Near-collision and operational event involving Beech Aircraft Corp. B200, VH-OWN and VH-LQR, Mount Hotham, Victoria, on 3 September 2015

Final report

What happened

On 3 September 2015, several multi-engine turboprop aircraft converged on the airspace above Mount Hotham Airport, Victoria, as part of a multi-day charter involving several operators. While conducting a number of area navigation (RNAV) Global Navigation Satellite System (GNSS) approaches, the pilot of a participating Beech Aircraft Corp B200 (King Air) aircraft, registered VH‑OWN, descended the aircraft below the minimum altitude and exceeded the tracking tolerance of the approach after experiencing GPS/autopilot difficulties. The pilot twice climbed the aircraft without following the prescribed missed approach procedure and manoeuvred in the Mount Hotham area. During this manoeuvring, the aircraft came into close proximity to another King Air, registered VH‑LQR, which had commenced the same approach. Both aircraft were in instrument meteorological conditions and unable to sight each other. Significant manoeuvring was also observed as VH‑OWN was on final approach to the Mount Hotham runway. All aircraft landed safely at Mount Hotham without injury to passengers or crew.

What the ATSB found

Difficulties in operating the GPS/autopilot resulted in the pilot of VH‑OWN experiencing an unexpected reduction in the level of supporting flight automation, and a significant increase in workload, while attempting to conduct RNAV (GNSS) approaches into Mount Hotham Airport. This increased workload affected both the pilot’s ability to follow established tracks such as the published approach and missed approach, and his ability to communicate his position accurately to other aircraft and the air traffic controller.

Although radar coverage in the area was limited, there were opportunities for the air traffic controller to identify when VH‑OWN was having tracking difficulties during all three approaches, and when VH‑OWN tracked towards the expected position of VH‑LQR. However, this position information was not effectively communicated, resulting in a missed opportunity to prevent a potential controlled flight into terrain and/or collision with VH‑LQR.

What's been done as a result

The pilot of VH‑OWN underwent flight testing by both a delegate of the Civil Aviation Safety Authority (CASA), and by a flying operations inspector employed by CASA, who recommended remedial training. Independent of this investigation, in February 2017 it became mandatory for all aircraft operating under instrument flight rules to be fitted with Automatic Dependence Surveillance – Broadcast, further increasing surveillance capability nationally, including in the Mount Hotham area.

Additionally, and independent of this investigation, the Department of Defence radar system, capable of surveillance in the Mount Hotham area, is scheduled for upgrade in late 2018. The radar system upgrade is likely to enhance the national air traffic system through the increased compatibility between that radar and the Airservices Australia surveillance system.

Safety message

Maintaining the pilot skill of operating an aircraft without the use of automation is essential in providing redundancy should the available automation be unexpectedly reduced. Additionally, as the responsibility for separation from other airspace users and terrain in Class G airspace lies with aircrew, it is imperative that pilots maintain the skills to navigate accurately, and interpret and utilise traffic information to maintain safe separation. From an air traffic control perspective, the occurrence highlights the safety benefit of communicating any apparent tracking anomalies and/or conflicts to the involved pilots.

Mount Hotham runway

Mount Hotham runway Source: Mount Hotham Airport and Resort

Source: Mount Hotham Airport and Resort

Context

Mount Hotham Airport

Mount Hotham Airport (Mount Hotham) is a certified aerodrome equipped with a sealed east-west runway, a passenger terminal and an aircraft parking apron adjacent to the runway. Located in the Victorian Alps at an elevation of approximately 4,300 ft above mean sea level, it is the highest certified aerodrome in Australia and is surrounded by mountainous terrain. The airport is not equipped with a control tower or air traffic control facilities and does not have ground-based navigation aids.[6] Approaches during weather conditions below those required for visual flight utilise a single area navigation (RNAV) Global Navigation Satellite System (GNSS) approach aligned with runway 29. The airport operator was a certified meteorological observer and weather observations were available on request, however many routine meteorological services associated with larger certified aerodromes were not available.

Airspace and air traffic services

The airspace above Mount Hotham is designated as Class G (uncontrolled) from the surface to Flight Level 180. In Class G airspace, pilots are responsible for separation from other airspace users and from terrain (see the section titled Traffic separation and collision avoidance in Class G).

To assist pilots to organise their own separation from other airspace users, some airports have been allocated a Common Traffic Advisory Frequency (CTAF). Pilots broadcast their position and intentions on the CTAF, enabling other pilots to identify them as a possible conflict and to manage their separation accordingly. Additionally, IFR aircraft in Class G airspace are provided with a traffic information service by an Airservices Australia (Airservices) air traffic controller (controller) about conflicting IFR and observed visual flight rules aircraft. The traffic information is based on pilot reports and, where coverage exists, air traffic service (ATS) surveillance data. The obligation to provide the traffic information ceases when the pilot reports changing to the CTAF.

To the south of Mount Hotham is East Sale airspace,[7] which falls under the jurisdiction of Department of Defence (Defence) controllers. Due to the location of Mount Hotham and the surrounding terrain, radar coverage of the area from Airservices equipment was limited to about 6,000 ft above mean sea level to the south and on the approach to Mount Hotham and to about 10,000 ft to the north of the airport. Defence radar coverage, however, was available above about 5,000 ft. At the time, Airservices did integrate some of the data from the East Sale radar, but due to an incompatibility between the systems, Defence radar data for the area to the north of Mount Hotham was not incorporated into the Airservices system.

The Civil Aviation Safety Authority (CASA) mandated the fitment and use of Automatic Dependant Surveillance Broadcast (ADS-B)[8] for all IFR flights in Australia from early 2017. At the time of this occurrence, however, the aircraft involved were not fitted with ADS-B, nor was it required.

The provision of a traffic information service is limited by the information available to the controller and the means available to pass that information to pilots. As each aircraft tracked towards Mount Hotham, the responsible controller provided a traffic information service in relation to aircraft in the vicinity. The controller also updated aircraft already in the vicinity of Mount Hotham of further aircraft entering that airspace. Once the aircraft began manoeuvring below 10,000 ft in the vicinity of Mount Hotham, including when conducting the approach, the controller could not always see them on their surveillance display. As such, a continuous surveillance service was not possible. None of the involved aircraft reported switching to the CTAF, resulting in radio communications occurring on both the CTAF and area frequencies. Additionally, as they were all operating under the IFR, there was still an obligation for the controller to provide a traffic information service.

The Airservices surveillance system incorporates a number of warnings and alerts to assist in the provision of an ATS. One of these, the Short Term Conflict Alert (STCA), provides advance warning to a controller that aircraft may be in conflict within the next 90 seconds. To operate, the STCA requires surveillance data on the aircraft involved. As there was limited surveillance data of the developing proximity event to the north of Mount Hotham, the STCA did not activate. In the event of a STCA activation, controllers are only able to provide an alert on the area radio frequency, not the CTAF

Pilots are assisted with separation from terrain around some airports in Class G airspace by the design of instrument approaches that include a minimum safe altitude in the vicinity of the airport. The instrument approach chart for Mount Hotham, the RNAV (GNSS) approach to runway 29, has a commencement height of not below 7,700 ft which is also the minimum safe altitude within 25 NM (46 km) of the Airport. The chart also notes that the Airport is 4,260 ft above mean sea level and displays a number of obstacles in the vicinity. These include a 4,200 ft obstacle to the north, and two obstacles to the west at 4,460 ft and 5,450 ft. Descent below 7,700 ft in the vicinity of Mount Hotham when not established on the RNAV (GNSS) approach reduces the safety margin for aircraft operating in instrument meteorological conditions.

Traffic separation and collision avoidance in Class G

The accurate provision and interpretation of traffic information is essential to enable pilots to separate their aircraft from other airspace users in Class G airspace. This allows pilots to accurately assess and respond to another aircraft’s position relative to their aircraft. During times of restricted visibility in uncontrolled airspace, aircraft separation is achieved by pilots broadcasting their position information and listening for and interpreting the position reports of other pilots. Additionally, as discussed above, a traffic information service is provided to the pilots of IFR flights and is also available on request to pilots of VFR aircraft, subject to controller workload. The timeliness and accuracy of traffic information broadcasts, including accurate position information and pilot intentions, is therefore pivotal in assuring adequate separation.

Prescribed traffic patterns such as air routes, mandatory approach and missed approach tracks and holding patterns also assist pilots in describing and interpreting an aircraft’s position relative to that traffic pattern (e.g. the aircraft is on the outbound leg of the holding pattern). It is mandatory for pilots flying in instrument metrological conditions to track via the prescribed missed approach procedure when aborting an approach in Class G airspace, unless a higher emergency exists.

Airspace risk management

The airspace above Mount Hotham Airport is classified as Class G from ground level to FL180. Above that sits Class E airspace from FL180 to FL245. The Australian Airspace Policy Statement (AAPS), published on 13 July 2015 and pursuant under the Airspace Act 2007, provides guidance to CASA on the administration of airspace. As stated previously, Class G airspace permits both IFR and VFR aircraft and they both receive a flight information service which includes directed traffic information to IFR flights on other IFR flights and known VFR flights. Class E airspace permits IFR and VFR flights however, IFR flights are provided with an ATC service and are separated from other IFR flights and receive traffic information on VFR flights as far as is practicable. VFR flights are provided with a flight information service, which includes traffic information, as far as is practicable.

The AAPS also determines when changes to airspace classification may be required in the airspace immediately around an aerodrome. Criteria on the annual passenger transport operations aircraft movements, the annual number of passengers and total annual aircraft movements must be met before a determination on the level of change can be made. The criteria numbers for Mount Hotham were substantially lower than what is required and as such Class G has been deemed as an appropriate classification.

The AAPS did not preclude CASA from examining the requirement for airspace changes should CASA consider such examination was required, for example, on risk or safety grounds.

Under the Airspace Regulations 2007, CASA is responsible for ensuring that the airspace architecture is appropriate for users and administrators and this is achieved through a review programme. The programme is cyclic and aims to review the entire Australian airspace architecture every 5 years.

At the time of this incident there had been no recent review of the airspace in the vicinity of the Mount Hotham Airport. However, an airspace review was completed in December 2011 on the airspace sectors that encompassed Mount Hotham Airport. The collision probability at numerous aerodromes within the review area was ascertained and utilised the CASA Office of Airspace Regulation Airspace Risk Model. Using that model, the risk was assessed as 3.38 x 10-6 for Mount Hotham. An airspace assessment for the entire area was also estimated at 1.39 x 10-4, which equated to about one collision every 7,200 years per airport.

The findings/conclusions for the review found that, based on analysis of data and received feedback, the airspace classification and hence air traffic services for those airspaces, within the review area were suitable.

Aircraft equipment

In addition to other flight guidance instruments, VH‑OWN (OWN) was equipped with a single certified GPS capable of conducting IFR enroute navigation and non-precision approach procedures.[9] The installation consisted of the Garmin GPS 155 receiver display unit (RDU), an external antenna, an annunciation control unit and the horizontal situation indicator (HSI).[10] The RDU received and processed signals from up to 12 GPS satellites to determine the aircraft’s position, altitude and time. Software within the unit provided information to the pilot for navigating the aircraft through a series of earth-referenced waypoints. The RDU, horizontal situation indicator and annunciator control unit were located on the instrument panel (Figure 5).

Figure 5: Cockpit instrument layout of VH‑OWN

Figure 5: Cockpit instrument layout of VH‑OWN. Source: Civil Aviation Safety Authority

The image depicts the aircraft on the ground with no power to the systems, and the insert of the expanded GPS annunciator panel is representative of the one installed in the aircraft. Source: ATSB
Receiver display unit and horizontal situation indicator

The navigation information was presented on the RDU in various user-selectable forms on a liquid crystal display. This information included groundspeed, aircraft track, distance, bearing and time to the next waypoint, and a graphical course deviation indicator (CDI). Selection of navigation data and presentation of the navigation information was controlled by the pilot using function keys and rotary knobs on the face of the unit. The display also presented various messages regarding the navigation mode and operational status of the receiver.

The pilot’s HSI could present course deviation indications based on information derived from the GPS receiver. When GPS was selected for display on the HSI, the CDI reflected the same graphical CDI displayed on the RDU.

Waypoint coordinates for RNAV (GNSS) non-precision approaches were stored in a navigation database on a data card, similar to a computer flash memory card. The data card was inserted into the RDU, and the data card waypoint coordinates could not be edited by the pilot. Jeppesen[11] provided an updated database for the GPS receiver every 28 days.

Annunciator control unit

The annunciation control unit was a combined annunciation and switching unit that allowed the pilot to:

  • select the navigation source between GPS or ground-based VHF navigation aids for presentation on the HSI (controlled by the GPS NAV button and annunciated by the GPS or NAV indicator),
  • manually ‘arm’ and ‘disarm’ a non-precision approach (controlled by the GPS APP button and annunciated by the ARM or ACTV indicator),
  • pause the automatic sequencing of waypoints (controlled by the GPS SEQ button and annunciated by the HOLD or AUTO indicator) (Figure 5).

The GPS manufacturer’s pilot guide described the use of the annunciator control panel when conducting a RNAV (GNSS) approach. Included in this guidance in order for the automatic waypoint sequencing to occur required:

  • the GPS SEQ button set to AUTO
  • the HSI set to the desired final course
  • the final approach waypoint as the active waypoint.

The guide required that when the SEQ switch is selected to HOLD and the HSI course is required to be adjusted, the HSI course must be set at least 2 seconds prior to returning the SEQ switch to AUTO. Releasing the SEQ switch from HOLD prior to setting the HSI course would result in the GPS capturing the present HSI setting as the desired course and/or may not give the autopilot sufficient time to react to any required heading change.

RNAV (GNSS) approach design

A landing approach to a runway can be conducted visually in visual meteorological conditions (VMC) and/or by using navigational instruments. However, in weather conditions below that determined for VMC (termed instrument meteorological conditions or IMC), pilots must conduct an instrument approach (Figure 1).

RNAV (GNSS) approaches are a type of non-precision instrument approach used by pilots to position an aircraft close to a runway with the intention to land. They provide pilots with lateral and longitudinal guidance based on a series of waypoints. These waypoints are published latitude and longitude positions in space with no associated ground navigational aid, and are pre-programmed into a GPS receiver in the aircraft.

There is generally more than one choice for the first waypoint (the initial approach fix or IAF), giving pilots a choice of direction to enter the approach, for example, from the south, east, or north, for a final runway approach from the east. As such, there are up to three waypoints published for the initial approach fix. The fifth and only unique letter of the initial approach fix is, for example, either A, B or C. The final four waypoints have the standard fifth letter of I (for intermediate fix or IF), F (for final approach fix or FAF), M (for missed approach point or MAPt) and H (for holding point beyond the runway for when a missed approach is conducted). A MAPt is also published, and is generally 500 m before the runway threshold, however in the case of Mount Hotham, it is 1.6 NM (3 km) from the runway threshold to allow for a steep initial climb requirement to avoid terrain in the event of a missed approach.

During the approach, the RDU in the cockpit displays how far the aircraft is away from the next waypoint in the approach sequence. From that information, pilots must determine what altitude they should be at based on published altitudes given in the approach chart. There is no vertical guidance generated by the RDU.

Conducting an RNAV (GNSS) approach

To operate an RNAV (GNSS) approach, a pilot must first select a pre-programmed approach in the aircraft’s RDU, selecting one of the three initial approach fixes (IAF). Once the approach is selected, the RDU will provide navigation guidance to the IAF and will automatically arm the approach within 30 NM (56 km) of the aerodrome. A course deviation indicator on the RDU and a cockpit HSI displays navigation error to the pilots. Approaching the IAF, the HSI will become more sensitive, making a steady transition from the 5 NM (9 km) to the 1 NM (1.8 km) scale either side of the desired track (Figure 6).

Once the aircraft has passed the IAF, the RDU will display the estimated distance and estimated time to travel to the IF. The desired track between the IAF and IF is shown on the RDU, matching the track shown on the approach chart. The approach chart also shows the desired altitude, or vertical profile, between these waypoints and the sector minimum safe altitude between these waypoints.

Once past the IF, the waypoint indicator displayed on the RDU changes to the FAF, and the estimated distance and time to the FAF is shown on the RDU. From 2 NM (3.7 km) from the FAF, the CDI scale will gradually change from 1 NM (1.8 km) either side of the track to 0.3 NM (600 m) by the time the FAF is reached so the pilot can more accurately track to the runway.

Figure 6: Generic RNAV (GNSS) approach

Figure 6: Generic RNAV (GNSS) approach. Source: Civil Aviation Safety Authority

Source: ATSB

As the aircraft approaches the FAF, the same process occurs as for approaching the IF, except the pilot must normally start the descent. Some approaches start the descent before the IF but this is not the case for Mount Hotham. To maintain the appropriate constant angle approach path, the pilot can use the altitude profile in the altitude/distance table on the approach chart for guidance.

Passing the FAF, the RDU waypoint distance changes again, with the distance displayed being referenced to the MAPt. Again, reference altitudes from the approach chart need to be compared with the distance displayed on the RDU to maintain the appropriate descent profile.

Receiver autonomous integrity monitoring

Receiver autonomous integrity monitoring (RAIM) is a technology developed to assess the integrity of GPS signals in a GPS receiver system. It is of special importance in safety-critical GPS applications, such as in aviation or marine navigation. Recorded RAIM data was examined for the period encompassing the occurrence and the representative integrity value was considerably better than that required for the conduct of the RNAV (GNSS) approach. Further to this, other aircraft conducting the approach with similar equipment reported no difficulties or RAIM alerts.

__________

  1. Ground-based navigation aids involve ground stations which transmit radio signals capable of being received by aircraft equipment for the use establishing aircraft position in relation to the transmitter.
  2. East Sale airspace: The airspace under the jurisdiction of the Defence controllers became active during the sequence of events. The Airservices controller liaised with their Defence counterpart to obtain clearances for all the aircraft in the Mount Hotham airspace to transit Defence airspace in the event of a missed approach.
  3. Automatic Dependant Surveillance – Broadcast (ADS-B): a system in which electronic equipment on-board an aircraft automatically broadcasts the precise location of the aircraft via a digital data link. The data can be used by other aircraft and air traffic control to show the aircraft’s position and altitude on display screens without the need for radar. An ADSB system can use the GPS and/or on-board systems to determine an aircraft position. A suitable transmitter then broadcasts that position at rapid intervals, along with identity, altitude, velocity and other data. Dedicated ADS-B grounds stations receive the broadcasts and relay the information to air traffic control for precise tracking of the aircraft.
  4. Non-precision approaches provide the pilot with lateral and/or longitudinal guidance during the approach and the pilot was responsible for maintaining a minimum predetermined height until passing a specific waypoint.
  5. Horizontal situation indicator (HSI): A flight instrument used by pilots to determine aircraft heading and positional/angular deviation from a selected radio navigation track or GPSderived track.
  6. Jeppesen is a division of the Boeing Company that provides products and services pertaining to navigation information and data bases in the support of civilian and military aviation.

Findings

From the evidence available, the following findings are made regarding the near-collision between two Beech Aircraft Corp B200 King Air aircraft, registered VH‑OWN and VH‑LQR, and other operational events involving VH‑OWN in the vicinity of Mount Hotham Airport, Victoria, on 3 September 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Contributing factors

  • Due to difficulties with the operation of the GPS and coupled autopilot, VH‑OWN did not turn at the intermediate fix to intercept the final approach course. As these difficulties were not corrected by the pilot, the aircraft deviated outside of the tracking tolerances of the approach, while descending below the lowest safe altitude during each of the multiple approach attempts.
  • Due to high workload and difficulties with the operation of GPS/autopilot system, the pilot of VH‑OWN did not broadcast accurate position reports, resulting in reduced separation, and a near-collision, with VH‑LQR.
  • The pilot’s ability to follow established tracks and accurately communicate the aircraft’s position was likely adversely affected by experiencing a high workload, due to factors including single-pilot IFR operations while conducting an area navigation (RNAV) Global Navigation Satellite System (GNSS) approach, existing weather minimums and the reduced available flight automation.
  • Despite intermittent surveillance coverage in the area of the Mount Hotham Airport, there was sufficient radar data to identify that the pilot of VH‑OWN was having tracking difficulties and that the aircraft was tracking towards the expected position of VH‑LQR. Due possibly to a focus on higher priority tasks, this information was not communicated to the affected pilots contrary to the intent of the traffic information service they were receiving.

Other factors that increased risk

  • The pilot of VH‑OWN did not track via the prescribed missed approach and prescribed holding pattern when experiencing global positioning system (GPS)/autopilot difficulties, and did not communicate this to the air traffic controller or the other traffic in the area. This increased the risk of a collision.
  • Airservices Australia’s surveillance coverage of the Class G airspace in the area to the north of the Mount Hotham Airport was limited. This negated protections such as automated system warnings and alerts, for example Short Term Conflict Alerts to warn the air traffic controller of traffic situations that could result in collisions.

Other findings

  • After detecting inconsistencies in the position reports from the pilot of VH‑OWN, the pilot of VH‑LQR stopped his descent at 8,000 ft. As a result, the separation between the aircraft was around 300 ft, ± 150 ft, and a collision was likely avoided.

The occurrence

At about 0825 Eastern Standard Time[1] on 3 September 2015, five low‑capacity twin‑engine turboprop aircraft flew from differing originating aerodromes towards Mount Hotham Airport, Victoria, (Mount Hotham) as part of a passenger charter involving a number of different operators. As the weather on arrival at Mount Hotham was below that required for a visual approach, the aircraft needed to carry out the published area navigation (RNAV) Global Navigation Satellite System (GNSS) instrument approach (see the section titled RNAV (GNSS) approach design) in order to navigate clear of cloud before landing.

The first aircraft to arrive in the Mount Hotham area was a Beech Aircraft Corp B200 King Air (King Air), registered VH‑OWN (OWN). At about 0829, the pilot of OWN commenced the RNAV (GNSS) approach for runway 29[2] from the south via the initial approach fix (IAF) waypoint HOTEC (EC)[3] using the autopilot, but experienced tracking difficulties on reaching the intermediate fix waypoint HOTEI (EI) (Figure 1).

Radar data showed that from EC to EI, OWN descended to 7,300 ft, 400 ft below the minimum permitted safe altitude. At 0830 the aircraft did not turn to intercept the inbound approach track at EI, but instead continued tracking to the north of the prescribed approach path and continued to descend to 6,300 ft. In response to the tracking difficulties, the pilot eventually discontinued the approach.

The pilot then climbed the aircraft to the minimum safe altitude of 7,700 ft while still tracking towards the north, rather than via the prescribed missed approach track. At 0834, the pilot of OWN advised the air traffic controller (controller) that he was in the missed approach, and commenced manoeuvring in the airspace in the Mount Hotham area, as the other charter aircraft progressively arrived for the RNAV (GNSS) approach for runway 29 (Figure 2).

Due to surveillance limitations to the north of Mount Hotham, surveillance data for OWN was not available to the controller from 0832 to 0838. During that time, the aircraft tracked from the east of Mount Hotham at 6,400 ft, to a position about 4 NM (7 km) east of the airfield at 7,900 ft. At 0838, the aircraft’s position did not match the pilot’s reported tracking details, though the controller did not comment on the erroneous tracking when providing the pilot with position information.

Figure 1: Partial radar data for the first approach conducted by VH‑OWN

Figure 1: Partial radar data for the first approach conducted by VH‑OWN. VH OWN’s track overlaid on the RNAV (GNSS) approach chart for Mount Hotham. Source: Airservices Australia, annotations by the ATSB

VH‑OWN’s track overlaid on the RNAV (GNSS) approach chart for Mount Hotham. Source: Airservices Australia, annotations by the ATSB

The second aircraft, also a King Air, arrived at Mount Hotham on the same track as OWN, commencing the approach at 0841 as the pilot of OWN reported that he would track to waypoint HOTEB (EB) and hold. The pilot of that aircraft conducted the RNAV (GNSS) approach from waypoint EC and landed on runway 29 at about 0846, having become visual with the ground close to the approach minimum altitude (741 ft above the runway).

Figure 2: Partial radar data for the second approach conducted by VH‑OWN

Figure 2: Partial radar data for the second approach conducted by VH‑OWN. VH OWN’s track overlaid on the RNAV (GNSS) approach chart for Mount Hotham. Source: Airservices Australia, annotations by the ATSB

VH‑OWN’s track overlaid on the RNAV (GNSS) approach chart for Mount Hotham. Source: Airservices Australia, annotations by the ATSB

Shortly after the pilot of OWN reported tracking for EB, the pilot of another aircraft tracking for Mount Hotham advised him on the area radio frequency that they were trying to talk to him on the Common Traffic Advisory Frequency (CTAF) (see the section titled Airspace and air traffic services).[4] The CTAF at Mount Hotham was not recorded, nor was it monitored by air traffic control.

The third aircraft to commence the approach was another King Air, registered VH‑LQR (LQR). On receiving advice from the pilot of OWN on the CTAF that he was to the west of Mount Hotham (see the section titled Traffic separation and collision avoidance in Class G), the pilot of LQR tracked inbound from the north-east on descent to 7,700 ft to commence the approach at the IAF HOTEA (EA). It was reported that subsequent broadcasts from the pilot of OWN on the CTAF indicated that the pilot was unsure of his position. Consequently, the pilot of LQR stopped descent at 8,000 ft while still to the north of EA.

At 0848, the controller attempted to contact the pilot of OWN and, when not successful, advised the pilot of LQR that OWN was going to conduct an approach in front of LQR. This information was surmised by the controller from the observed track of OWN. The pilot of LQR advised the controller that he believed the pilot of OWN was ‘on the approach’ but he was unable to contact him. Shortly afterwards, the pilot of LQR advised the controller that OWN was ‘turning inbound at EB for the approach’. However, surveillance data showed that, at that time, OWN was just to the south of EI at 7,700 ft tracking in a north-easterly direction.

From 0849, when LQR was about 18 NM (33 km) north of EA at flight level (FL) 141[5] to 0854 when the aircraft was about 1 NM (2 km) north of EA at 8,200 ft, surveillance data for LQR was not available to the controller. Surveillance data remained available for OWN during that period that showed the aircraft tracked to the east of EI and towards EA at 7,700 ft.

Figure 3: Radar data showing the near-collision between VH‑OWN and VH‑LQR

Figure 3: Radar data showing the near-collision between VH‑OWN and VH‑LQR. Department of Defence radar data showing the near-collision between VH OWN and VH LQR. This information was not available to the Airservices Australia air traffic controller. Source: Department of Defence, annotations by the ATSB. The image depicts the aircraft on the ground with no power to the systems, and the insert of the expanded GPS annunciator panel is representative of the one installed in the aircraft. Source: ATSB

Department of Defence radar data showing the near-collision between VH‑OWN and VH‑LQR. This information was not available to the Airservices Australia air traffic controller. Source: Department of Defence, annotations by the ATSB

Although not available on the controller’s surveillance display, data from the Department of Defence radar to the south of Mount Hotham at East Sale, Victoria, showed that OWN passed 300 ft below LQR, just north of EA at 0853 (Figure 3).

The pilot of OWN then attempted another approach (Figure 4) and experienced similar tracking difficulties. Radar data shows that the pilot again continued to descend to the north of the RNAV (GNSS) approach track to 5,800 ft, with the pilot later stating that he became visual and clear of cloud during the descent. The aircraft was then observed to carry out significant manoeuvring close to the ground while establishing the aircraft on short final to the runway before landing at about 0918.

All the involved aircraft were equipped with at least two independent communication radios, enabling the pilots to remain on the controller’s area frequency while also communicating with those in the other aircraft on the CTAF. During this time, none of the pilots reported transferring to the CTAF, and a number of pilots continued to make position reports to the controller, and to request updates on the location of other aircraft in the area, as well as advising tracking details.

Figure 4: Partial radar data for the third approach conducted by VH‑OWN overlaid on the RNAV (GNSS) approach chart for Mount Hotham.

Figure 4: Partial radar data for the third approach conducted by VH‑OWN overlaid on the RNAV (GNSS) approach chart for Mount Hotham. VH OWN’s track overlaid on the RNAV (GNSS) approach chart for Mount Hotham. Source: Airservices Australia, annotations by the ATSB

VH‑OWN’s track overlaid on the RNAV (GNSS) approach chart for Mount Hotham. Source: Airservices Australia, annotations by the ATSB

The following day, the pilot of OWN, along with a Civil Aviation Safety Authority (CASA)‑approved testing officer, conducted a test flight in OWN which included a practice area navigation RNAV (GNSS) approach in daylight visual meteorological conditions. While the aircraft reportedly did demonstrate a minor tracking anomaly when approaching the final approach fix, this did not replicate the situation of the previous day. Further opportunity to test-fly the aircraft and/or the GPS was hampered when the pilot of OWN destroyed the GPS removable data card before the ATSB had commenced an investigation, making it impossible to replicate the conditions of the occurrence flight. This action was taken after the pilot was reportedly told the data card was likely corrupted.

The pilot of OWN voluntarily suspended RNAV (GNSS) operations until he could undergo independent flight testing by CASA. This testing by CASA then resulted in a recommendation that the pilot complete remedial training before undergoing a further flight test. Following the second flight test, the pilot was deemed proficient and competent to resume operations. At no time during the two test flights were any anomalies with the GPS and/or autopilot recorded by either the occurrence pilot or the CASA-approved testing officers. CASA, however, advised that no formal testing of the aircraft or its equipment was conducted during those two flights beyond observation of functionality.

__________

  1. Eastern Standard Time (EST) was Coordinated Universal Time (UTC) + 10 hours.
  2. Runway number: the number represents the magnetic heading of the runway.
  3. There are generally five waypoints in Australian RNAV (GNSS) approaches. These waypoints usually have five alphanumeric characters which in Australia always consist of five letters. The first four letters of each waypoint remain the same within an approach, and represent the three letter aerodrome identifier (e.g. HOT for Mount Hotham), and the direction from which the aircraft has travelled during the final approach (e.g. in this approach E for east). Only the fifth letter in the waypoint name varies to identify which waypoint the aircraft is approaching.
  4. The Common Traffic Advisory Frequency (CTAF): A designated frequency on which pilots make positional broadcasts when operating in the vicinity of a non-controlled aerodrome.
  5. Flight level: At altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 141 equates to 14,100 ft

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • Beech Aircraft Corp B200 Pilot Operating Manual
  • Garmin TSO 155XL GPS Pilot Guide
  • Civil Aviation Safety Authority Manual of Standards Part 139
  • Aeronautical Information Publication Australia
  • Airservices Australia
  • Department of Defence
  • pilots of VH‑OWN, VH‑LQR and the other aircraft operating in the Mount Hotham area
  • Mount Hotham Airport operator.

References

ATSB (2006) Perceived Pilot Workload and Perceived Safety of RNAV (GNSS) Approaches. (20050342). Australian Transport Safety Bureau, Canberra.

Dismukes, R.K., Berman, B.A., and Loukopoulos, L.D., (2007). The Limits of Expertise, Rethinking Pilot Error and the Causes of Airline Accidents. Ashgate, UK.

