procedures is based on what is displayed to the fight crew on the ECAM, and any other relevant information that is contained in the FCOM.
The AirAsia X Flight Crew Training Manual[18] contained general guidance on the conduct of engine malfunctions. That guidance stated:
Most engine malfunctions are taken into account by one or several ECAM alerts that warn the flight crew and provide the flight crew with the actions to perform. However, some engine malfunctions require some knowledge and the analysis of the flight crew, so that the flight crew can recognize, understand, and manage these engine malfunctions.
When the flight crew identifies an abnormal parameter, the flight crew should use all the information available to analyze the engine malfunction. The flight crew should not consider only this abnormal parameter to perform their analysis.
If possible, the flight crew should keep the engine running in flight. Except if a procedure requires an engine shutdown, it is usually preferable to keep the engine running. Even at idle, the engine powers the hydraulic, electric, and bleed systems.
In addition, if the flight crew is not sure which engine has a malfunction, the flight crew should keep the engines running. If really damaged, the affected engine will eventually fail.
The ENG OIL LO PR ECAM procedures
If engine oil pressure drops below 25 psi, the ECAM will trigger the ENG 1(2) OIL LO PR (engine oil low pressure) level 3 alert, with an associated aural alert. The displayed ECAM procedure was:
THR LEVER (AFFECTED ENGINE).................................................IDLE
● IF WARNING PERSISTS:
ENG MASTER (AFFECTED ENGINE)..............................................OFF
Selecting the ENG MASTER switch to OFF will shut the engine down. If the flight crew select the ENG MASTER to OFF, the ECAM identified the ENG 1(2) SHUT DOWN (engine shutdown) procedure as an associated procedure.
ATSB observation
The flight crew delayed completing the procedure while they analysed the oil system parameters and the likely reason for the alert. After about 3.5 minutes, the flight crew advanced the thrust lever, and 30 seconds later, the engine stalled.
The ENG STALL ECAM procedures
An engine stall will trigger a level 2 alert, which is notified to the flight crew by the ENG 1(2) STALL (engine stall) ECAM message and associated aural alert. The displayed ECAM procedure is:
THR LEVER 1(2)....................................................................................IDLE
ENG 1(2) PARAMETERS.......................................................................CHECK
● IF ABNORMAL:
ENG MASTER 1(2).................................................................................OFF
If the flight crew select the ENG MASTER to OFF, the engine shutdown procedure is identified as an associated procedure.
The FCOM guidance for the engine stall procedure provided additional detail on the indications of a stalled engine, and also stated that an engine restart is at the flight crew’s discretion.
ATSB observation
The flight crew reacted to the stall condition in accordance with the procedure; however, about 30 seconds later the engine stalled again and then failed.
The ENG FAIL ECAM procedures
When the engine’s core speed is below idle while the engine MASTER switch is ON,[19] the ECAM will trigger a level 2 alert with the ENG 1(2) FAIL (engine fail) ECAM message being displayed and associated aural alert. The displayed ECAM procedure is:
ENG START SEL.........................................................................................IGN
THR LEVER (AFFECTED ENGINE)...........................................................IDLE
● IF NO ENG RELIGHT AFTER 30 S:
ENG MASTER (AFFECTED ENGINE)........................................................OFF
● IF DAMAGE:
[not relevant]
● IF NO DAMAGE:
ENG (AFFECTED) RELIGHT........................................................................CONSIDER
The procedure required the flight crew to determine whether the engine is damaged. The FCOM provided guidance on indications of damage to an engine. The FCOM procedure stated that:
Engine damage may be accompanied by:
● Explosions
● Significant increase in aircraft vibrations and/or buffeting
● Repeated, or uncontrollable engine stalls
● Associated abnormal indications, such as hydraulic fluid loss, no N2 or N3 indication.
The placing of the ENG MASTER switch to OFF would result in the engine being shut down. This would trigger the ENG 1(2) SHUT DOWN ECAM, which was also identified as an associated procedure. Appended to the end of the ENG 2 FAIL and part of the notice that the associated procedure was the ENG SHUT DOWN procedure, was the following additional information:
Apply the ENG SHUT DOWN procedure … if damage, or if engine relight is unsuccessful.
ATSB observation
The procedure included a restart (relight) procedure, being the first procedural action—the selection of the ENG START SEL (the engine start selector switch) to the IGN (ignition position).The flight crew shut the engine down in accordance with the engine failure procedure.
The ENG SHUT DOWN ECAM procedures
When an engine was shut down, the amber LAND ASAP (land as soon as possible) and ENG 1(2) SHUT DOWN ECAM messages were displayed. The engine shut down procedure was designed to place the aircraft in a configuration that enabled single engine operation.
ATSB observation
The shut down procedure does not include an option to, or guidance to consider, restarting the engine.
LAND ASAP message
The FCOM included definitions for the LAND ASAP ECAM message:
LAND ASAP (red). Land as soon as possible at the nearest airport at which a safe landing can be made. Note: LAND ASAP (red) information is applicable to a time-critical situation.
LAND ASAP (amber). Consider landing at the nearest suitable airport. The definition included a note, stating that the suitability criteria should be defined in accordance with the operator's policy.
Inflight engine relight
There was no ECAM displayed procedure for an in-flight engine relight. The FCOM and quick reference handbook (QRH) contained the ENG RELIGHT (IN FLIGHT) procedures.
Rolls-Royce advised that there is normally a delay of around 7 seconds between initiation of an inflight relight—through selection of the ENG MASTER switch to ON—and the first indication of rotation for N3.
The ENG START FAULT ECAM alert
The ENG 1(2) START FAULT level 2 alert was triggered when one of a number of conditions were detected during an engine start, including:
exceeding the starter time
an engine stall
the engine’s exhaust gas temperature exceeds the limit
no light up
low N1 speed.
The ECAM procedure associated with the alert is not provided in this report, as it is not relevant for the event’s investigation.
ATSB observation
The flight crew’s first attempted relight occurred about 13 minutes after the engine failed. The second relight occurred about 90 minutes later, just before the aircraft commenced its descent into Melbourne.
For the first relight, the airspeed and starter motor were unable to provide sufficient N3 rotation to trigger the FADEC to provide fuel to the engine. As a result, light up did not occur within the required time. This was the probable cause of the ENG START FAULT ECAM alert.
For the second relight, the airspeed and starter motor were able to provide sufficient N3 rotation to enable fuel flow and light off, but due to the deteriorated state of the engine the N3 did not increase sufficiently to enable disengagement of the starter motor until the flight crew stopped the relight through selecting the ENG MASTER switch to OFF.
Aerodrome information
Rescue and fire fighting services
The rescue and fire fighting services (RFFS) required for various aerodromes was established through the International Civil Aviation Organization (ICAO), 2016 Annex 14 to the Chicago Convention, titled Aerodrome Design and Operations.[20] The principal objective of RFFS is to save lives in the event of an aircraft accident or incident occurring at, or in the immediate vicinity of an aerodrome. An aerodrome’s required RFFS was based on a number of criteria, including the overall length and the fuselage width of the aircraft that predominantly use the aerodrome, and a threshold value in the number of movements of the highest category of aircraft. The various levels of RFFS category (CAT) establish a requirement for, among other things, the types and number of rescue and firefighting equipment required to be available at that aerodrome. Essentially, the larger the aircraft the higher the required RFFS CAT. The highest category was CAT 10.
Annex 14 also included a standard requiring that all aerodromes provide RFFS. Australia had a registered difference against this standard. That difference stated that not all international alternate aerodromes had RFFS. That difference also listed eight aerodromes where this was the case. Alice Springs was not included within that list.
Alice Springs
The AIP listed Alice Springs as a designated alternate airport to international airports. A designated alternate airport was defined as:
... an airport specified in the flight plan to which a flight may proceed when it becomes inadvisable to land at the airport of intended landing.
For the day of the occurrence, Alice Springs tower operated from 0830 to 1830 EST, with associated class C and D airspace[21] being active. The occurrence happened outside of these hours, where the airspace at and below FL 180 became class G. RFFS was CAT 7 from 0745 to 1830. At the time of the occurrence, Alice Springs Tower was not manned and RFFS was not available. The NOTAMs[22] contained in the OFP identified the correct RFFS availability.
Airservices Australia provided advice to the operator which stated that ‘outside the advertised operational hours RFF can be at Category 6 within 30 minutes notice in case of emergency’. This out of hours RFF support was provided by off-aerodrome municipal emergency services.
Neither pilot had operated into Alice Springs.
Adelaide
Adelaide operated a curfew from 2330 through 0630 EST. The aerodrome was available for nomination as a planned or unplanned alternate during the curfew. Specifically, curfew restrictions did not apply in a number of circumstances, including when the pilot of the aircraft had declared an in‑flight emergency, or when there was an urgent need for the aircraft to land to ensure the safety or security of the aircraft.
RFFS was CAT 9 from 0630 to 2330, and CAT 5 at other hours, however, on request and with one hour’s notice, RFFS could be raised to CAT 9. The NOTAMs contained in the OFP identified the correct RFFS availability.
The captain stated that he had operated into Adelaide twice and was familiar with that aerodrome, but was more familiar with Melbourne.
Melbourne
Melbourne did not operate a curfew. RFFS was CAT 10 with 24-hour availability.
Operational information
The occurrence involved an engine failure while the aircraft was operating as an extended range operations (ETOPS) flight.[23] An ETOPS segment commenced when the flight was more than the threshold time, 60 minutes at the engine out cruise speed, from an authorised ETOPS alternate aerodrome. The occurrence flight had a maximum authorised diversion time of 120 minutes, that is, the flight was approved to operate no further than 120 minutes from any authorised ETOPS alternate aerodrome. The flight’s operational flight plan (OFP) listed three alternate aerodromes. Alice Springs and Darwin were two of those alternate aerodromes. In-flight, the flight crew were able to use a number of approved ETOPS alternate aerodromes, including Adelaide and Melbourne, should they be required for use. At the time of the engine failure, the aircraft was approaching Alice Springs and, at the relevant ETOPS planning speed, was about:
30 minutes from Alice Springs
75 minutes from Adelaide
115 minutes from Melbourne.
The following discussion on operational considerations around the engine failure and subsequent actions includes:
an examination of Malaysian and Australian legislation, regulation and/or standards relevant to:
preflight planning requirements for international operations, and in particular alternate aerodrome requirements, for both normal operations and ETOPS
in-flight requirements following an engine failure
an overview of the operator’s operations manual suite
the operational flight planning requirements as contained within the operator’s operations manual
the inflight requirements as contained within the operator’s operations manual.
Malaysian and Australian regulatory requirements
The operator was registered in Malaysia and required to meet Malaysian regulations for the conduct of operations and the occurrence flight. The flight, and the occurrence, however, was over Australian territory and therefore Australian law applied. It is therefore necessary to consider the effect of both states’ legal and regulatory systems on the planning and conduct of the occurrence flight.
The Malaysian legislative and regulatory system that applied to civil aviation consisted of the Civil Aviation Act 1969 (Malaysia), the Civil Aviation Regulations 2016 (Malaysia) and subordinate rules, standards, requirements and procedures . The following points are relevant:
An operator was required to submit an operations manual to the regulator for approval.
The regulator was required to approve ETOPS operations. That approval included relevant procedures, the authorised ETOPS routes, and alternate aerodromes available to be used.
The Malaysian regulatory system applied to Malaysian registered aircraft extra-territorially.
ATSB observation
A Malaysian rule that came into effect shortly after the occurrence required an operator to ensure that an aerodrome of operation met the relevant RFFS category. The rule, however, enabled a Malaysian operator to use another state’s RFFS requirements when operating in that state’s flight information region, when those RFFS requirements differed from Malaysian requirements.
The Civil Aviation Act 1988 (Australia) required international aircraft operating into or from Australia to have permission from the Civil Aviation Safety Authority (CASA). At the time of the occurrence, AirAsia X was operating under a Foreign Aircraft Air Operator’s Certificate (FAAOC). Civil Aviation Order (CAO) 82.0 applied a number of conditions to Air Operator’s Certificates authorising, among other things, regular public transport operations. CASA advised that CAO 82.0 was not applicable to foreign registered aircraft. CASA also advised that, in accordance with the Chicago Convention, the AirAsia X’s operations manuals, as authorised by the Department of Civil Aviation Malaysia (DCAM),[24] were accepted by CASA for the purposes of issuing the FAAOC.
The Operations Manual suite
The operations manual (OM) suite, which was approved by the DCAM, contained the operator’s policies, instructions and procedures necessary for flight operations. There were four parts to the suite:
Part A General/Basic (OMA) that contained non-type related operational policies, instructions and procedures.
Part B Aeroplane Operating Manual (OMB) that contained all of the type related airplane operating manuals.
Part C Route and Airport (OMC) that contained route and airport information.
Part D Training (OMD) that contained training related information.
Operating procedures
The OMA contained ‘non-type related operational policies, instructions and procedures that are needed for a safe operation’. OMA Chapter 8 contained matters directly dealing with aircraft operations. That chapter contained a number of subsections, three of which were relevant for the occurrence event—flight preparation, flight procedures and ETOPS.
The OMC also contained material that supplemented the requirements in the OMA.
Flight preparation
The flight preparation section included criteria for determining the usability of aerodromes. The usability of an aerodrome was based on whether that aerodrome met:
certain physical and supporting infrastructure requirements, that is, it met the criteria for being an adequate airport
weather requirements at the projected time of use, that is, being an adequate airport that aerodrome met additional weather criteria for being a suitable airport.
An adequateairport was one that:
met the required runway characteristics, including sufficient length and performance requirements
had sufficient supporting infrastructure, including lighting, communications and navigation aids
had the recue and firefighting services (RFFS) required for the type of operation that it was to be used for
the pavement strength was compatible for the aircraft weight.
The adequateairport criteria also contained a limitation regarding operations over remote areas. That limitation required that a two engine aircraft operating over remote areas to not be flown more than 60 minutes:
from an adequate airport
at the one engine inoperative cruising speed
where weather conditions are forecast at or above the applicable landing minima at the expected time of arrival.
The exception to this limitation was when operating in accordance with ETOPS criteria.
The adequate airport criteria also contained the operator’s required RFFS categories[25] for various types of operations with their A330 aircraft. The A330 had an RFFS requirement for CAT 9. That RFFS requirement could be reduced, based on the type of operation that a particular adequate airport was to be used for. These reduced CAT requirements were:
CAT 8 for a departure or destination airport
CAT 7 for an enroute alternate airport
CAT 4 for an ETOPSsuitable airport.
Finally, the adequate airport requirements also included a statement that:
‘RFF[S] category required for ETOPS and Adequate alternates is 4’. This statement contradicted the CAT 7 requirement for an en route alternate airport. The operator advised that this statement should have read ‘RFF[S] category required for ETOPS Adequate alternates is 4’.
if during flight the aircraft captain becomes aware of an RFFS category downgrade, the captain may either divert or elect to accept an RFFS of no lower than CAT 4 and continue the flight.
A suitable airport was a departure, destination or alternate airport that met specific weather criteria at the time of the operation. The reported weather conditions at Alice Springs, Adelaide and Melbourne met the requirements for a suitable airport.
Flight procedures
The OMA section on flight procedures included policy and procedure for handling an abnormal/ emergency condition. Included within that material were the inflight requirements following an engine failure, which stated:
As a general rule if the reason for the engine failure cannot be clearly identified (ice, heavy rain, turbulence, etc.) then it shall not be restarted unless a greater emergency exists…
Two Engine Aircraft: The Commander/PIC shall: …
– Divert to the nearest suitable airport that is safe and operational.
– When two or more suitable airports are available then the nearest airport in flight time terms should be considered…
The following elements and others which may be relevant, should be considered, to determine whether an airport is suitable or not:
• Aircraft configuration and performance, current weight, systems status, required fuel versus usable fuel available, wind, weather, terrain, minimum altitudes, runway dimension, surface condition, braking devices available, navaids for approach and lighting available, RFF category at diversion airport and any injuries to any person or persons on board.
The Commander/PIC is expected to divert to the nearest suitable airport if operationally possible otherwise, he is expected to state his reason or reasons for the exceptional circumstances leading to him not to divert to the nearest suitable airport.
ATSB observation
The two restart attempts by the flight crew appear to be contrary to the engine failure rule stated in the flight procedures section of the OMA.
Following the engine failure, the flight procedures policy required a diversion to the nearest suitable airport.
The flight preparation section of the OMA detailed the criteria for a suitable airport. Those criteria included a requirement for RFFS for an en route alternate to be CAT 7. The aircraft captain stated that the decision to divert to Melbourne was based, in part, on the RFFS available at Adelaide, notified as being CAT 5. This was below that required for an en route alternate.
The flight crew reported that two elements that supported the decision to divert to Melbourne were passenger wellbeing and easier recovery of the aircraft. Both elements have an apparent commercial nature, but neither commercial considerations nor these specific elements are included in the determination of the suitability of an airport for diversion.
ETOPS
The OMA separated out all material pertaining to ETOPS into its own section. This section was broken down into a number of sub-sections that covered topics including general information, ETOPS specific definitions, dispatch requirements, normal and non-normal procedures. Regarding the scope of ETOPS policy, the introduction to ETOPS included the following statement:
The policies contained in this section are to be applied over and above AAX’s Flight Operations Standard Operating Policy when operating any of the specified ETOPS routes.
