Fumes event involving Airbus A320, VH-VNO, 211 km north of Melbourne Airport, Victoria, on 1 March 2016

Final report

What happened

On 1 March 2016, at 0640 Eastern Standard Time, a Tiger Airways Airbus A320 aircraft, registered VH-VNO (Figure 1), departed Brisbane, Queensland, on a scheduled passenger service to Melbourne, Victoria. On board were the captain, the first officer, four cabin crew members, and 63 passengers.

Figure 1: Tiger Airways Airbus A320, VH-VNO

Figure 1: Tiger Airways Airbus A320, VH-VNO

Source: Victor Pody

At about 0900 Eastern Daylight-saving Time (EDT), when the aircraft was abeam Parkes, New South Wales, the cabin crew detected a strong odour in the rear of the cabin, and notified the captain. The cabin crew were unsure what the smell was, but they later described it as being like that of an extinguished cigarette. The odour dissipated soon after. About 10 minutes later, it returned and the cabin crew again advised the flight crew.

The cabin crew conducted their normal procedures in response to fumes in the cabin. This included filling bins with water to quench any possible fire, and checking lavatories, galley and the rear of the cabin in an attempt to find the source of the fumes. They also assessed whether there was any evidence of heat or fire.

As the cabin crew were unable to locate the source of the fumes or to find any heat source, the captain further asked them to check the overhead lockers and the floor above the cargo hold. They were still unable to find the source.

In accordance with standard operations with fewer than 115 passengers on board, the flight crew had the cabin air on the low flow setting. In the absence of smoke, they elected to set the airflow to high and see if that removed the odour from the aircraft. The fumes subsequently subsided.

At 0933 EDT, the aircraft was about 211 km north of Melbourne, at flight level 320.[1] The flight crew had been cleared by air traffic control (ATC) to commence their descent for Melbourne. At that time, the cabin manager advised the captain that the fumes had returned and the odour was very strong. They also advised that three cabin crew members were feeling unwell, and that one had vomited.

The captain and first officer then reviewed the situation. They assessed that due to the cabin crew becoming ill, and the source of the fumes still unknown, they would contact ATC, declare a PAN,[2] and request direct tracking to Melbourne. The crew also requested radar vectoring to reduce the workload required to reprogram the flight management system from the previously cleared route already entered into the system.

The cabin manager then advised the captain that the odour was still very strong. The captain recommended that all passengers be moved forwards away from the odour, which was at the rear of the cabin. The captain advised the cabin manager that they had declared an emergency and requested a direct track to Melbourne, and switched the seatbelt sign on.

The air traffic controller asked how many people were unwell and would require ambulance on arrival. The captain discussed with the cabin manager before responding that three cabin crew members and no passengers were unwell. The captain advised the passengers that fire vehicles and ambulance would be present for their arrival at Melbourne Airport.

During the approach, the captain advised ATC that they expected to conduct a normal landing and taxi clear of the runway via a high-speed taxiway. They would then stop and evaluate whether they would continue to taxi to the bay or whether an evacuation of the aircraft would be necessary.

To allow ease of access by emergency vehicles, the control of all runways had been handed from the tower controller to the surface movement controller. Aircraft movements were temporarily suspended, therefore no other aircraft were cleared to take-off or land at the airport. The aircraft landed at 0958 EDT.

The captain had directed the cabin manager to check the rear of the cabin after the aircraft taxied clear of the runway, and advise whether the odour was still there. The cabin manager reported that it was not. The captain then spoke to the commander of the aviation rescue and firefighting service, advised that they would continue to taxi to the bay, and requested that they follow the aircraft. The captain then requested a clearance from ATC to taxi to the bay. The captain also advised the passengers of the situation.

Once parked at the bay, the flight crew elected not to start the auxiliary power unit because they had been unable to determine the source of the fumes or to exclude any potential fire hazard. The captain advised the cabin crew and passengers that the cabin would go dark and the emergency lighting would come on. After shutting the engines down, the captain advised the fire commander that other than sick members of the cabin crew, everything was normal. The captain then left the cockpit to address the passengers, who disembarked normally. The fire crew did not find any source of fumes or fire, nor did a subsequent engineering inspection reveal the source.

Safety message

This incident demonstrates effective crew resource management techniques to deal with an abnormal and evolving situation.

In the event of smoke or fire, the emergency procedures are clear, time is of the essence, and a MAYDAY[3] call is required. In this incident, however, the seriousness of the situation, the source of the fumes, and the potential risk of the situation, was difficult to assess. The crew’s decision to declare a PAN enabled air traffic control to provide assistance, without the immediacy that would have been required in the case of smoke or fire. As the situation unfolded, the flight crew continued to assess their options based on the information available. They made contingency plans in case things escalated or worsened, such as identifying the nearest airport for an emergency landing if required.

The third time the cabin crew reported the odour, and also became unwell, the flight crew had commenced descent, and the workload was very high. The flight crew demonstrated effective decision making and prioritisation based on the information available and the situation at hand. Throughout the approach to Melbourne, the flight crew communicated with each other, the cabin crew, the passengers, and air traffic control, which kept all parties informed and allowed appropriate assistance to be given.

Aviation Short Investigations Bulletin - Issue 49

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. At altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level. Flight level 320 equates to 32,000 ft.
  2. An internationally recognised radio call announcing an urgency condition which concerns the safety of an aircraft or its occupants but where the flight crew does not require immediate assistance.
  3. Mayday is an internationally recognised radio call for urgent assistance.

 

Occurrence summary

Investigation number AO-2016-016
Occurrence date 01/03/2016
Location 211 km N of Melbourne Airport
State Victoria
Report release date 27/07/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Fumes
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer Airbus
Model A320-232
Registration VH-VNO
Serial number 4053
Aircraft operator Tiger Airways Australia
Sector Jet
Operation type Air Transport High Capacity
Departure point Brisbane, Qld
Destination Melbourne, Vic.
Damage Nil

Descent below segment minimum safe altitude during a non-precision instrument approach involving Airbus A320, PK-AXY, 17 km west-south-west of Perth Airport, Western Australia, on 19 February 2016

Final report

What happened

On the evening of 19 February 2016, an Airbus A320 aircraft, registered PK-AXY and operated by PT Indonesia AirAsia was on a scheduled passenger service from Denpasar, Indonesia to Perth, Australia. During cruise, the captain’s flight management and guidance computer (FMGC1) failed. Due to the failure, the flight crew elected to use the first officer’s duplicate systems. For the aircraft’s arrival in Perth there was moderate to severe turbulence forecast below 3,000 ft with reports of windshear. The crew commenced an instrument landing system (ILS) approach to runway 21.

During the approach, the flight crew made a number of flight mode changes and autopilot selections, normal for an ILS approach with all aircraft operating systems available. However, some of those flight modes and autopilot selections relied on data from the failed FMGC1 and the autothrust system commanded increased engine thrust. The crew did not expect this engine response and elected to conduct a go-around. With an increasing crosswind on runway 21, the crew accepted a change of runway, to conduct a non-precision instrument approach to runway 06.

With the time available, the first officer programmed the new approach into his FMGC and conducted the approach briefing. During this period, the captain hand flew the aircraft and manually controlled the thrust. During the approach to runway 06, the crew descended the aircraft earlier than normal, but believed that they were on the correct flight path profile.

While descending, both flight crew became concerned that they could not visually identify the runway, and focused their attention outside the aircraft. At about that time, the approach controller received a “below minimum safe altitude” warning for the aircraft. The controller alerted the crew of their low altitude and instructed them to conduct a go-around. The crew then conducted another approach to runway 06 and landed.

What the ATSB found

The ATSB identified that the flight crew were unsuccessful in resolving the failure of the FMGC and had a limited understanding of how the failure affected the aircraft’s automation during the ILS approach. This resulted in the unexpected increase in engine thrust, which prompted a go-around.

The flight crew had a significant increase in workload due to the unresolved system failures, the conduct of a go-around and subsequent runway change. This, combined with the crew’s unfamiliarity and preparation for the runway 06 instrument approach, meant they did not effectively manage the descent during that approach.

The flight crew’s focus of attention outside the aircraft distracted them during a critical stage of flight. The crew did not detect that they had descended the aircraft below the specified segment minimum safe altitude.

The flight crew commenced their descent for the second runway 06 instrument approach later than normal, initially necessitating an increased rate of descent and at 300 ft the engine thrust reduced briefly to idle.

Safety message

Handling of approach to land is one of the ATSB’s SafetyWatch priorities. Unexpected events during the approach and landing can substantially increase what is often a high workload period. Adherence to standard operating procedures and correctly monitoring the aircraft and approach parameters provides assurance that the instrument approach can be safely completed. A go-around should be immediately carried out if the approach becomes unstable or the landing runway cannot be identified from the minimum descent altitude or missed approach point.

Context

Personnel information

The captain

The captain was an Indonesian national and held an Indonesian Airline Transport Pilot Licence (ATPL) and had accumulated about 13,500 hours of aeronautical experience. Of these, about 9,250 hours were in command and about 5,200 hours were on the A320. The captain reported flying into Perth 3 to 4 times a month (including a night approach on 13 February 2016), and conducting a VHF Omni Directional Radio Range (VOR) approach on runway 06 previously, although not often. The captain had conducted a VOR approach on 18 February, the day prior to the occurrence and reported that he regularly conducted non-precision VOR approaches into his home port of Denpasar.

The captain’s proficiency check records indicated that during the 6-month period prior to the occurrence he had successfully completed a non‑precision approach during his cyclic simulator training. His training record for September 2015 recorded competency with managing a flight management and guidance computer (FMGC) or instrument failure. The captain had been assessed as meeting the requirements of the International Civil Aviation Organization (ICAO) English language proficiency[28] at a level 4 standard.

The captain held the relevant Indonesian Certificate of Medical, First Class. That certificate required the pilot to wear corrective lenses for vision.

The first officer

The first officer, a Japanese national, held an Indonesian Commercial Pilot (Aeroplane) Licence (CPL) and had accumulated about 4,200 hours of aeronautical experience, with approximately 3,100 hours on the A320. The first officer had flown into Perth previously, but the occurrence flight was the first time he had conducted an approach into Perth at night, and it was his first runway 06 VOR approach. The first officer had conducted a VOR approach on the day prior to the incident and reported that he regularly conducted VOR approaches into Denpasar.

The first officer’s proficiency check records indicated that during the 6-month period prior to the occurrence he had successfully completed a non‑precision approach during his cyclic simulator training, including a non-precision approach and landing. The first officer had been assessed as meeting the requirements of the ICAO English language proficiency at a level 5 standard.

The first officer held the relevant Indonesian Certificate of Medical, First Class. That certificate required the pilot to wear lenses that correct for distance vision and possess glasses that correct for near vision.

Fatigue considerations

The flight crew reported feeling alert during the approaches. The ATSB reviewed their flight and duty times and 72-hour history prior to the occurrence, and found no evidence that they were likely to be affected by fatigue at the time of the incident.

Approach speed

The approach speed (VAPP) was computed for the crew by the flight management guidance computer (FMGC) and was based on the aircraft’s stall speed in the selected landing configuration, plus one third of the headwind component calculated from the airport wind entered by the flight crew into the FMGC.[29]

When operating in managed speed mode and to assist with maintaining the energy state of the aircraft in changing wind conditions, the FMGC also continuously calculated a target speed that took into account the instantaneous wind being experienced by the aircraft. That resulted in the target airspeed displayed to the crew on their primary flight displays increasing with strengthening headwind gusts and decreasing with weakening headwind or tailwind gusts (but not below VAPP). If the wind entered by the crew into the FMGC was the same as the instantaneous wind, then the target speed would be VAPP.

For the non-precision approaches to runway 06, the crew were operating the aircraft without the autopilot, autothrust engaged and consequently, were in selected speed mode, and the target speed displayed to the flight crew was VAPP.

Weather

At the time of the approaches, moderate to severe turbulence was forecast below 3,000 ft and ATC had received reports of windshear below 1,600 ft (see Table 1).

Table 1: Actual weather conditions as reported by successive ATIS reports at around the time of the flight by PK-AXY

Condition/requirementATIS and time issued
 ‘Romeo’ issued at 2132‘Sierra’ issued at 2153‘Tango’ issued at 2155
RunwayRunway 21Runway 06Runway 06
Wind120º M at 16 kt100º M at 16 kt gusting to 28 kt100º M at 16 kt gusting to 28 kt
CrosswindMax 16 ktMax 15 ktMax 15 kt
Cloud and visibilityCAVOK[30]CAVOKCAVOK
Significant weather warning

Moderate to severe turbulence reported below 3,000 ft

B737 reported moderate undershoot and overshoot windshear below 1,600 ft on final approach, runway 21 at 1330

Moderate to severe turbulence reported below 3,000 ft

Windshear warning

Moderate to severe turbulence reported below 3,000 ft

Analysis of the recorded information confirmed that turbulent conditions existed in the vicinity of Perth Airport at the time of the aircraft’s arrival. However, there were no activations of the aircraft’s windshear warning system[31] nor activation of the aircraft’s low-speed flight envelope protection systems.

Airport beacon and runway 06 lighting

The control tower at Perth Airport was equipped with a rotating aerodrome beacon, used to indicate the location of the airport from the air. The beacon alternated between a white and green flashing light, once every 6 seconds.

Runway 06/24 was equipped with high intensity runway lighting, selectable by the tower controller to six stages of intensity. It was also equipped with medium intensity runway lighting, selectable to three stages of intensity. There was no high intensity approach lighting for runway 06 or other lighting[32] to assist pilots identify the runway threshold, and nor was such lighting required. The high intensity runway lighting was selected to stage six (maximum intensity) for the crew’s second approach to runway 06.

Flight management guidance system failure

During the cruise, the flight crew received a red text message on the captain’s blank navigation display (ND) stating MAP NOT AVAIL and the first officer’s multipurpose control and display unit (MCDU2) displayed INDEPENDENT OPERATION. The captain’s ND remained inoperative, with the MAP NOT AVAIL message for the remainder of the flight.

The operator’s Flight Crew Operating Manual (FCOM) indicated that a ND may display a MAP NOT AVAIL message for several reasons:

  • The MODE CHANGE or RANGE CHANGE message has been displayed more than 6 seconds, or
  • The FMGC has failed, or
  • The FMGC has delivered an invalid aircraft position.

The MCDU may display an INDEPENDENT OPERATION message when the FMGCs operate independently of each other. In this case, the flight directors (FD) will also operate independently from one another, with the captain’s FD receiving data from FMGC1. The flight crew had access to the aircraft’s Quick Reference Handbook (QRH) and FCOM during flight. These documents were available for the crew to reference in the event of an aircraft system issue, such as a flight management guidance system (FMGS) failure.

Quick reference handbook

Within the ‘Abnormal and emergency procedures’ section of the QRH, under auto flight there is only one listed procedure, ‘Loss of FMS Data in Descent / Approach (Severe Reset)’. This procedure would not have been relevant at the time of the failure, as it occurred during cruise. However, the computer reset table located in the ‘Miscellaneous procedures’ section was relevant. The crew could not explain why they were unable to locate the relevant information.

The Airbus A320 QRH included a procedure to address one locked or blank MCDU, and another for both MCDUs locked (or blank) or FMGC malfunction. The inflight procedure for one locked/blank MCDU was to ‘Pull the CB [circuit breaker] for the locked or blank MCDU and push it back after 10 s[econds]’. The QRH procedure for both MCDU’s locked / FMGC malfunction was:

Short FMGC Reset:

In flight:

‐ FD 1(or 2) (OFF)

‐ Pull the CB [circuit breaker] of the affected FMGC

‐ Reset it after 10 s[econds].

Long FMGC Reset:

In flight:

‐ FD 1(or 2) (OFF)

‐ Pull the CB of the affected FMGC

‐ Reset it after 15 min[utes].

Note: Consider a long FMGC reset only if a short FMGC reset has no effect.

In this instance, the crew recognised that the frozen MCDU1 screen and other system indications suggested a FMGC failure, but conducted neither procedure.

Flight crew operating manual

The FCOM contained a number of different types of FMGS failures and related procedures. These were located in the Procedures section, under ‘Supplementary Procedures’. The table of contents for the supplementary procedures contained a section on auto flight with a subsection related to ‘FMGS Reset and Other Abnormal procedures’. The crew could not explain why they were unable to locate the relevant information.

The failure mode that most closely represented the messages the crew received, related to one flight management system (FMS) failing and latching, but with the FMS continuing to send valid but frozen guidance targets, corresponding to the last valid targets sent before the FMS failed. With this type of failure, the autopilot and FD on the affected side may remain available, and the failed FMGC continues to guide the aircraft using the frozen targets. The FCOM stated that the procedure for this failure is to:

DISREGARD the information coming from the failed side

DO NOT USE the AP [autopilot] on the affected side

- If the AP is engaged on the affected side:

FLY the aircraft back on the intended path

ENGAGE the AP on the operative side, according to the Recommended Practice for

Autopilot Engagement (Refer to FCTM/OP-030 Autopilot/Flight Director)

- If time permits:

PERFORM a long reset of the failed FMGC

Refer to PRO-SUP-22-10 Manual FMGS Reset - Manual Reset of One FMGC

- If the failure affects FMGC1, and if the FMGC1 is still failed and latched before the approach:

DO NOT USE AP1 for the approach

- Before disconnecting AP2:

REVERT to selected speed

DISCONNECT A/THR [autothrust]

Note: It prevents the A/THR from switching to the frozen speed target of the failed FMGC1 when the flight crew disconnects the AP2 for landing.

Dual control inputs on the sidestick

On the A320, each pilot has a sidestick that they can use to manually control the pitch and roll attitude of the aircraft. When the autopilot is engaged, the sidesticks are locked in the neutral position. If a pilot applies a force above a specific threshold, the sidestick becomes free and the autopilot disengages.

The handgrip on the sidestick contains a takeover push button. This button can be used to disconnect the autopilot or takeover from the opposite sidestick.

When the pilots move both sidesticks simultaneously, neither takes priority, and instead the system adds the signals of both sidesticks, with the total limited to the maximum deflection of a single sidestick. If there is a simultaneous deflection of both sidesticks, with a 2º off-neutral deflection, the two green ‘sidestick priority’ lights in the instrument panel’s glareshield illuminate and there will be a ‘dual input’ voice message.

Either pilot can deactivate the other sidestick and take full control by pressing and holding down the priority takeover pushbutton. If the takeover pushbutton is depressed for 40 seconds, the other sidestick is deactivated. It can be reactivated by momentarily pressing the pushbutton of either sidestick.

There was no record of either the captain or the first officer pushing the priority takeover pushbutton during the ILS approach, go-arounds, or during the remainder of the flight.

Handover/takeover procedures

To transfer controls the FCOM stated that the crewmembers must use the following callouts:

‐ To give control: The pilot calls out “YOU HAVE CONTROL”. The other pilot accepts this transfer by calling out “I HAVE CONTROL”, before assuming PF duties.

‐ To take control: The pilot calls out “I HAVE CONTROL”. The other pilot accepts this transfer by calling out “YOU HAVE CONTROL”, before assuming PM duties.

In addition, the Flight Crew Training Manual (FCTM) stated that ‘If the PM (or Instructor) needs to take over, the PM must press the sidestick takeover pushbutton, and announce: “I have control”.’

Types of dual control inputs

Airbus has analysed dual sidestick input events that have been reported to them. In Safety First, The Airbus Safety Magazine (December 2006), Airbus reports that they have found that there are three types of occurrences:

The “Spurious” Dual Stick inputs

Typically due to an inadvertent movement of the stick by the PNF [PM].

For example when grabbing the FCOM or when pressing the R/T [radio].

A spurious dual stick input only marginally affects the aircraft behavior due to only time limited & small inputs.

The “Comfort” Dual Stick inputs

Typically due to short interventions from the PNF [PM] who wants to improve the aircraft’s attitude or trajectory:

These are generally experienced in approach, during a capture (altitude localizer), or in flare, and have minor effects on the aircraft’s altitude/trajectory.

However, as the PF is not aware of the PNF’s [PM] interventions, he may be disturbed and may counteract the PNF’s [PM] inputs.

The “Instinctive” Dual Stick Inputs

Typically due to a “reflex” action on the part of the PNF [PM] on the stick. This instinctive reaction may come about when an unexpected event occurs, like for example an AP disengagement, an overspeed situation or a dangerous maneuver.

Such interventions are more significant in terms of stick deflection and duration. Usually in such situations, both pilots push the stick in the same direction, which may lead to over control, a situation illustrated by the above occurrence.

Autothrust system

Autothrust can be activated when the thrust levers are in the climb detent and the flight crew press the autothrust pushbutton on the flight control unit (FCU). When active the autothrust controls either airspeed or engine thrust as appropriate.

The autothrust will disconnect if the:

  • autothrust fails
  • autothrust pushbutton on the FCU is pressed[33]
  • instinctive disconnect button on the thrust lever is pressed
  • both thrust levers are set to idle.

The thrust lock function is activated when the thrust levers are in the climb detent and either of the flight crew pushes the autothrust pushbutton on the FCU, or the autothrust disconnects due to a failure. When this occurs, the thrust is locked at its level prior to disconnection. Moving the thrust levers out of the climb detent suppresses the thrust lock and associated warnings and gives the crew manual control with the thrust levers.

When the thrust lock function is active:

  • THR LK flashes amber on the flight mode annunciator (FMA)
  • electronic centralised aircraft monitor (ECAM) displays ENG THRUST LOCKED and this message flashes every 5 seconds
  • ECAM displays THR LEVERS …... MOVE
  • A single chime sounds and the master caution light flashes every 5 seconds.

Stabilised approach criteria

The FCOM specified that in visual conditions the approach should be stabilised at 500 ft above ground level (AGL). In order to be stabilised all of the following conditions had to be verified and meet at the stabilisation height:

  • the aircraft is on the correct lateral and vertical flight path
  • the aircraft is in the desired landing configuration
  • the thrust is stabilised, usually above idle, in order to maintain the target approach speed along the desired final approach path
  • there is no excessive flight parameter deviation.

If the aircraft was not stabilised by 500 ft AGL in visual conditions the crew were required to conduct a go-around, unless the flight crew estimated that only small corrections were necessary to rectify minor deviations from stabilised conditions due, amongst others, to external perturbations.