Burian, B.K., (2007) Very light jets in the national airspace system. In Proceedings of the 14th International Symposium on Aviation Psychology. Wright State University, Ohio.

Burian, B.K., Pruchnicki, S., Rogers, J., Christopher, B., Williams, K., Silverman, E., Drechsler, G., Mead, A., Hackworth, C., Runnels, B., (2013) Single-Pilot Workload Management in Entry-Level Jets. Study: 09-AJP61FGI-0048. Federal Aviation Administration & NASA Ames Research Centre, USA.

Green, R.G., Muir, H., James, M., Gradwell, D., Green, R.L., (1996) Human Factors for Pilots. Second Edition. Ashgate, UK.

Harris D., (2011) Human Performance on the Flight Deck. Ashgate, UK.

Orlady, H.W., and Orlady, L.M., (1999) Human Factors in Multi-Crew Flight Operations. Ashgate, UK.

Parasuraman, R., and Riley, V., (1997) Humans and Automation: Use, Misuse, Disuse, Abuse. Human Factors, June 1997 39(2), 230-253.

Wickens, C.D., Hollands, J.G., Banbury, S., Parasuraman, R., (2016) Engineering Psychology and Human Performance. Fourth Edition. Routledge, UK.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to a next of kin representative of the pilot of VH‑OWN, the pilot of VH‑LQR, Airservices Australia, the Department of Defence and the Civil Aviation Safety Authority.

Submissions were received from the Civil Aviation Safety Authority, Airservices Australia and the Department of Defence. The submissions were reviewed and, where considered appropriate, the text of the report was amended accordingly.

Safety analysis

Introduction

While attempting to make an approach and landing to Mount Hotham Airport (Mount Hotham) in instrument meteorological conditions, the pilot of VH‑OWN (OWN) experienced difficulty in remaining within tracking tolerances of the prescribed approach and did not follow the missed approach. Consequently, the pilot continued descending when outside of the approach tracking tolerances, and did not follow the prescribed missed approach when finally aborting the approach attempts. This, combined with inaccurate position broadcasts by the pilot of OWN to other aircraft in the area, nearly led to a collision with VH‑LQR (LQR) as that aircraft commenced the approach from the north‑east. During another final approach attempt, and after exiting the cloud layer, the pilot of OWN was observed carrying out significant manoeuvring at low altitude, north of the published approach path in order to line up with the runway and land at Mount Hotham.

The analysis will examine the following:

  • any global positioning system (GPS)/autopilot idiosyncrasies that resulted in an unexpected reduction to the level of automation available to the pilot of OWN
  • the effects of increased workload on the pilot’s ability to carry out the approach and provide accurate position reporting
  • the provision of a traffic information service
  • limitations in surveillance coverage and their effect on the ability of the air traffic controller (controller) to provide traffic information and/or traffic alerts in the Mount Hotham area.

Operation of the GPS/autopilot during the approach

The ATSB re-creation of the flight using Airservices Australia (Airservices) and Department of Defence (Defence) radar data showed that on the attempted approaches, OWN did not make the left turn onto the final course at the intermediate fix waypoint HOTEI (EI), and failed to intercept the desired final approach course of 291°. Instead, the aircraft maintained the approximate previous course of 001° used to track from the initial approach fix waypoint HOTEC (EC). This sustained course resulted in the aircraft exceeding the tracking tolerances of the approach and descending below the minimum safe altitude.

During interview, the pilot of OWN stated that in order to reduce workload, he always used the autopilot’s coupling function when conducting area navigation (RNAV) Global Navigation Satellite System (GNSS) approaches. This function automatically varied the aircraft’s heading to intercept and maintain the desired course. The pilot also stated that on approaching the intermediate fix waypoint EI, he received an alert from the GPS to indicate it was time to adjust the course deviation to the final approach course, and this was carried out with the autopilot coupled to the GPS track, and the GPS SEQ control switch continuously in AUTO.

Post-occurrence testing of the GPS/autopilot was hampered by the destruction of the GPS receiver’s removable data card, which stored pertinent waypoint and tracking data for various approaches. This, combined with the absence of a flight data recorder, cockpit voice recorder and further recall from the pilot, limited the opportunity to diagnose or attempt to replicate the occurrence conditions further. Flight testing carried out post occurrence by three separate Civil Aviation Safety Authority (CASA) testing officers in the aircraft did not see a repeat of the reported occurrence scenario.

The recall of events described by the pilot during initial interviews and follow-up questions did not coincide with recorded data from Airservices and Defence, or from other pilots in the area during the occurrence. Several hypotheses were tested regarding the operation of the GPS SEQ control switch and/or the direct-to functions of the GPS/autopilot system, and with statements obtained from other operators that used the same equipment. While some characteristics of the tracking difficulties during the occurrence could only be partially replicated, the investigation determined it was probable that the pilot of OWN experienced difficulties in tracking the final approach course, from the intermediate fix, when using the GPS coupled to the autopilot. Pilot recognition and response to these difficulties is discussed below.

Effects of workload on performance

Single-pilot flight under instrument flight rules, the conduct of the Mount Hotham RNAV (GNSS) approach in poor weather, and dealing with a high level of traffic outside controlled airspace are known to be highly demanding tasks. A combination of these tasks could elevate workload to the point that it adversely effects performance.

Workload has been defined by Orlady & Orlady (1999) as ‘reflecting the interaction between a specific individual and the demands imposed by a particular task. Workload represents the cost incurred by the human operator in achieving a particular level of performance.’ Each individual has a finite set of mental resources which allow them to process information and identify appropriate tasks.

High workload is known to lead to an increased error rate, and has the effect of reducing overall productivity (Harris, 2011). When the workload gets too high for the available set of resources, an individual will start to task shed, initially systematically and eventually randomly as the workload continues to increase. This leads to an overall degradation in performance (Green et al., 1996). Dismukes, Berman & Loukopoulos (2007) identify that this might occur by a pilot moving from a proactive assessment of a situation, commonly referred to in aviation as ‘being ahead of the aircraft’, to a reactive situation, where a pilot responds to events as they occur, without an overall strategy to manage the situation.

Automation is designed to support the human and reduce the mental capacity requirements on the pilot when in use, but cannot eliminate high workload situations from occurring altogether. Even with automation to assist, a pilot’s mental capacity may be reduced to the point that errors in navigation and flight control can still occur (Burian et al., 2013). A common effect of avionics issues in single-pilot, high performance aircraft is a deviation from the planned flight path (Burian, 2007). From this, it is likely that the deviation of flight path from the prescribed missed approach, and subsequent tracking difficulties, was an expected outcome of a high workload following on from the avionics issue.

Additionally, it is known that a reliance on a source of automation (in this case the ability of the aircraft to follow a programmed track with a reduced requirement for pilot input) may lead a pilot to insufficiently monitor the inputs into an automated system in order to reach effective decisions should the automation malfunction (Parasuraman & Riley, 1997). The outcome of doing this may be ’more severe when the automation failures are infrequent, occur for the first time in the operator’s experience and/or occurred after long periods of error-free performance’ (Wickens et al., 2016).

Further to this, the ATSB (2006) had previously surveyed 748 pilots on their experiences and perceptions of RNAV (GNSS) approaches. The survey results showed that, for pilots of category A and B aircraft (such as OWN), the RNAV (GNSS) approach was one of the highest workload approaches in terms of mental workload, physical workload and time pressure. Furthermore, in this study, Mount Hotham was ranked as the most difficult RNAV (GNSS) approach in Australia in terms of number of identified responses per 1,000 commercial movements. Circumstances known to increase the difficulty of an RNAV (GNSS) approach identified as present in this occurrence, include:

  • single-pilot operation of a multi-engine aircraft under instrument flight rules
  • operating in instrument meteorological conditions with cloud base close to the approach minimum altitude
  • unexpected reduction in the level of available automation
  • realigning the aircraft after aborting the approach
  • a high level of traffic in the vicinity of the airport
  • operating outside controlled airspace
  • Common Traffic Advisory Frequency (CTAF) and area frequency radio requirements
  • use of older or unfamiliar GPS equipment.

The pilot appeared to effectively manage the enroute task demands of the flight and descent into instrument meteorological conditions, up until the point on approach where the aircraft did not turn onto the expected inbound track at EI. From this position and for the rest of the flight, the pilot of OWN identified and reported his workload as ‘high’. The pilot’s desire to climb the aircraft clear of cloud, and his focus on attempting to restore a high level of automation (instead of reverting to hand flying without automation) could be indicative of wanting to lower the workload to a manageable level. At the same time, tracking tolerances for the approach were exceeded, the prescribed missed approach track was not followed, and inaccurate position reports were transmitted by the pilot. The investigation concluded that the pilot’s workload had elevated to a level that affected his ability to follow established tracks and accurately communicate his position to the air traffic controller and the other aircraft in the area.

Deviation from the prescribed missed approach

The regulations pertaining to the conduct of instrument approaches state that a pilot must follow the missed approach procedure specified for the instrument approach flown. For the Mount Hotham RNAV (GNSS), the prescribed missed approach required that, while on climb to the lowest safe altitude of 7,700 ft, aircraft should track towards the missed approach point before conducting a left-hand turn towards the holding waypoint HOTEH (EH), 8.7 NM (16 km) south of the runway.

The pilot of OWN reported to the Airservices’ controller being in the missed approach with the intention of then tracking to the holding waypoint EH. However, Defence radar data and later statements from the pilot of OWN to the ATSB indicated that at no time did the aircraft track via the prescribed missed approach. Instead, after descending to 6,300 ft to the north, OWN climbed in a northerly direction before turning back to the west, then south to bisect the initial and final tracks of the approach.

Due to limited surveillance data for the area, the controller was unable to determine that the pilot’s report of being in the missed approach was incorrect. The controller’s advice to the other traffic inbound for Mount Hotham that OWN was conducting the missed approach was based on the pilot’s report. As that report was erroneous, a false expectations of OWN’s position and intentions was created for the other aircraft in the vicinity, and for the controller.

Given the importance of accurate position reporting in supporting collision avoidance in Class G airspace, the inaccurate position and intention broadcast made by the pilot of OWN increased the risk of collision for other aircraft in the Mount Hotham area.

Provision of a traffic information service

The pilots of OWN and LQR were both operating under instrument flight rules and, as they did not report changing to the CTAF, they were monitoring both the area frequency as well as the CTAF. Consequently, the controller was required to continue to provide both pilots with a traffic information service. Consistent with that controller obligation, at different times, both pilots requested, and were provided with, traffic information and, when available, radar‑derived position information.

The Airservices’ surveillance data was limited in the final phase of approaches into Mount Hotham Airport. However, there were a number of opportunities for the controller to detect the inaccurate position and incorrect tracking reports made by the pilot of OWN:

  • the aircraft’s continued tracking in a north‑westerly direction after passing over the waypoint HOTEI (EI) while continuing to descend
  • re-acquisition of the aircraft by radar to the east of Mount Hotham 4 minutes after the pilot had reported established in the missed approach, which would have taken the aircraft to the west then south of Mount Hotham
  • Despite advising the intention to track towards waypoint HOTEB (EB), the aircraft instead tracked close to EI and then turned towards waypoint HOTEA (EA).

These were all opportunities to query the pilot on the aircraft’s track and the pilot’s intentions. Additionally, even though the actual position for LQR was not displayed to the controller between 0849 and 0854, the controller was aware that the pilot of that aircraft was tracking for EA, on descent to 7,700 ft to commence the approach. There was therefore the opportunity to identify the reducing separation between OWN and LQR.

Due to the size of the area under the controller’s jurisdiction, the scale of the surveillance display being used by the controller and a possible focus on higher priority tasks may have restricted their ability to detect the inaccurate tracking and position reports by the pilot of OWN. Further to this, the controller would not have been aware that the pilot was in instrument meteorological conditions, nor would the controller be aware of any position reports the pilot of OWN was making on the CTAF. Additionally, system warning and alerting functions designed to assist the controller in providing a service, such as the Short-Term Conflict Alert (STCA), were also impeded by the limitations of the surveillance coverage.

The provision of traffic information and alerts by controllers, however, are supplemental to the pilot’s responsibility to ensure separation from other airspace uses and terrain in Class G airspace. Additionally, CASA’s review of the airspace and level of air traffic service in the Mount Hotham area concluded that they were both suitable.

Positive pilot reaction to inconsistent position reports

The pilot of LQR stated that while tracking inbound to waypoint EA and on descent to 7,700 ft, he heard inconsistent position reports from the pilot of OWN on the CTAF. Initially the pilot of LQR believed that OWN was to the west of Mount Hotham and therefore not a traffic conflict. When the pilot of OWN corrected his position to being to the east of Mount Hotham, the pilot of LQR became concerned that there was a potential for a traffic conflict. The pilot of LQR then stopped descent at 8,000 ft and confirmed that both aircraft were using the same barometric setting on their respective altimeters. The pilot of LQR stated that this was not considered a suitable level of separation, but a last line of defence given the sudden threat of traffic conflict that he was presented with.

In uncontrolled airspace, it is a requirement to maintain a minimum of 1,000 ft vertical separation from other aircraft operating in close proximity under instrument meteorological conditions. In accordance with these regulations, for an altimeter to be usable in instrument meteorological conditions it must demonstrate an accuracy of ± 75 ft, but typically errors are, in reality, much smaller. Assuming the maximum allowable error existed in both aircraft, any discrepancy between the altimeters was limited to less than ± 150 ft.

Had the pilot of LQR not reacted to the inconsistent position reports by levelling off before reaching 7,700 ft, the proximity of the two aircraft would have been reduced from a vertical separation of 300 ft, ± 150 ft, to less than ± 150 ft.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-108
Occurrence date 03/09/2015
Location Mount Hotham Airport
State Victoria
Report release date 27/06/2018
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Near collision
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Beech Aircraft Corp
Model B200
Registration VH-OWN
Serial number BB-936
Aircraft operator Corporate and Leisure Aviation
Sector Turboprop
Operation type Charter
Departure point Essendon, Vic.
Destination Mount Hotham, Vic.
Damage Nil

Aircraft details

Manufacturer Beech Aircraft Corp
Model B200
Registration VH-LQR
Serial number BB-1054
Aircraft operator Altitude Aviation
Sector Turboprop
Operation type Charter
Damage Nil

Unreliable airspeed indication and stall warning involving an Airbus A320, VH‑FNP, near Perth, Western Australia, on 12 September 2015

Final report

Safety summary

What happened

On 12 September 2015, when a Virgin Australia Regional Airlines Airbus A320 aircraft, registered VH-FNP, was passing through about 8,500 ft on departure from Perth Airport, Western Australia, the autothrust and autopilot disconnected, and multiple alerts were generated. The flight crew continued the climb to an altitude of 20,000 ft, where they levelled out to troubleshoot the issues before returning to Perth. During the approach, when the flight crew were aligning the aircraft with the instrument landing system, they received a stall warning. The warning stopped after six seconds and the approach continued for a successful landing.

What the ATSB found

The ATSB found that blocked drain holes in the pitot probes prevented water from being effectively discharged, resulting in erroneous airspeed measurements in all three systems at various times during the take-off and climb. The erroneous airspeeds were not detected by the flight crew, but had been detected by the system, resulting in the autothrust and autopilot disconnecting, and the generation of multiple alerts, including a NAV ADR DISAGREE alert. That alert required the flight crew to crosscheck the three airspeed indications and the result would indicate if they had an airspeed or angle of attack disagreement. Due to the limited space in the alert message area, the NAV ADR DISAGREE alert was initially pushed off the screen by engine related alerts that were programmed to have a higher priority.

The engine related alerts did not require immediate actions by the flight crew, and because of their high-workload, the flight crew did not clear them and action the NAV ADR DISAGREE procedure until after the airspeeds had corrected themselves, and all displayed the same value. This led the flight crew to diagnose it as an angle of attack disagreement, which the procedure informed them, had the ‘risk of undue stall warning’. When they received the stall warning during the approach, the flight crew considered it spurious and disregarded that warning. However, there was nothing wrong with the angle of attack and the warning was real.

The ATSB also found that the NAV ADR DISAGREE alert and the associated procedure in the Airbus A320 may lead the flight crew to incorrectly identify the source of the alert (for example, angle of attack instead of airspeed) when there is a short-term disagreement in the airspeeds.

What's been done as a result

The aircraft manufacturer is in the process of updating the aircraft’s software so that the NAV ADR DISAGREE alert has a higher priority than the associated engine alerts. In the case of multiple alerts, it will take precedence over the other associated alerts and be immediately visible to the flight crew. In addition, the ‘risk of undue stall warning message’ will be removed from the aircraft status related to the NAV ADR DISAGREE alert.

Safety message

Modern aircraft with multiple interacting systems can have many layers between the source information and the flight crew. In such systems, where there is erroneous information from an information source, it is important that alerts and procedures be designed to ensure that the flight crew can correctly diagnose the source of the erroneous information. This is particularly important when the information may be erroneous for a short period.

Airbus A320, VH-FNP

ao-2015-107_final.jpg

Source: ATSB

Context

Meteorological information

The ATSB obtained weather information for Perth from several sources, including the Bureau of Meteorology (BoM) and the flight crew. The meteorological aerodrome report (METAR) noted the weather conditions at Perth Airport shortly before pushback at 0630 (Table 1).

Table 1: Perth Airport meteorological conditions at 0630

Wind5 kt from 260°
Visibility10 km, or greater
RainLight rain in showers
Cloud[28]

Few at 1,200 ft

Scattered at 3,000 ft

Broken at 4,500 ft

QNH[29]1013 HPa

 

There was also a TEMPO[30] present at the time, which indicated that winds could increase to gusts of 35 kt, visibility decrease to 3,000 m in showers with moderate rain, with scattered cloud down to 300 ft and broken cloud down to 800 ft.

The METAR for 0700 showed that there were no significant changes in the weather. The TEMPO was still active.

The weather radar for Perth showed that there were localised showers moving across the region. Figure 5 shows the rain showers in the area at 0650, the time that VH-FNP took off from Perth Airport. The showers were moving from the west towards the east.

Figure 5: Perth weather radar image at 0650 (2250 UTC)

Figure 5: Perth weather radar image at 0650 (2250 UTC)

The red arrow indicates the location of Perth Airport and the dashed red rectangle indicates the area presented with the flight path in Figure 6. Source: Bureau of Meteorology, annotated by the ATSB

The flightpath taken by VH-FNP was superimposed over the region highlighted by the dashed red rectangle in the radar, as shown above in Figure 5 (Figure 6).

Figure 6: Overlay of flight path on a zoomed in section of the weather radar image taken at 0650 (2250 UTC), where the region corresponds to the dashed red rectangle in Figure 5

Figure 6: Overlay of flight path on a zoomed in section of the weather radar image taken at 0650 (2250 UTC), where the region corresponds to the dashed red rectangle in Figure 5

Note: The green flight path indicates when the autopilot was engaged, orange when the autopilot was not engaged. Source: Bureau of Meteorology, annotated by the ATSB

The captain reported that on the evening before the flight, he had been awoken by heavy rain and that it was a ‘wintery morning’ when driving to the airport. The METAR confirmed that there had been 11.4 mm of rain since 0900, on the previous day.

The BoM climate summary for September 2015 showed that Perth Airport received rain on 1, 5, 6, 11, and 12 September 2015. The incident day (12 September) being the wettest day of the month. No rain was recorded at weather stations near Boolgeeda in September 2015.

ATSB observation:
The flight crew reported that the aircraft was in instrument meteorological conditions (IMC)[31] during the climb, and about 10 seconds before the autothrust disconnected, the cockpit voice recorder (CVR) captured the flight crew discussing showers when delaying their turn to the north. Given the flight crew’s reports and the proximity of the flight path to the rain on the weather radar, it was likely that VH-FNP passed through, or along the edges of, a rain cell before the autothrust and autopilot disconnected.

Aircraft information

VH-FNP is an Airbus A320-231 twin-turbine engine low-wing commercial transport aircraft, manufactured in France in 1993.

Skywest Airlines first registered the aircraft in Australia in April 2010 before Virgin Australia Regional Airlines (VARA) purchased Skywest Airlines. Skywest and VARA had primarily operated VH-FNP on charter flights from Perth to remote mining operations in Western Australia; however, more recently had increased its use on regular public transport operations. The occurrence flight was a mining charter flight that was part on an established ongoing contract.

Electronic instrument system

The A320’s electronic instrument system (EIS) presents data to the flight crew regarding the aircraft and its environment. It consists of the electronic flight instrument system (EFIS) and electronic centralised aircraft monitoring (ECAM) system (Figure 7, EFIS component highlighted in blue and ECAM components highlighted in yellow). The EFIS displays mostly flight parameters and navigation data on the primary flight displays (PFDs) and navigation displays (NDs). The ECAM presents data on the engine and warning display (E/WD) and system display (SD). Control and switching panels for the EFIS and ECAM are located on the glareshield and centre console. Master warning and caution lights are located on the glareshield to draw the flight crew’s attention to important messages on the ECAM.

Figure 7: Location of the EIS components in the A320 cockpit

Figure 7: Location of the EIS components in the A320 cockpit

Source: ATSB

The PFD presents flight environment information, such as airspeed, attitude and altitude, and some navigation information, such as heading and instrument landing system, to the flight crew. It also includes some flight mode information, such as autopilot and autothrust status (Figure 8).

Figure 8: Primary flight display – information zones (left) and presentation (right)

Figure 8: Primary flight display – information zones (left) and presentation (right)

The presentation is an example only and does not contain information from the event flight.Source: Airbus (left) and ATSB (right)

The ECAM is an integrated system that presents data monitored by the aircraft on the engine and warning display and system display pages in the centre of the instrument panel. The displays are divided into dedicated areas to display the following information as shown in Figure 9.

  • primary engine indications, fuel quantity, flap and slat position
  • warning and caution alerts, or memos
  • synoptic diagrams of aircraft systems and status messages
  • pertinent flight data (air temperature and gross weight).

Figure 9: ECAM displays – engine/warning display (upper) and system display (lower)

Figure 9: ECAM displays – engine/warning display (upper) and system display (lower)

Source: ATSB

The lower part of the E/WD is dedicated to ECAM warning and caution messages. The left section presents the specific warning messages and the right section lists the affected systems, secondary failures, memos or special notices (such as ’LAND ASAP’). When the flight warning computer (FWC) detects a failure, and if there is no flight phase inhibition active, the title of the warning is displayed followed by the associated procedures (actions and information).

The ECAM message area is limited in size and can display a maximum of seven lines. If there are too many messages, or the procedure extends beyond the bottom of the display, a green ‘overflow’ arrow appears at the bottom of the message area, as shown in Figure 2. The flight crew can scroll down to view the additional messages.

Airbus divides each flight into 10 distinct phases (Figure 10). To prevent distracting the flight crew during high-workload phases, and to prevent unnecessary warnings, the FWC inhibits some warnings from being presented on the ECAM during particular phases.

Figure 10: Airbus flight phases

Figure 10: Airbus flight phases

Source: Airbus and ATSB

The ECAM display uses a colour code to indicate the importance of the failure or the indication, providing the flight crew with an immediate indication of the urgency to take remedial actions (Table 2).

Table 2: ECAM colour coding

ColourImportance
RedThe configuration or failure requires immediate action.
AmberThe flight crew should be aware of the configuration or failure, but need not take immediate action.
GreenThe item is operating normally.
WhiteProvides guidance while various procedures are executed.
BlueActions to be carried out, or limitations.
MagentaMessage applies to particular pieces of equipment or situations.

 

ECAM alerts (warnings and cautions) are further divided into three levels, indicating its importance, with level 1 being the lowest and level 3 being the most critical. Depending upon the level, the message is presented on the ECAM as either a red warning, or amber caution, with an associated aural alert and illumination of a master warning or caution light on the instrument panel glareshield (Table 3).

Table 3: ECAM alert level descriptions

LevelDescriptionAural alertVisual alert
3

Red warning:

Immediate action required, due to:

aircraft is in a dangerous configuration, or limit flight condition (for example, stall)

system failure altering the flight safety (for example, engine fire).

Continuous repetitive chime, specific sound or synthetic voice

Flashing red ‘Master Warning’ light.

Red warning message on E/WD.

Automatic call of the relevant system page on the SD.

2

Amber caution:

The flight crew should be aware of the configuration or failure, but does not need to take immediate action. However, it was intended that time and situation permitting; these cautions should be considered without delay to prevent any further degradation of the affected system.

These are for system failures without any direct consequence on the flight safety (For example, green hydraulic system pressure low).

Single chime

Steady amber ‘Master Caution’ light.

Amber caution message on E/WD.

Automatic call of the relevant system page on the SD.

1

Amber caution:

Requires crew monitoring.

These are for system failures leading to a loss of redundancy or system degradation.

NoneAmber caution message on E/WD. Generally without procedure.

When there are multiple ECAM messages, the order in which they are presented is dictated by the alert level. Level 3 has priority over level 2, which has priority over level 1. For alerts of the same level, Airbus has assigned a priority based upon factors decided during design. Airbus advised the ATSB that for A320 aircraft, amber alerts for engine-related failures have a higher priority than amber alerts for navigation and air data failures.

The ECAM’s system display (SD) can display 12 system pages, including engine, bleed air, electrical, hydraulic, and flight control systems. The flight crew, using the ECAM control panel, may manually select each page, or the system may automatically display a page. System pages are automatically displayed when a system failure triggers a caution or warning message, or to advise the flight crew that a relevant parameter has drifted outside of its normal range. If there are no overriding system page priorities, particular pages are also automatically displayed as the flight phase’s default page. For example, the ENGINE page will be displayed for phases 3, 4, and 5 (take‑off phases).

Additionally, during phase 2, when the WHEEL page is the default page, moving either sidestick by more than 3° in pitch or roll, or when the rudder pedal is deflected by more than 22°, the system page will automatically change to the flight control (F/CTL) page. This will only occur during phase 2, as it is associated with a control check.

Park brake

The A320 park brake applies hydraulic pressure to the aircraft brakes. This can be applied at any time, but should only be used on the ground. To prevent the aircraft from landing with the park brake on, the aircraft’s flight warning computer will generate a level 2 amber PARK BRAKE ON alert when the park brake is on during flight. The system inhibits the warning for flight phases 1 to 5 and 8 to 10, all ground phases, so should only activate when the aircraft is airborne.

Auto flight

The aircraft’s auto flight system is centred on the flight management and guidance system (FMGS) and consists of two flight management and guidance computers, and two flight augmentation computers (FAC). The flight management part of the system controls: navigation and navigation radios, flight planning, performance prediction and optimisation, and display management. The flight guidance part provides autopilot, flight director and autothrust functions.

Flight crew interact with the system through two multipurpose control and display units in the centre pedestal and a flight control unit (FCU) in the centre glareshield. The FCU allows the flight crew to select and modify any flight parameters for short-term operation in selected guidance mode. The FCU also includes the autopilot and autothrust engagement controls.

The FMGS provides guidance information to either the flight director, or the autopilot. When the flight director is engaged, flight path guidance information is presented to the flight crew on the PFD. The flight crew then make control inputs to follow the flight path. When the autopilot is engaged, it will automatically make control inputs to guide the aircraft along the flight profile. The autopilot only controls the aerodynamic surface for the aircraft (elevator, aileron and rudder). Automatic engine thrust is provided by the autothrust function.

The FACs provide yaw damping and roll coordination functions through control of the rudder.

Autopilot

The aircraft has two autopilots, AP1 and AP2, which can be engaged by pressing the corresponding button on the FCU. The autopilot is disengaged by either the:

  • flight crew take an action on the flight control systems, such as pressing the takeover pushbutton on the sidestick (standard method), pushing the FCU autopilot button when engaged, or moving the sidestick control
  • engagement conditions are no longer met.

Detection of certain faults by the aircraft systems can result in the autopilot engagement conditions not being met, disengaging the autopilot.

Autopilot disengagement produces a level 3 alert, with a flashing red master warning light, red AUTO FLT AP OFF message on the ECAM, and an aural ‘cavalry charge’ alert.

Autothrust

The autothrust function connects the FMGS to the engine control system so that it can command the required thrust from the engines. When engaged, the autothrust function can provide a fixed thrust control, or airspeed control. Autothrust can operate independently, or with the autopilot.

Both the autopilot and autothrust systems can control the target airspeed, but both cannot be controlling at the same time. In managed climb and descent modes, the autothrust will hold the engine thrust, and the autopilot will control the airspeed.

The autothrust function requires at least one flight management and guidance computer, one FAC and two air data inertial reference systems to be operative. It will disconnect when the flight crew takes a particular action, such as pressing the instinctive disconnect button on the thrust levers (standard method), or pressing the A/THR button on the FCU, or automatically when the arming conditions are not met.

Autothrust disconnection produces a level 2 alert, with a master caution light, single chime and an amber AUTO FLT A/THR OFF message on the ECAM.

When the autothrust is disconnected and the thrust levers are in the climb detent, the thrust lock function will activate. Thrust lock will lock the thrust at its level prior to the disconnection and display a flashing amber message on the flight mode annunciator in the PFD. Thrust lock is disabled by moving the thrust levers out of the climb detent.

Power plants

VH-FNP was fitted with two International Aero Engines V2500 high-bypass turbofan engines. The engine is of a twin-shaft design, consisting of low-pressure (LP) and high-pressure (HP) systems on separate shafts (Figure 11). The low-pressure system consists of the fan, low-pressure compressor and turbine. Similarly, the high-pressure system consists of a high-pressure compressor and turbine.

Figure 11: V2500 engine schematic diagram

Figure 11: V2500 engine schematic diagram

Source: VARA Flight Crew Operating Manual. Additional annotation by ATSB

In normal operation, the engine thrust setting is achieved through control of the engine pressure ratio (EPR).[32] This normal mode of operation is referred to as EPR mode. To operate in EPR mode, the engine control system requires valid pressure and temperature data (P2, P5 and T2). To ensure the integrity of this data, the engine monitors the total air pressure measured by the aircraft’s air data reference (ADR) system. If the engine control system determines that either P2 or P5 are not valid, or cannot verify them against the aircraft supplied ADR data, thrust control will automatically revert to N1 mode. This will result in a level 2 amber ENG 1(2) EPR MODE FAULT alert on the ECAM.

In N1 mode, the rotational speed of the low-pressure system (N1) is controlled. N1 mode has two sub‑modes, rated N1 mode and degraded N1 mode. Reversion to rated N1 mode occurs when either P2 and/or P5 are invalid, and reversion to degraded N1 mode occurs when T2 or the ambient pressure parameters are not valid. Autothrust is not available when in N1 mode.

When in EPR mode, rated N1 mode can be manually selected through the ENG N1 MODE push-button switches on the overhead panel. After an automatic reversion to rated N1 mode, pressing the button confirms the mode.

In the case where the engine core speed drops below the idle speed, with the master switch on, the ECAM will present a level 2 amber ENG 1(2) FAIL alert. However, this warning is inhibited during flight phases 1 and 10 (engine start and after engine shutdown).