The definitions sub-section contained definitions specifically applicable to ETOPS. For the purposes of the occurrence, the following were relevant:
ETOPS operations. The definition stated the following:
ETOPS operations apply to all flights conducted in a twin-engine aircraft over a route that contains a point further than 60 minutes flying time from an ADEQUATE airport at the approved one-engine-out diversion cruise speed schedule in still air and ISA conditions.
Adequate airport. Otherwise known as an ETOPS adequate airport, the definition identified a number of variations or additions to the adequate airport criteria, as stated in the flight preparations section. These included:
the requirement for DCAM authorisation for an ETOPS alternate
the setting aside of runway pavement requirements[26]
the minimum acceptable RFFS as being CAT 4
that remote airports that have reduced or no RFFS capacity could be used, where the minimum capacity is met by municipal fire departments located off-airport. Alice Springs was specifically identified as being an example of this type of remote airport. The operator stated that Airservices Australia had advised that Alice Springs municipal fire services met the RFFS CAT 4 requirements.
Suitable Airport. Otherwise known as an ETOPS suitable airport, there were variations in the weather requirements for a suitable airport, but these were not applicable for the occurrence.
Maximum Diversion Time. This is the maximum flying time authorised from any point of the route to the nearest adequate airport. The definition included the following:
AAX is approved by DCAM for 120/180 minutes maximum diversion time. Refer to specific aircraft Operations Specifications (OPS SPECS).
It is only used for determining the area of operation, and therefore is not an operational time limitation for conducting a diversion, which has to cope with the prevailing weather conditions.
Maximum Diversion Distance: This definition applied a standard one engine out diversion profile and reference weight, resulting in still air standard distances for various approved diversion times. The following were applicable:
60 minutes. Also referred to as the threshold time, the equivalent distance was 430 NM (see Figure 5 for the application of this threshold time for the occurrence flight).
120 minutes. The equivalent distance was 823 NM. The OFP stated that the occurrence flight was an ETOPS flight limited to 120 minutes.
Figure 5: XAX221 flight track, with 430 NM range circles
The flight track of XAX221 is displayed, as are 430 NM range circles from the company preferred alternates of Melbourne, Adelaide and Alice Springs aerodromes. The positions of the ENG2 OIL LO PR warning and the two engine relight attempts are also shown.
Source: Google earth, modified by ATSB.
Area of operation: Also known as the ETOPS area of operation, this was defined as follows:
The ETOPS Area of Operation is the area in which it is permitted to conduct a flight under the ETOPS regulations. It is defined by the declared maximum diversion distance from an adequate airport (or set of adequate airports), and is represented by the area enclosed within the circles centred on the selected adequate airports, the radius of which is the declared maximum diversion distance.
The OMA separately listed Australia as an ETOPS area of operations.
ETOPS entry point (EEP). The point located on the aircraft’s outbound route, 60 minutes from the last adequate airport. It marks the beginning of the ETOPS segment.
ETOPS exit point (EXP). The point located on the aircraft’s route, where the aircraft has been flying in the ETOPS segment, it enters an area within the threshold time to an adequate aerodrome. It marks the end of the ETOPS segment.
ETOPS segment. Defined as follows:
The ETOPS segment (ETOPS area of operations) starts at the EEP and finishes at the exit point (EXP) when the flight path is back and remains within the 60 minutes area from an ADEQUATE airport. An ETOPS route can contain several successive ETOPS segments well separated from each other.
For a graphical presentation of the EEP, EXP and the ETOPS segment, see Figure 6.
Figure 6: The ETOPS segment, EEP and EXP.
Source: AirAsia X.
The dispatch requirements sub-section included guidance on the content and structure of an ETOPS OFP. As part of ETOPS dispatch requirements, the operator was required to keep a list of approved ETOPS routes with the corresponding en route alternates. The OM suite did not identify any specific ETOPS routes, but instead listed ETOPS areas of operations, which included Australia. The en route alternates were listed separately in the OMC, in a section titled Company Preferred Alternates.
The normal procedures sub-section included procedures relating to preflight cockpit preparation, taxiing, specific inflight procedures such as after airborne communications with dispatch, renomination of en route alternates, fuel and weather update requirements, and various procedures relating to whether the aircraft can meet the specific requirements for ETOPS flight prior to entering an ETOPS segment.
The non-normal procedures sub-section contained the following relevant content:
The Airbus recommendations and guidelines for inflight re-routing or diversion decision making contained in the flight crew operating manual (FCOM) was referenced.
A section titled Failure Cases Requiring a Diversion to the Nearest Airport stated:
In cases leading to a LAND ASAP message on ECAM or QRH, the crew are to follow the ECAM procedures and land at the nearest suitable airport. LAND ASAP in RED requires greater urgency than LAND ASAP in AMBER.
There were also procedures applicable to various systems failures that contained specific guidance prior to the ETOPS segment and during the ETOPS segment.
The operator advised that, as the aircraft had not entered an ETOPS segment, ETOPS policy and procedures did not apply to this particular phase of the aircraft’s flight.
ATSB Observation:
There are a number of items from the ETOPS subsection of the OMA which indicate that ETOPS policy and procedures did apply at the time of the engine failure:
Australia was listed as an ETOPS area of operations.
The definition of ETOPS operations did not limit the applicability of ETOPS policy and procedures to when the aircraft was within an ETOPS segment. Instead, the definition applied those requirements to the entire area enclosed by the ETOPS maximum range from an alternate. The ETOPS area of operations definition also supported this position, however, the ETOPS segment definition seemed to contradict this, at least from an ETOPS area of operations perspective.
There were multiple procedures within the OMA ETOPS sub-section that clearly applied outside of the ETOPS segment.
Of note, the LAND ASAP ECAM procedure applied to ETOPS operations, not all operations.
Company preferred alternates
The OMC contained criteria used to select company preferred alternates. The selection criteria for a company preferred alternate included 24 hour operations (unless otherwise stated) and an RFFS of CAT 7 or better (CAT 4 or better for ETOPS).
The OMC also contained a list of preferred alternate aerodromes. The intent of the list was to assist pilots in the selection of an aerodrome for a safe landing when circumstances necessitated, such as a change from a planned en route alternate. The list of company preferred alternates included:
Alice Springs, with a stated RFFS of CAT 6, and also an indication that additional information regarding operating time/hours applied
Adelaide, with a stated RFFS of CAT 9 during published normal hours and CAT 5 at other times.
That list also included Melbourne, Avalon and Sydney. The OMC also contained the following statement:
There is nothing to prevent pilots from considering airports that are not listed for diversion. However, it is the responsibility of the Commander to ensure that the aircraft performance requirements are met and the deviation from the prescribed criteria is justified under the circumstances.
Meteorological information
The following summarises the METARs[27] covering the period 2330 to 0330 for:
Alice Springs, visibility was greater than 10 km, the wind light and variable, temperature around 12 °C and dew point[28] 0 °C, with the QNH[29] 1021.
Adelaide, was CAVOK[30] with the wind light and variable, temperature around 13 °C and dew point 10 °C, QNH 1021, with a trend indicating no significant change.
Melbourne was CAVOK with a strong northerly wind of 20 kt but decreasing over the period, temperature around 13 °C and dew point 9 °C, QNH 1019. The METARs also included an observation of moderate to severe turbulence below 5,000 ft.
The ATIS[31] for the aircraft’s arrival at Melbourne stated that the wind was 350 degrees at 16 kt, and the weather conditions were CAVOK.
Flight recorders
The aircraft was fitted with a flight data recorder and cockpit voice recorder as required by regulation. The cockpit voice recorder was not obtained by the ATSB—the event would have been overwritten due to the length of flight. Additional data from the aircraft’s FADECs was obtained from the engine manufacturer.
Post flight examination of the engine
Examination by the engine manufacturer
Rolls-Royce conducted an investigation into the engine failure, which included an examination of the affected engine. That examination found the following:
there were no obvious engine oil leaks
oil tank contents were full
the engine magnetic chip detectors and oil filters were clean
the oil pressure pump drive shaft neck was fractured (Figure 7)
the high pressure (HP) assembly was seized due to bearing stress
damage to the HP assembly ball and roller bearings was consistent with engine operation without oil pressure.
Figure 7: Fractured oil pressure pump shaft
Source: Rolls-Royce.
On examination of the failed shaft, Rolls-Royce identified that the failure occurred at the shear neck,[32] but that the failure was not typical of any previous shear neck failures (Figure 8). Rolls‑Royce found that the shaft fracture was the result of fatigue cracking that originated at multiple sites within the shaft bore. Those cracks grew over time, weakening the shaft, until the remaining material failed in overstress. The material and shaft dimensions reportedly complied with specifications. Rolls-Royce was not able to determine what generated the fatigue cracks in this pump shaft. Other than the fracture in the shaft, the pump was in a serviceable condition.
Figure 8: Example of a typical shear neck fracture of an oil pressure pump shaft
Note that the fracture surface is perpendicular to the shaft axis.
Source: Rolls-Royce.
The Rolls-Royce investigation concluded that damage to the HP assembly bearings was consistent with engine operation without oil pressure. Rolls Royce also concluded that the surges were consistent with the expected behaviour of an engine with the identified damage to the HP bearings.
An analysis of the relight attempts was also completed. The analysis stated that during the:
first relight attempt, the engine did not reach the FUEL ON condition,[33] and therefore fuel flow remained at zero throughout the relight attempt.
during the second relight attempt:
at 0132:25, N3 exceeded the FUEL ON condition and fuel was introduced into the engine
11 seconds later the engine’s EGT[34] began to increase, indicating light up
N3 did not increase above the 50 per cent threshold required for starter disengagement, the highest recorded value being 43 per cent
oil pressure for the engine remained at zero throughout both relight attempts.
Oil pressure pump history
Rolls-Royce reported that the oil pressure pump had completed 2,250 cycles[35] and 13,597 hours since new. It had recently been removed from the engine and sent to the pump manufacturer for inspection and rebuild as part of checks for another engine issue. The pump shaft had been subjected to, and passed, non-destructive testing as part of the rebuild. Since being refitted to the engine, it had completed a further 20 hours and 6 flights. Rolls-Royce did not identify any significant events during the engine history that would have affected the oil pressure pump’s integrity.
The oil pressure pump model is common to both the Trent 700 and the Trent 800 (fitted to Boeing 777 aircraft). Rolls-Royce reported that in an initial review of in-service experience, it identified two previously reported cases of pump failure. The first was on a Trent 800, with approximately 3,000 hours since overhaul, and the second was on a Trent 700, with 7,730 hours since new. In both cases, the failure was a result of pump bearing seizure, and the fracture was perpendicular to the axis of the shaft, consistent with that shown in Figure 8.
Procedural instructions
Procedural compliance
In an article in the Airbus safety magazine Safety First, Airbus (2007) discussed the issue of trained flight crew not following procedures. Airbus identified that procedural compliance required not only good procedural design, but also appropriate explanations to support the procedure. Appropriate explanations ensure that flight crew have sufficient confidence in their skills and judgment to manage the situation. Airbus argued that mismatches between procedures (an instruction) and their implementation (an action) can be a function of human performance, which is not stable. Aside from factors such as fatigue, workload and stress, the implementation of procedures requires:
understanding the situation
understanding the procedure and its meaning
ensuring that all pre-conditions are checked
anticipating the expected results
ensuring that all actions required by the procedures are performed in the right order, with good judgment and with good synchronisation between crewmembers.
Airbus concluded that no set of procedures can substitute for human intelligence and flight experience. Safety is a function of a safe aircraft, procedures, and flight crew competence as an ability to manage the expected and unexpected.
Ambiguity in procedural construction
As pointed out by Airbus, good procedural design is a critical component of the safety equation. A factor influencing checklist performance is ambiguity of terms listed (Degani and Weiner, 1993). Once the appropriate procedure has been found (de Britto 1998):
the crew have to understand the content
then plan the necessary actions
and finally execute actions planned.
One type of understanding required is a literal understanding of the items. A literal understanding can be affected by ambiguity in the English language, particularly when the crew are from non-English speaking countries (de Britto, 1998; Burian, 2006).
To improve the effectiveness and clarity of technical documentation, the AeroSpace and Defence Industries Association of Europe published a guide on simplified English for use in technical publications (ASD-STE100). That guide included a dictionary that identified words that should be replaced with another word that provided a clearer meaning. The guide identified the verb ‘persist’ as one such word. It recommended that persist be replaced by ‘continue’. Airbus stated that it has an internal lexicon which is used to construct procedures displayed to flight crew through the ECAM. The operator stated that it did not hold a copy of that lexicon.
The ECAM procedure for the ENG 1(2) OIL LO PR[36] contained the precondition ‘IF WARNING PERSISTS’ before shutting the engine down. ‘Persist’, however, could refer to either a:
temporal sense, such that if the warning exists for a length of time, then the ENG MASTER switch is to be selected to OFF, however, the length of time was not specified in the procedure
change in the way that the condition presents itself, requiring a response to a change or absence of change—specifically the ECAM message goes away and the associated alerts cease.
The flight crew appear to have interpreted the precondition as a temporal change, as they stated that:
all other engine indications were normal after the thrust lever was retarded
they monitored the engine and then some minutes later advanced the thrust lever to trouble shoot the alert.
The Rolls-Royce engine operating instructions identified that the ENG X OIL LO PR message was a level 3 alert that triggered in response to the indicated oil pressure being below 25 psid.[37] The recommended procedure in flight was:
— THR LEVER X REDUCE
Reduce the thrust on the affected engine until the 'OIL LO PR' ECAM warning clears.
Continued operation of the affected engine is acceptable providing this thrust level is not exceeded.
If warning has not cleared even when the IDLE setting has been achieved.
— ENG MASTER X OFF
ATSB observation
Airbus have used the following procedure in the A330 FCOM as an equivalent procedure to the Rolls-Royce procedure:
THR LEVER (AFFECTED ENGINE)...........................................................IDLE
● IF WARNING PERSISTS:
ENG MASTER (AFFECTED ENGINE)........................................................OFF
This would indicate that Airbus have intended the use of ‘persists’ to mean ‘if warning has not cleared’, however, common language usage of persists is in a temporal sense.
Airbus comments regarding the occurrence
Airbus provided the following comments regarding flight crew’s response to the ENG OIL LO PR alert:
The ASD-STE100 standard proposes to use the ‘continue’ instead of ‘persist’. Having discussed with our native English speaking test pilots, such wording may also be interpreted by flight crews as a temporal requirement, as it is a synonym of ‘persists’.
In the controlled language used by Airbus, the word ‘persist’ is authorized and has the following meaning : "To continue to exist especially past a usual, expected, or normal time."
The ENG 1 (2) OIL LO PR alert is a red warning. As stated in the FCOM, such configuration/failure requires an immediate crew action, as this system failure may be altering the flight safety. Even if the flight crew misinterpreted the procedure line to be a temporal condition and not a conditional one, monitoring the engine for more than 3 minutes cannot be considered to be an appropriate crew response to an emergency procedure.
The AAIB UK analysis of previous events where spurious OIL LO PR alerts were generated shows that the majority of flight crews will consider such alert as genuine and therefore will shutdown the engine.
Human performance related information
Error
Errors are the result of actions that fail to generate the intended outcomes. The cognitive processes involved in achieving the goal provide a means of categorising error, and may relate to either the planning or execution of the activity. When there is a prior intention to act and the actions proceeded as planned, but the desired result is not achieved, that error is identified as a mistake. Reason (1990) stated that:
Mistakes are deficiencies or failures in the judgemental and/or inferential processes involved in the selection of an object or in the specification of the means to achieve it, irrespective of whether or not the actions directed by this decision-scheme run according to plan.
One type of mistake is known as a rule-based mistake, which involves the inappropriate matching of environmental signs to the situation and applying troubleshooting principles. Wickens and Hollands (2000) add that this type of mistake occurs when operators know, or believe they know the situation, and they invoke a rule or plan of action to deal with it.
While managing emergency or stressful situations, decision errors can occur. One example is when flight crew develop an incorrect interpretation of the situation, which leads to an inappropriate decision (Orasanu, 2010). Within these situations, demands on the flight crew increase (Woods and Patterson 2001). This is because:
more knowledge potentially needs to be recalled
there is more information to monitor and consequently, there is a changing set of data to integrate into a coherent assessment
theories need to be generated and evaluated
assessment may need to be revised as new data comes in
actions to protect the safety of systems need to be identified, carried out, and monitored for success
existing plans need to be modified or new plans formulated to cope with this process.
When evaluating a situation, there are often available cues that can actually leave the crew without a clear idea of the underlying problem (Orasanu, 2010). Various noises, thumps, vibrations, rumblings, pressure changes, or control problems indicate that something has happened, but not necessarily what. The cues signal potentially dangerous conditions that trigger emergency responses, regardless of the source of the problem. In addition, when experiencing stress and high workload, crews are vulnerable to missing important cues related to their situation and are likely to experience difficulty pulling together disparate pieces of information and making sense of them. This is especially true when some of that information is incomplete, ambiguous, or contradictory (Burian, Barshi, and Dismukes, 2005).
