Derailment of Rio Tinto train ND575, near Tom Price, Western Australia, on 15 December 2015

Final report

Safety summary

What happened

On 15 December 2015, train ND575 – a south bound empty bulk iron ore service operated by Rio Tinto, derailed on the Hamersley Railway east mainline, about 50 km north of Tom Price, Western Australia. As a result of the derailment, there was significant damage to track and rolling stock. There were no injuries.

What the ATSB found

The ATSB concluded that the derailment most likely began with a small horizontal track misalignment on the east mainline, just south of the Mt Brockman Road railway crossing. It was likely that the misalignment grew under train ND575, and eventually became large enough to cause the train to derail. The pathing of a large number of north-bound loaded ore trains on the east mainline probably caused a redistribution of longitudinal rail stresses south of the Mt Brockman railway crossing. This redistribution of rail stresses, coupled with extremely hot weather, and a track irregularity near the point of derailment, meant the track had a reduced capacity to withstand lateral forces, thereby increasing the likelihood of a track buckle event.

What's been done as a result

Rio Tinto have implemented a range of initiatives to reduce the risk of a similar occurrence including changes to operational and maintenance procedures, enhanced strategies for responding to minor track irregularities, and a strategy for balancing tonnage over the line.

Safety message

Early detection, assessment, and effective management of track defects are critical in minimising the risk of derailment and maintaining safe rail operations.

Derailed portion of train ND575, view looking north from ore car 20322

Derailed portion of train ND575, view looking north from ore car 20322

Source: Rio Tinto

The occurrence

On 15 December 2015, train ND575 operated as a routine empty bulk ore service from 7 Mile Yard, Dampier to Tom Price, Western Australia (Figure 1). The train departed 7 Mile Yard at 1004 and travelled on a section of double line, through to Brolga 27 (21.400 km),[1] then on a section of single line through to Emu Yard (78.500 km). The onward passage from Emu Yard, on the east mainline (double line track) through to Possum Station (227.250 km) was uneventful.

During this time, a series of south bound empty ore trains (YC2155, PD1058, RC1889, BC824, TD1284, YC156 and RD1890), also travelling on the east mainline, passed over the Mt Brockman Road railway crossing (234.335 km) at speeds ranging from 79 km/h to 59 km/h.

Figure 1: Location map – Rio Tinto network

Figure 1: Location map – Rio Tinto network. Source:  Map data (c) OpenStreetMap (and) contributors, CC-BY-SA

Source: Map data (c) OpenStreetMap (and) contributors, CC-BY-SA

The train departed Possum Station at 1614. At about 1619, after passing over the Mt Brockman Road railway crossing, the train driver reduced train power from notch 8 to notch 3 to maintain a track speed of not more than 80 km/h.

Shortly thereafter, the driver felt a small surge from the train, followed by an automatic emergency brake application. The driver looked back, towards the rear of the train, and saw a large dust cloud. He immediately ‘bailed off’[2] the independent train brakes to prevent the trailing ore wagons from bunching behind the locomotives during braking. The train slowed down, and came to a stop about 1 km past the Mt Brockman Road railway crossing.

Post occurrence

The driver spoke to train control and advised that the train had come to a stand south of the Mt Brockman Road railway crossing, and some ore cars had probably derailed. After speaking to train control, he detrained and walked the length of the train to inspect for damage.

On completing the inspection, he returned to the cab and communicated with train control, advising that 56-ore cars had derailed (Figure 2). The derailed wagons were located in positions 71 through to 126, and there was about 450 m of track damage.

Figure 2: Derailed portion of train, ore car 35907 and 30907 in foreground near 234.500 km

Figure 2: Derailed portion of train, ore car 35907 and 30907 in foreground near 234.500 km. Source:  Rio Tinto, annotation by ATSB

Source: Rio Tinto, annotation by ATSB

Rio Tinto dispatched operations staff, investigation and recovery crews to site. An authorised person, while on-site, tested the train driver for the presence of drugs and alcohol; the results were negative.

The railway network was re-opened to rail traffic, on a restricted basis, using the west mainline. The east mainline was made operational for rail traffic by 18 December 2015, three days after the derailment.

__________

  1. Measured from a zero reference mark at Dampier.
  2. ‘Bail off’ is a term used to describe the action of: • preventing the locomotive(s) brake from applying automatically during a train brake application, or • releasing the locomotive(s) independent brakes during a train brake application.

Sources and submissions

Sources of information

The sources of information during the investigation – Rio Tinto

References

  • RISSB National Guideline – Glossary of Railway Terminology
  • Bureau of Meteorology – Weather Observations for Paraburdoo, Western Australia (15 December 2015)
  • Rio Tinto: Asset Management Design Criteria – Rail Railway Route Infrastructure Civil & Track (DC-R001)
  • Rio Tinto: Asset Management Design Criteria – Rail Railway Route Infrastructure Civil & Track (DC-R001, 30 August 2010)
  • Rio Tinto: Incident Findings and Recommendations Report – Empty Train Derailment at 234.373 km MLETP (16 February 2016)
  • Rio Tinto: Code of Practice – Track and Civil, Volume 5 Track Geometry (GN-R105, 24 December 2014).

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to:

  • Driver of train ND575
  • Office of the National Rail Safety Regulator
  • Rio Tinto.

Submissions were received from Rio Tinto (incorporating the driver of train ND575) and the Office of the National Rail Safety Regulator. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Safety issues and actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety actions in order to reduce their safety risk. The ATSB has been advised of the following proactive safety actions in response to this occurrence.

Additional safety action taken by Rio Tinto

Rio Tinto has advised of the following proactive safety actions:

  • Update the track geometry condition management process to consider minor irregularities in multiple geometry parameters.
  • Utilise the instrumented ore car fleet for identification of sites at risk of rapid failure due to deterioration of minor irregularities in multiple ore car response parameters.
  • Develop and implement an improved rail stress management process.
  • Implement a tonnage balance strategy and deviation authority process.

Findings

From the evidence available, the following findings are made with respect to the derailment of train ND575, on the east mainline, about 50 km north of Tom Price, Western Australia on 15 December 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • The integrity of the east mainline was compromised by a small horizontal track misalignment near 234.373 km. The misalignment probably grew under train ND575, becoming large enough to cause the train derailment.

Other factors that increased risk

  • The pathing of a large number of north bound loaded ore trains, on the east mainline, probably caused a redistribution of longitudinal rail stresses south of the Mt Brockman railway crossing.. The redistribution of rail stresses, coupled with the extreme hot weather, and horizontal track misalignment (234.373 km) meant the track had a reduced capacity to withstand lateral forces, thereby increasing the likelihood of a track-buckling event near the point of derailment.
  • There was evidence of a growing track misalignment near the point of derailment, however, available management systems were ineffective in alerting maintenance staff to the heightened risk of a track-buckling event.

Other findings

  • The track was regularly inspected in accordance with Rio Tinto maintenance requirements.
  • Train handling and driver performance were very unlikely to have been factors that contributed to the derailment.
  • It is unlikely that the condition of rolling-stock was a factor that contributed to the derailment.

Safety analysis

Based on available evidence, the ATSB concluded that the derailment of train ND575 most likely originated at a horizontal track misalignment at 234.373 km on the east mainline, just south of the Mt Brockman Road railway crossing.

Track inspection and maintenance were found to be in accordance with Rio Tinto’s standards. Rolling stock and driver performance (train handling) were discounted as factors that contributed to the derailment.

The subsequent analysis focuses on track performance and operational demand, and track inspection philosophies as key areas of interest.

Track stability

Track integrity is of prime importance in the running of a safe railway, and is reliant on the inter-relationship of many track components, including the sub-base, ballast bed, sleepers, rail and fastening systems. Although continuously welded rail (CWR) provides significant advantages over traditional rail jointing methods (such as fish-plated track), track disturbing activities (for example, trains moving along a section of track, thermal expansion, resurfacing, undercutting and removal of rail defects) can have an effect on track stability, and result in track that is susceptible to buckling (horizontal misalignment).

Track buckling[13] typically occurs when longitudinal compressive forces, induced by thermal expansion, rail creep and dynamic vehicle loads produce a lateral or vertical load that exceeds the passive restraining forces provided by the track structure. The cause of buckling is normally associated with the following factors:[14]

  • longitudinal rail forces (compressive rail forces)
  • dynamic rail forces (vehicle interaction)
  • lateral track resistance.
Longitudinal rail forces

Longitudinal rail forces, those along the length of the track, can be considerable and are particularly sensitive to rail temperature. The neutral temperature (Rio Tinto used a temperature of 40 °C) or stress free temperature for rail is a theoretical temperature at which the rail is neither in tension nor in compression. If the rail temperature is greater than the neutral temperature, the rail will be in compression, with an increased likelihood of track buckling. Conversely, if the rail temperature is less than the neutral temperature, the rail will be in tension, with an increased likelihood of the rail breaking.

Longitudinal rail forces are directly proportional to the difference between the rail neutral temperature and actual rail temperature.

The high temperature at the time of derailment meant that the rail was in compression with a greater likelihood of a track-buckling event.

Dynamic rail forces

The long-term effect of trains moving along a section of track can result in rail movement (creep) and an associated redistribution of longitudinal rail stresses. Typically, a train slowing into a fixed point (for example a railway crossing or bridge structure) encourages bunching of the rail in the direction of train movement, thereby increasing the compressive forces within the track.

The Mt Brockman Road railway crossing was a fixed point in the track structure. The point of derailment (PoD) of the south-bound train ND575 was about 38 m south of the crossing on the east mainline.

During the period 19 November through to 13 December 2015, 666 loaded ore trains travelled in a northerly direction on the east mainline, compared to just 16 empty trains travelling in a southerly direction. The predominant traffic tonnage was therefore travelling north towards the Mt Brockman Road railway crossing. These loaded ore trains were also approaching the railway crossing on a slight downhill gradient and in trying to maintain a track speed of 80 km/h were probably braking. Therefore, with trains braking and the predominant traffic tonnage into the crossing, this would cause rail bunching (high compressive forces) on the southern side of the crossing.

On 11 December 2015, four days before the derailment, data from the track geometry car US6 showed evidence of worsening[15] horizontal track misalignment just south of the Mt Brockman Road railway crossing.

Observations (post derailment) between the PoD and Mt Brockman Road railway crossing clearly showed evidence of rail creep (Figure 9) through the resilient fasteners, and towards the railway crossing. The magnitude of the creep would have resulted in a significant increase in longitudinal compressive rail forces, exposing the track to an increased risk of buckling.

Lateral track resistance

Buckling resistance in the horizontal plane is contingent on the frictional interrelationship between sleepers and the surrounding ballast.[16] A buckle will develop when the lateral force exerted on the track structure exceeds the track’s ability to resist those forces. If the frictional bond between the sleepers and ballast is reduced, the lateral force required to generate a misalignment is lowered. This may result in a track-buckling event, even in areas that were previously stable.

The track’s ability to resist lateral forces is influenced by:

  • sleeper type and weight
  • ballast quality
  • compaction of ballast between sleepers
  • ballast shoulder geometry.

Ballast quality (angularity/sharpness of the ballast stone) is of critical importance in maximising lateral track stability. Where the ballast within the crib, and/or shoulder, is deficient or in poor condition, the track will be more susceptible to misalignment due to a lack of lateral resistance.[17]

Post derailment, the ballast and ballast profile was examined and found to be in good condition and was unlikely to have been a primary factor contributing to the derailment. However, there was evidence of increasing ore car bounce through this area (recorded by the IOCs in the eight months prior to the derailment). The bouncing of the ore cars would almost certainly cause a degradation of the frictional bonding between the ballast and sleepers, resulting in a reduction in lateral track resistance.

In conclusion, the pathing of a large number of loaded ore trains (travelling to Dampier) on the east mainline probably caused a redistribution of longitudinal rail stresses in a northerly direction towards the Mt Brockman railway crossing. The redistribution of rail stresses, coupled with the hot weather, and a degradation in track quality meant the track had a reduced capacity to withstand lateral forces increasing the likelihood of a track-buckling event.

__________

  1. Substantial misalignment contributed to by longitudinal thermal stresses overcoming the lateral or vertical resistance of the track. Glossary of Railway Terminology.
  2. Track Buckling Research in CWR from US DOT's Volpe Center. www.volpe.dot.gov/coi/pis/work/archive/buckling.html
  3. All measured data was below maintenance response requirements.
  4. Track Stability and Buckling - Rail Stress Management - Zayne Kristian Ole.
  5. ‘Improved knowledge of CWR track’ - Coenraad Esveld.

Context

Location

The Hamersley railway is a privately owned rail network in the Pilbara region of Western Australia, built for carrying iron ore. The line shown at Figure 1 connects the port of Dampier at King Bay to a cluster of mine sites located about 250 km to the south, including the Nammuldi mine. The derailment occurred about 38 m south of the Mt Brockman Road railway crossing (Figure 3) on the Hamersley railway east mainline, 50 km north of Tom Price.

Rio Tinto own and manage the Hamersley railway.

Figure 3: Derailment site, near Mt Brockman Road railway crossing showing point of derailment (PoD) and location of derailed wagons.

Figure 3: Derailment site, near Mt Brockman Road railway crossing showing point of derailment (PoD) and location of derailed wagons. Source:  Rio Tinto, annotation by ATSB

Source: Rio Tinto, annotation by ATSB

Train and train driver information

Train ND575 was a regular Rio Tinto empty ore service operating from the port of Dampier, travelling south on the east mainline, to the Nammuldi mine. The train comprised three GE Evolution locomotives (HL8180 leading, HL8157 and RL8117 trailing) followed by 112 permanently coupled ‘pooled fleet ore cars’ sets.[3] Each permanently coupled set of ore cars had an overall length of 18.667 m and tare weight of approximately 42 t. Train ND575 had an overall length of 2,160 m and was hauling a trailing mass of 4,704 t.

Train driver

The driver in control had extensive train driving experience. He had worked for Rio Tinto for about 16 years and had driven trains for about 27 years. He held the required qualifications to drive trains on the Hamersley network, and was route certified for the track where the derailment occurred.

An examination of the driver’s records confirmed that he had been assessed as meeting the medical standards prescribed by the National Standard for Health Assessment of Rail Safety Workers. A review of the driver’s roster by the ATSB determined that fatigue impairment was unlikely to have affected his performance. The driver said he felt well when signing on for duty, and at the time of the derailment.

Train handling

Locomotives HL8180, HL8157 and RL8117 were each equipped with data recorders (loco-logs). The loco-logs capture information such as date/time, speed, brake pipe pressure, throttle position, and distance travelled.

An extract of the data from the lead locomotive (HL8180) was used to derive the graph at Figure 4; from this data, it was found:

  • Train ND575 was travelling at 78 km/h (2 km/h below the permitted track speed) as it passed over the Mt Brockman Road railway crossing.
  • During the period 1619:35 through to 1619:42, the driver moved the throttle from position T8 to T3 thereby maintaining a train speed below the track speed limit of 80 km/h.
  • The speed of train ND575 dropped from 79 km/h (1 km/h below track speed) to 73 km/h as ore cars in the group 71 to 94 (ore cars numbered 25332 to 20353) passed over the point of derailment (PoD).
  • At 1620:04, the electronically controlled pneumatic (ECP) brake parameters changed, followed by an emergency brake application.
  • At 1620:06, the driver throttles off from T3 through to Idle, and bails off.
  • At 1620:08, there is evidence of an initial reduction in brake pipe pressure (BPP).
  • At 1620:11, there is a major BPP reduction.
  • Train slowed down, coming to a stand at 1620:23, about 1 km past the PoD.

Figure 4: Graph derived from loco-log data, lead locomotive THL8180

Figure 4: Graph derived from loco-log data, lead locomotive THL8180. Source: Rio Tinto, graphed by ATSB

Source: Rio Tinto, graphed by ATSB

A review of loco-log data corroborated the driver’s recollection of the final moments of the event, and showed that train handling, and driver performance was unlikely to have been factors that contributed to the derailment.

Rolling stock – pooled fleet ore cars

Train ND575 was hauling 112 pooled fleet ore car pairs. Two of the ore cars, 30907 and 30910 (position 102 and 154 respectively), were instrumented ore cars (IOCs). Data from the IOC at position 102 (30907) was corrupt after 1620:10. This probably coincided with the time the ore car incurred catastrophic damage during the derailment sequence. The second instrumented ore car (30910) did not pass over the PoD, and continued to supply data throughout and after the derailment event.

An examination of the non-corrupted data from IOC 30907 indicated a significant change in coupler forces at about the time ore car set 25335/20335 (position 81/82 - Figure 5) traversed the PoD. Based on the IOC data, and subsequent examination of damage to ore cars and the track, it was resolved that this probably coincided with the derailment event, and that ore car set 25335/20335 derailed first. Although ore car set 25332/20332 (position 71/72) was also in a derailed state, it was probably dragged off the track by ore car set 25335/20335 through to 25321/20321 (position 73/74).

Figure 5: Looking north - derailed ore car 25332/20332 (foreground) and ore car 25355/20335 (background)

Figure 5: Looking north - derailed ore car 25332/20332 (foreground) and ore car 25355/20335 (background). Source: Rio Tinto, annotation by ATSB

Source: Rio Tinto, annotation by ATSB

An onsite inspection of derailed ore cars found no evidence of component deterioration or damage that may have initiated the derailment. All ore cars were considered fit for purpose, and in compliance with Rio Tinto maintenance standards. A post-derailment review of Rio Tinto records established that all derailed ore cars were serviced in accordance with Rio Tinto’s engineering requirements, and that there were no outstanding maintenance issues.

An examination of data from trackside monitoring systems (RailBAM[4] and WID[5]) did not uncover any evidence of wagon overloading or wheel defects that may have contributed to the derailment.

Based on available evidence the ATSB considered unlikely that rolling-stock condition was a factor that contributed to the derailment.

Track information

The track from the port of Dampier to Tom Price comprised a combination of single line with crossing loops, and double line (east/west mainline) with crossovers. Rail traffic operated bi-directionally on the mainlines, a strategy used by Rio Tinto for balancing rail wear, and minimising stress build up in the rails.

The derailment occurred on the east mainline just south of Possum Station (227.25 km), about 50 km north of Tom Price. The track leading into the derailment site (travelling from north to south) was straight (tangent track) and on a slight upgrade followed by a slight downgrade towards the point of derailment (Figure 6). The track comprised standard gauge (1,435 mm), 68 kg/m continuously welded rail (CWR) mounted on concrete sleepers at 650 mm centres. The sleepers had resilient fasteners (Pandrol Clips) on a nominal 200 mm layer of ballast below the sleepers.

At the time of derailment, axle loads were limited to a maximum of 36 t. The speed limit for trains was 80 km/h. There were no further speed restrictions in place, approaching the derailment site.

Figure 6: Design track elevation – 230 km to 242 km, showing point of derailment and direction of train travel

Figure 6: Design track elevation – 230 km to 242 km, showing point of derailment and direction of train travel. Source:  Rio Tinto, annotation by ATSB

Source: Rio Tinto, annotation by ATSB

Examination of the track

The post derailment examination of evidence established that there were no apparent signs of track spread at or before the PoD, so gauge widening was discounted. Similarly, there were no signs of any broken/fractured rail immediately at or before the PoD. The track near the PoD (Figure 7) showed evidence of a significant horizontal displacement of the track to the right, in the direction of train travel, and was indicative of a track misalignment/buckling event. The railhead[6] at 234.373 km (Figure 7 – right image) showed evidence of wheel flange climb[7] on the right side running rail (direction of travel) followed by witness marks (about 4 – 5 m in length) consistent with a wheel flange crossing the railhead.

Figure 7: Witness marks at PoD (234.373 km) shown by line of arrows on railhead

Figure 7: Witness marks at PoD (234.373 km) shown by line of arrows on railhead. Source: Rio Tinto, annotation by ATSB

Source: Rio Tinto, annotation by ATSB

Damage to sleepers (Figure 7– right image and Figure 8) was only evident after the point where the wheel(s) dropped off the railhead. Beyond the drop-off point, the wheels and bogies of derailed ore cars advancing along the track progressively damaged the track structure, both within the four foot,[8] and to the right side of the track (direction of travel).

Figure 8: Ballast condition before PoD indicate profile and quality in accordance with Rio Tinto requirements

Figure 8: Ballast condition before PoD indicate profile and quality in accordance with Rio Tinto requirements. Source: Rio Tinto, annotation by ATSB

Source: Rio Tinto, annotation by ATSB

As initially intact but derailed ore cars continued to move along the track, and bounce over sleepers, bogie wheels caused heavy damage within the four foot. This resulted in ore cars tilting to the left, dropping off their bogies, and eventually ejecting to the left side of the track. This gave rise to the multi-wagon pile-up shown at Figure 2.

Rio Tinto measured the rail profile, post derailment. The ATSB assessed these measurements for compliance against Rio Tinto standards. Side wear was negligible, vertical wear was about 14 mm. Measurements confirmed that the rail profile was within specified limits, and unlikely to be a factor that contributed to the derailment.

The ATSB assessed the ballast and ballast profile for compliance against Rio Tinto standards using photographs and other information provided by Rio Tinto. The amount of ballast (Figure 8) within the cribs,[9] and the shoulder[10] width and height was all in accordance with requirements. There was no indication of ballast fouling at or near the derailment site.

While the track leading into the derailment was in good condition, there was evidence of rail creep[11] (Figure 9 – left image) between the PoD and the Mt Brockman Road railway crossing. The observed rail creep was in a northerly direction, that is, from the PoD towards the Mt Brockman Road railway crossing, which was acting as a fixed point. There was no observed rail creep at and to the north of the crossing (Figure 9 – right image).

Figure 9: Evidence of rail creep through resilient fastener at PoD

Figure 9: Evidence of rail creep through resilient fastener at PoD. Source: Rio Tinto, annotation by ATSB

Source: Rio Tinto, annotation by ATSB

Track inspection and maintenance standards

Inspections of track visually, and by use of mechanised track geometry vehicles, are two of the main methods for identifying and assessing track defects. Rio Tinto’s Track and Civil Code of Practice, Volume 5 Track Geometry (GN-R105) defined the criteria for assessing and recording the condition of track, and determining mandatory remedial maintenance actions. The standard identified two inspection routines: unscheduled and scheduled inspections.

Unscheduled

Unscheduled inspections were generally in response to defined events, such as extreme weather conditions known to increase the risk of geometry defects. Unscheduled inspections could also be triggered by third-party intervention, such as a train driver’s report of a rough riding track.

There were no train driver reports, regarding rough track/track quality near the PoD that resulted in an unscheduled inspection prior to the derailment.

Scheduled

Rio Tinto uses two main scheduled inspections methodologies for assessing track geometry and identifying defects. These comprise the visual inspections of track and the use of mechanised track geometry vehicles. GN-R105 mandated that inspections be carried out weekly (intervals not exceeding seven days) by track patrol (road/rail vehicle), two monthly by track geometry vehicle inspection, and six monthly by on-train inspections.

A review of maintenance records established that the track near the PoD (234.373 km) was:

  • Regularly inspected by track patrol (road/rail vehicle). The last inspection was on 12 December 2015, three days before the derailment. No defects were identified.
  • Regularly examined using a track geometry car US6. The last inspection was on 11 December 2015 (Figure 10 – red line), four days before the derailment. While the red line in Figure 10 shows that there was evidence of a growing horizontal track misalignment at the railway crossing, the magnitude of the misalignment was well below the Rio Tinto maintenance intervention limit (Figure 10 – ‘Critical Max’).

Figure 10: Graph showing growth of horizontal track misalignment at PoD from data obtained by track geometry car US6.

Figure 10: Graph showing growth of horizontal track misalignment at PoD from data obtained by track geometry car US6.. Source: Rio Tinto – annotations ATSB

Source: Rio Tinto – annotations ATSB

Rio Tinto advised that they do not usually record the date of on-train inspections, and therefore, could not advise if the last on-train inspection was done within the six-month period leading up to the derailment. However, Rio Tinto had an established process for monitoring track condition through a range of parameters (longitudinal, vertical and lateral acceleration) that indicated the ride quality of the fleet of IOCs. This data was progressively being optimised, by Monash University (Victoria) for Rio Tinto, to assist with the determination and evaluation of track irregularities. The setting and monitoring of pre-determined IOC track irregularity limits was intended to allow Rio Tinto to instigate site inspections on an as required basis to enable a maintenance response strategy before exceedances are reached.