Non-precision instrument approach

The Flight Crew Training Manual (FCTM) indicated that the overall strategy for conducting a non-precision instrument approach was to fly it ‘ILS alike’ with the same mental image or representation and similar procedure. The use of autopilot was recommended for all non-precision approaches as it reduced flight crew workload and facilitated monitoring of the procedure and the aircraft’s flight path. If the flight crew correctly programmed the FMGC, the autopilot and FD would ensure lateral and vertical managed guidance was available to conduct the approach.

Depending on whether the autopilot was being used, the PF either monitored the progress of the approach or provided the manual inputs to manage the aircraft’s lateral and vertical navigation, normally using the guidance targets displayed on the FD. In addition, the FCTM indicated that when conducting a non-precision instrument approach, the PF ‘should expand the instrument scan to include outside visual cues’ as the aircraft approached the minimum descent altitude.

The operator’s FCTM stipulated setting the go-around altitude on the FCU when the aircraft was established on final approach and if in a selected mode, the current aircraft altitude was below the missed approach altitude. The FCTM also prohibited setting the minimum descent altitude as the target altitude on the FCU, which could cause a spurious altitude capture and destabilisation of the approach at a critical stage.

Communication and standard callouts

The FCTM stated that if, for any reason, one parameter deviates from stabilised approach conditions, the PM will make the appropriate callout as follows:

ParameterExceedanceCallout
Indicated airspeedSpeed target +10 kt / -5 kt“SPEED”
Vertical speedDescent rate exceeds 1,200 ft/min“SINK RATE”
Pitch altitude+10º / -2.5º“PITCH”
Bank angle“BANK”
ILS OnlyLocaliserExcess deviation½ dot PFD“LOC”
 Glideslope ½ dot PFD“GLIDE”
Non precision approachCross track error greater than 0.1 NM“CROSS TRACK”
 Vertical deviation greater than ½ dot“V/DEV”
 Course greater than 2.5º (VOR)“COURSE”
 Course greater than 5º (Automatic direction finder)“COURSE”
 Altitude distance check“___FT HIGH (LOW)”

 

Altitude callouts were also to be made by the PM through to landing. Neither the captain nor first officer recollected any callouts being made.

Related occurrences

A search of the ATSB database for similar occurrences in the last 5 years was conducted. The search did not identify any occurrences where a flight crew had difficulty locating Perth Airport or the runways in CAVOK conditions.

The database contained six occurrences where an enhanced ground proximity warning system (EGPWS) glideslope warning had occurred during the runway 06 VOR approach. Of these, four related to the inadvertent selection of the ILS for another runway. There were a further 25 cases of glideslope warnings where the runway was not identified in the occurrence details. There was one record of an EGPWS terrain warning occurring at Perth although the approach involved was not identified. The occurrence details in that case suggested the terrain warning was spurious. There were no occurrences recorded in the ATSB occurrence database where an minimum safe altitude warning was issued by ATC during a runway 06 approach.

ATSB investigation AO-2010-027

On 4 and 29 May 2010, an Airbus A330 aircraft, operated by AirAsia X was involved in two separate occurrences on approach to the Gold Coast, Queensland, where the aircraft were descended below the segment minimum safe altitudes.[34] On both occasions, there was low cloud and reduced visibility on arrival at the Gold Coast. The ATSB found that these events were indicators of a minor safety issue regarding the operator's training of its flight crews, in relation to non-precision approaches.

ATSB investigation AO-2011-086

On 24 July 2011, a Boeing Company 777-3D7 aircraft, operated by Thai Airways, was conducting a runway 34 VOR approach to Melbourne Airport, Victoria.[35] During the approach, the tower controller observed that the aircraft was lower than required and asked the flight crew to check its altitude. The tower controller subsequently instructed the crew to conduct a go-around. However, while the crew did arrest the aircraft’s descent, there was a delay of about 50 seconds before they initiated the go-around and commenced a climb to the required altitude.

The ATSB established that the pilot in command may not have fully understood some aspects of the aircraft’s automated flight control systems and probably experienced ‘automation surprise’ when the aircraft pitched up to capture the VOR approach path. As a result, the remainder of the approach was conducted using the autopilot’s flight level change mode, where the aircraft’s rate of descent may be significantly higher than required. In addition, the flight crew inadvertently selected a lower than stipulated descent altitude, resulting in descent below the specified segment minimum safe altitude for that stage of the approach.

ATSB investigation AO-2011-076

On 30 June 2011, an Airbus A320 aircraft, operated by Tiger Airways Australia conducted a go-around procedure at Avalon Airport, Victoria, after an unsuccessful approach to runway 18.[36] While re-positioning the aircraft for another approach, this time on the reciprocal runway 36, the aircraft descended without further ATC clearance to below the assigned altitude. The flight crew was subsequently cleared for a visual approach; however, the aircraft descended to below the minimum permitted altitude of 2,000 ft, to 1,600 ft. The ATSB investigation found that the flight crew’s understanding of the aircraft’s position during the second approach was probably influenced by the workload associated with the runway change.

ATSB investigation AO-2016-124

On 11 September 2016 an Airbus A330 aircraft, operated by AirAsia X descended below the segment minimum safe altitude, near the Gold Coast Airport, Queensland.[37] The flight crew were cleared to conduct a RNAV-Z (GNSS) instrument approach to runway 14 at Gold Coast Airport in visual meteorological conditions. During the approach, the aircraft was observed to descend below a segment minimum safe altitude. At the time of publication, the ATSB investigation was ongoing.

__________

  1. ICAO has defined six levels of language proficiency, the top three levels (4, 5 and 6) are acceptable for operational flight crew. Level 4 (operational) requires retesting every 3 years, level 5 (extended) requires retesting every 6 years and level 6 (expert) does not require further testing.
  2. The calculation of VAPP by the FMGC was limited to the stall speed plus 5 kt as a minimum and stall speed plus 15 kt as a maximum. The FMGC-calculated value of VAPP can also be modified by the flight crew.
  3. Ceiling and visibility OK, meaning that the visibility, cloud and present weather are better than prescribed conditions. For an aerodrome weather report, those conditions are visibility 10 km or more, no significant cloud below 5,000 ft or cumulonimbus cloud and no other significant weather within 9 km of the aerodrome.
  4. Windshear detection is provided during takeoff and landing. During landing, the system is active from 1,300 ft to 50 ft radio altitude, with wing slat/flap selected.
  5. Such lighting could include runway lead-in lighting, runway threshold identification lights and sequenced flashing lights.
  6. This is not a recommended method of disconnecting the autothrust, as it will result in the engines entering the thrust lock mode.
  7. ATSB AO-2010-027, Operational non-compliances - Airbus A330, 9M-XXB, Gold Coast Airport, Queensland, 4 and 29 May 2010. Available from www.atsb.gov.au.
  8. ATSB AO-2011-086, Operational non-compliance involving Boeing 777, HS-TKD, 15 km south Melbourne Airport, Vic, 24 July 2011. Available from www.atsb.gov.au.
  9. ATSB AO-2011-076, Descent below the minimum permitted altitude, Airbus A320, VH-VNC, 15 km SSE of Avalon Airport, Vic, 30 June 2011. Available from www.atsb.gov.au.
  10. ATSB AO-2016-124, Decent below segment minimum safe altitude involving Airbus A330-343X, 9M-XXI, near Gold Coast Airport, Qld, on 11 September 2016. On completion, a copy of the investigation report will be available from www.atsb.gov.au.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • aircraft operator, PT Indonesia AirAsia
  • aircraft flight crew
  • provider of air traffic services, Airservices Australia
  • manufacturer of the aircraft, Airbus.

References

Dismukes, R.K., and Berman, B. (2010). Checklists and monitoring in the cockpit: Why crucial defences sometimes fail. NASA/TM-2010-216396, NASA Ames Research Centre, Moffett Field, CA.

Kahneman, D. (2011). Thinking, fast and slow. Allen Lane: London, UK.

Klein, G. (2008). Naturalistic decision making. Human Factors, Vol 50, No.3, pp.456-460.

Orlady, H.W., and Orlady, L.M. (1999). Human factors in multi-crew flight operations. Ashgate: Aldershot, UK.

PARC/CAST Flight Deck Automation Working Group. (2013). Operational use of flight path management systems. US Federal Aviation Administration.

Staal, M.A. (2004). Stress, cognition, and human performance: A literature review and conceptual framework. NASA/TM-2004-212824, NASA Ames Research Centre, Moffett Field, CA.

UK Civil Aviation Authority. (2013). Monitoring matters: Guidance on the development of pilot monitoring skills. Loss of Control Action Group, CAA Paper 2013/02, West Sussex, UK.

Wickens, C.D., and Hollands, J.G. (2000). Engineering psychology and human performance (Third edition). Prentice Hall: New Jersey, US.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to PT Indonesia AirAsia, the aircraft flight crew, Airservices Australia, the Civil Aviation Safety Authority, Airbus and the French Bureau d'Enquêtes et d'Analyses pour la sécurité de l'aviation civile.

Submissions were received from PT Indonesia AirAsia, Airservices Australia, the Civil Aviation Safety Authority, Airbus and the French Bureau d'Enquêtes et d'Analyses pour la sécurité de l'aviation civile. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Safety analysis

During the flight, the captain’s flight management guidance computer (FMGC1) failed. The flight crew’s response to this and their utilisation of FMGC1 during the runway 21 instrument landing system (ILS) approach, resulted in an unexpected increase in engine thrust and subsequent go-around. After conducting the go-around, they were required to change runways due to increased crosswind and conduct a VHF Omni Directional Radio Range (VOR) approach onto runway 06. During this VOR approach, air traffic control (ATC) received a minimum safe altitude warning, prompting the controller to alert the crew of their low altitude and instructed them to conduct a go-around. Subsequently, the flight crew made another approach for runway 06 and the aircraft landed safely.

The following analysis discusses the crew’s understanding and management of the FMGC failure, their systems knowledge, and the human performance factors that affected the management of the approaches, which resulted in two go-arounds.

Crew response to the flight management guidance system failure

During the cruise, when the captain identified that his multipurpose control and display unit (MCDU1) had frozen and the navigation display (ND) map became unavailable, the flight crew correctly identified an FMGC1 failure. However, they could not locate any information about how to resolve it in the aircraft’s manuals. Had they found the MCDU and FMGC reset procedures in the Quick Reference Handbook (QRH), the crew may have been able to rectify the failure. This would have provided normal operation of the captain’s navigation display ND and MCDU. With an operational MCDU, the captain would have been able to input the approach and aerodrome data into the FMGC1 and the unexpected increase in engine thrust would not have occurred.

Additional information on the failure mode was available in the Flight Crew Operating Manual (FCOM), but the flight crew did not find this information in that manual. The investigation was unable to determine why the crew did not locate the relevant information. This failure to find and action the QRH and FCOM, meant the aircraft systems remained degraded for the rest of the flight.

Understanding of system interactions and subsequent crew decision making during the runway 21 ILS approach

The flight crew discussed the FMGC1 failure during their first approach briefing and decided to use the first officer’s functioning MCDU (MCDU2) and ND on the descent. Because the crew had not previously found the information in the FCOM relating to the failure, they did not understand how it could affect the interactions between the aircraft systems and hence the conduct of the descent. They were therefore unaware that both autopilots, and in particular autopilot 1 (AP1), should not have been engaged during the instrument approach. The reason for not engaging AP1 was that FMGC1 took primacy over the first officer’s FMGC (FMGC2) when both autopilots were used and the data in FMGC1 had frozen at the time of failure.

When the flight crew engaged AP1 during the first approach, they did not recognise that the subsequent cabin pressure fault was related to the engagement of AP1 and its utilisation of FMGC1 data. Additionally, the crew did not realise that the FMGC1 target speed at the time of failure (253 kt) would be utilised when the speed mode was changed from a selected mode (which had a target speed of 160 kt at the time), to a managed mode after AP1 was engaged.

The issue of flight crew understanding systems interactions is not limited to this occurrence. In response to the increase in incident and accident reports of flight crew experiencing difficulties using flight path management systems, a United States Federal Aviation Administration-led Flight Deck Automation Working Group analysed several data sources to produce findings and recommendations for the use of automation on modern flight decks. The working group found that operators had concerns with the level of flight crew skills required for managing automated system malfunctions and/or failures. The working group was cognisant that it was impossible to train pilots in all possible malfunction situations or failure scenarios. They stated that pilots needed to be prepared to recognise the results of partial and complete system failures and intervene appropriately (PARC/CAST Flight Deck Automation Working Group, 2013).

Crew’s understanding of systems interactions and dual control inputs

In this case, the flight crew’s lack of understanding of how the systems interacted led to inappropriate system selections and resulted in the increase in engine thrust. Although the failure of FMGC1 had not been resolved by the flight crew prior to the aircraft commencing descent, FMGC2, MCDU2, autopilot 2 (AP2) and engine autothrust were all capable of normal operation and could have been used to complete the approach normally.

Although the flight crew elected to conduct a go-around when the engine thrust unexpectedly increased, there was a period of 25 seconds where dual sidestick control inputs occurred, prior to the captain taking over control of the aircraft. These dual control inputs indicate a level of confusion and lack of communication regarding conduct of the go-around and about which pilot was in control of the aircraft. There were other instances of dual control inputs of short duration (less than 5 seconds). While these inputs did not affect the flight, there have been other instances where sustained dual control inputs have had a detrimental effect on the control of the aircraft.

Reaction to automation functionality and decision making

Following the go-around and without understanding the reason for the increase in engine thrust or the effect the FMGC1 failure had on the system, the flight crew briefly re-engaged AP1. Due to doubts about the functionality of the automation, the captain then elected to reduce the level of automation, and manually fly the aircraft. This decision presented as being intuitively derived from patterns of behaviour the captain had used successfully in the past. The decision had the effect of removing the potentially problematic automation, but it also increased the crew’s workload.

Researchers (Klein 2008, Kahneman, 2011) have stated that, in time-constrained environments, individuals can make decisions using intuitive reasoning where the steps are often unconscious and based on pattern recognition. For intuitive or naturalistic decision-making, an experienced individual will identify a problem situation as similar or familiar to a situation they have dealt with before and will extract a plan of action from memory. If time permits, they will confirm their expectations prior to initiating action. If time does not permit, actions will need to be initiated with uncertainty that may result in a poor decision.

Crew workload after the initial go-around

Workload has been defined by Orlady and Orlady (1999) as:

…reflecting the interaction between a specific individual and the demands imposed by a particular task. Workload represents the cost incurred by the human operator in achieving a particular level of performance (p.203).

The available cognitive resources are finite and will vary depending on the experience and training of the individual as well as the level of stress and fatigue experienced. Workload is managed by balancing task demands such that, when workload is low, tasks are added and when workload becomes excessive, tasks are shed (Orlady and Orlady, 1999). Tasks, such as internal and external communication, can be shed in an efficient manner by eliminating low priority tasks or they can be shed inefficiently by abandoning important tasks. The task demands can be influenced by the mental and physical requirements of the task, as well as the time available (Wickens and Hollands, 2000).

Factors increasing crew workload

After the first approach, the flight crew’s workload increased substantially with the following conditions:

  • although the engine autothrust, AP2 and FMGC2 were still operating normally, the crew became uncertain about the automation’s functionality and elected to manually control the engine thrust and fly the aircraft using raw data.
  • the crew had limited experience, outside of simulator sessions, flying approaches manually.
  • the turbulent conditions increased the attention required by the captain to maintain desired heading, pitch attitude and airspeed.
  • the unexpected runway change meant the crew needed to program the approach into the first officer’s MCDU, review the approach and conduct a briefing prior to the approach.
  • the unexpected runway change and reduced timeframes limited the time available for the crew to review the approach charts.
  • the captain’s ND was still in operating in a degraded mode and was not displaying lateral tracking guidance for the VOR approach nor the information from the distance measuring equipment (DME). For that information, the captain needed to refer to the first officer’s ND on the other side of the cockpit instrument panel.
  • the captain’s flight director (FD) was still referencing the frozen FMGC1 and was not providing valid FD attitude guidance targets.
  • while the crew were experienced in flying non-precision VOR approaches, they had limited experience flying the Perth runway 06 VOR approach at night. The first officer reported never having flown the approach before.

Recorded data indicates that there was 8 minutes from making the decision to conduct the VOR approach to when the flight crew confirmed they were established on the approach, at 10 NM. The limited time available to prepare for the approach, combined with the degraded systems, would have further increased their workload.

Effect of increased workload

Workload and time pressure can lead to a reduction in the number of information sources an individual may access, and the frequency or duration of time these sources are checked (Staal, 2004). Amongst other effects, a high workload can result in individuals not understanding the implications of the information they are presented with.

In this occurrence, the captain’s workload was increased due to the decision to hand-fly the aircraft using the first officer’s ND for lateral tracking guidance and distance information during the VOR approaches. This increased workload made it more likely that, in the visual conditions, he would try and continue the approach using external visual reference.

The flight crew’s workload impacted their ability to manage the approaches and was evidenced by the shedding of tasks, such as:

  • reviewing the approach charts,
  • monitoring of the flight profile,
  • descending the aircraft without confirming the aircraft position,
  • neither crew member observing the DME distance,
  • breakdown in the crews’ use of standard operating procedures, such as selecting altitudes other than the missed approach altitude on the flight control unit, while conducting the non-precision instrument final approach.

Had the flight crew elected to hold and prepare prior to conducting the approach, they may have reduced their workload, improved their preparations and conducted a thorough briefing prior to conducting the unfamiliar approach.

Preparation and conduct of the first runway 06 VOR approach

During the first runway 06 VOR approach, the flight crew’s focus of attention was outside the aircraft, attempting to locate the runway. Although the crew were conducting the instrument approach in visual conditions, more attention should have been given to maintaining the aircraft on the prescribed instrument approach flight path profile, until reference was made to the runway landing environment and/or the instrument approach was discontinued. The following content explains how the crew's ability to monitor and maintain the correct flight profile and altitude during the approach was likely hindered. This resulted in the aircraft descending below the specified minimum safe altitude without being detected by the crew.

Crew focus of attention

The captain could not identify the runway and requested assistance from the first officer. Both flight crew then focused on locating the runway, with neither appearing to monitor the aircraft’s flight profile. The crew first became aware of the altitude constraint and that the aircraft had descended below it when advised by ATC. This indicates that both crew were distracted and neither was monitoring the approach at this time. Further indications that the crew was distracted from monitoring the approach included:

  • the captain took the first officer’s question about when to initiate descent as a prompt to descend without confirming the aircraft’s position.
  • the lack of detection that the aircraft was descended early.
  • the first officer thought aircraft was on correct profile because he observed an appropriate initial descent rate.
  • the descent rate increased substantially above that necessary for a 3-degree approach.
  • neither crew member observed the DME distance, after initiation of descent.
  • the first officer could not recall communicating altitude or distance information during the approach.
Crew ability to monitor the approach

Monitoring is an extensive set of behavioural skills that all flight crew are expected to have. This skill set is specified in the aircraft operator’s standard operating procedures and involves the primary roles of monitoring the aircraft’s flight path, communications and the activities of the pilot flying. The UK Civil Aviation Authority (UK CAA) (2013) has defined monitoring as:

The observation and interpretation of the flight path data, configuration status, automation modes, and on-board systems appropriate to the phase of flight. It involves a cognitive comparison against the expected values, modes, and procedures. It also includes observation of the other crew member and timely intervention in the event of deviation. (p.9)

The difficulties that flight crew have with maintaining effective monitoring are thought to be due to not directly controlling the system being monitored. Humans are inherently poor at maintaining vigilance for infrequent events and equipment failures in modern airline operations are rare. Flight crew rarely receive direct feedback on the effectiveness or consistency of their monitoring unlike the feedback they would receive when they may fly an aircraft manually (UK CAA, 2013).

Researchers (Dismukes & Berman, 2010) found that in most instances where flight crew were failing to monitor the aircraft state or position, there were competing concurrent task demands on the crew’s attention. Humans have a limited ability to divide attention amongst tasks and generally, have to switch attention back and forth between tasks. This leaves an individual vulnerable to losing track of the status of one task while being engaged in another.

Other factors affecting awareness of the flight profile

Believing they were on the correct profile, based on the vertical speed the first officer observed early in the descent, combined with the night conditions, and unfamiliarity with the approach reduced the visual cues outside of the cockpit available to the crew regarding the aircraft’s position. The reduced external visual cues along with the crew not utilising the available internal visual cues, such as the course deviation indicator, distance information and multifunction display, led to the crew not understanding where they were on the flight profile or where they were with respect to the runway.

Communication during the approach

The flight crew missed opportunities to identify the early descent, higher than normal rate of descent and descent below the segment minimum safe altitude because they were focused outside the cockpit rather than monitoring their primary flight instruments. The first officer did not provide the captain with the standard altitude and distance callouts, nor with an alert about the rate of descent, which resulted in the aircraft flying below the flight profile. This potentially reduced the captain’s awareness of the deviations from the standard approach and limited his ability to correct it. That communication was particularly important given that the crew had not optimised the aircraft’s remaining systems, with the captain attempting the approach without his ND and FD attitude guidance targets on his primary flight display.

Preparation and conduct of the second runway 06 VOR approach

During the vectoring for the second runway 06 VOR approach, the captain took on the pilot monitoring role. This gave the captain the opportunity to review the approach data and familiarise himself with the required flight profile. The captain returned to the role of pilot flying soon after the initial approach fix and elected to obtain visual contact with the runway prior to initiating the descent. Due to the late descent, the aircraft’s rate of descent was greater than 1,200 ft/min for a period of the approach (although it was stabilised by 1,000 ft).

Due to the captain manually controlling the engine thrust and the turbulence, the engine thrust was briefly at idle at about 300 ft above ground level, which did not meet the stabilised approach criteria and was coincident with an increasing rate of descent. Unstable approaches are known to increase risks in landing, although in this instance the landing was completed without further incident.

Appendices

Appendix A – Runway 21 ILS approach, aircraft track and flight data

Figure A1: Runway 21 ILS approach with aircraft track (blue)

Figure A1: Runway 21 ILS approach with aircraft track (blue)

Source: Naviga (modified by the ATSB)

Figure A2: Flight data showing autopilot and mode selections with a resulting thrust and speed increase during the runway 21 ILS approach. The descent depicted is from 3,000 ft to 2,000 ft.