In addition, there is the potential effect of confirmation bias. This is a type of bias that describes a tendency for people to seek information and cues that confirm the tentatively held hypothesis or belief, and not seek (or discount) those that support an opposite conclusion or belief (Wickens and Hollands 2000). Incorrectly interpreting cues due to confirmation bias can strengthen that bias, leading to further cues not being correctly interpreted.
The operator’s internal safety investigation process
Safety Management Systems
The International Civil Aviation Organization (ICAO) Annex 19 to the Chicago Convention, Safety Management, defines a safety management system (SMS) as ‘a systematic approach to managing safety, including the necessary organizational structures, accountabilities, policies and procedures’. The implementation framework for an SMS needs to include the conduct of safety investigations. In alignment with ICAO standards, r. 167 of the Civil Aviation Regulations Malaysia requires that service providers, including air operator certificate holders, shall establish a SMS.
One of the key SMS references documented in the operator’s SMS Manual was the Civil Aviation Authority of Singapore’s Advisory Circular AC-1-3(5), Safety Management Systems. This AC advised that organisations should ‘show that the investigation identifies contributing or causal factors, identifies and ensures the implementation of necessary corrective actions’ and that identified controls are implemented.
Purpose of a safety investigation with a systemic approach
The latest edition of ICAO Doc 9858 Safety Management Manual, released in 2018, states that:
The primary objective of the service provider safety investigation is to understand what happened, and how to prevent similar situations from occurring in the future by eliminating or mitigating safety deficiencies. This is achieved through careful and methodical examination of the event and applying the lessons learned to reduce the probability and/or consequence of future recurrences.
ICAO also advocates for a no-blame approach to investigations:
The safety investigation should focus on the identified hazards and safety risks and opportunities for improvement, not on blame or punishment.
ICAO further promote that safety provider’s investigation reports should include clearly defined findings and recommendations designed to eliminate or mitigate identified safety deficiencies.
The operator’s processes and approach to safety investigations
The operator's SMS policy stated that:
Investigations are undertaken to help identify areas of safety deficiencies. When reports are submitted, an investigation process takes place to discover the details of the occurrence. It is through this process that safety deficiencies can be identified and corrected.
The stated objectives of an investigation included not only establishing what happened, but to identify the local conditions and organisational factors that contributed to the occurrence, review the adequacy of existing system controls and barriers, and to formulate recommendations and lessons learned. The objectives also outlined that the operator took a no-blame approach to investigations.
The documented means for AirAsia X investigators to conduct their analysis included the AirAsia Systemic Investigation Analysis (ASIA) method, which was outlined in a Quick Reference Guide. The ASIA process was described as follows:
ASIA is a process for conducting a systemic analysis of data collected during an incident or accident investigation, and for summarising and reporting this information using a structured framework and standard terminology.
ASIA aims to broaden the spotlight from the errors of individuals and to identify factors at all levels of the organisation or broader system that contributed to the safety event. Correct application of the ASIA method will identify systemic safety deficiencies and guide the generation of effective recommendations to prevent recurrence of similar events.
AirAsia X SMS guidance material stated that the ASIA method was based on the Reason accident causation model.[38]
AirAsia X internal investigation report
The operator conducted an internal investigation into the occurrence.
A preliminary report from this investigation, released on 12 September 2016, contained a number of findings, including that the flight crew performed the ‘correct procedure’ by shutting down engine 2 after it had failed, and that the crew perceived that all engine indications and oil quantity were as indicating normal after engine shutdown. On the topic of the engine re-light attempts, the report stated that the flight crew referred to the FCOM, but were unsuccessful with each of the two attempts. With respect to the diversion to Melbourne, the report indicated that Melbourne was more favourable due to considerations around company RFFS requirements, Adelaide being under curfew, and passenger well-being (among others).
There were three safety recommendations, predominantly around needing to share the event with flight crew and the training department for enhancing current training programs. The operator published an update to the report in May 2018. The operator later advised that this updated report was their final report on the occurrence. This report restated the safety recommendations to share the event with flight crew and the training department for enhancing current training programs. It also contained two further recommendations, which concerned the issuing of a flight safety notice and a training bulletin designed to re-emphasised the inflight engine shutdown procedures and policies. The final report also included a finding that the decision by the flight crew to divert to Melbourne was not in accordance with the company policy that requires a landing at the nearest suitable airport when an amber LAND ASAP is displayed.
On 15 August 2007, an Airbus A330-300 aircraft, registered PK-GPF, was about 926 km north-west of Sydney, NSW en route to Denpasar, Indonesia when the right engine low oil pressure warning activated. The flight crew shut down the engine and commenced a descent to FL 240 while they advised ATC of the event and requested a clearance to return to Sydney. ATC cleared the crew to descend and to track directly to Sydney.
The ATSB found that it was probable that the flexible oil pressure transmitter tube fractured as a result of fatigue from the tube not being adequately supported while being subjected to high levels of vibration. As a result of the crack, engine oil leaked to atmosphere, activating the right engine low oil pressure warning. There had been a history of this cracking and the engine manufacturer, Rolls-Royce, had issued a service bulletin to provide additional support for the tube. This had not been incorporated into the occurrence aircraft.
The ATSB investigation report also noted that another service bulletin had been released in 2002 by the engine manufacturer to alleviate false low oil pressure warnings and fluctuating oil pressure readings. These false readings were attributed to intermittent electrical signals resulting from wear of the electrical contact pins on the oil pressure transmitter connectors.
AAIB UK Bulletin 9/2013 Airbus A330-343, G-VKSS 19 January 2013
On 19 January 2013, an Airbus A330, registered G-VKSS, was in the initial climb and passing 530 ft above ground level when it was struck by birds. The birds impacted the fan blades of both the left and right engines. Both engines were damaged, resulting in significant vibration. The left engine was shut down by the crew following an ENG 1 OIL LO PR ECAM message and the engine oil pressure indicated zero. The aircraft returned to the departure aerodrome.
The aircraft was fitted with Trent 700 engines. No defects were identified with the engine oil system. The left engine oil pressure indication was the result of the high engine vibration causing transient negative oil pressure. The oil pressure transducers detected the transient negative oil pressure. When combined with the engine’s electronic controller logic, this caused the system to generate a low oil pressure warning that was locked on until the engine was shut down.
Rolls-Royce advised that there had been seven previous events of high vibration resulting in the generation of a low oil pressure message. Of these, five had resulted in a precautionary shutdown. However, no details were provided as to why the other two did not result in a shutdown.
In 2018 Rolls-Royce introduced a number of modifications to address the issue of ‘Low Oil Pressure’ warnings being spuriously triggered due to high engine vibration. A new oil pressure transmitter with an electronic filter to dampen high frequency/high amplitude measurements from its input was introduced in a January 2018 engine service bulletin. The engine manufacture also determined that the oil pump failure detection logic in the electronic engine controller software was no longer required. This software function was disabled through an October 2018 engine service bulletin.
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Training and guidance
As part of a flight safety notice to flight crew, the operator, AirAsia X, emphasised the general rule regarding restarts following an engine failure. The rule, contained within Operations Manual, stated that a failed engine should not be restarted when the cause of that failure is unknown or there is insufficient information to determine the cause. That flight safety notice also reiterated the requirement to land at the nearest suitable airport when a LAND ASAP notification is displayed.
The operator also developed a training package to be presented at the flight crews’ annual base check classroom review. That package, based on the occurrence, was developed to identify lessons learnt from the oil pressure loss and subsequent engine failure, the engine restarts and the diversion decision making.
Findings
From the evidence available, the following findings are made with respect to the engine failure and diversion of an Airbus A330, registered 9M-XXD that occurred 445 km south-east of Alice Springs, South Australia on 16 August 2016. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Contributing factors
In response to an engine oil low pressure (ENG OIL LO PR) ECAM, resulting from a fractured shaft within the oil pressure pump, the flight crew continued to monitor the engine parameters instead of shutting the engine down. Due to a mistaken understanding that the alert was a false indication, the flight crew subsequently increased thrust.
The Airbus A330 engine oil low pressure (ENG OIL LO PR) abnormal procedure included the conditional instruction 'if the condition persists'. This may be interpreted as either requiring the flight crew wait a certain period of time to determine the continuation of the condition, as apparently interpreted by the flight crew, or, as intended by Airbus, that the condition has not changed as a result of the previous procedural step.
Contrary to operating procedures, the flight crew made two attempts to relight the failed engine.
The crew diverted to Melbourne instead of the nearest suitable aerodrome. This increased the time that the flight was exposed to the higher risk environment of single engine operations.
Appendices
Appendix 1: Malaysian legislation and regulation
The principal legislation covering civil aviation in Malaysia is the Civil Aviation Act 1969 (Malaysia). The act established the position of the Director General of Civil Aviation Malaysia (DGCA)[39] and enabled the Minister to make regulations for the purposes of carrying out the objects and purposes of the act, and for carrying out the Chicago Convention and its Annexes. That regulation is the Civil Aviation Regulations 2016 (Malaysia) (CARM). The act, regulations and other subordinate laws applied extraterritorially to Malaysian aircraft and flight crew. The act and regulations also enabled the DGCA to issue notices, circulars, directions or information as required.
The CARM required:
an operator to submit an operations manual to the Director General for approval
EDTO operations to be approved by the Director General, and for the Director General to establish the threshold time for an en route alternate.
The Aeronautical Information Circular (AIC) 09/2000 provided detail in the regulation of ETOPS, and which also applied to EDTO operations. The AIC included:
a method for approving ETOPS, which referenced ICAO Annex 6
a requirement that nominated adequate aerodromes be accepted by DCA
that en route alternate aerodromes required for ETOPS be included within the operational and air traffic services flight plans.
DCA published a number of Directives during 2016. These directives contained rules, standards, requirements and procedures pertaining to air operations. The following directives, which came into effect on 15 April 2016, were applicable:
Rules of the Air
specific approvals (SPA).
The rules of the air applied extraterritorially for Malaysian aircraft, ‘to the extent that they do not conflict with the rules published by the State having jurisdiction over the territory overflown’. The rules contained the Annex 6 definition for an alternate aerodrome.
The SPA contained a number of requirements that reflected the content of AIC 09/2000. En route alternate aerodrome requirements were also listed in the SPA, and stated the following:
An EDTO en route alternate aerodrome shall be considered adequate, if, at the expected time of use, the aerodrome is available and equipped with necessary ancillary services such as air traffic services (“ATS”), sufficient lighting, communications, weather reporting, navigation aids and emergency services and has at least one instrument approach procedure available.
Prior to conducting an EDTO flight, the operator shall ensure that an EDTO en route alternate aerodrome is available, within either the operator’s approved EDTO, or a diversion time based on the MEL generated serviceability status of the aeroplane, whichever is shorter.
The operator shall specify any required EDTO en route alternate aerodrome(s) in the operational flight plan and ATS flight plan.
DCA published two other directions on 12 September 2016. While coming into effect shortly after the occurrence, they contain information relevant to current EDTO requirements. These directions were:
organisation requirements for air operations (ORO)
commercial air transport (CAT).
The ORO required an operator to obtain a route qualification from DCA, which included that the route have sufficient aerodromes that are properly equipped for the operation. That requirement was expanded by the following:
The operator must ensure that relevant RFFS category must be met for applicable aircraft at the airport of operation. However certain countries adopted its own requirement especially for EDTO operation. Therefore, an operator may exercise its requirement whenever applicable if operating into their Flight Information Region (FIR).
Appendix 2: Extended range operations for two-engine turbine aircraft
Background
Prior to the 1980’s, regulation limited twin-engine aircraft to operations no more than 60 minutes range from an aerodrome. The introduction, in the 1980’s, of twin turbine engine aircraft capable of long-range operations resulted in the need to develop a method of extending this range limitation, while at the same time ensuring that an equivalent level of safety as that established by aircraft with more than two engines was attained. The result was a system of engine/airframe certification requirements, established engine reliability, and maintenance and operational procedures that created the necessary level of safety. The system was known as extended range operations, or ETOPS. From an ETOPS certification perspective, manufacturers were required to establish that the risk associated with the loss of both engines from independent causes met the required level of safety. From an operational procedural perspective, the risk associated with single engine operations was minimised through, among other things, the identification of, and procedural requirements attached to, the use of ETOPS specific en route alternate aerodromes. As a result of this system, twin turbine engine aircraft have progressively extended the time that they can operate from an en route alternate aerodrome, the diversion time, to more than 4 hours.
International standards for ETOPS
Standards applicable to ETOPS were contained in ICAO Annex 6 to the Chicago Convention, titled Part I – International Commercial Air Transport - Aeroplanes. The following requirements under these standards were applicable:
The state of the operator was required to issue an air operator’s certificate (AOC) to an operator. That AOC was to include operations specifications. An ETOPS authorisation, threshold time and maximum diversion time limits were to be stated in those operations specifications.
The operator was to submit an operations manual to the state of the operator for acceptance, and where required, approval. That operations manual was to:
detail the required content of the OFP
specify procedures for ETOPS, including engine failure procedures
nominate and determine the utilisation of diversion aerodromes
state the level of rescue and fire fighting services (RFFS) deemed acceptable for operations.
An operator was to prepare an OFP for all intended flights. In preparing that OFP, the operator was to:
ascertain that all required ground facilities were adequate for the operation, including that the aerodromes specified in the OFP had adequate RFFS
identify and state in the OFP the en route alternate aerodromes required for ETOPS.
Annex 6 also contained guidance for assessing what level of RFFS was acceptable for the various operational uses of aerodromes. An Airbus A330 aircraft required a base level RFFS of CAT 9. The recommended RFFS category for an en route alternate aerodrome was two levels below that base level—therefore the A330 required RFFS CAT 7 for an en route alternate aerodrome. Annex 6 also recommend that an ETOPS alternate aerodrome should have a minimum of CAT 4.
Flight Crew Operating Manual (FCOM) guidance on ETOPS
The special operations section of the FCOM contained general guidance on ETOPS, as well as specific ETOPS diversion procedures and profiles. It identified that the system design and the engine reliability met with applicable European Aviation Safety Agency (EASA) guidelines, as set forth in AMC 20-6 rev. 2 (EASA).
With respect to diversion decision making, AMC 20-6 contained the following guidance:
Factors to be considered when deciding upon the appropriate course of action and suitability of an aerodrome for diversion may include but are not limited to:
a. Aircraft configuration/weight/systems status;
b. Wind and weather conditions en route at the diversion altitude;
c. Minimum altitudes en route to the diversion aerodrome;
d. Fuel required for the diversion;
e. Aerodrome condition, terrain, weather and wind;
f. Runways available and runway surface condition;
g. Approach aids and lighting;
h. RFFS* capability at the diversion aerodrome;
i. Facilities for aircraft occupants - disembarkation & shelter;
j. Medical facilities;
k. Pilot’s familiarity with the aerodrome;
l. Information about the aerodrome available to the flight crew.
Contingency procedures should not be interpreted in any way that prejudices the final authority and responsibility of the pilot-in-command for the safe operation of the aeroplane.
Note: for an ETOPS en-route alternate aerodrome, a published RFFS category equivalent to ICAO category 4, available at 30 minutes notice, is acceptable.
Air Transport (Aeroplane) Licence, issued August 2007
Endorsements:
Pilot in command, A330
Ratings:
n/a
Medical certificate:
Class 1
Aeronautical experience:
Approximately 8,700 hours
Last flight review:
April 2016
First officer details
Licence details:
Air Transport (Aeroplane) Licence, issued September 2014
Endorsements:
Co-pilot A330
Ratings:
n/a
Medical certificate:
Class 1
Aeronautical experience:
Approximately 3,265 hours
Last flight review:
April 2016
Safety analysis
While en route from Sydney, NSW to Kuala Lumpur, Malaysia, the oil pressure pump drive shaft for the right engine (engine 2) of an AirAsia X Airbus A330 failed. That shaft failure resulted in the oil pressure in engine 2 dropping rapidly to 0 psi. The aircraft’s electronic centralised aircraft monitor (ECAM) detected the drop in oil pressure and notified the flight crew through the ENG 2 OIL LO PR alert and associated warning signals. In response to the alert, the flight crew reduced the engine’s thrust to idle in accordance with the displayed procedure, but then elected to monitor the engine instead of shutting it down as intended by the procedure. After almost four minutes, the flight crew returned the engine 2 thrust lever to the normal inflight position, resulting in the engine’s thrust increasing. Shortly thereafter, the engine surged a number of times and eventually failed. The flight crew completed the engine failure procedure, shutting the engine down, and initiated a diversion to Melbourne. During the diversion, the flight crew attempted to relight engine 2 twice, the first shortly after the engine failure, and the second just prior to descending into Melbourne. Rolls Royce determined that the drive shaft failed due to fatigue cracking, but this was an unusual failure that had not been observed previously.
This analysis will examine the flight crew’s:
response to the oil pressure alert and the subsequent engine failure
attempted relights of the failed engine
diversion decision.
The analysis will conclude with a discussion on the internal investigation conducted by the operator.