While examination of data recorded by the IOC fleet in the eight months prior to the derailment showed an increase in IOC suspension travel and bounce (potentially reflecting a degradation in track quality just south of the Mt Brockman Road railway crossing), the magnitude of the bounce was well below pre-determined intervention limits.

Environmental conditions

The closest Bureau of Meteorology weather station to the derailment site was located at Paraburdoo, about 100 km south of Possum Station. On the day of the derailment, the temperature recorded at Paraburdoo at 1500 was 42.3 °C. There was no rainfall recorded in the 24-hour period preceding the derailment. At the time of derailment (about 1620), the weather was fine and very hot, probably in excess of 43 °C. The minimum overnight temperature was 23.1 °C, a temperature differential of 20.7 °C. For the week preceding the derailment, the weather was dry and very hot; most days exceeded 40 °C.

Rio Tinto also measured actual rail temperature at specific sites along the track. The closest measuring station was at 224 km, about 10 km north of the derailment site. At the time of the derailment, rail temperature measured at the 224 km measuring station was 54.4 °C or 14.4 °C above Rio Tinto’s neutral rail temperature[12] of 40 °C.

Other track misalignment occurrences

The ATSB has investigated eight previous derailments that were attributed to track misalignment/buckle events, namely:

  • RO-2014-003 – Derailment of grain train 9130 at Emu, Victoria on 12 Feb 2014
  • RO-2013-006 – Derailment of train 3MC1 near Locksley, Victoria on 12 Feb 2013
  • RO-2013-002 – Derailment of freight train 3PS6 Yunta, South Australia on 17 Jan 2013
  • RO-2010-015 – Derailment of train 1MP5 at Goddards, Western Australia on 28 Dec 2010
  • RO-2009-004 – Derailment of freight train 6MB2 at Tottenham, Victoria on 30 Jan 2009
  • RO-2008-012 – Derailment of train 3DA2 near Katherine, Northern Territory on 4 Nov 2008
  • RO-2006-001 – Derailment of freight train 3AB6 Yerong Creek, New South Wales on 4 Jan 2006
  • RO-2005-002 - Derailment of train 6MP4 Koolyanobbing, Western Australia and train 6SP5 Booraan, Western Australia on 30 January 2005 (two different events on the same day).

Although each of these occurrences was unique in its own right, and involved various track owners and rail operators, there are some common factors. These factors should be considered in mitigating the risk of derailment from track misalignment/buckling events. They include:

  • The effects of track disturbing works need to be prudently managed, particularly during periods of hot weather.
  • Rail de-stressing operations, if incorrectly managed, can result in high longitudinal track forces, increasing the risk of track buckling events.
  • Ballast quality and profile is essential for providing resistance against lateral track movement.
  • Effective creep monitoring points should be considered (particularly high-risk areas such as curves, and near fixed points, such as railway crossings, turnouts and bridge structures), to assist maintenance staff in determining the potential risk of track misalignment events.
  • Organisations should consider appropriate ‘heat speed restriction’ strategies to lower the risk of derailment events arising from track buckling during periods of high ambient temperature.
  • Management and quality assurance processes need to be robust to ensure that track work is carried out in accordance with prescribed standards.
  • Trains travelling along a track, particularly in one direction, can result in a redistribution of longitudinal rail stresses along the track. A fixed point (level crossings, turnouts, bridge structures, etc.) can further compound the risk of longitudinal rail stress redistribution, resulting in increasing track-buckling risk.

__________

  1. Each ‘pooled fleet ore car’ comprised two permanently coupled ore cars, each independently supported on a pair of bogies.
  2. RailBAM® is a predictive monitoring system that detects and ranks wheel bearing faults and out-of-shape wheels (wheel flats) by monitoring the noise they make.
  3. WIDS is an acronym for wheel impact detection system. The WIDS system is primarily used for detecting wheel flats but can be used for calculating the weight of rolling stock.
  4. The upper part of the rail on which the wheels of rolling stock run.
  5. A derailment in which a wheel flange will climb to the railhead.
  6. The area between the rails of a standard gauge railway.
  7. Ballast area between sleepers.
  8. The ballasted section outside the sleeper ends.
  9. The longitudinal movement of the rails in track caused by expansion or contraction of the rail or the action of traffic.
  10. The stress free temperature for rail which is a theoretical temperature at which the rail is neither in tension nor in compression.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2017

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2015-025
Occurrence date 15/12/2015
Location near Tom Price
State Western Australia
Report release date 11/12/2017
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Accident
Highest injury level None

Train details

Train operator Rio Tinto
Train number ND575
Type of operation Iron Ore
Departure point 7 Mile Yard, Dampier, WA
Destination Tom Price, WA

Erratic airspeed indications involving Boeing 787, VH-VKE, 450 km north of Darwin, Northern Territory, on 21 December 2015

Final report

What happened

On 21 December 2015, a Boeing 787-8 aircraft, registered VH-VKE, departed Melbourne, Australia on a scheduled passenger transport service to Singapore. Approximately 4 hours into the flight, just north of Australia, the airspeed indications became erratic. As a result, the autopilot disconnected and the Primary Flight Control reverted to a mode with fewer automated functions and protections. After approximately 17 seconds the airspeed values returned to normal.

Due to the latching nature of the Primary Flight Control mode reversion, the aircraft had to be manually flown for the remainder of the flight and because of this, the crew diverted the aircraft and made an uneventful landing in Darwin, Australia.

What the ATSB found

The ATSB found that the aircraft had entered an area of weather with high ice water content, which caused the pitot-static systems to become affected by ice. The flight control logic detected a resulting drop in airspeed, sufficient to revert to secondary mode.

What has been done as a result

Boeing revised the flight control software to reduce the chances of reverting to secondary mode in a short duration, erratic airspeed event.

In response to a previous, similar event on another B787-8, the FAA published an airworthiness directive warning flight crew not to make large abrupt magnitude flight control inputs in response to unrealistic drops in airspeed.

Boeing also revised the flight control software to limit the rate of elevator feel reduction with drops in airspeed. This will specifically allow the column to stay at a higher feel force to mitigate large and abrupt unintentional pitch inputs.

Safety message

In this case, the crew showed a high level of professionalism in response to a weather-related event. The crew demonstrated high levels of communication and coordination, promptly applied checklists and procedures.

The ATSB brings to the attention of all flight crews, the importance of following documented procedures and directives when encountering weather related events.

Findings

From the evidence available, the following findings are made with respect to the erratic airspeed indications and subsequent flight control mode reversion on a Boeing 787-8, registered VH-VKE that occurred 250NM north of Darwin on 21 December 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • The aircraft entered a region of high ice water content which caused icing of the three independent pitot sources and anomalous airspeed indications.
  • Short duration anomalous airspeed indications caused the flight control computer to transition to secondary mode. In secondary mode, the autopilot and some auto-flight protections were unavailable to the flight crew.

The occurrence

On 21 December 2015, a Boeing 787-8 (B787) aircraft, registered VH-VKE, departed Melbourne, Australia on a scheduled passenger transport service to Singapore. The flight, operating as Jetstar Flight 07, departed at 0140 UTC (1240 local time)[1]. At 0550 UTC, the aircraft was in cruise, being operated at flight level[2] (FL) 400. The first officer was the pilot flying (PF) and autopilot and autothrottle were engaged.

At the date of this occurrence an airworthiness directive (AD/B787/2013-24-01) relating to reducing the risk of engine icing was in effect, requiring avoidance of ice crystal icing[3] conditions. As such, weather information with relevant en route icing conditions was used by the operator for the purposes of flight planning. In accordance with the AD, the crew manoeuvred around any observed weather conditions that had potential to cause icing to the engines.

Approaching waypoint CURLY, about 250 NM north of Darwin, Australia, the crew reported that a green coloured[4] area, with magenta[5] patches appeared ahead on their weather radar. This area was too close to avoid.

As a precaution the crew activated the seat-belt light. The aircraft entered an area of light turbulence which then increased to moderate. Concurrently with the increase in turbulence the crew noticed erratic airspeed indications on both PFDs, the autopilot disconnected and multiple EICAS[6] messages were displayed including AIRSPEED UNRELIABLE and FLIGHT CONTROL MODE. The FLIGHT CONTROL MODE annunciation indicated that the aircraft flight control system had reverted to secondary mode[7].

Shortly after the event, the captain took over the pilot flying role and the crew conducted the AIRSPEED UNRELIABLE checklist. The captain reported that this was a high workload situation and effective communication and coordination with the first officer greatly assisted the procedure.

The crew maintained an airspeed by setting a pitch angle and thrust level, as indicated in the applicable quick reference handbook table. Through comparison with this table, the crew were also able to identify the most accurate airspeed indication. The crew reported that at this stage it appeared that all indications had returned to normal.

The aircraft was 4 hours into an 8-hour journey, latched in secondary mode and could only be flown manually. Based on this, a decision was made to divert to Darwin, Northern Territory.

After jettisoning fuel to reduce the aircraft weight to maximum landing weight, the crew requested a straight-in approach and made an uneventful landing at Darwin airport.

Weather

A detailed meteorological analysis of the time and location of this event was conducted by the aircraft manufacturer’s specialists. The analysis showed that the area in question contained convective weather related to northern Australia’s monsoon season. These environmental conditions were highly conducive to ice crystal icing.

Airspeed indication system description

The B787 aircraft incorporated a pitot-static air-data reference system (ADRS), consisting of three independent pitot-static sensors. The sensed values from all three systems were input to a fault detection system that provided an airspeed value to the primary flight displays. This value was termed the voted airspeed.

The B787 also computed an angle of attack, synthetic airspeed (AOA speed) value that was available to the flight crew. This speed was derived from angle of attack and inertial data. Significant disparities between voted airspeed and AOA speed alerted the crew via AIRSPEED UNRELIABLE and the autopilot disconnecting.

If voted airspeed dropped to a specific threshold level, a reversion to a secondary flight control occurred. In secondary mode, the following functions of the flight control system were no longer available:

  • Autopilot
  • Auto speedbrakes
  • Envelope protection
  • Gust suppression
  • Pitch compensation
  • Roll/yaw asymmetry compensation
  • Tail strike protection

Elevator and rudder inputs are also more sensitive at some airspeeds, and yaw damping[8] is degraded. For the conditions of this event, secondary mode is a latched condition and once activated, normal mode can only be re-instated on the ground.

Flight data

Flight data from the occurrence shows that the voted airspeed value became erratic for approximately 17 seconds. The voted airspeed values deviated significantly below the independent AOA speed calculated by the aircraft flight computer. As indicated in Figure 1, the voted airspeed was NCD for more than 0.1 seconds twice throughout the event.

Figure 1: Graphical representation of flight data

Figure 1: Graphical representation of flight data

This figure illustrates the discrepancy between the recorded values of voted airspeed and synthetic AOA speed. Within 5 seconds of the diverging values the autopilot and flight computer mode reversion had occurred. The airspeed disagreement lasted for a total of around 17 seconds.

Related occurrences

ATSB occurrence database

A review of the ATSB’s occurrence database between 2006 and 2016 found 11 other occurrences involving high-capacity air transport category aircraft experiencing pitot-static system icing. None of these occurrences involved B787 aircraft.

Overseas occurrences

On 13 March 2014, a B787 operator en route to RJNK (Komatsu Airport) reported a severe turbulence event at FL290 and the Flight Control system reverted to secondary mode. Review of flight data was conducted and showed that, the voted airspeed dropped below 30 knots for 0.25 seconds which caused the system to revert to secondary mode. Four minutes later, the crew (following published procedures) cycled the Primary Flight Computers (PFC) disconnect switch and were able to regain Normal mode for the remainder of the flight. Weather conditions were identified as the likely contributor to the occurrence.

On 12 May 2015, during the cruise phase of flight, a B787 operator experienced a reversion to secondary mode for the remainder of the flight. The aircraft continued to its final destination and the landing was uneventful. Weather conditions were identified as the likely contributor to the occurrence.

__________

  1. Coordinated Universal Time (UTC): the time zone, equivalent to GMT, used for aviation. Local time zones around the world can be expressed as positive or negative offsets from UTC.
  2. Flight level: at altitudes above 10,000 ft. in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 370 equates to 37,000 ft.
  3. At temperatures below freezing near convective weather, the aircraft can encounter visible moisture made up of high concentrations of small ice crystals.
  4. The aircraft’s weather radar detected precipitation droplets. In simple terms, black indicated minimal rainfall, green indicated light rainfall, yellow is moderate rainfall and red indicated heavy rainfall.
  5. Magenta indicated turbulence.
  6. EICAS = Engine indicating and crew alerting system.
  7. Secondary mode: a mode of the flight control system with less automated functions and protections available. More detail is contained in the Airspeed indication System description section.
  8. A yaw damper is a device, independent of the autopilot system that applies rudder correction on order to reduce the lateral oscillations of an aircraft motion, with both rolling and yawing components (Dutch roll).

Safety analysis

Reasons for erratic airspeed indications

The weather analysis provided by the aircraft manufacturer’s meteorological specialists found that the erratic airspeed values likely resulted from ice crystal icing of the pitot-static systems. In this instance the icing affected the voted airspeed values for approximately 17 seconds.

Although there are three independent pitot-static systems for determining computed airspeed, adverse environmental conditions, as encountered during this flight, can affect all three simultaneously. On the B787, the synthetic AOA speed allows an independent source of airspeed as a comparison in order to validate the voted airspeed.

Once the airspeed values returned to normal, the ongoing flight was affected by the reversion and latching of the flight control computer to secondary mode.

Secondary mode reversion

A drop in recorded airspeed to, or below, a threshold level is referred to as a No Computed Data (NCD) state. Throughout the recorded airspeed fluctuations, there were two occasions where the value of voted airspeed went NCD for a sufficient time to revert the flight control system to secondary mode.

Boeing has taken action to revise the software in the flight control computer related to the secondary mode reversion. This revision has increased the time required in an NCD state to revert to secondary mode.

FAA Airworthiness directives

The FAA published an airworthiness directive (AD-2016-07-10) to advise crew not to make large magnitude abrupt control inputs as a response to sudden unrealistic drop in displayed airspeed at high actual airspeed. Abrupt control inputs in this condition could exceed the structural capability of the aircraft.

As a subsequent measure to the FAA AD, Boeing have revised the flight control software to limit the rate of elevator feel reduction, thereby reducing the risk of over controlling the aircraft at high speed.

Even though AD-2016-07-10 was published after this event, the crew actions were consistent with the directive in that they did not make any large changes to the control inputs.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • Flight data
  • Flight crew interviews
  • Jetstar operational documentation (Quick reference handbook, flight crew operations manual)
  • Boeing safety analysis results.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the flight crew, Jetstar Airways, The Boeing Company and the Civil Aviation Safety Authority.

Submissions were received from The Boeing Company and the Civil Aviation Safety Authority. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2017

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-149
Occurrence date 21/12/2015
Location 450 km north of Darwin
State Northern Territory
Report release date 14/06/2017
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Avionics/flight instruments
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer The Boeing Company
Model 787-8
Registration VH-VKE
Serial number 36230
Aircraft operator Jetstar Airways
Sector Jet
Operation type Air Transport High Capacity
Departure point Melbourne, Vic.
Destination Singapore
Damage Nil

Tail rotor strike of slung load involving a Eurocopter AS 350, VH-NPS, at Glenbrook, New South Wales, on 19 December 2015

Final report

What happened

On 19 December 2015, the pilot of a Eurocopter AS 350 helicopter, registered VH-NPS (NPS), was conducting fire control work near Glenbrook, New South Wales, with one crewperson on board. The fire control work included use of a Bambi Bucket (Figure 1) to drop water on the fires, slung under the helicopter by a 100 ft long-line.

Shortly before 1830 Eastern Daylight-saving Time (EDT), the pilot and crewperson decided they would cease operations for the day, due to the limited daylight remaining and the number of hours they had been on duty. The pilot elected to land the helicopter at Glenbrook helipad to refuel, before returning to base.

Figure 1: Bambi Busket

Bambi Bucket

Source: sei.ind.com

The helicopter landed with the bucket and line in front of the helicopter, and the fuel drum to the right of the helicopter. While the engine was still running and the rotor blades turning, the pilot realised that the helicopter’s fuel cap was on the left side and therefore needed to turn the helicopter around to access the fuel drum.

The crewperson exited, stood in front of the helicopter and took hold of the long-line to ensure it remained clear during the turn. The pilot then lifted the helicopter to about 2 ft above ground level. The crewperson used hand signals to direct the pilot to conduct a right turn, walking to stay in front of the helicopter, manage the long-line, and remain in the pilot’s sight. After the helicopter had turned 180°, the crewperson gave the signal to lower the helicopter, which the pilot followed. As the helicopter lowered down, the tail rotor struck the bucket, which was on the ground behind the helicopter. The pilot detected the strike as a vibration through the pedals, and immediately moved the helicopter forward slightly, lowered the collective, and landed.

The tail rotor was damaged (Figure 2); the pilot and crewperson were uninjured.       

Pilot comments

The pilot was not looking at the bucket, which ended up behind the helicopter, but following the crewperson’s hand signals. The pilot commented that to minimise risk he should have lifted back up, turned the helicopter to the left, to keep the path ahead of the tail rotor in sight, and set the bucket back down in front of the helicopter, keeping the bucket in sight at all times.

While both the pilot and crewperson were highly experienced in helicopter operations, both had limited experience specifically in fire control work.

Operator report

The operator conducted an investigation into the incident, and identified several factors that may have contributed to the incident:

  • Due to rostering requirements, an inexperienced fire operations pilot and crewperson were tasked together.
  • The pilot was on their ninth successive day of duty.
  • The pilot lost situational awareness of the bucket.
  • Fatigue may have played a small role in reducing the pilot’s situational awareness of the bucket, and the pilot may not have been aware of this fatigue level.
  • Task pressure to get the job done along with high workload due to last light requirements, crew transport and a request for the crew to continue water bombing, may have reduced situational awareness and crew communication.
  • Time pressure may have contributed to the incident. As incident work is high-paced, it is important for the crew to slow down to allow all critical checks to be completed in an unhurried manner.
  • The day had been extremely hot, highlighting the need for crew to remain well-hydrated, eat and take regular rest breaks.

Figure 2: Damage to VH-NPS tail rotor

Damage to VH-NPS tail rotor

Source: Helicopter operator

Safety action

Helicopter operator

As a result of this occurrence, the helicopter operator has advised the ATSB that they are taking the following safety actions:

Crew pairing

Where possible, pilots who are more experienced with a particular type of operation, such as fire control work, will be rostered with less experienced crewpersons and vice versa.

Fatigue management

The operator will monitor fatigue levels in a more robust manner, including crew self-reporting and managers monitoring their staff.

Training

The operator’s training strategy and practices will be overhauled, with a training package released by 30 March 2016. Pilots and crewpersons will be assessed on their understanding of the operations manual.

Safety message

This incident highlights the importance of effective risk assessment and crew communication. Careful risk assessment is particularly important where a non-standard manoeuvre is planned. Effective crew communication is vital to ensure that potential hazards are clearly identified and understood, and the associated risks are appropriately managed.

Aviation Short Investigations Bulletin - Issue 47

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-147
Occurrence date 19/12/2015
Location Richmond Airport, SW 26 km
State New South Wales
Report release date 13/04/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Miscellaneous - Other
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Eurocopter
Model AS.350B3
Registration VH-NPS
Serial number 3239
Sector Helicopter
Operation type Aerial Work
Departure point Warragamba Dam, NSW
Destination Glenbrook, NSW
Damage Minor

Low fuel event involving a Piper PA-31P-350, VH-OGW, at Bankstown, New South Wales, on 18 December 2015

Final report

What happened

On 18 December 2015, the pilot of a Piper PA-31P aircraft, registered VH-OGW (OGW), operated patient transfer flights from Bankstown to Merimbula, Wagga Wagga, Griffith and return to Bankstown, New South Wales.

At the start of the day, the aircraft was fuelled to a total of 440 L, which the pilot entered into the on-board fuel computer. After landing at Merimbula, the pilot added fuel to a total of 650 L on board. However, the pilot inadvertently entered a figure equating to about 710 L into the fuel computer at that time, which was 60 L more than the actual fuel on board.

Prior to departing on the final sector from Griffith to Bankstown, the pilot reviewed the fuel requirements for the flight. Based on figures from the fuel computer, there was sufficient fuel on board for the aircraft to land at Bankstown with 140 L remaining; which was in excess of the minimum reserves required. Also on board for the flight were a nurse and a patient.

After departure from Griffith, the aircraft climbed to flight level (FL) 110.[1] However, at FL 110, the aircraft encountered a headwind of about 20 kt. In order to conserve fuel, the pilot elected to descend to 10,000 ft, where the headwind decreased to about 10 to 15 kt.

At about 2300 Eastern Daylight-saving Time (EDT), the aircraft landed at Bankstown Airport. The following morning, prior to the first flight of the day, another company pilot dipped the aircraft’s fuel tanks, and assessed that only about 60 L of fuel remained after the previous flight. A minimum of 45 minutes of fixed fuel reserves, equating to 120 L, was required for the flight, hence the aircraft had landed the previous night with half the required fuel reserves remaining.

Wind

The forecast was for variable winds at 10 kt increasing to 20 kt above 10,000 ft. Based on the wind encountered on the previous sectors, the pilot expected a tailwind for the return flight.

Fuel calculations

The fuel computer provided the fuel flow and fuel consumed for each sector flown. The computer held two units: total fuel on board in US gallons (USG) as entered by the pilot; and fuel flow, which was calculated by fuel flow sensors in the fuel inlet lines. The fuel flow was displayed in USG per hour, and tallied the amount of fuel consumed in USG. The pilot could select to display the quantity of fuel remaining, which the computer calculated by subtracting the fuel consumed from the fuel on board figure entered by the pilot.

Before entering the fuel figures, the pilot converted the amount of fuel on board in L to USG as required for the computer. The incorrect figure entered at Merimbula may have resulted from a conversion error and/or a data entry error.

The pilot planned to land at Bankstown with 140 L of fuel remaining; and reported that the fuel computer indicated that 130-135 L remained after landing. The aircraft fuel gauges indicated that about 40 USG remained (150 L). Those figures corresponded with the pilot’s assessment of the planned fuel consumption and the headwind encountered during the flight.

Pilot comments

The pilot calculated that there was adequate fuel on board to meet the minimum fuel required for the flight plus a small excess; which would ensure the aircraft was below the maximum landing weight for the arrival to Bankstown, with fixed reserves intact.

The pilot had a total of 17.3 hours on the PA-31P aircraft type, although significantly more in the PA-31. The pilot had completed a company check flight in the aircraft that morning, and then operated three sectors prior to the incident flight.

The pilot had previously used the same type of on-board fuel computer in different aircraft, and assumed it was a reliable source for establishing the actual amount of fuel on board. However, the only reliable source approved by the operator, was to fill the fuel tanks to full, or to a known quantity and use a dipstick to crosscheck the fuel on board with the computer figure. The pilot stated that in aging aircraft, the fuel gauges were unreliable.

The pilot also commented that the dipstick provided a reliable indication of the fuel on board for the first flight of the day, but may provide an inaccurate reading if the aircraft was not parked on level ground.

Operator comments

The aircraft operator’s report into the incident stated that the pilot had not followed the fuel crosscheck requirements of the company operations manual.

Company flight crew subsequently verified that the fuel computer in that aircraft was accurate.

Safety action

Aircraft operator

As a result of this occurrence, the aircraft operator has advised the ATSB that they are taking the following safety actions:

Notice to air crew

The aircraft operator issued a notice to air crew (NOTAC) immediately following the incident. The notice reminded company flight crew of the importance of adhering to the company’s fuel cross check requirements. The notice also advised of an impending amendment to the Operations Manual to clarify the specific fuel cross check requirements of the PA-31P.