Figure A2: Flight data showing autopilot and mode selections with a resulting thrust and speed increase during the runway 21 ILS approach. The descent depicted is from 3,000 ft to 2,000 ft.

Note:

1. At 2143:04 AP1 was engaged

2. At 2144:37 the auto speed was changed to a managed mode resulting in an increase in the target airspeed (to 253 kt)

3. At 2144:51 the go-around was initiated

Source: ATSB

Appendix B – First runway 06 VOR approach, aircraft track and flight data

Figure B1: First runway 06 VOR approach with aircraft track (blue) and approximate location of go-around (red cross)

Figure B1: First runway 06 VOR approach with aircraft track (blue) and approximate location of go-around (red cross)

Source: Naviga (modified by the ATSB)

Figure B2: Flight data from first runway 06 VOR approach from 2,500 ft to 1,473 ft

Figure B2: Flight data from first runway 06 VOR approach from 2,500 ft to 1,473 ft

Note:

1. At 2200:45 descent initiated

2. At 2201:57 the go-around was initiated, at an altitude of 1,473 ft

The target CAS is the speed target that would appear on the speed tape of the primary flight display.

Source: ATSB

Appendix C – Second runway 06 VOR approach, aircraft track and flight data

Figure C1: Second runway 06 VOR approach with aircraft track (blue)

Figure C1: Second runway 06 VOR approach with aircraft track (blue)

Source: Naviga (modified by the ATSB)

Figure C2: Flight data from second runway 06 VOR approach from 2,500 ft to landing

Figure C2: Flight data from second runway 06 VOR approach from 2,500 ft to landing

Note:

1. At 2215:20 descent was initiated, at about 5 DME

Source: ATSB

Safety issues and actions

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out.

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence

As a result of this occurrence, PT Indonesia AirAsia have taken the following proactive safety action:

  • Implemented additional classroom sessions on aircraft line-check into the re-training program.
  • Incorporated the incident as a subject of the SPOT (Special Orientation Training) in the simulator syllabus.

Findings

From the evidence available, the following findings are made with respect to the operational event involving an Airbus A320, registered PK-AXY and operated by PT Indonesia AirAsia that occurred 17 km west-south-west of Perth Airport, Western Australia on 19 February 2016. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • The flight crew’s diagnosis of the captain’s failed flight management guidance computer was accurate, but after they did not find the procedure to follow, the failure was not appropriately managed. This resulted in degraded systems capability for the approach.
  • The flight crew had a limited understanding of how the captain’s failed flight management guidance computer would affect the use of the aircraft’s automated systems during the instrument landing system approach. This meant that their decision to engage autopilot 1 resulted in the frozen data stored in the failed guidance computer being utilised by the auto flight system, leading to an unexpected increase in engine thrust and prompted the crew to conduct a missed approach.
  • The unresolved system failures, combined with the conduct of a missed approach procedure and the subsequent runway change increased the flight crew's workload. This likely reduced their ability to analyse the actual extent to which their automation was degraded, and effectively manage the subsequent approaches.
  • During the first runway 06 non-precision approach, the flight crew’s focus of attention was outside the aircraft, attempting to locate the runway. This distraction, along with their unfamiliarity with the approach procedure, inhibited their ability to monitor and maintain the correct flight profile and altitude during the approach. The flight crew did not detect that the aircraft had descended below the segment minimum safe altitude for that stage of the approach.

Other safety factors

  • During the flight, multiple dual control inputs occurred, which in other circumstances have resulted in aircraft responding in an unexpected manner.
  • The aircraft's flight path profile was not adequately monitored or communicated between the flight crew during the non-precision instrument approaches to runway 06. This reduced the captain’s awareness of any deviation from the prescribed approach and limited his ability to correct it.
  • The second runway 06 non-precision instrument approach did not meet the stabilised approach criteria for a short period during the final approach, increasing the safety risk of the landing.

The occurrence

On the evening of 19 February 2016, an Airbus A320 aircraft, registered PK-AXY and operated by PT Indonesia AirAsia was on a scheduled passenger service from Denpasar, Indonesia to Perth, Australia. The aircraft was operated by two flight crew, four cabin crew and carried 96 passengers.

For the flight to Perth, the captain was the pilot flying (PF), with the first officer the pilot monitoring (PM).[1] A late requirement to change aircraft delayed the departure of the flight by 2 hours and the updated arrival time into Perth was estimated to be about 2130 Australian Western Standard Time.[2]

Departure and cruise

On departure from Denpasar Airport, the aircraft climbed to the cruise altitude of FL 370.[3] The flight proceeded normally until the aircraft was just over an hour from Perth when, at approximately 2024, the crew noticed that the captain’s multipurpose control and display unit (MCDU1)[4] had frozen and the captain’s navigation display (ND)[5] had the advisory message MAP NOT AVAIL. In addition, the first officer’s MCDU (MCDU2) displayed the message INDEPENDENT OPERATION, which indicated to the crew that the captain’s flight management and guidance computer (FMGC1)[6] had failed. Figure 1 depicts the location and interaction between the various equipment.

Figure 1: Schematic of A320 cockpit, depicting the location and interaction between various equipment

Figure 1: Schematic of A320 cockpit, depicting the location and interaction between various equipment

Source: Airbus Flight Crew Operating Manual

At the time of the FMGC1 failure, flight data indicated the aircraft was flying at a calibrated airspeed of 253 kt. A short time later, the captain recalled disengaging autopilot 1 (AP1)[7] and engaging autopilot 2 (AP2).

The flight crew reported that in an attempt to resolve the issues associated with the frozen MCDU1 screen and apparent FMGC1 failure, they referred to the Quick Reference Handbook (QRH) and the Flight Crew Operating Manual (FCOM) but they determined that there was no specific action for the failures. Instead, as the first officer’s FMGC (FMGC2) appeared to be operating normally, they decided to continue to Perth using his ND and MCDU, because these utilised the functioning FMGC. At 2040, about 15 minutes after the failure occurred, the crew climbed the aircraft to FL 380. The remaining 30 minutes of the cruise was uneventful.

Pre-descent planning and approach

Prior to the descent, the flight crew reviewed and briefed the approach altitude minima, planned arrival route, weather, go-around procedures, as well as conducting other normal pre-descent activities. For the aircraft’s arrival in Perth, moderate to severe turbulence was forecast below 3,000 ft, with visibility greater than 10 km and no significant cloud below 5,000 ft. As the crew had not identified any specific procedure for managing the FMGC failure, and the first officer’s duplicate systems appeared to be operating normally, his MCDU was used to program the arrival procedure and instrument landing system (ILS)[8] approach. The crew briefed that the first officer would take over as PF during the approach, as they believed it was better for the PF to have the functioning ND and MCDU.[9] The crew later reported that they did not identify or conduct further investigation to determine how the FMGC failure may affect continued flight operation or the conduct of the approach.

At about 2115, the flight crew commenced descent into Perth to conduct the JULIM 2A standard instrument arrival[10] and ILS approach to runway 21.[11] As the aircraft descended through 9,000 ft, the captain took over the role of PM while the first officer became PF.

The flight crew selected managed lateral and vertical descent modes[12] with AP2 selected. At about 2140 while descending through 5,000 ft, the crew received the first of three speed restrictions from air traffic control (ATC), which required a change from a managed speed mode to a selected speed mode,[13] to control the aircraft’s speed.

At about 2143, with the approach mode armed, the flight crew engaged AP1 and received a CAB PR LDG ELEV warning.[14] The warning was a result of engaging AP1 with an inoperative FMGC1.[15] This was because with both autopilots engaged, FMGC1 took precedence over FMGC2. The data programmed into FMGC1 at that time did not include the landing and approach data required for the aircraft’s flight management system to determine the cabin’s pressurisation schedule for the descent and landing. To resolve the cabin pressure warning, the crew set the cabin pressure to manual and continued the approach.

ILS approach to runway 21 and go-around

See Figure 2 for a profile view of the runway 21 ILS approach. At about 2144, the aircraft intercepted the localiser and the glideslope for the runway 21 ILS (Appendix A contains the aircraft track overlaid on the approach chart along with the flight data for the approach). At 2144:38, after reducing the aircraft’s selected speed to 160 kt and establishing the aircraft on the ILS, the selected altitude on the flight control unit (FCU)[16] was set to the go-around altitude, consistent with the operator’s standard operating procedure. A short time later, the flight crew elected to select a managed speed mode. This change resulted in the auto flight system attempting to capture the speed target contained in FMGC1 when it failed (which was 253 kt) and the autothrust system commanded an increase in engine thrust.

The flight crew recognised the increasing engine thrust and airspeed but they did not understand why it occurred. The captain told the first officer, ‘make a go-around’[17] and then advised ATC that they were conducting a go-around. From 2144:57, there was a period of 25 seconds where dual sidestick control inputs occurred. During this time, the autopilot automatically disengaged and the captain disconnected the autothrust system.[18] The recorded data indicated that neither the captain nor first officer pressed the priority takeover button[19] during this period. The captain recalled that at about 2,500 ft, at the flap 0 speed, he stated ‘okay, my control’ and took over as PF with the first officer taking the PM responsibilities. Recorded data indicates the captain had sole control of the aircraft at 2145:24, at an altitude of about 2,500 ft.

Figure 2: Profile view of the runway 21 ILS approach with aircraft flight profile (blue). The aircraft was on the ILS profile until the increase in engine thrust and go-around

Figure 2: Profile view of the runway 21 ILS approach with aircraft flight profile (blue). The aircraft was on the ILS profile until the increase in engine thrust and go-around

Source: Naviga (modified by the ATSB)

After the go-around and vectoring for the runway 06 VOR approach

After taking control of the aircraft, the captain reconnected the autopilot and autothrust. The recorded flight data indicates that the AP1 was engaged for 12 seconds, with the autothrust engaged and active for 10 seconds. The captain then decided to disconnect the autothrust to manually fly the aircraft, due to his uncertainty over the thrust increase during the previous approach and failure of FMGC1. The recorded data indicates that when the autothrust was disconnected the thrust lever was below the climb detent. This positioning of the thrust lever meant that it was unlikely the flight crew received a thrust lock (further information is provided in the Autothrust system sub-section in the Context).

At 2146, the first officer requested ATC provide radar vectors for another ILS approach to runway 21. ATC provided radar vectoring and issued clearance for the approach. However, about 4 minutes later, ATC advised the flight crew that the crosswind for runway 21 had increased to 22 kt, with gusts to 25 kt. Due to the increased crosswind, ATC offered the crew the option of conducting a VHF Omni Directional Radio Range (VOR)[20] approach and landing on runway 06.[21] At 2152, after confirming the crew’s preference to land on runway 06, ATC vectored them to the final approach track to conduct the VOR approach.[22] The captain considered there was sufficient time to prepare for the approach, so did not perceive a need to enter a holding pattern to complete the briefing. At 2156, ATC informed the crew that a new ATIS was current and that there was moderate to severe turbulence below 3,000 ft.

The first officer later recalled programming FMGC2 for the VOR approach, and briefing the captain for the approach. The first officer also cross-referenced the information in the FMGC with his paper copy of the instrument approach chart. The captain stated that they conducted a short briefing instead of a full briefing because the situation was moving so quickly.

VOR approach to runway 06 and subsequent go-around

At 2200, ATC asked the flight crew twice if they were established on the 248 radial (which was the inbound track for the VOR procedure) and the first officer responded that they were 10 NM from the runway. ATC again asked the crew to confirm they were established, and the first officer replied stating, that they were ‘established on the inbound radial 068’.[23] In response, ATC cleared the crew to conduct a VOR runway 06 approach, with 10 NM to touchdown. Shortly after, the captain recalled the first officer asking, ‘do we descend now captain?’ In response, captain initiated a descent from 2,500 ft when the aircraft was at 9 DME[24] (Figure 3). Soon after, the landing gear was extended and the first officer selected 1,600 ft on the FCU for the next descent altitude limit. However, the operator’s Flight Crew Training Manual (FCTM) required that the go-around altitude be set on the FCU when established on final approach.[25] Coincidentally, 1,600 ft was the corresponding segment minimum safe altitude for the runway 03 VOR approach, whereas the published altitude for that stage of the runway 06 approach was 1,900 ft.

The captain elected to continue manually flying the aircraft using his primary flight display (PFD) and the first officer’s ND, and manually controlling the engine thrust due to the apparent automation failures. The first officer continued to monitor the descent gradient and vertical speed, and later recalled believing that they were on the correct descent profile. However, for most of the descent, the aircraft’s rate of descent exceeded the recommended rate (700 ft/min) that was published on the approach chart for the aircraft’s groundspeed. The maximum recorded rate of descent briefly reached 1,550 ft/min.

As the approach continued, the flight crew became concerned that they could not see the runway, and both crew became focused on locating the runway. The first officer later reported that because of this, he was no longer monitoring the approach segment minimum safe altitude constraint or was aware of the aircraft’s below flight path deviation during the descent. Although the FCU altitude was set to 1,600 ft, the autopilots were not engaged and the aircraft descended through the selected altitude without capturing the target altitude.

To assist in locating the runway, the first officer asked ATC if they were on the ‘left side of the runway or right side of the runway’. At about the same time, the ATC radar displayed a minimum safe altitude warning (MSAW). In response, the approach controller instructed the flight crew to ‘go round, you are low, low altitude alert, go round’. The flight crew acknowledged the alert and immediately conducted a missed approach. The aircraft had descended to an altitude of 1,473 ft, before the climb was initiated, which was about 400 ft below the segment minimum safe altitude (Figure 3). Aircraft track and flight data for the approach is available in Appendix B.

Figure 3: Profile view of first runway 06 VOR approach with aircraft flight profile (blue). The flight profile shows the crew descending the aircraft below the 2,500 ft segment minimum safe altitude and continuing below the 1,900 ft segment minimum safe altitude before conducting a go-around.

Figure 3: Profile view of first runway 06 VOR approach with aircraft flight profile (blue). The flight profile shows the crew descending the aircraft below the 2,500 ft segment minimum safe altitude and continuing below the 1,900 ft segment minimum safe altitude before conducting a go-around.

Source: Naviga (modified by the ATSB)

Preparation and conduct of the second runway 06 VOR approach

After completing the go around, ATC radar vectored the flight crew for another VOR approach for runway 06. At around 2204, while the aircraft was being radar vectored, the captain requested that the first officer take over as PF so he could review the approach chart.

At about 2208, the flight crew engaged the autothrust. It remained engaged and active for about 4 minutes, before the FCU autothrust pushbutton was pressed at 2212 and the thrust lock became active until the thrust levers were moved from the climb detent.[26] The crew re-engaged the autothrust about a minute later, and it remained active for 25 seconds before being disengaged, again via the FCU autothrust push button and resulting in a second thrust lock. The crew again moved the thrust levers clearing the thrust lock warning. The crew did not re-engage the autothrust for the remainder of the flight.

During the second VOR approach while the first officer was the PF, there were four occasions where the captain made sidestick control inputs. These inputs were between 2 and 3 seconds in duration and the recorded data indicates that they were not sufficiently large to activate the dual input alert. Neither of the flight crew could recall why the dual inputs occurred.

At about 2212, the captain requested ATC turn on the high intensity lighting on runway 06 as they were still having difficulty seeing the runway. ATC responded that there were no high intensity runway lights for that runway. At 2214, when the aircraft was at an altitude of 2,500 ft, inbound on the final approach track of the VOR and at about 8 DME, the captain took over as PF and the first officer resumed the PM role. At about the same time, ATC asked the crew if they had the runway in sight and informed them that the tower had increased the runway lighting intensity. Approaching 6 DME, the flight crew selected the FCU altitude to the minimum descent altitude for the VOR approach, again contrary to the operator’s procedure for conducting a non-precision instrument approach. The captain confirmed to ATC that the runway was in sight, and at about 5 DME, initiated descent from 2,500 ft to land on runway 06 (see Figure 4 for the profile view of their second approach to runway 06).

Due to the late commencement of the descent from 2,500 ft, the aircraft exceeded the recommended rate of descent (700 ft/min) for the aircraft’s groundspeed until 1,100 ft above the height of the runway threshold. In addition, the aircraft’s rate of descent was greater than 1,200 ft/min[27] for a period of 40 seconds, from an altitude of about 2,100 ft to 1,200 ft. In this period, the rate of descent averaged 1,380 ft/min. When the aircraft was 1,000 ft above the height of the runway threshold, the rate of descent was below 700 ft/min. For a period of 22 seconds, from 430 ft to 120 ft above ground level (AGL), the aircraft’s vertical speed exceeded 700 ft/min and increased to a maximum of 1,100 ft/min. As this decent rate was below 1,200 ft/min, it did not require a callout by the first officer. At 300 ft AGL, the engine thrust reduced briefly to idle and at this point, the aircraft did not meet the stabilised approach criteria. Aircraft track and flight data for the approach is available in Appendix C.

Recorded flight data indicated dual sidestick control inputs occurred, one at 300 ft AGL for one second, then three times from 120 ft AGL until landing with durations of 3 to 5 seconds, these inputs would have resulted in a dual control input alert. However, the aircraft landed without further incident.

Figure 4: Profile view of second runway 06 VOR approach with aircraft flight profile (blue)

Figure 4: Profile view of second runway 06 VOR approach with aircraft flight profile (blue)

Source: Naviga (modified by the ATSB)

__________

  1. Pilot flying (PF) and Pilot monitoring (PM) are procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as when planning for the descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and aircraft flight path.
  2. Australian Western Standard Time (AWST) was Coordinated Universal Time (UTC) +8 hours.
  3. At altitudes above 10,000 ft in Australia, an aircraft’s height is measured in hundreds of feet above the standard atmospheric pressure datum of 1013.25 hPa. A height 37,000 ft above that standard pressure datum would be expressed FL 370.
  4. The MCDU is used by the flight crew to enter flight planning into the flight management guidance system and can also display various flight navigation information.
  5. The ND is a flight deck information display that is part of the electronic flight instrument system which displays a selected navigation information to the flight crew.
  6. The FMGC provides aircraft navigation, lateral and vertical guidance and aircraft performance functions along a pre-planned flight route.
  7. AP1 utilises data from FMGC1.
  8. A standard ground aid to landing, comprising two directional radio transmitters: the localizer, which provides direction in the horizontal plane; and the glideslope, for vertical plane direction, usually at an inclination of 3°. This is a type of precision approach procedure, designed for 3D instrument approach operations.
  9. It would have been possible for the captain’s ND to mirror the first officer’s, if their ND range and mode settings were the same.
  10. A designated arrival route that links a significant point along the planned route to a point from which a published instrument approach procedure can be commenced.
  11. Runway 21 was a precision approach runway, equipped with a category I ILS and visual approach aids.
  12. Managed modes: When the aircraft is using managed targets, the Flight Management and Guidance System (FMGS) guides it along lateral and vertical flight paths and speed profiles computed by the Flight Management function (FM) from data in the MCDU. FM manages the guidance targets.
  13. Selected modes: When the flight crew is using selected targets, the FMGS guides the aircraft along lateral and vertical flight paths and speed profiles to meet targets that the flight crew has selected manually on the FCU. The flight crew selects the guidance targets.
  14. This warning indicates that the elevation of the landing airport is not available from the FMGC and consequently, the landing elevation must be manually selected.
  15. With a single autopilot engaged the on-side FMGC is master. With both autopilots engaged, FMGC1 is master.
  16. Flight control unit: Located on the cockpit glareshield and is the short-term interface between the flight crew and the FMGC. It is used to modify flight parameters and engage or disengage the autopilot and autothrust functions. Different guidance modes can be selected to change various targets (speed, heading, track, altitude, flight path angle and vertical speed).
  17. A manoeuvre in which the flight crew discontinues the approach, increases engine thrust and reconfigures the aircraft to climb.
  18. The autothrust was disconnected via the instinctive disconnect pushbutton on the thrust lever.
  19. See further details in REF _Ref458419455 \h \* MERGEFORMAT Handover/takeover procedures section.
  20. A ground-based navigation aid that emits a signal that can be received by appropriately-equipped aircraft and represented as the aircraft’s bearing (called a 'radial') to or from that aid.
  21. Runway 06 was a non-precision approach runway, equipped with visual approach aids and a navigation aid at the airport provided directional guidance to complete a straight-in approach.
  22. This was a non-precision approach procedure, designed for 2D instrument approach operations.
  23. To fly inbound towards the VOR on the 248° radial, the crew needed to select 068° on the omni bearing selector.
  24. Distance Measuring Equipment (DME) is a ground-based transponder station. A signal from an aircraft to the ground station is used to calculate its distance (in nautical miles) from the ground station.
  25. This procedure was stipulated to avoid any unwanted autopilot capture of the selected target altitude.
  26. See REF _Ref499907660 \h \* MERGEFORMAT Types of dual control inputs section for further information on the thrust lock condition and how crew are to respond to it.
  27. During the final approach, the PM was required to call out ‘sink rate’, when the descent rate exceeded 1,200 ft/min.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2016-012
Occurrence date 19/02/2016
Location near Perth Airport
State Western Australia
Report release date 16/01/2018
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Flight below minimum altitude
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Airbus
Model A320
Registration PK-AXY
Serial number 5359
Aircraft operator PT. Indonesia AirAsia
Sector Jet
Operation type Air Transport High Capacity
Departure point Denpasar, Indonesia
Destination Perth, WA
Damage Nil

Incorrect configuration leading to a collision with terrain involving Cessna R182, VH-PFZ, 58 km south-west of Ingham ALA, Queensland, on 14 February 2016

Final report

What happened

On 14 February 2016, at about 0945 Eastern Standard Time (EST), the pilot of a Cessna R182 aeroplane, registered VH-PFZ, was returning to a private airstrip near Ingham aircraft landing area (ALA), Queensland. The pilot, who was the only person on board, had just completed a routine one-hour property inspection and decided to complete the flight with some practice touch and go circuits.

The pilot reported that the weather was fine, with minimal wind and a temperature of about 30 °C.

The pilot approached the circuit with the aircraft in the same configuration used for the inspection flight. This was with 20 inches of manifold pressure, the propeller set at 2,000 revolutions per minute (RPM), and the landing gear retracted.