Oil pressure alert and subsequent engine failure
The oil pressure pump shaft failure resulted in a level 3 failure red alert, and the ECAM message ENG 2 LO OIL PR and associated procedure being displayed to the flight crew. A level 3 alert is associated with a configuration or failure that requires an immediate crew action, as this configuration or failure may alter the safety of flight. After moving the thrust lever to idle, the procedure included a precondition for initiating the next and final step. That precondition required the flight crew to determine whether the ‘warning persists’, and if it did, then to shut the engine down. The flight crew probably interpreted the precondition as a temporal and not a conditional requirement:
temporal, in that any further action be delayed, an interpretation that could be supported by the Flight Crew Training Manual (FCTM) guidance that urged a bias towards deferring any action that will result in shutting an engine down, and to look beyond the abnormal parameter
conditional, as is the intent of the Rolls-Royce guidance to Airbus on the procedural design.
The flight crew elected to leave the engine at idle, and instead undertook further analysis of the engine indications. The flight crew’s actions point to two human performance issues in the conduct of the checklist:
potential ambiguity in the checklist’s construction
error in the flight crew’s performance, as a result of their mistaken belief as to the source of the level 3 alert.
Ambiguity in the checklist language
The engine manufacturer’s engine operating instructions clearly identified that the procedural response to the OIL LO PR message required the engine to be shut down if the message had not cleared when the idle setting had been achieved. The use of the word ‘persists’ in the precondition for completing the procedure in the Airbus ECAM procedure introduced the possibility of misinterpretation of the required precondition by the flight crew.
Effective communication, which includes all transfer of information whether spoken or written, is essential for the safe operation of flight. The quality and effectiveness of communication is determined by its intelligibility, that is, the degree to which the receiver understands the intended message. Individual words can have multiple meanings, while sentence construction and context can further complicate understanding.
While English is the international language of the aerospace industry, English is often not the native language of flight crew. An example of an attempt by an industry organisation to promote clarity in the use of English in technical documents is the ADS-STE100. That document highlights the potential ambiguity of the verb ‘persists’. Airbus have also identified that an internal lexicon is used in the construction of ECAM language. That lexicon does not appear to be publicly available.
The flight crew’s action in monitoring the engine parameters after partially completing the required procedure is a strong indicator of a misunderstanding in the language used for the precondition description.
Error in the conduct of the ENG 2 OIL LO PR procedure
Airbus pointed out that procedural non-compliance can be a function of understanding the procedure and its meaning. While the supporting explanation for the ENG OIL LO PR alert in the flight crew operations manual (FCOM) was limited, the ECAM was a level 3 alert. A level 3 or red alert denotes a ‘system failure that alters flight safety and requires immediate action’, and the associated procedure is one ‘which may result in personal injury or loss of life if not carefully followed’.
The flight crew’s response, however, should also be assessed in light of the FCTM’s guidance on shutting an engine down as well as the apparent miscomprehension of the ‘persist’ component of the procedure. The FCTM guidance stated that a flight crew should keep the engine operating unless the procedure required an engine shutdown. Instead of shutting the engine down, the flight crew mistakenly continued monitoring the condition of engine 2.
While monitoring the engine, the flight crew developed a belief that the zero oil pressure readings were due to a gauge error, as all other engine parameters were interpreted as being normal. This led to a mistaken understanding that the alert was a false indication. The flight crew subsequently increased engine 2’s thrust. The increase in thrust resulted in the engine surging then stalling, which triggered the ENG 2 STALL alert. The flight crew correctly actioned this new ECAM procedure, retarding the thrust lever. About 30 seconds later, however, the engine surged again and failed. The engine failing triggered the ENG 2 FAIL alert.
The flight crew’s action of increasing the thrust on engine 2 following the ENG 2 OIL LO PR alert led to the engine stalling and then failing. While it is likely that continued operation of the engine at idle thrust with zero oil pressure would have eventually resulted in sufficient bearing damage that would lead to stalls and engine failure, the increase in thrust accelerated that result and probably increased the damage to the engine.
Finally, as identified by the United Kingdom’s Air Accidents Investigation Branch bulletin 9/2013, there had been a recent series of false low oil pressure ECAM alerts on Rolls-Royce engine A330 aircraft. It is not known whether the flight crew were aware of these, or any subsequent Airbus notifications concerning this issue.
Attempted relights of the failed engine
The flight crew stated that, following the engine failure, they then actioned the ENG 2 FAIL procedure. That procedure included a restart (relight) attempt, and then required a decision about whether the engine was damaged. If the engine was deemed not to be damaged, the procedure prompted the flight crew to consider a further relight attempt. The conditions indicative of engine damage were contained within the FCOM, but not displayed on the ECAM. The flight crew later reported that they consulted the FCOM, following which they determined that the engine was not damaged. This may have been influenced by confirmation bias as there was evidence available to the crew that met the criteria for damage, including:
repeated or uncontrollable engine stalls—the engine experienced two surges/stalls. The ENG 2 STALL message alerted the flight crew to the first stall, to which they responded in accordance with the required procedure, and from which the engine recovered. The second stall was uncontrolled and resulted in the engine failing. The flight crew stated that they did not recognise the two stall events as being separate, however, they stated that they briefly saw the engine stall message and that the engine then failed. By this account, the engine experienced an uncontrollable engine stall.
abnormal engine indications—the guidance cites hydraulic fluid loss, no N2 or N3 indication as examples. The flight crew stated that they assessed the oil pressure indications as being abnormal after they had completed the initial actions for the ENG OIL LO PR alert.
Further, the FCOM version of the ENG 2 FAIL procedure stated, at the end of the procedure, that the engine should be shut down if a relight was unsuccessful.
About 10 minutes after shutting the engine down, the flight crew attempted to relight the engine. Prior to this attempt, the first following the engine shut down, there were a number of factors that should have alerted the flight crew that there was a problem with engine 2 and not to attempt to a relight:
The engine had an oil pressure issue, the source of which had not been clarified.
The engine had experienced a stall, then failed.
The engine indications were not normal.
The operations manual stated that a failed engine should not be restarted if the reason for the failure cannot be clearly identified.
The relight attempt that was part of the ENG FAIL procedure was not successful, and the subsequent ENG SHUT DOWN procedure did not include the option of a relight.
There was no safety risk to the aircraft that demanded a relight attempt, and there was significant contextual evidence related to that engine that should have created doubt about the engine. The flight crew’s first relight attempt was unsuccessful. They stated that the relight procedure was terminated as a result of the ENG 2 START FAULT message being displayed.
The flight crew commenced a second relight attempt of the failed engine just prior to descending into Melbourne. In addition to the above factors that should have alerted the flight crew that there was a problem with engine 2, there was the additional evidence of a failed restart attempt and the ENG 2 START FAULT message. For this restart, the engagement of the starter motor and the airspeed were sufficient to enable fuel to be introduced into the engine. While the engine relit shortly after, the Rolls-Royce report identified that either prior to, or as a result of, the second relight attempt, the damage to the engine was sufficient to ensure that the engine could not achieve rpm for sustained operation. Further, the flight crew stated that the relight attempt was terminated as a result of vibrations from the engine.
The multiple failures and abnormal indications associated with engine 2 should have raised questions for the flight crew on the cause of the failures and the viability of the engine. The operator’s procedures stated that, if the reason for an engine failure cannot be clearly identified, then it shall not be restarted unless a greater emergency exists. A greater emergency did not exist. Contrary to the operator’s procedures, the flight crew attempted two restarts on the failed engine.
The diversion
A factual synopsis
Following the first engine surge the flight crew declared an emergency and notified ATC of the event, requested descent, and indicated an initial intention to divert to Melbourne. ATC cleared the aircraft to divert to Melbourne and descend. Following the second surge and subsequent engine failure, the flight crew confirmed the intent to divert to Melbourne. A few minutes later, the flight crew contacted maintenance support, who stated a preference for Melbourne as the diversion target due to better support, but stated that the decision was the aircraft captain’s. Shortly after, the flight crew requested advice on the runway in use in Adelaide, and whether the Adelaide curfew was in force. ATC responded with the runway, and that the curfew would be waived if the flight crew declared an emergency. The flight crew did not respond to this advice.
From the flight crew’s perspective, the following considerations influenced the diversion decision:
The minimum RFFS requirement for a diversion airport was CAT 7.
Adelaide was not preferred due to the curfew and RFFS status being below the required CAT 7 and the flight crew being more familiar with Melbourne.
Melbourne provided the best option due to RFFS and maintenance support.
Due to the close proximity of Adelaide to the intended diversion route, it offered a diversion option should a subsequent emergency require an immediate diversion.
The final decision to divert to Melbourne could be delayed until an equal time point between Melbourne and Adelaide.
The flight crew’s stated belief that the emergency was controlled, which formed the basis for not using Alice Springs.
From an inflight procedural perspective, the diversion following an engine failure required consideration of a number of criteria:
The flight was ETOPS, but the operator advised that ETOPS policy and procedure did not apply, as the aircraft had not yet entered an ETOPS segment.
The OMA required response to an engine failure during normal (non-ETOPS) operations was to divert to the nearest suitable aerodrome. The criteria for a suitable aerodrome included a minimum RFFS of CAT 7.
The OMA required response to a LAND ASAP ECAM message, which was part of the ETOPS procedural section, was to land at the nearest ETOPS suitable aerodrome. The ETOPS suitable aerodrome criteria required a minimum RFFS of CAT 4.
Alice Springs, which was nominated in the operational flight plan (OFP) as an en route alternate, had no RFFS capability during the required period of use, but the operator stated that it meet the adequate aerodrome requirements through municipal fire services that were located off-aerodrome.
Adelaide, which was not nominated as an en route alternate but was listed as a company preferred alternate, had RFFS CAT 5 with the capacity to be CAT 9 with one hour’s notice. Adelaide also had a curfew operating during the flight, but an in-flight emergency was sufficient to override those curfew restrictions.
At the time of the engine failure, the aircraft was within the 60‑minute zone from a company approved adequate en route aerodrome—Alice Springs—and had not entered and ETOPS segment.
OMA stated criteria for determination of whether an aerodrome was suitable for diversion did not include commercial criteria such as availability of maintenance.
The Airbus FCOM definition for an amber LAND ASAP included that the flight crew consider landing at the nearest suitable aerodrome.
At no point during the diversion did the aircraft exit the 60-minute zone from a company approved alternate.
‘ETOPS’/‘Flight’ policy and procedures
The OMA ETOPS policies and procedures section contained statements indicating they applied to the diversion:
The section commenced with a statement that the ETOPS section applied over and above standard operations policy when operating on specified ETOPS routes. The aircraft was operating on an ETOPS route that was authorised by the Malaysian regulator.
The ETOPS definition section stated that ETOPS operations apply to all twin-engine aircraft over a route that contains a point further than 60 minutes flying time from an adequate airport. The aircraft was flying on a route that met this description.
Further, the structure of the ETOPS section—in that it contained policies and procedures that specifically required certain preflight checks, immediate actions post departure, and actions before entry into an ETOPS segment—indicated that these policies and procedures were applicable outside of the ETOPS segment. The ETOPS section contained a requirement to divert to the nearest suitable airport when a LAND ASAP message was displayed. The ETOPS section contained specific criteria for this type of airport. Those criteria included a minimum RFFS of CAT 4. Therefore, under these policies and procedures, the available diversion airports were Alice Springs, Adelaide and Melbourne.
The operator stated that the OMA ETOPS policies and procedures did not apply for the diversion, as the aircraft had not entered an ETOPS segment. Therefore, policies and procedures contained within the OMA ‘Flight procedures’ section applied. Those policies and procedures specifically required diversion to the nearest suitable aerodrome following an engine failure. An engine failure will result in a LAND ASAP message if the engine is not restarted. The criteria for a suitable aerodrome was determined by the ‘Flight planning’ section, which stipulated a minimum RFFS of CAT 7. The operator stated that this could be reduced to CAT 6 on authorisation of the Flight Operations Director. This was the case with Alice Springs. Therefore, under these policies and procedures, the available diversion airports were Alice Springs and Melbourne.
The flight crew stated that the ‘Flight procedures’ minimum RFFS requirement of CAT 7 was the basis of the decision to not use Adelaide. The effect was to limit the airports available for a diversion. That is, a variation in required RFFS CAT for an en route alternate airport available to be used for diversion was based on whether or not the aircraft had passed a specific point in the flight plan—a point that had only a marginal relationship to the actual flight conditions. If an emergency condition enables the flight crew to use an aerodrome with a lower RFFS CAT after passing this point, there is no reason the same RFFS CAT cannot be used before passing that point. The difference is not based in safety.
The safety aspect of the diversion to Melbourne
Both the normal and the ETOPS procedures in the OMA required a diversion to the nearest suitable aerodrome following an engine failure. The captain stated that the decision to bypass Adelaide for Melbourne was based on Adelaide not having the required RFFS, but there was also a commercial advantage cited. Alice Springs was not considered as the emergency was controlled.
Regarding the controlled emergency, shortly after the engine failed the flight crew attempted a restart. That restart failed. The aircraft was then limited to operating on a single engine. While it is argued that ETOPS did not apply in this instance, the development of ETOPS is instructive in considering the safety effect of the loss of an engine on twin turbine-engine aircraft. The increased and increasing reliability of turbine engines has resulted in the capacity of this aircraft type to fly further from an en route airport that is available for use in the event of an engine failure—that is the increasing ETOPS range of these aircraft. The basis for certifying this increasing ETOPS range is the likelihood of a catastrophic result from engine failure—that is the likelihood of a double engine failure. The statistical probability of a double engine failure is materially less than the probability assigned to a catastrophic accident. The point to note, however, is that following an engine failure, the risk to the aircraft is the statistical likelihood of the remaining engine failing. This is an elevated risk in comparison to normal operations. While certification identifies that single engine operations can be achieved out to the limit of the ETOPS range, safety would indicate that the earliest landing is the safest option. As stated in the operator’s OMA, in all cases involving an engine failure the requirement is to land at the nearest suitable airport. Other risk factors can affect this decision; however, commercial considerations are not included.
The nearest suitable airport at the time of the engine failure was Alice Springs. The operator’s internal investigation stated that the diversion did not meet the policy and procedures requirement to divert to the nearest suitable alternate. Communications records and flight crew statement indicate that the flight crew intended to divert to Melbourne from the initiation of the diversion. Alice Springs was available and it nominated in the OFP as an en route alternate airport. Adelaide was a company preferred alternate, and while it was subject to curfew restrictions and RFFS limitations these were not an impediment to its use as a diversion airport. In conclusion, the diversion to Melbourne resulted in an increase in the time that the flight was exposed to the higher risk environment of single engine operations.
The occurrence
At 2137 Eastern Standard Time[1] on 16 August 2016, an AirAsia X Airbus A330-343X,[2] registered 9M-XXD, departed from Sydney, New South Wales. The aircraft was performing the scheduled passenger service XAX221 to Kuala Lumpur, Malaysia. The flight crew consisted of the aircraft captain, who was the pilot monitoring (PM),[3] and the first officer, who was the pilot flying (PF).
The flight’s operational flight plan stated that the flight was an extended range operations (ETOPS) flight,[4] with a ‘maximum diversion time [in the event that one engine failed] in still air limited to 120 minutes’. The operational flight plan listed Alice Springs and Darwin as the only planned Australian ETOPS alternate aerodromes.[5] The first ETOPS operating area was about 400 NM (740 km) outbound from Alice Springs, Northern Territory.
As the aircraft approached Alice Springs (Figure 1), the right engine’s (engine 2) oil pressure pump failed, and shortly thereafter, the engine failed. The aircraft descended and diverted to Melbourne. During the diversion, the flight crew attempted two restarts of the failed engine. The aircraft landed at Melbourne at 0159 on 17 August 2016.
Figure 1: XAX221 flight path
Source: Google earth, modified by ATSB.
The following description of the occurrence will focus on the oil pressure pump failure and subsequent engine failure, the flight crew’s actions, including the diversion decision, and the two restart attempts. Information contained therein is derived from data recorded by the full authority digital engine control systems,[6] data from the flight data recorder, air traffic control recordings and flight crew interviews.
The oil pressure pump failure and subsequent engine failure
As the aircraft was in cruise at flight level[7] (FL) 380 and tracking towards Alice Springs, the engine 2 oil pressure pump failed as a result of the pump’s drive shaft failing, resulting in a rapid and total loss of engine oil pressure. The shaft failure occurred at 2343:20, while the aircraft was 240 NM (445 km) south-east of Alice Springs. Over the subsequent 7 seconds, the aircraft’s flight data recorder (FDR) recorded the engine 2 oil pressure drop from 90 to 0 psi ((1) and green line on Figure 2).
Figure 2: Engine data recorded by the flight data recorder
Legend from bottom: ‘Oil P’ oil pressure; ‘Oil Q’ oil quantity units; ‘Oil T’ oil temperature; ‘TLA’ thrust lever angle; ‘N1’,’N2’, ‘N3’ refer to low-pressure, intermediate-pressure and high-pressure (respectively) engine fan speeds.
Source: ATSB.
While no oil was being fed into the engine as a result of the oil pressure pump shaft failure, the air pressure in the bearing chambers would have forced the residual oil in the chambers down the scavenge lines and back to the tank. This resulted in the indicated oil quantity increasing by about one third ((2) and purple line on Figure 2).
ENG 2 OIL LO PR message
The loss of oil pressure was detected by the electronic centralised aircraft monitor (ECAM). At 2343:33, the ECAM alerted the flight crew by:
triggering the ’master warning’ lights, located on the glareshield panel (Figure 3), and associated aural warning alert
displaying the level 3 red warning alert ‘ENG 2 OIL LO PR’ message and associated emergency procedure on the engine/warning display (Figure 3)
displaying the engine schematics on the system display (Figure 3).