The amendment stated:

PA31P aircraft have a calibrated dipstick provided and an on-board Shadin fuel computer installed. The dipstick must be utilised for visual confirmation of a known fuel amount to be entered into the Shadin. In the event the dipstick is lost and/or the Shadin is un-serviceable then check if fuel quantity can be visually seen at the bottom of the tank, if fuel is lapping at the entry point the aircraft has 300 litres on-board. A pilot shall not depart on any mission without a visual confirmation of this minimum 300 litres.

Visual fuel crosscheck using the dipstick must be completed to verify the accuracy of the Shadin and the accuracy of pilot input into the Shadin on each subsequent sector where fuel is not added.

Safety message

The ATSB SafetyWatch highlights the broad safety concerns that come out of our investigation findings and from the occurrence data reported to us by industry. One of the safety concerns relates to aircraft fuel management.

Pilots are reminded of the importance of careful attention to aircraft fuel state. ATSB Research report AR-2011-112 Avoidable accidents No. 5 Starved and exhausted: Fuel management aviation accidents, discusses issues surrounding fuel management and provides some insight into fuel related aviation accidents. The report states that ‘accurate fuel management starts with knowing exactly how much fuel is being carried at the commencement of a flight. This is easy to know if the aircraft tanks are full, or filled to tabs’.

This incident highlights the need for pilots to use a known fuel quantity to obtain accurate fuel figures, and not rely on planned fuel consumption or a fuel calculator. Many factors can affect planned fuel consumption, including power and fuel mixture settings, variance in wind direction and strength, and holding or delays due to air traffic control. Furthermore, on-board fuel computers that rely on manual data entry may also be subject to error.

Aviation Short Investigations Bulletin - Issue 47

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. At altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 110 equates to 11,000 ft.

Occurrence summary

Investigation number AO-2015-146
Occurrence date 18/12/2015
Location Bankstown Airport
State New South Wales
Report release date 13/04/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Low fuel
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Piper Aircraft Corp
Model PA-31P-350
Registration VH-OGW
Serial number 31P-8414044
Sector Piston
Operation type Medical Transport
Departure point Griffith, NSW
Destination Bankstown, NSW
Damage Nil

Flight crew incapacitation involving a Socata TBM 700, VH-YZZ, Lake Macquarie ALA, New South Wales, on 15 December 2015

Final report

What happened

On the morning of 15 December 2015, a SOCATA TBM 700 aircraft, registered VH-YZZ (YZZ), departed Gold Coast Airport, Queensland for Lake Macquarie Airport, New South Wales. On board were the pilot and one passenger.

The flight to Lake Macquarie was uneventful and the pilot reported feeling well.

SOCATA TBM 700, VH-YZZ

SOCATA TBM 700, VH-YZZ

Source: Martin Eadie/Airliners.net

Having not previously landed at Lake Macquarie, the pilot overflew the aerodrome, at approximately 1,500 ft above ground level, to confirm the airfield layout. After the overflight, the pilot joined the upwind leg and commenced a left circuit for runway 07 (Figure 1). The aircraft was configured for landing during this time and, when on final, the approach speed was set to 80 kt.

Figure 1: Indicative flight path of YZZ overflying Lake Macquarie Airport prior to joining the downwind and final legs of the approach to runway 07

Figure 1: Indicative flight path of YZZ overflying Lake Macquarie Airport prior to joining the downwind and final legs of the approach to runway 07

Source: Google maps – modified by ATSB

When YZZ was on short final, the pilot began to feel ‘woozy’ and, shortly after, lost consciousness. Closed circuit television footage showed the aircraft descended onto the runway and bounced before impacting the runway in a nose-low attitude to the left of runway centreline. The nose-low impact collapsed the nose gear and caused the forward section of the aircraft to strike the runway, bending all four propeller blades. It was at this time that the pilot regained consciousness, approximately 5 to 10 seconds after losing consciousness. The aircraft then skidded on the runway before veering to the right, and onto the grass (Figure 2). The aircraft eventually stopped on the grass area next to the runway (Figure 3).

Figure 2: Final approach path of YZZ to runway 07 with the approximate positions the aircraft first impacted the runway, bounced, the second impact and the approximate path YZZ skidded along, and across, the runway before coming to a stop on the grass

rid24-yzz-impact-path.png

Source: Google maps – modified by ATSB

Figure 3: YZZ post-accident showing the damage to the forward section of the aircraft as a result of the nose gear collapse and skidding on the ground

Figure 3: YZZ post-accident showing the damage to the forward section of the aircraft as a result of the nose gear collapse and skidding on the ground

Source: Phil Hearne/Fairfax syndication

After YZZ had come to a stop, the pilot and the passenger detected a burning smell and made an emergency egress from the aircraft. Once they were safely clear of the aircraft, the pilot saw that there was no fire and that the smell was from the nose gear being jammed under the fuselage and skidding on the runway surface. The pilot then re-entered the aircraft and shut down the engine to ensure that the risk of fire was eliminated. Neither the pilot nor the passenger were injured in the accident, however the aircraft was substantially damaged.

Aircraft systems

All systems on the aircraft were functioning normally. There was no fault evident with any system that could have contributed to the pilot’s loss of consciousness.

Pilot comments

The pilot stated they were well rested, had eaten prior to and during flight and were appropriately hydrated. The pilot reported that they had no previous loss of consciousness events, nor were there any extra pressures or distractions that may have affected them during the flight.

Medical tests and monitoring after the accident found that the loss of consciousness was due to a previously undiagnosed heart condition.

Safety message

The health of flight crew is vitally important for the safe operation of aircraft. Ultimately, all flight crew are responsible for monitoring their own health and wellbeing. Any deterioration in health that may affect the performance of flight crew should be taken seriously.

While in this instance, the pilot had no indication of a health concern before to the event, it is important for pilots to assess their fitness to fly prior to flight. The following checklist provides a quick reference. A description of aeromedical factors is available in the US Federal Aviation Authority (FAA) Pilot’s Handbook of Aeronautical Knowledge.

US Federal Aviation Administration - I'm safe checklist

Source: US Federal Aviation Administration

In February 2016, the ATSB released a research report into pilot incapacitation occurrences between 2010 and 2014. The report provides valuable insight into pilot incapacitation occurrences in high-capacity air transport, low-capacity air transport and general aviation.

The report highlights how pilot incapacitation can occur in any operation type, albeit rarely. Of interest, the research found that around 75 per cent of the incapacitation occurrences happened in high-capacity air transport operations (about 1 in every 34,000 flights). With the main causes being gastrointestinal illness and laser strikes. Low-capacity air transport and general aviation had fewer occurrences with a wider variation of causes of pilot incapacitation. These ranged from environmental causes, such as hypoxia, to medical conditions, such as heart attack.

Importantly, the report reminds pilots in general aviation, to assess their fitness prior to flight. Assessment of fitness includes being aware of any illness or external pressures they may be experiencing.

Aviation Short Investigations Bulletin - Issue 47

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-145
Occurrence date 15/12/2015
Location Lake Macquarie ALA
State New South Wales
Report release date 13/04/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Flight crew incapacitation
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer SOCATA-Groupe Aerospatiale
Model TBM 700
Registration VH-YZZ
Serial number 226
Sector Turboprop
Operation type Private
Departure point Gold Coast, Qld
Destination Lake Macquarie, NSW
Damage Substantial

Signal passed at danger and derailment of empty Tangara service 109D, at Hornsby, New South Wales, on 17 December 2015

Final report

What happened

At approximately 1600 Eastern Daylight-saving Time[1] on 17 December 2015, the rostered driver of 109D arrived at Hornsby Maintenance Centre (HMC) to take charge of the train. The rostered driver was scheduled to meet with the preparing driver of 109D at 1606. However, when the rostered driver arrived at the train, he was unable to find the preparing driver and found the train’s controls were in an isolated state.

The rostered driver was in process of cutting in (starting up) the train when he received a bell from the guard on 109D. Confused by the bell, the rostered driver called the guard on the train intercom. The guard said they needed to conduct a ‘continuity test’[2]. The rostered driver agreed then commenced with the continuity test.

Shortly after, another driver (passenger driver) arrived at the crew compartment guard side door and asked the rostered driver if he could travel as a passenger to Epping Station. The rostered driver agreed and continued with the continuity test.

At 1606, the HMC yard shunter approached 109D and provided a hand gesture (wave) to the rostered driver, which the rostered driver understood as a signal to depart from HMC. After a second wave from the HMC yard shunter, the rostered driver indicated his intent to depart. The rostered driver recalled feeling under pressure to depart the train and did not complete the continuity test or log onto the Metronet radio[3] before departing the train.

At 16:08:22, 109D departed from signal HY4FRB on the Outwards Car Shed Road (OCSR). See Figures 1 and 2.

Figure 1: Train detected in block section after Signal HY4FRB

Figure 1: Train detected in block section after Signal HY4FRB. 
Screenshot from ATRICS (Advanced Train Running and Information Control Systems). Annotations show the locations of Hornsby Station, Signal HY82, the red line indicatring a train in the block section and Signal HY4FRB. Source: Sydney Trains ATRICS , annotated by ATSB

Source: Sydney Trains ATRICS[4], annotated by ATSB

Figure 2: View from train driver’s cab to signal HY4FRB at HMC

Figure 2: View from train driver’s cab to signal HY4FRB at HMC. Photograph of the tracks. Annotation highlights the location of Signal HY4FRB. Source: ATSB

Source: ATSB

As the train progressed along the OCSR towards signal HY82, the rostered driver and passenger driver recall discussing work schedules with each other.

The passenger driver asked the rostered driver for his route diagram[5]. The rostered driver recalled seeing signal HY82 displaying a ‘proceed at caution’ indication (amber light) before attempting to locate the route diagram from inside his workbag, located on the nearby driver’s seat.

The rostered driver gave the route diagram to the passenger driver who looked at the diagram to confirm the scheduled arrival time at Epping station before handing it back to the rostered driver.

At 16:09:07, 109D appeared on the ATRICS board when the train occupied the block sections between signals HY4FRB and HY82. HY4FRB had a ‘proceed at caution’ indication and HY82 had a stop indication.

At 16:10:42, a yellow line from 534 points to Platform 3 Hornsby Station appeared on ATRICS, which indicated the Network Control Officer Hornsby Panel[6] (NCOH) had requested the intended route for 109D. Additionally, ATRICS indicated 109D occupied the block section directly after signal HY82 (HY82AT) with signal HY82 displaying a stop indication. This was also reflected in the Weslock data log[7]. This meant 109D had passed signal HY82 at stop – Signal Passed at Danger (SPAD). See Figure 3.

Figure 3: Route set for Platform 3 and 109D is occupying block section HY82AT

Figure 3: Route set for Platform 3 and 109D is occupying block section HY82AT.
Screenshot from ATRICS (Advanced Train Running and Information Control Systems). Annotations highlight the route for 109D set to PLatform 3 as indicated by a yellow line, 534 points, HY82AT block section ingicating occupied while HY82 is at stop, Signal HY82 at stop indication, and Signal HY4FRB at caution indication. Source: Sydney Trains ATRICS, annotated by ATSB

Source: Sydney Trains ATRICS, annotated by ATSB

Examination of the ATRICS and Weslock data showed that signal HY82 was at stop and 534 points were set to direct traffic towards platforms 1 and 2 (normal position) as train 109D approached. See Figure 4.

Less than one second before 109D passed signal HY82 at stop, the NCOH had requested a route from signal HY82 towards Platform 3, requiring 534 points to move to the reverse position.

Figure 4: Signal HY82 and 534 points. 534 points set for movement straight ahead (normal position)

Figure 4: Signal HY82 and 534 points. 534 points set for movement straight ahead (normal position). Source: ATSB

Source: ATSB

Train 109D was able to pass signal HY82 and travel the seven metres to 534 points before the points could change position. As the lead bogie of the first carriage travelled over 534 points (still in the normal position), the points started to reverse position, directing the trailing bogie towards Platform 3. The opposing movements of the leading and trailing bogies caused the carriage to twist and eventually derail the train. See Figure 5.

Figure 5: 109D derailed over 534 points

Figure 5: 109D derailed over 534 points. Source: ATSB

Source: ATSB

At 16:10:57, 109D is indicated on ATRICS as occupying block HY82AT and block HY82BT. See Figure 6.

Figure 6: 109D occupying section HY82AT and HY82BT

Figure 6: 109D occupying section HY82AT and HY82BT. Source: Sydney Trains ATRICS, annotated by ATSB

Source: Sydney Trains ATRICS, annotated by ATSB

The leading bogie was confirmed to have travelled straight ahead as it triggered occupation of block section HY82BT. However, the trailing bogie of the first carriage and the remainder of the train had been diverted towards Platform 3 Hornsby Station (block section HY82AT).

The rostered driver recalled feeling the train twist in an awkward way as he passed over 534 points and applied the brakes to stop the train.

109D travelled 553 metres in 2 minutes and 20 seconds between Signal HY4FRB and Signal HY82, averaging a speed of 14.2 km/h. See Figure 7.

Figure 7: Path of 109D from OCSR to 534 points

Figure 7: Path of 109D from OCSR to 534 points. Source: Sydney Trains NLA 302 Hornsby, annotated by ATSB

Source: Sydney Trains NLA 302 Hornsby, annotated by ATSB

At 16:11, SPAD alarms sounded at Homebush Control Centre on the Hornsby ATRICS panel. The NCOH received alarms and attempted calls over the Metronet radio but was unable to speak with the caller.

At 16:14, the NCOH attempted to receive another call however was still unable to connect with the person on the other end.

At 16:15, the NCOH made contact with another driver on 167N, which was on the Up Main line and asked for confirmation whether 109D had derailed. The driver of 167N was able to confirm that 109D had derailed.

At 16:16, the driver of a nearby train, N24, called the NCOH. The driver of N24 could see the derailed train describing it to the NCOH as “a bogie in the dirt”. The NCOH requested the driver of N24 to pull up, to make an emergency stop.

The NCOH informed the Train Controller and Operations Controller at the Rail Management Centre (RMC) that 109D had SPAD and possibly derailed.

At 16:18, the NCOH made an emergency broadcast for all trains in the Hornsby Area to come to a stop. The NCOH attempted to contact 109D without success.

At 16:20, the Incident Rail Commander (IRC) was informed by the Shift Manager RMC of a SPAD coming out of the OCSR and was required to attend. The IRC advised he would be there in approximately 15 minutes.

At 16:21 the driver of N24 called the NCOH and provided a phone number of the passenger driver on 109D.

At 16:40, the IRC arrived at Hornsby and approached 109D from a side gate halfway between Hornsby Station and the sidings. The IRC recalled recognising a train technician and seeing another person on the track ahead near 109D.

The IRC contacted the Signaller and created a safe place utilising the disabled train[8].

At 17:05, the IRC discussed the condition of the situation with the relevant disciplines (Overhead electrical, Signals, Civil and Train Technician). The IRC determined that the train could be pulled back from 534 points to release the interlocking of the signals caused by the presence of 109D occupying the block sections HY82AT and HY82BT.

At 17:17, the IRC had 109D propelled back to signal HY82. The IRC informed Train Control the movement was successful and standing train protection would remain with the train now standing on the down side of signal HY82.

By 18:15, Overhead electrical, Civil and Signals had certified the infrastructure fit for purpose.

Due to delays caused by the SPAD and derailment over 534 points, 109D remained at signal HY82 until after the peak period before being moved back into HMC.

Safety analysis

Driver distraction

The rostered driver allowed the passenger driver to ride in the driver’s cab to get to Epping Station.

While this practice has been accepted by the organisation, this situation heightens the risk of distraction to the driver operating the train. In this incident, both the rostered driver and passenger driver recall making conversation about their days and their work schedules as the train departed from HMC and traversed the OCSR towards signal HY82 and 534 points.

At the time of departure from HMC and onto the OCSR, the rostered driver passed two signals:

  • The first signal, HY4FRB, when leaving HMC on the OCSR.
  • The second signal, HY82, which was approximately 550 metres further along the OCSR and the signal that was passed at danger.

HY4FRB displayed a ‘proceed at caution’ indication (amber light), while HY82 displayed a stop indication (red light) for the duration of the incident.

The rostered driver recalls spotting a ‘proceed at caution’ indication when asked about the aspect of signal HY82. However, it is likely the signal with a ‘proceed at caution’ indication was HY4FRB. It is likely the rostered driver lost situational awareness and missed seeing signal HY82 due to being involved in conversation with the passenger driver.

Emergency communication systems

When train drivers prepare a train for service, they are required to log onto the Metronet train radio system to ensure they have communications with Train Control.

In this incident, there was a preventable delay in establishing communications between the Signaller and the train crew on 109D after the incident had occurred. Had the Metronet radio system been logged in, there would have been direct communications between the Signaller and the train driver of 109D.

Reliable communications between Train Control and train services, including train crew, is paramount for safe operations, especially during degraded and emergency situations.

Route familiarity

This was the first occasion the rostered driver had departed the HMC without supervision, since his familiarity training of the area approximately three months before.

Findings

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

  • The rostered driver of 109D was distracted by interaction with the passenger driver at the critical time of approach to signal HY82.
  • Without being logged onto the Metronet radio system, effective communications could not be made between Train Control and 109D.
  • This was the rostered driver’s first unsupervised departure from HMC onto the OCSR since being qualified as a driver.

Safety action

The ATSB has been advised of the following proactive safety action in response to this occurrence.

Sydney Trains

  • Conducted briefings with train crew on compliance to network rules and procedures and a previously issued safe work instruction on eliminating in-cab distraction.
  • Completed a major upgrade of the track and signalling in Hornsby yard. This included the reconfiguration of various tracks and points on through lines as well as the provision of new signalling, train stops and signal telephones.

Safety message

Train drivers must maintain situational awareness at all times when driving trains. Any driver riding as a passenger in the driver’s cab must respect the driver’s requirement to be vigilant and not engage in any way that may distract the driver in control of the train.

Rolling stock details

Manufacturer and model:A. Goninan & Co, Tangara 
Operator:Sydney Trains 
Carriage number:D6171 
Type of operation:Rail 
Persons on board:Crew – 2Passengers – 1
Injuries:Crew – 0Passengers – 0
Rolling stock damage:Minor 

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. Eastern Daylight-saving Time (ED-sT): Coordinated Universal Time (UTC) + 11
  2. A continuity test is a check of the train’s air brakes and communications systems.
  3. The Metronet radio is the closed communication system used between train drivers and Network Control Officers on the Sydney metropolitan rail network.
  4. ATRICS (Advanced Train Running and Information Control Systems), is the software package developed for the Sydney metropolitan rail system. It is used to control the signalling system and provide feedback to train controllers about the position of points, status of signals and location of trains.
  5. The driver’s route diagram is the driver’s work schedule for the day which typically includes times and train service numbers that the driver is required to meet.
  6. The NCOH is one of many network control officers who manage the safe movement of trains around the network through operating track points and controlled signals.
  7. Weslock is the precision data logging system and this information is similarly represented in the ATRICS.
  8. Creating a safe place utilising standing rail traffic is colloquially known as ‘Standing Train Protection’. NTR 432 Protecting activities associated with in-service rail traffic is the procedure which describes this process.

Occurrence summary

Investigation number RO-2015-026
Occurrence date 17/12/2015
Location Hornsby
State New South Wales
Report release date 14/12/2018
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Incident
Highest injury level None

Train details

Train operator Sydney Trains
Train number 109D
Type of operation Passenger
Departure point Hornsby, NSW
Destination Central Station, NSW
Train damage Minor

Operational event involving Boeing 787, 9V-OJC, near Perth Airport, Western Australia, on 4 December 2015

Final report

Safety summary

What happened

On 4 December 2015, a Scoot Boeing 787-9 aircraft, registered in Singapore as 9V-OJC (OJC) was operating a scheduled passenger flight from Changi International Airport, Singapore, to Perth International Airport, Western Australia. At about 1743 Western Standard time, OJC commenced an instrument landing system (ILS) approach to runway 21 at Perth.

During the approach, the aircraft’s autopilot flight director system (AFDS) entered a degraded mode, and presented the crew with information that they erroneously believed represented the glideslope. The crew followed the displayed information, which resulted in a descent below the designed approach path and the subsequent activation of the aircraft’s enhanced ground proximity warning system. The crew conducted a go-around, and completed an uneventful approach and landing.

What the ATSB found

During the approach, a disturbance of the ILS glideslope signal occurred, likely due to an aircraft taxiing for take‑off on runway 21, resulting in OJC capturing the ILS glideslope prematurely. Because of this, the AFDS entered a degraded mode, presenting the crew with information extrapolated from a previous position, rather than updated glideslope information.

While taking actions to reset the AFDS, the crew continued descending as per the presented information, without identifying cues that indicated the information was unreliable. This resulted in an abnormally high rate of descent, leading to a descent below the designed approach path, and activation of the aircraft’s enhanced ground proximity warning system.

The flight crew were likely experiencing higher than normal workload, due to a combination of the high speed approach and troubleshooting the unexpected glideslope indications. This reduced the effectiveness of cockpit communication and delayed correction of the aircraft’s low altitude.

What's been done as a result

The aircraft operator advised they communicated the essential elements of this event and associated AFDS implications (including primary flight display and head-up display indications) to the pilot group. Pilots have been reminded to monitor the basic flight instruments and relevant check heights during the approach, in addition to the aircraft calculated guidance.

Stabilised approach criteria and associated callouts and actions have also been emphasised. In addition, the importance of energy management and use of the HUD to monitor appropriate descent path information has been highlighted.

Safety message

Flight crew are reminded that when conducting an ILS approach in visual conditions, ILS signal paths are not protected by air traffic control, and may be subject to interference. The aircraft’s flight path needs to be constantly monitored to ensure that guidance presented to the flight crew is valid. Constant monitoring will also ensure that early action can be taken to correct any deviation from the approach path.

Safety issues and action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Scoot

As a result of this occurrence, Scoot has advised the ATSB that they communicated the essential elements of this event and the associated autopilot flight director system implications and primary flight display and head-up display (HUD) indications to the pilot group. Pilots have been reminded to monitor the basic flight instruments and relevant check heights during the approach, alongside the aircraft calculated parameters. Stabilised approach criteria and associated callouts and actions have also been emphasised, and the importance of energy management and use of the HUD to monitor appropriate descent path information have been highlighted.

This communication assisted the captain in the event on 20 April 2016 in identifying the glideslope disruption shortly after it occurred.

Context

Personnel information

Both the captain and the first officer held all licences, medical certificates and training required to operate the aircraft at the time of the incident. There was also a second officer on the flight deck who was completing an observation flight as part of his 787 training.

Both the captain and first officer had previously operated the Boeing 777 aircraft, and completed the conversion training to the Boeing 787 aircraft within six months of this occurrence.

The captain had over 18,000 total flying hours, with over 15,000 hours as pilot in command (PIC) at the time of the occurrence, including 373 hours on the Boeing 787, 338 hours of which were as PIC.

The first officer had over 5,300 hours total flying hours, with 152 on the Boeing 787, including 62 as pilot in command under supervision.

Evidence collected about the pilot rosters and sleep patterns prior to the occurrence indicated that fatigue was not likely to have been a contributing factor in this incident.

Instrument landing system signal interference

In certain conditions, the integrity of an instrument landing system (ILS) is not protected, and signal disturbances may be experienced, even while the flight crew are conducting an instrument approach. Pilots may experience ILS beam bends and other interference in circumstances where the critical or sensitive areas of the ILS are not protected.

Disturbances to ILS localiser and glideslope courses may be caused by fixed structures, such as buildings (static distortion), or moving vehicles or aircraft (dynamic distortion). The total ILS course distortion is determined by the summation of static and dynamic distortion, and this is used to define critical areas near each localiser and glideslope antenna. [7] The critical area is surrounded by a sensitive area. These areas will differ for each approach. Figure 2 shows an example of the critical and sensitive areas around an ILS antenna.