Air data reference system

The air data reference (ADR) system[33] senses air temperature, static and total air pressure, and angle of attack information. It then converts them to useable data, such as computed airspeed and altitude, for supply to other aircraft systems, including the FMGS, flight warning computers, flight control system, and engine control system.

The ADR system consists of three independent systems: one for the captain (ADR 1), one for the first officer (ADR 2) and a standby system (ADR 3). Air data is collected from the external airflow via 14 external probes and ports mounted on the forward fuselage (Figure 12).

Figure 12: Air data reference system external probe locations

Figure 12: Air data reference system external probe locations

Source: Airbus

Sensors connected to these probes convert the external air conditions to electronic signals, which are then sent to the three air data inertial reference units (ADIRUs) (Figure 13). The ADIRUs then convert these signals to useable system data. The standby system also supplies static and total (pitot) air pressure to direct reading analogue airspeed and altitude indicators on the instrument panel.

Figure 13: Air data reference system schematic

Figure 13: Air data reference system schematic

ADM = air data module (the sensor that converts air pressure to an electric signal). Source: Airbus

In the normal configuration, the captain’s PFD presents information from ADIRU 1, the first officer’s from ADIRU 2. However, in case of an ADIRU 1 or 2 failure, ADIRU 3 data can be directed to either the captain’s or first officer’s PFD, as required, using the EFIS switching in the centre pedestal (Figure 7 and Figure 14).

Figure 14: EFIS switching panel. Air data source switch highlighted by yellow box

Figure 14: EFIS switching panel. Air data source switch highlighted by yellow box

Source: ATSB

All of the external probes and ports are heated to prevent the accumulation of ice, which could degrade their accuracy. The captain’s, first officer’s and standby systems are controlled and monitored by three independent probe heat computers.

The probes are automatically heated when at least one engine is running, or when the aircraft is in flight. They can also be manually operated through a pushbutton in the cockpit. When on the ground, the pitot and total air temperature probes operate at a low level and automatically change to normal power when airborne.

If a fault is detected in any of the ADR systems, a level 2 alert is raised, activating the master caution and presenting an amber NAV ADR 1(2)(3) FAULT message on the ECAM. A FAULT light on the applicable ADR pushbutton switch on the overhead panel is also illuminated to indicate which system is affected.

If one ADR has been detected as being faulty, or has been rejected by the flight control computers, and there is an airspeed or angle of attack disagreement between the remaining two ADRs, then a level 2 alert is raised. This activates the master caution and presents an amber NAV ADR DISAGREE message on the ECAM.

Pitot probe details

The pitot probes collect the total air pressure, which is a combination of the static (ambient) air pressure and the pressure increase due to moving air being brought to a standstill. The difference between the measured total and static air pressure is the component due to the velocity alone, and as such is used to calculate the airspeed.

The pitot probe is a tube with a forward facing opening mounted on the side of the fuselage (Figure 15). To ensure it has clean air, the opening of the probe is held away from the fuselage. To prevent water from blocking the probe, two small drain holes are drilled into the lower side of the probe.

Figure 15: Pitot probe

Figure 15: Pitot probe

Source: ATSB

Flight control system

General

The Airbus A320 has a digital fly-by-wire control system. Manual control inputs made by the pilots on the sidesticks, or autopilot computer commands, are interpreted by the flight control computers and converted to control surface movements. Seven flight control computers, including the two FACs, control the aircraft’s elevators for pitch control, ailerons and spoilers for roll control, and rudder for yaw control. Signals from these computers are sent directly to the associated control surfaces and to the EIS for presentation of pertinent information.

To prevent damage to the vertical stabiliser, the FACs include a rudder travel limit function. This function reduces the maximum rudder travel deflection at high airspeeds. In the case of a loss of the rudder travel limit system in the clean configuration,[34] the rudder deflection limit is held at the last value. When the slats are extended, the FACs automatically set the rudder deflection limit at the low-speed setting (maximum authorised deflection).

If one FAC is unable to provide rudder travel limit function, a level 1 alert is activated. The master caution is not activated, but an amber RUD TRV LIM 1(2) message is presented on the ECAM. If both FACs are unable to provide the rudder travel limit function, a level 2 alert is activated. This activates the master caution and presents an amber RUD TRV LIM SYS message on the ECAM.

Control laws

The A320 flight control system operates according to three sets of control laws:

  • normal law
  • alternate law
  • direct law.

As the name suggests, normal law is the control law used in normal operation. Under normal law,[35] sidestick inputs command a load factor, which the flight control computers convert to the appropriate elevator deflections. Normal law includes the following flight envelope protections:

  • load factor limitation
  • pitch attitude protection
  • high angle of attack protection, limiting the angle of attack, preventing the aircraft from stalling
  • high speed protection
  • bank angle protection.

The FACs calculate a speed corresponding to the limit angle of attack, which presented to the flight crew on the airspeed indicators as a minimum speed warning area. The FACs also calculate the minimum and maximum limit speeds, manoeuvring speeds and speed trend. These speeds are included in a set of speeds referred to as ‘characteristic speeds’ presented to the flight crew on their PFDs.

To function in normal law, the flight control computers require valid air data from the ADRs. The computers monitor all three ADR systems to assess the validity of the air data parameters. If the value of a parameter from one ADR differs from the others, the flight control system will discard the non-consistent value and use the other two.[36] However, if all values are different the system cannot determine the correct value and cannot ensure the functions of normal law. In this case, the system will reconfigure the control laws to alternate law, depending on the data it can validate.[37] Reversion to direct law will occur at landing gear extension.

When in alternate law, the control laws are predominantly the same as normal law, but the level of flight envelope protection is reduced. The flight control system has two levels of alternate law, with or without reduced protections.

  • Alternate law with reduced protections - provides load factor limitation, low‑speed stability, and high-speed stability. There are no pitch or roll attitude protections and the high angle of attack protections are replaced with a stall warning.
  • Alternate law without reduced protections - loses all flight envelope protections, except for load factor limitation. High angle of attack protection is replaced by a stall warning.[38]

For both levels of alternate law, a calculated stall warning speed is presented on the PFD airspeed indicator, replacing the high angle of attack protection speeds.

The type of failure, or the nature of the particular system that failed, dictates which alternate law is used. For example, when the system detects a computed airspeed disagreement, the system reconfigures to alternate law without reduced protections. However, when an angle of attack disagreement is detected, the system will reconfigure to alternate law with reduced protections.

The flight crew is alerted to the reconfiguration to alternate law by the activation of the master caution, presentation of an amber F/CTL ALTN LAW message on the ECAM, and amber ‘x’ symbols replace the green normal envelope protection symbols on the PFD.

Certain other system failures, such as failure of all three inertial reference systems, result in the flight control system reconfiguring to direct law. When in direct law, there is a direct stick-to-elevator and stick-to-roll-control-surface relationship, and the rudders are directly controlled by the rudder pedals through a mechanical interconnect. Automatic elevator and rudder trimming is lost and manual trim must be used. All flight envelope protections are lost except for the stall and overspeed warnings.

When the system reconfigures to direct law, the flight crew is alerted in the same manner as for reconfiguration to alternate law, except the ECAM message is F/CTL DIRECT LAW, it is indicated on the PFD and the flight control page on the system display is automatically displayed.

Centralised fault display system

The electronic systems in the A320 all contain built-in test equipment (BITE), which monitors and identifies any faults within the system. The BITE from all the aircraft’s electronic systems are monitored and recorded by the centralised fault display system (CFDS). The CFDS classifies faults into three classes:

  • Class 1 being those indicated to the flight crew by means of the ECAM, or other flight deck effect.
  • Class 2 being faults indicated to maintenance personnel by the CFDS and trigger a maintenance alert in the ECAM status page.
  • Class 3 are faults indicated to maintenance personnel through the CFDS, but do not trigger a maintenance alert.

Fault messages recorded by the CFDS can be accessed by the flight crew and maintenance personnel through the multipurpose control and display units that form part of the FMGS. The CFDS collates the fault messages into a number of reports. One such report, the post-flight report (PFR), can be accessed at the completion of a flight.[39] The PFR presents a list of the ECAM alerts and failure messages that occurred during the previous flight. The list includes the time, flight phase, ATA number[40] and description of the ECAM and failure messages. The list of failure messages also identifies the source of the failure message.

The order in which the ECAM warning messages are presented on the PFR is the order in which the CFDS received the alerts, and does not necessarily indicate the order in which they were presented to the flight crew on the ECAM.

Reports can be sent to a printer installed in the centre pedestal.

Maintenance personnel can also directly access the BITE of each electronic system through the CFDS. The information from the BITE is used for troubleshooting failures, and is referred to as troubleshooting data.

Maintenance information

Post-flight troubleshooting

Following the incident, the operator’s maintenance personnel downloaded the PFR, troubleshooting data and flight data recorder from the aircraft. Copies of that data were sent to the aircraft manufacturer and the ATSB. The aircraft manufacturer used the data to assist the operator identify the source of the faults and return the aircraft to service. The manufacturer also used that data to perform a detailed analysis of the flight to determine the sequence of events and assess the aircraft system behaviour. A summary of their analysis is presented later in the report in the section titled Manufacturer’s analysis.

The PFR included 23 ECAM warnings and 15 failure messages (Figure 16). Those messages primarily related to the engine control, flight control, auto flight and navigation systems.

Figure 16: Post-flight report from VH-FNP

Figure 16: Post-flight report from VH-FNP

Note: The time used by the CFDS is UTC, identified as GMT (Greenwich Mean Time).

Source: VARA

As part of the troubleshooting, the operator performed a flush of the pitot system (probe and tube connecting probe to air data module). They also cleaned the pitot probe drain holes. Table 4 provides a summary of the results of these actions.

Table 4: Results of pitot system cleaning

Pitot systemResults
1 (captain)Water ejected during flushing. One drain hole blocked.
2 (first officer)Water ejected during flushing. One drain hole blocked.
3 (standby)Water and an object ejected during flushing. Both drain holes blocked.

The object ejected from pitot system 3 was not captured, nor was the material cleaned from the drain holes collected. There was no requirement in the maintenance instructions for any ejected material to be collected or analysed.

Troubleshooting tasks and maintenance action recommended by the manufacturer were carried out and the aircraft returned to service without further recurrence of the airspeed issues. The only anomalies identified were those associated with contamination of the pitot probes.

Pitot probe maintenance

The Airbus A320 Maintenance Planning Document included detailed routine cleaning of the pitot probes. It specified that cleaning of one out of the three pitot probes must be performed alternately on pitot 1, 2 and 3 every 6 months or 750 flight hours.

The operator reported to the ATSB that their maintenance planning system specified that the pitot probes be alternated between each probe at an interval of 4 months or 750 flight hours. This was more regular than the interval specified by the manufacturer. The last probe cleaning actions were reportedly carried out on:

  • pitot 2 (first officer) on 26 January 2015
  • pitot 3 (standby) on 17 May 2015
  • pitot 1 (captain) on 6 September 2015.

The operator also reported that they had not previously experienced any issues with contamination of pitot probes in their fleet of aircraft, which included Fokker F50 and F100, and Airbus A320 aircraft. In addition, there had not been any events recorded where the fuselage of VH-FNP near the pitot probes had been contaminated by mud or clay that would explain the contamination identified within the probes.

At the request of the ATSB, the operator performed visual inspections of the pitot probes in their A320 fleet. Those inspections, and reliability data from the operator’s fleet, did not identify any increase in contamination events that indicated a need for inspections over and above the manufacturer’s requirements.

Erratic airspeed indications – maintenance actions

On 15 July 2014, Airbus released an In-Service Information document to A320 operators regarding the maintenance actions for erratic airspeed indications.[41] The purpose for the issue of the document was listed as ‘providing operators with the list of scheduled maintenance actions that will minimize occurrence of airspeed discrepancies, as well as recommended actions to perform on aircraft whenever such an event happens.’ The background to the service information listed a number of erratic airspeed events reported to Airbus, including residual airspeed display on the PFD while the aircraft is not moving, airspeed discrepancies or fluctuations in-flight, and flight controls alternate law activation due to air data discrepancies.

Airbus noted in that information that investigations on A320 family aircraft showed that most of the airspeed discrepancy events, during take-off or approach, were the result of water contamination of the pitot probes and the pitot probe drainage holes being obstructed by external particles. It also noted that pitot probe part number C16195BA, the type fitted to VH-FNP, had an enhanced water trap and relocated drain holes to provide improved behaviour when faced with adverse weather conditions such as heavy rain.

The In-Service Information document provided troubleshooting information specifically for the case of steady residual airspeed indications while on the ground. Those actions included functional testing of the air data modules, flushing of the principal total pressure lines (pitot system), and draining and flushing of the standby system. It was also recommended that after an erratic airspeed event, that the flight control computers be reset to ensure that any latched faults are de-latched before the next flight.

Detailed examination of pitot probes

On 2 November 2015 (about seven weeks after the incident), all three pitot probes (Thales part number C16195BA, manufactured in 2007 and 2008) were removed from the aircraft and sent to the probe manufacturer for detailed examination. The probes were subjected to the manufacturer’s standard acceptance test procedure and compared to the acceptable limitations of the component maintenance manual. Two of the probes were then cut open for detailed examination of anomalies identified in the interior of the probes. Table 5 summarises the findings of the testing and examinations. Further detail of the examinations is provided in Appendix A.

Table 5: Summary of testing and examination of the pitot probes removed from FNP

Captain’s probe (pitot 1)Failed the acceptance tests due to one drain hole being blocked by an unidentified black substance (Figure 17) and internal contamination by a red clay substance, an example of which is shown in Figure 18 (left)
First officer’s probe (pitot 2)Passed the acceptance tests and found to be in acceptable condition in accordance with the component maintenance manual
Standby probe (pitot 3)Failed the acceptance tests due to internal contamination by a red clay substance, example of which is shown in Figure 18 (right)

Figure 17: Image of substance partially blocking one drain hole in the captain's pitot probe

Figure 17: Image of substance partially blocking one drain hole in the captain's pitot probe

Source: Thales

Figure 18: Examples of the red clay contamination inside the captain’s (left) and standby (right) pitot probes

Figure 18: Examples of the red clay contamination inside the captain’s (left) and standby (right) pitot probes

Source: Thales

ATSB observation:
After the incident, the pitot probes were subject to cleaning procedures followed by over 1 month of normal operational service. Thus, the findings of the examinations do not necessarily represent the condition of the tubes at the time of the occurrence.

Other than the contamination, there were no observations made by the manufacturer to indicate that the probes were not otherwise serviceable.

The source of the contamination could not be determined. The aircraft regularly operated into airports associated with iron ore mining operations in north-western Australia, where red mineral rich soils are common. However, the means or timing of ingress could not be determined.

Airworthiness directives

European Aviation Safety Agency (EASA) airworthiness directive (AD), AD 2014-0237R1, in force at the time of the incident, required the replacement of Thales part number C16195BA pitot probes, the type fitted to VH-FNP. The AD was originally issued in November 2014 and required replacement of the probes within 48 months (4 years) after the date of original issue. The background information provided in the AD noted:

Occurrences have been reported on A320 family aeroplanes of airspeed indication discrepancies while flying at high altitudes in inclement weather conditions. Investigation results indicated that A320 aeroplanes equipped with Thales Avionics Part Number (P/N) 50620-10 or P/N C16195AA pitot probes appear to have a greater susceptibility to adverse environmental conditions than aeroplanes equipped with certain other pitot probes.

Prompted by earlier occurrences, DGAC France issued AD 2001-362 to require replacement of Thales (formerly known as Sextant) P/N 50620-10 pitot probes with Thales P/N C16195AA probes.

Since that AD was issued, Thales pitot probe P/N C16195BA was designed, which improved airspeed indication behaviour in heavy rain conditions, but did not demonstrate the same level of robustness to withstand high-altitude ice crystals. Based on these findings, EASA have decided to implement replacement of the affected Thales probes as a precautionary measure to improve the safety level of the affected aeroplanes.

Consequently, EASA issued AD 2014-0237, retaining the requirements of DGAC France AD 2001-362, which was superseded, to require replacement of Thales Avionics pitot probes P/N C16195AA and P/N C16195BA.

On 9 October 2015 (about one month after this incident), AD 2014-0237R1 was superseded by EASA AD 2015-025, which reduced the compliance time from 48 months, to 24 months.

ATSB observation:
Although VH-FNP was still operating with the Thales C16195BA probes, it was within the compliance period for the AD 2014-0237. It was also within the reduced compliance time of the superseding AD.

The ATSB notes that this incident occurred at low altitude and at temperatures where the formation of ice crystals was unlikely. Thus, although the probes were scheduled for replacement due to a susceptibility to blockage, the conditions resulting in the blockage of the probes on VH-FNP were unrelated to those associated with the AD.

Operating procedures

Normal procedures

Use of pitot covers

The FCOM included supplementary procedures for adverse weather, including airports covered with volcanic ash, sand or dust. These procedures included the fitment of pitot probe covers when parked, but were presented as recommendations that operators can consider applying based on their experience and the amount of contaminant.

The operator also contained procedures for securing their aircraft on overnight stays, or for extended periods of time (greater than 3 hours). Among other items, flight crew and engineering personnel were required to, where possible, install covers on pitot and static probes.

Abnormal procedures

During operation, the procedures presented on the ECAM are the primary source of procedural information. They contain the ‘need to know’ information for flight crew to complete the procedure. Further explanatory, ‘nice to know’ information, and detailed information to assist the flight crew in obtaining a full understanding of the logic of the aircraft and pilot interfaces is provided in the FCOM.

The FCOM provides the procedure in a manner that is similar to the presentation on the ECAM, interspersed with the additional information found only in the FCOM. The information presented on the ECAM during the flight was not recorded, so the following information is from the FCOM only. Information likely presented in the ECAM is inferred by the coloured text in a format similar to the ECAM.[42]

Auto flight – autothrust off

The first ECAM alert that the flight crew received was the autothrust disconnection alert (AUTO FLT A/THR OFF). This alert is only generated on the ECAM when the disconnection is involuntary (that is, not initiated by the flight crew). There are no crew actions, and the purpose of the alert is to raise the flight crew’s awareness of the aircraft state. However, the detailed information in the FCOM notes that if the autothrust has failed, the flight crew may be able to recover it by engaging the other autopilot and re-engaging the autothrust.

Auto flight – autopilot off

When the autopilot disconnected, a red ECAM alert was generated. This is a level 3 warning, which would have replaced any lower level alerts from the top line of the ECAM. There were no specific procedures prescribed for this warning. The ECAM message was provided for crew awareness, so they could take manual control, as required.

Engine EPR mode fault

The flight crew discussions on the CVR indicated that the first ECAM message that they were aware of after the autopilot disconnected was the engine 1 EPR mode fault. The ECAM procedure required that the N1 mode be selected ON for both engines, and then the thrust be manually adjusted (Figure 19).

Figure 19: ECAM procedure – engine EPR mode fault

Figure 19: ECAM procedure – engine EPR mode fault

Source: ATSB

The FCOM noted that both engines are selected to N1 mode to ‘ease’ the thrust setting. It also noted that recovery of EPR mode on both engines may be attempted by switching off both ENG N1 MODE pushbutton switches.

Navigation – ADR disagree

After the flight crew had cleared EPR mode faults for both engines 1 and 2, they were presented with an amber NAV ADR DISAGREE alert. The ECAM procedure for this alert first required the flight crew to cross‑check [compare] the three airspeeds. If the airspeeds disagree, the procedure refers the flight crew to apply the ADR check procedure. If there is no airspeed disagreement, the flight crew are directed to an angle of attack (AOA) discrepancy (Figure 20).

Figure 20: ECAM procedure – navigation ADR disagree

Figure 20: ECAM procedure – navigation ADR disagree

Source: ATSB

Within the NAV ADR DISAGREE procedure in the FCOM, there was associated information on the flight control – alternate law procedure (Figure 21).

Figure 21: FCOM procedure – navigation ADR disagree

Figure 21: FCOM procedure – navigation ADR disagree

Source: VARA A320 FCOM

ATSB observation:
Although the FCOM provided specific procedures for how to manage an airspeed discrepancy (refer to Unreliable airspeed indication/ADR check procedure), the only information the flight crew were provided with for an angle of attack discrepancy was that there was a risk of undue stall warning.

While the angle of attack values could be viewed on the ‘alpha call up’ page on the multipurpose control and display unit, there was no reference to this feature in the procedure to confirm an angle of attack disagreement.

If the system specifically identified a fault in any of the angle of attack systems, an amber ECAM alert (NAV CAPT (F/O)(STBY) AOA FAULT) is raised. The FCOM procedure for that alert was ‘crew awareness’.

Flight control – Alternate law

The flight control alternate law (F/CTL ALTN LAW) ECAM alert did not require any crew actions; it was primarily to bring to the attention of the flight crew the status of the flight control system and the associated limitations. In particular, it included notification that the flight envelope protections were lost.

Auto flight – rudder travel limiter system

After clearing the alternate law ECAM alert, the flight crew were presented with an amber auto flight rudder travel limiter system (AUTO FLT RUD TRV LIM SYS) alert. This alert is activated when both rudder travel limiter systems are inoperative. The ECAM message contains both advisory information regarding rudder use above 160 kt and flight crew actions associated with resetting the two FACs (Figure 22).

Figure 22: ECAM procedure – Auto flight rudder travel limiter system

Figure 22: ECAM procedure – Auto flight rudder travel limiter system

Source: ATSB

The FCOM provided further information regarding additional limitations for failure of associated systems and landing with the fault. However, none of this was applicable in this case after the flight crew reset the systems during the flight.

After FAC 1 had been reset, the flight crew were presented with an auto flight rudder travel limiter 2 alert. There were no limitations or crew actions associated with this alert. This alert was likely activated when FAC 1 was reset, because rudder travel limiter system 1 was then functional, negating the conditions for the rudder travel limiter system fault message.

The FCOM noted that the alert was for crew awareness.

Stall warning and stall recovery

A procedure for stall recovery was also included in the FCOM (Figure 23). The procedure was to pitch the nose down, to reduce the angle of attack, level the wings, and smoothly increase thrust, as required as soon as any stall indication was recognised.

Figure 23: FCOM procedure – Stall recovery

Figure 23: FCOM procedure – Stall recovery

Source: VARA A320 FCOM

Windshear detection fault

The windshear detection function is part of the FACs, and depends on airspeed. When the FACs rejected all ADRs after the detection of the airspeed disagreement during descent, the windshear detection system was disabled and the fault detected by the warning system.

The windshear detection function is only provided for take-off and landing, so the system fault warning was inhibited while the flaps were retracted. As the FACs were not reset after the airspeed disagreement on descent, the windshear detection fault was present, but the flight crew were not alerted to the windshear detection fault until the first stage of flaps were deployed.

The ECAM presents an amber WINDSHEAR DET FAULT message. There are no associated flight crew actions, and the FCOM notes that it is for crew awareness.

Flight control – Direct law

The flight control direct law (F/CTL DIRECT LAW) ECAM alert did not require any crew actions; all information in both the ECAM and FCOM related to limitations associated with the change in the status of the flight control system.

Navigation – Indicated airspeed discrepancy

The ECAM included the NAV IAS DISCREPANCY amber alert, which is activated when there is a discrepancy detected between the airspeeds indicated on the captain’s and first officer’s displays. The associated procedure required the flight crew to cross check the three airspeeds and use the air data switching as required.

ATSB observation:
There was no indication in the recorded data that this alert was raised by the aircraft systems during the climb, indicating that ADR 3 (standby airspeed) was rejected before the ADR 1 and 2 resulting in the system raising the NAV ADR DISAGREE alert.

The manufacturer advised that the NAV ADR DISAGREE inhibits the NAV IAS DISCREPANCY alert. As the NAV ADR DISAGREE alert was latched until the end of the flight, a NAV IAS DISCREPANCY alert was not triggered when the flight crew identified an airspeed discrepancy between the captain’s and first officer’s airspeed displays.

Unreliable airspeed indication/ADR check procedure

The ADR check procedure referred to in the NAV ADR DISAGREE procedure was combined with the unreliable speed indication procedure. That procedure began with general information regarding sources, identification, and management of unreliable airspeed (Figure 24).

Figure 24: Unreliable airspeed indication/ADR check procedure – lead-in information

Figure 24: Unreliable airspeed indication/ADR check procedure – lead-in information

Source: VARA A320 FCOM

ATSB observation:
The number and nature of the indications of unreliable airspeed indicate that the development of a situation can be insidious and not necessarily obvious to the flight crew.

The initial actions required for an unreliable airspeed event were identified as memory items to ensure that the aircraft is in a safe flight state (Figure 25).

Figure 25: Unreliable airspeed indication – Initial actions

Figure 25: Unreliable airspeed indication – Initial actions

Source: VARA A320 FCOM

The remainder of the procedure provides information, such as pitch attitude and thrust settings that ensure that the aircraft is at a safe airspeed for the remaining phases of flight (climb, cruise, descent, and approach). It also includes troubleshooting techniques to identify the affected ADR(s). The procedure required that the affected ADR(s) be switched off to ensure that the flight control and flight guidance computers do not use erroneous, but coherent, data. In the case that all ADRs are affected, or the erroneous ADR cannot be identified, one is to be left on to ensure that stall warning remains available. Particular note is made that flight crew are to respect stall warnings.

ATSB observation:
When the autothrust and autopilot first disconnected, the captain announced that he had control and that he would fly the aircraft ‘ten degrees nose up’. Although this was consistent with the unreliable speed indication procedure when below FL 100, there was no indication from the recorded information or interviews that the captain was aware of an airspeed discrepancy and intentionally carried out that procedure. It was more likely an instinctive reaction to the loss of automation to ensure that the aircraft was in a state that the captain knew was safe.

When the captain’s airspeed deviated from the other indications during the descent, the flight crew were provided with an opportunity to identify that they were confronted with an unreliable airspeed indication event. However, their actions following this do not appear to indicate that they had made this connection.

The act of switching the air data source for the captain’s indicator from CAS 1 to CAS 3 was consistent with the NAV IAS DISCREPANCY alert, but there was no record of the alert having been triggered. Neither was it consistent with the unreliable speed indication procedure, because the crew did not switch off any of the ADRs, the aircraft was not levelled out for troubleshooting, there was no discussion regarding unreliable airspeed, and they did not respond to the stall warning that occurred after the air data source was switched to CAS 3.

Recorded information

The aircraft was fitted with a flight data recorder (FDR) and cockpit voice recorder (CVR) as required by the applicable legislation. The FDR was downloaded by the operator and the digital file sent to the ATSB. The CVR was sent to, and downloaded by the ATSB.

Flight data recorder

The FDR contained about 25 hours of flight data, which included the data from the incident flight, and 19 preceding flights. Plots of the pertinent recorded data are presented in Appendix C. The data showed that:

  • Just after starting the first (number 2) engine, the airspeed on the captain’s side increased to about 110 kt before returning to zero after about 2 minutes. During this time, the groundspeed was zero.
  • During the temporary airspeed increase after the first engine was started, the angle of attack recorded from ADR 1 (AOA 1) became valid for a short time and showed a value that was greater than 60°, a value inconsistent with a normal flight.
  • The flight phase initially changed from 4 to 8 to 9 while the airspeed was active in the first 2 minutes. It remained at phase 9 until about 0645 (22:45 UTC),[43] when the aircraft was taxiing for take-off when it reduced to phase 2.

[Note – Flight phase 2 is the flight phase immediately after engine start until the aircraft was accelerating during take-off; phase 4 is 80 kt to lift-off, phase 8 is touchdown to 80 kt, and phase 9 is from 80 kt to first engine shutdown.]

ATSB observations:
The recorded flight phase was inconsistent with the actual flight phase. This discrepancy explains the abnormal system behaviour on the ground before the flight.

The engine failure and park brake warnings are not inhibited in phases 8 and 9, so when the park brake was on during engine start, the system treated it as being incorrectly set. Also, engine 1 had not been started, so the engine speed was below the threshold to activate an engine failure warning.

In addition, the automatic control system page function is not active in phases 8 and 9, so when the captain performed the pre-flight control checks, the page did not automatically display. The timing of the ‘Extra control check’ (refer to Figure C3 in Appendix C) was such that the flight phase had returned to the correct value when that was carried out, explaining why the page automatically displayed on that occasion.

  • The master warning first occurred at the same time that the autopilot disengaged (during initial climb), flight directors disangaged, the control law changed from normal to alternate, and the speed mode changed from managed to selected (noted as ‘Multiple alerts’ in the figures).
  • During the climb, the recorded airspeed varied from 210 kt to 325 kt.
  • The aircraft was levelled out at 20,000 ft (FL 200).
  • Multiple attempts were made to re-engage the autopilot, before it engaged at 0722:50 (23:22:50 UTC). Each of the unsuccessful attempts was associated with a master warning activation.
  • There was a sharp change in the computed airspeed (CAS) at about 0742 (23:42 UTC). This was consistent with the time the flight crew identified that the captain’s airspeed was deviating and they changed to ADR 3. AOA 1 became invalid at the same time, confirming the captain’s change to ADR 3. AOA 1 remained invalid for the remainder of the flight, until CAS 3 dropped below 30 kt during landing. The autopilot was disconnected at about the same time, but given that the captain made a control input, this was likely intentional.
  • The autopilot again disengaged about 3 minutes after the captain changed to ADR 3. It was not re-engaged during the remainder of the flight.
  • The stall warning was activated at 0755:03 (23:55:03 UTC). During this time, the captain made some nose-down inputs; however, the computed airspeed remained relatively constant, varying by 1 kt, during the stall warning. The aircraft was at a roll attitude (bank angle) of about 10° when the stall warning activated, and was further increased by the captain’s sidestick input while the stall warning was active (Appendix C, Figure C6).
  • The flight control laws changed from alternate to direct during the approach, consistent with the system logic when the landing gear is extended in alternate law.
  • The aircraft landed at 0800:38 (00:00:38 UTC).
  • During the landing roll, the CAS temporarily increased from 30 kt to about 80 kt, which was inconsistent with the ground speed, which was about zero. The first officer’s (ADR 2) angle of attack remained valid during this time, indicating that ADR 2 information was being recorded.
Cockpit voice recorder

The cockpit voice recorder contained approximately 2 hours of recorded data from the incident flight. It included conversations between the flight crew, air traffic control and cabin crew, cockpit sounds and alerts and warnings. The recording was clear, and with the flight data recordings and interviews, was used to develop the sequence of events.

Manufacturer’s analysis

The aircraft manufacturer, Airbus, performed an analysis of the flight based upon the FDR data and troubleshooting data from the flight guidance computer and flight augmentation computer. A copy of their analysis was provided to the ATSB.

As part of their analysis, the manufacturer constructed a detailed sequence of events that analysed the system behaviour based upon the recorded data, a summary of which is presented in Appendix D of this report. The manufacturer also examined the engine reversion to N1 mode, modelled the airspeed evolution during key events, examined the stall warning activation, and the anomalous on-ground airspeed events.