Included within the engine schematics on the system display were the oil system parameters.
In response to the ECAM alert, the captain took over duty as the PF, and at 2343:47, the engine 2 thrust lever was retarded to idle ((3) and blue line on Figure 2). The flight crew reported that, after retarding the thrust lever, the emergency procedure required the flight crew to monitor the engine and to shut the engine down if the problem persisted. While the warning persisted after the thrust lever was retarded, the flight crew stated that all other engine indications were normal. Specifically, while the crew could see that the oil pressure was indicating zero, there was still oil quantity. The flight crew recalled that, as this was the only abnormal indication, they were reluctant to shut engine 2 down. This also led them to believe that the fault might be a false warning from the oil pressure indicator.
The first engine stall
About 3.5 minutes after retarding the thrust lever to idle, at 2347:14, the flight crew advanced the thrust lever for engine 2 to the CL[8] position (see (4) and blue line at Figure 2). The flight crew stated that this was done with the intent of checking/troubleshooting the engine. Approximately 40 seconds later, at 2347:55, engine 2 stalled[9] and began to run down ((5) on Figure 2). In an immediate response to the stall, the engine’s full authority digital engine control[10] (FADEC) briefly cut the fuel flow to the engine, enabling the engine’s airflow to return to normal. The stall was accompanied by a significant spike in recorded engine vibration.
The ECAM detected the stall at 2347:57, and alerted the flight crew by:
triggering the ’master caution’ lights and associated caution aural alert
displaying the level 2 amber ECAM message ‘ENG 2 STALL’ with its associated abnormal procedure on the engine/warning display
displaying the engine schematics on the system display.
The flight crew responded to the ECAM alert by retarding the thrust lever to idle ((6) and blue line on Figure 2). The engine parameters stabilised at an idle setting.
Shortly thereafter, at 2348:02, the flight crew declared a PAN PAN[11] to air traffic control (ATC), stating that they had experienced an engine stall and requesting descent to FL 250. In communications with ATC over the following 30 seconds, the flight crew stated that they were ‘breaking off the airway doing a left turn’ and declared a probable intention to divert to Melbourne.
The second engine stall
At 2348:37, 35 seconds after the first engine stall, the engine stalled again and ran down further ((7) on Figure 2). The second engine stall was also accompanied by a significant spike in the recorded engine vibration. The FADEC again responded by briefly cutting the fuel flow, however, this time the engine did not recover. The engine continued to run down, and failed. The ECAM detected the engine failure and at 2348:42, alerted the flight crew by:
again, triggering the master caution lights and associated caution aural alert
displaying the level 2 amber ‘ENG 2 FAIL’ ECAM message, with its associated abnormal procedure on the engine/warning display
displaying the engine schematics on the system display.
The flight crew responded to the ENG 2 FAIL ECAM alert by commencing the displayed procedure. That procedure included a decision about whether the engine was damaged. The flight crew stated that they consulted the flight manuals and determined that the engine was not damaged. In accordance with the required procedure, the engine master switch was selected to off at 2348:50, shutting the engine down ((8) on Figure 2).
Flight crew’s recollection of the engine stall/failure
The flight crew later reported that, coincident with the stall, they heard a slight bang from engine 2. The flight crew reported that, at the same time, they observed the ENG 2 STALL ECAM message, which was almost immediately replaced by the ENG 2 FAIL message. The ENG 2 FAIL message was coincident with the engine failing.
Actions following the engine failure
The following communications between XAX221 and Melbourne ATC immediately following the second engine stall and subsequent failure were relevant:
At 2353 the flight crew advised ATC that the intention was to divert to Melbourne.
At 2355 ATC re-cleared the aircraft to track direct to position ARBEY[12] and then to Melbourne, and to descend to FL 250.
At 2356 the flight crew called the operator’s maintenance support using Satcom, reporting that engine 2 had been shut down due to low oil pressure followed by an engine stall. The flight crew requested advice regarding the preferred diversion destination for either Adelaide or Melbourne. Maintenance support advised of a preference for Melbourne due to technical support concerns with Adelaide, but that the decision was the aircraft captain’s.
At 2358 ATC requested the flight crew confirm the nature of the situation. The flight crew responded, stating:
…the situation now is we have the number two engine oil, that pressure is zero then [unintelligible]. Then after that is engine stall which we shut down the engine. Then at the moment we are flying on single engine before we are able to double check for engine start, then our decision is to proceed to Melbourne sir.
At 0019 ATC requested the flight crew advise if there was visible damage or evidence of fire. The flight crew reported that there was no damage, just that low oil indication led to an engine stall. In subsequent communications, the flight crew requested advice on the runway in use at Adelaide, and whether Adelaide had a curfew. ATC advised that the curfew in Adelaide was in force, but that if the flight crew declared an emergency the curfew would be waived. The flight crew responded that their intention was to continue to Melbourne. There were no further communications between the flight crew and ATC about Adelaide.
The diversion decision
Relevant company nominated alternate aerodromes available for diversion at the time that the flight crew declared the PAN PAN, and the distance to those aerodromes, were:
Alice Springs, about 205 NM (380 km)
Adelaide, about 545 NM (1,009 km)
Melbourne, about 815 NM (1,509 km).
The captain stated that the initial diversion decision was to go to Melbourne—Alice Springs was closest but discounted as the emergency was considered to be controlled. This decision was based on the understanding that the track took the aircraft close to Adelaide, which would allow for a diversion to Adelaide if conditions deteriorated.
The captain stated that the flight crew then reviewed the decision using the company’s integrated decision-making model. As part of that process, the captain reported that:
in terms of safety, the emergency was controlled and the engine secured
weather at both Adelaide and Melbourne was good, although Melbourne had an indication of moderate turbulence
Adelaide was subject to curfew, but that ATC later advised it was ready to accept the aircraft
rescue and fire fighting services at Adelaide were below that required for the company’s operations
from a passenger wellbeing perspective, Melbourne was preferred
the company had a station in Melbourne, which would enable easier aircraft recovery.
The first officer later stated that Alice Springs was not considered due to the it being an uncontrolled airfield that used pilot activated lighting.[13] The captain reported that the flight crew calculated an equal time point[14] between Adelaide and Melbourne. When the aircraft arrived at this point, they decided to continue to Melbourne for better recovery of the aircraft and passengers. The flight crew also reported there was concern regarding the Melbourne weather forecast due to the turbulence, although this concern was alleviated when later weather updates identified the Melbourne weather as good.
Attempted engine restarts
Two attempts to restart (relight) the failed engine were conducted during the diversion to Melbourne. The flight crew later reported that the intent to relight the failed engine was based on the ‘engine fail’ (ENG FAIL) procedure, which instructed the flight crew to consider a relight provided the engine was not damaged. The flight crew reported that, after working through the quick reference handbook and flight crew operating manual, they determined that the engine was not damaged.
At 0002:14 on 17 August, about 13 minutes after shutting the engine down, the flight crew attempted to relight engine 2. The following engine parameters were recorded immediately preceding the relight attempt:
N1[15] was indicating a stable 23 per cent rotation
N2 was indicating a stable 7 per cent rotation
N3 was indicating 0 per cent rotation.
The relight attempt commenced when the engine master switch was selected to ON at 0002:15, and ceased at 0003:38 when the switch was selected to OFF. During the relight attempt, the aircraft was slowly descending from FL 239 to FL 232 with the airspeed slowly increasing from 258 kt to 280 kt. The attempted relight was unsuccessful. During the relight attempt, the ‘ENG 2 START FAULT’ ECAM message was displayed.
At 0132:00, just before commencing descent into Melbourne, a second relight was attempted by the flight crew. During this relight attempt, the aircraft was at FL 190 and the airspeed about 315 kt. The following engine parameters were recorded immediately before the relight attempt commenced:
N1 was stable at about 25 per cent rotation
N2 stable at about 6 per cent rotation
N3 stable at 0 per cent rotation.
The flight data identified that both relight attempts were starter motor assisted relights. For the second relight, there was a 13 second delay from the initiation of the relight until the first indication of rotation of N3. A further 12 seconds later, at 0132:25, N3 achieved sufficient rotation for fuel to be introduced into the engine. At this time, N1 remained at 25 per cent, N2 had increased to 12 per cent and N3 had increased to 25 per cent. At 0132:36 a successful relight occurred, however, N1 remained at 25 per cent, N2 had increased to about 22 per cent, and N3 had stabilised at about 43 per cent. The flight crew later reported that, during the relight, vibrations were felt from the engine. As a result of this vibration, at 0132:46, the flight crew ceased the relight attempt and shut down engine 2.
The sources of information during the investigation included:
the flight crew
AirAsia X
Airbus Industrie
Rolls-Royce
Civil Aviation Safety Authority (CASA)
Civil Aviation Authority Malaysia (CAAM)
Airservices Australia
Air Accident Investigation Bureau, Malaysia (AAIB MY)
Bureau d'Enquêtes et d'Analyses pour la Sécurité de l'Aviation Civile (BEA)
Air Accident Investigations Branch, United Kingdom (AAIB UK).
References
AeroSpace, A.S.D., 2013. Defence Industries Association of Europe. Simplified Technical English, Specification ASD-STE100, (6).
Airbus. 2007, ‘Compliance to Operational Procedures – Why do well trained and experienced pilots not always follow procedures?’, Safety First, Issue #05 December 2007, pp. 20-23.
Burian B.K., Barshi I., and Dismukes K., 2005, The challenge of aviation emergency and abnormal situations, NASA report (213462), Moffett Field.
International Civil Aviation Organization (ICAO) 2018, Document 9859 Safety Management Manual¸ 4th Ed (advanced unedited), ICAO, Montreal.
Li, Y. and Guldenmund, F.W., 2018. Safety management systems: A broad overview of the literature. Safety Science, 103, pp.94-123.
Orasanu, J., 2010, ‘Flight crew decision-making’, in Kani, B., Helmreich, R., Anca, J. (eds), Crew resource management, 2nd Ed, Academic Press, San Diego.
Reason J., 1990, Human error, Cambridge University Press, Cambridge.
Reason, J.T., Carthey, J. and De Leval, M.R., 2001. Diagnosing “vulnerable system syndrome”: an essential prerequisite to effective risk management. BMJ Quality & Safety, 10(suppl 2), pp.ii21-ii25.
Wickens and Hollands (2000). Engineering psychology and human performance. (3rd edn). New Jersey: Prentice-Hall.
Woods, D.D. and Patterson E.S., 2001, ‘How unexpected events produce an escalation of cognitive and coordinative demands’, in Hancock P.A. and Desmond P.A. (Eds), 2000, Stress, Workload and Fatigue, Lawrence Erlbaum Associates, Hillsdale, NJ.
Submissions
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the flight crew, AirAsia X, Airbus, Rolls-Royce, CASA, CAAM, AAIB MY, AAIB UK, and BEA.
Submissions were received from AirAsia X, CAAM, AAIB MY, Rolls-Royce, Airbus, BEA and CASA. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 9 August 2016, at about 1310 Eastern Standard Time (EST), a Cessna A188B aircraft, registered VH-BCT (BCT), taxied to depart from a private strip near Hay Airport, New South Wales to complete a run to spread fertiliser on the property. The pilot was the only person on board the aerial agriculture operation.
The pilot had already completed two spreading runs, for the field being treated, and on each occasion, the pilot took-off and banked the aircraft to the right, and then banked to the left to align with the field. During the third take-off, the pilot noticed a vehicle traveling along a road at the beginning of the spreading run for that field. The pilot climbed the aircraft to about 200 ft and commenced an orbit to allow the vehicle to move out of the way (Figure 1).
Figure 1: Map showing the location of the landing area, field to be treated and the aircraft flight path
Source: Google earth, modified by the ATSB
During the 30-degree turn to the left, the aircraft started an aerodynamic buffet.[1] The pilot moved the engine controls to full power but did not notice a difference in engine noise or a change in the aircraft performance. At the same time, the pilot levelled the aircraft wings, lowered the nose to increase speed and as there was no change in the performance, they began jettisoning the load. Due to the load type, the pilot had to jettison the load slowly so as not to block the spreader. The pilot elected to return to the airstrip to check the operation of the engine and commenced a gentle turn to the left. The aircraft continued to buffet and the altitude continued to decrease, despite having full engine power selected and the load being jettisoned. The pilot continued to lower the nose of the aircraft and when it became evident that the aircraft was not going to make the strip, the pilot elected to land straight ahead. As the aircraft flew over a channel, the tail wheel clipped that channel, and the aircraft collided with the ground on the flat area between two channels. The landing gear and propeller detached as the aircraft continued forward and came to rest on the top of the opposite channel. As there was a lot of fuel leaking from the fuel tanks, the pilot quickly turned off the engine magnetos and the electrical master switch and exited the aircraft through the cockpit door. The pilot was uninjured and the aircraft was substantially damaged (Figure 2).
Figure 2: BCT at the accident site
Source: Aircraft owner
Pilot comment
The pilot indicated that the wind was steady throughout the day, 12 to 15 knots gusting to 20 and from a northerly direction.
The pilot commented that the engine was not performing how it had been on the previous 17 flights that day. They also reported that at about 200 ft, there was little time from when the problem was first noticed to when the aircraft landed. The pilot reported expecting an instant response when full power was applied, a change in engine noise, and the aircraft should have gained airspeed and continued flying like had happened on previous turns.
The pilot indicated that the aerodynamic buffet occurs frequently during the spreading of fertiliser and occurs well above an aerodynamic stall. It indicates that the aircraft is getting slow and to ease off the pressure on the control column and increase engine power. The pilot reported that the aircraft maintained an aerodynamic buffet all the way to the ground.
The pilot indicated that the aircraft’s seat restraint was a 4-point harness and that they had locked the inertia reel system for the flight and it had worked well. The pilot was wearing a helmet at the time of the accident.
The aircraft was refuelled the night before the accident at Hay Airport and again from fuel drums about 20 minutes flight time prior to the accident. The pilot completed fuel drains on the aircraft and the drum pump and did not notice any issues. The pilot checked the fuel from the drums after the accident and found no contamination. Another aircraft completed the spreading job the day of the accident and also used the fuel from the drums and had no issues.
Operator comment
The aircraft operator conducted an investigation and identified the following:
The pilot had completed 17 similar flights that day, prior to the accident flight.
During the turn, the pilot allowed the aircraft speed to diminish and they did not have the height to recover.
The aircraft was loaded with about 600 kg fertiliser and about 130 litres of fuel. The aircraft engine and propeller had been modified from a Continental IO-520 engine to a Continental IO‑550 engine with a three bladed constant speed propeller.
A licensed aircraft maintenance engineer inspected the engine and no reason was identified for an engine power loss. The engine magnetos and engine carburettor were tested separately and found to be operating normally. As such, the operator believed the engine was still producing full power at the time of the accident. The engine and propeller were extensively damaged by the accident sequence (Figure 3).
The pilot had about 1,927 flight hours in the Cessna 188 conducting top dressing operations. In the last 12 months, the pilot had predominately flown an Air Tractor AT-502 turbo propeller aircraft and more recently had flown about 40 flight hours in the Cessna 188. Unlike the AT-502, there is very little difference between working power and full power in the Cessna 188. This may have resulted in the pilot having an over expectation of the aircraft performance especially when fitted with a spreader.
The aircraft was also fitted with vortex generators[3] that allowed the aircraft to have a lower stall speed than the published stall speed. However, when the stall is reached there is considerable more speed required to resume normal flight and also more height loss to regain that speed at the working height of 150 to 250 ft. With the aircraft fully loaded, the pilot would not have enough height to regain enough speed to recover.
Another company pilot was also flying about 74 km south of the accident site, in a different aircraft type. They experienced down drafts, 20 knot winds, and a downgrade of performance in the downwind turns. With the increase of engine power, the effect of a downwind turn was negated.
Safety analysis
During a turn, the pilot allowed the speed to decrease and the aircraft started a buffet like an approaching aerodynamic stall. The pilot lowered the nose of the aircraft to increase the speed, levelled the wings, selected full engine power and started jettisoning the load. The pilot continued to lower the nose of the aircraft in in an attempted to regain control of the aircraft until it collided with the ground. With the vortex generators, the full load, and the minimal difference between working and full engine power, there was not enough height to recover the aircraft.
Although the pilot believed the aircraft engine was not performing as well as it had in previous flights there was no indications of this before the turn. No problems were identified with the engine after the accident, however, it had been extensively damaged during the accident sequence. The engine’s inability to counteract the effect of the buffeting during the turn (as the aircraft was fully loaded and minimal additional power was available above normal operating power), possibly also influenced by the pilot’s recent experience with a more powerful aircraft, may have influenced this belief.
Findings
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
During a turn, at a slow speed the aircraft started to buffet like approaching an aerodynamic stall. Due to the vortex generators, full load and insufficient engine power available, there was not enough height for the pilot to regain control of the aircraft before it collided with the ground.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Aircraft operator
As a result of this occurrence, the aircraft operator has advised the ATSB that they are taking the following safety actions:
The pilot has undergone refresher training on the effects of the wind on a downwind turn and flight training in windy conditions with reference to the airspeed and lighter aircraft weights.