The pilot joined downwind for runway 22 as per their normal procedure, and conducted their downwind checks. However, they inadvertently omitted one of the checks. Although they extended the landing gear, they did not return the pitch control to the HIGH RPM (full fine) position. The pilot continued with the approach, and selected full flap, but again omitted the pre-landing checks on final approach. This oversight left the pitch control lever at about 2,000 RPM.[1]

The pilot described the approach and initial touchdown as a little faster and higher than normal, with the touchdown point about 300 m into the 1,100 m airstrip (Figure 1).The aircraft ballooned slightly. At about 10-15 ft above ground level, the pilot commenced a go-around and applied full throttle, with the propeller remaining at 2,000 RPM. With an airspeed of 64 kt, the pilot assessed there was sufficient airspeed to climb out, so retracted all of the flap and then the landing gear.

Figure 1: Initial touchdown point on runway 22, and VH-PFZ (far end)

Figure 1: Initial touchdown point on runway 22, and VH-PFZ (far end)

Source: Pilot

However, the aircraft began to sink, and the nose dropped. Moments later, the main landing gear struck the ground. This second ‘touchdown’ was about 265 m beyond the first, (about 565 m along the airstrip). The pilot attempted to keep the nose of the aircraft raised. However, the propeller struck the ground and the pilot realised that the nose wheel had retracted, so closed the throttle. The aircraft continued to skid along the runway. The propeller stopped rotating when the aircraft had travelled about another 77 m. The aircraft then continued to slide sideways, and the right main landing gear retracted (Figure 2). The pilot was not injured, but the aircraft sustained substantial damage.

Figure 2: VH-PFZ showing retracted nose wheel and right landing gear, and damaged propeller

Figure 2: VH-PFZ showing retracted nose wheel and right landing gear, and damaged propeller

Source: Pilot

Pilot experience and comments

The pilot had attained almost 4,000 hours of flight experience, 2,800 of which were in VH-PFZ.

The pilot reported that there had been no particular issues affecting the flight on the day, the weather was good, and the inspection flight had been enjoyable. However, the temperature was 30 °C, which increased the density altitude.[2] The pilot could not attribute any particular reason for the checklist oversight.

The pilot reported that during their early flying training, when they had been training for a go-round, they had been instructed to retract all the flap with their right hand, then immediately move their right hand onto the landing gear selector, and retract the landing gear. The pilot commented that ‘the flap travelling up reduced the lift being produced, and the landing gear retracting reduced the drag. These two actions balance out each other.’ The pilot qualified this statement by stating that this technique should only be attempted once a positive rate of climb has been achieved. On this occasion this had not occurred.

The pilot consulted the aircraft’s performance charts post-accident. With the correct propeller (2,400 RPM) and manifold pressure settings, the aircraft delivers the maximum brake horsepower (BHP).[3] For any of the take-off configurations (see POH data below), it is a requirement to have the propeller in the full fine position of 2,400 RPM. The charts do not cater for propeller settings of 2,000 RPM. The pilot reasoned that landing further along the runway than normal may have contributed to a slight rushing of the go-round sequence. It is possible, that this mindset also contributed to retracting the flap and landing gear prior to achieving a positive rate of climb.

The pilot also reported that possibly being too comfortable in the aircraft, and the reliance on its performance, had created an expectation that all would be well.

The pilot summarised that engine RPM was insufficient to produce enough thrust to maintain altitude and climb at the critical point of change in aircraft configuration, while retracting the flap and landing gear.

Cessna R182 Pilot operating handbook (POH)

Information from a generic 1981 Cessna R182 pilot operating handbook stated that the propeller control should be moved to HIGH RPM (full fine) prior to landing.

The Normal Take-off checklist included:

  • Propeller HIGH RPM (2,400 RPM)
  • Climb speed 70 kt indicated airspeed (KIAS) (Flaps 20°)
  • Climb speed 80 KIAS (Flaps UP).
  • Brakes – APPLY momentarily when airborne
  • Landing gear – RETRACT in climb out
  • Wing Flaps – RETRACT

The Short Field Take-off technique included:

  • Propeller HIGH RPM (2,400 RPM)
  • Climb speed – 59 KIAS until all obstacles are cleared.
  • Landing gear – RETRACT after obstacles are cleared
  • Wing Flaps – RETRACT slowly after reaching 70 KIAS.

ATSB comment

The pilot could not recall any particular reason as to why the pre-landing check (propeller control to HIGH RPM (full fine)) was overlooked on two occasions in the circuit.

Although the aircraft could have landed safely in this configuration, attempting to climb with the propeller still at 2,000 RPM created a chain of events from which the pilot did not recover.

The pilot’s decision to retract the flaps all at once, followed immediately by the landing gear, prior to obtaining a positive rate of climb at a low altitude also decreased the aircraft’s performance. The elevation of the airport was 1,100 ft above mean sea level. This, coupled with a warm day of around 30 °C, translated to a higher density altitude,2 resulting in reduced performance.

Safety message

Although the pilot did not recall any distraction which could have led to the omission of the checklist item on both the downwind and final approach checklists, this omission fits a familiar pattern.

Any change of routine or even cognitive thoughts can distract a pilot from an essential checklist item. Research conducted by the ATSB found that distractions, or a change in routine, were an everyday part of flying, and that pilots generally responded quickly and efficiently. The report, Dangerous Distraction: An examination of accidents and incidents involving pilot distraction in Australia between 1997 and 2004 speaks to these issues.

This research commented that pilot distractions in the study did not always occur in response to non-normal tasks. In fact, the research indicated that distraction can occur when pilots are conducting normal routine tasks.

Aviation Short Investigations Bulletin - Issue 47

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. High RPM (full fine) was 2,400 RPM for that aircraft.
  2. An increased density altitude would have increased the power required and decreased the power available.
  3. BHP is the power developed by the engine

Occurrence summary

Investigation number AO-2016-011
Occurrence date 14/02/2016
Location 58 km south-west of Ingham (ALA)
State Queensland
Report release date 27/05/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model R182
Registration VH-PFZ
Serial number R18201731
Sector Piston
Operation type Aerial Work
Departure point Kangaroo Hill, Qld
Destination Kangaroo Hill, Qld
Damage Substantial

Wirestrike and collision with terrain involving a Robinson R44, VH-HXY, near Townsville, Queensland, on 14 February 2016

Final report

What happened

On 14 February 2016, the pilot of a Robinson R44 helicopter, registered VH-HXY, conducted a local private flight from a property about 90 km north of Hughenden, Queensland.

After operating for about 1 hour, the pilot landed near a water trough to check a float. During the approach and landing, the pilot sighted powerlines strung across the trough, and manoeuvred to remain clear of them.

While the helicopter was on the ground, the wind veered from a south-west to a southerly direction, so that to take off into wind, the helicopter would track perpendicular to the powerlines. After completing the pre-take-off checks, the pilot turned his attention to a mob of cattle, to ensure the noise of the helicopter would not send them through a fence.

The helicopter lifted off initially parallel to the powerlines, and the pilot then turned the helicopter to manoeuvre around a tree and climbed to about 20 ft above ground level. The tree momentarily obscured the powerlines and the pilot’s attention was on the cattle.

As the helicopter rounded the tree, at an airspeed of about 50 kt, the skids struck the powerlines. The pilot heard the wires contact the helicopter and it decelerated rapidly. The pilot lowered the collective[1] and pulled back on the cyclic[2] control, but the helicopter rolled forwards over the wires, descended rapidly, and collided with the ground left side down in a nose-down attitude.

The wire was hooked on the helicopter’s right skid, with electrical power still running through it. After the blades stopped turning, the pilot exited the helicopter. The pilot was not injured and the helicopter was destroyed (Figure 1).

Figure 1: Accident site of Robinson R44 helicopter, registered VH-HXY

rid22-picture-5.png

Source: Helicopter owner

Safety message

ATSB research indicates that in 63 per cent of reported wirestrike incidents, pilots were aware of the position of the wire before they struck it. In this instance, the pilot was aware of the powerline however, they were unable to see the wires from the helicopter’s position on the ground due to a tree. The pilot’s attention was then diverted to the cattle and did not maintain awareness of the wires.

The Aerial Agricultural Association of Australia suggests a way to keep focus is to ask yourself:

  • Where is the wire now?
  • What do I do about it?
  • Where am I in the paddock?

For further risk management strategies for agricultural operations, refer to the Aerial Application Pilots Manual.

The ATSB publication Avoidable Accidents No. 2 – Wirestrikes involving known wires: A manageable aerial agricultural hazard, explains strategies to help minimise the risk of striking wires while flying. Pilots are reminded to avoid unnecessary distractions and to refocus when distracted. Distraction, combined with difficulty in seeing wires makes them extremely hard to avoid at the last minute.

Aviation Short Investigations Bulletin - Issue 47

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. A primary helicopter flight control that simultaneously affects the pitch of all blades of a lifting rotor. Collective input is the main control for vertical velocity.
  2. A primary helicopter flight control that is similar to an aircraft control column. Cyclic input tilts the main rotor disc varying the attitude of the helicopter and hence the lateral direction.

Occurrence summary

Investigation number AO-2016-010
Occurrence date 14/02/2016
Location near Townsville Airport (Boonacarbaroo Station)
State Queensland
Report release date 13/04/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Wirestrike
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Robinson Helicopter Co
Model R44
Registration VH-HXY
Serial number 0350
Sector Helicopter
Operation type Private
Departure point Boonacarbaroo Station, Qld
Damage Destroyed

Wheels up landing involving Nanchang CJ-6, VH-ALO, Barwon Heads Airport, Victoria, on 6 February 2016

Final report

What happened

On 6 February 2016, at about 1250 Eastern Daylight Time (EDT), the pilot of a Nanchang CJ-6 aircraft, registered VH-ALO (ALO), was completing the first in a series of formation ‘combat’ joy flights booked for that day. The ‘combat’ flight, which consisted of a pilot and passenger on board each of two Nanchang aircraft (ALO and Number 2), had departed Barwon Heads airport, Victoria, about twenty-five minutes earlier. The pilot of ALO acted as the leader aircraft (or ‘Number 1’)[1] for the formation flight.

At the chosen ‘break-point’[2] on upwind, Number 2 positioned ahead of ALO in the circuit. The two Nanchang aircraft remained in this single-file sequence behind a Pipistrel aircraft, which had joined the circuit on the downwind leg for runway 36. The Pipistrel aircraft landed, then rolled through to the end of the runway in order to exit; Number 2 followed suit. As ALO touched down, third in a close landing sequence, the pilot realised that they had not completed the pre-landing checks, and the landing gear had not been extended. The aircraft slid along the sealed runway, coming to a stop just off the centreline (Figure 1). The pilot and passenger were not injured, and were able to safely egress. The aircraft sustained damage to the propeller, engine and the underside of the fuselage.

Figure 1: Nanchang VH-ALO, on runway 36 after a wheels up landing

rid24-ao-2016-009-accident-photo.jpg

Source: Pilot

Events leading to the wheels up landing

As the formation joined upwind, the pilot from a parachute aircraft operating at the airport, broadcast that tandem parachutists (student and instructor) had been dropped, and that this parachute aircraft was now conducting a second pass to drop the final student(s).

Figure 2: Barwon Heads airport showing relative positions of the formation, Pipistrel and the drop zone

rid25-ao-2016-009-draft-airport-diagram.jpg

Source: En Route Supplement Australia entry for Barwon Heads; annotated by the ATSB

To avoid any issues for the novice parachute jumpers, and to prevent Number 2 from flying too close to the drop zone in the preferred echelon right,[3] ‘dead side’[4] of the circuit join, the pilot in ALO made the decision that the formation would remain in the echelon left configuration and join over the top of runway 36. At the break point, Number 2 would move ahead, and both aircraft would conduct an early turn onto crosswind. This would keep both Nanchang aircraft well clear of the remaining parachute jumpers approaching the drop zone (Figure 2).

However, while the formation was still on upwind, the pilot of a smaller Pipistrel aircraft broadcast their intention to join the downwind leg for runway 36 (Figure 2), further delaying the Nanchang’s turn onto crosswind. To maintain a reasonable separation from the Pipistrel, the two Nanchang pilots conducted a much wider crosswind leg, and resultant circuit, than normal.

The pilot in ALO continued to check for the remaining parachute jumpers, while broadcasting and responding to pertinent radio reports on behalf of the formation; and also managing the ‘slowing down’ of the formation. Once the Pipistrel has passed abeam the formation’s position, and because the runway at Barwon Heads is too narrow to allow a formation landing, the pilot in ALO instructed the pilot in Number 2 to ‘break’. The landing order became the Pipistrel, followed by Number 2 and then ALO.

The Pipistrel touched down, and took some time to roll through to the only available exit taxiway at the end of runway 36. The pilot in Number 2 requested the pilot in the Pipistrel to expedite the exit, as they wanted to land, but could not land until the Pipistrel was clear of the runway. The pilot in ALO reported keeping a close eye on proceedings in front of their aircraft. This included sideslipping the aircraft to maintain a clear view of the runway movements as the Nanchang has limited vision over the nose at slow airspeeds.

Once Number 2 had landed and cleared the runway, the pilot in ALO reported flaring the aircraft in preparation for landing. It was not until the pilot heard the noise of the aircraft scraping the runway that they realised that the landing gear had not been extended.

Pilot experience and comment

The pilot had around 2,950 flying hours, with about 1,800 of these on Nanchang aircraft.

  • The pilot reported that although feeling relatively fresh on the day, due to other demands, the previous week had been personally ‘full on’ and somewhat draining. This may have had played a small part in the oversight of the downwind and pre-landing checklists.
  • With the combination of the parachute activities, the slower aircraft in the circuit, and the less than optimal echelon left formation configuration, the pilot in ALO reported their attention moved from their own aircraft into the Number 2 aircraft. Still maintaining the duties of Number 1 of the formation, but in the unusual ‘behind’ position, they had checked that Number 2’s landing gear had been extended, and kept a close watch on the spacing of the three aircraft.
  • The pilot reported the Nanchang is always a challenge to slow down until the landing gear is extended. The landing gear can be extended once the airspeed had reduced to 108 knots (usually during the downwind checks). The extension provides sufficient aerodynamic drag to reduce the airspeed closer to the desired approach speed.
  • The pilot reported that it was more common for these combat flights to operate from Moorabbin Airport, where the wider runways allowed a formation landing.
  • These events and conditions, combined with no landing gear warning system being fitted to these early military training aircraft, allowed the pilot’s attention to remain distracted and the landing gear was not selected down.

Safety message

The combination of factors distracting the pilot’s attention during the approach and landing led to the downwind and pre-landing checklists being overlooked. The lack of any landing gear warning system fitted to the aircraft, which would have alerted the pilot to the incorrect configuration, left no protection between the distraction and the final action.

According to an Interruptions / distractions briefing note by the Flight Safety Foundation, interruptions and distractions usually result from the following factors:

  • flight crew-ATC, flight deck or flight crew-cabin crew communication
  • head down work, and
  • response to an abnormal condition or unexpected situation.

Further information is available at:

Flight Safety Foundation Approach-and-landing accident reduction

.

Research conducted by the ATSB identified 325 occurrences between 1997 and 2004, which involved distractions. Of these, 54 occurred during the landing phase of flight.

ATSB (2006). Dangerous Distraction: An examination of accidents and incidents involving pilot distraction in Australia between 1997 and 2004. (Research and Analysis report B2004/0324).

Aviation Short Investigations Bulletin - Issue 48

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. In an echelon formation, number 1 (ALO in this instance) is the lead aircraft, and makes the decisions for the formation and also makes and responds to all radio communication for the formation; each individual pilot is still responsible for their own aircraft’s safety.
  2. The position in the circuit, where the pilot in the lead aircraft (ALO) in the formation determines that the formation will manoeuvre into single file, usually with Number 1 in the lead.
  3. An echelon formation is where the aircraft (usually military) are arranged diagonally. In a left echelon, each station (in this case Number 2) was stationed behind and to the left of the lead aircraft) ALO (adapted from Wikipedia definition).
  4. The non-active side of the circuit.

Occurrence summary

Investigation number AO-2016-009
Occurrence date 06/02/2016
Location Barwon Heads/Geelong (ALA)
State Victoria
Report release date 27/05/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Wheels up landing
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Nanchang Aircraft
Model CJ-6
Registration VH-ALO
Serial number 4532002
Sector Piston
Operation type Charter
Departure point Barwon Heads, Vic.
Destination Barwon Heads, Vic.
Damage Substantial

Wirestrike involving a Kavanagh G-450 balloon, VH-RUW, Mareeba, Queensland, on 7 February 2016

Final report

What happened

On 7 February 2016, the pilot of a Kavanagh G-450 balloon, registered VH-RUW, conducted a 30-minute scenic flight from Mareeba, Queensland with 18 passengers on board.

Shortly before 0627 Eastern Standard Time (EST), the balloon approached the target landing area. The pilot referred to his iPad, which showed the location of the balloon and a set of powerlines strung across the paddock. The balloon was then about 30 ft above ground level, travelling at a ground speed of 7 kt, with a descent rate of 50 ft per minute. The pilot confirmed that all the passengers were in the correct landing position.

The pilot sighted two power poles either side of the landing area, but was unable to see the wires. The pilot estimated where the wires would be based on the crossbars on the poles, and assessed that the balloon had sufficient height to pass over the powerlines. The pilot then sighted the powerlines, about half a metre ahead of and below the basket. The pilot applied all four burners to try to climb and avoid the powerlines, but the left side of the basket contacted one wire, breaking it. The pilot heard a loud fizzing noise and immediately realised they had struck a powerline.

The pilot checked that the passengers were all ok and still in the landing position, and checked that there was no evidence of fire. Due to the amount of heat in the balloon, the balloon was climbing. The pilot then conducted a normal controlled descent and landing into a paddock about 500 m beyond the original planned landing site. The balloon landed without further incident and no one was injured. The wicker basket sustained scorching (Figure 1) and a stainless steel cable fixed to the underside of the basket sustained arc damage.

Figure 1: Scorch marks on wicker basket

Figure 1: Scorch marks on wicker basket

Source: Balloon operator

Landing site

The balloon operator and the pilot had used the paddock on many occasions for both launching and landing.

The balloon’s track crossed the powerlines at an angle (Figure 2). As the balloon approached the wires, the pilot lost sight of the pole to the left and used the pole on the right to gauge their height. However, the left pole was situated on a hill and higher than the right pole, and the wires sloped upwards from the right pole to the left. The pilot’s assessment of sufficient height was based on the lower pole; consequently, the left side of the basket struck the wires to the high side.

The powerlines were difficult to see as the area was heavily vegetated. The sun was to the right of the balloon and did not affect the pilot’s vision of the wires.

Figure 2: Balloon track and location of powerlines

Figure 2: Balloon track and location of powerlines

 

Source: Balloon operator

Powerlines and markings

The balloon operator used the following strategies to improve powerline awareness:

  • The operator had developed an iPad application which pilots used in-flight as an early powerline warning system, which showed all of the powerlines on a google earth map, and the balloon’s current location. The energy company provided updates to the location of the powerlines at six monthly intervals.
  • The operator maintained a map of powerlines identified by the company pilots to be of low visibility. These were highlighted on the application to draw pilots’ attention.
  • Company pilots were required to visit the site of identified low-visibility powerlines to familiarise themselves with the location of the lines.
  • In addition, ground personnel were expected to identify from the ground any powerlines in the balloon’s flight path, which may pose a risk to the balloon on approach to land, and to confirm that the pilot was aware of the lines and their location.
  • The balloon operator had designated the powerlines at the site to be low-visibility, and had paid the energy provider to fit white marker flags with a reflective green centre to the wires to increase the pilot’s ability to see the lines (or flags). Despite being clearly visible from the ground, the pilot was unable to see the flags. This may have been due to the effect of the wind deflecting the flags at an angle, and possibly their colour.

Pilot comments

Two other balloons had already landed in the paddock. The pilot elected to fly on rather than conduct an emergency descent after the wirestrike, because a high rate of descent from that height carried a risk of injury to the pilot and passengers, and to avoid a collision with the balloons that had landed ahead.

Safety action

Balloon operator

As a result of this occurrence, the balloon operator has advised the ATSB that they are taking the following safety actions:

Review of powerline markings

The operator is investigating the installation of more visible three-dimensional powerline markings such as balls.

Communication to company pilots

The operator will circulate a copy of their investigation report and findings to all company pilots. Pilots are reminded to consider the possibility of sloping powerlines and apply an appropriate clearance margin when overflying them.

Safety message

The ATSB research report, Wirestrikes involving known wires: A manageable aerial agriculture hazard, explains a number of strategies to assist pilots manage the risk of wirestrikes. These include:

  • ensure you are fit to fly
  • prioritise safety
  • conduct thorough pre-flight planning
  • avoid unnecessary distractions
  • don’t rely on your ability to react in time to avoid a wire
  • have a systematic approach to safely managing wires.

The Australian Ballooning Federation produced safety advisory notice pilot circular number 18 in 2012, detailing strategies to avoid wirestrikes.

Aviation Short Investigations Bulletin - Issue 48

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Aviation Short Investigation Bulletin - AB-2016-044

Occurrence summary

Investigation number AO-2016-008
Occurrence date 07/02/2016
Location near Mareeba Aerodrome (Byrnes Rd)
State Queensland
Report release date 27/05/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Wirestrike
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Kavanagh Balloons
Model G-450
Registration VH-RUW
Serial number G450-401
Sector Balloon
Operation type Ballooning
Destination Mareeba, Qld
Damage Minor

Derailment of MTM train TD1064, near Rushall Station in Fitzroy North, Melbourne, Victoria, on 6 February 2016

Final report

Safety summary

What happened

At about 1650 on 6 February 2016, metropolitan passenger train TD1064 was travelling towards Melbourne between Merri and Rushall Railway Stations when it derailed one bogie on a small-radius curve. There was one minor injury reported.

The derailed car was foul of the adjacent track and there was the potential for more serious consequences had a train from the opposite direction been passing at the time.

What the ATSB found

The ATSB found that the leading right-hand wheel of the second car climbed the outside rail of the small-radius curve. The main factors contributing to the derailment were the high coefficient of friction between wheel and rail and the geometry of a rail joint. The train was being operated within the speed limit for this curve and the manner of its operation did not contribute to the derailment.