Engine reversion to N1 mode

With the assistance of the engine manufacturer, International Aero Engines, Airbus examined the behaviour of the engines during the incident and found that both engines reverted to rated N1 mode following disagreement between the engine inlet pressure sensor (P2) and the aircraft total pressure data from ADR 1 and 2.

Airspeed estimations

The manufacturer estimated the actual airspeeds during the flight using their performance model for the aircraft. The simulation used values recorded during the flight and wind corrections were computed to match the ground speed evolution. The simulations were carried out for the key phases of flight.

Climb phase (0654:05 to 0703:05)

The simulation showed that the recorded CAS 1 deviated from the actual airspeed for a period of about 4 minutes, before returning to the actual airspeed (Figure 26). The simulation showed that CAS 1 was overestimated by up to 60 kts. The estimated and recorded values reconverged at about 0700, shortly before the aircraft was levelled out at FL 200.

Figure 26: Airspeed estimation during the climb phase (recorded – red, estimated – blue)

Figure 26: Airspeed estimation during the climb phase (recorded – red, estimated – blue)

Note: The x-axis is in seconds from 0754:05. The y-axis is airspeed in kt. Source: Airbus

Level flight at FL 200

A simulation of the flight at 0715:55, while maintaining FL 200, showed that the estimated airspeeds were consistent with the recorded computed airspeeds. CAS 1 was recorded during this phase.

Descent phase (0742:32 to 0746:32)

The simulation showed that CAS 1 deviated significantly from the actual airspeed (Figure 27). In this case, the recorded airspeed underestimated the airspeed by up to 60 kt, before the flight crew switched to ADR 3 at about 106 seconds. The correlation between the recorded and estimated airspeeds from this time onwards indicates that ADR 3 was correctly computing the airspeed.

Figure 27: Airspeed estimation during the– descent phase (recorded – red, estimated – blue)

Figure 27: Airspeed estimation during the– descent phase (recorded – red, estimated – blue)

Note: The x-axis is in seconds from 0742:32. The y-axis is airspeed in kt. Source: Airbus

Stall warning

A period of 50 seconds, incorporating the stall warning at 0755:03, was simulated (Figure 28). This showed that, at this time CAS 3, which was the airspeed referenced on the captain’s PFD, was consistent with the actual airspeed.

Figure 28: Airspeed estimation around the time of the stall warning (recorded – red, estimated – blue)

Figure 28: Airspeed estimation around the time of the stall warning (recorded – red, estimated – blue)

Note: The x-axis is in seconds from 0754:22. The y-axis is airspeed in kt. Source: Airbus

Stall warning activation analysis

The stall warning, which activated at 0755:03 and lasted for 6 seconds, was analysed by the manufacturer. At the time of the stall warning, the aircraft had a Mach number of about 0.3. At this Mach number, the angle of attack threshold to trigger a stall warning is 8°.

The only valid angle of attack recorded on the FDR from this period was that from ADR 2 (AOA 2). At the time the warning activated, AOA 2 was recorded at a value of 7.4°. However, the stall warning logic in the flight warning system only requires one of the three angle of attack values to exceed the threshold. Up until the captain changed over to ADR 3, AOA 1 and AOA 2 had been consistent, so it was most likely that the stall warning was triggered by AOA 3, which was not recorded.

When the stall warning activated, a small lateral acceleration was also recorded, indicating a wind gust from the right side. The placement of the angle of attack probe for ADR 3 is such that a lateral gust could produce a local increase in the angle of attack.[44] In this case, it was probably sufficient to go beyond the stall warning threshold, triggering the warning. Thus, the manufacturer determined that the stall warning experienced by the flight crew while intercepting the Perth runway 21 localiser was a genuine stall warning, albeit nominal.

ATSB observations:
Stall warnings are designed to activate at an angle of attack that provides some margin before the aircraft will actually stall. In this case, the angle of attack measured by one sensor was sufficient to activate the stall warning, but there was no indication that the aircraft had stalled.

In their analysis of the sequence of events (Appendix D), the manufacturer identified that the captain made nose-down control inputs while the stall warning was activated. However, the CVR captured the captain clearly verbalising that he was disregarding the stall warning. Although the nose‑down inputs occurred during the stall warning, there was no significant change in the airspeed and the bank angle was increased during the time the warning was active. Thus, it is more likely that the nose-down control inputs were required to control the desired flight path and not related to the warning.

Airspeed anomalies on the ground

The manufacturer analysed the recorded airspeed anomalies when the aircraft was on the ground, after engine start and after landing.

After engine start, the recorded CAS increased up to 110 kt, before decreasing again to below 30 kt. At the same time, AOA 1 was valid and AOA 2 was invalid, indicating that the recorded value was CAS 1.[45] The increase in CAS 1 was consistent with a temporary obstruction of the pitot probe for ADR 1 (the captain’s side). Activation of the pitot probe heating after engine start heated the air trapped inside the probe, increasing its pressure, which has the same effect as an increase in airspeed.

During the take-off roll, ADR 3 was rejected by the aircraft’s computers. This was probably due to CAS 3 deviating from CAS 1 and CAS 2 and detected by the cross-comparison of airspeeds, which is active above 80 kt.

ATSB observation:
During the take-off roll, the first officer announced passing 100 kt and the captain confirmed this speed. The interaction between the flight crew when conducting this check was captured on the CVR; however, the level of that interaction was not sufficient to determine if the flight crew checked all three airspeed indicators, or only the airspeed on their primary indicators (CAS 1 and CAS 2). As only CAS 1 was recorded by the FDR during the take-off, there was insufficient information to determine if there was an airspeed discrepancy between the standby and primary airspeed indicators when the 100 kt check was carried out by the flight crew.

After landing, below 20 kt ground speed, the recorded CAS temporarily increased to 80 kt, before it decreased to below 30 kt. AOA 2 was valid at that time, so CAS 2 was being recorded on the FDR at that time. This was also consistent with a temporary obstruction of the pitot probe for ADR 2 (the first officer’s side). Without air passing the pitot probes to cool them down, heating of the probe similarly increased the pressure inside the pitot probe, increasing the indicated airspeed.

Manufacturer’s conclusions

Based upon their analysis and the reports of water ejection from the pitot probes during post-flight maintenance, the manufacturer concluded that the fault messages and flight control system reconfigurations experienced during the flight were the result of discrepancies in the computed airspeeds, and that:

• These airspeed discrepancies were due to temporary obstructions of the pitot probes, occurring at least:

  - Before take-off on the Captain Source (ADR1)
  - During the take-off roll on the Standby source (ADR3)
  - During the climb and descent on the Captain source (ADR1)
  - During the descent on the F/O [first officer] source (ADR2)
  - After landing on the F/O source (ADR2)

They also noted that:

• During the approach, the stall warning was nominally triggered for 6s and nose-down crew actions were recorded on the sidestick (up to ~1/3 of the full forward stick).

Other occurrences

VH-FNP on 9 September 2015

A review of the previous flights contained on the FDR found that on 9 September 2015, the recorded airspeed increased up to around 250 kt while the aircraft was stationary on the ground at Boolgeeda Airport, WA.[46] This was three flights prior to the incident flight on 12 September 2015.

The operator reported that, in this case, the flight crew noticed the erroneous airspeed, and after consultation with the maintenance controller in Perth, completely powered down (engines and electrical) the aircraft. The airspeed was still indicating above 100 kt when the power was removed.

Similar to the 12 September incident, the flight phase transitioned to a post-landing phase before the aircraft had commenced the flight. However, in this case, it then started to fluctuate between 0 and 15, indicating that the aircraft no longer considered the parameter valid.

The operator reported that, after the aircraft had been reset by powering down, it operated normally for several flights prior to the incident flight. However, the FDR captured two more on ground airspeed spikes before the aircraft departed Boolgeeda on 9 September. These airspeed anomalies appear to have again resulted in changes to the flight phase, potentially effecting the logic of a number of systems.

The operator did not conduct any troubleshooting maintenance actions following this event, so it could not be confirmed if the pitot probes were contaminated. However, the system behaviour was consistent with the incident on 12 September 2015, when contamination was identified.

ATSB observation:
The event on 9 September 2015 could be considered to have been an ‘erratic airspeed’ event as defined in the Airbus In-Service Information documentation, which should probably have resulted in some maintenance actions. This would have required the flight crew to report it as an event to the operator’s maintenance personnel, which they appeared to have done during the event, but the restart of the systems appeared to correct the situation. Although the recorded data indicated that there was still an erroneous airspeed situation during the take-off, this was not identified by the flight crew and reported to maintenance. Thus, it is probable that no further maintenance actions were carried out as they considered the restart to have corrected a transient anomaly.

Other indications of airspeed anomalies on VH-FNP

A review of post-flight reports preceding the 12 September 2105 incident, found that ADR 3 had been rejected by the flight control system on three other occasions. No in-flight airspeed anomalies were reported for these flights:

  • 9 September 2105 (Boolgeeda to Perth), ADR 3 rejected during flight phase 5 (lift-off to 1,500 ft)
  • 11 September 2015 (Perth to Karratha), ADR 3 rejected during flight phase 4 (80 kt to lift-off)
  • 11 September 2015 (Karratha to Perth), ADR 3 rejected during flight phase 2 (engine start).
Other unreliable airspeed indication occurrences

The ATSB, and other international agencies, have previously investigated a number of unreliable airspeed events. Due to the complex and proprietary systems included in many modern transport aircraft the symptoms and procedures associated with an unreliable airspeed event can vary between aircraft and manufacturers. To compare and contrast how the unreliable airspeed indications presented themselves and how the flight crew responded to the situation, the ATSB limited a review of other unreliable airspeed indication investigations to those involving other Airbus aircraft .[47] These include:

Airbus A320-232, VH-JQX, 20 September 2010[48]

VH-JQX was on descent through FL 300 when the flight crew received a number of ECAM alerts, including A/THR OFF, F/CTL ALTN LAW, and ENG 1(2) EPR MODE FAULT. At the same time, the captain’s and first officer’s PFDs lost airspeed, altitude and descent data. The outside air temperature was -30°C and there was light rain. After about 2 minutes, the airspeed indications returned to the PFDs.

The incident was not the subject of a full investigation; however, the information presented indicated that the conditions were conducive to icing and the faults and loss of air data was the result of a temporary blockage of the aircraft’s pitot probes.

Airbus A330-202, VH-EBA, 28 October 2009[49]

VH-EBA was operating at FL 390 south of Guam on a flight between Narita, Japan, and Coolangatta, Australia. Soon after entering cloud, the flight crew noticed a rapid drop in the captain’s airspeed indication. Immediately after, the autothrust, autopilot and flight directors disconnected, a NAV ADR DISAGREE alert was activated and the flight control system reconfigured to alternate law.

The investigation found that the airspeed disagreement was due to a temporary obstruction of the captain's and standby pitot probes, probably due to ice crystals. A similar event occurred on the same aircraft on 15 March 2009.

Airbus A330-243, A6-EYJ, 21 November 2013[50]

A6-EYJ was departing Brisbane Airport for a flight to Singapore. One take-off was rejected by the captain after observing an airspeed indication failure on his PFD. The aircraft was examined by maintenance personnel, who transposed air data inertial reference units (ADIRUs) 1 and 2, and the aircraft was dispatched with ADIRU 2 inoperative in accordance with the minimum equipment list.

During the subsequent take-off, the captain became aware of an airspeed discrepancy after V1[51] and the take-off was continued. Once airborne, the autothrust and flight directors automatically disconnected, and the flight controls reconfigured to alternate law. The captain selected ADR 3 for his PFD and declared a MAYDAY,[52] before returning to Brisbane for an overweight landing.

Visual inspection of the pitot probes found that the captain’s probe was obstructed, while the other two probes were clear. Subsequent examination found that the captain’s pitot probe had been blocked by a mud dauber wasp’s nest, likely built while the aircraft was on the ground in Brisbane.

As a result of this occurrence, the operator changed their policy to require covers to be used at Brisbane regardless of time on ground, the airport operator extended their wasp inspection and eradication program and the Civil Aviation Safety Authority produced several publications on the implications of mud wasp activity.

Airbus A321-231, G-EUXM, 20 April 2012[53]

On two separate flights, airspeed indications became temporarily unreliable. On both of those occasions, the flight crew recognised that the airspeed was unreliable and managed it in accordance with the associated procedures.

On the first occasion, although the flight crew had observed unreliable airspeed indications, by the time they actioned the NAV ADR DISAGREE alert, the airspeeds had returned to normal. The flight crew noted and agreed to follow the ‘If no spd [speed] disagree’ section of the associated procedure, which noted that there was an angle of attack discrepancy. Referring to the abnormal procedures, the flight crew identified that the angle of attack fault might cause spurious stall warnings. The flight was diverted to an alternate airport for a landing without further incident.

Following the flight, the pitot probes (which were the same part number as those on VH-FNP) were removed and examined by the manufacturer. No issues with the probes were identified. The investigation determined that the unreliable airspeed indications were likely due to the accumulation of ice crystals in the pitot probes, which was beyond the capability of the heating system to melt and disperse, temporarily blocking the probes.

Airbus A320, 24 January 2007[54]

During a flight from Nuremburg, Germany to London, UK, an Airbus A320 (registration not provided) was in a climb and passing through FL 120 when there was a malfunction of all three airspeed indicators. There was a loud bang near the cockpit window, immediately followed by an ECAM warning display ‘ADR1, ADR2, and ADR3 FAULT’, with simultaneous failure of both autopilots, autothrust and flight directors. The control system mode reconfigured to alternate law.

The captain took manual control of the aircraft and levelled the aircraft out. The flight crew observed that the airspeed indicators presented different values from 230 to 260 kt. The flight crew worked through the associated procedures and diverted to a different airport, landing without further event.

The wings and tailplane had been de-iced prior to the flight, but the fuselage was not. Ice was observed on the forward fuselage after the aircraft landed and at the time of the incident, the aircraft was passing through an inversion where the air temperature increased from -3 °C to +1 °C.

The investigation determined that the loud bang was probably due to the separation of a sheet of ice from the nose of the aircraft. There were no issues identified with the systems, so it was likely that the different airspeed measurements were due to impurities (ice, snow, or water) in the pitot static system pressure lines.

ATSB observations:
In all of these cases, the flight crew happened to observe unreliable airspeed indications.

In only one case did the flight crew progress down the angle of attack discrepancy path; however, in that case, no stall warnings were generated. As such, although it was a somewhat similar situation, how the flight crew would have reacted to any stall warnings is unknown.

In all cases, except the A330 with mud wasp contamination and possibly the 2007 German A320, the contamination was from ice in atmospheric conditions, which were likely beyond the capability of the pitot probe heating to dissipate. There were no indications of probes with blocked drain holes in any of these occurrences.

__________

  1. Cloud cover: in aviation, cloud cover is reported using words that denote the extent of the cover – ‘few’ indicates that up to a quarter of the sky is covered, ‘scattered’ indicates that cloud is covering between a quarter and a half of the sky, ‘broken’ indicates that more than half to almost all the sky is covered, and ‘overcast’ indicates that all the sky is covered.
  2. The local atmospheric air pressure at mean sea level.
  3. Information provided in the weather reports to indicate a temporary deterioration in the forecast weather conditions, during which significant variation in prevailing conditions are expected to last for periods of between 30 and 60 minutes.
  4. Weather conditions that require pilots to fly primarily by reference to instruments, rather than by outside visual reference. Typically, this means flying in cloud or limited visibility.
  5. The ratio of the LP turbine exhaust pressure (P5) to the engine intake pressure (P2).
  6. The air data reference system is part of the air data inertial reference system (ADIRS), the other part being the inertial reference system. This report is only concerned with the air data reference system.
  7. Flaps and landing gear retracted.
  8. The description provided is applicable to normal law in flight mode. Normal law includes a number of other modes, such as flare mode, where the control laws differ from those described. However, for the purposes of this report, only the flight mode is described.
  9. Some of the flight control computers will latch a discarded air data parameter out (that is discontinue using that parameter) until the computer has been reset, even if the parameter returns to being consistent with the other parameters.
  10. Other system failures may also result in the flight computers reconfiguring to alternate or direct laws.
  11. The stall warning includes a synthetic voice ‘STALL’ message produced over the audio system and cockpit speaker.
  12. The CFDS retains the PFRs from the previous 63 flight legs.
  13. The ATA number is a standardised reference system widely used on commercial aircraft to identify the particular functional area. For example, ATA 27 refers to flight controls.
  14. Airbus In-Service Information reference 34.13.00004. This document was also applicable to A300, A310, A318, A319, A321, A330, A340, and A380 aircraft.
  15. Only the applicable information from each procedure is presented here. A copy of the FCOM procedures associated with all the ECAM alerts generated during the flight are presented Appendix B.
  16. The times recorded on the FDR, as presented in Appendix C, are in UTC.
  17. The angle of attack probe for ADR 3 is located well below the aircraft’s horizontal axis. Wind from the side of the aircraft will flow around the fuselage, inducing an upward component on the local airflow below the horizontal axis.
  18. The ADR system logic is such that the airspeed will become valid above 30 kt and the angle of attack will become valid when the airspeed is above 60 kt.
  19. A plot of the pertinent data from the FDR is presented in Appendix E.
  20. Airbus reported to the ATSB that according to their database of reports, the failure case of multiple transient total pitot obstructions due to contamination by foreign material on ground occurred at a rate that was considered ‘remote’. Where, remote is defined in the design standard for the aircraft (Joint Aviation Requirements Part 25) as a rate of 10-5 to 10-7 occurrences per flight hour (an average of one occurrence every 100,000 to 10,000,000-flight hours).
  21. ATSB investigation number AO-2010-070. Available at: www.atsb.gov.au/publications/investigation_reports/2010/aair/ao-2010-070/
  22. ATSB investigation AO-2009-065, Available at: www.atsb.gov.au/publications/investigation_reports/2009/aair/ao-2009-065/
  23. ATSB investigation AO-2013-212, Available at: www.atsb.gov.au/publications/investigation_reports/2013/aair/ao-2013-212/
  24. The maximum speed at which a take-off can be aborted.
  25. MAYDAY: an internationally recognised radio call announcing a distress condition where an aircraft or its occupants are being threatened by serious and/or imminent danger and the flight crew require immediate assistance.
  26. United Kingdom Air Accidents Investigation Branch (AAIB) report EW/C2012/04/06. Available at: https://assets.publishing.service.gov.uk/media/5422ffd3e5274a1317000a6f/Airbus_A321-231__G-EUXM_09-13.pdf
  27. German Federal Bureau of Aircraft Accident Investigation (Bundesstelle für Flugunfalluntersuchung, BFU) report 5X002-0/07.Available at: www.bfu-web.de/EN/Publications/Investigation%20Report/2007/Report_07_5X002_A320_AirspeedIndicators.pdf

Findings

From the analysis of the evidence available, the following findings are made with respect to the unreliable airspeed indications and stall warning event involving the Virgin Australia Regional Airlines Airbus A320, VH-FNP, near Perth Airport on 12 September 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and:

(a) can reasonably be regarded as having the potential to adversely affect the safety of future operations

(b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

Unreliable airspeed indications
  • Drains in all three pitot probes were blocked, preventing water contamination from being effectively discharged.
  • Before and during the flight, water temporarily obstructed all three of the aircraft’s pitot probes, resulting in erroneous airspeed indications. Differences in the airspeeds across the three air data reference systems consequently affected the engine control, flight control and auto flight systems, degrading their functionality and generating multiple system alerts.
Diagnosis of NAV ADR DISAGREE alert source
  • The flight crew’s workload following multiple system failures was high, affecting their ability to process information quickly. This, combined with maintaining safe flight, resulted in the flight crew taking about 8 minutes to attend to the engine alerts and action the NAV ADR DISAGREE procedure.
  • When the flight crew actioned the NAV ADR DISAGREE procedure, the airspeeds were consistent on all indicators, leading them to incorrectly diagnose that the system failure was the result of an angle of attack discrepancy rather than erroneous airspeeds. The procedure informed them that in this situation, there was a risk of undue stall warning.
  • Although the NAV ADR DISAGREE had more immediate safety implications relating to unreliable airspeed, the ECAM alert priority logic placed this alert below the engine-related faults. As a result, the NAV ADR DISAGREE alert was not immediately visible to the flight crew due to the limited space available on the ECAM display. [Safety issue]
  • A NAV ADR DISAGREE alert can be triggered by either an airspeed discrepancy, or angle of attack discrepancy. The alert does not indicate which, and the associated procedure may lead flight crews to incorrectly diagnosing the source of the alert when the airspeed is erroneous for a short period and no airspeed discrepancy is present when the procedure is carried out. [Safety issue]

Other factors that increased risk

  • Believing it to be an erroneous warning due to an angle of attack discrepancy, the flight crew disregarded a real stall warning during the approach.

Additional findings

  • The source of the foreign material blocking the pitot probe drain holes could not be identified.

The occurrence

Preparation for the flight

On 12 September 2015, a Virgin Australia Regional Airlines (VARA) Airbus A320-231, registered VH-FNP (FNP), was prepared for a charter flight from Perth Airport, Western Australia (WA) to Boolgeeda Airport, WA. When the captain arrived at the aircraft, he noticed the ground engineer had the auxiliary power unit running, which was normal, but also had a ground power unit connected to the aircraft. The engineer informed the captain that this was because the batteries had gone flat during overnight maintenance to rectify a previous issue with a flight management and guidance system.[1] Upon entering the cockpit, the captain found it was still untidy from the overnight maintenance and a number of controls and system configurations were not in their normal settings.

Confirming that the batteries were charging, the captain continued preparation for the flight. The first officer joined the captain at the aircraft and they completed the pre-flight preparation without further issue. The battery charge was completed and the seven cabin crew and 139 passengers boarded ready for departure.

Take-off and climb

At 0636 Western Standard Time,[2] the aircraft pushed back from the terminal and the flight crew started the engines, commencing with engine 2.[3] While engine 2 was starting, the flight crew received two system alerts: ‘park brake on’ and ‘engine 1 shutdown’. The captain discussed this with the engineer, remarking that it was probably related to the overnight maintenance and the batteries being low, but would see what happened when engine 1 was started. However, both alerts appeared to resolve themselves and disappeared before engine 1 start was commenced. The flight crew reported that it was not unusual to receive short ‘spurious’ alerts during engine start, so continued with the preparation for departure. At this time, the captain also remarked to the engineer his concern about possibly getting spurious alerts at a critical time and requested that they hold for a couple of minutes to make sure there were no more alerts.

While the aircraft was being taxied to the runway, the flight crew performed a flight control check, which involved moving all controls to their extents to ensure full and correct movement. The flight crew reported that it is normal system behaviour for the flight control system page to automatically appear on the system display[4] when the controls are moved for this check; however, on this occasion the captain had to manually select the flight controls page. The flight crew discussed this and associating it with the spurious alerts during engine start decided to continue with the flight. The taxi was continued to the end of runway 21 and at 0650, the flight crew commenced the take‑off from runway 21, with the captain as the pilot flying.[5]

During the take-off roll, the first officer announced passing 100 kt, which was confirmed verbally by the captain.[6] The aircraft continued to accelerate; it was rotated and lifted off into a positive climb away to the south on a standard instrument departure.

After making a turn to the west, with the autopilot and autothrust systems engaged, air traffic control (ATC) cancelled the standard instrument departure and cleared them to track direct to Morawa.[7] The flight crew requested, and were cleared, to continue on their current westward heading so that they could clear some showers that were in the area.

At 0654:39, as the aircraft was climbing through about 8,000 ft above mean sea level, the autothrust disengaged, generating an alert and locking the thrust at the current setting. Ten seconds later, the autopilot disengaged (Figure 1).

Figure 1: The flight path taken by VH-FNP when departing from Perth, up to the point that the autopilot disengaged

Figure 1: The flight path taken by VH-FNP when departing from Perth, up to the point that the autopilot disengaged

Note: The green flight path indicates when the autopilot was engaged, orange when the autopilot was not engaged. North is toward the top of the image. Source: Google earth, annotated by the ATSB

The flight crew attempted to re-engage the autopilot, but without success. They then identified on the electronic centralised aircraft monitoring (ECAM) system an alert for engine 1 EPR mode[8] fault (ENG 1 EPR MODE FAULT). At this point, the ECAM likely presented the following alerts to the flight crew (Figure 2).

Figure 2: Representation of the ECAM messages presented to the flight crew when the autopilot disengaged[9]

Figure 2: Representation of the ECAM messages presented to the flight crew when the autopilot disengaged

Source: ATSB

The captain took manual control of the aircraft and continued the climb. At this time, the aircraft had automatically changed the mode of airspeed control from ‘managed’ to ‘selected’,[10] and advised the flight crew to set the target airspeed to the green dot speed.[11] However, the green dot speed was not presented to the flight crew on the airspeed indicator, so the captain elected to fly the aircraft at a 10° nose-up attitude to ensure that the aircraft continued to climb.

While continuing the climb, the captain turned the aircraft northward toward the cleared track to Morawa, and asked the first officer to attempt to get some automation back. The captain made comment to the first officer regarding the airspeed limit and the loss of other speed information. The speed indicated on the captain’s display at this time was about 290 kt, 40 kt above their cleared speed of 250 kt.

At 0657:11 (2 minutes and 21 seconds after the autopilot disconnected), while passing through about 15,700 ft, the flight crew were cleared by ATC to flight level (FL)[12] 350. Before acknowledging this, the captain asked the first officer to commence the actions presented on the ECAM related to the alerts (referred to as ECAM actions). However, as the first officer commenced reading from the ECAM, starting with the autoflight (AUTO FLT AP OFF) alert, the captain interrupted him to confirm the clearance from ATC. The first officer confirmed the cleared altitude and attempted to continue with the ECAM actions, but the captain decided that he did not wish to continue to the cleared altitude and asked the first officer to request clearance to FL 200 instead. The request was granted by ATC, who were also informed that they were troubleshooting.

Before continuing with the ECAM actions, the captain asked the first officer to contact the cabin to have the cabin crew and passengers remain seated while they deal with some technical issues.

During this period, the captain’s primary concerns were controlling the aircraft on the correct heading, considering the approach of FL 200, and attempting to get some control of the speed. The first officer again attempted to commence the ECAM actions, but as they started the ENG 1 EPR MODE FAULT actions, ATC contacted the flight crew, to transfer from Perth Departures to Melbourne Centre, which required a change in the radio frequency.

At this time, noting that the aircraft was also approaching FL 200, the captain expressed a concern that the speed would increase as they levelled out so they needed to deal with the engines. The captain asked the first officer to continue with the ECAM actions for the engines, and delay communications with ATC. The ECAM actions for the ENG 1 EPR MODE FAULT involved switching both engines to N1 mode[13] and manually adjusting the thrust. When this was completed and the aircraft levelled out, the first officer reminded the captain of ATC’s request for a frequency change.

The captain noted that the airspeed was coming back down to 250 kt and requested that the first officer speak to Melbourne Centre and inform them of their situation. During the conversation, the captain also requested a change in heading to 360° (north), which would be easier to maintain than a track to a waypoint, when flying manually. The request was approved by ATC.

Troubleshooting and return to Perth

Having organised their ATC clearances, the flight crew then returned their attention to the ECAM actions. The flight crew had already completed all of the actions for the ENG 1 EPR MODE FAULT, but none of those actions resulted in a change to the ECAM display, so the first action taken was to clear that alert. The next message, ENG 2 EPR MODE FAULT required the same action, which having already been completed required only the alert to be cleared. When this was done, the first officer announced that the next alert was NAV ADR DISAGREE. At almost 8 minutes 30 seconds since the autopilot had disconnected, this was the first time that the flight crew had made mention of the NAV ADR DISAGREE (navigation - air data reference disagree) message.

The specified action for the NAV ADR DISAGREE alert was to crosscheck the airspeeds between the captain, first officer and standby indicators. As the first officer started actioning the ECAM, the captain asked him to make a cabin announcement to let the passengers know that they were having some technical issues and that they would be returning to Perth when they had sorted them out. While the captain was asking the first officer to do this, the first officer was heard calling out ‘two-fifty, two-fifty, two-fifty’ [consistent with the airspeed at that time]. The cabin crew were busy making an announcement, so the first officer was not able to make the cabin announcement, and the flight crew continued with the ECAM actions. The captain confirmed with the first officer that there was no disagreement with the airspeeds. Noting that, if there had been an airspeed discrepancy, the air data reference (ADR) check procedure was required, but because there was not, he announced that there was an angle of attack[14] discrepancy.[15]

The flight crew briefly discussed an angle of attack discrepancy. This appeared to cause some confusion, with the first officer reading out some figures of 5° and 6°[16] and indicating that there was no discrepancy. Although the captain had a questioning tone in his voice, they accepted the ECAM instructions and cleared the message.

Upon clearing the NAV ADR DISAGREE alert, a F/CTL ALTN LAW (flight control alternate law)[17] alert was presented. Upon receiving this alert, the captain indicated that the issue might have been more significant than first thought. There were no associated actions for the flight crew to take, only advisory information that protections were lost and that the airspeed limit was 320 kt, so the flight crew cleared the alert. This then brought up an AUTO FLT A/THR OFF (auto flight authothrust off) ECAM alert.[18] Again, there were no actions for the flight crew to attend to, so this alert was cleared.

The flight crew were then presented with another ECAM alert, this time for AUTO FLT RUD TRV LIM SYS (autoflight rudder travel limiter system). The ECAM provided advisory information to the flight crew to use the rudder with care above 160 kt. The first officer then switched off, then back on, flight augmentation computer number 1 (FAC 1) in accordance with the ECAM procedure. This resulted in the presentation of two more ECAM alerts. The first, which was likely transitory, was AUTO FLT RUD TRIM1 FAULT (autoflight rudder trim 1 fault) followed by AUTO FLT RUD TRV LIM 2 (autoflight rudder travel limiter 2). The second of these ECAM alerts merely noted that the flight crew be aware of the fault and had no procedure to rectify the fault.

At this point, about 11minutes 30 seconds after the autopilot disconnected, the captain decided to pause the ECAM actions so that they could assess the situation and deal with other activities. The captain asked the first officer to check for any tripped circuit breakers, which required the first officer to leave his seat. No tripped circuit breakers were identified. The captain also took this time to update the cabin crew, passengers and the company. Meanwhile, they continued northward away from Perth.

After communicating with the cabin and the company, the flight crew continued their troubleshooting. This included reviewing the Flight Crew Operating Manual (FCOM) for more detailed information on ECAM alerts and system faults, and attempting to re-engage the autopilot (without success).

While reviewing the detailed information in the FCOM, the flight crew reviewed the NAV ADR DISAGREE procedure, and the associated alternate law procedure. The information in those procedures advised the flight crew that if there was no speed disagreement, then there was an angle of attack discrepancy and that there was ‘risk of undue stall warning’. It also advised the flight crew that the flight controls would revert to direct law when the landing gear was lowered.