Figure 2: Example of glide path critical and sensitive area dimensions

Figure 2: Example of glide path critical and sensitive area dimensions.
Source: International Civil Aviation Organisation Annex 10 (2018)

Source: International Civil Aviation Organisation Annex 10 (2018)

Different levels of protection of the critical or sensitive areas of the ILS are provided by ATC depending on the:

  • type of approach being conducted
  • position of the aircraft on the approach
  • weather conditions at the time.

For low-visibility approaches, when the cloud ceiling is at or below 600 ft, or the visibility is less than 2,000 m, no aircraft or vehicle is permitted to enter the critical areas when an arriving aircraft is within the outer marker, or 4 NM (7.4 km) from the threshold if there is no outer marker. The sensitive area will only be protected if the cloud ceiling or visibility is below that required to conduct a Category 1 ILS approach.

Flight crew are requested to inform ATC if they are conducting an autoland or coupled approach. This does not, however, ensure the critical area will be protected. When the cloud ceiling is above 600 ft, or the visibility is greater than 2,000 m, neither the ILS critical or sensitive areas are protected. When an area is protected, all aircraft will be held at a holding point which is outside of the protected area.

While the weather conditions were suitable for the flight crew to conduct a visual approach, it was not standard practice to assign visual approaches to foreign carriers, unless specifically requested by the pilot, and only after the pilot reported having the runway in sight. In this case, the flight crew had the runway in sight, but had not reported this to the controller while they were continuing with the instrument approach, nor were they required to.

Around the time of the glideslope disruption experienced by OJC, a Boeing 737 taxied from Terminal 1 and took off on Runway 21 (Figure 3). The ATSB assessed that the movement of that aircraft likely caused the signal disruption.

Figure 3: Perth Airport runway 21 showing location of glide path antenna, holding points and path of taxiing aircraft prior to take-off.

Figure 3: Perth Airport runway 21 showing location of glide path antenna, holding points and path of taxiing aircraft prior to take-off.
Source: Google, annotated by the ATSB.

Image shows the holding points for runway 21 at Perth. Between the holding points is the critical area which may be disrupted by an aircraft or vehicle movement. The red arrow shows where the 737 taxied onto the runway, likely causing a disturbance to the glideslope.

Source: Google, annotated by the ATSB.

Approach speeds

As OJC descended, ATC requested the aircraft maintain a higher than usual speed (280 kt) to maintain separation with other aircraft. The Scoot operations manual advised flight crew that their speed should be reduced to below 250 kt by 5,000 ft, subject to ATC requirements.

An Airservices Australia safety bulletin current at the time of the occurrence (2015), stated

Standard Terminal Area Arrival Speeds (STAAS) were introduced to improve safety and efficiency by bringing more predictability to arrival sequences at Brisbane, Sydney, Melbourne and Perth airports.

The STAAS speeds for an aircraft arriving were:

  • 250 kt at or below 10,000 ft
  • 230 kt between 20 NM and either 10 NM or the initial approach fix, unless otherwise specified on the approach chart
  • Between 185–160 kt between either 10 NM or the initial approach fix and 5 NM
  • Between 150–160 kt within 5 NM of the runway threshold.

On the Runway 21 ILS approach chart (Figure 1), the published maximum speed was 185 kt at the initial approach fix (HAIGH) and 160 kt from 5 NM. Guidance to pilots in the Airservices Australia Aeronautical Information Publication identified that:

Aircraft are expected to continue at previously specified speeds, commence speed reduction prior to the next promulgated speed and be at the speed by the specified point.

ATC may vary the published speeds where required for traffic management.

Air traffic control provided the following instructions to the flight crew:

  • At 1740:16, passing 20 NM, the crew were instructed to descend to 4,000 ft and reduce speed from 280 kt to desired speed
  • At 1741:34, passing 14.75 NM, the crew were instructed to descend to 2,500 ft and were cleared for the ILS approach
  • At 1742:22, around 11 NM, the crew were instructed to commence speed reduction for the approach
  • At 1742:55, around 9 NM, the aircraft was instructed to reduce speed to 170 kt
  • At 1743:32, around 7 NM, the crew were instructed to reduce to minimum speed, as the traffic ahead had slowed.

The speed change instructions were issued as the aircraft was descending and setting up to capture the localiser and glideslope for the approach, and during the early stage of the approach. As per the controller instructions, the crew were requested to reduce over 110 kt of speed in under four minutes. The flight crew reduced the speed from 280 kt to just below 200 kt in this time, having flown approximately 18 NM.

Guidance from the Flight Safety Foundation (2009) suggested deceleration on a 3° glideslope is difficult for an aircraft in a clean configuration (gear and flaps up), and can be around 10-20 kt per nautical mile with approach flaps and landing gear down. Additional deceleration can be achieved with deployment of speed brakes.

Head-up display

The head-up display (HUD) is one of the major differences between the Boeing 777 and 787 aircraft. Pilots completing a conversion course between the aircraft must complete training on HUD use, and are required to maintain currency in its use. Both pilots had completed this training.

Gibb, Grey and Scharff (2010) explain:

A head-up display projects aircraft status information to pilots to minimise their head-down time and allow more time to view the external scene outside the aircraft.

They note that the HUD is:

designed to remedy the problems associated with pilots shifting lens accommodation as they changed their gaze from close cockpit displays to far outside environmental objects.

While generally beneficial for flight crew in maintaining situational awareness, one issue which can arise with HUD use is that pilots cannot focus on both the HUD information and the outside environment simultaneously, and attention may become focused on one to the expense of the other (Crawford and Neal 2006, Nichol 2015). Wickens et al (2013) identified research showing that pilots using a HUD may be slower at identifying and responding to an unexpected event than when shifting focus between a scan of the primary flight display and the outside environment.

Additionally, as HUD displays are monochromatic, the way standard alerts displayed on the primary flight appear in colours such as green, amber and red are changed for display on the HUD (FAA, 2010). Nichol (2015) stated:

This results in the removal of a layer of information normally provided by colour coding. While the use of identical symbology and similar layout mitigates this somewhat, lack of colour is nevertheless something that pilots will take some time to adjust to.

Communication

At the time of the localiser and glideslope capture, the first officer was the pilot flying and the captain was the pilot monitoring.

In the sequence of events provided by the operator, the captain noted the aircraft was getting low, and instructed the first officer to stop the descent. The first officer reportedly did not take action at this time, as he was assessing the cautions displayed on the PFD and EICAS.

The Captain then took over flying duties from the first officer and arrested the descent. At this time, the first officer called for a go-around either two or three times. After the aural glideslope alert was sounded, the captain increased engine power and commenced the go-around. Flight data indicates that this occurred just prior to 1745.

The flight crew identified later that some standard procedural calls on the approach had been omitted during the first approach.

The approach controller coordinated handover of OJC with the tower controller between 1743 and 1744, advising that he had instructed the flight crew to reduce to minimum speed, and that there was minimum spacing between OJC and the previous aircraft. The flight crew were then instructed to change to the tower frequency. Thirty seconds later, the tower controller called the approach controller to say that the aircraft looked low. The approach controller advised that communication with the aircraft had already been transferred to the tower controller.

At 1745, prior to the go-around call from the crew, the tower controller instructed the flight crew of OJC to check altitude. At this point the crew had commenced the go-around.

Related occurrences

Subsequent Scoot occurrence

On 20 April 2016, another Scoot Boeing 787-9, registered 9V-OJD, also experienced a glideslope anomaly on the runway 21 ILS approach to Perth Airport.

In this occurrence, the flight crew observed a fluctuation of the glideslope indications, which was followed by an unusual pitch-down of the aircraft and an abnormally high rate of descent of about 1,400 fpm. The flight crew recognised the abnormal flight director commands as being the result of a glideslope disturbance, due to safety information released by the operator to their crew following the 4 December 2015 event. The autopilot was disconnected and the aircraft hand-flown to regain and maintain the appropriate flight path. The glideslope signal returned to normal function a short time later and the remainder of the approach and landing were uneventful. Following the landing, air traffic control informed the flight crew that an aircraft had departed from Runway 21 while the Boeing 787 was conducting the approach.

Both the ATSB and Boeing analysed the aircraft flight data and determined the event to be similar to the occurrence on 4 December 2015.

Other similar occurrences

A search of the ATSB database showed a number of similar occurrences had been reported to the ATSB in the five years from the start of 2015 to the end of 2019. These occurred across Australia, including on Runway 21 at Perth Airport. In most of these events, it was identified that an aircraft was taxiing, or taking off during the time of the glideslope or localiser interruption.

ATSB Investigation AO-2017-023

On 12 February 2017, a Boeing 747-47UF (freighter) aircraft was operating from Honolulu, United States to Sydney, Australia. The captain was the pilot monitoring (PM), and the first officer was the pilot flying (PF) . Shortly after the turn onto the final approach, the PF called ‘glideslope captured’ and the aircraft started to descend. However, the PM’s primary flight display was still showing the aircraft below the glideslope.

The PM crosschecked the PF’s display and noticed the glideslope was captured, then checked their own display and noticed there was a failure flag displayed for the glideslope. The PM again crosschecked the PF’s display, noticed there was a failure flag for the PF’s glideslope, and instructed the PF to disconnect the autopilot and stop the descent. During this process, a minimum safe altitude-warning alert appeared for the air traffic controller, who instructed the flight crew to conduct a go-around. At the time the 747 intercepted the localiser, another aircraft was on the taxiway within the ILS critical area.

__________

  1. The critical area is a volume of airspace encompassing lateral and vertical dimensions based around the localiser and glideslope antennas to protect the ILS signal transmissions to airborne aircraft in poor weather.

Safety analysis

The aircraft’s descent below the approach path glideslope occurred in daylight visual conditions following a disturbance to the glideslope signal. This analysis will examine the likely source of the glideslope disturbance, subsequent autopilot operation, and factors that contributed to the abnormal descent profile.

Glideslope disturbance

The glideslope signal disturbance occurred at about the same time that a Boeing 737 aircraft taxied and departed on runway 21. As the movement of that aircraft was in the vicinity of the ILS critical area, it was likely that this aircraft’s proximity to the antenna as it entered and lined up on the runway caused the interference to the glideslope signal.

As this event occurred in day visual flight rules conditions, and 9V-OJC was outside the outer marker of the approach when the disruption occurred there was no requirement for air traffic control to protect the ILS critical area. While weather conditions did not require the conduct of an instrument approach, it was normal for all international aircraft arriving at Perth to be sequenced via the prevailing runway instrument approach.

Approach flight path

The glideslope signal disturbance caused the autopilot flight director system (AFDS) to capture the glideslope prematurely. When an anomaly between the aircraft’s expected and actual flight paths was detected, the system by design entered into a degraded mode of operation.

The speed of the aircraft was high (206 kt) at the time the aircraft entered the degraded mode. As the descent rate required to maintain the designed glideslope is directly proportional to the speed of the aircraft, the calculated descent rate at that point in time was also relatively high. In the degraded mode, the AFDS maintained the aircraft in an attitude-stabilising mode, and in this case, with a higher-than-required descent rate. As the speed of the aircraft reduced, the difference between the required and actual descent rate increased.

A review of the recorded data indicated that glideslope mode failure indications appeared on both the primary flight displays and the head-up displays, however the flight crew did not recall seeing this initially. In addition, an ‘AUTOPILOT’ caution message should have been displayed on the engine-indicating and crew‑alerting system, but again the crew did not see this at the time. As they did not notice any warnings, the crew continued to descend as per the displayed flight director information. The crew reported they only observed the indications after hearing the aural ‘GLIDESLOPE’ caution.

Recorded flight data indicated that the crew manually disconnected the autopilot, and deselected and reselected the flight directors after the autopilot entered the degraded mode, when the aircraft was at 2,150 ft. The flight crew did not recall these actions, likely due to the workload at the time.

The actions of disconnecting the autopilot and re-selecting the flight directors re-set the AFDS, resulting in localiser (LOC) and vertical speed (V/S) modes becoming active with the glideslope (G/S) mode armed. However, as the aircraft’s flight path was diverging below the glideslope, the glideslope approach mode did not become active.

Based on analysis of the recorded flight data, it appears that, following autopilot disconnect and re-selection of the flight directors, the flight crew did not confirm the activation of the glideslope approach mode. As the aircraft was diverging below the glideslope in V/S mode, the glideslope mode remained in the armed (white) mode and not the active (green) mode. Consequently, rather than providing guidance to maintain the glideslope, the flight directors were providing guidance to maintain the descent rate approximate to that which existed when the modes were reselected.

This led to a descent rate about 1,000 feet per minute higher than was required for the approach, and in excess of the permitted rate of descent to comply with the operator’s stabilised approach procedures. Based on the flight path flown, it appears likely the flight crew misinterpreted the flight director commands as guidance to maintain the glideslope.

Workload

Periods of high workload are a normal function of the various stages of a flight, particularly during take-off, approach and landing. Workload during these periods is managed by following standard operating procedures and effective communication and teamwork, both between the pilots and with air traffic control.

While pilots are trained to operate under a range of conditions, familiarity and recency with an aircraft type can affect a pilot’s ability to manage these high-workload situations. The pilot flying had experience on the Boeing 777, but had only been operating on the Boeing 787 for a few months, and was likely still developing expertise specific to this aircraft type.

The Boeing 787 was also the first aircraft where the pilot flying had experienced using a head-up display. While head-up displays have been identified to be preferred by pilots over traditional head-down displays, they are known to have a potential inattentional blindness effect, meaning that pilots may inadvertently focus on one piece of information to the detriment of others (Gibb, Grey and Scarff, 2010).

The high-speed descent clearance given to the crew of OJC, while not unusual, was continued below the operator’s normal limit of 5,000ft. The air traffic controller directed the crew to use ‘desired speed’, an instruction that permitted the crew to reduce speed, but the flight crew did not slow the aircraft. The crew only began slowing the aircraft when cleared for the approach. This put OJC closer to the proceeding aircraft and, to ensure separation was maintained, the controller directed the crew to reduce speed to 170 kt, then to minimum speed. This was a relatively large speed reduction, to be completed in a limited time, which resulted in a further increase in workload for the crew.

The high-speed descent and subsequent high-speed approach also meant that there was limited opportunity for the crew to identify any abnormal attitude changes associated with the glideslope disturbance. In interview afterwards, remarks by the pilot flying about being mindful of the need to slow down, the deviation from normal speeds, the time taken to process the meaning of indications displayed on the HUD and PFD, and the communication and control changes between the crew were likely indicative of a higher-than-normal workload.

About 25 seconds after capturing the glideslope, the autopilot was manually disconnected and the pilot monitoring (captain) made several rapid changes to the flight directors and approach modes. Those actions appear to have been performed in response to the unusual indications displayed following the glideslope disturbance. They also appear to have been actioned without the usual action and confirmation as required by normal standard operating procedures.

As a consequence of not confirming the status of the reselected modes, both flight crew members appear to have experienced a degree of autopilot and flight director mode confusion. The crew incorrectly assumed that the correct glideslope information was being displayed, and did not notice any indications to the contrary. The high workload may also explain the discrepancy between when the flight crew thought they disconnected the autopilot and when the recorded data indicated the disconnection occurred.

Reports from the flight crew that they missed making, and/or did not hear some of the required standard approach calls, including the altitude crossing check at the outer marker, indicate some task-shedding occurred due to the high workload.

Findings

From the evidence available, the following findings are made with respect to the flight below minimum altitude involving Boeing 787, registered 9V-OJC, on 4 December 2015.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • The aircraft prematurely captured the runway 21 glideslope as a signal anomaly occurred, most likely caused by another aircraft taxiing to take off on the same runway. This resulted in the autopilot flight director system reverting to a degraded mode of operation.
  • Following disruption to the glideslope, the crew descended the aircraft unaware that the information they were following was taking them below the ILS glideslope, leading to activation of the aircraft's ground proximity warning system.
  • The flight crew were likely experiencing higher than normal workload, due to a combination of the high speed approach and troubleshooting the unexpected glideslope indications. This reduced the effectiveness of cockpit communication and delayed correction of the aircraft’s low altitude.

The occurrence

On 4 December 2015, a Scoot Boeing 787-9 aircraft, registered in Singapore as 9V-OJC (OJC), was operating a scheduled passenger flight from Changi International Airport, Singapore, to Perth International Airport, Western Australia. The first officer was the pilot flying (PF), and the captain was the pilot monitoring (PM)[1]. Also on the flight deck was a second officer conducting his first observation flight as part of his training on the 787 aircraft.

During the descent into Perth, Air Traffic Control (ATC) cancelled the normal speed restriction of a maximum of 250 kt below 10,000 ft, and requested the flight crew maintain 280 kt. This higher‑than‑normal speed was required to allow sequencing with other arriving traffic.

At about 1736 Western Standard Time,[2] as the aircraft was approaching 9,000 ft, the crew contacted the Perth approach controller and were instructed to maintain 9,000 ft. About a minute later, they were cleared to descend to 5,000 ft. At this time, the flight crew had a conversation about the speed they were flying being higher than the operator’s guidelines, which recommended a speed no greater than 250kts below 5,000 ft. The captain subsequently instructed the first officer to maintain the higher speed, as per the ATC instructions.

At 1740, after being cleared to descend to 4,000 ft, the crew reported to the controller that they were still maintaining 280 kt. In response, the approach controller advised the crew to resume their desired speed. The standard arrival speed at this point was 230 kt.

At 1741, the flight crew were cleared for a further descent to 2,500 ft and were given clearance to conduct the Runway 21 Instrument Landing System[3] (ILS) approach (Figure 1). At 1742, the approach controller instructed the crew to reduce speed for the approach. After 30 seconds, the crew were instructed to reduce speed further to 170 kt. At this time, the aircraft was approaching waypoint HAIGH, the initial approach fix (IAF) of the ILS approach, at an altitude of 2,600 ft and with an airspeed of about 240 kt. The published arrival speed from HAIGH was between 160 kt and 185 kt.

At 1743:13, both the ILS localiser (LOC) and glideslope (G/S) functions appeared to have been captured normally, with flight crew noting green indications for both on the flight mode annunciation panel. At this point, the aircraft was clear of cloud and the flight crew had the runway in sight. The Perth Automated Terminal Information Service identified the visibility as greater than 10 km, and the cloud as ‘FEW’[4] at 3,000 ft.

At 1743:32, the aircraft was directed by ATC to slow to the minimum approach speed. At 1744, the aircraft approached the outer marker (OM) (Figure 1) while descending through an altitude of about 1,000 ft, with a descent rate of about 1,800 fpm and an airspeed of 184 kt. This altitude was about 500 ft below the required height for this point of the approach, with a descent rate about double that required to maintain the glideslope.

A review of recorded Continuous Parameter Logging flight data after the incident indicated that, at around the time of the glideslope capture, there was a three‑second disturbance to the glideslope signal. This disturbance should have appeared as a slight oscillation of the glideslope indications on both the primary flight displays (PFDs) and the head-up displays (HUDs). The flight crew later reported that they did not notice the disturbance. The data further showed that the glideslope was prematurely captured by the autopilot flight director system (AFDS). As a result of the temporary disturbance, the AFDS entered a degraded mode of operation several seconds after the disturbance. At the time this occurred, 1743:36, the aircraft was at a distance of about 7 DME[5] (about 13 km) from the Runway 21 threshold, and past the initial approach fix waypoint HAIGH, descending through 2,120 ft with a descent rate of about 1,300 feet per minute (fpm) and an airspeed of 206 kt.

Figure 1 - Perth runway 21 ILS approach chart used by Scoot flight crew

Figure 1 - Perth runway 21 ILS approach chart used by Scoot flight crew.
Source: Jeppesen annotated by ATSB

Red boxes show the expected height at the outer marker (1480 ft when 4.5 nm from runway threshold), required altitudes to maintain the three degree glideslope for the approach, and the expected decent rate in feet per minute to maintain the glideslope for a range of approach speeds.

Source: Jeppesen annotated by ATSB

In the degraded mode, the glideslope flight path was no longer tracked by the AFDS, and instead the AFDS entered an attitude-stabilising mode based on the inertial data existing at that time. The resulting descent rate guidance displayed to the flight crew on the flight director was higher than that required to maintain the published 3° approach path.

The flight crew did not recall seeing any of the indications in the flight deck about the degraded AFDS mode, which should have normally displayed as both an amber line displayed through the G/S active mode text on the PFD, and as a line through the G/S active mode text on the HUD. In addition, an ‘AUTOPILOT’ caution message should have been displayed on the engine indicating and crew alerting system (EICAS). The flight data indicated that the autopilot was manually disconnected at 1743:38, two seconds after the AFDS entered the degraded mode, and the flight directors were cycled off then on again at 1743:45 with the intention of resetting the AFDS. The LOC and V/S modes then became active.

At 1744:24, the flight crew received an aural ‘GLIDESLOPE’ alert from the aircraft’s enhanced ground proximity warning system, indicating an excessive deviation below the required glideslope approach path. The flight crew later recalled that it was after receiving the ‘GLIDESLOPE’ caution alert that they observed a line through the G/S text on their PFDs and failure mode indication on the HUDs. The first officer reported also observing an ‘AUTOPILOT’ caution message on the EICAS at about this time. These indications are consistent with the AFDS degraded mode. Flight data indicated that the crew were taking action to respond to the degraded mode just prior to the aural alert. Resetting the flight directors resulted in the LOC and Vertical Speed (V/S) modes becoming active. The G/S mode remained armed, but did not become active.

In response to the alert, the captain then instructed the first officer to ‘power up’ and stop further descent. The first officer did not respond at this point, as he was reportedly still managing the energy of the aircraft to slow the approach down, and assessing the caution messages received.

As the aircraft passed over the OM, it descended through 930 ft with an airspeed of 180 kt, and a descent rate of 1,700 fpm. The required height at this point was 1,480 ft, the target approach speed was 156 kt, and a descent rate of about 850 fpm. The procedural approach speed limit was 160 kt. At this time, the captain took control of the aircraft with the intention of arresting the descent rate, correcting the flight path, and continuing the approach. However, the first officer advised the captain that the approach was outside the company’s stable approach criteria and recommended they conduct a go-around. As this was occurring, the flight crew visually observed that the precision approach path indicator (PAPI)[6] lights were all red, indicating the aircraft was significantly lower than required for the approach, and commenced a go-around.

At about 1745, the Perth Tower controller asked the crew to confirm they had visual reference with the runway, and to check their altitude. At that stage the aircraft had climbed to an altitude of 650 ft. The crew responded to the controller, advising that they were conducting a go-around.

A minimum altitude of 590 ft (520 ft above the ground) was recorded at 1744:47, when the aircraft was at 3.5 DME (5 km) from the runway, at a position where the glideslope height was 1,160 ft. The time between the first aural ‘GLIDESLOPE’ caution and commencement of the climb in the go-around was 23 seconds.

The aircraft subsequently conducted another ILS approach to the same runway. There was no signal disturbance during that approach and the ILS was conducted in accordance with the prescribed procedure. The aircraft landed at about 1758.

__________

  1. Pilot flying (PF) and pilot monitoring (PM): procedurally assigned roles with specifically assigned duties at specific stages of a flight. The PF does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The PM carries out support duties and monitors the PF’s actions and the aircraft’s flight path.
  2. Western Standard Time (WST): Coordinated Universal Time (UTC) + 8 hours.
  3. The instrument landing system is a ground-based precision approach and landing aid. The main elements are (1) the localiser antenna, which provides centreline guidance; (2) the glideslope antenna, which provides a nominal 3° descent guidance; (3) the marker beacons (outer, middle and inner), which are used for altimetry checks and to indicate what stage of the approach has been reached; and (4) the approach lights (Distance Measuring Equipment (DME) and/or Global Navigation Satellite System (GNSS) may be used in lieu of marker beacons).
  4. When measuring cloud cover, the sky is broken up into eighths (oktas). ‘FEW’ cloud equates to 1 to 2 oktas of cloud.
  5. Distance measuring equipment (DME): DME display provides pilots with a distance measurement in nautical miles to the relevant DME station. In this case, the runway 21 touchdown point.
  6. Precision Approach Path Indicator (PAPI): a ground based system that uses a system of white and red lights used by pilots to identify the correct approach path to the runway when conducting a visual approach.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • the crew of 9V-OJC
  • Scoot
  • Airservices Australia
  • Boeing.