It was found that the train’s wheel flanges and the rail’s gauge-face had low levels of lubrication. The performance of rail lubricators on the metropolitan network had diminished prior to the derailment, leading to a deficiency in lubrication on the network. This was probably the result of a decline in lubricator maintenance. Rail lubricator maintenance was being transferred from contractors to Metro Trains Melbourne (MTM) staff and this transition was not adequately managed.

The derailment at this point on the curve was triggered by a lateral angular discontinuity at a mechanical rail joint, resulting in a localised increase in the wheel-to-rail lateral force. The network’s track geometry standard did not preclude the presence of such a discontinuity.

While not mandated by MTM, a check rail on this small-radius curve (installed adjacent to the inner rail) would have provided an additional defence against flange-climb and derailment. A network standard to potentially address derailment risk at higher-risk locations was under consideration at the time of this derailment.

A number of other safety factors were identified that were not directly causal to this incident. They included the ineffective locating of some rail lubricators within the network, a high tolerance on allowable track geometry deviations at this and similar low-speed mainline locations, and a failure to address a wide-gauge defect on this curve.

What's been done as a result

MTM have undertaken a range of actions including the wide-spread installation of new electronic lubricators and significant changes to the management of track condition and faults. These actions, when taken in concert, are expected to reduce the risk of derailment on small-radius curves.

Safety message

The potential for flange-climb derailment on small-radius curves is sensitive to track condition and lubrication between wheel and rail gauge-face. It is therefore important to maintain lubrication across the network and address reductions in performance flagged by unusual wheel wear or evidence of metal loss at the wheel-rail interface.

Findings

From the evidence available, the following findings are made with respect to the derailment of train TD1064 near Rushall Station on 6 February 2016. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • There was insufficient lubrication between wheel flanges and the outside rail of the 118 m small-radius curve (Up track) between Merri and Rushall Railway Stations.
  • The performance of rail lubricators on the network had diminished in the months leading up to the derailment.
  • The maintenance of rail lubricators had become less effective in the months leading up to the derailment. This work was being transferred from contractors to internal Metro Trains Melbourne (MTM ) staff and the transition was not adequately managed. [Safety Issue]
  • The flanges of the train’s recently-machined wheels had machining grooves and had been roughened through a lack of network lubrication, resulting in a higher contact surface coefficient of friction. This increased the probability of flange-climb compared to a typical wheel worn on a well-lubricated network.
  • Recent machining of the train’s wheels had returned them to the ‘as-new’ wheel profile that had a lower flange angle (to the horizontal) than a typical worn wheel. This increased the probability of flange-climb.
  • A lateral angular discontinuity at a mechanical joint in the outside rail resulted in a localised peak in the wheel-to-rail lateral force and probably an increased wheel/rail angle-of-attack. This initiated the flange-climb at this particular point on the curve.
  • The network’s track geometry standard did not include any specific requirement to limit a localised lateral angular discontinuity in rail line at a mechanical joint. [Safety issue]

Other factors that increased risk

  • The positioning of the rail lubricators at this and several other locations on the network was not consistent with MTM guidelines and probably reduced their effectiveness. [Safety issue]
  • The network’s track geometry standards were probably unsuitable for small-radius Broad-Gauge curves. A combination of track geometry irregularities had increased the probability of flange-climb at several locations on the small-radius Rushall curve. [Safety issue]
  • Track geometry through the Rushall curve was not managed in accordance with MTM network standards. A wide-gauge ‘A’ fault was not rectified in the field despite being closed-out on the asset management system. [Safety Issue]
  • There was no network standard that directly dealt with increased derailment risk on small-radius curves. [Safety Issue]
  • The Digital Train Radio System did not allow a Train Emergency Call to override an initial lower-priority call. [Safety Issue]

Occurrence

The Melbourne metropolitan rail network and its passenger rolling stock are operated by Metro Trains Melbourne (MTM)[1].

On 5 February 2016, the wheels on this six-car trainset were subject to scheduled machining. This returned the wheels to the ‘as-new’ wheel profile and the train was returned to normal service the next day.

On 6 February 2016, this trainset operated scheduled services from Craigieburn to Flinders Street Station, then Flinders Street Station (via the City Loop) to South Morang. From there, the train ran to Southern Cross then returned to South Morang where it formed the 1630 South Morang-to-Flinders Street service TD1064.

Service TD1064 departed South Morang as scheduled. At about 1650, when travelling between Merri and Rushall Railway Stations (Figure 1), the leading bogie of the second car derailed. The train derailed on a small-radius curve travelling at a speed of about 20 km/h.

Figure 1: The derailment location within the Melbourne suburb of North Fitzroy.

Figure 1: The derailment location within the Melbourne suburb of North Fitzroy. The immediate area of the derailment location is shown enlarged.
Source: Google Maps, annotated by the Chief Investigator Transport Safety (Vic)

The immediate area of the derailment location is shown enlarged.Source: Google Maps, annotated by the Chief Investigator Transport Safety (Vic)

The train quickly came to a stop with the leading-end of the second car foul of the adjacent line (Figure 2). The driver was initially unsuccessful in attempts to contact Metrol[2] via the train radio system[3]. The driver subsequently established contact using a company-issued mobile phone about six minutes after the derailment. It was then about another minute before any approaching rail traffic could be halted.

Figure 2: View of the derailed leading-end bogie of the second car

Figure 2: View of the derailed leading-end bogie of the second car. The leading-end of the second car derailed, and is shown sitting foul of the clearance of the opposite (adjacent) running line.
Source: Chief Investigator, Transport Safety (Vic)
The leading-end of the second car derailed, and is shown sitting foul of the clearance of the opposite (adjacent) running line. Source: Chief Investigator, Transport Safety (Vic)

There was one reported passenger injury and minor track and train damage. The double-track location was returned to service in time for the morning peak period the following day.

On 11 February 2016, five days after the derailment of TD1064, a track regulator derailed on the same curve, a short distance from the first derailment. Following this second derailment, there were further track works undertaken on the Rushall curve.

__________

  1. MTM is a consortium of Hong Kong’s MTR Corporation (formerly Mass Transit Railway), Australia’s John Holland Group and UGL Rail, a division of UGL (formerly United Group Limited).
  2. Metropolitan Train Control Centre. The control centre for all rail traffic in the Melbourne metropolitan region.
  3. The GSM-R digital train radio system for the Melbourne metropolitan rail network that was brought into operation in 2014

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Metro Trains Melbourne (train operator)
  • Monash Institute of Rail Technology (consultant)
  • ITW Polymers & Fluids (lubricant supplier).

References

Iwnicki S (2006), Handbook of Railway Vehicle Dynamics, CRC Press, pp 221

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to:

  • Metro Trains Melbourne
  • Office of The National Rail Safety Regulator.

Extracts of this draft report were provided to:

  • Institute of Rail Technology (Monash University)
  • ITW Polymers & Fluids.

Submissions were received from Metro Trains Melbourne, Monash University and ITW Polymer. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Context

Location

The train was negotiating a 118 m radius-curve, the most severe mainline curve on the MTM network. Known as the ‘Rushall curve’, it was located in North Fitzroy about seven rail km from the Melbourne CBD. The curve had a permanent speed restriction in the Up[4] direction of 30 km/h.

This small-radius curve existed as a remnant of a triangular junction that originally connected the (then) Epping Line to the Royal Park-to-Northcote Loop (also known as the Inner Circle Line). The connection was severed in 1965 and the Royal Park-to-Northcote Loop was subsequently closed. The curve that formed the junction’s eastern leg remained as a portion of the main line between Merri and Rushall Stations (Figure 3).

Figure 3: Derailment location on the 118 m Rushall curve

Figure 3: Derailment location on the 118 m Rushall curve. The red dotted lines indicate the layout of the closed sections of the original junction. 
Source: Google Earth, annotated by the Chief Investigator, Transport Safety (Vic)
The red dotted lines indicate the layout of the closed sections of the original junction. Source: Google Earth, annotated by the Chief Investigator, Transport Safety (Vic)

Track construction and condition

Travelling towards Melbourne, the Rushall curve was on a 1-in-70 downgrade. It was constructed using wooden sleepers supporting typically 13.7 m lengths of rail joined by mechanical (fishplated) joints in a staggered[5] pattern. Around the point-of-derailment (PoD), rails were on double-shoulder base plates generally attached by plate screws. Rails were mostly secured using resilient fasteners with some use of dog-spikes.

The most recent MTM engineering inspection[6] of the curve was on 2 March 2015 at which time the track was reported as being fit-for-purpose for one year.

Examination of the track following this derailment found evidence of pumping[7] and angular misalignment at mechanical joints. The gauge-face of the outside rail (high leg) had sustained noticeable side wear.

Track geometry

Network tolerances

MTM engineering specification (track)[8] included fault bands for key geometric parameters including track gauge, cant, twist, rail lateral alignment (line) and vertical variation (top) (Figure 4). The fault bands were the same for tangent and curved track.

Figure 4: MTM track geometry maintenance tolerances.

Figure 4: MTM track geometry maintenance tolerances. The condition tolerances for the Rushall curve were those pertaining to a track speed of 40 km/h (outlined in red).
Source: Metro Trains Melbourne, annotated by Chief Investigator, Transport Safety (Vic)
The condition tolerances for the Rushall curve were those pertaining to a track speed of 40 km/h (outlined in red). Source: Metro Trains Melbourne, annotated by Chief Investigator, Transport Safety (Vic)

The engineering specification stated that:

  • An ‘A’ fault was to be removed or corrected so that it fell into the ‘B’ fault band, or better. It was permitted to apply a speed restriction to move an ‘A’ fault to the ‘B’ band.
  • ‘B’ faults were to be considered when assessing trends and when planning track maintenance, and did not require immediate corrective action.

The Jolimont – South Morang line, that included the Rushall curve, was classified as Track Class 3 (100 km/h) and the geometry tolerances for this class and speed applied for the majority of this line. However, the engineering specification stated that for locations where the line speed was less than the Track Class speed, the fault parameters corresponding to the line speed for that location should be applied. On that basis, for the Rushall curve, the 40 km/h fault limits applied (outlined in red in Figure 4).

Track geometry recording car pre-derailment

The track geometry of the derailment curve was measured using the IEV100 track recording vehicle on 1 December 2015, about two months before the derailment. This identified three ‘A’ faults within the curve based on the 100 km/h line speed (Figure 5). When re-assessed against the requirements for 40 km/h track, only the two wide-gauge faults (at 7.577 km and 7.516 km) remained as ‘A’ faults. Neither of these faults was near the Point-of-Flange-Climb (PoFC) at about 7.554 km.

Figure 5: ‘A’ faults identified within the Rushall curve by the IEV100 recording vehicle

Location of peak (km)

Parameter

Magnitude recorded

(mm)

Class 3 (100 km/h) ‘A’ fault threshold

(mm)

Class 5 (40 km/h) ‘A’ fault threshold

(mm)

7.577

Wide gauge

34

20

26

7.537

Twist (short)

30

25

41

7.516

Wide gauge

33

20

26

Source: MTM track geometry recording 1 December 2015

Post-derailment geometry measurements

Following the derailment, the track geometry through the location was measured over a distance of 90 m from the estimated PoFC back towards Merri station. The geometry was measured using a KRAB[9] track recording trolley that reflects the track’s geometry in an unloaded state. This unloaded measurement would typically be an underestimate of track irregularity compared to the geometry during the passage of a train or the track recording vehicle.

At the estimated PoFC, measured geometry was below the 100 km/h and 40 km/h ‘B’ fault limits for all parameters except gauge. At the PoFC the gauge was about 16 mm wide. This is at the lower limit of the 40 km/h ‘B’ fault band and so would not be considered a critical defect.

Larger irregularities were found away from the PoFC. A static wide-gauge of 29 mm was measured by the KRAB at 7.572 km and was probably the same fault (of 34 mm) identified at 7.577 km by the IEV100 on 1 December 2015, prior to the derailment.[10]

Rail wear

Measurement of the 90 m of track approaching and including the PoFC showed that rail wear was comfortably within the specified limits for top and side wear, and percentage of head loss.

The inner face of the outside rail at the derailment location displayed a generally worn profile consistent with its situation within a small-radius curve. The gauge-face angle was within the network’s permitted maximum of 26 degrees (to the vertical). The measured angle of the gauge-face at the estimated PoFC was about 17 degrees and the highest measured gauge-face angle within the curve was 23 degrees (about 75 m prior to the PoFC).

Rail gauge-face surface condition

The coefficient of friction at the wheel/rail interface can have a significant impact on the risk of flange-climb derailment. The higher the friction between the contact surfaces, the greater the potential for a wheel to climb the gauge-face of the rail.

The gauge-face of the outer rail was clean and dry, with no visual evidence of either lubricant or contaminants and with a roughened surface (Figure 6).

Figure 6: Gauge-face at estimated point-of-flange-climb

Figure 6: Gauge-face at estimated point-of-flange-climb. Source: Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

Below the worn gauge-face there were steel filings (snow) on the rail foot and ballast (Figure 7).

Figure 7: Metal filings deposited on the track ballast

Figure 7: Metal filings deposited on the track ballast. Source: Chief Investigator, Transport Safety (Vic)
Source: Chief Investigator, Transport Safety (Vic)

The presence of both the rough gauge-face surface and metal filings below the rail were indicative of high friction and wear conditions and hence indicated a probable deficiency of lubrication between gauge-face and wheel-flange.

The train

Configuration

Train TD1064 comprised two 3-car Alstom X’Trapolis sets (9M-1305T-10M and 1M-1301T-2M) coupled as a 6-car train. The sets were based at the Craigieburn depot and their maintenance was up-to-date.

Post-derailment vehicle inspections

Inspections were conducted on the lead bogie and suspension of car 1305T. Tests and inspections included assessment of bogie frame, suspension and traction components and connections with the leading car. No defects or deviations from specification were identified.

There were witness marks indicating impact between the bogie and the bump stops that limit bogie rotation. Similar marks were found on other X’Trapolis vehicles suggesting that this contact was not uncommon within the fleet. MTM analysis indicated that a static clearance of about 25 mm should have existed at the bump stops when travelling on a 118 m curve.

Wheels

Recent machining

On 5 February 2016, the wheels on both car-sets were subject to a scheduled machining on the underfloor wheel lathe at the Epping Workshops. The wheels were returned to the MP2[11] wheel profile that represents the standard wheel profile for the X’Trapolis fleet. Following the machining, the total distance run to derailment was 79 km.

Post-derailment wheel inspections

Inspection identified circumferential machining grooves from recent machining. On the tread running surfaces, these grooves had been removed and burnished by rolling contact. The burnished regions were consistent with abrasion of the wheel treads from normal tracking of the wheelsets. There were no material defects detected on any wheels during visual inspection.[12]

All wheel flanges on both sides of the train exhibited a localised band of coarse scoring. This scoring was more pronounced on the wheels on the right-hand side of the leading three-car set (in the direction of travel between Merri and Rushall stations), and therefore on those wheels that had been running on the outside of the derailment curve. The scoring damage in the area of the ‘throat’ (the tread-to-flange radius) was consistent with adhesive wear, and indicated the wheel flanges had been bearing against the rail head. These wheels were dry and did not exhibit any signs of track lubricant.

The wear condition of the first wheel to derail was consistent with other wheels on the right-hand side of the train. The wheel exhibited a band of scoring about 10 mm wide, located within the radius and onto the flange (Figure 8). The location of the wear, like other wheels on the right-hand side of the leading three-car set, indicated that the flange had been riding high on the rail head during curving prior to the derailment.

Figure 8: Views of the leading right-hand wheel of car 1305T showing observed wear

Figure 8: Views of the leading right-hand wheel of car 1305T showing observed wear.
The left-hand photograph shows a general view of the wheel’s condition. The right-hand photograph shows the heavy scoring within the throat (the tread-to-flange radius) and extending to mid-flange. The machining marks can also be seen to the outside of the scoring. This wheel was the first to derail and also exhibited ballast abrasion markings at the outer edge of its tread.
Source: ALS Industrial

The left-hand photograph shows a general view of the wheel’s condition. The right-hand photograph shows the heavy scoring within the throat (the tread-to-flange radius) and extending to mid-flange. The machining marks can also be seen to the outside of the scoring. This wheel was the first to derail and also exhibited ballast abrasion markings at the outer edge of its tread.Source: ALS Industrial

Fleet-wide wheel deterioration

MTM rolling stock division began identifying dry and rough flanges on its fleet in December 2015. The extent of the dry wheel flange issue across the MTM suburban fleet then increased during January 2016 and coincided with increasing wheel wear rates on the V/Line[13] VLocity fleet.[14]

Train driver

The driver had been a Melbourne electric train driver for 11 years. He commenced duty at Epping at 1540, a little more than an hour prior to the incident. The operation of the train was consistent with MTM’s requirements, including speed through the derailment curve. The driver underwent a Preliminary Breath Test at Flinders Street station, returning a negative result.

Simulation of train TD1064 passage through Rushall curve

Site evidence indicated that the derailment had occurred as a result of a wheel climbing the outside rail. A computer simulation was conducted of the transit of train TD1064 through the Rushall curve[15] to identify features that might have contributed to or influenced this flange-climb tendency.

A flange-climb derailment is the climbing of a wheel up the rail gauge-face, then onto, along and over the top of the rail. The simulation used Nadal’s[16] single wheel L/V limit criterion to evaluate the potential for flange climb where L is the lateral force of wheel-on-rail, and V is the vertical force of wheel-on-rail (Figure 9). The Nadal equation is widely used by the railway industry.

Figure 9: Nadal criterion for flange-climb derailment

Figure 9: Nadal criterion for flange-climb derailment. The equation defines the L/V ratio at and above which flange-climb is expected to occur for contact conditions defined by coefficient of friction and flange angle.
Source: Nadal equation

The equation defines the L/V ratio at and above which flange-climb is expected to occur for contact conditions defined by coefficient of friction and flange angle.Source: Nadal equation

The Nadal equation relates the L/V ratio to the physical conditions at the wheel-rail contact. Flange-climb is likely when the L/V ratio equals or exceeds the right-hand side of the equation that is composed of the coefficient of friction between rail and wheel (µ) and the wheel flange angle (α). The required L/V ratio for flange-climb reduces, and therefore the potential for flange-climb increases, as:

  • wheel-to-rail friction increases
  • wheel flange angle (to the horizontal) decreases

The L/V ratio that occurs at the wheel-rail contact point is an outcome of the dynamic response of the train to the track geometry. The potential for flange climb increases as L/V increases and therefore as:

  • the lateral force (L) increases
  • the vertical force (V) decreases, such as during wheel unloading.

Rail lubrication

Lubrication can be used to reduce friction levels between rail gauge-face and wheel flange. MTM used mechanical rail lubricators (known colloquially as ‘grease pots’) to dispense grease to the rail gauge-face at certain locations. The rail lubricator intended to service the outside rail of the Rushall curve (travelling towards Melbourne) was located about 20 m past Merri Railway Station and about 330 m before the Rushall curve (Figure 10).

Figure 10: Location of the rail lubricator, identified as point A

Figure 10: Location of the rail lubricator, identified as point A.
The train was travelling from Merri toward Rushall. Point A represents the position of the rail lubricator on the Up (Melbourne-bound) track, and point B depicts the start of the 118 m curve (the target curve for lubrication) in red. The yellow dotted line represents tangent track and the yellow solid line is the intervening curve. The distance from A to B (orange) was about 330 m.
Source: Google Earth, annotated by the Chief Investigator,
The train was travelling from Merri toward Rushall. Point A represents the position of the rail lubricator on the Up (Melbourne-bound) track, and point B depicts the start of the 118 m curve (the target curve for lubrication) in red. The yellow dotted line represents tangent track and the yellow solid line is the intervening curve. The distance from A to B (orange) was about 330 m.Source: Google Earth, annotated by the Chief Investigator, Transport Safety (Vic)

The lubricator ahead of the Rushall curve was typical of that used on the Melbourne Metropolitan network (Figure 11). A spring-loaded piston within the lubricator reservoir pressurises the grease. When two lubricator plunger pins (integral to the manifold block) are actuated by a passing wheel tread, grease is pumped from the manifold block to a dispensing ‘wiper’ blade attached to the gauge-face of the rail. From here grease is picked up by wheel flanges (assuming effective flange contact with the rail head) and distributed along the gauge–face.

Figure 11: The rail lubricator servicing the outside rail of the Rushall curve

Figure 11: The rail lubricator servicing the outside rail of the Rushall curve. Source: Chief Investigator, Transport Safety (Vic)

Source: Chief Investigator, Transport Safety (Vic)

Lubricant

MTM uses ROCOL Curve Grease in its rail lubricators. It is lithium dioxide-based, and contains solid graphite dispersed in highly-refined mineral oil to provide low friction and a high load-carrying capacity. It works by depositing a ‘boundary lubricant’ on the rail gauge-face (a thin film that remains effective under extreme pressures) and has a working temperature range from -10 ºC to 150 ºC.

The product has been in use since 1998 and the manufacturer has supplied MTM since 2010 – the amount supplied to MTM having increased over the previous two years. The manufacturer advised that in the past five years there have been no changes to the product’s composition (formulation) and no changes to the composition of its material components or their specifications. The product is also supplied to New South Wales (NSW) railways.

The supplier does not provide technical guidance to the customer on dosage rates or on the optimum location of rail lubricators. The manufacturer advised that the presence of metallic fines (snow) below the rail would indicate a lack of lubrication.

Rail lubricator maintenance

Rail lubricators were subject to scheduled servicing during a process known as a Pit Cleaning Occupation (PCO). In this process, the immediate environment around and between station platforms was serviced and maintained.

Through 2015, rail lubricators were maintained by Sunstone Resources Pty Ltd[17] under contract from MTM. These arrangements changed towards the end of 2015 and MTM advised that it ceased using Sunstone for lubricator maintenance in December 2015.

Around this time, one individual from the Sunstone lubricator maintenance team joined MTM. He and an existing MTM employee were tasked with training other MTM track maintenance staff in lubricator maintenance. MTM advised that it had been difficult to organise safeworking arrangements for access to the track during this transition period and that lubrication activities were subsequently fully re-established in February 2016.