At 0720:42, after advising ATC of their intent to return to Perth, the captain again tried to re‑engage the autopilot. The autopilot did not engage, but the captain noticed that he now had a flight director[19] available. The flight crew discussed the improvement that having this available made to their workload and decided to try resetting FAC 2. After resetting FAC 2, the flight crew found that they had the autopilot back.

Having the autopilot back on, the flight crew returned their attention to preparing from the return and landing. The captain again reviewed the FCOM information highlighting the risk of undue stall warning.

At 0723:45, when the aircraft was about 245 km north of Perth, the flight crew requested, and received, a clearance to return the Perth. After making the turn back towards Perth, the flight crew continued with their preparation for the approach and landing. During their discussions, the captain indicated that he felt some of the alerts might have been spurious.

Having been advised by ATC that descent into Perth was available; the captain transferred control to the first officer, and requested and received a clearance to descend to 10,000 ft. The first officer commenced the descent at 0736, when about 140 km north of Perth.

The flight from take-off to the top of descent, indicating where the key events took place is presented in Figure 3.

Figure 3: The flight path from take-off up to top of descent with key points identified

Figure 3: The flight path from take-off up to top of descent with key points identified

Note: The green flight path indicates when the autopilot was engaged, orange when the autopilot was not engaged. North is toward the left of the image. Source: Google earth, annotated by the ATSB

Descent and landing

The descent progressed normally; the captain had updated the cabin crew and company on the situation and they had been cleared by ATC to descend to 5,000 ft. At 0743, as they were passing through about 10,000 ft, the captain noticed that the airspeed was decreasing and informed the first officer, who had control. The first officer recalled observing that the minimum speed warning area on the captain’s airspeed indicator was increasing and announced that there was a disagreement between the airspeed indicators. At the same time, the captain disconnected the autopilot and both crew checked the airspeeds on all three indicators. They identified that the captain’s was indicating lower than the other two, so the captain switched his air data source to ADR 3. This resulted in the captain’s indicated airspeed increasing to a speed consistent with the first officer’s indicator. The captain then re-engaged the autopilot and continued with their landing preparations.

About 3 minutes later, when the flight crew had completed the approach checklist and been cleared by ATC to descend to 2,500 ft, the autopilot disconnected. At this time, the first officer stated that his airspeed was indicating 220 kt, with a target of 230 kt. The captain did not verbalise what speed his was indicating, but the recorded data from the flight indicated that his was about 230 kt.[20]

The captain checked the ECAM, cleared the autopilot disconnect warning and noted that the RUD TRV LIM SYS alert had reappeared. The captain announced that because they had already had that fault, they would just clear it to get the ECAM status back to what it was.

Noticing that they were probably slightly high on the descent to set up for the approach, the captain contacted ATC and requested radar vectors[21] to the west, so they could get a few more track miles before turning back to intercept the localiser.[22] ATC accepted the request and cleared them to turn to the right and maintain 5,000 ft.

During an orbit to the west, the captain recapped their situation. Particular note was made that they were in alternate law, which would transition to direct law when the landing gear was extended and that [flight envelope] protections were lost. He also reiterated that there was a risk of undue stall warning.

While heading east, back towards the approach path, the captain contacted ATC to declare a PAN,[23] notifying them that they had control system issues, were manually flying the aircraft and were in alternate law. ATC offered the attendance of emergency services for the landing, which the captain accepted.

After commencing a turn to the right to intercept the localiser, the captain took control from the first officer. The captain requested that flaps 1[24] be selected and the target speed reduced to 200 kt. At 0755:02, the aircraft was at an altitude of 2,550 ft and was still in the turn when the stall warning[25] activated. While the stall warning was active, the captain continued the turn and repeatedly announced ‘disregard’. After 6 seconds, the stall warning ceased.

After being cleared by ATC for the approach to runway 21, the captain noted that there was a windshear detection fault. He commented to the first officer that this was to be expected, given the spurious alerts and requested the associated ECAM alert be cleared.[26]

The flight crew continued the approach, and after capturing the glideslope,[27] the captain requested that flap 3 be selected. The first officer noted that the limit speed for flap 3 was 185 kt. The captain noted that his airspeed was indicating 175 kt, but the first officer informed him that his was indicating 190 kt. They continued the approach and the captain requested the target airspeed be set to 145 kt, about 3 kt higher than the calculated approach speed, to carry a little extra speed for the approach.

At about 2,400 ft, the landing gear was extended and the approach continued under manual control. The aircraft touched down at 0800 and the landing was completed without further incident. The attending emergency services were not required and the flight crew taxied the aircraft back to the bay.

The descent and approach flight path, with the key events identified, is presented in Figure 4.

Figure 4: Descent and approach flight path into Perth with key points identified

Figure 4: Descent and approach flight path into Perth with key points identified

Note: The green flight path indicates when the autopilot was engaged, orange when the autopilot was not engaged. North is to the left of the image. Source: Google earth, annotated by the ATSB

__________

  1. An integrated system that computes the aircraft’s position using a database of aircraft performance and navigation data. It can direct the aircraft along a planned flight profile (ground track, vertical and speed profiles).
  2. Western Standard Time (WST): Coordinated Universal Time (UTC) + 8 hours.
  3. The engines on the A320 are numbered 1 and 2 from left to right looking forward. That is, engine 1 is on the left wing and engine 2 is on the right wing.
  4. The system display is a display on the instrument panel dedicated to presenting information about particular systems. The system of interest can be displayed either automatically, in the case of a system failure, or manually selected by the flight crew. Further information is contained in the section titled Electronic instrument system.
  5. Pilot flying and pilot monitoring: procedurally assigned roles with specifically assigned duties at specific stages of a flight. The pilot flying does most of the flying, except in defined circumstances; such as planning for descent, approach and landing. The pilot monitoring carries out support duties and monitors the pilot flying’s actions and the aircraft’s flight path.
  6. According to the analysis carried out by the aircraft manufacturer (refer to the section titled Manufacturer’s analysis), an airspeed discrepancy was identified in the stand-by system (CAS 3) during the take-off roll. It could not be determined from the recorded information if CAS 3 was erroneous when the 100 kt check was carried out.
  7. A navigation waypoint about 300 km to the north of Perth.
  8. EPR (engine pressure ratio) mode is the engine’s normal operating mode. In this mode, thrust controlled is based upon the ratio of the engine inlet and exhaust pressures. Autothrust requires that EPR mode is available. Further information on the engine modes is in the section titled Power plants.
  9. This representation is based upon information supplied by Airbus and is prior to the flight crew actioning any of the ECAM procedures.
  10. The aircraft provides two types of automatic control, managed and selected. In managed mode, the target parameters, for example airspeed, are calculated by the flight guidance and management computers to attain the predetermined flight path. In selected mode, those targets are selected by the flight crew.
  11. A characteristic speed for the aircraft that gives the best lift-to-drag speed for the clean (flaps and landing gear retracted) aircraft at the current weight. The green dot speed is presented to the flight crew as a green dot on the airspeed indicator. Flying at the green dot speed will achieve the best climb gradient.
  12. Flight level: at altitudes above 10,000 ft in Australia, an aircraft’s height above mean sea level is referred to as a flight level (FL). FL 350 equates to 35,000 ft
  13. An alternate engine control mode based upon the rotational speed of the engine’s low-pressure system (N1). Further information on the engine modes is in the section titled Power plants.
  14. The relative angle of the wing section to the oncoming airflow.
  15. This was in accordance with the procedure for a NAV ADR DISAGREE alert. Refer to section titled Operating procedures Abnormal procedures - Navigation – ADR disagree for more information.
  16. The angle of attack is not presented on any of the primary displays in the Airbus A320. It can be displayed on the multipurpose control and display unit in the centre pedestal; however, the first officer reported that these figures were instinctively read out from the pitch attitude of the aircraft and were not angle of attack values.
  17. The digital ‘fly-by-wire’ control system in the Airbus A320 has three control laws; normal, alternate and direct. Further information on these laws can be found in the Flight control system section of this report.
  18. The ECAM is designed to prioritise the alerts so that if there are multiple alerts, the alert deemed most important appears higher on the list. This message was likely the alert generated when the autothrust disengaged 10 seconds before the autopilot disengaged, but the other alerts were assigned a higher priority, pushing this alert off the available screen space. Refer to the section titled Electronic instrument system for more information on the ECAM.
  19. A function of the autoflight system that provides flight guidance information to the flight crew on their flight displays for them to follow with manual control inputs. Accurately following the flight director guidance will have the same result as having the autopilot on. Further information on the flight director can be found in the Auto flight section of this report.
  20. The aircraft was fitted with a flight data recorder and cockpit voice recorder. Further information is provided in the  Recorded information section of this report.
  21. Radar vectors are tracking directions provided by ATC to assist the flight crew with navigation.
  22. The localiser is part of a ground based instrument landing system (ILS) that provides lateral (left-right) guidance to the flight crew.
  23. An internationally recognised radio call announcing an urgency condition, which concerns the safety of an aircraft or its occupants, but where the flight crew does not require immediate assistance.
  24. The first stage of flaps, which at this stage consisted on extension of the leading edge slats only.
  25. The stall warning consists of activation of the master warning light and an aural ‘stall’ announcement.
  26. The alert was likely a real alert, consistent with the system operation, but misinterpreted by the captain. As described in the section of the report titled Operating procedures - Windshear detection fault, the fault warning is inhibited until the flaps are extended, so the captain may not have associated the alert with the factors that led to the fault.
  27. The glideslope is part of a ground based instrument landing system that provides vertical (up-down) guidance to the flight crew.

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • flight crew of VH-FNP
  • flight recorders from VH-FNP
  • Virgin Australia Regional Airlines
  • Airbus
  • Bureau of Meteorology.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to Virgin Australia Regional Airlines, the flight crew of VH-FNP, Airbus, the French Bureau d’Enquêtes et d’Analyses pour la sécurité de l’aviation civile (BEA), and the Civil Aviation Safety Authority.

Submissions were received from Virgin Australia Regional Airlines, the flight crew of VH-FNP, Airbus, the French Bureau d’Enquêtes et d’Analyses pour la sécurité de l’aviation civile (BEA), and the Civil Aviation Safety Authority. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Safety analysis

Introduction

After passing through about 8,500 ft on departure from Perth Airport, Western Australia, the autothrust and autopilot disconnected, and multiple alerts were generated. The flight crew continued the climb to an altitude of 20,000 ft, where they levelled out to troubleshoot the issues before returning to Perth. During the approach, when the flight crew were aligning the aircraft with the instrument landing system, they received a stall warning. The warning stopped after 6 seconds and the approach was continued for a successful landing.

This analysis will examine the factors that contributed to the generation of the multiple alerts, the factors that contributed to the flight crew incorrectly diagnosing the source of the alerts, and the subsequent effects on the continued safe flight of the aircraft.

Blocked pitot probes and unreliable airspeed indications

The system behaviour and the warnings received by the flight crew were consistent with discrepancies between the computed airspeeds (CAS) during the flight. Primarily, two unreliable airspeed indication events occurred during the flight. The first was during the climb out of Perth, when the aircraft was passing through 8,500 ft. The second was at about 10,000 ft, when the aircraft was descending back into Perth.

In the absence of technical issues with the measuring devices, airspeed discrepancies are typically a result of a blockage in either the pitot, or static systems. The source of the airspeed inaccuracies can be determined by how the airspeed changes.

For example, in a constant speed climb with a blocked pitot (inlet and drain holes), the total pressure measurement will remain constant while the static pressure decreases. The resulting increase in the pressure difference will lead to an apparent increase in the airspeed.[55] However, in the same flight conditions (constant speed climb) with a blocked static port, the measured static pressure will remain constant, while the total air pressure will decrease, due to its static pressure component decreasing with altitude. This will lead to a decrease in the apparent airspeed. In a similar manner, when descending at a constant speed, a blocked pitot will result in a decreasing apparent airspeed. A blocked static port will result in an apparent increase in speed.

The manufacturer’s simulations identified that during the climb out of Perth, CAS 1 was overestimated for several minutes. Their simulation also showed that during the descent back into Perth, CAS 1 was underestimating the airspeed before the captain changed to air data reference (ADR) system 3. Both of these airspeed discrepancies were consistent with a blockage in the captain’s pitot probe inlet and drain holes.

On both occasions, the total air temperature[56] was above freezing and the probe heating was on. Thus, it was unlikely that the probe was blocked from ice accumulation, as had been experienced on other aircraft investigated for airspeed discrepancies. In this case, given the rainy conditions that existed around Perth on the morning of the incident flight, the captain’s probe was likely blocked by liquid water.

Although the flight data recorder only recorded one CAS parameter, it was inferred from the system behaviour that all three ADR systems produced erroneous airspeed data at various times during the flight. The reports of water being ejected from all three systems during the post-incident servicing was verification that all three pitot systems were affected by water contamination during the flight. The standby system (ADR 3) was potentially further affected by solid matter contamination, as indicated by the dark object ejected when the system was flushed. However, given that simulation showed that it was correctly estimating the speed after the captain selected it as his source, the issues with CAS 3 were also transient.

The erroneous airspeed indications that occurred when the engine was first started indicated that the captain’s pitot probe was probably contaminated before the flight. A similar incident 3 days prior was also consistent with contamination with liquid water. There was no reported rain in the Boolgeeda area in the period around 9 September 2015, but there was in Perth. As such, it was likely that the water contamination was the result of recent rains in the Perth region that became trapped in the system due to the blocked drain holes.

According to the European Aviation Safety Agency airworthiness directives, these probes had improved airspeed indication behaviour in heavy rain, compared to the previously fitted probes. This tolerance to rain was due, in part, to the small drain holes in the probes. This feature is only effective if the holes are open and free for water to escape through them. The post-incident servicing found that there were blockages in at least one of the two drain holes on each probe.

The blocked drain holes likely prevented water contamination from being effectively discharged, leading to temporary obstructions in the pitot probes. The obstructions resulted in erroneous airspeed indications that differed across the three systems. This affected numerous systems, including the engine control, flight control and auto flight systems, degrading their functionality and generating multiple system alerts.

The post-incident servicing actions, which identified the blocked drain holes and foreign object in the standby system, only required the maintenance personnel to clean the system as part of troubleshooting and return to service actions. These actions occurred shortly after the incident and the ATSB had not started a formal investigation. As such, there was no requirement for a forensic examination of the air data systems, and the substance(s) blocking the pitot probes was not identified.

The probes were removed from the aircraft several weeks later, for a detailed forensic examination by the manufacturer. However, the aircraft had been back in operation, so the contaminants that were identified during those examinations could not be conclusively linked to the events on 12 September 2015.

The in-service information distributed to A320 operators in July 2014 listed scheduled maintenance actions to minimise the occurrence of airspeed discrepancies as well as the actions they recommend be performed when such an event happens. That information noted previous occurrences where residual airspeed was displayed on the primary flight display while the aircraft was not moving. It also noted that most of the airspeed discrepancy events investigated by them were due to water in the pitot probes and the probe draining holes being obstructed by external particles; however, it implied that the revised probes, as fitted to FNP had improved their behaviour in adverse weather conditions.

Clearing of the pitot probes, including the drain holes, is a scheduled maintenance action for the aircraft. This cleaning is on a rotational basis, which the operator carried out more frequently than was required by the manufacturer’s schedule. The ATSB was not aware of a rate of adverse pitot probe drain hole blockage to suggest that the cleaning schedule is generally inadequate across the A320 fleet. Other than this event, the operator had not identified a fleet-wide reliability issue to suggest that it was not adequate for their particular operations. In fact, the last probe to be cleaned, the captain’s pitot probe, had been cleaned only 3 days before the first airspeed anomaly at Boolgeeda, and 6 days before the incident flight. Thus, whatever blocked the drain holes of the captain’s probe probably entered the probes shortly after they were cleaned.

The on-ground event on 9 September 2015 was an opportunity for the operator to have identified an unreliable airspeed indication event and carried out the actions recommended by the manufacturer. The aircraft was remote from the maintenance organisation at the time, but the flight crew reportedly contacted them for advice. Following that advice, the flight control system was reset by a complete powering down of the aircraft electrics, which, to the flight crew appeared to correct the airspeed anomaly. The ATSB did not determine why the operator did not perform the actions recommended by the manufacturer. However, given the maintenance personnel were basing it on a report from a flight crew at a remote airport and the aircraft operated on the subsequent return flight to Perth, and for another 2 days without any flight crew identifying airspeed issues, the operator may not have identified it as an unreliable airspeed event.

Diagnosis of the NAV ADR DISAGREE alert source

The flight crew were not aware of and did not action the NAV ADR DISAGREE procedure until about 8 minutes had passed since the alert was generated. By this time, the airspeed discrepancy that had generated the alert was no longer present. Therefore, when the flight crew crosschecked the airspeeds, the airspeeds were consistent and they diagnosed the issue as an angle of attack discrepancy. Several factors were identified that led to the flight crew incorrectly diagnosing the source of the NAV ADR DISAGREE alert when carrying out the associated procedure:

  • the flight crew’s high workload
  • priority of alerts programmed into the ECAM
  • suitability of the NAV ADR DISAGREE procedure for short duration airspeed disagreements.

Flight crew workload

When the captain arrived at the aircraft, it was not in a state in which he would normally receive it. Maintenance work from the previous night had left the batteries flat, the cockpit was in a messy state, and some of the systems required reconfiguring. The captain had not experienced an A320 aircraft with a flat battery before, so had some uncertainties to what effect that may have on the aircraft’s systems.

During the engine start, the flight crew received ‘spurious’ engine failure and park brake on alerts. In addition, when the flight controls were being checked, the system did not automatically display the flight controls page on the electronic centralised aircraft monitoring (ECAM) system display, as expected. Although the system behaviour was not erroneous for the airspeed data it was receiving, it was abnormal and probably confirmed some of the captain’s concerns about the effects of the flat battery. At one point shortly before take-off, the captain commented that most of the problems they ‘have seen are probably a direct result of the flat batteries’.

When the aircraft was in the early stages of climb, a recognised high-workload period, the autothrust and autopilot disconnected, and multiple alerts were triggered. It was likely that the flight crew’s workload was higher than normal from the start of the flight and increased further with the unfavourable weather conditions in the area, including a rain shower through which the aircraft was either in, or at the edges of. At the time, the flight crew had also just been cleared to cancel the standard instrument departure and track direct to their next en route waypoint. The captain requested that this be delayed so that they could clear the weather, suggesting that the workload was high and they did not wish to increase it.

When the automation disconnected and the alerts triggered, it was likely that the flight crew’s workload was very high. The flight crew’s actions in the minutes after, particularly those of the captain indicated that they had reached the limits of their attentional resources and were only dealing with what they perceived to be the most critical issues. Initially, consistent with the normal aviation flight principles of ‘aviate, navigate, communicate’, the captain’s focus was on ensuring that the aircraft was under control and in a stable climb.

When the autothrust disconnected, thrust lock was activated and the aircraft was still climbing. The flight crew had weather, and a likely return to Perth, to deal with, so actioning the amber alerts on the ECAM (those that by definition the flight crew should be aware of, but need not take immediate action) were probably low on their priority list.

When they were preparing to level the aircraft at FL 200, they actioned the engine 1 engine pressure ratio (EPR) mode ECAM to ensure that they had engine control so as to avoid an overspeed situation. Completing the actions associated with the engine 1 EPR mode fault and clearing the message from the ECAM would have brought the next alert message, engine 2 EPR mode fault, into view. The actions for this were the same, so the flight crew left this and turned their attention to what they probably considered were more immediate matters, which at that time was navigating the aircraft to the north of Perth, a required change in ATC frequency, and informing the cabin crew and passengers of their situation.

Comments made by the captain during the flight indicate that he considered that they faced an issue that was greater than a simple individual system failure. This was probably a result of the multiple system alerts, described by the captain as ‘concurrent issues’, and the (unrelated) flat battery situation before flight. This probably made it more difficult for the captain to understand the situation facing them.

In summary, the ATSB found that the flight crew’s workload following multiple system failures was high, affecting their ability to process information quickly and attend to multiple tasks. This, combined with maintaining safe flight, resulted in the flight crew taking about 8 minutes to attend to the engine alerts and action the NAV ADR DISAGREE procedure.

ECAM alert priorities

When multiple alerts are generated, the ECAM is designed to provide the flight crew with the alerts in the order of priority. The highest priority alerts, red alerts, were those that required immediate actions to ensure the safety of flight. Red alerts took precedence above amber alerts; those that required action, but if not performed immediately would not endanger the flight.

Initially, the only alerts that were visible on the ECAM were the red AUTO FLT AP OFF and amber ENG 1 EPR MODE FAULT, and its associated procedure. The NAV ADR DISAGREE message had been triggered, which, in accordance with the priorities set by the manufacturer during the design of the ECAM system, had a lower priority than engine fault messages. Due to the limited space available in the message area on the ECAM display, the NAV ADR DISAGREE message was off screen and not immediately visible to the flight crew.

The system provided the facility for the flight crew to view the messages off the screen, but given that the highest priority message on the screen did not require any immediate actions, there was no reason for the flight crew to divert resources away from their other tasks in a high-workload situation.

On this flight, as the engine ECAM alerts took priority over the NAV ADR DISAGREE alert, the flight crew did not carry out the procedures until after the airspeed had corrected itself, leading to an incorrect diagnosis of the origin of the alert.

Even outside of this situation, an EPR mode fault results in the engines reverting to N1 mode. This would not pose a short-term hazard to the flight, as the flight crew still have control of engine thrust. However, control of the aircraft is dependent upon reliable airspeed information, particularly if already at high or low airspeed. Therefore, unreliable airspeed indications can have a much greater shorter-term effect on the safety of flight, particularly when the flight crew is not aware that their airspeeds are potentially erroneous.

NAV ADR DISAGREE procedure

In the A320, a NAV ADR DISAGREE alert can be triggered by either an airspeed or an angle of attack disagreement. The alert itself does not indicate the source. Determination of the source relies solely upon comparison of the airspeeds across the three indicators. If they disagree, then the source is an airspeed discrepancy and the appropriate airspeed procedure commenced. However, if the airspeeds agree, then by default, the alert must have been generated by an angle of attack disagreement. There is no requirement for the diagnosis to be confirmed by examining the individual angle of attack measurements.

In the A320, flight crew are able to examine the ADR angle-off attack values; however, they are not presented on the primary flight displays, and require the flight crew to access and display a page on the multipurpose control and display unit in the centre pedestal. In this occurrence, the flight crew discussed an angle of attack discrepancy, but for undetermined reasons did not access the angle of attack page to confirm the discrepancy.

Once the NAV ADR DISAGREE alert has been generated, it is latched in the system until it is cleared by the flight crew, even if the conditions that triggered the alert are no longer present. However, this incident highlighted that, if the alert is generated by a temporary airspeed disagreement, and the procedure is not actioned while the airspeeds are in disagreement, then the source of the disagreement can be incorrectly diagnosed. This could result in the flight crew not taking the appropriate actions associated with an unreliable airspeed indication, continue making reference to incorrect airspeed data, or not responding to a valid stall warning.

In addition, according to the flight control system logic, the reconfiguration from normal law to alternate law can be due to, amongst a range of other faults, an airspeed or angle of attack disagreement. Depending on whether it is an airspeed or an angle of attack disagreement, the level of alternate law flight envelope protection will differ (alternate law with or without reduced protections). Therefore, in cases such as this, where either the airspeed or the angle of attack is in disagreement, the aircraft is capable of determining the source of an air data disagreement; however, this information is not provided to the flight crew.

Stall warning

Before commencing the approach, the flight crew had briefed on the possibility of spurious stall warnings, as indicated by the ECAM status associated with the NAV ADR DISAGREE alert. When they then received a stall warning while turning onto the localiser, they disregarded the alert, believing it to be spurious. The flight crew reported that their basis for determining that the warning was spurious was the information provided by the ECAM NAV ADR DISAGREE procedure, which they interpreted as being an expectation that stall warnings would be spurious. There was no indication from the CVR, or interviews, that they confirmed the validity of the warning using other sources such as power and pitch attitude, instead relying on the airspeeds as the primary indicator.

In this case, the stall warning was only nominal and due to a combination of the side gust and the location of the standby angle of attack sensor. However, a stall warning indicates to flight crew that margins from a stall are reduced, increasing the risk of stalling and losing control. The stall warning system logic requires only one sensor to exceed the threshold to trigger the warning. Even in the case of a NAV ADR DISAGREE that was a result of an angle of attack discrepancy, the stall warning may be triggered by a valid angle of attack measurement. There is no ready way for the flight crew to determine this and they should respond as though any warning is valid, particularly when at low altitude.

__________

  1. Normally, the greater the speed, the greater the component due to speed, and thus, the greater the difference between the pitot and static pressures. However, this difference could be due to a decrease in the static pressure with a constant total pressure.
  2. The combination of the static (ambient) air temperature and the temperature increase due to rapidly changing the speed of the air when it impacts the aircraft.

Glossary

A/THRAutothrust
ADAirworthiness directive
ADIRUAir data inertial reference unit
ADRAir data reference
ALTN LAWAlternate law
AOAAngle of attack
APAutopilot
ATCAir traffic control
AUTO FLTAuto flight
BITEBuilt-in test equipment
BoMBureau of Meteorology
CASComputed airspeed
CFDSCentralised fault display system
CMMComponent maintenance manual
CVRCockpit voice recorder
E/WDEngine and warning display
EASAEuropean Aviation Safety Agency
ECAMElectronic centralised aircraft monitoring
EFISElectronic flight instrument systems
EISElectronic instrument system
ELACElevator aileron computer
EPREngine pressure ratio
F/CTLFlight control
FACFlight augmentation computer
FCOMFlight Crew Operating Manual
FCUFlight control unit
FDRFlight data recorder
FLFlight level
FMGSFlight management and guidance system
FWCFlight warning computer
HPHigh pressure
IMCInstrument meteorological conditions
ktknot
LPLow pressure
METARMeteorological aerodrome report
N1Engine low-pressure system rotational speed
NAVNavigation
NDNavigation display
PFDPrimary flight display
PFRPost-flight report
RUD TVL LIM SYSRudder travel limiter system
SDSystem display
SECSpoiler elevator computer
SIDStandard instrument departure
TLAThrust lever angle
UTCUniversal coordinated time
VARAVirgin Australia Regional Airlines
WSTWestern standard time

Appendices

Appendix A – Detailed examination of pitot probes

On 2 November 2015, all three pitot probes (Thales part number C16195BA, manufactured in 2007 and 2008) were removed from the aircraft and sent to the probe manufacturer for detailed examination. The probes were subjected to the manufacturer’s standard acceptance test procedure and compared to the acceptable limitations of the component maintenance manual (CMM). Two of the probes were then cut open for detailed examination of anomalies identified in the interior of the probes. The following summarises the findings of the testing and examinations.

Captain probe (pitot 1)

The captain’s probe contained some erosion of the leading edge of the mast, closest to the fuselage. There was also slight erosion and corrosion at the pitot tube entrance; however, it was considered acceptable in accordance with the in-service criteria of the CMM.

Internal examination of the probe found that one of the drain holes was partially blocked by a ‘dark solid’ substance (Figure A1). Spectrographic examination found that it consisted predominantly of carbon and oxygen, but its origin was not identified.

Figure A1: Image of substance partially blocking one drain hole in the captain's pitot probe

Figure 17: Image of substance partially blocking one drain hole in the captain's pitot probe

Source: Thales

Contamination of the interior of the pitot tube by a red substance was also identified in three locations within the captain’s pitot probe (Figure A2). Spectrographic examination of that substance identified that it consisted predominantly of oxygen, silicon, iron, aluminium and carbon and that it had an infrared spectrum consistent with an aluminium silicate clay.

Figure A2: Image of red contamination (red arrows) in the captain’s pitot probe

Figure A2: Image of red contamination (red arrows) in the captain’s pitot probe

Note: The spiral structure inside the pitot probe tube is the heating element. Source: Thales

The captain’s pitot probe failed the acceptance tests due to the blocked drain hole and the contamination by the red clay substance.

First officer’s probe (pitot 2)

The first officer’s probe contained slight erosion and corrosion at the pitot tube entrance; however, it was considered acceptable in accordance with the in-service criteria of the CMM. The internal pitot tube was in good condition. This probe was found to be in acceptable condition in accordance with the CMM.

Standby probe (pitot 3)

The standby probe was slightly twisted, but was still within the CMM limits. The tube was in good condition, with some very slight erosion and corrosion at the pitot tube entrance; however, it was considered acceptable in accordance with the in-service criteria of the CMM.

Contamination deep within the interior of the pitot tube by a red substance was also identified in the standby pitot probe (Figure A3). Spectrographic examination of that substance identified that it consisted predominantly of oxygen, silicon, iron, aluminium and carbon and that it had an infrared spectrum consistent with an aluminium silicate clay.

Figure A3: Image of red contamination (red arrows) in the standby pitot probe

Figure A3: Image of red contamination (red arrows) in the standby pitot probe

Note: The spiral structure inside the pitot probe tube is the heating element. Source: Thales

The standby pitot probe failed the acceptance tests due to the contamination by the red clay substance.

Appendix B – Flight Crew Operating Manual abnormal procedures

This appendix presents the Virgin Australia Regional Airlines (VARA) full Flight Crew Operating Manual (FCOM) procedures associated with the electronic centralised aircraft monitoring (ECAM) alerts generated during the incident flight. The procedures are presented in the same order in which the flight crew encountered them during the flight.

Figure B1: FCOM procedure – Autoflight autothrust off[57]

Figure B1: FCOM procedure – Autoflight autothrust off

Source: VARA A320 FCOM

Figure B2: FCOM procedure – Auto flight autopilot off

Figure A2: FCOM procedure – Auto flight autopilot off

Source: VARA A320 FCOM

Figure B3: FCOM procedure – Engine 1(or 2) EPR mode fault

Figure B3: FCOM procedure – Engine 1(or 2) EPR mode fault

Source: VARA A320 FCOM

Figure B4: FCOM procedure – Navigation ADR disagree

Figure B4: FCOM procedure – Navigation ADR disagree

Source: VARA A320 FCOM

Figure B5: FCOM procedure – Navigation captain, first officer, or standby, angle of attack (AOA) fault

Figure B5: FCOM procedure – Navigation captain, first officer, or standby, angle of attack (AOA) fault

Source: VARA A320 FCOM

Figure B6: FCOM procedure – Flight control alternate law

Figure B6: FCOM procedure – Flight control alternate law

Source: VARA A320 FCOM

Figure B7: FCOM procedure – Auto flight rudder travel limiter system

Figure B7: FCOM procedure – Auto flight rudder travel limiter system

Source: VARA A320 FCOM

Figure B8: FCOM procedure – Auto flight rudder travel limiter 1 (or 2)

Figure B8: FCOM procedure – Auto flight rudder travel limiter 1 (or 2)

Source: VARA A320 FCOM

Figure B9: FCOM procedure – Auto flight rudder trim 1 (or 2) fault

Figure B9: FCOM procedure – Auto flight rudder trim 1 (or 2) fault

Source: VARA A320 FCOM

Figure B10: FCOM procedure – Windshear detection fault

Figure B10: FCOM procedure – Windshear detection fault

Source: VARA A320 FCOM

Figure B11: FCOM procedure – Flight control direct law

Figure B11: FCOM procedure – Flight control direct law

Source: VARA A320 FCOM

Figure B12: FCOM procedure – Navigation indicated airspeed discrepancy

Figure B12: FCOM procedure – Navigation indicated airspeed discrepancy

Source: VARA A320 FCOM

Figure B13: FCOM procedure – Stall recovery

Figure 23: FCOM procedure – Stall recovery

Source: VARA A320 FCOM

Figure B14: FCOM procedure – Navigation indicated airspeed discrepancy

Figure B14: FCOM procedure – Navigation indicated airspeed discrepancy

Figure B14: FCOM procedure – Navigation indicated airspeed discrepancy

Figure B14: FCOM procedure – Navigation indicated airspeed discrepancy

Figure B14: FCOM procedure – Navigation indicated airspeed discrepancy

Figure B14: FCOM procedure – Navigation indicated airspeed discrepancy

Figure B14: FCOM procedure – Navigation indicated airspeed discrepancy

Figure B14: FCOM procedure – Navigation indicated airspeed discrepancy

[Remainder of section presents the climb, cruise, descent and approach tables.]