References

Airservices Australia (2015), Safety Bulletin – Standard Terminal Area Arrival Speeds. 23 January 2015.

Crawford, J and Neal, A (2006), A Review of the Perceptual and Cognitive Issues Associated with the Use of Head-Up Displays in Commercial Aviation. International Journal of Aviation Psychology, Volume 16, Number 1 pp 1-19.

Federal Aviation Administration (2010); Advisory Circular AC-25.1322-1 Flightcrew Alerting. US Department of Transportation, Federal Aviation Administration.

Flight Safety Foundation (2009), Approach and Landing Accident Reduction Toolkit Briefing note 4.2 – Energy Management. Flight Safety Foundation.

Gibb, R, Gray, R and Scharff, L (2010), Aviation Visual Perception. Ashgate, United Kingdom

International Civil Aviation Organisation (2018); Annex 10 – Aeronautical Telecommunications Volume 1 Radio Navigation Aids. Seventh Edition, July 2018. International Civil Aviation Organisation.

Nichol, RJ (2015), Airline Head-Up Display Systems: Human Factors Considerations. International Journal of Economics and Management Sciences, Volume 4, Issue 5.

Wickens, CD, Hollands, JG, Banbury, S and Parasuraman, R (2013); Engineering Psychology and Human Performance. Fourth Edition. Pearson Education.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the crew of 9V-OJC, the operator, Airservices Australia, Boeing, the Civil Aviation Safety Authority, the National Transportation Safety Board (United States) and the Transport Safety Investigation Bureau (Singapore)

Submissions were received from the operator, the Transport Safety Investigation Bureau (Singapore) and Boeing. The submissions were reviewed, and, where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2020

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-144
Occurrence date 04/12/2015
Location 13 km from Perth Airport
State Western Australia
Report release date 26/06/2020
Report status Final
Investigation level Defined
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Navigation - Other
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer The Boeing Company
Model 787-9
Registration 9V-OJC
Serial number 37114
Sector Jet
Operation type Air Transport High Capacity
Departure point Singapore
Destination Perth, Western Australia
Damage Nil

Collision with a pole involving an Air Tractor AT-502B, VH-PTF, near Dalby, Queensland, on 4 December 2015

Final report

What happened

On 4 December 2015, the pilot of an Air Tractor AT-502B aircraft, registered VH-PTF, was conducting aerial spraying operations from Dalby Airport, Queensland.

The pilot had commenced duty for the day at about 0500 Eastern Standard Time (EST). At about 1200, the pilot took a short meal break. During the break, the pilot was provided with a map of the next area to be sprayed, which included a number of gas wells. Each gas well was on a gravel pad, with an antenna that posed a potential hazard to low-flying aircraft. The pilot was advised that there were no other known hazards, such as powerlines, in the area.

The aircraft was fuelled and 1,600 L of liquid chemical loaded into the aircraft hopper. The aircraft departed at about 1210, and tracked towards the field to be sprayed, which was about 13 NM to the south-west. The pilot then overflew the area to inspect the field, first at about 100 ft above ground level (AGL), then at about 50 ft AGL. The pilot noted the wells on the gravel pads, and verified that there were no powerlines in the treatment area. The pilot also saw a solar panel a short distance from a well, located in the crop and not on a separate pad (Figure 1). The pilot did not see an antenna at the site of the solar panel at that time.

Figure 1: Field showing well on gravel pad and solar panel

rid22-picture-5.png

Source: Google earth – annotated by ATSB

The pilot elected to use the solar panel as a reference point and established a plan for the spraying. The aircraft then climbed and tracked a short distance away, and the pilot set up the GPS in readiness to commence the spray run.

The pilot commenced the first spray run, tracking towards the solar panel. As the aircraft came within about 20-30 m of the panel, the pilot noticed a pole behind the panel, protruding about 3 m above the crop, with an antenna on it. The pilot immediately conducted a climb to avoid the pole and antenna, but the aircraft struck the pole (Figure 2).

The pilot’s primary concern was to check that the aircraft was still controllable. The pilot conducted a climb to a safe height and checked the flight controls and all controls responded normally. The pilot could not see any damage to the aircraft or any fuel venting from the tanks. The pilot then checked the engine instruments and all indications were normal. There was a slight vibration, which the pilot assessed as possible damage to a panel on the airframe, or a blade of the spray pump used to disperse the load. The pilot therefore switched the pump off, but the vibration continued.[1]

Figure 2: Bore with solar panels and pole (after collision)

pole.jpg

Source: Aircraft operator

At that stage, the pilot decided that it was not necessary to dump the chemical load. The pilot decided to land as soon as practicable and assess the damage to the aircraft. They elected to return to Dalby, where there were emergency services available. The pilot broadcast on the UHF radio advising the company that the aircraft had struck a pole, was still flying normally, and would be returning to the airport. However, as the aircraft was relatively heavy, the pilot elected to spray about 500-600 L of the chemical, at a higher flow rate than normal, to reduce the load prior to returning to land.

During the return flight, the aircraft still had a minor vibration. The pilot overflew the runway at Dalby to check the wind direction and speed before joining the circuit. The pilot conducted the approach about 5 kt faster than normal, due to the weight of the aircraft and the unknown effect of the damage caused by the collision with the pole. The aircraft landed safely at about 1240, and the pilot was uninjured. The aircraft sustained damage to the left wing and the propeller (Figure 3).

Pilot comments

The pilot provided the following comments:

  • Most of the gas wells had an antenna on a pole, similar to the one the aircraft struck, however they were of a considerable height and on a gravel pad. The pilot had assumed that the gas company equipment was located on gravel pads.
  • The galvanisation on the pole had no shine and it blended into the background of the crop. A line of trees beyond the crop also made the pole difficult to see. It would have stood out more clearly against a blue background of sky.
  • The solar panels were located on a ground water quality bore, with the (pole and) antenna for satellite transmission.
  • Pilots from the same company had previously conducted spraying operations in that field, but the pole had not been in place then.

Figure 3: Damage to propeller (left) and wing damage (right)

rid24-picture-5.png

Source: Aircraft operator

Safety message

This incident highlights the importance of communication in identifying risks for low-level flying operations. Additionally, unknown hazards can be very difficult to see. The use of clearly visible markings may help pilots identify hazards during a field inspection. Pilots can then make a plan to avoid them during spraying operations.

The ATSB report Wirestrikes involving known wires: A manageable aerial agriculture hazard, cautioned pilots to conduct an aerial reconnaissance to confirm the location of wires and other hazards. Having a plan and a procedure to minimise the risk of collision with hazards is a valuable mitigation strategy. Further risk management strategies for agricultural operations are detailed in the Aerial Application Pilots Manual.

Aviation Short Investigations Bulletin - Issue 47

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. The aircraft was fitted with a wind-driven spray pump. Occasionally a blade can separate and cause vibration. If the pilot switches the pump off and the vibration ceases, they have isolated the source of vibration,

Occurrence summary

Investigation number AO-2015-142
Occurrence date 04/12/2015
Location near Dalby
State Queensland
Report release date 13/04/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Air Tractor Inc
Model AT-502B
Registration VH-PTF
Serial number 502B-0404
Sector Turboprop
Operation type Aerial Work
Departure point Dalby, Qld
Destination Dalby, Qld
Damage Substantial

Contact with wharf by Madang Coast, Townsville, Queensland, on 16 November 2015

Final report

Safety summary

What happened

At about 2106 Eastern Standard Time, on 16 November 2015, a pilot boarded Madang Coast for its transit into Townsville, Queensland. The master and pilot completed the master-pilot information exchange, which included the berthing plan at Berth 10. As the ship approached the berth, the first line ashore, the forward spring, was looped over a bollard on Berth 10. The forward mooring party made two turns around the first post of the bitts and held onto the spring line. However, shortly after, as weight came onto the line, the line slipped on the post and fell slack.

Madang Coast started moving off the berth towards a ship on the opposite berth. Despite repeated efforts to hold on to the line, it continued to fall slack. Subsequently, Madang Coast‘s bow made contact with the shore end of Berth 10 and its port quarter with the ship on the opposite berth. Both ships sustained minor damage and there were no injuries.

What the ATSB has found

As Madang Coast came alongside the wharf, the forward spring line slipped and could not be used to manoeuvre against. After the spring line slipped, the distance from the stern to the wharf was too far for the aft mooring party to throw any heaving lines ashore. Hence, the stern’s movement away from the wharf continued.

The shipping agent requested a tug reduction for the ship’s berthing. The acting regional harbour master, pilot manager and the ship’s master were all unaware that the agent’s application was made without the master’s knowledge.

The pilotage service did not have documented guidance procedures for berthing or any associated contingencies. The risk management processes were not sufficiently mature nor resilient enough to effectively identify and mitigate risks in pilotage services.

What's been done as a result

The Port of Townsville Limited (POTL) Pilotage Services has completed a review of, and subsequently updated and fully implemented a safety management system (SMS). The SMS included detailed berthing, operations and emergency procedures amongst others. The qualifications and training requirements for licensing pilots for the number of observation, supervised and check trips have significantly increased.

The tug reduction requesting procedure has been updated and now requires a declaration by the ship’s master that an assessment of the intended manoeuvre(s) to and/or from berths have been undertaken.

Safety message

Risk management issues associated with the safe pilotage of ships are commonly known by all parties involved. However, the reality as opposed to the hypothesised scenarios are not always understood nor acted upon. Numerous incidents and their subsequent findings already provide the answers to many of retrospective questions that are asked. Where internal risk management processes may fail to address those questions, forward thinking can. Effective risk management systems and processes can lead to the identification, collation and assessment of found hazards, and, thus, provide the most appropriate mitigation measures.

Ship details

Ship details

Name:

Madang Coast

IMO number:

9135767

Call sign:

P2V5305

Flag:

Papua New Guinea

Classification society:

DNV GL

Ship type:

General cargo ship

Builder:

Severnav S.A., Societatea Comerciala, Romania

Year built:

1997

Owner(s):

Consort Express Lines

Manager:

Consort Express Lines

Gross tonnage:

4,004 t

Deadweight (summer):

5,125 t

Summer draught:

6.55 m

Length overall:

104.75 m

Moulded breadth:

16.40 m

Moulded depth:

8.30 m

Main engine(s):

8L32/40 MAN B&W

Total power:

3,520 kW

Speed:

15.00 knots

Damage:

Minor

 

Context

Madang Coast

At the time of the incident, the 105 m Madang Coast was registered in Papua New Guinea, classed with DNV GL, and managed by Consort Express Lines, Papua New Guinea. The ship had a crew of 15, consisting of a Sri Lankan master and 14 Papua New Guinean nationals.

The master had 18 years of seagoing experience and held a master’s certificate of competency. He had sailed as master for 1 year on a sister ship to Madang Coast, with frequent port calls into Townsville. He had joined Madang Coast about 3 months before the incident.

The second mate had over 5 years of seagoing experience and held a watchkeeping deck officer’s certificate of competency. He had joined Madang Coast about 10 months before the incident.

The bosun had 30 years of seagoing experience and had sailed as bosun for 15 years. He had joined Madang Coast about 4 months before to the incident.

Propulsion

Madang Coast was fitted with a left-handed turning[8] controllable pitch propeller (CPP) which rotated at a constant speed, in the same direction. Ahead and astern movements were controlled by adjusting the degree of pitch applied to the propeller blades.

During an astern movement, the propeller creates a transverse force on the ship’s hull, commonly called cut. Consequently, the stern would move to port causing the bow to sheer to starboard. As the astern pitch increased, this effect would also increase.

Further, when the pitch is set at zero, the equivalent of ‘stop’ for a fixed pitch propeller, Madang Coast would creep slowly ahead. These characteristics had been noted on the pilot card:

Bow swings to starboard when astern propulsion. Vessel creeps ahead when pitch is set at ‘0’.

Madang Coast was also fitted with a 280 kW bow thruster and a Becker rudder.[9]

Mooring equipment

Madang Coast’s forward mooring deck equipment and fittings consisted of two windlass drum ends,[10] two pedestal rollers[11] and four twin bollard bitts (Figure 5). The mooring plan usually involved using five mooring lines forward (three head lines and two spring lines) and five mooring lines aft (three stern lines and two spring lines). The head lines and stern lines were heaved in by taking turns around the rotating drum end and then manually pulling on the line to create friction for it to grip the drum.

A spring line was usually the first line ashore and held onto (prevented from paying out) by making at least two turns around one post of twin bollard bitts. The remaining spring lines were tensioned using the same method as for the head/stern lines.

When in position alongside, each mooring line was made fast by making six complete turns around one post on a set of bitts. However, due to the limited number of bitts, two lines were made fast on the same set of bitts.

Figure 5: Mooring deck equipment

Figure 5: Mooring deck equipment. Source: ATSB

Source: ATSB

Port procedures

Maritime Safety Queensland (MSQ) is responsible for improving maritime safety for shipping and recreational craft through regulation in Queensland, amongst other functions. The Transport Operations (Marine Safety) Regulations 1994 describe the pilotage areas. A Regional Harbour Master (RHM) controls the pilotage areas within their region and has the authority to direct the master of a ship to navigate or operate a ship in a prescribed way.

Each pilotage area has a Port Procedures and Information for Shipping Manual. The manual details mandatory regulations, procedures, and services to be observed. The manual also contained guidelines and information to assist masters, owners and agents of ships arriving and departing the area.

In Queensland, an online booking and port movement information website, Queensland Shipping Information Planning System (QSHIPS), is used to book any shipping movements. Shipping agents are required to enter ship arrival details, such as berthing information and tug requirements, directly into the booking system, at least 48 hours in advance.

MSQ’s vessel traffic services (VTS) manage the system and are responsible for updating QSHIPS as changes occur. They are responsible for informing relevant personnel such as pilots, tug and lines boat crews and port marine services of any changes.

Port of Townsville operations

The Port of Townsville is the third largest port in Queensland and averaged 1,440 vessel movements and 12 million tonnes of cargo per annum. That is more than 75 per cent of the state of Queensland’s metals cargoes and more than 12 per cent of the state’s total international cargo trade.

Townsville Inner Harbour

Berth 10 (Figure 6) was located on the western side of the harbour and formed a finger pier between Ross Creek and Berth 9. Due to its proximity to Ross Creek, ships approaching the berth pocket may be affected by tidal streams flooding and ebbing into and out of the creek. Berth 10 was designed as a roll-on/roll-off, and general cargo berth for ships up to 300 m.

Figure 6: Townsville Inner Harbour

Figure 6: Townsville Inner Harbour. Source: Maritime Safety Queensland

Source: Maritime Safety Queensland

Tugs

Two tugs were available for towage in Townsville. Shipping agents booked tugs on behalf of ships’ masters via the QSHIPS programme for which they were charged a fee for service. Outside of normal working hours, the tugs were not manned, unless a booking had been made.

MSQ’s Port Procedures[12] detailed tug usage guidelines[13] for the Port of Townsville. The number of tugs required was determined by the berth, the ship’s length and if it was to be swung prior to berthing. For Berth 10, a ship of Madang Coast’s length and berthing starboard side alongside required one tug.

However, ships with operable and efficient thrusters and/or enhanced ship-handling capabilities could have the tug requirements reduced. During a ship’s first inbound transit, a pilot would assess and make recommendations for subsequent transits to the RHM for consideration. As Madang Coast was fitted with a bow thruster and Becker rudder it met the requirements of enhanced manoeuvrability and hence had an allowable tug reduction from one to no tugs.

Tug reduction request

The Port of Townsville Limited (POTL) Pilotage Services’ Standard Operating Procedures (SOPs) provided the following guidance for ordering of tugs:

It is not a Pilot’s responsibility to order tugs.

VTS advise agents of tug requirements in accordance with the Port Procedures Manual and the order is made directly by the agents to the tug company for the port. Variations in addition to the prescribed for a particular job are at the pilot’s discretion.

Any reduction to the prescribed no [number] of tugs for a movement has to be approved by the RHM.

Therefore, when a pilot determined the use of a tug was required, they were able to use their discretion to request it. This decision could be taken either after reviewing the daily shipping schedule, on the way to the ship or upon boarding it. However, there would be a delay to the berthing, as if the tugs were not ordered for a specific shipping movement then they were not manned nor on standby. The delay could be up to 2 hours before the tugs were available. These delays, along with the associated commercial pressures of turnaround times and tug costs are among the many factors that can influence the decision-making process.

On 13 November 2015, three days prior to the berthing, the shipping agent submitted a request to the RHM for a tug reduction for Madang Coast’s 16 November 2015 berthing. The shipping agent did not consult the ship’s master about this request, nor was he required to at that time.

The acting RHM (ARHM) consulted the port guidelines and Madang Coast met the requirements for a tug reduction:

An operable and efficient Bow / Stern thruster: means a fully operational, sufficiently immersed bow thruster, adequately powered relative to ship’s size and prevailing weather conditions.

He then discussed the application with the pilot manager and it was agreed that the ship could berth without the use of a tug. The ARHM granted the reduction and the shipping agent was notified. The shipping agent updated QSHIPS and the shipping schedules, which were sent out twice a day, noted that Madang Coast was to berth without a tug.

Lines boats

A lines boat is a small vessel that is used to tow mooring lines from the ship to the wharf when the distance is too great for the crew to use a hand-thrown messenger line or the mooring line is to large or heavy to be easily handled manually.

MSQ’s Port Procedures stated, amongst others, that a lines boat was required for the following cases:

all ships with an LOA [length overall] >150m at berth 10

all vessels berthing without tugs (with or without thrusters) – use of a line[s] boat is at the discretion[14] of the pilot berthing the vessel.

Pilotage

On 2 November 2013, the responsibility for the management and delivery of pilotage services in Queensland ports was transferred from MSQ to the various port authorities. Pilotage Services, now a division of the POTL, managed and provided the pilotage services in Townsville. Ownership of the application and approval process for pilot licences and exemptions remained with MSQ. Pilotage was compulsory for all ships over 50 m, unless the RHM had issued an exemption.

Pilot training content and approach

At the time of the incident, a pilot’s training consisted of theoretical and practical observation, study and assessment. MSQ issued training requirements[15] that specified what training had to be completed for each level[16] within each area endorsement (Appendix B). POTL Pilotage Services provided the training and practical assessments. The RHM assessed the theoretical knowledge and issued the pilotage certificate. The pilotage certificate consisted of a licence valid for 5 years, and an area specific endorsement, valid for 2 years.

Each level of pilotage, from trainee (level 4) to unrestricted (level 1), required the pilot to complete a number of observation trips of qualified pilots conducting trips at that level. They were then required to conduct trips under supervision, and then check (assessment) trips.

Additionally, every pilot, at intervals of less than 2 years, had to undertake a check (assessment) of two pilotage trips (an arrival and departure) with a licenced check pilot. Further, after an incident, or if a pilot expressed a concern about berthing, they were sent on observation trips with other pilots.

The pilot

The pilot assigned to Madang Coast held a current foreign going master’s certificate of competency, an unrestricted pilot’s licence, and a check-pilot[17] licence for Townsville. He had 12 years’ experience at sea and a further 10 years of pilotage in various Australian and New Zealand ports prior to joining MSQ in 2011.[18] He had piloted Madang Coast and a sister ship into and out of Townsville on numerous occasions.

Pilotage Services procedures and guidance

The Ports Australia Australian Port Marine Safety Management Guidelines (2015) provided a framework to encourage systemised evaluation of risk, and suggest ways to address and minimise the risk. The Guidelines were not considered a regulatory requirement, rather, they represented a ‘good practice’ framework for a Port Marine Safety Management System (SMS). These guidelines recommended the following:

Ports should develop standard berthing plans containing minimum agreed requirements following consultation with affected parties

It was also recognised in the guidance that passage plans were subject to change and it was important not to constrain a master or pilot’s need to react to unforeseen circumstances.

Pilotage Services Safety Management System

In 2011, the Townsville pilotage services, then part of MSQ, developed a Pilotage SMS (PSMS) for the Townsville Pilotage Services. At the time of the occurrence, the SMS document (and therefore the berthing guidelines within) had not been approved, as some of the pilots and the pilot manager disagreed with aspects of it. Therefore, there was not an approved working document, and it remained as a draft format.

In August 2013, an audit of the Townsville Pilotage Service’s 2011 draft PSMS was completed 2 months before MSQ divested itself of pilotage services. The RHM noted that documented procedures for deviating from the passage plan, contingency plans and emergency situations for the pilotage area were in the process of being developed. Further, with reference to the 2011 draft PSMS, they noted the document presented had not been formally adopted by Townsville Pilotage Services as it was still under review prior to adoption.

In 2014, POTL Pilotage Services’ SOPs were implemented, which included elements of the 2011 draft PSMS. The SOPs detailed reference material, duties and responsibilities and passage plans amongst others. In a November 2014 audit, the RHM again recommended the POTL Pilotage Service to develop documented procedures for contingency plans and emergency situations, this time through the pilot meeting minutes. In addition, with regard to emergency situations, the audit also recommended that pilots discuss various scenarios during pilot meetings. This was to develop awareness and identify options to consider in the event of an emergency once past the point of no return.

In November 2015, an audit was completed 11 days prior to the incident. The RHM noted the POTL Pilotage Service now operated under the POTL’s existing SMS.[19] It was also noted that procedures were in place for deviating from the passage plan and that the procedures for emergency situations were discussed and documented at pilot meetings in the minutes. However, the RHM recommended that the POTL document standard operating procedures for emergency situations during pilotage.

Berthing manoeuvre guidance for Berth 10

At the time of the incident, there was no published guidance in the SOPs for berthing ships in Townsville. The only guidance for berthing a ship was detailed in the 2011 draft PSMS. The draft PSMS included guidance for when swinging a ship to port or starboard when berthing port side alongside. Additionally, when no swing was required, the ship was to be berthed starboard side alongside.

General guidance from the draft PSMS for berthing at Berth 10 included:

Smaller vessels, berthing without tugs, often berth starboard side to (head in) to the berth.

Due to the nature of the cargo worked and the size of the vessels that call at this berth tugs are often not required.

In general pilots require a shore end back spring line to be run first as this provides the potential to prevent the vessel from moving too far into the shore end of the pocket.

Specific guidance for berthing when no swing was required included:

Pilots vary the angle of approach to the berth allowing for:

  1. prevailing conditions – wind direction and strength
  2. tidal streams in and out of the creek
  3. tug allocation and/or thruster/s and/or planned use of anchor/s
  4. vessel speed.

Pilots reduce speed gradually and maintain heading using helm, thrusters, tug/s and/or anchors.

Once inside the pocket the vessel is positioned parallel to the berth and manoeuvred alongside using tug/s, thruster/s, the line’s launch and/or mooring lines.

Berthing method

Previous berthing methods

Madang Coast had berthed starboard side alongside at Berth 10 on six previous occasions in as many months without incident, and over 20 times in total. Three methods had been used to berth the ship during the previous 6 months (Table 1). The methods included dredging an anchor,[20] using a tug, and using a forward back spring to manoeuvre against.

Table 1: Madang Coast’s berthing history at Berth 10

Tug
used

Number of tugs
and position

Anchor
dredged

Forward
spring line

Tidal
conditions

No

-

No

Yes

flooding

No

-

Yes (Stbd)

No

flooding

No

-

No

Yes

flooding

Yes

One - aft

No

No

ebbing

No

-

No

Yes

flooding

No

-

No

Yes

flooding

Source: POTL Pilotage Services, berthings between April and September 2015

It was not unusual practice for a tug not to be ordered when the wind was from the north, as the ship had berthed without incident on those occasions. However, on one arrival a tug was used as the tide was ebbing and the wind was from the south-east (acting on the ship’s beam, pushing the ship onto the berth).

The berthing method used by a pilot depended on a number of factors, such as wind direction and force, windage, draught, tidal conditions, use of a tug and/or lines boat and characteristics of the ship.

Pilot’s berthing plan

The pilot’s plan for berthing Madang Coast on 13 November 2015 involved approaching the berth at a shallow angle with minimal headway (Figure 7).