Safety message
In this accident, the time available to manage the degradation of the aircraft performance meant that there were little options in regards to a landing area. The accident highlights the importance of taking positive action and maintaining aircraft control in both turning back to the strip or conducting a forced landing, while being aware of flare energy and aircraft stall speeds.
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 9 August 2016 at about 2020 Central Standard Time (CST), a Raytheon B200 aircraft, registered VH‑ZCJ (ZCJ), departed from Darwin Airport, Northern Territory (NT), to collect a patient from Tindal Airport, NT, for transfer to Darwin. On board the flight from Darwin were the pilot and one flight nurse.
As the flight approached Tindal Airport, the pilot checked the Tindal ATIS[1] which stated that runway 14 was not available. There was no NOTAM[2] to indicate that was the case, so the pilot contacted Brisbane Centre air traffic control (ATC) to confirm the status of Tindal Airport. Brisbane Centre ATC advised the pilot there was an earlier incident at Tindal that was now cleared and runway 14 would be available for their arrival. The aircraft landed on runway 14 with Tindal ATC still active, at about 2120, then back-tracked runway 14 and parked at the terminal for the patient collection.
The patient was loaded on board ZCJ at about 2250. At about 2300, the Tindal ATC tower closed and procedures for operating at non-controlled aerodromes then applied. The pilot taxied ZCJ for departure at 2309. They entered runway 14 from taxiway echo (Figure 1), lined up for departure ensuring they used the entire runway length available and applied power. At about 70 kt, the pilot performed their ‘cross check of airspeed indicators’. At this time there were no warning indications, so the pilot committed to continue the take-off.
At about 85–87 kt, the pilot felt the aircraft nose wheel strike something on the runway with an associated vibration through the rudder pedals. The pilot checked the airspeed, observed the aircraft was continuing to accelerate and there was no change in directional control, so they rotated the aircraft at the lift-off speed of 94 kt.
After departure, the pilot contacted the Tindal Airport emergency services and asked them to inspect the runway to check on the status of the aircraft arrestor cable (refer to Aircraft Arrestor System and Enroute Supplement Australia). The emergency services inspected the runway and advised the pilot that the arrestor cable was in the raised position, and that they would immediately report this to the Tindal Airport cable barrier crew for rectification.
The pilot continued the flight to Darwin and enroute contacted their company chief pilot to report the incident and discuss options for the management of the landing at Darwin. They also discussed the management of the patient in the event of a landing incident or accident. The chief pilot, in turn, contacted one of the company check and training captains, and notified Darwin ATC. On approach to Darwin, the pilot consulted the checklist for landing with an unsafe landing gear. When they extended the landing gear, there were no unsafe indications, so the pilot considered a blown tyre was the most credible risk for the landing.
The chief pilot then advised the pilot that Darwin ATC had activated their emergency response for the landing. They also suggested that the nurse look outside the cabin windows for any visual indications of damage. The nurse could not see any indications of damage. The pilot conducted their approach and landed at Darwin Airport without further incident. The aircraft was not damaged and there were no injuries.
Aircraft Arrestor System
The Tindal Airport aircraft arrestor system (AAS) is used to stop military jets that have a malfunction, which may otherwise cause them to overrun the runway. In this case, the jet will lower a hook at the rear of the aircraft to catch the cable. The AAS includes two cables, one positioned at either end of the runway and displaced from the respective threshold as displayed on the airport diagram of runway 14 (Figure 1).
Figure 1: Tindal airport apron diagram
Source: Airservices, annotated by ATSB
The AAS may be controlled by ATC from the Tindal ATC tower through each cable’s control console, or by the AAS barrier crew from the runway site control location. Each location control console feeds into the hook cable control module, which manages the cable position logic (Figure 2). When ATC is active the control of the system is with the Tindal ATC tower. When the tower closes, ATC select the AAS controller to ‘maintenance’, which switches the control to the runway site control location.
There are four pushbutton selection/indicator lights on the tower control consoles (Figure 2). They comprise two green UP and DOWN pushbuttons, an amber maintenance pushbutton and a red fail pushbutton. The maintenance pushbutton is used to pass AAS control between the tower and runway site control location.
When AAS control is passed to the runway site control, the amber maintenance pushbutton will illuminate to indicate the runway site have control of the AAS. The red fail pushbutton will also flash, and be accompanied by an audible clicking. This is a warning to the tower controllers that they do not have control of the AAS. The warning is cancelled by manually depressing the fail pushbutton. In maintenance control, the tower console UP and DOWN pushbuttons are indicator lights only, which will respond to cable position changes made at the runway location.
Figure 2: Tower control console cable pushbuttons
Source: Tindal Airport
The runway site control has a physical switch, which is selected to either the UP or DOWN position. When control of the cable is passed from the tower to the runway site control, the hook cable control module will command the cable into the position selected on the runway site control switch.
When an aircraft is arrested with the AAS, the barrier crew take control of the AAS from ATC until the aircraft is released and the inspection and servicing of the cable completed. On completion of the cable servicing, the barrier crew lower the cable using the site control switch before passing control of the AAS back to ATC.
On 9 August 2016, at about 2045 CST, the runway 14 AAS was used to stop a military jet. The barrier crew then entered the runway and performed the servicing and reset of the cable. This task required the control of the AAS to be passed from the tower to the runway site control. The servicing and reset also required the cable to be cycled between the UP and DOWN positions. On completion of the reset the barrier crew passed AAS control back to the tower with the runway site control switch selected in the UP position. This deviated from the barrier crew’s normal procedures, which required them to lower the cable into the DOWN position before passing control back to the tower.
Tindal ATC did not notice the discrepancy with the handover. They cycled the cable to check serviceability, then continued with normal cable operation for the remainder of ATC services. The cable was in the DOWN position for the arrival of ZCJ. When the Tindal ATC tower closed at 2300, the controller closing the tower performed the procedural steps, which included (1) ensuring the cable is set to DOWN on their control console, and (2) once confirmed DOWN, select AAS control to maintenance. The ATC procedural steps did not include checking the position of the cable after the maintenance selection.
There are no differences in the maintenance and fail pushbutton light indications if the cable changes position after control is passed to maintenance. However, the DOWN pushbutton green light would extinguish after about one second and the UP pushbutton green light would illuminate after about 10–15 seconds.
When the airport emergency services inspected the cable at 2320 they found the cable raised and contacted the barrier crew supervisor. The supervisor inspected the runway site control location and found the switch selected to the UP position.
Enroute Supplement Australia
The Enroute Supplement Australia entry for Tindal airport includes the following information:
Physical characteristics: Recessed bi-directional hookcables installed 1,266 ft from threshold runway 14 and 1,515 ft from threshold runway 32… Distance between cables 6,214 ft… No arrestable aircraft operations or outside tower hours – both ends down. No crossing restrictions in down position... In the event of power failure, cables will rise to a height of 10 cm until [power] restored – recommended that aircraft not approved to trample hookcables confine operations to between cables during CTAF.
Enroute Supplement Australia introduction paragraph 22.2 b. states:
Pilots should refer to the Pilot Operating Handbook of Flight Manual for specific restrictions for each aircraft. In the absence of any reference to trampling in either the Handbook or Manual, trampling is not authorised.
Company procedures for Aircraft Arrestor System
The pilot was unaware of any previous incident or discussion within the company regarding the AAS at Tindal Airport. There is no reference to trampling hook cables in their B200 flight manual and therefore no trample speed approved for the aircraft. The company did not have a procedure in place to require their pilots to avoid the runway length which incorporates the AAS when non-controlled aerodrome procedures apply.
ATSB comment
The ATSB notes that although there was sufficient runway for the pilot to stop the aircraft after trampling the cable, they were already passed their ’airspeed indicator cross check’. After this point, the pilot was mentally committed to continue the take-off and only to abort the take-off for a cockpit warning light.
It is likely that when the Tindal Airport tower closed and passed AAS control to maintenance, the runway 14 threshold AAS cable raised into the UP position in response to the existing site control switch selection, and this was not detected by ATC during the tower closing procedure.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Airport operator
As a result of this occurrence, the airport operator has advised the ATSB that they are taking the following safety actions:
Training
The training for barrier crew is to be reviewed to ensure the runway switch is set to DOWN during hand-over procedures. A maintenance assurance inspection is to be investigated for the purpose of verification of switch position within the hand-over procedure.
ATC training is to be reviewed to ensure indication of DOWN position after hook cable is switched to maintenance position.
Aircraft operator
As a result of this occurrence, the aircraft operator has advised the ATSB that they are taking the following safety actions:
Operations notice
The company has issued an operations notice to their flight crew to advise them of the incident and instruct them that if the pilot in command cannot be assured of the cable status, to taxi past the cable prior to take-off, or land long to avoid it on arrival.
Training
The company’s pilot training syllabus relating to potential hazards associated with operating at military aerodromes was updated to include arrestor cables.
Safety message
While the outcome of this incident was benign, the actions of the pilot demonstrated how crew resource management skills can be employed to engage assistance from outside the aircraft to effectively manage an unexpected risk. Their decision to contact Tindal Airport emergency services mitigated a potential risk to other operators before the tower re-opened.
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 9 August 2016, at about 0930 Western Standard Time, a Cessna 210N aircraft, registered VH-NLV (NLV), departed Kununurra Airport for a scenic charter flight to Mitchell Plateau aircraft landing area (ALA), Western Australia (WA), with a pilot and five passengers on board.
Shortly before 1100, the pilot of NLV tracked for a straight-in approach to runway 06 at Mitchell Plateau ALA.
At that time, the pilot of a Gippsland Aeronautics GA-8 aircraft, registered VH-BFL (BFL), prepared to taxi at Mitchell Plateau ALA, for a scenic charter flight to Kalumburu, WA, with four passengers on board.
When about 5 NM from the ALA, the pilot of NLV broadcast on the CTAF, advising they were on a 5-mile final for runway 06 at Mitchell Plateau, and did not receive a response.
The pilot of BFL reported that they broadcast a taxi call, a call prior to entering runway 16/34 to taxi to runway 06 and prior to entering runway 06. The pilot inadvertently made those broadcasts company frequency instead of CTAF.
When at about 1 NM on final approach to runway 06, the pilot of NLV broadcast again on the CTAF and did not receive a response.
As the pilot of NLV flared the aircraft for landing, they sighted BFL taxi onto runway 06. After landing, the pilot of NLV braked more heavily than normal and moved to the left of the runway to increase the separation between the two aircraft.
As BFL entered runway 06, the pilot sighted NLV in the landing roll and also moved to their left. The pilots assessed that the aircraft passed within 2 m of each other at taxi speed and neither aircraft moved outside the runway strip. The aircraft were not damaged and no injuries were sustained.
Pilots are encouraged to prioritise their attention carefully and appropriately as they near non-towered aerodromes. An effective lookout for other aircraft, supported by communication with traffic in the vicinity, should be a high priority.
On 9 August 2016, at about 0930 Western Standard Time (WST), a Cessna 210N aircraft, registered VH-NLV (NLV), departed Kununurra Airport for a scenic charter flight to Mitchell Plateau aircraft landing area (ALA), Western Australia (WA), with a pilot and five passengers on board.
Shortly before 1100, after completing orbits overhead Mitchell Falls, about 9 NM south-west of Mitchell Plateau ALA, the pilot of NLV positioned the aircraft to track for a straight-in approach to runway 06 at Mitchell Plateau ALA (Figure 1).
Figure 1: Mitchell Plateau ALA showing approximate aircraft tracks
Source: Google earth – annotated by ATSB
At that time, the pilot of a Gippsland Aeronautics GA-8 aircraft, registered VH-BFL (BFL), prepared to taxi at Mitchell Plateau ALA, for a scenic charter flight to Kalumburu, WA, with four passengers on board. Prior to taxiing, the pilot of BFL selected a company frequency on the aircraft’s radio and communicated with the pilot of another aircraft. After that communication, the pilot pressed the radio’s frequency select button in an attempt to switch to the North Kimberley common traffic advisory frequency (CTAF). However, the pilot did not detect at that time that the CTAF had not been selected and the radio remained tuned to the company frequency.
When about 5 NM from the ALA, the pilot of NLV broadcast on the CTAF, advising they were on a 5-mile final for runway 06 at Mitchell Plateau, and did not receive a response. When about 3 NM from the runway, the pilot of NLV sighted an aircraft (BFL) on the parking bay at the ALA, with the beacon on, indicating that the aircraft’s engine was running.
The pilot of BFL reported that they broadcast a taxi call and a call advising that BFL was entering runway 16/34 to taxi to runway 06, and subsequently broadcast prior to entering runway 06 to backtrack to the runway threshold. The pilot inadvertently made those broadcasts company frequency instead of CTAF and did not receive any response.
When at about 1 NM on final approach to runway 06, the pilot of NLV broadcast again on the CTAF and did not receive a response. From the aircraft’s position, the parking bay and adjacent taxiway were obscured by a line of trees, and the pilot was unable to see BFL.
As the pilot of NLV flared the aircraft for landing, they sighted BFL turn left and taxi onto runway 06. The pilot of NLV assessed that if they conducted a go-around the aircraft may be unable to climb fast enough to avoid the aircraft on the runway and could not diverge from the runway direction due to the trees beside the runway, therefore the pilot elected to land. After landing, the pilot of NLV braked more heavily than normal and moved to the left of the runway to increase the separation between the two aircraft.
As BFL entered runway 06 to backtrack, the pilot sighted NLV in the landing roll and also moved to their left. The pilots assessed that the aircraft passed within 2 m of each other at taxi speed and neither aircraft moved outside the runway strip. The aircraft were not damaged, and no injuries were sustained.
Pilot comments
Pilot of VH-NLV
The pilot of NLV commented that during the flare, they considered conducting a go-around, but assessed that due to the high outside temperature, the aircraft may not have adequate climb performance to pass at a safe height above BFL.
Pilot of VH-BFL
The pilot of BFL had been in the airport terminal for about 2 hours before the incident. They commented that as the CTAF covered a large area, normally they would have very good awareness of other aircraft operating there. As they had not been listening to the radio during the time in the terminal, they were not aware of NLV. The pilot recalled looking for aircraft as they taxied onto runway 06, but did not see NLV.
The pilot also commented that due to a delay on the ground, they were keen to get away, and that may have contributed to not noticing that the radio was still on the company frequency.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following safety action in response to this occurrence.
Operator of VH-BFL
As a result of this occurrence, the operator of BFL has advised the ATSB that they are taking the following safety actions:
Flight crew briefing
The operator is proposing the following briefing for new flight crew regarding radio procedures:
mentally confirm the required frequency
visually confirm the required frequency is set as active, and the correct COM is selected on the audio panel
aurally check by activating the squelch.
In addition, company pilots will be reminded to be mindful of the impact that stress (such as that due to delays) can have on their performance, to recognise the signs and symptoms of stress, and to return to the basics of good airmanship if/when they find themselves under stress and pressure.
Safety message
The ATSB SafetyWatch highlights the broad safety concerns that come out of our investigation findings and from the occurrence data reported to us by industry. One of the safety concerns is safety around non-towered aerodromes.
Pilots are encouraged to prioritise their attention carefully and appropriately as they near non-towered aerodromes. An effective lookout for other aircraft, supported by communication with traffic in the vicinity, should be a high priority.
The ATSB report Limitations of the See-and-Avoid Principle outlines the major factors that limit the effectiveness of un-alerted see-and-avoid. Insufficient communication between pilots operating in the same area is the most common cause of safety incidents near non-controlled aerodromes.
Most occurrences reported to the ATSB at non-towered aerodromes involve conflicts between aircraft, or between aircraft and ground vehicles. In particular, active runways should be approached with caution. The ATSB publication A pilot’s guide to staying safe in the vicinity of non-towered aerodromes, stated that a large number of the conflicts between aircraft involved:
ineffective communication between pilots operating in close proximity
the incorrect assessment of other aircraft’s positions and intentions
relying on the radio as a substitute for an effective visual lookout
failure to follow published procedures.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 23 May 2016 at about 0700 Western Standard Time, a team of ground and flight crew commenced sling operations to move a drill rig and associated platform and equipment by helicopter to a new location on a salt lake at Lake Disappointment, Western Australia.
The ground team for the removal of the equipment consisted of a load master and a driller’s offsider. The pilot of an Aerospatiale Industries AS350 helicopter, registered VH-BII, worked with the ground crew to move three mats and a power pack to a new site, before returning to move the rig. The load master and offsider attached the rig to the hook under the helicopter and attached two tag lines – 6 m loop slings, to the load on separate corners. At about 1040, in readiness to lift the rig, the load master advised the pilot using hand signals that the load was attached and that they were clear and ready for the lift.
The helicopter climbed and the rig lifted a few centimetres above the ground. The load swivelled as it lifted off the ground, and pushed against a PVC pipe protruding from a bore hole. The load master and offsider stepped in closer to manoeuvre the rig clear of the pipe.
The pilot observed the ground crew then step away from the rig. As they stepped back, the offsider had inadvertently stepped into the loop of the tag line. As the helicopter lifted the rig, the tag line went taught, and the offsider’s leg was ensnared in the loop. The offsider was lifted off the ground by the leg and the helicopter began lifting the load. The load master radioed the pilot, and advised that the offsider was hanging in the loop.