Appendix C – Recorded data from the incident flight on 12 September 2015

The flight data recorder (FDR) contained about 25 hours of flight data, which included the data from the incident flight, and 19 preceding flights. The following figures present data from the incident flight that were applicable to the development of the sequence of events.

Notes about the following FDR data:

  • The FDR contained more than 300 individual parameters. Not all of those parameters were required to develop the sequence of events. Only those deemed to be of interest to the investigation are presented.
  • Times were recorded in UTC. For local times, add 8 hours to the UTC time. For example, 22:53:25 UTC is 0653:25 WST.
  • The FDR started recording when the first (number 2) engine was started.
  • Only one source of computed airspeed was recorded. By default, this was the airspeed presented on the captain’s primary flight display, unless it was invalid, in which case the first officer’s side is presented, if valid.
  • The FDR recorded the angle of attack from the captain’s and first officer’s systems only. The standby system was not recorded.

Figure C1: Flight data – auto flight parameters (complete flight)

Figure C1: Flight data – auto flight parameters (complete flight)

Source: ATSB

Figure C2: Flight data – flight controls (complete flight)

Figure C2: Flight data – flight controls (complete flight)

Source: ATSB

Figure C3: Flight data – flight controls (pre-flight and take-off)

Figure C3: Flight data – flight controls (pre-flight and take-off)

Source: ATSB

Figure C4: Flight data – environmental parameters (complete flight)

Figure C4: Flight data – environmental parameters (complete flight)

Note: The validity of the angle of attack (AOA) is inferred by its behaviour. When it cycles between maximum and minimum values, it is deemed invalid. Source: ATSB

Figure C5: Flight data – Engine parameters (complete flight)

Figure C5: Flight data – Engine parameters (complete flight)

TLA = thrust lever angle. A measure of the thrust lever position. Source: ATSB

Figure C6: Flight data – Key parameters during stall warning

Figure C6: Flight data – Key parameters during stall warning

Source: ATSB

Appendix D – Manufacturer’s detailed sequence of events analysis

As part of their analysis of the incident, the aircraft manufacturer, Airbus, performed a detailed sequence of events analysis. Table D1 presents a summary of the key events from the manufacturer’s sequence of event analysis.

Table D1: Summary of key events from manufacturer’s sequence of events analysis

PhaseTime (WST)Events
Take-off0650:43

Between 80 kts and take-off, ADR 3 was rejected by the ELACs[58] and FACs.[59] This was probably due to a CAS discrepancy.

This was latched[60] in the ELACs for the remainder of the flight, but not by the flight guidance computer and FACs.

Climb0654:39Autothrust disconnected. Thrust lock activated.
 0654:49

Engines 1 and 2 reverted from EPR mode to N1 mode, due to the engines rejecting the inlet total pressure, P2.

The following ECAM alerts were triggered:

- ENG 1 EPR MODE FAULT

- ENG 2 EPR MODE FAULT

 0654:50

Captain’s CAS was 287 kts and increasing.

Autopilot 1 involuntary disconnected and both flight directors disengaged.

Following ECAM alerts were triggered:

- AUTO FLT AP OFF

- AUTO FLT RUD TRV LIM SYS

- NAV ADR DISAGREE

- F/CTL ALTN LAW

Loss of autopilot, flight directors and rudder travel limiter were due to rejection of all ADR parameters in both FACs. ADR rejections latched by FACs and characteristic speeds lost.

ADR rejection not latched by the flight guidance computer.

Because ELACs had already rejected and latched ADR 3, when ADR 1 and ADR 2 disagreed, ELAC reverted to alternate law. The ADR disagree was latched in the ELACs for the remainder of the flight. The ELAC identified the ADR disagree was not due to an angle of attack discrepancy, but from CAS, Mach, or TAS[61] discrepancy.

The SECs[62] also detected CAS discrepancies between ADR 1 and 3 and ADR 1 and 2.

 0655:06

CAS 1 reached peak value of 306 kt. Aircraft pitch angle reached maximum angle.

Engines rejected low-pressure turbine exhaust pressure, P5. No effect on engine performance.

CAS 1 evolution over this period was not consistent with constant engine thrust and pitch angle.

Cruise0701

Aircraft levelled off at FL200.

Thrust levers moved out of climb detent. Thrust lock supressed.

 0706:50

Yaw damper 1 was briefly recorded faulty and the following ECAM messages were triggered:

- AUTO FLT RUD TRIM 1 FAULT

- AUTO FLT RUD TRV LIM 2

This was consistent with the reset of FAC 1, which was an action requested in the AUTO FLT RUD TRV LIM SYS procedure.

Flight director 1 became available, but did not automatically reengage, probably because it had been switched off, before the FAC was reset.

 0707 to 0722

Several unsuccessful attempts to reengage the autopilot were made.

Autopilot engagement was prevented by the flight guidance computer because FAC 2 still rejecting all ADR.

At 0721:00, flight director 1 was reengaged.

 0722:00

Yaw damper 2 briefly recorded faulty and the following ECAM message was triggered:

- AUTO FLT RUD TRIM 2 FAULT

This was consistent with the reset of FAC 2, which was an action requested in the AUT FLT RUD TRV LIM SYS procedure.

 0722:36

Flight director 2 automatically reengaged.

Autopilot 1 was reengaged.

In-flight turn-back initiated [Aircraft turned back towards Perth]

Descent0736:25Descent into Perth Airport commenced.
 0743:00

Recorded CAS (at the time CAS 1) started to decrease from 230 kt down to 190 kt over 1 minute and 15 seconds.

The autopilot pitched nose down and the crew increased thrust to maintain target airspeed.

 0743:33FAC and flight guidance computers reject ADR 1 and use ADR 3. Autopilot pitched the aircraft up, indicating that CAS 3 was higher than CAS 1.
 0743:49

CAS (from ADR 1) was still decreasing.

The autopilot was disengaged by a nose-down sidestick input by captain.

 0744:18

Jump in CAS from 190 kt to 247 kt. Corresponding jump in Mach and altitude. Angle of attack values from ADR 1 recorded as invalid.

[This was consistent with the report that the captain switched to ADR 3.]

The autopilot was reengaged 7 seconds later.

 0746:00

The autopilot and both flight directors involuntarily disengaged when both FACs reject all ADR data after a discrepancy between ADR 2 and ADR 3. Autopilot and flight directors remained off for the remainder of the flight.

The following ECAM alerts were triggered:

- AUTO FLT AP OFF

- AUTO FLT RUD TRV LIM SYS

This was likely due to the rejection of ADR 2 because ADR 1 had already been already rejected.

Reset of the FACs, which was part of AUT FLT RUD TRV LIM SYS procedure, was not carried out.

 0755:00

Captain manually flying aircraft.

Flap setting 1 selected.

 0755:03

Stall warning triggered for 6 seconds.

Angle of attack from ADR 2 recorded as 7.4°. For current speed, stall warning threshold was 8°.

Nose-down sidestick inputs of up to ~1/3 of the full forward limit were made by captain.

The following ECAM alert was triggered:

- WINDSHEAR DET FAULT

Windshear fault due to earlier rejection of all ADRs by the FACs. ECAM alert only triggered when in high-lift configuration.

Approach0759:13

Landing gear was extended.

Flight control laws reverted from alternate to direct law.

Landing0700:38Landing carried out by captain in direct l.

Appendix E – Recorded data from 9 September 2015 airspeed anomaly

Appendix E – Recorded data from 9 September 2015 airspeed anomaly. The frame count is a parameter recorded on the FDR that counts in seconds. This count is generated external to the FDR, so when power is removed from the FDR, but other systems have power, the count continues, but is not recorded by the FDR, resulting in steps in the count. If the aircraft is completely powered down, the count resets to zero. Such steps indicate some level of powering down of the aircraft. Source: ATSB

Note: The frame count is a parameter recorded on the FDR that counts in seconds. This count is generated external to the FDR, so when power is removed from the FDR, but other systems have power, the count continues, but is not recorded by the FDR, resulting in steps in the count. If the aircraft is completely powered down, the count resets to zero. Such steps indicate some level of powering down of the aircraft. Source: ATSB

__________

  1. The FCOM provides three ‘layers’ of information. The associated layer is identified in the right hand margin of the FCOM. Layer 1 (L1) is for ‘Need to know’ and presents information that is necessary in the cockpit. L2 is ‘nice to know’ information, provided in order to fully understand the logic of the aircraft and pilot interfaces. L3 is ‘detailed’ information that are not necessarily needed in flight. L1 is the default level, so is not necessarily identified in the text of FCOM.
  2. Elevator aileron computers – a flight control system computer
  3. Flight augmentation computer – a flight control system computer
  4. Latched means that the system has locked out the parameter from being used again until the system is reset. If the parameter is not latched, it can be used again by the systems when it is in agreement with the other ADR values.
  5. True airspeed.
  6. Spoiler elevator computers – a flight control system computer

Safety issues and actions

The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the aviation, industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.

Priority of NAV ADR DISAGREE alert

Safety issue number: AO-2015-107-SI-01

Safety issue description: Although the NAV ADR DISAGREE had more immediate safety implications relating to unreliable airspeed, the ECAM alert priority logic placed this alert below the engine-related faults. As a result, the NAV ADR DISAGREE alert was not immediately visible to the flight crew due to the limited space available on the ECAM display.

NAV ADR DISAGREE procedure

Safety issue number: AO-2015-107-SI-02

Safety issue description: A NAV ADR DISAGREE alert can be triggered by either an airspeed discrepancy, or angle of attack discrepancy. The alert does not indicate which, and the associated procedure may lead flight crews to incorrectly diagnosing the source of the alert when the airspeed is erroneous for a short period and no airspeed discrepancy is present when the procedure is carried out.

Aircraft details

Aircraft details

Manufacturer and model:Airbus A320-231
Year of manufacture:1993
Registration:VH-FNP
Operator:Virgin Australia Regional Airlines
Serial number:0429
Total Time In Service56,671 hours
Type of operation:Passenger - charter
Persons on board:Crew – 9Passengers – 139
Injuries:Crew – NilPassengers – Nil
Damage:None

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2019

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-107
Occurrence date 12/09/2015
Location near Perth
State Western Australia
Report release date 04/04/2019
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Avionics/flight instruments
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Airbus
Model A320-231
Registration VH-FNP
Serial number 0429
Aircraft operator Virgin Australia Regional Airlines
Sector Jet
Operation type Charter
Departure point Perth, WA
Destination Boolgeeda Airport, WA
Damage Nil

Unsafe proximity and radar vector below minimum vector altitude involving a Boeing 777-31HER, A6-EBU, and two 737-838s, VH-VXS and VH-VYE, Melbourne Airport, Victoria, on 5 July 2015

Final report

What happened

On the evening of 5 July 2015, land and hold short operations (LAHSO) were in effect at Melbourne Airport, Victoria. This allowed for simultaneous landings on crossing runways, with the requirement that one aircraft stops well before the intersection of the runways. On this evening, an Emirates Boeing 777 was cleared for an immediate take-off from runway 34 while two Qantas Boeing 737s were on approach to runways 34 and 27. This resulted in the crew of the Boeing 737 on approach to runway 27 initiating a missed approach, followed by the crew of the Boeing 737 on approach to runway 34 being instructed by air traffic control (ATC) to go-around. The Boeing 737 on approach to runway 34 was then radar vectored by ATC below the minimum vector altitude.

What the ATSB found

The ATSB found that, since 2011, Airservices Australia had been aware of the hazard associated with the inability to separate aircraft that were below the appropriate lowest safe altitude at night but had not adequately mitigated it. This resulted in a situation where, in the event of a simultaneous go-around at night during LAHSO at Melbourne Airport, there was no safe option available for air traffic controllers to establish a separation standard and to ensure a mid-air collision did not occur when aircraft were below minimum vector altitude. Though Airservices Australia had implemented a number of preventative controls prior to this occurrence in response to concerns expressed by the Civil Aviation Safety Authority (CASA), a recovery control was not implemented until 2016.

Additionally, the compromised separation recovery training provided to the air traffic controllers employed in the Melbourne ATC Tower did not include a night scenario for missed approaches during LAHSO.

What's been done as a result

Airservices Australia has received an exemption from CASA to radar vector aircraft below the minimum vector altitude at night at Melbourne Airport under certain conditions. Airservices Australia has also instigated a stagger procedure for land and hold short arrival pairs such that aircraft will not come into unsafe proximity in the event of a missed approach. Training in compromised separation recovery at night during LAHSO has also been introduced for Melbourne ATC Tower controllers.

Safety message

Though air traffic controllers have a duty of care to intervene in a situation where they believe that the safety of an aircraft may be in doubt, such interventions can have unintended consequences. When assessing possible actions to address a hazard, the air traffic service provider should consider both preventative and recovery controls. Additionally, simulator training is useful for developing emergency response skills and, as such, should address all credible compromised separation recovery scenarios.

Safety issue and actions

The safety issue identified during this investigation is listed in the Findings and Safety issue and actions sections of this report. The ATSB expects that the safety issue identified by the investigation should be addressed by the relevant organisation. In addressing this issue, the ATSB prefers to encourage the relevant organisation to initiate safety action proactively, rather than to issue formal safety recommendations or safety advisory notices.

Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the aviation industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

The initial public version of these safety issues and actions are repeated separately on the ATSB website to facilitate monitoring by interested parties. Where relevant the safety issues and actions will be updated on the ATSB website as information comes to hand.

Hazard associated with the inability to separate aircraft below the appropriate lowest safe altitude at night

Safety Issue: AO-2015-084-SI-01

Safety issue description:

The hazard associated with the inability to separate aircraft that are below the appropriate lowest safe altitude at night was identified but not adequately mitigated. This resulted in a situation where, in the event of a simultaneous go-around at night during land and hold short operations at Melbourne Airport, there was no safe option available to air traffic controllers to establish a separation standard when aircraft were below minimum vector altitude.

Additional safety actions

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety actions by Airservices Australia in response to this occurrence:

  • Training in night-time compromised separation recovery during LAHSO was completed by all Melbourne Tower controllers in March 2016.
  • On 10 March 2016, an arrival stagger was introduced for LAHSO arrival pairs to ensure that, in the event of a missed approach, the aircraft would not be in unsafe proximity at the runway intersection.

Additional details

Melbourne Aerodrome Control On-the-job Training Instructor details

Initial rating:December 2008
Rating:Melbourne Aerodrome Control
Endorsements:Airways Clearance Delivery, Aerodrome Control, Surface Movement, Coordinator
Qualification:On-the-job Training Instructor
Medical certificate:Valid
Last competency assessment:April 2015

Melbourne Tower Coordinator details

Initial rating:February 1996
Rating:Melbourne Aerodrome Control
Endorsements:Airways Clearance Delivery, Aerodrome Control, Surface Movement, Coordinator
Medical certificate:Valid
Last competency assessment:March 2015

Sources and submissions

Sources of information

The sources of information during the investigation included:

  • Airservices Australia
  • the Civil Aviation Safety Authority
  • the airlines involved
  • flight crew from VH‑VXS, VH‑VYE and A6‑EBU
  • the air traffic controllers involved.

References

Arthur, W., Bennett, W., Stanush, P.L. & McNelly, T.L., 1998, ‘Factors that influence skill decay and retention: A quantitative review and analysis,’ Human Performance, vol. 11, pp. 57-101.

Gibb, R., Gray, R. & Scharff, L., 2010, Aviation visual perception, Ashgate, Surrey, England.

Isaac, A. R. with Ruitenberg, B., 1999, Air traffic control: human performance factors, Ashgate, Aldershot, England.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

Submissions were received from Airservices Australia, the Civil Aviation Safety Authority, the airlines involved, the flight crew from VH‑VXS and VH‑VYE, the Dubai Civil Aviation Authority and the involved air traffic controllers. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

The occurrence

At 1808 Eastern Standard Time[1] on 5 July 2015, an Emirates Boeing 777‑31HER (B777), registered A6‑EBU and flight number 405, conducting a scheduled passenger flight to Changi Airport, Singapore was issued instructions to line up on runway 34[2] (Figure 1) at Melbourne Airport. The instruction was issued by a trainee Melbourne Aerodrome Controller (trainee tower controller)[3] following discussion with her on‑the‑job training instructor (tower OJTI). Also in the Tower were the Melbourne Tower Coordinator (coordinator) and a controller providing both Melbourne Surface Movement Control and Airways Clearance Delivery. At the same time, two Qantas Boeing 737‑838s (B737s) were about 5 NM (9 km) from the threshold of their respective runways under land and hold short operations (LAHSO):[4]

  • the B737 on final for runway 27, registered VH‑VXS (VXS) and flight number 449, was conducting a scheduled passenger flight from Sydney, New South Wales
  • the B737 on final for runway 34, VH‑VYE (VYE) and flight number 819, was conducting a scheduled passenger flight from Canberra, Australian Capital Territory.

Under LAHSO, the B737 tracking to land on runway 34 was required to land and stop before the intersection with runway 27, allowing the other B737 to land on the full length of runway 27.

About 30 seconds later, as the B777 continued to taxi towards the runway, the aircraft was cleared for an immediate take-off.[5] In one continuous movement, the B777 flight crew followed the taxiway lights onto the runway and executed a 90˚ turn to line up on the runway centre line prior to commencing the take-off roll.[6] This manoeuvre took longer than the trainee tower controller and the tower OJTI had anticipated and, by the time the B777 had commenced the take-off roll at 1810, VXS was at about 2.5 NM (5 km) from the runway 27 threshold passing 1,300 ft above mean sea level (AMSL)[7] on descent and VYE was less than 2 NM (4 km) from the runway 34 threshold passing 1,100 ft on descent.

Due to the slower than anticipated speed by the B777 commencing its take-off roll, the trainee tower controller requested the flight crew of VXS to reduce to minimum speed. The flight crew responded that they were at minimum speed. The tower OJTI then asked the trainee tower controller to inform the flight crew of VXS that, in the event of a missed approach, the flight crew were to expedite climb to 4,000 ft as there was ‘traffic departing the crossing runway.’ In response to this transmission, at 1810, the flight crew of VXS advised that they were going around.[8] At that time, VXS was about 1.2 NM (2.2 km) from the runway 27 threshold passing 900 ft on descent and VYE was about 1 NM (2 km) from the runway 34 threshold passing 800 ft on descent.

Figure 1: Melbourne Airport diagram with runways 27 and 34 indicated (green and blue respectively) and the location where the B777 entered runway 34 indicated by a purple arrow

Figure 1: Melbourne Airport diagram with runways 27 and 34 indicated (green and blue respectively) and the location where the B777 entered runway 34 indicated by a purple arrow. Source: Airservices Australia, modified by the ATSB

Source: Airservices Australia, modified by the ATSB

The coordinator expressed concern that the departing B777 was still occupying runway 34 and that a runway separation standard would not be maintained with the arriving VYE.[9] Receiving what he deemed an unsatisfactory response from the tower OJTI, the coordinator then instructed the trainee tower controller to send VYE around.[10] At the same time as the trainee tower controller instructed the flight crew of VYE to go around, at 1811, a runway 34 occupancy caution activated in the Tower because the B777 was still on runway 34 and VYE was less than 15 seconds flight time from the threshold.[11] Two seconds later, the caution upgraded to a warning as VYE was now less than 10 seconds flight time from the threshold descending through 500 ft and the B777 was still on the runway, passing taxiway FOXTROT (Figure 2). At that time, VXS was less than 1 NM (2 km) from the runway 27 threshold climbing through 1,100 ft.

Figure 2: Melbourne Airport diagram with runways 27 and 34 indicated (green and blue respectively), and the location of the B777 (purple arrow) passing taxiway FOXTROT (yellow) at 1810:34

Figure 2: Melbourne Airport diagram with runways 27 and 34 indicated (green and blue respectively), and the location of the B777 (purple arrow) passing taxiway FOXTROT (yellow) at 1810:34. Source: Airservices Australia, modified by the ATSB

Source: Airservices Australia, modified by the ATSB

Seconds later the flight crew of VYE reported that they had commenced the go-around. Surveillance data showed that the B777 was still on runway 34, south of the intersection with runway 27. The trainee tower controller then advised the flight crew of VYE that a B737 (i.e. VXS) was going around on runway 27 but used the incorrect runway identification – runway 34 instead of runway 27.

At 1810:43, as VYE flew over the threshold of runway 34, surveillance data showed the aircraft climbing through 600 ft with the B777 still on the runway, still south of the intersection with runway 27, with VXS less than 0.3 NM (0.6 km) from the threshold of runway 27 climbing through 1,200 ft.

Nine seconds later at 1810:52, as VYE left 1,000 ft on climb overhead runway 34 (Figure 3), the trainee tower controller was instructed to tell the flight crew to turn right onto a heading of 360˚ while the aircraft was below the minimum vector altitude (MVA) of 2,000 ft.[12] At that time, surveillance data showed the B777 north of the runway 27 intersection climbing through 800 ft and VXS overhead runway 27 climbing straight ahead through 1,700 ft. Shortly afterwards, the trainee tower controller issued a wake turbulence caution to the flight crew of VYE[13] in relation to the B777 departing runway 34.

Figure 3: Melbourne Airport diagram showing the location and height of the B777 (purple), VH‑VXS (green) and VH‑VYE (blue) at 1810:52

Figure 3: Melbourne Airport diagram showing the location and height of the B777 (purple), VH‑VXS (green) and VH‑VYE (blue) at 1810:52. Source: Airservices Australia, modified by the ATSB

Source: Airservices Australia, modified by the ATSB

Fourteen seconds later at 1811:18, VYE was just south of runway 27 and climbing through 2,100 ft – now above the MVA of 2,000 ft. All aircraft were now tracking well clear of each other and their flight paths were diverging, with the B777 continuing to Changi and the two 737s being re-sequenced to land at Melbourne Airport without further incident.

At no time was traffic information[14] provided to the flight crew of the B777 regarding either B737.

Airservices Australia (Airservices) surveillance data showed that separation between the two B737s reduced to about 0.9 NM (2 km) and 900 ft as VXS crossed runway 34 in front of VYE, climbing in the missed approach on runway 27. At that time, VYE was also climbing, conducting a go-around from runway 34. The tower controller was responsible for maintaining a separation standard and the only available standard was visual.[15] However, due to the limitations of human vision at night[16] and the disposition and trajectory of traffic at the time, visual separation could not be assured.

__________

  1. Eastern Standard Time (EST): Coordinated Universal Time (UTC) + 10 hours.
  2. Runway number: the number represents the magnetic heading of the runway.
  3. See the section titled On-the-job instruction.
  4. See the section titled Land and hold short operations.
  5. Immediate take-off: A clearance for immediate take-off may be issued to an aircraft before it enters the runway. On acceptance of such clearance the aircraft shall taxi out to the runway and take off in one continuous movement.
  6. See the section titled Entering runway 34.
  7. Above mean sea level (AMSL): the elevation (on the ground) or altitude (in the air) of an object, relative to the average sea level datum. Unless stated otherwise, all heights referenced in this report are AMSL.
  8. Go-around: a standard manoeuvre in which flight crew discontinue the approach, increase power and reconfigure the aircraft to climb. See also the section titled Missed approach and go-around.
  9. See the section titled Runway separation standard.
  10. See the section titled Controller best judgement and duty of care.
  11. See the section titled Advanced Surface Movement Guidance Control System.
  12. Minimum vector altitude (MVA): the lowest altitude a controller may assign to a pilot in accordance with a radar terrain clearance chart that has resulted from a survey of obstacles in the area.
  13. See the section titled Wake turbulence separation standard.
  14. See the section titled Traffic information.
  15. Visual separation standard: A means of spacing aircraft using visual observation by a tower controller, or by a pilot when the pilot is assigned separation responsibility.
  16. See the section titled Vision at night.

Context

Personnel information

The Melbourne Tower (Tower) was staffed by four Airservices air traffic controllers, the:

  • trainee Melbourne Aerodrome Controller (trainee tower controller)
  • Melbourne Aerodrome Control on-the-job training instructor (tower OJTI)
  • Melbourne Coordinator (coordinator)
  • a controller performing the combined duties of the Melbourne Surface Movement Controller and the Melbourne Airways Clearance Delivery Controller.

With the exception of the trainee tower controller, each controller was correctly endorsed and no fatigue‑related issues were identified. The tower OJTI and the coordinator were also endorsed in all Tower control positions.

The trainee tower controller was on her fourth under-training shift and had not used or observed land and hold short operations (LAHSO) before. Though she had 11 years’ experience working in busy control towers overseas, the trainee tower controller held no endorsements at Melbourne Airport.

All controllers had completed the Tower-specific compromised separation recovery training.[17]

The flight crew from the three involved aircraft were correctly licenced and fit for duty.

Entering runway 34

A senior Tower controller reported that, during the day, most aircraft line up on runway 34 by following the runway 16 taxi-off markings (in yellow on Figure 4), entering the runway via a curve. Some aircraft also follow this path at night, but some follow the taxiway lighting onto runway 34, resulting in a 90˚ turn to line up in the departure direction (in orange on Figure 4).

Figure 4: Threshold of runway 34 at Melbourne Airport, showing the curved line-up track in yellow, and the track in orange that follows the taxiway lighting

Figure 4: Threshold of runway 34 at Melbourne Airport, showing the curved line-up track in yellow, and the track in orange that follows the taxiway lighting. Source: Google Maps, modified by the ATSB
Source: Google Maps, modified by the ATSB

The trainee tower controller and the tower OJTI both reported that, when issued with a clearance for an immediate take-off, they had expected the Boeing 777‑31HER (B777) to line up via the curved entry to runway 34. The controllers believed that by entering runway 34 via a 90˚ turn, the B777’s take-off was delayed.

‘Cleared for an immediate take-off’, is an internationally used phrase that requires the flight crew to taxi onto the runway and take off in one continuous movement. It does not specify the runway entry technique.

The B777 flight crew later reported that they did taxi out and take off in one continuous movement and recorded data supports this. Further, the operator advised that, as performance calculations required the full length of the runway, the 90-degree line up manoeuvre was required.

Missed approach and go-around

When, for any reason, flight crew judge that an approach cannot be continued to a successful landing, a missed approach or go-around is flown. For this reason, a clearance to land authorises the flight crew to go-around or carry out a missed approach. An approach may be discontinued for a number of reasons including:

  • The required visual references have not been established by the decision altitude/height or minimum descent altitude/height or is acquired but is subsequently lost.
  • The approach is, or has become, unstable.
  • The aircraft is not positioned so as to allow a controlled touchdown within the designated runway touchdown zone with a consequent risk of aircraft damage with or without a runway excursion if the attempt is continued.
  • The runway is obstructed.
  • Landing clearance has not been received or is issued and later cancelled.
  • A go-around is being flown for training purposes.

A missed approach procedure is designed for each instrument approach to provide terrain and obstacle protection. When flight crew conduct a missed approach from a visual approach, they must initially remain on runway track and remain visual until re-cleared by the controller. As the flight crew must reconfigure the aircraft during the missed approach, workload can be high.

Land and hold short operations

To improve airport capacity and air traffic system efficiency, LAHSO involves aircraft landing and holding short of an intersecting runway (see Figure 1 for the runway configuration at Melbourne Airport) while another aircraft takes off or lands on an intersecting runway. At Melbourne Airport, the landing rate during LAHSO is about 44 aircraft per hour, and about 24 when LAHSO is not in use. Also used in Canada and the US, in Australia LAHSO is only available to operators who have received authorisation from the Civil Aviation Safety Authority to participate in the procedure. During LAHSO, the aircraft issued a hold short requirement is classified as the ‘active participant’, and the aircraft which has unrestricted use of the full length of the crossing runway is classified as the ‘passive participant’. Under LAHSO, simultaneous take-off and landing is permitted only during the day, but simultaneous landings are permitted day and night. In Australia, with the exception of one operator, foreign-operated aircraft are not permitted to participate in LAHSO.

LAHSO has been used in Australia for over 20 years and, at the time of the occurrence, was used at Adelaide, Darwin and Melbourne airports. The procedure is used by day only at Darwin Airport[18] as the crossing runway, runway 18/36, is not lit at night. Following an Airservices review of this occurrence, LAHSO is no longer used at night at Adelaide Airport. At Melbourne Airport, on the day of the occurrence, end of civil twilight was 1743, about half an hour prior to the occurrence.

LAHSO was only conducted when certain cloud base and visibility conditions existed – the cloud base, or ceiling, must not be less than the minimum vector altitude (MVA) within 8 NM (15 km) of the Airport and the visibility not less than 8 km. With an elevation of 434 ft and the highest MVA within 8 NM (15 km) being 2,400 ft, the minimum cloud base for LAHSO at Melbourne Airport was 2,000 ft above ground level. Documentation also required that the Automatic Terminal Information Service broadcast include advice that LAHSO was in progress and stipulate which runway was in use for both arriving and departing aircraft, and which was for arriving aircraft only. All of these requirements were met on the night of this occurrence.

On occasions, an aircraft may require the ‘landing only’ runway for departure, referred to as an off‑mode departure. Managing arriving and departing aircraft operating under LAHSO is made more complex when an off-mode departure is required.

To ensure LAHSO participants are aware of the other aircraft, specific phraseology is stipulated. When landing is approved for an active participant during LAHSO, the following phraseology is used:

  • Controller: ‘(callsign) (other aircraft type) departing (or landing) on crossing runway, hold short runway (number) cleared to land runway (number)’
  • Flight crew: ‘hold short runway (number) cleared to land runway (number) (callsign)’

The phraseology used for the passive participant is:

  • Controller: ‘(callsign) (other aircraft type) landing on crossing runway will hold short cleared to land (or to take-off) runway (number)’
  • Flight crew: ‘cleared to land (or take-off) runway (number) (callsign)’

Additionally, during LAHSO, the tower controller is responsible for maintaining visual separation in the event of a missed approach or a dual missed approach. This is until such time as another separation standard can be applied, either 3 NM (6 km) or 1,000 ft.