Records for rail lubricator maintenance on the South Morang line from July 2015 to February 2016 (Figure 12) indicated that monthly inspection and maintenance had been conducted through to December 2015, and that no further maintenance had then occurred until after the derailment.

Figure 12: Recorded lubricator maintenance on the Rushall curve lubricator

Date

Piston movement (cm)

ATSB notes

18/7/15

24

 

15/8/15

22

 

12/9/15

25

 

11/10/15

19

 

14/11/15

10

Reduced quality of record

12/12/15

18

Reduced quality of record

12/2/16

15

Following derailment

This table displays the dates of lubricator maintenance on the Rushall curve lubricator. The piston position is an indication of the amount of grease remaining in the pot. A piston position of 30 cm indicated that the lubricator ‘pot’ was nearing empty.Source: Metro Trains Melbourne

The lubricator inspection records provided no detail on the extent of any refill and whether the piston movement measurement was taken before or after refill. Other entries on these records, around inspection activities undertaken and lubricator settings, were identical across all records.

Inspection frequency

The relevant MTM work instruction[18] specified the steps associated with lubricator maintenance, the tools required and management accountabilities. This instruction stated that the asset manager was responsible for determining the type and frequency of lubrication inspection in order to ensure a safe and efficient track infrastructure.

MTM advised that the maintenance plan required that lubricators be inspected every three months. This differed from the monthly interval specified up until 2012 and was reportedly the result of a risk assessment process. Irrespective of this reduced frequency of planned inspection, records indicate that the Sunstone maintenance team were inspecting lubricators on a monthly cycle.

Related occurrences

On 11 February 2016, five days after the derailment, a track regulator[19] travelling towards Melbourne derailed on the Rushall curve at a subsequent mechanical joint on the Up track. The flange-climb was again just beyond a rail joint in the outside rail (Figure 13). The derailment had occurred despite hand-greasing of the rail gauge-face following the first derailment.

Figure 13: The Point-of-Flange-Climb and track of the wheel flange across the rail head

Figure 13: The Point-of-Flange-Climb and track of the wheel flange across the rail head. The photograph is annotated to show the direction of train travel (yellow arrow) and the flange track along and across the rail head (red line). Note that the point of flange-climb commenced immediately after the rail joint. Source: Chief Investigator, Transport Safety (Vic)

The photograph is annotated to show the direction of train travel (yellow arrow) and the flange track along and across the rail head (red line). Note that the point of flange-climb commenced immediately after the rail joint.Source: Chief Investigator, Transport Safety (Vic)

__________

  1. Towards Melbourne
  2. When rail joints on the Up and Down rails are not opposite (adjacent to) each other, but are positioned alternately.
  3. Referred to as Curve Close Inspection in MTM procedures, and entails a thorough walking inspection by track engineers.
  4. The dynamic vertical action of the track structure that occurs during the passing of a train. Where the track structure spans an area of degraded subgrade (e.g. with deficient drainage), this action can force fine ballast particles, soil, and water to the surface, fouling the ballast and reducing its load-bearing qualities.
  5. MTM Engineering Specification Track, MTSP 030100-01 Track Geometry Maintenance Tolerances, Version 1, September 2012
  6. Named after its Czech manufacturer.
  7. The IEV100 recording of 34 mm was measured under load and was higher than the static measurement of 29 mm.
  8. The MP2 wheel profile was developed in the 1980s for the Comeng Disc-braked fleet, and has subsequently been applied to the wheels of all bogies with minimal axle-steering capacity.
  9. ALS Industrial Material Evaluation Report 030362-1-1, 2016
  10. V/Line operates Victorian regional rail services. Its trains also operate on the Melbourne metropolitan network
  11. Institute of Railway Technology VLocity Wheel Wear Investigation for V/Line Pty Ltd, Report No. Monash/RT/2016/1144, 1 April 2016
  12. Dynamic simulation of wheel-to-rail contact was conducted by the Institute of Railway Technology, Department of Mechanical Engineering, Monash University. The simulation used Universal Mechanism (UM) software developed by the Laboratory of Computational Mechanics in Russia.
  13. Nadal, M.J., Locomotives à Vapeur; (Collection: Encyclopédie Scientifique, - Bibliothèque de Mécanique Appliquée et Génie, 1908).
  14. Founded in 2013 with shareholders MTR (Hong Kong), John Holland Group and UGL Limited. Sunstone Resources has subsequently ceased operation.
  15. MTMI 033100-04, L2-TRK-MAI-005 Track Maintenance Instruction, Rail Lubricator – Examination and Servicing, Version 1, effective 14 June 2013.
  16. Maintenance vehicle used to distribute and profile track ballast.

Safety issues and actions

The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to rail industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.

Rail lubricator maintenance

Safety issue number: RO-2016-002-SI-01

Safety issue description: The maintenance of rail lubricators had become less effective in the months leading up to the derailment. This work was being transferred from contractors to internal Metro Trains Melbourne (MTM) staff and the transition was not adequately managed.

Standard for angular discontinuity at mechanical joints

Safety issue number: RO-2016-002-SI-02

Safety issue description: The network’s track geometry standard did not include any specific requirement to limit a localised lateral angular discontinuity in rail line at a mechanical joint.

Location of rail lubricators

Safety issue number: RO-2016-002-SI-03

Safety issue description: The positioning of the rail lubricators at this and several other locations on the network was not consistent with MTM guidelines and probably reduced their effectiveness.

Track geometry standards

Safety issue number: RO-2016-002-SI-04

Safety issue description: The network’s track geometry standards were probably unsuitable for small-radius Broad-Gauge curves. A combination of track geometry irregularities had increased the probability of flange-climb at several locations on the small-radius Rushall curve.

Management of wide gauge defect

Safety issue number: RO-2016-002-SI-05

Safety issue description: Track geometry through the Rushall curve was not managed in accordance with MTM network standards. A wide-gauge ‘A’ fault was not rectified in the field despite being closed-out on the asset management system.

Standard for derailment risk on small-radius curves

Safety issue number: RO-2016-002-SI-06

Safety issue description: There was no network standard that directly dealt with increased derailment risk on small-radius curves.

Train radio functionality

Safety issue number: RO-2016-002-SI-07

Safety issue description:  The functionality of the Digital Train Radio System (DTRS) did not allow an emergency call to override an initial lower-priority call.

Safety analysis

The derailment

Train TD1064 was travelling towards Melbourne when it derailed on the tightest curve on the metropolitan mainline network. The train was being operated within the speed limit for this curve and its manner of operation did not contribute to the derailment.

Site observations identified that the train derailed as a result of flange-climb by the leading right-hand wheel of the second car.

Wheel-rail coefficient of friction and lubrication

Coefficient of friction

At the point of flange-climb, the rail gauge-face surface indicated high-friction wheel-to-rail contact. Metal filings from this contact were also observed at the base of the rail. Based on measurements from across the network, expert opinion[20] was that the coefficient of friction between the gauge-face and wheel flange was probably around 0.45 at the derailment location.

The coefficient of friction between the wheel and rail has a significant influence on the risk of flange-climb derailment. Simulations applying flange-climb criterion to this curving scenario showed that the potential for flange-climb increased significantly with increasing friction (Figure 14).

Figure 14: Simulation results for the derailed car (1305T) for a range of friction conditions

Figure 14: Simulation results for the derailed car (1305T) for a range of friction conditions. The diagram shows the estimated Nadal index through the Rushall curve for a range of wheel-rail coefficients of friction. The higher the coefficient of friction, the greater the likelihood of flange-climb derailment.
Source: Institute of Railway Technology (Monash University)

The diagram shows the estimated Nadal index through the Rushall curve for a range of wheel-rail coefficients of friction. The higher the coefficient of friction, the greater the likelihood of flange-climb derailment. Source: Institute of Railway Technology (Monash University)

Relationship between lubrication and coefficient of friction

The relationship between the coefficient of friction and lubricant film thickness is well-established. The higher the lubricant film thickness, the lower the coefficient of friction between wheel flange and rail. For example, a friction coefficient of 0.15 is considered to represent a well-lubricated contact condition, whereas around 0.45 would represent an unlubricated interface.

In the case of small-radius curves, effective lubrication is critical. In this instance, there were clear signs of abrasive metal-to-metal contact indicating that lubrication between rail and wheel was inadequate.

Network lubrication

Metro Trains Melbourne (MTM) rolling stock division identified an increasing rate of dry and rough wheel flanges from December through to this derailment. This increased presence of dry flanges in the MTM fleet was almost certainly the result of a deterioration in rail lubrication across the network. The dry summer conditions may have also added to a reduction in lubrication performance.

MTM advised that previous periods of dry and rough flanges in 1987, 2006 and 2012 were identified as likely being the result of issues with the filling and servicing of rail lubricators. The most recent period of dry flanges was also likely to be associated with lubricator inspection and maintenance.

Rail lubricator maintenance

The arrangements for maintaining lubricators were changed towards the end of 2015 when MTM ceased using its affiliated contract company. There was then no further inspection of lubricators on the South Morang line until after the derailment in February 2016.

MTM advised that their maintenance plan required that lubricators be inspected every three months, although up to December 2015, lubricator inspection was reportedly on a monthly cycle. MTM track managers were aware of the specified maintenance cycle of three months and this may have influenced them in taking several months to establish an effective lubricator maintenance regime.

Fleet rolling stock wheel condition indicated that the degree and standard of network rail lubrication had started declining in December 2015 and had further deteriorated through January and early February 2016. The most probable reason for this deterioration was a reduction in the effectiveness of rail lubrication across the network. This probably resulted from inadequate lubricator maintenance during the transition from contracted to internal maintenance.

MTM was aware of the fleet-wide deterioration in wheel condition, but the response was inadequate to prevent this derailment.

Location of lubricators

MTM managed flange-to-rail lubrication using fixed rail lubricators. Guidance on the placement of rail lubricators was provided in an MTM procedure[21], and included the advice that lubricators:

  • should not be positioned at or near small-radius curves[22] (defined as being with radii less than 300 m)
  • should not be positioned at locations where there was no or minimal wheel flange contact (such as on tangent track)
  • should not be co-located (adjacently on each rail), but rather each lubricator should be located at the entrance to the curve it was intended to service
  • should be located at the beginning of a moderate-radius feeder curve ahead of the more severe target curve.

Specialist advice provided to MTM’s predecessors was that track lubricators should be located at the lead-in to the target curve. Two reports (prepared in 2000[23] and 2007[24]) provided information about the effective siting of rail lubricators. Many of the lubricators examined during these studies were located on sections of tangent track distant from the curves being serviced. Advice was provided that such positioning was not suitable for efficient lubrication. In addition, the practice of co-locating lubricators (for each rail) was identified as ineffective and undesirable.

MTM’s procedure (June 2013) for locating rail lubricators reflected the advice provided within these specialist’s reports. However, a recent MTM audit found that 43 per cent of lubricators were in fact located on tangent track. This would have resulted in an inefficient use of lubricant and the potential for lubricator performance to be less effective than desired.

The lubricator that was provided to service the gauge-face of the outside rail of the left-hand Rushall curve (Up track) was located on tangent track in advance of an intervening right-hand curve. This would have led to less-effective pick-up of lubricant, and where pick-up did occur, too much of that lubricant being deposited directly back onto the track (Figure 15).

Figure 15: Rail lubricator for the Rushall curve Up track and grease plume

Figure 15: Rail lubricator for the Rushall curve Up track and grease plume. This image shows the rail lubricator for the Rushall curve, located on tangent track. The grease plume indicates that much of the lubricant has been flung off the wheel and deposited on the track. Note that the right-hand curve in the distance is an intervening (opposite) curve, and is not the one intended to be served by this lubricator. The left-hand Rushall curve is further in the distance and not shown on this photograph.
Sourc
This image shows the rail lubricator for the Rushall curve, located on tangent track. The grease plume indicates that much of the lubricant has been flung off the wheel and deposited on the track. Note that the right-hand curve in the distance is an intervening (opposite) curve, and is not the one intended to be served by this lubricator. The left-hand Rushall curve is further in the distance and not shown on this photograph.Source: Chief Investigator Transport Safety (Vic)

Wheel-to-rail contact

Wheel surface condition

Compared to a typical worn wheel, the recently-machined wheels of train TD1064 had roughened flanges. There was heavy scoring of the throat, and some remaining circumferential machining grooves towards the flange tip (Figure 16). The scored and grooved area was within the band that would contact the rail gauge-face, and it is probable that this roughened surface contributed to an increased coefficient of friction between wheel and rail.

Figure 16: Comparison between derailed wheel (left) and normally worn wheel (right)

Figure 16: Comparison between derailed wheel (left) and normally worn wheel (right). This image depicts the difference between the surface condition of the derailment wheel (left) and a typical worn wheel (right). The derailment wheel shows heavy scoring within the throat (the tread-to-flange radius) and residual machining grooves, compared to the relatively smooth finish on the normally-worn wheel.
Source: Chief Investigator, Transport Safety (Vic)

This image depicts the difference between the surface condition of the derailment wheel (left) and a typical worn wheel (right). The derailment wheel shows heavy scoring within the throat (the tread-to-flange radius) and residual machining grooves, compared to the relatively smooth finish on the normally-worn wheel.Source: Chief Investigator, Transport Safety (Vic)

It is probable that there was insufficient lubrication on those parts of the network traversed prior to the derailment, leading to the wheels suffering excessive abrasive wear and scoring. The roughened surface and machining grooves increased the likelihood of a flange-climb event. Application of lubricant to the wheel flange after machining of the wheels, and/or an improved surface finish, can reduce friction and reduce the risk of flange-climb by a newly-profiled wheel set.[25]

Wheel profiles

The current MP2 wheel profile has been in service on the Melbourne network for more than 20 years, with no known reported issues. The MP2 wheel flange angle of 70 degrees (to the horizontal) provides good protection against flange-climb, particularly when combined with effective rail lubrication in sharp curves. As the MP2 wheels wear, the flange angle increases to around 72 degrees, which improves protection against flange climb (Figure 17).

Figure 17: L-on-V ratio for flange climb, for a range of flange angles (FA)

Figure 17: L-on-V ratio for flange climb, for a range of flange angles (FA). Source: Institute of Railway Technology (Monash University)

The figure shows the effect of flange angle on the relationship between the L/V ratio required for flange climb and contact coefficient of friction. The MP2 wheel profile in a new or newly-machined condition represents the worst case in terms of flange-climb risk, with a flange angle of 70°. As this profile wears, the flange angle increases to an average of around 72° (matching the typical gauge-face profile), with an upper level of around 73°, and the potential for flange-climb reduces.Source: Institute of Railway Technology (Monash University)

The wheels of derailed car 1305T had been re-machined to the MP2 wheel profile the day before the derailment and had only run over a distance of 79 km. Although the MP2 profile provided good protection against flange-climb, the flange angle of the newly-machined wheels increased the risk of flange-climb compared to wheels that were in a worn condition.

Wheel-to-rail contact

Measured profiles of the outside rail in the derailment curve generally matched closely with the worn MP2 wheel profile. The gauge-face angle was generally around 18 degrees (to the vertical) which was consistent with the flange angle of 72 degrees (to the horizontal) of worn wheels. The angle of the gauge-face was also well within the network limit of 26 degrees.

An overlay of wheel and rail profiles (Figure 18) showed no significant abnormality and rail contact conditions were generally consistent with expectations. Comparison between this overlay and a worn wheel-to-rail overlay found that the newly-machined wheel rode slightly higher on the rail.

Figure 18: Wheel - rail profile overlay for the right-hand wheels of the derailed bogie

Figure 18: Wheel - rail profile overlay for the right-hand wheels of the derailed bogie. Source: Institute of Railway Technology (Monash University)

Source: Institute of Railway Technology (Monash University)

Angular discontinuity at rail joint

The mechanical rail joint located just prior to the estimated Point-of-Flange-Climb (PoFC) had created a lateral angular discontinuity (kink) in the line of the rail (Figure 19).

Figure 19: The outside rail and the lateral angular discontinuity at the mechanical joint

Figure 19: The outside rail and the lateral angular discontinuity at the mechanical joint. The photograph is annotated to show the direction of train travel (yellow arrow) and the flange track along and across the rail head (red line). Note that the point of flange-climb commenced immediately after the rail joint.
Source: Chief Investigator, Transport Safety (Vic)

The two images depict the angular change in the line of rail at the mechanical rail joint (indicated by yellow arrows) that was about 0.6 m ahead of the first detectable point of flange climb. The train’s direction of travel is shown by the red arrows.Source: Chief Investigator, Transport Safety (Vic)

The angular discontinuity at the mechanical joint would have had the effect of increasing the wheel-to-rail angle-of-attack to the rail and causing a peak in the wheel-to-rail lateral force. This peak is also evidenced by the peak in rail head side-wear at this location (Figure 20).

Figure 20: Top and side-wear for the outside rail of the derailment curve

Figure 20: Top and side-wear for the outside rail of the derailment curve. Source: Institute of Railway Technology (Monash University)

This figure shows the sharp increase in side-wear at the estimated PoFC, just beyond the mechanical joint. The sharp increase in side-wear correlates with the angular discontinuity at the mechanical rail joint.Source: Institute of Railway Technology (Monash University)

It is therefore probable that in the context of poor lubrication and existing track geometry, the angular discontinuity at the mechanical joint was sufficient to initiate flange-climb at this particular point on the curve. A second derailment a few days later involving a track machine, was also the result of flange-climb by its leading right-hand wheel just beyond a subsequent mechanical joint.

Identification and management of joint misalignment

The network’s track geometry standard did not include any specific requirement to directly assess a localised angular discontinuity at a mechanical joint. The measurement and monitoring of rail line is specified within the network maintenance standards (Figure 21).

Figure 21: The MTM network line variation standard for 110 km/h and 40 km/h speeds

 

Class 3 (100 km/h)

Class 5 (40 km/h)

A Fault

30 mm

50 mm

B Fault

20 mm

37 mm

The table shows the fault criteria for 100 km/h track, as applied to the corridor, and 40 km/h track, as applied to the Rushall curve.Source: Extracted from MTM maintenance specifications

The track geometry recorded after the derailment showed several peaks (positive) and troughs (negative) in rail line deviation (Figure 22). In the area of the derailment, all peaks and troughs were below the 40 km/h ‘B’ Fault criteria. The series of peaks leading to the PoFC are consistent with the joint spacing.

Figure 22: Track ‘line’ through the Rushall curve measured following the derailment

Figure 22: Track ‘line’ through the Rushall curve measured following the derailment. Source: Institute of Railway Technology (Monash University)

Source: Institute of Railway Technology (Monash University)

In December, prior to the derailment, the IEV100 track recording vehicle had also detected variations in the line of both rails within the Rushall curve. There were two recorded deviations in each rail, although neither at the Point-of-Derailment. Again however, all line faults were below the threshold for a ‘B’ fault applied to 40 km/h track and so did not require maintenance action.

In the context of the prevailing high friction wheel-rail conditions, the general track condition and geometry and the re-profiled wheels, the geometry at the mechanical joint was sufficient to result in flange-climb at that location.

Noting that track ‘line’ was within the applied network track geometry maintenance tolerances, there was no other system in place to identify that the degraded state of geometry at a mechanical joint may be such as to promote a flange-climb event.

Influence of other track geometry on potential for flange-climb

In simulation studies using a coefficient of friction of 0.5, the criterion for flange-climb was exceeded at four locations within the Rushall curve (Figure 23). The derailment of train TD1064 did not occur at any of these points, but rather a smaller peak in Nadal Index that, when combined with the effects of the mechanical rail joint, produced the conditions for flange climb.[26] Nevertheless, the potential for flange-climb existed at several locations through the curve and partial climbing at these locations was possible. For the three days prior to the derailment, the car-set’s logger recorded numerous acceleration transients at various locations through the Rushall curve, suggesting unusual tracking behaviour.

Figure 23: Results of the simulation (the Nadal index) for a coefficient of friction of 0.5

Figure 23: Results of the simulation (the Nadal index) for a coefficient of friction of 0.5. Source: Institute of Railway Technology (Monash University)

The simulation showed that the Nadal index of 1, that is the threshold for derailment, was potentially exceeded at four locations. The greatest exceedance is circled on the figure. The PoFC was at a smaller peak with an index of about 0.75 (identified by the blue arrow). This data resolution and modelling used in the simulation did not account for the localised effect of the joint.Source: Institute of Railway Technology (Monash University)

The maximum Nadal Index calculated by simulation occurred at a point at which a number of track geometric features combined to make the train susceptible to flange-climb, in particular a peak in track twist (Figure 24).

Figure 24: Measured track short twist through the Rushall curve

Figure 24: Measured track short twist through the Rushall curve. Source: Institute of Railway Technology (Monash University)

 

The short twist (3.5 m chord) in track geometry (circled) coincided with the maximum Nadal Index circled in Figure 23. This figure is plotted in the opposite direction to Figure 24.Source: Institute of Railway Technology (Monash University)

The peak in Nadal Index occurred where there was an in-phase[27] lateral alignment variation towards the inside of the curve and out-of-phase[28] variations in left and right rail ‘top’, leading to the track twist.The combined effect of a change in lateral alignment towards the inside of the curve and the partial wheel unloading associated with the twist increased the L-to-V ratio to a critical level, increasing the likelihood of flange-climb.

Tolerances within track geometry standards

At the simulated point of highest risk of flange-climb, track geometry, including top, line, twist and gauge, was compliant with the network’s 40 km/h limit that was applied to the Rushall curve (Figure 25). However, in the prevailing high-friction conditions, a combination of these compliant geometric irregularities, particularly twist and line, resulted in a high chance of flange-climb.

Figure 25: Geometric parameters at the maximum L/V

 

Measured parameter at the Maximum L/V

 

Class 3 (100 km/h)

Class 5 (40 km/h)

Line

28 mm

A Fault

30 mm

50 mm

   

B Fault

20 mm

37 mm

Top

< 20 mm

A Fault

28 mm

42 mm

   

B Fault

22 mm

32 mm

Short Twist

33 mm

A Fault

25 mm

41 mm

   

B Fault

18 mm

33 mm

Source: Chief Investigator, Transport Safety (Vic)

The current network tolerances on track geometry for low-speed curves did not prevent the potential for flange-climb reaching these critical levels, suggesting that the current track geometry limits were inadequate for small-radius mainline curves where flange-climb risk is at its highest.