As the ship approached the berth, the forward mooring party were to run a forward back spring line and when instructed, hold onto the line.

As weight came onto the line, the forward movement of the ship would bring it slowly alongside. A short ahead movement of the ship’s propulsion and with the rudder hard-over to port would swing the ship’s stern in and the bow thruster could be used to maintain the bow’s position. Once alongside, the ship’s final position could be adjusted by using the head and stern mooring lines and/or main engine.

Figure 7: Planned berthing manoeuvre

Figure 7: Planned berthing manoeuvre. Source: ATSB

Source: ATSB

Safety management

A safety management system can be defined as a planned, documented and verifiable method of managing hazards and associated risks. Key operational safety risks can be identified by incorporating processes and practices for:

  • managing operational safety matters
  • incident reporting
  • holding regular meetings
  • collation and analysis of safety information.

The benefits of doing so include an increased ability to identify, assess and mitigate safety risks. Relevant references such as the National Marine Safety Committee’s National Marine Safety Guidance Manual refer to risk management in SMSs:[21]

The primary objective of a pilot organisation is to manage the risk to life, vessels, the environment within the port or pilotage area, during pilotage. A pilot organisations’ SMS should address all significant risks identified using a recognised methodology.

However, only the Townsville Pilotage Service’s 2011 draft PSMS included risk management guidance such as:

Every pilotage involves an assessment and the formulation of a plan in order to minimise and mitigate the risk inherent to the operation. For a majority of pilotage operations this risk is planned for and dealt with by adhering to Regulators legislation, terminal requirements and this PSMS.

Further, the 2011 draft PSMS also contained further guidance for ‘Operational Controls as Threat Barriers’.[22] The guidance detailed that the barriers listed in the draft PSMS were not all of the available options and pilots should use any as required.

Safety reporting

The pilots were required to report all marine incidents[23] and near misses to the pilotage manager as soon as practically possible. The Pilotage Information Management System (PIMS) was used to report marine incidents, other incidents not defined as a marine incident and other information.

PIMS was a voluntary reporting system for Australian ports. After a report was logged into PIMS, it was automatically distributed to all Townsville pilots and the pilot manager. The reports could also be sent to the RHM and the Australian Maritime Safety Authority (AMSA). The reported information could potentially benefit another pilot in the same port or other ports or alert the pilotage manager of action required regarding a vessel. Any PIMS reports raised were also added to the minutes of pilot meetings for discussion.

Pilotage meetings

Pilotage meetings were typically held every 2 to 3 months. The pilotage manager arranged the meetings and sent an agenda to all attendees. All pilots and the RHM were expected to attend and POTL managers and other guests were invited as required. Those who could not attend were noted as apologies. The meeting agenda generally covered administrative matters, port authority and berth updates, navigational issues, PIMS reports and, on occasion, contingency plan discussion points, amongst others. Meeting minutes were taken and promulgated to all attendees. In general, the minutes provided a brief overview of the agenda and any subsequent outcomes.

The pilot manager and RHM indicated that besides general issues, PIMS reports were discussed and anything of concern could be raised as an agenda item. They also outlined that the pilot meetings were used to discuss policies and to facilitate consultation with people outside of the pilot group.

Weather

At 1550 on 16 November 2108, the Bureau of Meteorology issued a Coastal Waters Forecast for the Townsville coast:

Winds: North-easterly 10 to 15 knots, reaching up to 20 knots offshore north of Cape Bowling Green in the evening. Winds decreasing to about 10 knots in the late evening.[24]

At 2200, the wind speed at the entry to the Sea Channel was 13.7 kt from 004° and at Townsville’s airport[25] was 10 kt from 010°.

Effect of wind

When a ship reduces speed and during berthing, the effect of the wind can create difficulties for a ship with an all aft accommodation (Figure 8). With the wind abeam or abaft the beam and the ship stopped in the water, the superstructure and funnel offer a cross-section to the wind. Further, the area of freeboard[26] from forward of the bridge to the bow also needs to be considered. The centre of effort of the wind (W) acts upon the combination of these two areas and it is further forward than expected.

When considering the underwater profile of the ship, the position of the pivot point (P)[27] is close to midships when stopped. The centre of effort of the wind and the pivot point are close together and the wind creates a minimal turning influence on the ship.

However, when the ship is making headway the pivot point moves forward but the centre of effort of the wind remains where it is. This creates a turning lever between P and W, and depending on the strength of the wind, the ship will develop a swing of the bow into the wind.

This effect increases at lower speeds as the pivot point moves further forward. Therefore, as the speed reduces the effect of the wind progressively increases.

Figure 8: Effect of wind with headway

Figure 8: Effect of wind with headway. Source: The Nautical Institute, modified by the ATSB

Source: The Nautical Institute, modified by the ATSB

Previous occurrences

In September 2015, several months prior to the incident, a PIMS report had been raised for a ship’s contact with Berth 4. The ship had two tugs allocated for berthing due to generator issues. Strong south-easterly winds had been experienced leading up to the pilotage, with the wind from the south-east at about 20 to 25 kt. After boarding the ship, the pilot confirmed the tug attendance with the duty tug master.

However, during transit of Platypus Channel, the master of one tug informed the pilot that the other tug had been cancelled the previous day. The pilot then queried this with the Vessel Traffic Services Officer, who confirmed it, as the ship’s generator had been repaired the previous day. Hence, the ship had reverted to its normal tug allocation of one tug for a ship of her length. The pilotage continued without issue, but upon berthing the ship made contact with the wharf. The pilot attributed this to having only one tug for berthing in those wind conditions. He stated that he would have requested two tugs for berthing, but as the ship already had been allocated one tug, he did not make this request.

__________

  1. When viewed from astern, looking forward, a left-handed turning propeller is seen to rotate anti-clockwise.
  2. A spade-type rudder with flap. The Becker-type rudder has a moving flap on the trailing edge. When the rudder moves, a mechanical linkage diverts the flap to a higher angle to maximise the sideways thrust.
  3. Drum ends are driven by a horizontal axle that is usually shared by a mooring winch or the anchor windlass.
  4. A pedestal roller is generally used to change the direction of lead of a mooring or other line on deck.
  5. Maritime Safety Queensland Port Procedures and Information for Shipping – Townsville.
  6. Port Procedure and Information for Shipping – Townsville – July 2015, Section 9.
  7. Pilots discretion was referred to in the draft PSMS as ‘variations in addition to the above guidelines are at the pilot’s discretion. Pilots are to exercise this discretion to ensure safety of the vessel i.e. during strong winds’.
  8. Record of qualifications and training for Queensland Port Pilots for the Pilotage area of Townsville.
  9. Area endorsement levels are based on ship lengths.
  10. A check pilot is licensed under regulation as a pilot and is authorised to assess an applicant's competence to be issued a new or renewed Licence or Pilotage Area Endorsement.
  11. At the time of employment, MSQ provided pilotage services in Queensland. His employment was transferred to the Port of Townsville Limited, when MSQ divested itself of its pilotage service division.
  12. Document POTL 1023 R(2) Port of Townsville Pilot Services Standard Operating Procedures. R(2) introduced on 13 May 2015. R(3) was added to the quality document system in March 2016.
  13. Term used to describe the towing of an anchor at a short stay.
  14. The revised guidelines were developed by the National Marine Safety Committee (NMSC) in conjunction with Ports Australia, the Australian Marine Pilots Association and Marine Safety Queensland, in 2008.
  15. Amongst others, the PSMS detailed the following as threat barriers: the generic passage plan, the ship’s passage plan, the master-pilot exchange, weather forecasts and warnings, pilot training and the PSMS. The latter two indirectly feed into enacting of contingency plans.
  16. An incident resulting in the loss of a person from a ship, the death of a person, a collision, a stranding, material damage or danger of serious damage to a ship amongst others.
  17. Cape Bowling Green is 65 km east by south of Townsville. The BoM defines evening as 1900 to 2000 and late evening as after 2100.
  18. Townsville’s airport is approximately 7 km west of the port.
  19. Vertical distance from the waterline to the upper deck.
  20. The itinerant vertical axis about which a ship rotates during a turn.

Sources and submissions

Sources of information

The sources of information during the investigation include:

  • the crew of Madang Coast
  • the Port of Townsville pilots
  • the Regional Harbour Master for Townsville
  • the Australian Border Force
  • the Port of Townsville
  • Maritime Safety Queensland.

References

Maritime Safety Queensland (MSQ) 2015, Record of qualifications and training for Queensland Port Pilots for the Pilotage area of Townsville, MSQ, Brisbane. Available at www.msq.qld.gov.au

Maritime Safety Queensland (MSQ) 2015, Licensing and Training of Marine Pilots in Queensland, MSQ, Brisbane. Available at www.msq.qld.gov.au

Maritime Safety Queensland (MSQ) 2015, Port Procedure and Information for Shipping – Townsville, MSQ, Brisbane. Available at www.msq.qld.gov.au

National Marine Safety Committee, 2015, National Marine Safety Guidance Manual – Guidelines for Marine Pilotage Standard in Australia (Edition 2), Sydney.

Port of Townsville Limited 2015, Pilotage Services – Standard Operating Procedures, Townsville.

Port of Townsville Limited 2016, Pilotage Services – SMS Part 1 - Standard Operating Procedures – POT 123, Townsville.

Port of Townsville Limited 2016, Pilotage Services – SMS Part 2 – Townsville Port Operations – POT 1836, Townsville.

Port of Townsville Limited 2016, Pilotage Services – SMS Part 6 – Emergency Management Procedures, Townsville, Abbort Point & Lucinda – POT 1935, Townsville.

Rowe, Captain RW (with Russell, Captain PJD). The Ship Handler’s Guide, The Nautical Institute in conjunction with the Warsash Maritime Centre, London.

Townsville Pilotage Services 2011, Pilotage Safety Management System, Townsville.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

Submissions were received from the pilot, the Australian Maritime Safety Authority, Maritime Safety Queensland and the Port of Townsville. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

The occurrence

At 1636 Eastern Standard Time[1] on 13 November 2015, the 105 m general cargo ship Madang Coast arrived at the outer anchorage, Townsville, Queensland, from Port Moresby, Papua New Guinea. At 1930 on 16 November 2015, the ship weighed anchor and started its approach towards the Townsville Harbour pilot boarding ground (Figure 1). The bridge team consisted of the master, the chief mate as the officer of the watch (OOW), and a seaman as the helmsman.

Figure 1: Section of navigational chart Aus 257 showing Madang Coast’s track into Townsville Harbour

Figure 1: Section of navigational chart Aus 257 showing Madang Coast’s track into Townsville Harbour. Source: Australian Hydrographic Service, annotated by the ATSB


Source: Australian Hydrographic Service, annotated by the ATSB

At 2106, a Townsville pilot boarded Madang Coast and was escorted to the bridge, where he asked the master for full ahead manoeuvring speed (Appendix A). The master and pilot then commenced the master-pilot information exchange. During the exchange, they discussed information regarding the ship, the inward passage and the berthing plan.

The agreed berthing plan involved a bow-in shallow angle approach, to berth starboard side alongside, without a tug or a lines boat.[2] The ship would approach the wharf with minimum headway and the forward mooring party would run a forward backspring line as the first line ashore. With tension on the spring line and rudder hard-over to port, this should bring the ship in bodily, parallel to the berth. The aft mooring party would then run a stern line ashore to control the stern. The remaining mooring lines would then be run ashore forward and aft.

The master relayed the berthing plan to the second mate via his UHF radio. The second mate was in charge of the forward mooring party, consisting of himself, the bosun and a seaman. He acknowledged the instructions.

At 2146, Madang Coast entered the harbour basin at a speed of 5 kt.[3] The pilot continued to reduce the speed as he manoeuvred the ship across the harbour to Berth 10. By 2149, with the speed at 3.6 kt, the pilot asked for stop and shortly after asked for dead slow astern. At 2151, with the ship just over two cables[4] from the berth, the pilot asked for slow astern with the speed now 3.2 kt.

Figure 2: Madang Coast’s approach to Berth 10 showing times at each position

Figure 2: Madang Coast’s approach to Berth 10 showing times at each position. Source: Australian Hydrographic Service, annotated by the ATSB


Source: Australian Hydrographic Service, annotated by the ATSB

At about 2153, the pilot advised the master he could see the bridge marker on the wharf, the approximate position of the ship’s bridge when the ship was in its final position alongside. Shortly after, stevedores waiting on Berth 10 for the ship’s arrival advised the pilot via VHF radio that the ship’s bow had just entered the berthing pocket. At that time, the wind was from the north at about 11 to 16 kt.

At 2156, the pilot asked for stop and the master set the ship’s controllable pitch propeller (CPP) to zero pitch with about 100 m to run ahead (Figure 2 and Figure 3). Madang Coast was now parallel to, and about 15 m off the wharf, at a speed of 1.8 kt. Shortly after, when the bridge marker was about midships, the ship’s stern started to slowly move away from the wharf.

At 2157, with 25 m to run ahead, the pilot used astern pitch to further reduce the ship’s speed. About 30 seconds later, the forward mooring party threw a heaving line[5] ashore and started running out the forward spring line as the stevedores heaved it ashore.

Figure 3: CCTV images of Madang Coast’s attempted berthing at Berth 10

Figure 3: CCTV images of Madang Coast’s attempted berthing at Berth 10. Source: Port of Townsville, annotated by the ATSB

Source: Port of Townsville, annotated by the ATSB

Shortly after 2158, the line was ashore and was looped over a bollard on Berth 10. The CPP pitch was reduced to zero, with the ship’s speed now at 0.8 kt ahead. The master then informed the second mate to hold on to the forward spring line. The second mate relayed this to the bosun and seaman and they made two turns around the first post of the bitts[6] and manually held onto the working end of the line. At about 2159, as weight came on the forward spring line, the ship’s bow began to pivot towards the wharf. Shortly after, the spring line slipped on the bitts and it fell slack. The bow continued to pivot towards the wharf and the stern continued to move away from it.

At 2201, with the wind effect acting on Madang Coast’s accommodation block at the stern of the ship, the stern drifted away from the berth and towards an oil/chemical tanker (Lynda Victory), on the opposite berth. The master instructed the second mate to hold on to the spring line again and the pilot requested tug assistance from the Townsville vessel traffic service (VTS). About 30 seconds later, tension came on the spring line but only for a short time before it fell slack again.

By that time, the pilot and master could see that the spring line was not holding, and they thought the windlass drum end brake had slipped. The master instructed the second mate to take up the slack and hold onto the mooring line. As the spring line was on the bitts, not the drum end, any slack needed to be heaved in manually by the forward mooring party. This was not an easy or quick task, and as the ship continued to move ahead, more line continued to pay out.

Over the next minute, the pilot and master waited for the slack to be taken up and line secured. During this time, the ship’s stern moved further from the wharf, due to the action of an astern movement and the wind effect. When the forward mooring party finally heaved the spring line in manually, the tension came on the line momentarily, and then it started paying out again.

The master then instructed the second mate to take up the slack, and for the line to be heaved in again. The forward mooring party then removed the line from the bitts and manually carried it to the windlass drum and started heaving the line in. However, as weight started to come on the line, it slipped again once on the drum end. The ship continued to move away from the wharf.

At 2202, the pilot tried to recover control and used ahead pitch with full port rudder to bring the ship back towards the berth. However, the spring line continued to slip and pay out. As the ship continued to close on the shore end of Berth 10, the pilot ordered the port anchor to be dropped, and held on the brake at one shackle.[7]

At 2203, the port anchor was let go and held on the brake. Immediately thereafter, the crew also let go the starboard anchor. By 2205, Madang Coast’s bow had made contact with the shore end of Berth 10 and its port quarter with Lynda Victory. The port quarter moved a short distance aft along Lynda Victory’s hull, coming to rest at 2207 and remaining in this position awaiting the arrival of the tug (Figure 4).

At 2242, a tug arrived off Madang Coast’s starboard quarter and by 2306, the ship was all fast alongside Berth 10 without further incident.

Upon inspection, it was found that Madang Coast and Lynda Victory both received scrape marks and small indentations to the shell plating. Minor damage was also found along the edge of Berth 10 where Madang Coast’s bow had made contact. On 17 November 2015, the ship’s classification society surveyed Madang Coast and found minor indentations that did not affect its structural integrity. The ship subsequently sailed from Townsville on 18 November 2015.

Figure 4: Madang Coast in contact with Lynda Victory and the wharf

Figure 4: Madang Coast in contact with Lynda Victory and the wharf. Source: Port of Townsville

Source: Port of Townsville

__________

  1. Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours.
  2. Lines boat, a boat used to transfer berthing lines from ship to shore.
  3. One knot, or one nautical mile per hour equals 1.852 kilometres per hour.
  4. One cable equals one tenth of a nautical mile or 185.2 m.
  5. A heaving line is a small diameter rope attached to a mooring line. It has a weighted end that is thrown to the shore allowing the mooring line to then be pulled across.
  6. A rectangular base welded to the deck of the ship, upon which two vertical bitts are welded.
  7. One shackle equals 90 ft or 27.43 m.

Safety analysis

As the Madang Coast approached the berth, the first mooring line ashore was looped over a bollard on Berth 10. However, shortly after, as weight came onto the mooring line, it slipped on the post of the twin bollard and fell slack. Madang Coast started moving off the berth and the stern drifted towards a ship alongside, on the opposite berth. Despite repeated efforts by the ship’s forward mooring party crewmembers to hold onto the mooring line, Madang Coast‘s bow made contact with the shore end of Berth 10, and its port quarter with the ship on the opposite berth.

This analysis will examine Madang Coast’s berthing plan, the Port of Townsville Limited (POTL) Pilotage Services guidance for berthing, tug reduction processes and the procedures for pilotage risk management, contingency planning and pilotage best practice.

Guidance for berthing

Madang Coast’s berthing

The pilot assigned to Madang Coast prepared the Townsville Pilotage Plan for its arrival prior to boarding. The plan detailed the wind and tidal conditions, and that a forward spring line would be the first line ashore.

When the first line was run ashore, the forward mooring party made two turns around one post of twin bollard bitts. The mooring party commonly used this method and it required the working end of the line (free end) to be continuously manned and held on to by an operator to maintain tension. On this occasion, when tension came onto the line, the mooring party could not hold onto it and it started to pay out. During interview, the forward mooring party crewmembers stated this berthing was different to previous berthings, as the ship was coming alongside faster than they would normally expect.

The ship had approached the wharf at about 1.8 kt and astern pitch on the ship’s controllable pitch propeller (CPP) was used to reduce the speed to about 0.8 kt, when the spring line was run ashore. Consequently, the left-handed turning CPP led to the stern starting to cut to port and move away from the berth. Further, the effect of the wind progressively increased as the ship’s speed slowly reduced, exacerbating the movement away from the wharf.

The master instructed the second mate to pick up the slack in the line. He expected this would be achieved quickly, as he and the pilot had assumed the spring line had been run around a pedestal roller and onto the windlass drum end. However, the master and the pilot had a different comprehension of the situation to that of the forward mooring party.

Despite the repeated efforts of the forward mooring party to recover and hold onto the mooring line, the ship’s stern moved further from the wharf. Without the spring line to manoeuvre against, the ship’s movement went unchecked. Hence, it is likely that the ship’s approach speed in combination with the use of only two turns of the spring line around the twin bollard post contributed to the spring line slipping.

Contingency planning

Contingency planning is a risk management tool, which provides additional controls to avoid and effectively manage adverse events. Anticipation of, and preparation for, a possible event during the non-time pressured planning phase, makes the reaction to that event more effective. The reaction may then be one from a known and practised range of options, rather than an unknown, instantaneous reaction in an unexpected, time-pressured and stressful situation. Further, such planning allows for the identification of single points of failure, which can then be mitigated for they have a chance to occur. Learning only from real emergencies is not practical and therefore, should be enhanced through training, ideally simulation in a controlled environment.

At the time of the incident, the Port Procedures stated:

The master and pilot should exchange information regarding navigational procedures, local conditions and rules and the ship's characteristics. The proposed manoeuvres should be discussed with the master before commencing the pilotage.

The pilot is the local knowledge expert and is employed to conduct the ship because of this specific knowledge. Madang Coast’s pilot had prepared the pilotage plan for its arrival and detailed the wind and tidal conditions, that the spring line would be the first line ashore and that no tugs had been ordered. The pilot and master had discussed and agreed the berthing manoeuvre, using a forward spring line only. This was deemed a routine berthing and had been completed successfully without incident before. However, contingency plans were not detailed or discussed during the master-pilot exchange (MPX).

It was only after the spring line had continued to slip and the ship continued to move off the berth that the pilot considered contingencies. These included requesting a tug, dropping an anchor and running stern lines to control the stern’s movement. However, it would take considerable time for a tug to attend. In addition, stern lines could not be run ashore as the distance from the stern to the berth was now too far for lines to be run ashore nor was a line’s boat in attendance. Further, when the pilot instructed the master to let go the port anchor, the bow was too close to the wharf for the anchor to be effective in preventing the bow from contacting Berth 10. Consideration of single points of failure during the planning of the berthing, such as the spring line slipping, should have resulted in mitigations such as those listed above being in place earlier in case the planned for potential adverse event eventuated.

The berthing plan relied solely on the use of the forward spring line to manoeuvre the ship alongside. It had not been risk assessed nor had contingencies been considered. As a result, a single failure at such a late stage of the berthing meant that the incident could not be avoided.

Pilotage Services Standard Operating Procedures

Risk management

At the time of the incident, POTL Pilotage Services standard operating procedures (SOP) risk management process only referred to marine incident reporting and the use of Pilot Information Management System (PIMS). That is, the PIMS reports submitted by pilots were the main source of safety risk management. Although promulgated to all pilots, the reports were only discussed as a group during the pilotage meetings, which were held about every 2 to 3 months. Several pilots had questioned the effectiveness of PIMS as a safety reporting system. There was a perception amongst the pilots that the reports were infrequently logged, and could be used to highlight their own errors, or used as a punitive tool. Even so, the pilots were keen to see PIMS used more frequently, to report a wider range of safety issues and to learn from each other.

Between November 2013 and November 2015, the pilot meeting minutes show that PIMS reports were discussed. However, the minutes only included minimal information related to PIMS reports and did not include detailed outcomes or details of what was actually discussed. In addition, they did not record any discussion points arising from a PIMS report submitted 2 months prior to the incident, which involved a tug reduction and subsequent contact with a berth. Without detailed minutes of discussion points or incorporation of agreed outcomes into the SOPs, any learning opportunities remained with those at the meeting and were lost to those who could not attend.

Further, without structured processes to identify, collate and assess hazards and risks, there was a reduced likelihood of effective management of potential risks associated with pilotage. Therefore, at the time of the incident, the risk management processes were not sufficiently mature nor resilient enough to effectively identify and mitigate risks in pilotage services.

Berthing methods and best practice

At the time of the incident, there was no specific guidance for berthing methods nor manoeuvres, such as standardised berthing plans. There was a perception among several pilots that standardised berthing plans were the same concept as prescriptive methods. The imposition or enforcement of them may restrict the ability of a pilot to respond to an unplanned situation, as a pilot may then attempt to return to the standard plan, rather than adapt to an evolving situation.

All pilots were exposed to the different berthing manoeuvres used by other pilots during observation and supervised trips when undertaking an area endorsement. These trips enabled the pilots to observe their peers’ methods of berthing ships. They then either developed their own or followed other pilots’ techniques and methods. The area endorsements were seen as the main way to refresh the pilots’ knowledge. Hence, the pilots used a variety of individualistic berthing methods to berth ships in the absence of standard berthing plans.

Further, as pilots continued to progress through the competency levels, they could do so by using their own berthing manoeuvre preferences and hence, becoming less familiar and practised with other manoeuvres and less likely to conduct them.