Runway separation standard

For the aircraft involved in this occurrence, separation standards require that the aircraft landing behind a departing aircraft cannot cross the runway threshold until the preceding aircraft is airborne and:

  • has either commenced a turn, or
  • is beyond the point on the runway at which a landing aircraft could be expected to complete its landing roll and there is sufficient distance to enable the landing aircraft to manoeuvre safely in the event of a missed approach.

Wake turbulence separation standard

In addition to providing runway separation, wake turbulence[19] standards must also be applied for aircraft departing or going around behind another aircraft. Separation is either time- or distance-based, and is determined by the wake turbulence categories of the aircraft involved. The maximum take-off weight of the B777 place the aircraft in the heavy aircraft category, and the B737‑838 in the medium category. The time-based standard between the aircraft was 2 minutes, and the applicable distance standard is 5 NM (9 km). As Melbourne is a radar tower environment, only the distance standard was applicable.

A wake turbulence standard is not required between an aircraft landing behind an aircraft taking off on the same runway. If the landing aircraft, however, conducts a missed approach behind one departing, the aircraft in the missed approach is considered a departing aircraft. As the trainee tower controller did on this occasion, the controller should issue a wake turbulence caution to the flight crew of a following aircraft when less than the applicable wake turbulence standard exists.

Traffic information

Traffic information is issued by an air traffic controller to alert flight crew to other known or observed traffic. This traffic may be in proximity to the position or intended route of the aircraft, and the issued traffic information helps the flight crew avoid a collision. Traffic information should be provided when, in the controller’s judgement, one aircraft may observe another aircraft and could be uncertain of their intention.

Traffic information should be concise and, to assist flight crew in identifying other aircraft, may include the following information if deemed relevant by the controller:

  • aircraft identification
  • type and description, if unusual
  • position information
  • direction of flight or route of the aircraft
  • level
  • intentions of the pilot.

The provision of traffic information, and the content of that information, is reliant on the controller’s assessment of the underlying need.

Compromised separation recovery training

Compromised separation recovery actions are important emergency response actions. They need to be implemented by controllers promptly and accurately when determined that separation standards have been, or will shortly be, compromised. To ensure emergency response actions are conducted effectively, they need to be regularly practiced. Skill decay is more likely to occur when tasks are rarely performed (Arthur et al., 1998), as is the case for compromised separation recovery actions during actual controlling.

Controllers are required to issue safety alerts to pilots of aircraft as a priority when the controller becomes aware that aircraft are considered to be in unsafe proximity. This is the case unless a pilot advises that action is being taken to resolve the situation, or that the other aircraft is in sight. No safety alerts were issued by the trainee tower controller during this occurrence.

An ATSB investigation into a loss of separation assurance near Tindal, Northern Territory in 2014 found that Airservices had not provided controllers with effective simulator-based compromised separation recovery training. This report, ATSB investigation AO-2014-074Loss of separation assurance involving A 330 9VSTQ and A320 VHVFH near Tindal, Northern Territory on 24 April 2014, available on the ATSB website, was not released until May 2016, after the occurrence under investigation here.

Vision at night

The tower controller can provide heading information to flight crew to establish and/or ensure separation in the event of a missed approach and, if the aircraft is below the MVA, by day the controller can transfer the responsibility for terrain clearance to the flight crew. As the human visual perceptual system, however, is physiologically limited in perceiving within a night-time environment (Gibb et al., 2010), the responsibility for terrain clearance when an aircraft is being radar vectored at night must remain with the controller.

Another issue discussed by Gibb et al. relates to flight crew susceptibility to glare from bright city lights during approach and landing at night. A review of US investigation reports into accidents and incidents from 1978 to 2005 found 58 documented vision-related accidents and incidents, with 93 per cent occurring during the approach and landing phase.

Additionally, because of the absence of any size cues at night (i.e. at night the apparent size of an object is related to its brightness rather than its image size) the judgement of distance is extremely difficult (Isaac and Ruitenberg, 1999). In providing visual separation, controllers should rely primarily on azimuth; for example, one aircraft to the northwest and another to the northeast. To ensure that aircraft are not in close proximity, caution should be exercised when using a judgement of relative distance or height for visual separation.

Though flight crew can sight and monitor another aircraft at night, the physiological limitations limit their ability to visually separate. These same physiological limitations hinder a controller’s ability to monitor aircraft at night visually, both when attempting to separate visually and in determining if an aircraft is on the runway or airborne.

Controller best judgement and duty of care

The Civil Aviation Safety Regulations Part 172 contains the standards for the provision of air traffic services. The regulations include advice that:

…the provider may deviate from the standards if an emergency, or other circumstance, arises that makes the deviation necessary in the interests of aviation safety.

The Manual of Air Traffic Services[20] includes:

Best Judgement. Do not allow anything in these instructions to preclude you from exercising your best judgement and initiative when:

a. The safety of an aircraft may be considered to be in doubt: or

b. A situation is not covered specifically by these instructions.

The Airservices National Air Traffic Service Procedure Manual[21] includes:

Duty of care. Upon becoming aware of information such that it would be reasonable to conclude that an unsafe situation has, or may occur, it would be expected that all necessary action is taken to remove that risk.

Note: The extent of the action required will be driven by professional judgement given the particular circumstances and would include an assessment of the likelihood of the event occurring and the potential severity of the outcome.

Further, the National Air Traffic Service Procedure Manual includes:

Reasonable assurance. A controller’s professional judgement that they have ‘reasonable assurance’ of achieving a particular separation standard requires them to be certain that:

a. The disposition and relative performance of all aircraft, vehicle or persons concerned are such that at all times and under normal operation the separation between them will not be less than that mandated;

b. If the anticipation of an aircraft, vehicle or person operating in the expected way is essential to achieving separation then that aircraft, vehicle or person is provided with sufficient information to make them aware of the dependency; and

Any equipment, the continued operation of which is necessary to assure separation, is operating within normal parameters and there is no reason to expect that the serviceability or performance will change.

On-the-job instruction

Air traffic control training comprises theoretical, simulator and on-the-job components. On-the-job instruction is conducted in the workplace by specially trained instructors. The trainee may move through control positions in a hierarchical manner – for example Surface Movement Control then Aerodrome Control (tower), although the trainee involved in this occurrence had started as a tower trainee.

Airservices stated that the overriding principle for an OJTI is that safety must never be compromised. The training for OJTI also included information about the types of errors to be expected:

  • Those that must be prevented as they would compromise safety
  • Those that must be corrected immediately
  • Those where correction can be delayed as the trainee could learn from the outcome
  • Those that result from a lack of experience where correction is not necessary.

Intervention strategies for an OJTI range from questioning the trainee, to suggesting an alternate course of action, to directing the trainee, and finally to intervening by taking over or overriding the trainee. Intervention is the last resort and only used to ensure safety.

While conducting training, overall responsibility for the provision of a safe and efficient air traffic service resides with the OJTI, as the trainee is either not licenced or not endorsed. During the training period, the trainee will be given more and more responsibility for the control and separation of aircraft, but the OJTI must monitor the trainee’s performance and ensure that any errors or omissions that may impact safety can be corrected in a timely manner. To facilitate this, the communication system provides a facility to enable the OJTI to override the trainee’s transmissions.

Advanced Surface Movement Guidance Control System

The Melbourne Tower is fitted with an integrated tower automation suite that presents information to controllers by way of a number of computer screens. Different integrated tower automation suite installations exist to incorporate the differing automation available in control towers across Australia. The Melbourne Airport integrated tower automation suite incorporates an Advanced Surface Movement Guidance Control System – a system that provides the controller with surveillance data for vehicles and aircraft on the ground, and airborne aircraft in the immediate vicinity of the Airport. The Advanced Surface Movement Guidance Control System generates aural alerts based on two logics:

  • Time to threshold for an arrival on a single runway if the Advanced Surface Movement Guidance Control System detects a vehicle or aircraft (targets) on that runway:
    • Caution: 15 seconds from that runway’s threshold
    • Warning: 10 seconds from that runway’s threshold.
  • Target to target where a collision risk exists between two targets.

In addition to the aural caution and warning, the controller also received a visual representation of the caution and warning alerts.

On receipt of an Advanced Surface Movement Guidance Control System caution or warning, the controller is required to scan the aerodrome traffic immediately to assess the integrity of the alert. If required, the controller should then issue traffic advice, control instructions and/or a safety alert. Though the controller did not issue any traffic or safety alerts, she had already instructed the B737 on final for runway 34 to go around prior to the activation of the caution and the warning.

Airborne collision avoidance system limitations

Regular public transport aircraft are fitted with airborne collision avoidance systems (ACAS) that, independently of any ground-based air traffic control system, provide collision avoidance protection by advising flight crew of traffic in their immediate area. Traffic advisories (TAs) provide a visual representation of the proximate traffic to assist flight crew to sight that aircraft. Resolution advisories (RAs) provide recommended vertical escape manoeuvres (either climb or descend) to either increase or maintain existing vertical separation between aircraft. When the two aircraft involved are capable of RAs, ACAS uses data from both aircraft to determine the best solution and issues coordinated and complimentary RAs to the flight crew – one to climb and the other to descend. Consequently, flight crew are taught to respond to an RA regardless of any instruction from a controller.

The collision system logic is complex and is based on sensitivity levels, time intervals to the closest point of approach and the size of the protected volume around the aircraft. Critically, the sensitivity level is based on the altitude of the aircraft and, below 1,000 ft above ground level, RAs are inhibited and TAs are only issued when the proximate aircraft is within 20 seconds to the closest point of approach. In this occurrence, with Melbourne Airport at 434 ft, RAs would not have been issued when the aircraft were below 1,434 ft, i.e. during the time of their closest proximity.

ACAS is considered the last line of defence against a mid-air collision and should not be relied on as a separation method.

Terrain awareness and warning systems

Regular public transport aircraft are also fitted with terrain awareness and warning systems (TAWS). This system relates aircraft position, which should be from a GPS source which can be internal to the equipment or fed from the aircraft flight management system, to an almost worldwide terrain/obstacle/airport database which the equipment manufacturer regularly updates. A comprehensive set of reliable cautions and warnings can be generated which use both the radio altimeter and relative position. TAWS provides a forward looking terrain avoidance function that looks ahead of the aircraft along and below its lateral and vertical flight path and provides suitable alerts if a potential controlled flight into terrain threat exists.

Like the ACAS, a TAWS is considered the last line of defence against controlled flight into terrain and should not be relied on as a separation method.

Previous occurrences

In October 2011, at Melbourne Airport, at night and during LAHSO, an aircraft on final to land on runway 34 conducted a missed approach while another aircraft was landing on runway 27. As the aircraft in the missed approach was below the MVA, the controller was unable to issue a radar vector to ensure separation. The occurrence was reported but ATSB did not investigate.

__________

  1. See the section titled Compromised separation recovery training.
  2. Air traffic services at Darwin Airport are provided by the Department of Defence.
  3. Wake turbulence: turbulence from wing tip vortices that result from the creation of lift. Those from large, heavy aircraft are very powerful and persistent, and are capable of causing control difficulties for smaller aircraft either following or below.
  4. Manual of Air Traffic Services (MATS): MATS is a joint document of the Department of Defence (Defence) and Airservices Australia (Airservices) and is based on the rules published in the Civil Aviation Safety Authority Civil Aviation Safety Regulations Part 172 – Manual of Standards (MOS) and the International Civil Aviation Organization (ICAO) standards and recommended practices, combined with rules specified by Defence and Airservices. The requirements and obligations details in MATS are in accordance with provisions and regulations of the Air Navigation Act 1920, Air Services Act 1995, and Defence Instructions.
  5. National Air Traffic Service (ATS) Procedure Manual (NAPM): NAPM details the procedures used by Airservices Australia to standardise service delivery when using ATS system tools and must be applied to all ATS units.

Safety analysis

At night on 5 July 2015, three aircraft came into unsafe proximity during take-off and landing at Melbourne Airport, Victoria. Shortly afterwards, one aircraft was radar vectored in a missed approach while below the minimum vector altitude (MVA). This analysis discusses the relevant controller actions and the organisational issues identified during the investigation.

Use of runway 34 for off-mode departures

Sequencing for arriving aircraft at Melbourne Airport has been computerised to ensure consistency and efficiency. The sequencing tool, MAESTRO, is used by Airservices at a number of airports and uses the actual position and speed information from their surveillance system to determine each aircraft’s landing runway and position in the sequence. This information is displayed to the controllers to enable them to use speed control, vectoring or holding to achieve an orderly traffic flow.

When land and hold short operations (LAHSO) are in place for runways 27 and 34, both runways are available for arriving aircraft, but only runway 27 is available for departing aircraft. Some larger aircraft, however, require runway 34 for departure due to its greater length. Additionally, runway 34 can be more attractive to departing aircraft due to a shorter taxi distance, or the runway being better aligned to their departure direction.

MAESTRO builds a gap into the runway 27 arrival sequence to allow for departing aircraft. Aircraft departing from runway 34 are considered off-mode during LAHSO, and a controller must fit departures into the arrival sequence based on their best judgement. For the aircraft involved in this occurrence, runway separation requires that a landing aircraft cannot touch down until the preceding departing aircraft, using the same runway, is airborne.

On the night of this occurrence, in the gap between arrivals sequenced to runway 34, one off‑mode departure had already used runway 34 prior to the B777 being lined up. Though the flight crew of the B777 had received the current Automatic Terminal Information Service[22] stating that LAHSO were in use, being an international operator, the flight crew may not have been aware that both runways at Melbourne Airport were being used for simultaneous arrivals and they were not told about the B737s on final for both runways.

In a statement, the captain of the aircraft on final for runway 27, VH‑VXS (VXS), reported he had heard the instruction to the B777 for an immediate departure. After observing the preceding aircraft depart from runway 34, he believed that his aircraft would be in close proximity to the B777 when they landed, so he had asked the first officer to prepare for a missed approach. Shortly after, and having determined that there was insufficient spacing with the B777, the captain instructed the first officer to initiate a missed approach as the B737 was approaching 500 ft above ground level.

The coordinator became concerned about the sequence when he realised that the flight crew of the B777 had not been advised of the B737 (VXS) going around from final runway 27. Due to the limitations of human vision at night, judgement of distance is extremely difficult, and the coordinator was concerned that the B777 flight crew may have elected to initiate a rejected take-off if they perceived the B737 as a possible threat. If the B777 had rejected the take-off and remained on the runway, there may have been insufficient runway behind that aircraft for the landing roll of the B737 on final for runway 34, VH‑VYE (VYE). Additionally, the coordinator was concerned that there was a high probability that the runway separation standard would not be achieved between the B777 and VYE.

The coordinator communicated his concerns to the trainee tower controller and the tower OJTI. On receiving what he deemed an unsatisfactory response, and believing the situation to be safety‑ and time‑critical, the coordinator instructed the trainee tower controller to send VYE around. The trainee tower controller and the tower OJTI later reported that, as the B777 commenced the take-off roll, they also had concerns about the sequence and the potential for a loss of separation between the two aircraft using runway 34. However, immediately prior to that they both thought that the sequence, while ‘tight’, would work. In that context, if separation relies on an expected rate of aircraft ground movement that may not occur, it is prudent to have an alternative plan. This is more important if the involved aircraft is large and/or operated by international flight crew who may be less familiar with the airport. However, on this occasion the actions of the B777 flight crew were appropriate.

Given the specific LAHSO phraseology required to be used by the Tower controller, and the necessity for a read back by the flight crew of VYE of the restriction to hold short, there may have been insufficient time available for the trainee tower controller to clear both arriving aircraft to land. The trainee tower controller, on her first exposure to LAHSO, had about 29 seconds to:

  • issue a landing clearance to the flight crew of VYE, including the restriction to hold short of runway 27
  • receive a correct read back of the restriction from the flight crew
  • issue a landing clearance to the flight crew of VXS, including advice that VYE was landing on runway 34 but would hold short of runway 27.

Had the line-up and take-off clearance for the B777 been delayed, the two B737s would have landed under LAHSO and the B777 could have then departed without any time pressure. Alternatively, the provision of traffic information on the two B737s to the flight crew of the B777 would have made them aware of the traffic situation and provided the option of expediting their departure or remaining clear of the runway.

Unsafe proximity

Two aircraft arriving simultaneously for different runways during LAHSO are separated by the requirement that one aircraft lands and stops prior to the intersection of the runways. When one or both aircraft however, conduct a missed approach, another separation standard is required. The only available standard was visual. As both aircraft were tracking towards the runway intersection, the controller could not be assured that visual separation would be maintained as the judgement of distance at night is limited by the physiology of the human eye.

Airservices surveillance data showed that separation between the two B737s reduced to about 0.9 NM (2 km) and 900 ft as VXS crossed runway 34 in front of VYE, as VXS climbed in the missed approach on runway 27. At that time, VYE was also climbing, conducting a go-around from runway 34. The tower controller was responsible for maintaining visual separation; however, due to the limitations of its application at night, a surveillance (radar) separation standard of 3 NM (6 km) or 1,000 ft was arguably more appropriate.

As a clearance to land is also a clearance to conduct a missed approach, controllers should have a plan for such an eventuality and act on that plan in a timely manner.

The action of the coordinator in instructing the trainer tower controller to send VYE around changed what was a potential loss of runway separation into a loss of separation between airborne aircraft.

Radar vectors

Though VYE, while going around on runway 34, did not fly through the flight path of the B777 as it executed the go-around, it was 1.5 NM (3 km) behind the B777 instead of the required wake turbulence standard of 5 NM (9 km). The radar vector and caution were issued by the trainee tower controller to expedite the re-establishment of a standard. Additionally, the radar vector increased the divergence between the flight paths of the two B737s when VXS was 0.9 NM (2 km) ahead of VYE and 900 ft above, passing from the right to left.

When an aircraft is vectored by a controller, the responsibility for navigation and terrain clearance is transferred from the flight crew to the controller. A MVA is calculated to ensure terrain clearance at the stated minimum levels and vectoring below the MVA would only be conducted in an emergency situation. At the time of the occurrence, the coordinator believed that the situation was both time- and safety-critical, and he deemed that issuing a radar vector below MVA was the only course of action available, and that action had earlier been sanctioned by his manager.[23] As such, he told the trainee controller to issue the radar vector to the flight crew of VYE.

Hazard assessment and mitigation strategies

Following correspondence from the Civil Aviation Safety Authority (CASA) prior to October 2011 about concerns in relation to separating aircraft below the appropriate lowest safe altitude at night during two-runway operations at Brisbane Airport, Airservices had suspended that type of operation at Brisbane. As stated earlier,[24] in 2011 one of a LAHSO arrival pair at Melbourne Airport conducted a go-around at night and the controller was unable to radar vector to ensure separation. The day after the 2011 occurrence at Melbourne Airport, CASA again wrote to Airservices requesting an explanation as to:

… what safety precautions are in place to ensure the safety of aircraft participating in LAHSO at night and why this procedure should not be suspended at night until the safety study … is completed.

In a letter to Airservices a week later, CASA stated:

… the (air traffic management) system should not rely, as a primary means of defence, on vectoring or heading changes for (instrument flight rules) category aircraft at night that are below the appropriate minimum altitude.

The safety study referenced in CASA’s initial letter was published by Airservices in October 2012 and included two relevant hazards:

  • Hazard 901/1 – a go-around at night causing a loss of the ability of controllers to provide separation.
  • Hazard 901/10 – two aircraft perform a go-around.

At the time of the safety study’s publication, two controls had been put in place to address Hazard 901/1:

  • cloud ceiling increased to the MVA
  • the visibility standard increased to 8 km (4 NM).

Only the first of the following controls identified for Hazard 901/10, however, had been met:

  • Only conduct LAHSO at aerodromes and at times when a reasonable benefit is being realised and these times or conditions to be identified in (local instructions).
  • Formalise sequencing intervals or cut off distances to reduce likelihood of go-arounds during LAHSO caused by an occupied runway.
  • Implement procedures to reduce pilot initiated go-arounds due to unstable approach for which there is (a controller) attribution.

CASA continued to express concern in relation to aircraft separation following a go-around at night, early in 2013 providing a discussion paper again articulating concerns about the safety of aircraft below MVA and providing options, including the instigation of a stagger between LAHSO arrival pairs. In April 2013, Melbourne Tower controllers also expressed concerns and were advised by management that radar vectoring below MVA at night was acceptable as a last resort.

In January 2015, following a CASA audit of LAHSO at Melbourne Airport, they made the following observation:

To reduce the risk of aircraft in close proximity, CASA requests that Airservices review the procedures to achieve separation assurance following a double go-around, especially the ability of the tower controller to provide visual separation in certain meteorological conditions.

Airservices ‘noted’ the finding and determined that the issue was being considered in an extant review of LAHSO at Melbourne Airport.

Airservices suspended night LAHSO at Melbourne Airport in November 2015, 4 months after this occurrence. An Airservices survey of obstacles later confirmed that limited radar vectors below MVA did not pose a hazard to aircraft at night, and, in April 2016, CASA issued an exemption to Airservices to radar vector below MVA at night at Melbourne Airport as long as a number of conditions were met. The CASA exemption is limited to aircraft involved in LAHSO. That day, night LAHSO was reintroduced at Melbourne Airport. Another control instigated by Airservices in early 2016, though recommended by CASA in early 2013, was a stagger for arriving LAHSO pairs:

to reduce the risk of two aircraft being in ‘unsafe proximity’ (i.e. passing the runway intersection within 20 seconds of each other) in the case of a double go-around.

Though Airservices was aware of the hazard from at least October 2011, as noted by CASA, in early 2013 the only controls put in place or proposed were preventative in nature i.e. designed to reduce the risk of an aircraft conducting a missed approach at night during LAHSO at Melbourne Airport. Not until 2016 did Airservices put in place a recovery control[25] – a surveyed area where aircraft could be radar vectored when below MVA at night. Had Airservices pursued a recovery control after the 2011 occurrence, the radar vector issued by the trainee tower controller would have been in accordance with documented procedure and training, and would not have resulted in a breakdown of separation with terrain.

Compromised separation recovery training

At the time of this occurrence, the compromised separation recovery training for Melbourne Tower controllers was conducted in a simulator, using various scenarios relevant to Melbourne Airport.

Though one training scenario involved aircraft conducting missed approaches from both runways under LAHSO, the scenario was during daylight hours. As LAHSO is only conducted in visual meteorological conditions, during the day the controller can assign the responsibility for terrain clearance to the flight crew when radar vectors were issued below the MVA.

At night when radar vectoring, the controller must retain the responsibility for terrain clearance. No LAHSO-related simulator training scenarios were at night, though night-time scenarios have now been added.

__________

  1. Automated Terminal Information Service (ATIS): The provision of current, routine information to arriving and departing aircraft by means of continuous and repetitive broadcasts during the hours when the unit responsible for the service is in operation.
  2. See the section titled Hazard assessment and mitigation strategies.
  3. See the section titled Previous occurrences.
  4. Recovery control: designed to recover a critical situation to a safe outcome.

Findings

From the evidence available, the following findings are made with respect to the unsafe proximity and radar vector while below the minimum vector altitude involving a Boeing 777‑31HER, registered A6-EBU, and two Boeing 737‑838s, registered VH‑VXS and VH‑VYE, at Melbourne Airport on 5 July 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • The decision to clear the flight crew of A6‑EBU for an immediate take-off, combined with the aircraft’s slower than anticipated rate of movement, resulted in it coming into proximity with VH‑VXS and VH‑VYE.
  • The proximity between A6‑EBU, VH‑VXS and VH‑VYE resulted in the flight crew of VH-VXS on final for runway 27 electing to go around and the flight crew of VH-VYE on final for runway 34 being instructed to go around on the direction of the Melbourne Coordinator.
  • Although initiated due to a safety concern, the decision by the Melbourne Coordinator to instruct the crew of VH‑VYE to go around resulted in an airborne loss of separation compared to a potential loss of separation on the ground.
  • The simultaneous go-arounds conducted by VH-VYE and VH-VXS, sequenced to land on intersecting runways under land and hold short operations at Melbourne Airport, resulted in the controller issuing a radar vector to the flight crew of VH-VYE while the aircraft was below minimum vector altitude to assure surveillance and wake turbulence separation.
  • The radar vector issued at night to the flight crew of VH-VYE when no other options were available, though intended to ensure wake turbulence and surveillance separation behind A6‑EBU and separation assurance with VH-VXS, did not assure terrain and obstacle clearance.
  • The hazard associated with the inability to separate aircraft that are below the appropriate lowest safe altitude at night was identified but not adequately mitigated. This resulted in a situation where, in the event of a simultaneous go-around at night during land and hold short operations at Melbourne Airport, there was no safe option available for air traffic controllers to establish a separation standard when aircraft were below minimum vector altitude. [Safety issue]

Other factors that increased risk

  • The lack of night-time compromised separation training scenarios for the Melbourne Air Traffic Control Tower controllers increased the risk of the controllers responding inappropriately when aircraft were in proximity at night.
  • The automated sequencing system used by Airservices Australia at Melbourne Airport (MAESTRO) did not ensure that two aircraft would not arrive at the intersection of the runways at the same time during land and hold short operations, increasing the risk of unsafe proximity at the intersection.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-084
Occurrence date 05/07/2015
Location Melbourne Airport
State Victoria
Report release date 06/08/2018
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Flight below minimum altitude
Occurrence class Incident
Highest injury level None

Aircraft details

Manufacturer The Boeing Company
Model 777-31HER
Registration A6-EBU
Serial number 34484
Aircraft operator Emirates
Sector Jet
Operation type Air Transport High Capacity
Departure point Melbourne, Vic.
Destination Changi, Singapore
Damage Nil

Aircraft details

Manufacturer The Boeing Company
Model 737-838
Registration VH-VXS
Serial number 33725
Aircraft operator Qantas Airways Ltd.
Sector Jet
Operation type Air Transport High Capacity
Departure point Sydney, NSW
Destination Melbourne, Vic.
Damage Nil

Aircraft details

Manufacturer The Boeing Company
Model 737-838
Registration VH-VYE
Serial number 33993
Aircraft operator Qantas Airways Ltd.
Sector Jet
Operation type Air Transport High Capacity
Departure point Canberra, ACT
Destination Melbourne, Vic.
Damage Nil

Technical assistance to Recreational Aviation Australia in the examination of a fractured eyebolt from the collision with terrain involving a Fasterway Powered Parachute, near Theodore, Queensland, on 30 May 2015

Final report

On 30 May 2015, a Fasterway powered parachute, recreational registration 19-7677, collided with terrain near Theodore, Queensland. The pilot, the sole occupant, died as a result of the accident.  

As part of its assistance to Queensland Coronial authorities, Recreational Aviation Australia (RA-Aus) requested technical assistance from the Australian Transport Safety Bureau (ATSB) in the visual examination of a fractured bolt from the powered parachute (Figure 1). The bolt and associated eyenut was one of four assemblies that attached the parachute to the frame of the aircraft.

To protect the information supplied by RA-Aus to the ATSB and the ATSB's investigative work to provide the requested assistance, the ATSB initiated an investigation under the Transport Safety Investigation Act 2003.

Figure 1: Submitted eyenut and fractured bolt

Submitted eyenut and fractured bolt

Source: ATSB

The fracture surface was smooth, flat, and perpendicular to the principal axis of the bolt. Crack progression marks (beach marks) extended radially from one side of the bolt and covered approximately 90% of the fracture surface area (Figure 2). The remaining small region towards the outer edge of the bolt exhibited features consistent with an overstress failure. The large area of fatigue cracking and small overstress area indicated that failure of the bolt was due to high cycle low stress fatigue cracking.

Figure 2: Bolt fracture surface showing evidence of fatigue crack progression (beach) marks

Bolt fracture surface showing evidence of fatigue crack progression (beach) marks

Source: ATSB

The above information was provided to RA-Aus. At the request of the Coroner, no further work was undertaken by the ATSB.

The information contained in this web update is released in accordance with section 25 of the Transport Safety Investigation Act 2003.

Occurrence summary

Investigation number AE-2015-075
Occurrence date 30/05/2015
Location Theodore
State Queensland
Report release date 15/01/2016
Report status Final
Investigation level Defined
Investigation type External Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Model Fasterway powered parachute
Registration 19-7677
Sector Sport and recreational
Operation type Sports Aviation
Departure point Theodore, Qld
Damage Substantial

VFR into IMC involving a PA28 aircraft, VH-TAU, near Latrobe Valley Airport, Victoria, on 8 September 2015

Final report

What happened

Flight planning

On the morning of 8 September 2015, a pilot planned a navigation exercise from Moorabbin Airport, overhead Yarram aircraft landing area (ALA), and then on to Bairnsdale Airport, Victoria (Figure 1). The return flight from Bairnsdale to Moorabbin was to be via Latrobe Valley Airport, Victoria. The pilot had recently passed their Private Pilot Licence, and this solo navigational exercise was part of the training toward a Commercial Pilot Licence.

Figure 1: Planned route for the navigation exercise

rid19-ao-2015-106-figure-1-melbourne-wac.jpg

Source: Airservices Australia Melbourne World Aeronautical Chart (WAC)

The pilot reviewed the Area 30 weather forecast, including the terminal area forecasts (TAFs)[1] and METARs[2] for Moorabbin, Latrobe Valley, and Bairnsdale, to assess the suitability of the conditions for the planned visual flight rules (VFR) flight.

The Area 30 Forecast (ARFOR) overview, issued at 0805 Eastern Standard Time (EST), which covered the time of the flight, predicted isolated scattered showers, and snowfalls above 4,000 ft. Low cloud with precipitation particularly on the windward slopes was also forecast. It was expected that this low cloud would contract to the north-east section of Area 30 by 1200, and clear by 1400. The wind below 5,000 ft was forecast as south-westerly and between 20 and 25 kt. A note stated that winds up to 5,000 ft were forecast to be 10-20 kt stronger in the east (including the Bairnsdale region).

Confident that the flight could be safely conducted under the VFR, the pilot then discussed the planned route, and associated weather forecasts with a senior instructor at the flying school. During this discussion, the pilot and instructor decided that due to the METAR at Bairnsdale Airport indicating strong winds of up to 35 kt, the pilot should make an assessment upon arrival there. If the pilot did not assess the wind as suitable/safe for landing, the brief was to overfly the airport and commence the return leg to Latrobe Valley. They also decided to delay the flight’s departure time from Moorabbin, so that the planned arrival time back into Latrobe Valley fell outside the INTER/TEMPO[3] period for this airport.

Pilot recollection of the flight

The pilot prepared a Piper PA28 (Warrior) aircraft, registered VH-TAU (TAU), and then departed Moorabbin at the delayed time of 1239. The pilot reported that both the departure and initial climb went as planned.