Influence of cant excess at lower train speeds

At the PoFC, the track cant of 77 mm was close to the design level and well within the network’s tolerances. However, the train’s low speed of 20 km/h meant that the cant at the PoFC was in excess of the equilibrium cant[29] of about 40 mm for that train speed. This excess cant condition would have increased the leading wheel angle-of-attack and propensity for flange climb.

Management of wide gauge

Gauge-widening of small-radius curves was a standard, documented, MTM practice[30] in which track maintenance staff were trained. The network standard specified that for curves of 120 m radius and less (as was the Rushall curve), the track gauge may be widened by up to 12 mm.

Post-derailment measurement identified that track gauge through the curve was variable and often exceeded the specified widening of up to 12 mm (Figure 26).

Figure 26: Track gauge through Rushall curve measured after derailment

Figure 26: Track gauge through Rushall curve measured after derailment. Source: Institute of Railway Technology (Monash University)

This diagram shows numerous exceedances of the wide gauge ‘B’ limit and one ‘A’ limit exceedance within the Rushall curve.Source: Institute of Railway Technology (Monash University)

The post-incident track measurement also identified a wide-gauge ‘A’ fault[31] although the fault was not at the PoFC, and so did not contribute to the derailment.

Records indicate that the wide-gauge ‘A’ fault had been present since early 2015, and had not been corrected. The history of this fault can be tracked over time (Figure 27).

Figure 27: History of wide gauge “A’ fault

Date

Wide Gauge

Recorded km[32]

__________

  1. The small variations in recorded km position are considered within tolerance across the different recording systems.

Comment

1/3/15

33 mm

7.571

Work order TR005087

No evidence of close-out.

1/12/15

34 mm

7.577

Recorded by IEV100

7/12/15

   

‘A’ fault closed-out on Ellipse[33]

__________

  1. Ellipse is an asset management and resource planning application used by MTM.

11/2/16

29 mm

7.572

KRAB post-incident (static)

Source: MTM maintenance records

In terms of flange-climb, the effect of wide gauge is related to an increase in wheel angle-of-attack.

In this instance the wide gauge of over 30 mm was excessive, and this ‘A’ fault was permitted to exist for an extended period, contrary to network standards. The fault was closed-out on the asset management system even though it had not been rectified.

Risk mitigation for small-radius curves

MTM infrastructure standards had no special requirements for the management of derailment risk on small-radius curves. Following risk assessments in 2013[34], the potential need for further derailment protection at high risk locations was flagged. The development of an associated network standard was still under consideration at the time of the Rushall derailment.

Use of Check Rails to mitigate risk of flange climb

One possible method of derailment protection on small-radius curves is a check rail. A check rail (laid closely parallel to and inside the running rail) can be installed on severely-curved track to reduce the risk of derailment and to limit rail head and gauge-face wear. This extra rail comes into contact with the back of the wheel flange and can be used on sharp curves (and other locations) as a check against the opposite wheel of the wheelset climbing the high rail[35]. This restriction to lateral displacement also serves to distribute the lateral force on the wheelset, relieving some of the force on the outside flange (Figure 28).

Figure 28: Use of a check rail in a curve

Figure 28: Use of a check rail in a curve. This illustration demonstrates how a check rail interacts with the back face of the inside wheel flange.
Source: Chief Investigator, Transport Safety (Vic)

This illustration demonstrates how a check rail interacts with the back face of the inside wheel flange.Source: Chief Investigator, Transport Safety (Vic)

Check rails have long been a common global track engineering feature, although their use in Australia has diminished. Check rails were previously used on the Melbourne metropolitan rail network until their general use was discontinued at some point during the 1960s. Check rails had previously been installed on the Up and Down Rushall curves (Figure 29).

Figure 29: Historical use of check rails on Rushall curve c1965.

Figure 29: Historical use of check rails on Rushall curve c1965. The red arrows show check rails on both Up and Down tracks. The left-hand track in this image is the derailment curve.
Source: Bob Wilson, annotated by the Chief Investigator Transport Safety (Vic)
The red arrows show check rails on both Up and Down tracks. The left-hand track in this image is the derailment curve.Source: Bob Wilson, annotated by the Chief Investigator Transport Safety (Vic)

The use of check rails is mandated in several overseas jurisdictions, but not in Australia. Other Australian jurisdictions advised as follows:

  • In NSW, check rails now exist on only a few lines of Tourist & Heritage status. Apart from these operations, NSW country and metro lines have no curvature below 150 m radius and no longer use check rails
  • In South Australia, the Adelaide Metro (a broad-gauge network) has no curvature more severe than 200 m radius and does not use check rails for curve derailment prevention. They advised, however, that they do make use of check rails for derailment prevention in locations where critical buildings or structures are in extremely close proximity to the track and considered to be vulnerable

Information from sampled international jurisdictions was that:

  • In the United Kingdom, check rails are required on passenger lines with curves having a horizontal radius of 200 m or less[36]
  • Irish Rail[37] also required check rails for curves having a radius of 200 m or less.[38] Its infrastructure standards also warn of the possible requirement for check rails where curve radius is more than 200 m but occurs on a hazardous embankment (from a derailment point of view), and where it carries heavy traffic likely to cause severe rail side wear
  • In the United States of America, four transit operators use what is termed a restraining rail for small-radius curves. The radius below which the restraining rail is mandated varies between operators and ranges between 152 m and 305 m[39].

Delay in reporting derailment

Prompt reporting of incidents to the control centre is important to allow emergency response and also to prevent possible further incidents or injuries. In this case the train derailed and one carriage was foul of the adjacent Down passenger line.

The driver was initially unsuccessful in trying to contact Metrol via the train radio, and subsequently made contact by using a company-issued mobile phone. This led to a significant delay of about 7 minutes between the derailment and the halting of traffic through the location.

The Digital Train Radio System (DTRS) has several levels of call with escalating priority and treatment by Metrol. The DTRS log showed that in this instance the driver initially made three lower-priority Train Controller Calls (TCC). A TCC is placed in a queue for the train controller for that track group to respond when able. The driver’s recollection was that he pushed the Train Emergency Call (TEC) button, the level 2 priority call that should be used in an emergency but where there is no immediate danger, however, the system did not recognise or register this call. Post-incident testing of the DTRS by MTM found that once a TCC call was queued, the system would not override it with a TEC call. The system required that the lower-priority call first be cancelled by the driver prior to initiating a higher-priority call.

There is also a Rail Emergency Call (REC) feature on the DTRS that is the highest-priority call. REC calls go to Metrol and to other trains on the same line, to enable those train drivers to take immediate action. It should be used when an emergency could physically affect other trains, such as in the event of a derailment where an adjacent running line is or may be fouled. As this derailed train was lying foul of the other track, an REC call would have been appropriate.

__________

  1. Friction measurements undertaken by the Institute of Railway Technology (Monash University) elsewhere in the Victorian rail network have found that for rough, dry surfaces (such as those observed at the Rushall derailment site), gauge-face friction levels of around 0.45 could be expected.
  2. MTPR 033100-04 L2-TRK-PRO-031 Track Procedure Rail Lubrication, Version 1. Effective 14 June 2013.
  3. Due to the potential for inefficient and often excessive lubrication and contamination of the running surface.
  4. Rail Services Australia Technical Report (December 2000).
  5. Marich Consulting Technical Note on track lubrication (November 2007).
  6. Transportation Research Board (2005) Flange Climb Derailment Criteria and Wheel/Rail Profile Management and Maintenance Guidelines for Transit Operations, The National Academies Press pp25.
  7. The data resolution and modelling used in the simulation were such that the localised effects of the mechanical joint were not modelled.
  8. Both rails having a lateral alignment variation occurring roughly at the same point.
  9. Meaning one rail is peaking while the other is in a trough.
  10. The cant at which the centrifugal force developed during the movement of a train on a curved track at a particular speed is balanced by the cant provided.
  11. MTPR 033000-08 MTM WELDED TRACK MANAGEMENT MANUAL, v2, Chapter 8, clause 1.13.
  12. For the 40 km/h curve, the ‘A’ fault band for wide gauge was 26 mm and above.
  13. The small variations in recorded km position are considered within tolerance across the different recording systems.
  14. Ellipse is an asset management and resource planning application used by MTM.
  15. MTM Project Engineering Support, Regional Rail Link, Derailment Containment: RRL Derailment on High Risk Locations (Draft, v1, advised by MTM as being current).
  16. Australasian Railway Association Glossary for National Code of Practice and Dictionary of Railway Terminology.
  17. UK Railway Group Standard GC/RT5021 December 2011.
  18. Otherwise known as Iarnród Éireann, Irish Rail is the operator of the national Broad-Gauge railway network of Ireland (Republic of Ireland and jointly with Northern Ireland Railways).
  19. Irish Rail standards I-PWY-1154: Horizontal Curvature Design, Issue 1.0, 7/1106, and I-PWY-1106: Track Construction Standards, Issue 1.0, 13/09/2005.
  20. Transportation Research Board (2005) Flange Climb Derailment Criteria and Wheel/Rail Profile Management and Maintenance Guidelines for Transit Operations, The National Academies Press pp 37.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2016-002
Occurrence date 06/02/2016
Location Near Rushall Railway Station, Fitzroy North
State Victoria
Report release date 16/05/2018
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Incident
Highest injury level Minor

Train details

Train operator Metro Trains Melbourne
Train number TD1064
Type of operation Passenger
Departure point South Morang, Vic.
Destination Melbourne (Flinders St), Vic.
Train damage Minor

Accident to Auster J5/F aircraft VH-AFK near Jenolan Caves NSW on 16 October 1954

Summary

This accident was investigated by the late R. W. Adsett, then Senior Examiner of Airmen, New South Wales Region, and his report appears at Enclosure 6B. The following is a summary of the evidence.

Auster J5/F VH-AFK , owned and operated by C. M. Hazelton, trading as Hazel ton Air Taxi and Charter Service, Toogong, New South Wales, departed Bankstown Aerodrome, New South Wales, at 1517 hours on the 16th October, 1954, for Toogong, 124 miles on a bearing of 287°T from Bankstown and directly across the Great Dividing Range. The aircraft was being flown solo by the owner on a private flight and, as the pilot did not hold an instrument rating and the aircraft was not equipped for instrument flight, it was to be conducted under the visual flight rules. The forecast weather throughout the route was "8/8th cloud, base 300-400 feet above terrain about highlands and base at times 100 feet or less in rain on western part of the route.

Accident site map for VH-AFK

Occurrence summary

Investigation number VH-AFK 1954
Occurrence date 16/10/1954
Location near Jenolan Caves
Report status Final
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Occurrence class Accident
Highest injury level None

Derailment of freight train WG713, at Denman, New South Wales, on 19 January 2016

Final report

Safety summary

What happened

On 19 January 2016, at approximately 0400 Australian Eastern Daylight Time (AEDT), an empty Pacific National coal train derailed in a section between the Ogilvie and Rosemount Road level crossings at Denman, New South Wales. The lead bogie of the 64th wagon behind the locomotives operated in a derailed state for a period of time before re-railing at the Rosemount Road level crossing.

The train crew were unaware of the incident until they were notified by the Australian Rail Track Corporation’s (ARTC) network controller, after a signal electrician advised of track damage at that location. The train stopped at Bylong Loop approximately 71 km away from the derailment site.

What the ATSB found

The derailment occurred near a long twist track defect in an area with other known track geometry defects that had been identified a week before. The defective area was managed with Temporary Speed Restrictions (TSRs) until it could be repaired. It was found that the area deteriorated at a faster rate than anticipated, leading to the derailment. The known long twist defect was measured after the derailment and found to be out of ARTC’s acceptable tolerance limits within its Civil Code of Practice (COP).

The ATSB found the track was damaged between the point of derailment up to the Rosemount Rd level crossing. The track damage and marks exhibited on the steel road plate of the level crossing were consistent with that of a train derailing and re-railing.

What has been done as a result

Since the incident, ARTC has:

  • Instigated a recurring weekly “Unscheduled Asset Examination” to inspect the track formation at the incident location until permanent repairs could be completed.
  • Repaired and reconditioned the formation in the area in July 2017.
  • Reviewed its track/civil engineering standards and guidance documentation.

Safety message

Maintenance inspection and categorisation of defects must take into account that defects may deteriorate faster than expected. Factors that can contribute to rapid deterioration should be considered when developing maintenance responses.

Safety analysis

The investigation determined the derailment likely occurred because of a known long twist defect in an area with other known twist defects. The long twist defect had deteriorated at a faster rate than anticipated to a point where it exceeded the tolerance limits specified within the Australian Rail Track Corporation’s (ARTC) Civil Code of Practice (COP). The long twist defect’s increased rate of deterioration was likely due to the known problematic formation in the area.

This section examines the factors which likely contributed to the track deteriorating leading up to the derailment. It also examines the actions taken to manage risk on the network after the train derailed.

Defect identification and prioritisation

ARTC’s COP, specifically Civil Technical Maintenance Plan (TMP) ETE-00-03, requires the routine inspection of its railway infrastructure for track geometry defects. The methods of routine inspection within this plan included, but were not limited, to the use of hi-rail vehicles, track geometry recording car and walking inspections. Track and civil defects could also be identified from reviewing train driver reports, in which case, the affected area would be inspected and verified by maintenance personnel.

Defects identified were then entered into ARTC’s defect management system ‘Ellipse’. The defects were then managed in accordance with the COP.

Track and civil defects were repaired based on the risk they presented and were prioritised. The priority of a defect was determined by considering the size of the defect and the track speed. The classification of priority within ARTC’s COP ranged from ‘Emergency 1’ (E1) which was the highest and ‘Priority 3’ (N) which was the lowest priority. The repair of a defect could be delayed (priority reduced) by the application of a suitable Temporary Speed Restriction (TSR) in accordance with ‘Table 5.5 – Section 5’ of the COP. It must be noted that in some cases, a TSR may not be an effective risk control and a more stringent maintenance response should be considered. This is dependent on the nature of a defect and the track’s characteristics which may contribute to further deterioration. The following was stipulated in ARTC’s COP:

The responses defined in Table 5.5 are based on isolated geometric defects. A more stringent response than that mandated by the geometry alone may be necessary if deterioration of the infrastructure both at the defect and on adjoining track is in evidence.

Track maintenance history

On 20 May 2015, ARTC identified a P3 long twist defect at 314.550 km through a routine hi-rail inspection. Subsequently, on 27 May 2015, a track formation failure was recorded in the vicinity of the defect. As a result of this, a geotechnical inspection was scheduled and the track was tamped[8] on 17 June 2015.

The geotechnical inspection was completed on 21 July 2015 by an ARTC geotechnical engineer. The inspection identified a weakened formation which was heaving towards the Up cess[9] (see Figure 10). As an outcome, the geotechnical engineer recommended the track formation be reconditioned. This work was scheduled to be completed in the 2017/2018 Annual Maintenance Plan (AMP).

As a temporary solution to address the formation problem, the geotechnical engineer recommended the installation of a shear key[10] at the most affected area ‘314.510 – 314.535’. Its purpose was to improve drainage and strengthen the formation. This was installed on 21 August 2015.

On 12 September 2015, a routine track geometry recording car inspection identified a P1 long twist defect and top loss in both rails in the vicinity of the shear key at 314.523 km (see Figure 8). The track was again tamped and the defects were repaired on 7 October 2015.

On 12 January 2016, the driver of loaded coal train UL112 reported “rough riding” at approximately 314.500 km. Train UL112 was travelling at 50 km/h (35 km/h below the maximum allowable speed). The driver recommended a TSR of 40 km/h through the area. The track was assessed by ARTC and a P2 top defect was entered into their defect management system (Ellipse). A 40 km/h TSR was then imposed extending from 314.450 km to 314.600 km.

On 14 January 2016, a scheduled track geometry recording car inspection through the area identified the following (see Figure 9):

  • Top loss on both the Up and Down rail between 314.450 km – 314.550 km
  • An Emergency 1 short twist defect at 314.544 km
  • Two Emergency 1 long twist defects at 314.504 km and 314.546 km
  • A Priority 1 short twist defect at 314.499 km
  • A Priority 1 long twist defect at 314.513 km.

In response to the defects identified by the track geometry car, the 40 km/h TSR was reduced further to 20 km/h. The application of the 20 km/h TSR was in accordance with Section 5 - Table 5.5 of ARTC’s COP and hence reduced the defective area’s repair priority. The area was scheduled to be tamped (realigned) on 20 January 2016 to repair the identified defects.

On 15 January 2016, the crew of loaded coal train, UL234, called network control and reported that their train had experienced substantial lean as it passed through the affected area at 20 km/h. ARTC responded to this by inspecting the track and observed an empty coal train pass through the area at 20 km/h. ARTC maintenance personnel did not record any issues and certified the track for the existing 20 km/h speed restriction.

On 19 January 2016, the defective area had deteriorated to a point where the 64th wagon of train WG713 likely could not negotiate the defective area and derailed then re-railed at the Rosemount Rd level crossing (see Figure 6).

Figure 8: Track geometry recording car’s graph 12 September 2015

Figure 8: Track geometry recording car’s graph 12 September 2015. Source: ARTC (Annotated by the ATSB)

Source: ARTC (Annotated by the ATSB)

Figure 9: Track geometry recording car’s graph 14 January 2016

Figure 9: Track geometry recording car’s graph 14 January 2016.  Source: ARTC (Annotated by the ATSB)

Source: ARTC (Annotated by the ATSB)

Track infrastructure and maintenance analysis

Track formation

The track at the incident location was built on a low height fill embankment which levelled out in the Up direction. The formation comprised of sandy gravelly clay (fill) which was overlying a firm to stiff clay subgrade[11]. The track was built many years ago and ARTC data suggests that the capping layer[12] was built with a grade towards the Up cess so that rainfall onto the track would be directed to the Up side cess drain. This grade would have assisted in directing water away from the formation and reduced the likelihood of formation problems as a result of water ingress. The capping layer would have also protected the track from the migration of fines from the formation which could lead to ballast fouling which could affect drainage and stability.

The ARTC geotechnical inspection following the formation failure in May 2015 identified:

  • Variable ballast and capping layer depths
  • Perched water at the ballast level
  • Ballast fouling, likely due to fines migrating up from the formation
  • Softened subgrade due to water penetration
  • Cess heave on the Up-side of the track.

ARTC determined that the formation failure was due to a ballast pocket which had developed due to cumulative plastic strain[13]. It is likely that this was caused over time because of cyclic loading from normal train operations.

The ballast pocket would have prohibited water from draining away from the track as intended which likely contributed to the formation becoming saturated. This likely provided an environment for localised formation displacement under train loading (cumulative shear failure). As a consequence of this, it is likely that the formation displaced to a point where it was observed as heaving towards the Up cess which was identified by ARTC maintenance personnel on 20 May 2015 (see Figure 10).

Track geometry defects are typically associated with ballast pockets. The track geometry can be temporarily repaired by track tamping to keep the line operational, however the defects will continue to reappear overtime until the underlying formation problem is rectified.

As a result of the geotechnical inspection completed by ARTC, the following was recommended by the geotechnical engineer:

A long-term solution to recondition the area by removing track panels, replacing the soft formation and restablishing the capping layer/ballast depths

A short-term solution by installing a shear key which would remove the softened formation adjacent to the track and replace it with a stronger backfill.

As mentioned in the previous section, a shear key was installed in August 2015 as a temporary solution to the formation problem and track reconditioning was included into the 2017/2018 AMP.

Figure 10: Image depicting a ballast pocket caused by cumulative shear failure

Figure 10: Image depicting a ballast pocket caused by cumulative shear failure. Source: ARTC (Annotated by the ATSB)

Source: ARTC, annotated by the ATSB

Track drainage

Water entering the formation likely comprised of overland flows from slightly elevated terrain (up slopes) from the north and northwest. The incident location was also within a ‘sag point’. A sag point is the low point between two uphill gradients. Sag points are known to be more susceptible to water pooling than other locations due to the capture of water between the adjacent descending gradients.

A cess drain was observed on the Up-side of the track. The cess drain was likely designed to direct water to an open drain adjacent to the Up-side culvert at 314.450 km. The culvert was likely designed to direct water from the Up side open drain to a connected open drain on the Down side. The culvert consisted of three 600-mm reinforced concrete pipes laid under the track from the Up side to the Down side. The Down-side open drain likely directed water away from the track (see Figure 11).

The ATSB observed that the Up-side cess drain was shallow and had a relatively flat gradient. Vegetation was also observed in both the Up and Down open drains, as well as the Up-side cess drain. The ATSB determined that the vegetation in the Up-side cess drain, its level gradient and shallow depth likely restricted drainage in rainy periods from the up slopes.

The Bureau of Meteorology (BOM) recorded 49.4 mm of rainfall at the Muswellbrook Lindisfarne metereological station over two days, on 14 and 15 January 2016, four days before the derailment. The recorded rainfall was approximately 10 km away from Denman. This rainfall combined with the track’s less than effective drainage and existing ballast pocket, likely contributed to further water entering the formation before the derailment. This may have increased the track’s susceptibility to displace and deteriorate at a faster rate under train loading.

Figure 11: Drainage at incident location, orange arrows showing the expected flow of water

Figure 11: Drainage at incident location, orange arrows showing the expected flow of water. Source: Google Earth, annotated by the ATSB

Source: Google Earth, annotated by the ATSB

Shear key

The geotechnical engineer recommended that a shear key be installed between 314.510 km and 314.535 km to strengthen the formation which had experienced the failure. The scope of work was to include; digging a trench by excavating soft formation adjacent to the Up side of the track and backfilling the trench with an aggregate material. The geotechnical engineer recommended the following specifications for the shear key:

The shear key be 25 m long extending from 314.510 km to 314.535 km (area of heave)

The width be at least 1.2 times the depth excavated

The backfill be angular, clean, free-draining material with a wet strength of 100 kN

The backfill material have an aggregate size between 100 mm and 250 mm (large aggregate gabion rock)

Deepening of the cess in front of the shear key (Up-side cess)

Including one 300-mm-wide cross-drain on the country end of the shear key at a depth of at least 200 mm below the ballast pocket.

Extending the cross-drain to the Down rail at a grade of 1 in 20 sloping down to the deepened Up-side cess drain.