Standardised plans, when incorporating best practice can provide an understanding of the ‘how, when and why’ of things being done and allow for contingencies. The Ship Handler’s Guide outlines that a proactive instead of reactive approach will also enable the better transfer of knowledge to new pilots. As no two pilotages are the same, guidance for berthing methods, for example at Berth 10, could be developed using the collective combined knowledge and experience of the pilots. When used in combination with a risk based framework, the overall flexibility could be enhanced through the development and incorporation of effective contingency plans. Guidance that is revised, amended, briefed and debriefed could also be used for training pilots and provide opportunities for continuous development and knowledge sharing.

Port procedures

Tug usage and reduction guidelines

On 13 November, the shipping agent submitted a request for a tug reduction, as was the usual practice for Madang Coast. Following a review of the guidelines and a discussion with the pilot manager, the acting Regional Harbour Master (ARHM) approved the tug reduction request subject to the weather at the time. This information relayed to the shipping agent and Townsville Vessel Traffic Services (VTS). Further, the daily shipping schedule[28] detailed that no tugs were booked for the ship.

The ARHM, pilot manager, and master were all unaware that the agent’s request was made without the master’s knowledge. During interview, the master stated he had expected a tug to assist berthing due to the wind conditions at the time. This was despite him not requesting nor liaising with the shipping agent to organise this. When he was informed of the tug reduction by the pilot during the MPX, he did not object and allowed the pilotage to continue.

Neither the Port Procedures nor the SOPs included a requirement to consult with a ship’s master before the removal of tugs was approved. The pilot became aware of the tug reduction after he reviewed the daily shipping schedule on 16 November. Whilst this tug reduction process followed the Port Procedures, those directly involved in the pilotage were not consulted.

Audit findings

At the time of the contact, Marine Safety Queensland’s (MSQ) Port Procedures Manual stated that the MPX should include ‘general agreement on plans and procedures including contingency plans for the anticipated passage’.[29] However, the SOPs did not contain any passage or berthing contingency plans for the Townsville pilotage area.

The 2014 and 2015 audits included findings regarding procedures for emergency situations:

Procedures for emergency situations for the pilotage area. Pilots will discuss various scenarios during the pilot meetings to develop awareness and identify options to consider in event of an emergency once past the point of no return.

Procedures for emergency situations within the pilotage area to be added as an independent section in the Pilotage SOP's.

However, in the period between the 2014 and 2015 audits, only two scenarios were discussed at the pilot meetings, and the outcomes and plans were not minuted as required by the audit finding, nor added to the SOPs.

External auditing is an invaluable tool for identifying areas for improvement. However, for it to be effective both parties need to have a follow-up process that ensures audit findings are appropriately monitored, actioned, and closed out in a timely and appropriate manner.

__________

  1. The shipping schedule detailed movements from 1630, 16 November to 2359, 18 November 2015.
  2. Port procedures and information for Shipping – Port of Townsville. Pilotage, Section 8.5.

Findings

From the evidence available, the following findings are made with respect to the contact made by Madang Coast on 16 November 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • As Madang Coast came alongside the wharf, the forward spring line slipped and could not be used to manoeuvre against. This was likely a result of the mooring line holding arrangement and the ship’s approach speed.
  • As the ship approached the wharf, the combination of wind effect and astern movement moved the stern away from the wharf. As the spring line could not be used to manoeuvre against, the stern could not be brought back.
  • The pilotage plan did not identify nor consider contingencies for single points of failures, therefore when the mooring line slipped, the contact with the wharf and adjacent ship could not be avoided.
  • The Port of Townsville Limited Pilotage Service risk management processes were not sufficiently mature nor resilient enough to effectively identify and mitigate risks during pilotage. [Safety issue]

Other factors that increased risk

  • The Port of Townsville Limited Pilotage Services’ Pilotage Service Safety Management System did not have documented guidance on berthing manoeuvres nor any associated contingencies. [Safety issue]
  • The Port Procedures manual for Townsville allowed shipping agents to request a tug reduction without the knowledge of the ship’s master. [Safety issue]
  • The regional harbour master and the pilotage service did not have processes in place to follow up audit findings, to ensure that they were appropriately monitored, actioned and closed out in a timely manner. [Safety issue]

Appendices

Appendix A – Pilot card manoeuvring information

Manoeuvring engine order

RPM/Pitch

Speed in knots
Loaded condition

Speed in knots
Ballast condition

Full ahead

7.5

12.0

13.0

Half ahead

4.0

8.0

8.7

Slow ahead

2.5

5.0

5.4

Dead slow ahead

1.0

2.5

2.6

Dead slow astern

1.0

   

Slow astern

2.5

   

Half astern

4.0

   

Full astern

7.5

   

Appendix B – Townsville Pilotage training requirements

Qualifications and training for Queensland Port Pilots for the Pilotage area of Townsville

Level

4

3

2

1

Check Pilot

Ship length

up to
120 m

up to
195 m

Up to
205 m

unrestricted

 

Pilotage trips

 

20 Level 4

20 Level 3

20 Level 2

200

Observation[30] trips

14

(4 at night)

7 arr & 7 dep

2

4

on Level 2 ships

2

2 panamax arrivals

 

Supervised[31] trips

9

6 arr & 3 dep

2 during darkness

6

4 arr

2 during darkness

(1 arr & 1 dep)

6

during darkness

(1 arr & 1 dep)

6

2 panamax

2 high windage

during darkness

(1 arr & 1 dep)

 

Check[32] trips

2

2

2

2

2

1 arr 1 dep

Radar and ARPA course

Yes

Yes

Yes

Yes

Yes

Bridge Resource Management

 

Yes

Yes

Yes

Yes

Simulator course or Ship Handling Course

 

Yes

Yes

Yes

Yes

Marine Pilots Training Course

     

Yes

Yes

Source: MSQ (2015 requirements)

Appendix C – Updated Townsville Pilotage training requirements (in red)

Qualifications and training for Queensland Port Pilots for the Pilotage area of Townsville

Level

4

3

2

1

Check Pilot

Ship length

up to 120 m

up to 195 m

Up to 205 m

unrestricted

 

Pilotage trips

 

20 Level 4

20 Level 3

20 Level 2

200

Pilotage trips

       

1000

Observation trips

Before incident

14

(4 at night)

7 arr & 7 dep

2

4

on Level 2 ships

2

2 panamax arrivals

 

Observation trips

30

(10 at night)

min 14 arr & dep

3 with an anchor

4 without a tug

11

6 arr & 5 dep

4

2 arr & 2 dep

10

6 arr & 4 dep

 

Supervised trips

9

6 arr & 3 dep

(2 during darkness)

6

4 arr

(1 arr & 1 dep during darkness)

6

(1 arr & 1 dep during darkness)

6

(1 arr & 1 dep during darkness)

 

Supervised trips

12

8 arr & 4 dep

(4 without a tug)

(2 arr & 2 dep during darkness)

8

5 arr & 5 dep

(2 using a tug)

(2 arr & 2 dep during darkness)

9

(1 arr & 1 dep during darkness)

6

(1 arr & 1 dep during darkness)

 

Check trips

2

2

2

2

2

1 arr 1 dep

Check trips

3

1 arr, 1 dep &

1 berthing without a tug

3

4

3

2

1 arr 1 dep

Radar and ARPA course

Yes

Yes

Yes

Yes

Yes

Bridge Resource Management

 

Yes

Yes

Yes

Yes

Simulator course or Ship Handling Course

 

Yes

Yes

Yes

Yes

Marine Pilots Training Course

     

Yes

Yes

Workplace trainer / assessor

       

Yes

Source: MSQ (2016 requirements)

__________

  1. Trainee pilots observe qualified senior pilots conducting pilotage trips.
  2. A mentoring trip by a qualified senior pilot to train a conducting pilot
  3. An assessment of a conducting pilot’s competence as a pilot

Safety issues and actions

The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the marine industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

The initial public version of these safety issues and actions are provided separately on the ATSB website to facilitate monitoring by interested parties. Where relevant the safety issues and actions will be updated on the ATSB website as information comes to hand.

Risk management

Safety issue number: MO-2015-007-SI-01

Safety issue description

The Port of Townsville Limited Pilotage Service risk management processes were not sufficiently mature nor resilient enough to effectively identify and mitigate risks during pilotage.

Contingency planning

Safety issue number: MO-2015-007-SI-02

Safety issue description

The Port of Townsville Limited Pilotage Services’ Pilotage Service Safety Management System did not have documented guidance on berthing manoeuvres nor any associated contingencies.

Tug reduction process

Safety issue number: MO-2015-007-SI-03

Safety issue description

The Port Procedures manual for Townsville allowed shipping agents to request a tug reduction without the knowledge of the ship’s master.

Audit response

Safety issue number: MO-2015-007-SI-04

Safety issue description

The regional harbour master and the pilotage service did not have processes in place to follow up audit findings, to ensure that they were appropriately monitored, actioned and closed out in a timely manner.

Additional safety action

Following this contact, the ATSB was advised the following addition safety action has been taken:

MSQ has implemented a Continuing Professional Development framework (CPD), developed by the Australian Marine Pilotage Institute (AMPI). The CPD applies to all marine pilots licenced by MSQ for providing pilotage services in Queensland ports. The focus is on improved pilotage training by making it contemporary and relevant to pilots’ needs in their ports. As the training is more progressive, new developments and initiatives within the pilotage profession can be identified and incorporated. Current pilots have a transitional period of 3 years to obtain sufficient professional development to be eligible for consideration of renewal of their pilot licence. See Appendix C for details.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number 323-MO-2015-007
Occurrence date 16/11/2015
Location Townsville Harbour, Berth 10
State Queensland
Report release date 19/02/2019
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Marine
Marine occurrence category Contact
Occurrence class Serious Incident
Highest injury level None

Ship details

Name Madang Coast
IMO number 9135767
Ship type Pilotage
Flag Papua New Guinea
Manager Consort Express Lines, Papua New Guinea
Departure point Papua New Guinea
Destination Townsville, Qld

Derailment of loaded ore train M03544 near Walla, Western Australia, on 3 December 2015

Final report

Safety summary

What happened

On 2 December 2015, BHP Billiton (BHPB) train M03544 was loaded with iron ore at Yandi, Western Australia (WA). The train departed Yandi at about 2211 Western Standard Time (WST) and travelled north towards Port Hedland, WA, on the Newman main line.

At about 0530 on 3 December 2015, the train controller based in Perth was alerted to a dragging equipment detector (DED) alarm at the 67 km mark at Walla. Seven seconds later, train M03544 recorded a loss of brake pipe air pressure before the train came to a stop with the lead locomotive positioned near the 64.188 km mark, about 3 km from the DED.

The train controller contacted the train driver, advising that DED alarms had activated on both the east and west tracks. The train driver informed the controller that a loss of brake pipe air pressure had resulted in an uncommanded brake application bringing the train to a stop.

Shortly afterwards, as the driver walked towards the rear of the train to determine the cause of the loss of air pressure, he found that the train had separated and derailed.

What the ATSB found

The ATSB investigation identified that train M03544 derailed due to a broken rail. A fracture of the rail was probably initiated by the rapid growth of a detectable, yet unidentified, fatigue‑related transverse defect(s) in the west rail near the 67 km mark during the passage of the train.

The investigation also identified that the condition of the rail in the vicinity of the fracture contributed to relatively frequent failures in that area.

Finally, ultrasonic defect testing of the rail was undertaken in the heat of the day, potentially masking defects due to compressive forces in the rail.

What's been done as a result

In response to this occurrence, the operator of the train and track, BHP Billiton, took measures to improve track condition and reduce in-service rail defects by:

  • accelerating the re-railing of 833 kilometres of track, including replacement of the track in the vicinity of the fracture
  • the introduction of processes to:
    • reduce the initiation of rolling contact fatigue cracks in rail track
    • improve rail defect detection to prevent fatigue cracks from progressing to track failure.

Safety message

Early detection, assessment, and effective management of track defects is critical to minimising the risk of derailment and maintaining safe rail operations. Therefore, it is essential that track maintenance and infrastructure fault detection be of a high standard.

The occurrence

On 2 December 2015, BHP Billiton (BHPB) train M03544 was loaded with iron ore at Yandi, Western Australia (WA). The train departed Yandi at about 2211 Western Standard Time (WST) and travelled north towards Port Hedland, WA, on the Newman main line.

At the about 0221 the following morning, the train stopped for a driver changeover at the 199.447 km mark at Garden (Figure 1). The train resumed its travel to Port Hedland at about 0244.

Near Turner (Figure 1), at about the 119 km mark, the train driver of southbound train M03568 carried out a roll-by inspection as it crossed train M03544. The driver of train M03568 observed no defects on train M03544.

When the rear of the train had passed the 108 km mark, the train controller based in Perth observed that the track remained occupied. The controller contacted the train crew and issued an operational speed restriction of 60 km/h. The controller also requested maintenance staff to inspect the track infrastructure to determine the cause of the occupation.[1]

At about 0527, on approach to the 67 km mark, the train was travelling at a speed of about 61 km/h on a descending grade under dynamic brake.

At about 0528, the lead locomotives passed the dragging equipment detector (DED) located at the 67.01 km mark. About 2 minutes later, the train driver applied a brake command to manage train speed.

Figure 1: Map of the Pilbara region showing the derailment location

Figure 1: Map of the Pilbara region showing the derailment location. Source: Geoscience Australia annotated by ATSB

Source: Geoscience Australia annotated by ATSB

At 0530:29, the train controller was alerted to a DED alarm. At this time, the lead locomotives were about 2.35 km past the location of the DED detector (the train was 2.83 km in length).

About 7 seconds later, the train recorded a loss of brake pipe air pressure. As a result, the train came to a stop at 0531:24 with the lead locomotive positioned near the 64.188 km mark (about 3 km from the DED).

The train controller contacted the train driver advising that DED alarms had activated on both the east and west tracks. The train driver informed the controller that a loss of brake pipe air pressure had resulted in an uncommanded brake application bringing the train to a stop.

Shortly afterwards, the train driver began walking towards the rear of the train to determine the cause of the loss of brake pipe air pressure.

The train driver found that two ore cars located at positions 80 (OC 2266) and 81 (OC 6182) in the ‘B’ rake portion of the train had separated (Figure 2). The gap between the cars was about 350 m but they had not derailed. At position 85 (OC 8934), the driver found the trailing axle on the trailing bogie had derailed. The next four ore cars (that is, immediately trailing OC 8934) had derailed and overturned onto the west side of the track but had remained coupled.

Trailing the four derailed cars on the west side of the track, there was a gap of about 20 m. The next group of 21 ore cars (positions 90 to 110) had derailed in the vicinity of the 66.950 km mark. The first 10 of these ore cars were severely damaged and had concertinaed to both the west and east sides of the west track. Some of the cars had come to rest at 90° to the direction of travel. A number of the derailed ore cars pushed the east track laterally out of alignment for about 10 m in an easterly direction.

The remainder of the cars, from position 111 through to the end of the train (position 132), had remained on the track.

The derailment resulted in significant damage to 26 ore cars (Figure 3) but no one was injured.

Following the clean-up of iron ore, vehicles, wayside equipment and track materials, 50 m of the east track and 200 m of the west track was rebuilt. Operations on the Newman mainline east and west tracks recommenced on 5 December 2015.

Figure 2: Diagram of the ore cars near the 67.0 km mark

Figure 2: Diagram of the ore cars near the 67.0 km mark. Source: BHP Billiton, annotated by ATSB

Source: BHP Billiton, annotated by ATSB

Figure 3: Derailed, loaded iron ore cars located in the rear portion of train M03544

Figure 3: Derailed, loaded iron ore cars located in the rear portion of train M03544. Source: BHP Billiton
Source: BHP Billiton

__________

  1. The cause of the track occupation was later identified as the result of a broken flash-butt weld at the 107.8 km mark.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • BHP Billiton ICAM investigation report (rev 4)
  • ALS Global Examination of failed rail section ex – Newman Main Line (91HM0474 Rev 1)
  • ABEN Technical Services W15-0109 - Derailment Review - Rail Testing Aspects
  • Rail Technology International 67km Derailment Response
  • NTS Ultrasonics Review: Derailment Investigation Report
  • Institute of Railway Technology Review of Investigation Reports (Monash/RT/2016/1140)
  • International Heavy Haul Association 2015 Managing the Transition from Rail Wear to Rolling Contact Fatigue in a Heavy Haul Environment
  • BHP Billiton Standard - Code of Practice Track Engineering - Number: 0002664 Version: 2.1

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to BHP Billiton, Office of the National Rail Safety Regulator, and Rail Technology International.

Submissions were received from BHP Billiton and the Office of the National Rail Safety Regulator. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Context

The Australian Transport Safety Bureau (ATSB) did not attend the incident site. The information presented in this section of the report and the analysis section that follows is principally based on information provided to the ATSB by BHP Billiton (BHPB), including reports commissioned by BHPB.

Location

Walla Siding is located on the Newman Railway in the Pilbara region of Western Australia (WA). The Newman Railway carries iron ore from seven inland mines to two port facilities at Port Hedland (Figure 1). The railway generally runs in a north-south alignment with the track kilometre distance starting at zero from Port Hedland and increasing as it runs south. Walla Siding is located about 60 km south of Port Hedland.

Weather

Weather conditions at the time of the derailment were fine and clear. The temperature ranged from a minimum of 23.0 °C to a maximum of 32.7 °C.

Train M03544 and its crew

Train M03544 was a heavy haul, bulk iron ore service operated by BHPB. The train was 2.83 km in length and had a total weight of about 41,562 t. The train was hauled by four EMD SD70 ACe locomotives. There were two locomotives positioned at the front of the train, and a rake of 132 ore cars (‘A’ rake). Another two locomotives were positioned in the middle of the train, with a further 132 trailing ore cars (‘B’ rake) (Figure 4).

Figure 4: Typical arrangement of BHPB iron ore train consist

Figure 4: Typical arrangement of BHPB iron ore train consist. Source: ATSB
Source: ATSB

The crew consisted of two train drivers, one working the train and the other travelling passenger. The train driver commenced shift at 2200 on 2 December 2015. The driver had worked two shifts following a rest and recreation break and had had 8 hours rest before boarding the train at Garden (Figure 1). He had 30 years of train driving experience. He had been assessed and reaccredited as a mainline locomotive driver on 15 January 2015.

The driver was tested for the presence of alcohol and other drugs following the derailment, returning a negative result.

Locomotive data extracted after the derailment verified the train speed was 61 km/h through the point of derailment. The train driver had maintained the operational speed restriction of 60 km/h imposed by the train controller near the 108 km mark.

The investigation found that improper train handling or excessive speed did not contribute to the derailment.

Rolling stock

The BHPB ore trains are operated as unit trains using a variety of ore car types including A Goninan and Co/Lynx Engineering (GOLYNX), Qiqihar Railway Rolling Stock (Group) Company (QRRS) and Bradken. The typical arrangement of the ore car fleet comprises of rotary couplers on the ‘A’ end and a fixed coupler on the ‘B’ end (Figure 5). An electronically controlled pneumatic (ECP) braking system was fitted to these ore cars. The ore cars operating with isolated brakes in train M03544 was less than 1.5 per cent of the total braking capacity, and this proportion was within BHPB’s operating standard.

Figure 5: Typical BHPB ore car arrangement

Figure 5: Typical BHPB ore car arrangement. Source: BHP Billiton, annotated by ATSB.

Source: BHP Billiton, annotated by ATSB.

BHPB used a trip-based maintenance strategy where ore cars were serviced after 246 return trips from Port Hedland to the Newman mine sites. [2] This return trip interval between maintenance equated to the ore cars being serviced about every 210,000 km.

An assessment of maintenance records for the ore cars in train M03544 found that 21 cars in ‘A’ rake were due to be serviced. Two of these ore cars had maintenance requests as the return trip service interval had been exceeded. The majority of the cars in ‘B’ rake had completed 34 trips. In total, 7.9 per cent of ore cars had exceeded the maintenance interval.

An inspection of the derailed ore cars found no evidence of fractured wheels or failed axle bearings. Data extracted from the wayside hotbox detector (HBD) site located at the 84 km mark found no evidence of high bearing temperatures in train M03544 before it derailed.

Wheel impact load detection (WILD)[3] sites on the Newman network recorded two ore cars in train M03544 with ‘severity 2’ (intermediate level) peak load impacts of 31 t and 31.2 t. These ore cars were located in ‘A’ rake at positions 31 and 37 respectively. Both ore cars had ‘cut-out requests’ noted on the wayside equipment alarm report, indicating that these vehicles were scheduled to be inspected and removed from service for repair.

There were no excessive wheel impact loads detected in ‘B’ rake of train M03544 and preceding train M0356.

There was no track defect recorded in the vicinity of the 67 km mark on the day of the derailment. The signalling system maintained a continuous track circuit before the arrival of train M03544.

A review of the train’s payloads found ore car 8667 at position 61 in ‘B’ rake was slightly heavier than the majority of other ore cars in the consist, with a gross weight of 162.7 t. Ore car 8667 was located 25 cars ahead of ore car 8934, the first car to derail near the 67 km mark. Although more heavily loaded, the loading on car 8667 conformed to BHPB transit mass standards.

Visual inspections of the rolling stock, reviews of maintenance records, wayside monitoring detection systems and data concluded it was unlikely that a significant rolling stock defect had initiated or contributed the derailment of train M03544.

Rail impacts on wheels

The four ore cars immediately ahead of the first derailed ore car, 8934 (Figure 22), were quarantined and transferred to Mooka where an inspection found rail impact marks on the left wheel tread surfaces. The ore cars were transferred to Port Hedland where the iron ore was dumped. The wheel sets were removed from ore cars 8819 and 3290 at the ore car repair shop where a detailed examination of the wheel tread surfaces was carried out. Single impact marks found on each left wheel of ore cars 8819 and 3290 were consistent with impacts with a broken rail head. The impact marks generally increased in magnitude relative to their trailing position and ore car 8934 (that is, the first derailed car).

Wheelset number 2L of ore car 8934 showed four wheel tread surface impact marks (Figure 6 & Figure 7). In the direction of wheel travel/rotation, the impact marks were intermittently spaced, generally oval-shaped about 45 mm long and angled at about 90° to the wheel flange.

Figure 6: Ore car 8934 - wheelset 2L impact marks from broken rail segments

Figure 6: Ore car 8934 - wheelset 2L impact marks from broken rail segments. The top photo shows the radial spacing of the rail impact marks viewed from the back of the wheel. The bottom photo shows three of four corresponding rail impacts looking from the front of the wheel. Enlarged details of the four rail impact marks are shown in Figure 7. Source: BHP Billiton, annotated by ATSB.

The top photo shows the radial spacing of the rail impact marks viewed from the back of the wheel. The bottom photo shows three of four corresponding rail impacts looking from the front of the wheel. Enlarged details of the four rail impact marks are shown in Figure 7.

Source: BHP Billiton, annotated by ATSB.

Figure 7: Enlargements of the four rail impact marks ore car 8934 - wheelset number 2L

Figure 7: Enlargements of the four rail impact marks ore car 8934 - wheelset number 2L. Numbered 1 – 4, corresponding rail impact bruises on the wheel tread surface (Figure 6) on ore car 8934 - wheelset #2L. All impact marks are transverse, angled about 90° across the tread surface. - Source:  BHP Billiton.

Numbered 1 – 4, corresponding rail impact bruises on the wheel tread surface (Figure 6) on ore car 8934 - wheelset #2L. All impact marks are transverse, angled about 90° across the tread surface.

Source: BHP Billiton.

Track infrastructure

The BHPB iron ore railway was a standard gauge track structure constructed with 68 kg/m rail fastened with resilient clips to concrete sleepers. The rails were continuously welded and joined with flash-butt[4] and aluminothermic[5] welds. The sleepers were contained in a crushed rock ballast and BHPB operated trains of 40 t axle loads over its track infrastructure.

In the direction of travel, the west track through the location of the derailment was tangent on a downhill gradient varying between -0.22 per cent and -0.8 per cent. Maximum track speed was prescribed at 75 km/h. The majority of loaded trains traverse the west track with empty trains returning via the east track.

The BHPB specification SPEC-073-C-12006 described the assessment and classification and response to rail defects with ratings for three levels of severity. A severity level 1 required more urgent attention than that of a severity level 3 (Table 1).