The helicopter was then about 50–60 ft above the salt lake. The pilot turned the helicopter around to return to the pad and descended to about 15–20 ft above the ground. The pilot also slowed the helicopter as much as possible given the load and the tailwind, to a groundspeed of about 25 kt.
The offsider then freed their leg and was about to jump off, but the helicopter then started to climb and accelerate. The offsider therefore released the tag line and dropped about 10 m into the mud below. The offsider sustained a serious injury.
This incident highlights the importance of conducting a thorough risk analysis prior to commencing operations. The risk assessment should clearly identify hazards and introduce measures that mitigate any associated risks.
On 23 May 2016 at about 0600 Western Standard Time (WST), a team of ground and flight crew met to discuss the day’s operations to move a drill rig and associated platform and equipment by helicopter to a new location at Lake Disappointment, Western Australia (Figure 1). The rig had been operating on a salt lake and the move involved two helicopters – an Aerospatiale Industries AS350 helicopter, registered VH-BII (BII), to move the rig and heavier equipment, and a smaller helicopter (Robinson R44) to move the smaller, lighter equipment and personnel.
Figure 1: Drilling rig on Lake Disappointment
Source: Ground crew operator
The pilot of BII suggested that the ground crew use tag lines for the operation. These would enable the ground crew to manoeuvre the loads as necessary while the load was off the ground slung under the helicopter. For tag lines, the pilot provided the ground crew with slings – 6 m loops (Figure 2), which they were to attach to the loads that were already encased in other slings ready for moving.
The ground team for the removal of the equipment, consisted of a load master and a driller’s offsider. The driller’s offsider involved in the operation was new to the role. For the operation, the offisider’s role included ground support and to sling equipment under the guidance of the load master. The load master was to guide the helicopter using hand signals and a two-way radio to communicate with the helicopter pilot.
Figure 2: Loop slings
Source: Operator of VH-BII
At about 0700, the pilot of BII commenced sling operations. The pilot worked with the ground crew to move three mats (weighing 550 kg each) and a power pack (770 kg) to a new site, before returning to move the rig (about 700 kg). The pilot positioned the helicopter into wind. The load master and offsider attached the rig to the hook under the helicopter using the slings around the load and four attachment points. They attached two tag lines to the load on separate corners. At about 1040, in readiness to lift the rig, the load master advised the pilot using hand signals that the load was attached and that they were clear and ready for the lift.
The pilot commenced lifting the rig. The helicopter climbed and the rig lifted a few centimetres above the ground. The load swivelled as it lifted off the ground, and pushed against a PVC pipe protruding from a bore hole. The load master and offsider stepped in closer to guide the rig. The load master pushed the rig while the offsider pulled on the tag line to manoeuvre the rig clear of the pipe.
The pilot looked down through a window in the floor of the helicopter beside the seat and observed the ground crew then step away from the rig. The pilot then shifted their attention inside the cockpit to the instruments to monitor power settings and continued with the lift.
As they[1] stepped back, the offsider had inadvertently stepped into the loop of the tag line. As the helicopter lifted the rig, the tag line went taught, and the offsider’s leg was ensnared in the loop. The offsider was lifted off the ground by the leg and the helicopter began lifting the load. The load master radioed the pilot, and advised that the offsider was hanging in the loop.
By the time the pilot became aware that the offsider was caught in the loop, the helicopter was about 50–60 ft above the salt lake. The pilot turned the helicopter around to return to the pad and encountered a tailwind of 8–10 kt. The helicopter overflew mud flats and the pilot descended as low as they felt was safe, which was about 15–20 ft above the ground. The pilot also slowed the helicopter as much as possible given the load and the tailwind, to a groundspeed of about 25 kt.
The offsider then freed their leg and was about to jump off from about 2 m above the ground, but reported that the helicopter then started to climb and accelerate. Now only holding on by their hands, the offsider was concerned that they would not be able to hold on much longer if the helicopter sped up, and that they risked injury from falling further as the helicopter climbed. The offsider therefore released the tag line and dropped into the mud below. The offsider estimated they were about 10 m above the ground when they let go.
The load master ran to assist the offsider. The pilot saw the offsider land in the mud and flew the helicopter to an island nearby and put the rig down. The pilot of the R44 helicopter working on the site picked up the offsider, who was then taken for medical assessment. The offsider sustained a serious injury.
Pilot comments
The pilot later commented that, having become aware that the offsider was ensnared, they had no intention of putting the rig down while the offsider was hanging underneath. The pilot intended to turn the helicopter back around into wind to slow the helicopter sufficiently for the offisider to release themselves back onto the ground, at the pad where they had lifted off.
The ground crew had cautioned each other to be careful of the loop. But with the noise and downwash of the helicopter, watching the rig taking off, and the tag line hanging 4-5 m after the load, the offsider was ensnared.
In future, if a ground crewmember became trapped in a line, the pilot would remain in radio contact with the load master and would not put the load down. They would return as quickly as possible to the site so the load master could assist with the safe release of the offsider.
Driller’s offsider comments
The offsider commented that once they were slung under the helicopter there was no way they could communicate with the pilot or the load master. The offsider did not have a radio. The helicopter was then about 100 m from the pad and too far away to be able to hear or communicate with the load master. Although there was a small window in the floor of the helicopter, the pilot would not have been able to see the offsider hanging as they were below the rig.
The offsider further commented that it was important for the load master, or person in radio communication with the pilot, to ensure all ground personnel were a safe distance from the helicopter before giving the pilot the all clear to lift.
The offsider also commented that use of a sling as a tag line carries increased risk of ensarement. A single or unlooped line would be less hazardous.
Ground crew operations company report
The ground crew operations company conducted an investigation into the incident and identified three contributing factors:
Tag lines to loads were introduced without an associated risk assessment.
The offsider was a new employee and was not fully aware of the hazards.
The load shifted in an unexpected direction, resulting in the ground crew moving back in towards the rig after the load master had given the all clear.
Helicopter operator report
The helicopter operator conducted an investigation into the incident and included the following conclusions:
The pilot was appropriately qualified, current and proficient.
The format of the ground crew briefing did not, nor was it required to, include an entanglement response in emergency procedures.
Tag lines were new equipment on the project and were introduced without a formal risk assessment. There were no formal procedures for the use of tag lines and the risk of entanglement was not identified at the time. The 6 metre loops usually used for lifting loads were not standard tag lines.
Some improvements could be made with better communication between pilot and ground crew which may require additional training or practice. This may have been a factor in this incident.
The pilot met the procedural take-off requirement visually ensuring they were clear of the load before lifting started, however, procedures do not identify risk aspects of multiple ground crew operations nor do they take into account the high workload of the pilot at time of lift.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following safety action in response to this occurrence.
Ground crew operations
As a result of this occurrence, the ground crew operations company has advised the ATSB that they have taken the following safety actions:
people carrying out slinging operations are to use more appropriate tag lines – 16 mm single strand synthetic rope[2]
helicopter pilot to visually confirm the load is not entangled prior to moving off
job hazard analysis to incorporate the use of tag lines
safe working procedures to take into account visual confirmation that the load is clear
promotion of ‘take 5 culture’[4] to address hazards as they are identified
platform scales to weigh rig items have been provided, sling line certification has been conducted and routine condition inspections have been conducted
UHF radios have been installed.
Helicopter operator
As a result of this occurrence, the operator of BII has advised the ATSB that they have taken the following safety actions:
Enhanced briefing implemented for client ground crew which includes potential of entanglement and preventative measures as well as roles when there are more than one ground crew member.
A risk profile has been completed for tag line use.
Clients are provided with a personal protective equipment list for their personnel involved with ground operations.
Safety message
This incident highlights the importance of conducting a thorough risk analysis prior to commencing operations. The risk assessment should clearly identify hazards and introduce measures that mitigate any associated risks. In addition, it is important to consider possible emergency scenarios and develop procedures to follow in the event of an abnormal situation developing.
Appropriate training is essential for personnel working in complex operations. In addition to individual roles and skills, training should include how team members work together to maintain and improve safety. Part of working together safely involves effective communication and a mutual understanding of phrases and signals.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On the evening of 6 August 2016, Jetstar Airways flight JQ12, a Boeing 787 aircraft, registered VH‑VKK, departed from Tokyo, Japan on a scheduled passenger transport flight to the Gold Coast, Queensland. On board the aircraft were two flight crew, nine cabin crew and 309 passengers.
The aircraft was pushed back from the gate at Narita Airport, Tokyo, at 1133 UTC. About two and a half hours into the flight, cruising at FL 400, the flight crew were alerted to low engine oil pressure in the right engine. The flight crew performed the checklist actions, which led to shutting down the right engine. The captain identified Guam Airport as the nearest suitable airport, about 370 km to the south of their position. They descended the aircraft to FL 220 due to single engine performance limitations and diverted around some weather as they tracked towards Guam Airport. The captain reported that they made an uneventful one engine landing on runway 24 at about 1520 UTC.
On inspection, the right engine transfer gearbox was found to be fractured, which was the source of the loss of oil from the engine.
This incident highlights the importance of flight crew complying with checklist actions when dealing with a fault condition. Inflight, the crew did not have knowledge of the extent of the damage to the engine transfer gearbox. However, by following their training and checklist procedures, they reduced the risk of a potential escalation of the fault.
On the evening of 6 August 2016, Jetstar Airways flight JQ12, a Boeing 787 aircraft, registered VH-VKK, departed from Tokyo, Japan on a scheduled passenger transport flight to the Gold Coast, Queensland. On board the aircraft were two flight crew, nine cabin crew and 309 passengers.
The aircraft was pushed back from the gate at Narita Airport, Tokyo, at 1133 UTC.[1] About two hours into the flight, the flight crew received an engine indication and crew alerting system (EICAS) message ELEC GEN DRIVE R2, which indicated a fault with the number 2 generator in the right engine. The flight crew performed the checklist actions for that fault, which included disconnecting the number 2 generator drive from the engine driven accessory gearbox (AGB) and starting the auxiliary power unit to supplement the aircraft electrical power with the auxiliary power unit driven generators.
About 30 minutes later, cruising at FL 400,[2] the secondary engine instruments appeared[3] on the flight crews’ multi-function displays and the flight crew detected there was a low oil quantity indication for the right engine. While the flight crew investigated the engine indications, another EICAS message annunciated, ENG OIL PRESS R, which indicated low oil pressure in the right engine. The flight crew performed the checklist actions for low oil pressure in the right engine. The right engine auto-throttle was switched off and the right engine thrust lever retarded to idle. The low oil pressure EICAS message momentarily cleared before it returned again, and the flight crew shut down the right engine in accordance with the checklist procedures.
The captain identified Guam Airport as the nearest suitable airport, about 370 km to the south of their position. They made a PAN[4] call to Guam air traffic control, who provided them with a clearance to manoeuvre as required for a landing at Guam Airport. The flight crew sent a message using the aircraft communications addressing and reporting system to their operations control that they were diverting the aircraft to Guam. They descended the aircraft to FL 220 due to single engine performance limitations and diverted around some weather as they tracked towards Guam Airport. The captain reported that they made an uneventful one engine landing on runway 24 at about 1520 UTC.
After the aircraft vacated the runway, the captain held the aircraft on the taxiway to allow the airport emergency services to inspect the engine before they taxied the aircraft to the arrival gate. The aircraft was shut down at the arrival gate without further incident.
Maintenance findings
When the engine cowls were opened for the initial inspection there was a large quantity of oil found throughout the engine and a considerable amount of metallic debris found within the engine oil system. A data download of the engine was performed and the results were sent to GE Aviation, the engine manufacturer, for review. GE Aviation provided options for returning the aircraft to service, of which Jetstar determined an engine change was the most expeditious.
Engine manufacturer findings
GE Aviation found there was no history or shift in oil system parameters except for the chip count[5] on this flight. Chips are detected and recorded by the engine debris monitoring system (DMS), within the engine oil system.
On the incident flight, the right engine oil system started to detect chips from about one hour into the flight. The chip count reached seven when the crew were alerted to disconnect the number 2 generator. At 1415 a status message was generated for ENG OIL DMS R, which indicated the chip count for the right engine had reached eight.
Between 1415 and 1419 the chip count reached 11, there was a rapid loss of engine oil, a momentary spike in vibration from the engine number 1 bearing, and the EICAS message to the flight crew reporting low engine oil pressure. The engine was shut down and the aircraft landed about 52 minutes later.
Engine driven gearboxes
Engine rotation is transmitted to an inlet gearbox (IGB) with a radial driveshaft, which connects to a transfer gearbox (TGB). The TGB transmits the engine speed to the AGB via a horizontal driveshaft (Figure 1). The AGB drives the accessories necessary for engine operation and other aircraft services, such as the generators for the aircraft electrical system. The engine oil system provides lubrication, cooling and removes debris from the gearboxes.
Figure 1: Engine driven gearboxes
Source: Boeing, annotated by ATSB
Transfer gearbox damage
On inspection, the TGB housing was found to be fractured (Figure 2). The TGB oil screen was found with metallic debris and the engine oil DMS sensor was found with metallic debris (Figure 3). The manufacturer’s inspection of the TGB failure indicated it was consistent with a known failure mode of the TGB described in their service bulletin (SB) 72-0298.
Figure 2: Transfer gearbox damage
Source: Jetstar Airways
Figure 3: DMS sensor and TGB oil screen metallic debris
Source: Jetstar Airways
GE Aviation service bulletin 72-0298
GE Aviation SB 72-0298 revision 0, dated 31 March 2016, is applicable to all GEnx‑1B engines, which were the engines fitted to VH-VKK at the time of the incident. The SB introduces a new transfer gearbox (TGB) configuration. According to the SB:
Pre-modified TGBs have a radial bevel gear with potential resonance modes (see Resonance) in the engine operating range. Excitation of resonance modes may lead to a gear fracture, which can result in engine oil loss and an in-flight shut down. The SB modification introduces a new damper ring groove to the radial bevel gear and a damper ring to mitigate the excitation of the resonance modes.
GE Aviation recommended the compliance periods for the SB in Table 1 below, which are based upon the number of cycles since new (CSN) for the TGB as of 31 March 2016.
Table 1: SB 72-0298 compliance
Cycles Since New (CSN) as of 31 March 2016
Compliance period from 31 March 2016
TGB less than 300 CSN
12 months
TGB between 300 and 1,000 CSN
10 months
TGB greater than 1,000 CSN
8 months
Jetstar management of service bulletin 72-0298
The SB related modifications for the Jetstar 787 fleet was managed with a risk profile developed by GE Aviation. The risk profile had four levels of risk for TGB failures, which depended on a number of engine operating factors in addition to the TGB CSN. Jetstar responded to the SB terminating action by immediately sourcing additional post-modification units from the manufacturer and prioritised the TGB modification in accordance with the order of highest to lowest TGB risk until the incident flight. The incident engine TGB was identified as the lowest risk (based on lowest CSN, limited in-service operational data and GE Aviation recommendations) for the Jetstar fleet at the time of the incident.
The incident engine TGB had 181 CSN at the time of the incident and therefore the compliance date to complete the SB for this engine was 31 March 2017. The engine modification to comply with the SB for the incident engine was scheduled for 31 December 2016.
Resonance
All machinery have a natural frequency of vibration. If a particular abnormality in the machinery generates a forced vibration, which vibrates in-phase and at the same frequency as the natural frequency of vibration, then the energy will magnify. The frequency at which this occurs is known as the resonant frequency (Figure 4). If there is insufficient damping present at the resonant frequency, then the amplitude of the vibrations will increase with each cycle. Excessive movement of components with high energy can cause a catastrophic failure of the machinery.
Figure 4: Resonant frequency for damped and undamped vibration
Source: ATSB
Jetstar Airways extended diversion time operations
Twin engine turbine aeroplanes are normally restricted to operating on routes where if an engine fails or is shut down in-flight, the aircraft is within 60 minutes flight time, at the cruise speed for one engine inoperative, to a suitable airport. Extended diversion time operations (EDTO) permit the Boeing 787 to operate on routes which are further than the 60 minutes flight time in the event of an engine in-flight shut down (IFSD). EDTO approval for an operator is subject to the continuous monitoring of the engine IFSD rate.
For the Jetstar Boeing 787 fleet the EDTO approval at the time of the incident was for up to 180 minutes, which required a target IFSD rate of not greater than 0.02 per 1,000 flight hours. Prior to the incident flight, Jetstar were operating at a rolling 12 month IFSD rate of 0 per 1,000 flight hours, which increased to 0.0096 post-incident. Jetstar have performed several unscheduled engine changes on their 787 fleet since introduction into service, but no changes prior to the incident flight related to the fault condition identified in SB 72-0298.
ATSB comment
The ATSB notes that the failure of the TGB and loss of oil is a potential failure mode known to the engine manufacturer and operator. This condition is under risk management through the service bulletin process and the operator was within the compliance period at the time of the incident. Prior to the incident flight, the incident TGB was assessed as being in the lowest risk profile for the operator’s fleet.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Jetstar Airways
In light of the incident, Jetstar amended their TGB modification schedule in order to prioritise at least one engine TGB on each aircraft airframe in their fleet at the earliest opportunity (known as depairing or decoupling). The fleet was completely depaired from 26 August 2016. Jetstar completed the modification programme for their fleet in November 2016.
Safety message
This incident highlights the importance of flight crew complying with checklist actions when dealing with a fault condition. Inflight, the crew did not have knowledge of the extent of the damage to the engine TGB. However, by following their training and checklist procedures, they reduced the risk of a potential escalation of the fault.