ARTC advised that the shear key was installed on 21 August 2015 and was 25 m long, 1.2 m deep and 1.2 m wide. The backfill material used was clean, angular gabion rock of an aggregate size between 100 and 250 mm and no geo-fabric was used (see Figure 12).

Figure 12: Shear key construction at Denman

Figure 12: Shear key construction at Denman. Source: ARTC

Source: ARTC

The ATSB found that the actual shear key width was 20% less than the recommended width specified by the geotechnical engineer. This meant that the shear strength of the shear key would have been lower than what was specified by the geotechnical engineer. It was also identified that a cross-drain was not installed as per the geotechnical engineer’s recommendation.

The absence of the specified cross-drain would have contributed to unwanted water entering the shear key and formation adjacent to the track. This likely assisted further displacement of the formation under train loading after its installation.

The use of large aggregate gabion rock as a backfill material likely introduced voids between the rock particles adjacent to the track. The absence of a geo-fabric and these voids likely provided a pathway for sludge (soft formation and water) to move into the voids. Without the shear key having any drainage capability, the water was likely trapped and contributed to degrade the track formation over time.

The ATSB determined that removing soft formation adjacent to the ballast pocket and replacing it with a non-cohesive, higher strength backfill likely improved the formations shear strength immediately after installation. However, without the specified drainage, combined with the large aggregate size of the backfill without a geo-fabric, likely contributed to continued formation displacement over time.

The ATSB found that, three weeks after the installation of the shear key, a P1 long twist defect was identified in the vicinity at 314.523 km. This was probably due to soft fill and water moving into the backfill voids causing the track to settle and twist.

The ATSB also found that the shear key’s location was incorrectly recorded at 314.600 km – 314.630 km. The incorrect record of the shear keys location may have contributed to unreliable monitoring of its performance after being installed.

Impact of applied temporary speed restrictions

Speed restrictions are typically applied to reduce the dynamic impacts exerted by trains on existing track defects. These impacts can worsen a track defect and may increase the likelihood of a derailment. Although speed restrictions are applied to protect defects by reducing these dynamic impacts, reducing train speeds in some circumstances can further degrade a defect and/or increase risk of derailment. This is dependent on the nature of the defect and the track characteristics.

A train negotiating through a curve at speed experiences centrifugal force[14]. To prevent a train from becoming unstable as a result of this force, superelevation is designed into a curve. Superelevation is a difference in height between two rails, with the higher rail being the outer rail. This height difference assists in balancing the effect of centrifugal and gravitational forces exerted on the track.

Centrifugal force is a function of train speed, mass and a curve’s radius. A higher anticipated centrifugal force will require a higher superelevation design to mitigate its effects. Reducing the speed of a train on superelevated track can therefore transfer a greater proportion of the train’s mass onto the low rail and overload it. This can also reduce the force applied onto the higher rail increasing the risk of high-rail wheel climb.

A transition is designed between tangent and curved track. This is a gradual uniform change in superelevation and curvature. A transition prevents a train from becoming unstable due to a sudden change in direction. The superelevation within a transition increases to a maximum as it approaches a curve and reduces as it approaches a straight section of track.

The derailment occurred approximately five metres after the transition (highest superelevation in the curve) for a 600 m radius curve in an area with a known problematic formation (see Figure 6). The normal line speed at the incident location was 85 km/h for freight trains and 110 km/h for passenger trains. A TSR of 40 km/h was imposed on 12 January 2016 due to an identified top defect and two days later, the track geometery recording car identified five twist defects in the area. This deterioration was likely a result of the track settling due to a displaced formation.

As a response to the identified defects, ARTC reduced the speed at the location further to 20 km/h. The 20 km/h speed restriction reduced the defect priorities and hence extended their repair times as per ARTC’s COP. 132 trains passed over the defective area between the time that the 20 km/h TSR was imposed before the derailment.

Considering the frequency of trains through the area, high axle loads (loaded coal trains) and that the track was superelevated, the 20 km/h TSR likely exposed the low rail (Up rail) to an unintended increase in cyclic load. This loading condition on the Up side combined with the weakened formation, probably contributed to further degradation of the already existing twist defects.

One day after the application of the 20 km/h TSR, a loaded coal train reported “substantial lean” while passing through the affected area. This should have indicated that the TSR may not have been an appropriate maintenance response for the location considering it was superelevated and had a weakened formation.

As a response to the driver’s report, maintenance personnel inspected the track and observed an empty coal train pass over the affected area. Maintenance personnel reported no problems and certified the track for the existing 20 km/h TSR in place. It is likely that the empty coal train observed to pass over the defective area would not have provided a reflection of the track condition under fully loaded conditions. The loaded coal train wheels would have likely depressed the low rail more than the unloaded coal train.

The largest defect recorded at the incident location after WG713 derailed on 19 January 2016 was a 77-mm-long twist defect (high superelevation). The defect’s size was outside the tolerance limit within ARTC’s COP for any speed and was determined to be the likely contributing factor to the derailment.

Incident management

Train WG713 had travelled for approximately 70 minutes between the time the NCO was alerted to a signal failure and the time the signal electrician confirmed track damage. The signal electrician formed the opinion that the track damage was as a result of train WG713 dragging equipment.

The NCO was in contact with the two trains travelling in the opposite direction to WG713, however did not request the train crews to report on the track condition between Denman and Wilpinjong. Track damage between Denman and Wilpinjong may have increased the two trains’ operating risk if WG713 was indeed dragging equipment.

With the exception of the above, the ATSB determined that the affected area was adequately protected and train movements in approach to Denman were adequately managed after the derailment.

TSR procedure compliance

ARTC’s TSR procedure requires a Speed Restriction Notification Form PP163F-01 be completed by the local maintenance depot. This form was required to be sent to train control to allow the track speed database to be updated. The track speed database provides all NCOs with TSR information so that they can communicate accurate data to rolling stock operators. Without this database being updated correctly, train drivers would rely on speed boards for speed limit information only.

This form was completed on 13 January 2016 for the 40 km/h TSR imposed on 12 January. However, it was not updated for the 20 km/h TSR imposed on 14 January. This meant that while the correct speed (20 km/h) was displayed on track, the higher (40 km/h) TSR was still recorded on the track speed database.

The wayside monitor located approximately 75 m from the POM recorded the speeds of all passing trains. It was found that train WG713 complied with the 20 km/h TSR. This was also verified by examining the locomotive’s on-board data loggers.

Of the 132 trains passing the location, 11 exceeded the 20 km/h TSR with six of the exceedances being over 40 km/h. Three of these trains exceeded 60 km/h with the highest recorded speed being 65 km/h on 18 January.

It was evident that speed boards alone were not reliable in managing the application of the TSRs. An updated database would have provided additional information to NCOs and train drivers for the required speed for that section.

The train speed exceedances likely exposed the track to dynamic forces which may have contributed to the defective area deteriorating at a faster rate and increased the risk of a derailment at a higher speed.

Train management

Train WG713’s speed was managed appropriately on approach to and through the TSR. Due to the uphill grade, locomotive power was applied continuously after the initial speed reduction for the TSR. The power applied likely induced tensile draft forces which assisted in re-railing the derailed wagon at the level crossing. It was found that the driver’s actions did not contribute to the incident and that the uphill grade ahead of the Rosemount Rd level crossing likely mitigated the consequence of the derailment.

Incident wagon

The incident wagon, RHCH 7293A was transported to Pacific National’s One Spot maintenance facility at Newcastle for inspection and testing. A twist test was conducted on the incident wagon and no defects were recorded. The ATSB concluded that it is likely that the wagon did not contribute to the derailment.

__________

  1. Tamping is the process by which the rails are lifted by a track machine called a tamper and ballast is packed underneath the reails to restore track alignment.
  2. The cess is the area along either side of a railway track; the Up cess is the area alongside the UP rail and the Down cess is the area alongside the Down rail.
  3. A shear key is an earth-retaining structure which in this case was a trench adjacent to the track filled with gabion rock (see Figure 12).
  4. Subgrade: The native soil which forms part of the track formation
  5. Capping layer: A well-compacted layer of fine aggregate material (sand or gravel) which sits above the formation. It prevents water from penetrating the formation and prevents the migrations of fines up into the ballast.
  6. Plastic Strain: Strain induced by load which causes irreversible deformation of the formation
  7. Centrifugal force: A force which acts on a body which is moving in a circular path and is directed away from the centre around which the body is moving.

The occurrence

Train WG713 with a crew of two was travelling within New South Wales (NSW) from Kooragang Coal Terminal, Newcastle to Wilpinjong Colliery, near Mudgee. As WG713 approached Denman, the train was slowed to comply with a 20 km/h Temporary Speed Restriction (TSR) in force across an area (314.450 km to 314.600 km) with known track geometry defects.

Figure 1: Incident location, Denman, NSW

Figure 1: Incident location, Denman, NSW. Source: ATSB

Source: ATSB

At 314.540 km, the left-hand wheels (in the direction of travel) of the lead bogie of the 64th wagon behind the locomotives mounted the rail. The right-hand wheels likely followed the profile of a long twist[1] defect approximately 30 m before the Point of Mount (POM) which resulted in the left-hand wheels losing vertical load (unloading). This wheel unloading allowed the left-hand wheel flanges to rise onto the Down rail[2] (outside rail) head. The left-hand wheels then tracked across the railhead of the Down rail for 10 m before dropping off the rail at 314.550 km (see Figure 1).

As a consequence of this, the right-hand wheels in the direction of travel also dropped off the Up rail (inside rail), into the four foot (area between the two rails). All wheels of the lead bogie then ran in a derailed state for approximately 690 m towards the Rosemount Road level crossing (see Figure 6). The wheels then struck the steel road plate of the level crossing (see Figure 2). This lifted the wheels up above railhead height and all four wheels re-railed. This was likely assisted by the longitudinal tensile draft forces in the train as the locomotives applied power to pull the train up the grade.

As the wheels ran in a derailed state, they impacted the track fastenings and the foot of the rail. A number of rail welded joints, sleepers and fasteners were damaged by the derailed wheels on both rails. The Up rail at 315.056 km suffered a full cross-section break at an alumninothermic weld joint (see Figure 3). The rail break subsequently broke the track circuit which triggered a signal failure to occur. At 0400 the Network Control Officer (NCO) located at the Australian Rail Track Corporation’s (ARTC) Network Control Centre North (NCCN) was alerted to the problem after the train had cleared the section. The train crew were unaware that the train had derailed and continued onto their destination.

Figure 2: Wheel strike marks on Rosemount Road level crossing road plate

Figure 2: Wheel strike marks on Rosemount Road level crossing road plate. Source: ATSB

Source: ATSB

Figure 3: Broken Up rail at 315.056 due to weld being struck by WG713’s derailed wheel

Figure 3: Broken Up rail at 315.056 due to weld being struck by WG713’s derailed wheel. Source: ATSB

Source: ATSB

Post-occurrence

The NCO responded to the signal failure by calling the crew of WG713 at 0403. The crew reported they had cleared the section and they were not aware of any problems. The NCO then called a signal electrician to investigate the problem at 0406.The signal electrician arrived at the location and called the NCO at 0501 to obtain a Controlled Signal Block[3] (CSB) to inspect the area.

A crew member of WG713 called the NCO at 0503 requesting they be routed into Bylong Loop to restart a locomotive that had shut down in Cox’s Gap No.1 Tunnel. This tunnel was located at 367.000 km, which was 53 km away from Denman and 18 km away from Bylong.

The signal electrician called the NCO at 0510 and reported track damage at the location. The signal electrician advised that track repairs were going to be necessary and that WG713 should be stopped due to potentially dragging equipment on the train. The NCO then contacted WG713 and informed the train crew there was track damage at Denman. The NCO requested the crew to inspect their train when they stopped at Bylong Loop.

The signal electrician called the NCO at 0519 and reported a broken rail at the location which had most likely caused the failed track circuit. At this time, train WG713 was still travelling towards Bylong Loop. A crew member of WG713 called the NCO at 0527 and advised they had arrived at Bylong Loop and one crew member was preparing to inspect the train.

At 0532, the crew of WG713 contacted the NCO and advised that they had inspected WG713 and identified no issues with the train.

At 0550, the NCO contacted train UL264 which was travelling in the Up direction and had passed WG713. At this time, UL264 was approaching Yarrawa Loop located just before Denman. The NCO warned the train driver there was track damage ahead at Denman and requested that UL264 proceed into Yarrawa loop with caution and stop. At this time, the NCO was of the opinion that WG713 may have derailed at Denman and asked the train driver of UL264 to report any damage they observed.

At 0555, the NCO contacted train AT712, another train which was travelling in the Up direction and was approaching Murumbo (see Figure 5). The NCO requested that the train driver proceed into Murumbo loop and stop due to track damage at Denman.

The derailed wagon was taken to Pacific National’s One Spot facility in Kooragang and inspected and tested. A twist test[4] was conducted by Pacific National staff in accordance with its standards.

__________

  1. Long Twist: Variation in cross level (height difference between two rails) measured over 14 metres.
  2. The Up rail in NSW is the left-hand rail when facing Sydney; similarly, the Down rail is the right-hand rail when facing Sydney.
  3. A Controlled Signal Block (CSB) is a form of track worksite protection where the Network Control Officer (NCO) sets controlled signals on either side of a section to stop. This excludes rail traffic from both directions from entering a section of track.
  4. A twist test is to assess a unit of rolling stock’s capability to negotiate a specific curve radius and superelevation.

Safety issues and actions

Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the rail industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report

Surface drainage in areas with degraded formations

Safety issue number: RO-2016-001-SI-02

Safety issue description: The location did not have adequate surface drainage which likely contributed to formation degradation over time.

Shear key installation

Safety issue: RO-2016-001-SI-01

Safety issue description: The shear key was not installed in accordance with the geotechnical engineer’s specification with respect to the following:

a) It did not include a cross-drain.

b) Its width was less than the specified width.

Maintenance response to recurring track defects in areas with a degraded formation

Safety issue: RO-2016-001-SI-03

Safety issue description: A more stringent maintenance response than that for an isolated track geometry defect was not considered or implemented in accordance with ARTC’s COP. A more stringent maintenance response should have been considered given the degraded formation and the track’s rapid deterioration between 12-14 January 2016, two days prior to the derailment.

Additional safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk.

Findings

From the evidence available, the following findings are made with respect to the derailment of empty coal train WG713 at Denman NSW on 19 January 2016. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

The investigation determined that the following factors likely contributed to the derailment:

  • A known long twist defect in an area with other known twist defects which deteriorated at a faster rate than anticipated.
  • The deterioration rate in the area was due to a known degraded formation between 314.450 km and 314.550 km.
  • The location did not have adequate surface drainage which likely contributed to formation degradation over time. [Safety Issue]
  • The shear key was not installed in accordance with the geotechnical engineers specification with respect to the following: a) It did not include a cross-drain b) Its actual width was less than the specified width. [Safety Issue]
  • A more stringent maintenance response than that for an isolated track geometry defect was not considered or implemented in accordance with ARTC’s COP. A more stringent maintenance response should have been considered given the degraded formation and the tracks rapid deterioration between 12-14 January 2016, two days prior to the derailment. [Safety Issue]
  • The application of a 20 km/h TSR on superelevated track likely distributed train loads onto the lower rail which exposed it to an unintended increase in cyclic load. This loading condition likely contributed to deteriorating the already existing twist defects.

Other factors that increased risk

  • The actual location of the shear key was incorrectly recorded. This may have contributed to unreliable monitoring of its performance.
  • 49.4 mm of rainfall during the four days before the derailment likely softened the formation and may have made it prone to further displacement.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • The Australian Rail Track Corporation Ltd.
  • Pacific National Pty Ltd.

Context

Incident location

The incident occurred on the Ulan Line as the train passed through Denman in NSW, part of the the Australian Rail Track Corporation (ARTC) network in the Hunter Region.

Figure 4: Incident location map

Figure 4: Incident location map. Source: Geoscience Australia, modified by the ATSB

Source: Geoscience Australia, modified by the ATSB

The area was controlled through Centralised Traffic Control (CTC) and there were lineside signals to regulate the passage of rail traffic. Track circuits associated with the signals allowed the NCO to see the location of trains in that area.

Figure 5: Track diagram, Muswellbrook to Ulan Coal

figure5_ro2016001_.png

Source: ARTC (Annotated by the ATSB)

Rail infrastructure information

The track at the incident location was a Class-1C single bi-directional line with 60 kg/m head hardened rail. The sleeper type was heavy-duty concrete, clipped together with pandrol e-clip resilient fastenings. The track bed formation consisted of firm to stiff silty clay, underlain by stiff sandy clay.

The track between 314.400 km and 314.450 km had an average falling gradient of 1:382 in the Down direction[5]; the track then began to climb at an average gradient of 1:63 between 314.450 km and 315.000 km. A culvert and open drain was located at 314.450 km, approximately five metres from the Ogilvie Rd level crossing in the Down direction (see Figure 6). The gradient of the Up side cess adjacent to the track was relatively flat from the Point of Mount (POM) to the culvert. The POM was within a 600 m radius right-hand curve just after a transition where superelevation was at its maximum (see Figure 6).

A wayside monitoring station was located approximately 75 m before the POM in the Up direction (see Figure 6). It measured bearing temperature, train speed and axles passed.

Train information

Train WG713 was an empty coal train operated by Pacific National. It consisted of three 90-class locomotives and 92 coal wagons. The total mass of the train was 2099.2 tonnes (not including locomotives). The total length of train was 1510.32 m.

The wagons of WG713 were coal hoppers, a mix of RHFH, RHCH and NHYC types. The lead bogie of the 64th wagon (RHCH 7293A) behind the locomotives in the consist derailed.

The condition and maintenance history of the incident wagon was examined. RHCH 7293A had been maintained at the required frequency and there were no outstanding defects. Post incident testing of the rolling stock did not reveal any significant defects that may have contributed to the derailment.

Site observations post-incident

ATSB investigators examined the incident site on 19 January 2016. The ATSB completed measurements and identified a number of twist defects with the largest being a 77 mm Emergency 1[6] long twist between 314.500 km and 314.550 km. Top[7] loss in the Up rail was also observed at the incident location.

It was further observed that the derailed wheels had damaged a number of concrete sleepers, track fastenings and rail welds. Upon examining the damage at the site, it was evident that at least two wheel sets had derailed.

The steel crossing plate of the Rosemount Road level crossing, 690 m away from the derailment location, displayed damage consistent with rail wheels striking and running over the crossing (see Figure 2). The wheel strike marks indicate a direction of travel back onto the rail track and no damage was evident after the level crossing. This indicated that a combination of the tensile draft longitudinal forces and the wheel striking the road crossing plate elevated the wheel flange sufficiently to assist re-railing the train.

Upon inspection of the wagons of train WG713, the ATSB identified wheel damage on the leading bogie of the 64th wagon. The wheel damage observed was consistent with damage typically found as a result of a wheel having operated in a derailed state for a period of time (see Figure 7).

ATSB investigators inspected the train which traversed the affected location before WG713 and no evidence of damage on that train was found.

Figure 6: Incident location aerial view

Figure 6: Incident location aerial view. Source: Six Maps, Annotated by the ATSB

Source: Six Maps, Annotated by the ATSB

Figure 7: Wheel damage (all four wheels displayed similar damage)

Figure 7: Wheel damage (all four wheels displayed similar damage). Source: ATSB

Source: ATSB

__________

  1. In NSW, Up direction: Towards Sydney, Down direction: Away from Sydney.
  2. Emergency 1: The most severe defect classification as per ARTC’s COP. An Emergency 1 defect is required to be inspected prior to the next train passing and/or repaired before the next train.
  3. Top: Top is the vertical alignment measured for each rail. Top loss refers to a loss of vertical alignment for a length of rail and a top defect refers to top loss which passes a certain threshold within ARTC’s Code of Practice.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2016-001
Occurrence date 19/01/2016
Location Denman
State New South Wales
Report release date 25/03/2019
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Incident
Highest injury level None

Train details

Train operator Pacific National
Train number WG713
Type of operation Bulk coal freight
Departure point Kooragang Coal Terminal, Newcastle, NSW
Destination Wilpinjong Mine, NSW
Train damage Minor

Collision with terrain involving a Robinson R22, VH-NCL, at Newman Airport, Western Australia, on 6 November 2015

Final report

What happened

On 6 November 2015, the pilot of a Robinson R22 helicopter, registered VH-NCL, prepared to conduct a private flight with one passenger on board, from Newman Airport in Western Australia.

At about 0830 Western Standard Time (WST), the helicopter lifted off to about 10 ft above ground level, and the pilot commenced hover-taxiing. As the helicopter started to move forwards, it encountered a gust of wind from behind and sank rapidly. The helicopter landed heavily, then bounced and rotated rapidly to the right. During the accident sequence, the main rotor blade severed the tail, and the helicopter sustained substantial damage (Figure 1). The pilot and passenger were not injured.

Figure 1: Accident site showing damage to VH-NCL

rId21 Picture 5

Source: Airservices Australia - Aviation Rescue Fire Fighting

Loss of tail rotor effectiveness

Loss of tail rotor effectiveness (LTE) causes a yaw to the right in helicopters with a counter-clockwise rotating main rotor. When operating at airspeeds below 30 kt, a tailwind may result in an uncommanded turn, if the tail rotor is unable to provide adequate thrust to maintain directional control. To reduce the onset of LTE, the United States Federal Aviation Administration (FAA) Helicopter Flying Handbook, advises pilots to:

Avoid tailwinds below an airspeed of 30 knots. If loss of translational lift occurs, it results in an increased power demand and additional anti-torque pressures.

To recover from LTE:

If the rotation cannot be stopped and ground contact is imminent, an autorotation may be the best course of action. Maintain full left pedal until the rotation stops, then adjust to maintain heading.

Aviation Short Investigations Bulletin Issue 46

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

 

Occurrence summary

Investigation number AO-2015-128
Occurrence date 06/11/2015
Location Newman Airport
State Western Australia
Report release date 28/01/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Minor

Aircraft details

Manufacturer Robinson Helicopter Co
Model R22 BETA
Registration VH-NCL
Serial number 4430
Sector Piston
Operation type Private
Departure point Newman, WA
Damage Substantial