Table 1: Rail defect severity ratings

Severity rating

Defect condition

Corrective action

Comments

1

Immediate risk of broken rail or interruption to haulage operations

Clamp and remove within 24hrs

Track may be closed for some defect conditions

2

Will not develop to Severity 1 before next scheduled inspection

Clamp and remove within 1 week

Corrective action period may be reduced in the event of increased haulage rates

3

Will not develop to Severity 2 before next scheduled inspection

Clamp and remove within 1 month

Corrective action period may be reduced in the event of increased haulage rates

Track geometry inspections

As part of the process in determining track condition, a series of track geometry parameters such as vertical and horizontal alignment, cross level variation, twist and gauge are considered. Potential track defects are examined and their severity determined with reference to defined defect limits for each track geometry parameter. The defined limits were documented in the BHPB standards.

A track geometry car is used to measure the track accurately and compare the results against a table of defect limits, which allows an appropriate response category to be allocated based also on rated track speed. Personnel conducting track patrols and unscheduled inspections also assess the severity of potential defects based on their knowledge and experience but do not normally take measurements.

On 27 November 2015, two severity 3 defects were found on the west track at the 67.052 km and 67.038 km locations. These were classified as severity 3 geometry defects requiring inspection within 28 days and repair within 12 weeks.

Rail and welded joint inspections

Patrol inspections were usually performed on the track between Port Hedland and Yandi while travelling in a road/rail vehicle at intervals not exceeding 2 days. Patrol inspections looked for visible rail defects such as broken rails, damaged rail surfaces or rail deformation. General inspections were performed for all new rail welds, and in response to previously identified defects or unusual rail conditions.

Continuous, detailed non-destructive test inspections (NDT) were carried out using vehicle-mounted and/or manual (handheld) ultrasonic test methods to detect internal and surface rail defects (See the section titled Ultrasonic tests – west track). Manual ultrasonic testing was used to verify the integrity of new aluminothermic and flash-butt welds and to confirm the size of suspected defects identified by continuous testing or visual inspection.

Identified rail defects were assessed within a series of defect categories such as transverse defect,[6] horizontal/vertical split or weld defect in the rail head, web, or foot.[7] The classification, position and size of defects were analysed with reference to a table of defect limits and associated severity codes. The severity codes defined the appropriate response required to control any risk to railway operational safety.

Rail defects were assessed within three levels, where a severity level 1 (red) broken weld defect must be removed before the passage of the next train. Severity level 2 defects (yellow) were to be generally actioned through regular reassessment or removed within 24 hours of discovery. A severity 3 level (blue) defect generally required a response time of 48 hours with daily reassessments and removal as soon as practically possible.

According to BHP Billiton Iron Ore, aluminothermic welds, and to a lesser extent flash-butt welds, were known to exhibit an increased frequency of defects and broken rails relative to those which occurred in parent rail. For this reason, all defects associated with welds may be classified separately to those in parent rail, or in cases where the generic defect types (for example, transverse defect) are identical, classified at a higher severity levels.

Welding records showed that the insulated rail joint[8] (IRJ) located at the 67 km mark was replaced on 5 September 2015 (Figure 8).

Figure 8: West track, location of repairs to rail sections near the 67 km mark

Figure 8: West track, location of repairs to rail sections near the 67 km mark. Video image capture of the west track showing the east and west rail near the insulated rail joints at the 67 km mark. There were a number of welds in close proximity (orange arrows). Source: Rail Technology International, annotated by ATSB

Video image capture of the west track showing the east and west rail near the insulated rail joints at the 67 km mark. There were a number of welds in close proximity (orange arrows).

Source: Rail Technology International, annotated by ATSB

Tamping

All BHPB track tamping was carried out based on data from the dynamic track recording vehicle and track geometry defect exceedance reports. Geometry defects exceeding thresholds over a longitudinal distance greater than 2 m contributed to increased maintenance and potentially a derailment.

A review of track maintenance records found that hand tamping was carried out at the 67.01 km mark on 30 September 2015. The records showed that about 1 month later (on 28 October 2015), the track was machine tamped on the west track between the 66.0 km to 66.9 km locations.

A track geometry report dated 24 November 2015 identified three defects located between the 65.5 km and 68.7 km locations on the west track. Low rail height was reported in this section but no significant anomalies were found.

A review of the track condition index[9] for 400 m north and south of the 67 km mark found no extraordinary geometry conditions.

Insulated rail joints

Records showed repairs on the west rail were carried out on 5 September 2015 to the broken IRJ at the 67.00 km mark. The most recent previous break of the IRJ at the same location had occurred on 25 June 2015.

The routine 3-monthly inspections of IRJs were found to have been carried out. On 20 November 2015, an inspection of the IRJs on the east and west tracks at the 67 km mark was carried out with no defects identified.

Rail height

The height of new rail was 185.7 mm. On tangent track, a minimum height wear limit of 166 mm was applied.

On the Newman west track for a distance of up to 10 m either side of the IRJ at the 67.0 km mark, rail height was measured at about 183 mm. The rail height on each side of those higher rail sections was about 11 mm lower at 172 mm (Figure 9).

Figure 9: Graph showing the variation in rail height near the IRJ at the 67 km mark

Figure 9: Graph showing the variation in rail height near the IRJ at the 67 km mark. Source: Rail Technology International

Source: Rail Technology International

Broken rails (west track)

An inspection of records listing broken rail defects for the period 1 January and 3 December 2015 showed three rail breaks on the west track between the 66 km and 68 km marks. On 2 November 2015, an aluminothermic weld repair was carried out on the west rail at the 67.27 km mark. Two other aluminothermic weld repairs to the east rail were made at the 67 km mark on 25 July 2015 and a second break on 24 September 2015 at the 67.01 km mark was recorded.

Rail grinding

Rail grinding is carried out to re-profile the rail head and in the process, removing small rolling contact fatigue (RCF) cracks. This grinding reduces the likelihood of RCF cracks developing into transverse defects deeper into the rail head, which can result in a rail break (usually under a loaded train).

A review of BHPB records showed that rail grinding on the west track through the location of the derailment was in accordance with the specification at the following locations:

  • 2 October 2015 – 65.5 to 74.8 km
  • 20 August 2015 – 64.6 to 67 km
  • 26 May 2015 – 65.8 to 73.2 km.

Ultrasonic tests - west track

Ultrasonic rail testing involves passing sound waves into the rail and monitoring the echo returned by the sound waves reflecting off internal and external surfaces (reflectors). Defects within the rail (Figure 10) create reflectors which return unique echo patterns depending on their type, location and size. Examination of the echo patterns allows an operator to deduce the existence, type and size of suspected rail defects.

Figure 10: Rail defect types

Figure 10: Rail defect types. Source: Australian Rail Track Corporation Non-Destructive Testing of Rail (for Internal & Surface Defects) ETE-01-03.

Source: Australian Rail Track Corporation Non-Destructive Testing of Rail (for Internal & Surface Defects) ETE-01-03.

Ultrasonic inspections of rail on the BHPB network were carried out at intervals based on rail haulage rates measured in million gross tonnes (MGT). The minimum rail inspection frequency is 5 MGT and was conducted through the contracted services of Rail Technology International (RTI) using a road-rail vehicle.

Limitations of ultrasonic testing

Ultrasonic rail testing relies on detecting an echo from sound waves reflecting off internal and external surfaces (reflectors). Detection of defects using this method requires skilled operators and the ability of the equipment to detect a clear echo reliably is dependent on a number of factors, such as:

  • Grease, dirt or uneven rail surfaces (due to shelling, pitting and/or worn rail profiles) can reduce the quality of the interface between the ultrasonic probe wheels and the rail surface.
  • The geometry of the defect may reflect the sound waves away from the probe wheels thereby attenuating the echo signal received by the ultrasonic test equipment.
  • Low reflectivity of the defect surfaces may result in greater attenuation of the reflected sound waves than those of a surface with high reflectivity.
  • Equipment calibration.
  • Compressive forces within the rail (due to high rail temperature) may push the surfaces of a defect together such that the sound waves are transmitted through the defect rather than reflecting off the surfaces of the defect.

A review of one of BHPB’s internal investigation reports[10] for this occurrence noted that ‘small transverse defects are easier to detect when the track is cooler’. The review also noted that:

…previous ultrasonic inspections of track were only carried out at night, where the advantage of ultrasonic testing, when the rail is cool and with reduced thermal stress, allowed for greater detection of transverse defects. The night inspections were carried out on the Mt Newman railway, however this practice ceased many years ago for non-technical reasons...

This review recommended that consideration should be given to reintroducing the practice of night inspections.

Assessment of data

The last ultrasonic test carried out on 29 November 2015, four days before the derailment, found a severity 1 transverse defect at the 67.280 km mark on the west rail. The defect was located in the rail head at an aluminothermic weld joint. The defect was removed 2 days later with replacement rail aluminothermically welded in-situ.

Between 1 January and 28 November 2015, two other severity 1 defects (Table 1) were detected on the west track between the 66 km and 68 km marks on the Port Hedland to Yandi line. These defects were also removed. In this period, one severity 3 defect was found on the west rail at the 68.197 km mark, about 1.2 km from the location of the derailment.

__________

  1. Ore cars with higher trips were allowed to operate with asset protection and condition monitoring systems where the wheel condition permitted (i.e. where flange, and tread condition remained within prescribed tolerances).
  2. Wheel Impact Load Detector (WILD) is a safety system used to identify defective wheels by measuring the dynamic impact on railway track.
  3. The fusion welding of rail ends by electric arc heating and contact under high pressure.
  4. A welding process in which an aluminothermic reaction takes place within a crucible and the resultant metal flows into a mould enclosing the rail ends that are to be joined.
  5. Transverse defects are progressive fractures that spread across the width of the rail.
  6. Not all under-foot defects are detectable by ultrasonic or visible inspections.
  7. A rail joint manufactured and assembled such that the joined rails are electrically insulated from each other.
  8. Track Condition Index (TCI) is a single unit of measurement of track condition in any one 100 m segment of track. This value is calculated through the application of weightings to returned geometrical measurements. Geometrical parameter weightings have been defined based on their influence to track performance. (BHP Billiton Track Engineering CoP v2.1)
  9. NTS Ultrasonics Pty Ltd REVIEW: DERAILMENT INVESTIGATION REPORT: WALLA 67 KM. 3/12/2015.

Findings

From the evidence available, the following findings are made with respect to the derailment of the loaded BHP Billiton iron ore train M03544 near Walla, Western Australia on 4 December 2015.

These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • Train M03544 most likely derailed as a result of passing over a fractured section of rail.
  • The fracture of the rail probably resulted from rapid growth of undetected fatigue‑related transverse defect(s) in the west rail near the 67 km mark during the passage of train M03544.
  • The fatigue‑related transverse defect was probably detectable, but not identified during ultrasonic testing of the rail.
  • The general condition of the rail on the west track, in the vicinity of the rail fracture, contributed to relatively frequent failures in that area. [Safety issue]

Other factors that increased risk

  • Ultrasonic testing was undertaken in the heat of the day when rail temperatures were high, potentially masking defects due to compressive forces in the rail.

Safety analysis

Broken rail section

Following derailment of train M03544, BHP Billiton (BHPB) commissioned a series of investigations into the incident. The investigations concluded that the derailment most likely occurred due to a broken rail on the west track near the 67 km location. The cause of the broken rail was attributed to an undetected transverse defect that likely resulted from rolling contact fatigue (RCF). The defect was found in a 1.1 m length of rail retrieved from the derailment site (Figure 11).

Figure 11: Broken rail with fatigue cracks

Figure 11: Broken rail with fatigue cracks. Source: BHP Billiton

Source: BHP Billiton

The provider of ultrasonic rail testing for the occurrence track, Rail Technology International (RTI), disagreed with BHPB’s finding as they concluded that that 1.1 m length of rail was ‘highly unlikely’ to have been in service at the time of the derailment. This conclusion was based on a number of factors such as weld finish, appearance/condition of the fracture surface, and size and number of defects. The ATSB conducted a review of the evidence and concluded:

  • The weld finish in the 1.1 m section was consistent with welds in the vicinity of the 67 km mark.
  • The oxidised appearance/condition of the fracture surfaces resulted from water being used onsite to wash the surface in preparation for detailed photography.
  • Specialist metallurgical examination of the section concluded that the fracture surfaces were only lightly corroded. That was consistent with a relatively recent failure.

Additionally, the rail height on the west track was about 172 mm, except for a 20 m section of 183 mm height rail in the vicinity of the 67 km mark. The height of the recovered length of rail was consistent with the rail height west track near the 67 km mark.

Finally, there were four welds at about 5 m intervals in each rail of the west track near the 67 km mark. The welds closest to the insulated rail joint (IRJ) joined rail of similar height, whereas the outer welds joined rail of different heights. The weld in the recovered section of rail indicated joints of similar height rail.

Considering all of the above, the ATSB concluded that the 1.1m broken section of rail was probably in service immediately prior to the derailment and not from a previous rail failure.

While the RTI report suggested the more likely cause of the derailment ‘would be a failure of wheel, bogie or axle’, no specific evidence was provided to support that conclusion. Furthermore, there was no evidence of rolling stock failure found onsite (both rolling stock and prior track scarring) that contributed to the derailment and the general disposition of the derailed cars was consistent with failure of the track rather than rolling components of the train. However, there were contact marks on the wheels consistent with track discontinuity. It was considered most likely the witness marks on the wheel occurred as the west rail suffered multiple fractures near the 67 km mark under the passage of ore cars.

The ATSB considered the potential influence of the higher than normal forces on the rail recorded by the wheel impact load detector during the passage of train M03544, as well as the preceding train. The magnitude of the impact forces, were not considered sufficient to initiate derailment but may have contributed to rapid failure of a weakened section of rail.

Specialist analysis of the recovered rail found that the fracture initiated at two fatigue‑related transverse defects (Figure 12), with the remainder of the fracture occurring relatively quickly due to overload associated with passage of train M03544.

Figure 12: Large fatigue crack in rail section

Figure 12: Large fatigue crack in rail section. Source: BHP Billiton

Source: BHP Billiton

Rail stress-free (neutral) temperature

The area surrounding the 67 km point had been subjected to several maintenance activities, including a few days before the derailment. The records showed that a length of rail was installed at about the 67.150 km mark when the rail temperature was about 65 °C. That, along with other activities, would most likely increase the stress-free temperature of the track in that area. An increase in stress-free temperature had the effect of shifting the effective operating envelope of track structure.

According to BHPB, the stress-free track temperature was 40 °C. This specification was based on midpoint average minimum and maximum temperatures expected for that time of year (summer). If the stress-free temperature of rail is too low, there is a higher risk of track buckling in warmer weather. Conversely, if the stress-free temperature is too high, there is a higher risk of rail breaks in cooler weather. Given the time of the derailment (about 0530) and higher stress-free temperature, it was most likely that the track temperature was lower than the stress-free temperature. This meant that the rail was most likely in a state of tensile force (that is stretched), excluding track buckle as a cause for the derailment.

Rail at a temperature 20 °C below stress-free temperature is unlikely to cause a catastrophic failure in itself. The dynamic nature of a passing loaded train (high load, high cycle) could expose a weakness in the track or rail structure under tensile stress. This weakness could lead to a rail break. A rail break allows the rail to separate, and the separation depends on how much below stress-free temperature the rail temperature is. The greater the difference between these temperatures, the greater will be the separation.

The wider the gap on the rail running surface, the more passing wheels will pound the opening. Successive wheel impacts lead to further deformation, increased running surface discontinuity, and increased risk of derailment.

The most recent rail breaks (25 July and 24 September 2015) had a recorded gap of 60 mm and 90 mm respectively, a significant discontinuity of the running surface increasing the risk of derailment.

The BHPB investigation report noted that broken rails in the recent past had not led to derailment. The following from a report authored by the Institute of Railway Technology at Monash University for BHPB is also relevant.

Straight breaks or vertical fractures, for example from a single isolated transverse defect or a defective weld, generally present a very low risk of derailment, and to the author’s knowledge, none have occurred despite a considerable increase in the incidence of broken rails since 2012.

Therefore, derailment risk is greatly increased with incorrectly stressed rail. In the event of a broken rail, the gap will widen increasing the running surface discontinuity.

Track condition

The ATSB reviewed the BHPB-commissioned specialist reports that it used to determine the findings of its investigation.

One of the BHBP reports, in discussing the scoping of track locations for re-railing, revealed that the section between 60 km and 73 km locations of the west track was in poor condition, noting that:

… extensive areas where the rail asset integrity was less than adequate (ballast condition, head height, numerous aluminothermic welds, rolling contact fatigue (RCF) developing into TD due to grinding debt[11] etc.).

According to BHPB, delays and changing priorities resulted in the section of track between 66 km and 69.5 km being deferred from the re-rail plans until April 2016.

The BHPB report concluded:

The general condition of the rail was such that failures occurred frequently and further rail failure could be expected unless the asset integrity is improved. Rail failure may lead to derailment if circumstances reinforce each other resulting in cascading failures culminating in derailment. At the time of derailment the following rail related factors resulted in a high risk of rail failure:

- the existence of a grinding debt resulting in an increased risk that RCF cracks become TD’s;

- extensive areas where the rail head height is of concern; and

- a high number of aluminothermic welds.

The rail condition, high axle loads combined with wheel impact loads exacerbate the rate of rail failure. Some “wheel impact breeding hot spots” initiate the development of high impact wheels which spread defects through the weakened rail network.

The rail failure KPI set during the FY 16 budgeting process is one failure per week. This KPI benchmarks poorly against heavy haul rail industry. The setting of a KPI at this level indicates a lack of knowledge of what best in class should or could be. A benchmarking review performed in September / October 2015 has identified this as something to be addressed and consequently the KPI is (as of February 2016) being reconsidered to drive improvements.

There is history of over reliance on aluminothermic welding with knowledge that such welds will generate more failures.

The finding and conclusions of BHPB’s reports indicated that the general condition of the rail on the west track in the vicinity of the rail fracture was poor and contributed to relatively frequent failures in that region.

Ultrasonic testing

The 1.1 m section of fractured rail found onsite (Figure 11) contained one large and two small areas of fatigue cracking. Initially, BHPB assessed that the rail defect that led to the fracture was not detected during RTI’s last ultrasonic rail inspection on 29 November 2015.

However, after analysis of the RTI data, BHPB concluded that a large transverse defect was detectable but not identified by the individual operator conducting the inspection. That conclusion was disputed by RTI on the basis that BHPB had misinterpreted the ultrasonic signature of a weld in that location as being that of a transverse defect.

The ATSB reviewed RTI ultrasonic recordings from the 29 November inspection (RTI replayed the data via proprietary software and captured the information in a video file). The ATSB viewed the video file 50 m on either side of the IRJ at the 67 km mark (see Figure 8). Approaching the area of interest (in the direction of travel in Figure 8), ultrasonic signatures were evident about 5 m from the IRJ. No other significant signatures were identified.

The ATSB also reviewed previous ultrasonic recordings for the same location on 15 and 25 November and compared them with those of 29 November. No ultrasonic indication was recorded on 15 November and a small indication was recorded on 25 November (Figure 13). Ultrasonic indications from the nearby IRJ at the 67 km mark where also compared for those three dates and found to be largely consistent. The consistency of the IRJ ultrasonic signatures supported a conclusion that the signals for the rail position shown in Figure 13 were indicative of a developing rail defect.

Figure 13: Ultrasonic indications
(left – 15 November, centre – 25 November, right29 November)

Figure 13: Ultrasonic indications 
(left – 15 November, centre – 25 November, right – 29 November). Source: Rail Technology International

Source: Rail Technology International

Specialist reports commissioned by BHPB, and authored by NTS Ultrasonics and Aben Technical Services, also assessed the variations in signatures at that location across the three dates in November 2015. Those reports both supported a conclusion that the signals were indicative of a developing transverse defect, with the NTS Ultrasonics report stating that:

…From these data traces it seems that the transverse defect has grown very quickly between 25/11 and 29/11.

Based on signal variations, the NTS report also stated that the accuracy of some of the data across these three runs may have been affected by ultrasonic probe positioning and calibration issues. Neither of these reports discussed differences between ultrasonic signatures associated with welds compared to transverse rail defects. The Aben report did however discuss interpretation of the 29 November 2015 signature as follows:

The indication as seen on 29-11-2015 run bears a marked resemblance to the end of rail head indications as seen in the IRJs... A large vertical TD [transverse defect] is geometrically very similar to the rail end in an IRJ, and the lack of any indications from areas below the head of the rail once again points to a head only discontinuity.

Based on a review of the ultrasonic data in the area of the rail failure, and all of the available specialist reviews, the ATSB concluded that the developing defect transverse defect was probably detectable.

Finally, the NTS Ultrasonics report, in discussing factors that can adversely affect the identification of defects, stated:

… Rail flaw detection is one of those occupations where the operator must be fully alert all the time, not unlike air traffic control and other high attention occupations. In some circumstances operators can be distracted from monitoring the system, and sometimes overloaded with data from the system. As highlighted in the Aben report, when a lot of data is coming in (from many closely spaced welds, for example), the operator may feel under pressure to move through the data quickly and perhaps not giving each data set the attention it warrants. Misclassification is a possibility, and the successful performance of these systems must depend on the experience of the operators.

Crossing train control area boundaries requires radio contact with track controllers, and this may be distracting. Apparently the 67 km mark is close to such a boundary.

Ultrasonic testing of the tracks was conducted during hours most likely when the rail temperature was higher than the stress‑free temperature of 40 °C. Rails at a higher temperature are subjected to compressive forces. These compressive forces may mask certain rail defects, such as transverse cracks. It was noted by staff onsite that the grind markings were on the rail head. Data from the most recent RTI inspection did not appear to be affected by the grind markings on the rail head.

The RTI report (in response to the initial BHPB report) commented that since the start of 2015, RTI had reported 247 transverse defects in parent rail and 131 transverse defects in welds.

The specialist report authored by NTS Ultrasonics stated:

The advantages of testing rail at night when the track is cooler (lower thermal stresses) was established many years ago on the Mt Newman line, but the practice was dropped for non-technical reasons.

Consideration should be given to reintroducing this practice.

In its recommendations, the BHPB derailment investigation report stated that:

BHPBIO should obtain clarification from RTI on how the following factors affect detection of rail defects including details on mitigating controls that address the variability of these factors:

- Calibration of equipment;

- Rail stresses;

- Probe contact;

- Gain settings;

- Rail crown conditions including wear and foreign contamination like oils;

- Noise filtering;

- Rail profile; and

- Track geometry.

The following from the NTS report is relevant to the limitations of ultrasonic testing:

To a large extent, the basic principles of ultrasonic rail flaw detection were established by the mid-1980s and have not changed much since. The use of digital technology has made data presentations, data storage, and instrument control better, but the underlying ultrasonic technology has barely changed in over 30 years. Other inspection technologies such as eddy current and ACFM have seen recent development for rail, but are not complete inspection technologies. Perhaps a review of the current “state of the art” in rail flaw detection could recommend useful combinations of technology to be considered for future inspection contracts as well as setting useful directions for research and development. It is possible that rail flaw detection will develop in useful ways if the end users of the services are more pro-active in asking for reasonable improvements and helping provide the resources to make it happen.

__________

  1. Insufficient profile grinding of the rail head to ensure the removal of rolling contact fatigue cracks.

Safety issues and actions

The safety issue identified during this investigation is listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

The initial public version of these safety issues and actions are repeated separately on the ATSB website to facilitate monitoring by interested parties. Where relevant the safety issues and actions will be updated on the ATSB website as information comes to hand.

Rail condition

The general condition of the rail on the west track, in the vicinity of the rail fracture, contributed to relatively frequent failures in that area.

Safety Issue: RO-2015-023-SI-01

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2015-023
Occurrence date 03/12/2015
Location near Walla
State Western Australia
Report release date 12/10/2018
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Derailment
Occurrence class Serious Incident
Highest injury level None

Train details

Train operator BHP Billiton Iron Ore
Train number M03544
Type of operation Freight
Departure point Yandi, WA
Destination Port Hedland, WA
Train damage Substantial