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
At about 1330 Western Standard Time on the 7 August 2016, a Skippers Aviation de Havilland DHC-8 aircraft, registered VH-XFP, departed Perth Airport for Shark Bay Western Australia. Two flight crew, one cabin crew and 30 passengers were on board the regular public transport flight.
As the aircraft approached the cruising altitude flight level (FL) 180, the master warning activated and the cabin pressure warning light illuminated. The crew observed that the cabin altitude indicated about 12,600 ft with an excessive rate of climb, where the rate of climb indicator had gone to its maximum indicated reading. They conducted their phase one memory checklist items for a rapid depressurisation and an emergency descent. Both crewmembers fitted their oxygen masks and the captain, who was not the flying pilot, took control of the aircraft. The captain made an announcement through the aircraft’s public announcement system. However, the announcement was muffled and distorted and the cabin crewmember did not understand what was being said. The first officer declared an emergency (PAN PAN) to air traffic control and advised that they were on descent through FL 175.
The captain levelled the aircraft at about 10,000 ft, re-engaged the autopilot and the crew conducted the cabin pressurisation failure checklist. The crew were not able to regain control of the cabin pressurisation.
The aircraft returned for a landing at Perth without further incident. The two flight crew, one cabin crew and 30 passengers were not injured and the aircraft was not damaged.
The reaction time for pilots to fit oxygen masks is of critical importance when there is a cabin pressurisation failure. For the crew in this occurrence, it was the first action taken when they detected that the cabin pressure warning light was on.
At about 1330 Western Standard Time (WST) on the 7 August 2016, a Skippers Aviation de Havilland DHC‑8-106 aircraft, registered VH-XFP (XFP), departed Perth Airport for Shark Bay Western Australia. Two flight crew, one cabin crew and 30 passengers were on board the regular public transport flight.
At about 10,000 ft, the flight crew conducted the transition checklist items that included checking the cabin pressurisation system and noted that everything was operating normally. The captain observed that the cabin altitude[1] was about 4,000 ft, the rate of climb was between 250 ft and 500 ft, and the maximum differential pressure between the outside air pressure and the cabin air pressure was about 2.5 to 3 psi (Figure 1).
Figure 1: Cabin pressure indicator panel showing the cabin differential pressure, cabin altimeter and cabin altitude rate of climb indicators
Source: Aircraft Maintenance Manual, modified by the ATSB
At about flight level (FL) 176[2] the flight crew engaged the autopilot. As the aircraft approached the cruising altitude FL 180, the master warning activated and the cabin pressure warning light[3] illuminated. The crew observed that the cabin altitude indicated about 12,600 ft with an excessive rate of climb, where the rate of climb indicator had gone to its maximum indicated reading. They conducted their phase one memory checklist items for a rapid depressurisation and an emergency descent. Both crewmembers fitted their oxygen masks and the captain, who was not the flying pilot, took control of the aircraft. The captain made an announcement through the aircraft’s public announcement (PA) system. However, the announcement was muffled and distorted and the cabin crewmember did not understand what was being said. The cabin crewmember tried contacting the flight crew but did not get a response. The flight crew selected the passenger seat belt sign on and commenced an emergency descent. The cabin crewmember realised that the aircraft was in a descent, fastened their seatbelt and using the PA system instructed the passengers to do the same. The cabin crewmember did not use supplemental oxygen (available at the flight attendant seat), as they were not aware of the nature of the emergency. Oxygen was not made available for passengers (see Passenger oxygen requirements below). The first officer declared an emergency (PAN PAN)[4] to air traffic control and advised that they were on descent through FL 175.
The captain levelled the aircraft at about 10,000 ft, re-engaged the autopilot and the crew conducted the cabin pressurisation failure checklist. The crew were not able to regain control of the cabin pressurisation. The maximum cabin altitude observed by the crew was just over 14,000 ft and this had returned to 10,000 ft when the aircraft was at an altitude of about 10,000 ft. The cabin pressure warning light remained on. The captain called the cabin crewmember and informed them that they were returning to Perth. The cabin crewmember then carried out a cabin check to ensure that the passengers were not injured and the cabin was secured.
The flight crew contacted the operator’s maintenance personnel and were not able to isolate the reason for the fault. As the aircraft was above the maximum landing weight, they tracked to Rottnest Island to conduct a holding pattern to burn enough fuel to reduce the weight for a landing at Perth. The cabin pressure warning light extinguished on the way to Rottnest Island. The aircraft returned for a landing at Perth without further incident. The two flight crew, one cabin crew and 30 passengers were not injured and the aircraft was not damaged.
Passenger Oxygen requirements
Due to the lower altitudes that this aircraft model operates at, drop down oxygen masks for passengers and cabin crew were not installed nor required. Instead, the aircraft was supplied with portable oxygen bottles that can be handed out throughout the cabin to 10 per cent of the occupants, providing oxygen for half an hour. This is in accordance with Civil Aviation Order 20.4 (7) Supplemental oxygen requirements for pressurised aircraft engaged in flights not above flight level 250:
7.5 Supplemental oxygen for passengers
(a) where the aircraft can safely descend to Flight Level 140 or a lower level within 4 minutes at all points along the planned route and maintain Flight Level 140 or a lower level for the remainder of the flight — to provide 10% of the passengers with supplemental oxygen for 30 minutes or 20% of the passengers with supplemental oxygen for 15 minutes;
Captains comment
The captain reported practicing emergency descents and pressurisation faults about two weeks prior to the occurrence when conducting simulator training. They commented how valuable that training was to be prepared for this type of occurrence where they could identify that it was not a gradual or subtle depressurisation.
The captain reported that there was no warning or anything that would have indicated that there was a cabin pressurisation failure apart from the activation of the cabin pressure warning system.
The captain was not aware that the PA to the cabin was muffled. The captain also reported that the cabin crewmember had not heard the instruction for cabin crewmembers to use supplemental oxygen until after the flight had landed.
Operator comments
The operator conducted an investigation into the occurrence, and after testing of the forward safety outflow valve, found that it was outside the aircraft maintenance manual specifications, and believed that it was the reason for the cabin pressurisation failure.
The operator reported that during the occurrence, the captain made a public announcement, which the passengers and cabin attendant did not understand as the announcement was muffled and distorted. The pilot’s oxygen mask audio system was tested and found to be serviceable. The most likely reason that the announcement was not heard clearly was that the oxygen masks might have distorted the communication.
Safety analysis
The forward outflow valve was not operating as required which led to a rapid depressurisation of the aircraft as it approached its cruising altitude.
The PA announcement from the captain was muffled, resulting in the cabin crewmember not initialling realising that the flight crew were conducting an emergency descent and that they should use supplemental oxygen.
Findings
These findings should not be read as apportioning blame or liability to any particular organisation or individual.
The aircraft’s cabin pressurisation system failed resulting in the aircraft depressurising.
The PA to the cabin was muffled as the crew were using oxygen masks and potentially critical information was not communicated to the flight attendant and the passengers.
The flight crew fitted their oxygen masks immediately, when they noticed, at about 12,600 ft cabin altitude that the cabin pressure warning system had activated.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Skippers Aviation
As a result of this occurrence, the aircraft operator has advised the ATSB that they are taking the following safety actions:
Raise pilot awareness on the difficulty of communication when they fit an oxygen mask and its effect on their clarity of speech. In such cases, they may be required to be more deliberate and punctuate their instructions.
The continuing airworthiness management system will continue to monitor XFP for any associated defects. The faulty valve will be overhauled to determine why it failed.
Safety message
The reaction time for pilots to fit oxygen masks is of critical importance when there is a cabin pressurisation failure. For the crew in this occurrence, it was the first action taken when they detected that the cabin pressure warning light was on. A misconception is that it is easy to recognise the symptoms of hypoxia and take corrective action before becoming seriously impaired. The signs and symptoms vary depending on the individual, the altitude and the extent of the exposure. While other significant effects of hypoxia usually do not occur in a healthy person in an unpressurised aircraft below 12,000 ft above mean sea level (AMSL), there is no assurance that this will always be the case. Furthermore, the altitude range of impairment due to hypoxia is best described as a continuum; there is no definitive altitude at which the effects of hypoxia begin or end. To mitigate the risk associated with these variations, if hypoxia is suspected, a descent to altitudes below 10,000 ft AMSL is suggested.
Additional information is provided in the following publications:
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
The Safety Investigation Board (SIB) of the Pakistan Civil Aviation Authority is investigating an engine failure and runway excursion involving a Beechcraft 1900D aircraft, registered AP-BII that occurred on 18 March 2016. On 4 August 2016, the SIB requested the appointment of an ATSB investigator as accredited representative to the SIB investigation in accordance with clause 5.23 of Annex 13 to the Convention on International Civil Aviation Aircraft Accident and Incident Investigation.
The SIB requested the ATSB accredited representative to oversight a technical examination of the aircraft’s engine at a maintenance facility in Brisbane, Queensland. To facilitate this support, the ATSB initiated an investigation under the Australian Transport Safety Investigation Act 2003.
On 6 January 2017, the SIB advised the ATSB that, as all investigation work within Australia had now been completed, ATSB assistance was no longer required.
The SIB is responsible for, and will administer the release of the final investigation report into the occurrence involving AP-BII. Any enquiries regarding the SIB investigation should, in the first instance, be directed to the:
On the morning of 4 August 2016, Qantas Flight QF61, an Airbus A330 aircraft, registered VH‑QPC, was prepared for departure from Brisbane Airport, Queensland, for a flight to Narita Airport, Tokyo, Japan.
The flight dispatcher, responsible for flight planning, started building the flight plan for QF61 at about 0800 Eastern Standard Time (EST) at the company integrated operations centre (IOC). In addition to the destination of Narita Airport, the flight plan included two destination alternate[1] airports, Haneda Airport, Tokyo, Japan and Saipan International Airport, Saipan (Figure 1). Saipan Airport was also the extended diversion time operations (EDTO)[2] alternate airport (see Extended diversion time operations).
During the process of building the flight plan, the flight dispatcher noticed one of the aircraft’s two global positioning system (GPS) navigation units was recorded as an unserviceable item on the aircraft minimum equipment list (MEL).[3] The flight dispatcher also identified that two serviceable GPS units were required at dispatch, due to the forecast westerly winds, to allow the use of Saipan Airport runway 25 GPS approach as an alternate airport for destination and EDTO purposes. Therefore, they contacted the section of the IOC responsible for aircraft maintenance (maintenance watch) to check if the unserviceable MEL item (GPS 2) would be cleared before the aircraft’s departure.
Maintenance watch indicated that the unit would be fixed and the unserviceability removed before the aircraft departed.[4] The flight dispatcher completed the flight planning documents with the GPS 2 unit listed as an unserviceable MEL[5] item – with the expectation that this would be removed before departure. However, the dispatcher did not make a note in the flight planning documents to advise the flight crew that this MEL item should be cleared before the flight departed. They then sent the documents to the flight crew about 85 minutes prior to the scheduled departure time.[6]
The captain for QF61 signed on for work at Brisbane Airport at 0945, after receiving an electronic copy of the flight plan and briefing package. After reviewing the package, the captain requested an additional 1,700 kg of fuel to allow for a second mainland Japan destination alternate airport (Nagoya in addition to Haneda) (Figure 1). They then discussed the implications of the unserviceable GPS 2 unit with the other two flight crewmembers.
Figure 1: QF61 Destination and EDTO alternates
Source: Google earth, annotated by ATSB
The captain initially thought that two GPS units were required at dispatch because the Saipan Airport runway 25 approach procedure required GPS. However, after further discussion they decided that they were mistaken as maintenance and flight dispatch were aware one GPS was unserviceable and the captain had very few past experiences of an incorrect serviceability requirement at dispatch. One flight crew member then mentioned that the flight crew operating manual indicated one GPS unit was required.[7]
The captain referred to the MEL. The MEL includes the MEL items and their associated operational procedures. The operational procedures may impose additional operational requirements to what is documented in the MEL items. The MEL item for the aircraft GPS function indicated only one GPS unit was required at dispatch. However, the associated operational procedures indicated that ‘primary means GNSS approval’[8] was required at dispatch if the alternate airport arrival procedure requires GPS navigation. ‘Primary means GNSS approval’ indicated the requirement for two operational GPS units. When the captain reviewed the MEL operational procedures they considered the reference to ‘alternate’ to be a reference to destination alternate airport and not to an EDTO alternate airport. They planned to use Saipan as an EDTO alternate airport and not a destination alternate airport, having already decided to add a second mainland Japan destination alternate airport. This fitted with their expectation that the unserviceable GPS 2 MEL item was acceptable for their flight.
The flight departed from Brisbane with 12 crew and 231 passengers on board and proceeded in accordance with the flight plan. As QF61 travelled north along the east coast of Australia, the captain was uncomfortable with their decision to accept the aircraft with GPS 2 listed as unserviceable.[9] Therefore, the captain reviewed the flight plan and the publications. They concluded they had misinterpreted the MEL operational procedures reference to alternate airport requirements and that their flight plan required two serviceable GPS units to use the Saipan Airport runway 25 GPS approach for destination or EDTO alternate airport purposes.
The captain identified Guam Airport (runway 24R VOR/DME[10]) as a suitable airport to plan to use instead of Saipan Airport for their EDTO alternate airport and briefed the other two flight crew members. However, one flight crew member queried if Guam could be used for replanning in lieu of Saipan without two serviceable GPS units. The attention of this flight crewmember was drawn to a note on one of the Guam terminal plate pages (Figure 2), which indicated runway 24R required ‘primary means GNSS approval’ for use as an alternate airport. However, the captain considered that this was a reference to the destination alternate (which required two separate approaches) and that the runway 24R VOR/DME approach could be used for EDTO alternate purposes (see Use of Guam Airport as an adequate aerodrome).
The captain entered a new critical point[11] between Tokyo and Guam (in lieu of Saipan) into the aircraft flight management and guidance computer. The computer calculated that an extra 800 kg of fuel was required, which was within the limits of the extra fuel the captain requested before departure. The flight continued to Narita Airport and landed without further incident.
The GPS 2 unit was observed by the crew to be serviceable throughout the flight. It was tested by maintenance at Narita Airport, found to be serviceable, and then removed from the MEL unserviceability list before the next flight.
Extended diversion time operations
For the A330, extended diversion time operations (EDTO) apply at any stage of the flight where the flight time to an adequate aerodrome (EDTO alternate), at the one engine inoperative cruise speed, is greater than 60 minutes. The EDTO limit for the A330 is 180 minutes.
For further information on EDTO requirements refer to Civil Aviation Advisory Publication 82-1(1): Extended diversion time operations (EDTO)
Use of Guam Airport as an adequate aerodrome
In accordance with Civil Aviation Order 82.0 paragraph 2.1, an EDTO alternate aerodrome requires at least one suitable authorised instrument approach procedure. Therefore, the Guam Airport runway 24R VOR/DME approach could be used by flight QF61 for this purpose.
If Guam Airport runway 24R had been used as a destination alternate airport, then two instrument approach procedures, which do not use a common ground based radio navigation aid, would have been required. In this case, the runway 24R GPS approach would have been required as the second approach and therefore two serviceable GPS units would have been required at dispatch. Hence the reference to ‘primary means GNSS approval’ for runway 24R on the Guam terminal plate page, which caught the attention of one of the flight crew members (Figure 2).
For further information about alternate requirements for international IFR[12] operations outside Australia, refer to Civil Aviation Safety Authority Manual of Standards 173 paragraph 8.1.11.
Figure 2: Guam terminal procedures note for Qantas operations
Source: Aircraft captain, annotated by ATSB
Global positioning system unserviceability
The number 2 GPS was recorded as unserviceable and raised as an MEL item for QPC on 31 July 2016. The A330 GPS MEL had a repair interval of 10 consecutive calendar days and was scheduled for repair on 8 August 2016. No change was made to this schedule prior to the dispatch of flight QF61 on 4 August 2016.
Flight dispatcher comment
The flight plan had a free text box on the front page, which the flight dispatcher used to communicate the presence of a tropical storm to the flight crew in the incident flight. The flight dispatcher commented that in future they would use this free text box to communicate to the flight crew if they expected a change to the MEL status of the aircraft before dispatch.
ATSB comment
The ATSB notes that in large organisations there may be multiple departments with responsibilities for the dispatch of an aircraft. Whereas procedures are normally executed within a department, processes often involve multiple departments. Cross-checks occurred within the IOC and separately among the flight crew during this incident flight, but the cross-checks were not conducted between the departments, where personnel had a different mental model of the situation. The flight dispatcher believed the GPS 2 MEL item would be cleared before flight and the captain believed the flight was planned to be released with the GPS 2 as an unserviceable MEL item.
Safety message
This incident highlights the importance of personnel challenging their own assumptions when something does not appear right in the environment. After the dispatch of QF61 from Brisbane Airport, the captain experienced a ‘gut feeling’ that something was not right. Rather than ignore their sense of unease, the captain reviewed the flight plan and company documents, identified the problem and resolved the issue so that the flight could continue without compromising safety. Throughout the process, they kept the other flight crewmembers informed of the problem they had identified and their decision-making, which enabled the crew to provide feedback to the captain.
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.