To maintain separation from the cloud, the pilot levelled the aircraft at about 3,000 ft above mean sea level (AMSL) and conducted a crosscheck of their calculations. They visually confirmed the aircraft’s location, noting this on the flight plan.

About 15 NM into the initial leg of the flight (Figure 2), the pilot reported noticing some cloud on the ranges around the aircraft, with the base at about 3,000 ft. Still with the mindset that the weather was suitable for the flight, and wanting to continue, the pilot elected to fly around the lower patches of cloud. At this stage, they were confident that they could ‘push on’. The pilot reported that they had accompanied a friend on the same navigation exercise the previous week, in similar weather conditions. The pilot’s friend had had been successful in negotiating the weather and completing the flight.

Figure 2: Initial leg of flight planned track, from Moorabbin Airport to overhead Yarram ALA

rid20-picture-5.jpg

Source: Airservices Australia – Melbourne Visual Navigation Chart annotated by ATSB

In hindsight, the pilot reported an unawareness of how thick and widespread the cloud ahead really was, and how it was different to what had been expected. After manoeuvring around several patches of cloud, the pilot made a decision to conduct a 180° turn onto the reciprocal track, and return to Moorabbin. After logging the diversion time on the flight plan, the pilot initiated a turn to the left. Almost instantly, the pilot realised that the aircraft was now completely engulfed in cloud, and had entered instrument meteorological conditions (IMC). The pilot was not instrument rated, nor was the aircraft approved for flight in IMC. The aircraft was equipped with a Very High Frequency Omnidirectional Range (VOR), but the pilot had not been trained to operate this navigational aid.

Although having completed the mandatory basic instrument flight requirements during earlier training, the pilot had not been in cloud before; and reported feeling totally overwhelmed by such an unfamiliar environment. While trying to control the aircraft solely by reference to the instruments, the pilot reported having an escalating concern about the aircraft’s altitude, the height of the surrounding terrain, and the total loss of visual cues to be able to ascertain the aircraft’s position.

The request for assistance

At about 1313, the pilot reported stopping the turn at a heading of about 300 °M, levelling the wings, and called Melbourne Centre for assistance (see Table 1).

Melbourne Centre clarified the aircraft’s position, and placed an uncertainty phase (INCERFA[4] ) on the aircraft. The air traffic controller (ATC) then contacted the instructor in an instrument flight rules (IFR) Cirrus S22, VH-QQT (QQT), who was conducting dual IFR training at nearby Latrobe Valley Airport. The controller at Melbourne Centre confirmed the in-flight conditions with the instructor in QQT, who advised that the cloud tops were about 6,500 ft. Both the instructor and controller then focussed on assisting the pilot in TAU.

Assistance provided by instructor in QQT

The experienced instructor in QQT began providing assistance over the radio to the pilot in TAU. After establishing the facts, and the pilot’s level of experience, the instructor in QQT began to ‘mentor’ the pilot in TAU. The instructor was concerned about the current altitude, which was below the lowest safe altitude (LSALT) of 3,400 ft in the area, and the possibility of icing. Therefore, the instructor talked the pilot through maintaining a focus on keeping the aircraft wings level (to prevent a turn), while initiating a climb through the thick layer of cloud.

The instructor in QQT was able to work methodically with the pilot in TAU, focusing on reducing the pilot’s workload and keeping them calm. The instructor requested all the required airspace clearances for both aircraft from ATC; and ATC assisted in arranging and expediting these. The pilot in TAU reported clear of cloud at about 6,400 ft, some 15 NM north of the original flight planned track (Figures 3 and 4).

ATC then provided vectors to the instructor in QQT to locate TAU, which was now some distance from the Cirrus. The instructor advised that the transponder paint of TAU on the traffic collision avoidance system (TCAS) in QQT had kept ‘dropping out’.

The instructor in QQT continued to work closely with ATC who again arranged all required clearances for both aircraft in tandem, back to Moorabbin. As part of this assistance, ATC advised the instructor that there was a large break in the cloud over Port Phillip Bay west of Moorabbin. The two aircraft travelled to this area and once the instructor had confirmed that the pilot in TAU was orientated, and able to manage the descent, approach and landing back into Moorabbin, the two aircraft parted and TAU landed uneventfully some minutes later.

Figure 3: Surveillance image at about the time VH-TAU first broke clear of cloud. Note distance from intended waypoint of Yarram

rid21-ao-2015-106-figure-xx-radar-plot-clear-of-cloud.jpg

Source: Airservices Australia annotated by the ATSB

Figure 4: Google earth representation of where TAU broke clear of cloud

Google earth representation of where TAU broke clear of cloud

Source: Google earth annotated by ATSB

Actual flight path

The ATSB was provided with surveillance data from Airservices Australia. Table 1 presents a summary of what the surveillance data showed.

Table 1: Surveillance data - main points

Summary of what the surveillance data showed. Compiled by ATSB from Airservices Australia surveillance data

Source: Compiled by ATSB from Airservices Australia surveillance data

Relevant Terminal Area Forecasts (TAFs)

In addition to the overview of the Area 30 forecast mentioned previously, the relevant TAFs covering the period of the flight are as follows:

Moorabbin: Issued at 0907: Scattered cloud at 3,000-4,000 ft, with deteriorating conditions from 1800.

Bairnsdale: Issued at 1027: Wind from 250°T at 14 kt; 10 km visibility; light rain showers and scattered cloud at 3,000 ft, with broken cloud at 4,000 ft.

Latrobe Valley: Issued at 1030: 10 km visibility, light rain showers. Cloud few at 2,500 ft and scattered at 3,500 ft.

Safety message

The importance of seeking assistance from ATC as soon as a pilot is in difficulty, or preferably before they reach that point, cannot be overstated. This is a common and important message in most of the educational material on VFR into IMC scenarios. It almost certainly led to a good outcome in this occurrence. ATC could prioritise resources and gain assistance from a nearby aircraft. In this occurrence, good teamwork between the pilots of both aircraft and air traffic control ensured a successful outcome.

The ATSB and CASA publications listed below highlight the importance of really understanding the weather you may encounter at the planning stage, making good decisions, knowing your aircraft and all its equipment, and using a personal minimums checklist.

The ATSB SafetyWatch highlights the broad safety concerns that come out of our investigation findings and from the occurrence data reported to us by industry. Flying with reduced visual cues such as in this occurrence remains one of the ATSB’s major safety concerns.

Number 4 in the Avoidable Accidents series published by the ATSB, Accidents involving pilots in Instrument Meteorological Conditions, lists three key messages for pilots:

  • Avoiding deteriorating weather or IMC requires thorough pre-flight planning, having alternate plans in case of an unexpected deterioration in the weather, and making timely decisions to turn back or divert.
  • Pressing on into IMC conditions with no instrument rating carries a significant risk of severe spatial disorientation due to powerful and misleading orientation sensations in the absence of visual cues. Disorientation can affect any pilot, no matter what their level of experience.
  • VFR pilots are encouraged to use a ‘personal minimums’ checklist to help control and manage flight risks through identifying risk factors that include marginal weather conditions.

Available from CASA’s online store are:

Weather to Fly – This DVD highlights the dangers of flying in cloud, and how to avoid VFR into IMC.

Flight Planning – always thinking ahead. A flight-planning guide designed to help you in planning and conducting your flight. This guide includes a ‘personal minimums checklist.

Aviation Short Investigations Bulletin - Issue 47

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. A Terminal Area Forecast (TAF) is a statement of meteorological conditions expected for a specified period in the airspace within a radius of 5NM of the aerodrome reference point.
  2. METAR: Routine aerodrome weather report issued at fixed times, hourly or half-hourly.
  3. INTER An intermittent deterioration in the forecast weather conditions, during which a significant variation in prevailing conditions is expected to last for periods of less than 30 minutes duration.TEMPO A temporary deterioration in the forecast weather conditions, during which significant variation in prevailing conditions are expected to last for periods of between 30 and 60 minutes.
  4. INCERFA is the first of three alert phases available to ATC. This is a phase of ‘uncertainty’ in regard to the welfare of the aircraft and its occupant(s).

Occurrence summary

Investigation number AO-2015-106
Occurrence date 08/09/2015
Location Latrobe Valley Airport
State Victoria
Report release date 13/04/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category VFR into IMC
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Piper Aircraft Corp
Model PA-28-161
Registration VH-TAU
Serial number 2842209
Sector Piston
Departure point Moorabbin, Vic.
Destination Bairnsdale, Vic.

Aircraft details

Manufacturer Cirrus Design Corporation
Model SR22
Registration VH-QQT
Serial number 3139
Sector Piston
Operation type Flying Training
Departure point Moorabbin, Vic.
Destination Latrobe Valley, Vic.
Damage Nil

Collision with terrain involving Cessna 172, VH-ZEW, near Millbrook, Victoria, on 8 September 2015

Recommendations

The lack of manufacturer written advice, limitations, cautions, or warnings (written or aural) about autopilot response to manual pilot control inputs meant that pilots may be unaware that their actions can lead to significant out of trim situations, and associated aircraft control issues.

ATSB safety recommendation to Cessna Aircraft Company (Textron) 

Number: AO-2015-105-SR-004

The ATSB recommends that Cessna Aircraft Company, in conjunction with Garmin, implement changes to their operations manuals so that all aircraft types fitted with their autopilots have the limitations, cautions and warnings applied consistently.

ATSB safety recommendation to Garmin 

Number: AO-2015-105-SR-006

The ATSB recommends that Garmin, in conjunction with aircraft manufacturers, takes action to ensure that all aircraft types fitted with their autopilots have the limitations, cautions and warnings documented in the aircraft’s operating manuals. Further, the ATSB recommends that Garmin consider the use of audible warnings to enhance pilots’ awareness of mistrim situations brought on by the autopilot system.

Final report

Safety summary

What happened

At about 1410 Eastern Standard Time on 8 September 2015, the pilot of a Cessna Aircraft Company 172S, registered VH-ZEW, departed Point Cook Airfield, Victoria, on a solo navigational training flight via waypoints that included Ballarat Airport, Victoria. GPS data showed that the aircraft was on the third leg of the planned journey, cruising at about 3,000 ft above mean sea level when it started to descend rapidly. The aircraft impacted rising terrain at about 2,200 ft and was destroyed. The pilot who was the sole occupant, was fatally injured.

What the ATSB found

The site and wreckage inspection identified that the aircraft impacted terrain in a level, slight right‑wing low attitude. That indicated that the pilot likely stopped the aircraft’s descent and started to initiate a manoeuvre to avoid the terrain. It is likely that the pilot manually manipulated the controls while the autopilot was on and engaged in a vertical mode. As a consequence, the autopilot re-trimmed the aircraft against pilot inputs, inducing a nose-down mistrim situation, which led to a rapid descent. The aircraft’s low operating height above the ground, due to the extent and base of the cloud, along with rising terrain in front of the aircraft, gave the pilot limited time to diagnose, react, and recover before the ground impact.

There was no advice, limitation, or warning in the aircraft pilot operating handbook or avionics manual to indicate that if a force is applied to control column while the autopilot is engaged, that the aircraft’s autopilot system will trim against the control column force, and possibly lead to a significant out of trim situation. Training requirements for autopilot systems was rudimentary at the recreational pilot licence (RPL) level due to stipulated operational limitations for its use. At the time of the accident there was no regulatory requirement for pilots to demonstrate autopilot competency at the RPL level.

What's been done as a result

The ATSB issued safety recommendations to the aircraft and autopilot manufacturers about the provision of limitations, cautions and warnings for autopilot systems and audible pitch trim movement.

The flight training organisation updated their operations manual, as a result of flight testing they conducted, to include warnings about the operation and function of the autopilot system absent in the manufacturer’s documentation. The hazard of manual manipulation of the flight controls with the autopilot engaged was also emphasised to students.

Safety message

Technologically advanced avionics and autopilot systems are now often fitted to general aviation aircraft used for flight training, private and charter operations. It is essential for all pilots to develop a thorough understanding and operation of all systems fitted to the aircraft they are flying. It is also important that student pilots consolidate manual flight and navigation skills before using the advanced auto flight modes or extensively using autopilot systems. Avionics and aircraft manufacturers should increase pilot awareness of automated systems by providing written warnings surrounding known issues and including visual and aural alerts in auto flight systems to increase pilot awareness of non-standard inputs. Fundamentally, pilots should be aware that if the automation is not performing as expected, then the safest option under most circumstances is to disengage the system and manually fly the aircraft.

VH-ZEW main wreckage

VH-ZEW main wreckage. Source: ATSB

Source: ATSB

The occurrence

On the morning of 8 September 2015, a student pilot commenced preparing for an upcoming training flight. As part of that preparation, she completed a flight plan for the flight, which was her first solo navigation training exercise. Her instructor stated that she had shown him the pre‑flight plan and they discussed the expected en-route weather, which was poor in the morning but forecast to improve in the afternoon.

The instructor approved the flight plan and at about 1410 Eastern Standard Time,[1] the student pilot of the Cessna Aircraft Company 172S Skyhawk SP, registered VH-ZEW (ZEW), departed Point Cook Airport, Victoria, on a return training flight via various waypoints, including Ballarat Airport (Figure 1). GPS data indicated that the aircraft had passed through the third waypoint of the planned journey, cruising at about 1,000 ft above ground level when it started to descend rapidly.

Figure 1: Map showing the aircraft’s flight path, take-off point and accident site. ZEW was between the Ballarat airfield to Melton Reservoir waypoints at the time of the accident.

Figure 1: Map showing the aircraft’s flight path, take-off point and accident site. ZEW was between the Ballarat airfield to Melton Reservoir waypoints at the time of the accident. Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB

Witnesses stated that at about 1540 they observed the aircraft flying very low and heading toward a high terrain feature called Black Mount, near Millbrook. The aircraft then crested Black Mount before it disappeared from sight.

About 10 minutes before the accident, a pilot operating an aircraft in the local area overheard the pilot of ZEW providing a position report by radio, overhead Ballarat Airfield. The pilot did not report any difficulties. The pilot did not hear any further radio transmissions from the pilot of ZEW.

A property owner in the area heard a noise, which they later realised was the aircraft flying nearby. As they travelled to a paddock on the property, they located the aircraft at the accident site (Figure 2). The pilot was the sole occupant, and had sustained fatal injuries. The aircraft was destroyed.

Figure 2: Last recorded aircraft position, witness locations, and accident site. The high terrain is an extinct volcano called Black Mount

Figure 2: Last recorded aircraft position, witness locations, and accident site. The high terrain is an extinct volcano called Black Mount. Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB

  1. Eastern Standard Time (EST) was Coordinated Universal Time (UTC) +10 hours.

Context

Pilot information

The pilot was enrolled as a student conducting training for a Commercial Pilot (Aeroplane) Licence through a university Associate Degree in Aviation.

The pilot had passed the general flight proficiency test in the month prior to the accident, and had applied for an aeroplane Recreational Pilot Licence.[2]

The last recorded flight hours for the pilot was on 4 September 2015, with a total of 53.8 hours, all of which was in a Cessna Aircraft Company 172S (172S). The accident flight was the first navigational flight conducted by the pilot without a flight instructor on board.

Medical information

The pilot was reported to have been fit and well with no observed problems with health or behaviour. The pilot held current Class 1 and 2 Aviation Medical Certificates with no restrictions.

The autopsy and toxicology examinations did not reveal any issues that would have contributed to the accident.

Aircraft information

General

The Cessna Aircraft Company C172S (172S) is a four seat, high wing, all metal, fixed undercarriage aircraft with a single reciprocating engine, driving a fixed pitch two bladed propeller (Figure 3).

Figure 3: Exemplar Cessna 172S

Figure 3: Exemplar Cessna 172S. Source: ATSB

Source: ATSB

VH-ZEW

VH-ZEW (ZEW) was a Cessna 172S aircraft, built in 2011, and certified in the normal and utility aircraft categories. It had accumulated 2,218 flight hours at the time of the accident. The aircraft was registered in Australia in May 2011. It had a current certificate of airworthiness and maintenance release with no annotated defects. The last maintenance inspection was conducted about two weeks prior to the accident. Examination of the maintenance documentation did not indicate any anomalies.

A post-accident analysis of the aircraft weight and balance indicated that the aircraft was within limits during the entire flight.

Engine information

The engine was a four cylinder horizontally opposed, normally aspirated, fuel injected piston engine.

The engine manufacturer’s recommended time before overhaul had been exceeded by 218.7 flight hours due to a replacement engine supply issue. As a consequence, the aircraft was downgraded from Charter to the Aerial work category and the engine was maintained in accordance with the on-condition requirements of CASA Airworthiness Directive (AD)/ENG/5.

Integrated instrument and avionics system

The 172S was factory fitted with a Cessna Nav III, comprising of a Garmin G1000 integrated avionics system (G1000). The G1000 provided display and control interface for communication, navigation, surveillance, automatic flight control system (AFCS), primary flight instrumentation, engine indication, and annunciation systems on two liquid crystal display units and an audio panel.

The two display units consisted of a Primary Flight Display (PFD) on the left (pilot side), and the Multi-Function Display (MFD) on the right (Figure 4). The audio panel can be seen located between the two display units. The aircraft was not fitted with the optional Terrain Awareness and Warning System (TAWS) but it did have a coloured topographical map feature to enhance pilots’ awareness of the local area terrain.

Recording capability

The G1000 system was capable of storing 60 flight and engine parameters on a data memory card, which is inserted into the lower card slot of the MFD. Data was logged to a new file each time the MFD was switched on. All parameters were recorded at one‑second intervals.

Figure 4: Exemplar cockpit layout showing G1000 avionics system, with primary flight display (left), multi-function displays (right) and memory card position

Figure 4: Exemplar cockpit layout showing G1000 avionics system, with primary flight display (left), multi-function displays (right) and memory card position. Source: Cessna Aircraft Company, modified by the ATSB

Source: Cessna Aircraft Company, modified by the ATSB

Automatic Flight Control System

The AFCS is primarily intended to assist the flight crew in the basic control and tactical guidance of the airplane. The system may also provide workload relief to the pilots, provide a capability to fly a flight path more accurately than by hand, and to assist with control if the aircraft is inadvertently flown into instrument meteorological conditions.

The 172S was manufactured with two AFCS options, the Bendix/King (now Honeywell) KAP140 fitted to earlier manufactured 172S, or the fully integrated Garmin GFC700 fitted to later model 172S, including VH-ZEW.

Autopilot operation

The GFC700 included a two-axis autopilot that operated flight control surface servos to provide automatic flight control. The autopilot controlled the aircraft pitch and roll attitudes following commands received from the flight director. Pitch trim was controlled automatically through an automatic trim (autotrim) function, which provided trim commands to the pitch trim servo, to relieve any sustained effort required by the pitch servo.

The servo motor control limits the maximum servo speed and torque. The servo gearboxes are equipped with slip-clutches set to certain values. This allows the servos to be overridden in case of an emergency.

Pitch Axis and Pitch Trim

The autopilot pitch axis uses pitch rate to stabilise the aircraft pitch attitude during upsets and flight director manoeuvres. Flight director pitch commands are rate- and attitude-limited, combined with pitch damper control, and sent to the pitch servo motor.

When the autopilot is not engaged, manual electric trim (MET) is active and may be used to command the pitch trim servo. This allows the aircraft to be trimmed by using the control wheel split switch rather than the trim wheel, located below the throttle control knob. The left switch is the ARM contact and the right switch controls the UP (forward) and DN (rearward) contacts. Manual trim commands are generated only when both sides of the switch are operated simultaneously. If either side of the switch is active separately for more than three seconds, the MET function is disabled and ‘PTRM’ is enunciated on the PFD. Operation of the pitch trim servo also results in movement of the trim wheel. Trim movement speeds are scheduled with respect to airspeed so that trim movement slows down when airspeed increases to provide a response that is more consistent.

Roll Axis

The autopilot roll axis uses roll rate to stabilise aircraft roll attitude during upsets and flight director manoeuvres. The flight director roll commands are rate- and attitude-limited, combined with roll damper control, and sent to the roll servo motor.

Autopilot controls

The autopilot can be selected ON by depressing the Autopilot (AP) button. The autopilot can be selected OFF in a number of ways by pressing the:

  • AP button after the autopilot was selected ON
  • red autopilot disconnect (AP DISC) button, which is located on the pilot’s control wheel
  • manual electric trim (MET) left pitch trim and arm switch
  • go around (GA) button (located beside the throttle control knob)

Manual disengagement is indicated by a five second flashing yellow ‘AP’ annunciation and a two second autopilot disconnect aural alert.

Automatic autopilot disengagement is indicated by a flashing red ‘AP’ annunciation and autopilot disconnect aural alert, which will continue until acknowledged by pushing the AP DISC or MET switch. Automatic disengagement occurs due to:

  • system failure
  • invalid sensor data
  • inability to compute default flight director modes (flight director also disengages automatically)

Further, the selection of the control wheel steering (CWS) button will momentarily disengage the pitch and roll servos for the time that it remains depressed, allowing the aircraft to be hand flown (Figure 5). The ‘AP’ annunciation is temporarily replaced by ‘CWS’ in white for the duration of CWS manoeuvres. In most scenarios, releasing the CWS button reengages the autopilot with a new reference. AFCS behaviour may vary depending on the flight director mode active at the time CWS button is depressed.

Figure 5: GFC 700 autopilot controls on the PFD, MFD and control yoke

Figure 5: GFC 700 autopilot controls on the PFD, MFD and control yoke. Source: Garmin, modified by the ATSB

Source: Garmin, modified by the ATSB

Flight director operation

When the flight director is activated (FD switch ON), the flight director commands can be flown by the pilot. The flight director is displayed as command bars on the primary flight display, indicating the pre-selected flight path of the aircraft. When the autopilot (AP) is selected ON, the flight director is activated and provides commands to the autopilot.

Flight director modes

The autopilot system has numerous modes of operation. A brief description of the relevant pitch and roll modes with the autopilot selected to ON are listed below.

  • Pitch Hold Mode (PIT) – When the autopilot is selected on, the flight director is activated and Pitch Hold Mode (PIT) is selected by default. In PIT, the flight director maintains a constant pitch attitude called the pitch reference. The pitch reference is set to the aircraft attitude at the moment of mode selection.
  • Altitude Hold Mode (ALT) – Altitude Hold Mode can be activated by pressing the ALT Key, the aircraft then maintains the current altitude to the nearest ten feet as an altitude reference, shown in the AFCS status box.
  • Heading Hold Mode (HDG) – Heading Select Mode is activated by pressing the HDG key. Activation of the heading mode commands the autopilot to acquire and maintain the aircraft’s selected heading.
  • Heading/Altitude (HDG/ALT) – Combination of two modes that hold selected heading and reference altitude when selected.
  • Heading/Pitch (HDG/Pitch) – Combination of two modes that hold selected heading and current pitch attitude when selected.
  • Wings level/altitude (WL/ALT) – rolls the aircraft to level the wings and holds the reference altitude.

Autopilot pre-take-off checks

The operating limitation section of the Garmin GFC 700 AFCS pilot operating handbook stipulated that:

The GFC 700 AFCS pre-flight test must be successfully completed prior to use of the autopilot, flight director or manual electric trim.

The normal procedures section of the POH stated that pre-take-off checks included:

Autopilot – ENGAGE (if installed) (push AP button on either PFD or MFD bezel)

Flight Controls – CHECK (verify autopilot can be overpowered in both pitch and roll axes)

A/P TRIM DISC Button – PRESS (if installed) (verify autopilot disengages and aural alert is heard)

Manufacturer autopilot limitations, cautions and warnings

Cessna 172S fitted with the Bendix King KAP140 autopilot

The Cessna 172S aircraft were originally manufactured with the KAP140 autopilot system when they were first produced. The KAP140 had a two-axis autopilot control with functions and inputs such as altitude selection and barometric correction that operated independently from the G1000 avionics system.

The Pilot Operating Handbook Supplement 3, titled ' Bendix/King KAP 140 2 axis autopilot' contained the following warning on page S3-29:

DO NOT MOVE THE CONTROL WHEEL WHEN THE AUTOPILOT IS ENGAGED. IF THE PILOT TRIES TO FLY THE AIRPLANE MANUALLY WHEN THE AUTOPILOT IS ENGAGED OR TRIES TO "HELP" THE AUTOPILOT, THE AUTOPILOT WILL ADJUST THE PITCH TRIM TO OPPOSE CONTROL WHEEL MOVEMENT AND CAUSE THE AIRPLANE TO GO OUT OF TRIM. THE OUT-OF-TRIM CONDITION WILL CAUSE LARGE ELEVATOR CONTROL FORCES WHEN THE AUTOPILOT IS DISENGAGED.

Further to that warning, Operating Limitation number 9 stated:

Manually overriding the autopilot to change pitch or roll attitude is prohibited (Disengage the autopilot before moving the control wheel manually).

The Bendix King KAP140 Autopilot System manual indicated the system was capable of generating aural alert annunciations. Aural alerts relating to pitch trim were:

1. "TRIM IN MOTION, TRIM IN MOTION…" - which activated with pitch trim running for more than 5 seconds.

2. "CHECK PITCH TRIM" - which activated when an out of trim condition has existed for more than 15 seconds

Cessna 172S fitted with the GFC700 autopilot

The GFC700 (fitted to VH-ZEW) superseded the KAP140 autopilot part way through production of the Cessna 172S.

In contrast to the warnings and limitations given in the Bendix/King KAP140 2 axis autopilot manual, the ATSB was unable to locate any similar advice, limitations, or warnings applicable to the GFC700 automatic flight control system (AFCS) about manually overriding the autopilot, even though the autopilot reacts the same way. Further, the system did not provide aural alerts or warnings for pitch trim in motion or out of trim conditions such as those provided in the KAP 140 system.

Other aircraft types fitted with the GFC700 autopilot

Numerous other aircraft types have the G1000 avionics system with the GFC700 fitted. The ATSB conducted a search of the Pilots Operating Handbooks for the Cessna Caravan 208, Cirrus SR20/22, Aerospatiale TBM 850, Beechcraft G36 and G58, Mooney M20 (M, R, TN) and Diamond DA42. Of those, the Beechcraft, Diamond, and Mooney aircraft had warnings that would inform a pilot about the issues surrounding the sustained application of an override force with the autopilot ON and engaged.

For example, the Diamond DA42 Normal operating procedure for operation of the GFC700 has a warning at the front of section 4A.6.8 which states:

It is the responsibility of the pilot in command to monitor the autopilot when it is engaged. The pilot should be prepared to immediately disconnect the autopilot and to take prompt corrective action in the event of unexpected or unusual autopilot behaviour. Do not attempt to manually fly the airplane with the autopilot engaged. The autopilot servos will oppose pilot input and will trim opposite the direction of pilot input (pitch axis only). This could lead to a significant out-of-trim condition. Disconnect the autopilot if manual control is desired.

The ATSB asked the aircraft and avionics manufacturers about this disparity between autopilot written and aural warnings, a summary of their response is provided below.

The avionics manufacturer stated that the presence of a limitation, caution or warning is generally left up to the certifier of the equipment in the airplane. They also indicated that they did not believe that a limitation, caution or warning was required because:

  • Virtually all autopilots certified in that category react the same way. Therefore, it is common knowledge not to try to fly the airplane while the autopilot is flying, any more than a pilot should not try to fly the airplane while the other pilot is trying to do so.
  • The primary pitch servo can only generate a certain amount of force, and in Garmin autopilots that force is always set such that the pilot can overpower the servo at less than the certification requirement limits.
  • When the primary pitch servo reaches its maximum value, the airplane will depart from the selected vertical reference, which will be obvious to the pilot.
  • The Garmin autopilot also has an amber “ELE” [visual] alert on the PFD when the pitch servo reaches a certain level of effort.
  • Practically speaking, an aircraft flight manual note, limitation or caution would not be effective against an inadvertent input.
  • For a deliberate attempt by the pilot to manipulate the flight controls while the autopilot is flying, the initial response of the autopilot would be to input servo torque to oppose the pilot effort. It does not do so at maximum servo effort, but only ramps up to the maximum servo effort when the initial inputs are ineffective.
  • The pilot will be well aware of the continually increasing control wheel force and should either disconnect the autopilot or quit inputting force into the flight controls.
  • AC 25.1329-1C[3] also deals with this scenario and only requires that the disengagement not result in a potential hazard. Since the pilot can overpower the out-of-trim condition at that point, and will have at least one hand on the control wheel disconnect, there is no hazard.

The aircraft manufacturer concurred with the avionics manufacturer in that they did not believe written limitations, cautions or warnings were required.

The visual ELE alert mentioned by the avionics manufacturer may indicate a mistrim situation and provides an up or down arrow to indicate the direction of force (up arrow nose up etc.) that is required by the pilot when the autopilot is disconnected. The alert is not accompanied by an aural warning. Figure 6 is an extract from the G1000 cockpit reference guide, which shows the amber caution with an explanation.

Figure 6: Status alert for elevator mistrim

Figure 6: Status alert for elevator mistrim. Source: Garmin

Source: Garmin

Autopilot electric trim failure procedure

The emergencies section of the Cessna 172S Nav III Pilot Operating Handbook procedure for autopilot or electric trim failure stated:

Section 3 Emergencies

Page 3-22 – AUTOPILOT OR ELECTRIC TRIM FAILURE (if installed)

AUTOPILOT OR ELECTRIC TRIM FAILURE (if installed) AP OR PTRM ANNUNCIATOR(S) COME ON

1. Control Wheel - GRASP FIRMLY (regain control of airplane)

2. A/P TRIM DISC Button - PRESS and HOLD (throughout recovery)

3. Elevator Trim Control - ADJUST MANUALLY (as necessary)

4. AUTO PILOT Circuit Breaker - OPEN (pull out)

5. A/P TRIM DISC Button - RELEASE

WARNING

FOLLOWING AN AUTOPILOT, AUTOTRIM OR MANUAL ELECTRIC TRIM SYSTEM MALFUNCTION, DO NOT ENGAGE THE AUTOPILOT UNTIL THE CAUSE OF THE MALFUNCTION HAS BEEN CORRECTED.

Autopilot altitude limitations

The operating limitations section of the Cessna 172S Nav III Pilots Operating Handbook stipulates that:

The autopilot must be disengaged below 200 feet AGL [above ground level] during approach operations and below 800 feet AGL during all other operations.

The flight training organisation’s operations manual states:

AUTOPILOT PROCEDURES

The autopilot is not to be used during operations below 1500 ft AGL…

Mode awareness

The flight training organisation’s operations manual stated that:

Autopilot MODE AWARENESS is critical to aircraft safety. Autopilot mode situational awareness is particularly important in the G1000 aircraft with additional mode capability, and the remote position of the annunciator panel. If aircraft performance is not in accordance with the selected mode, re-check the mode annunciation is correct (i.e. the selected mode is engaged). If the problem persists, select basic modes, or over ride and disconnect.

DO NOT persist with the automation if you do not understand what is happening, or selected modes are not doing what they are supposed to.

The Autopilot is a very useful workload management tool, particularly when planning in-flight diversions, lost procedures, or operating in controlled airspace. Prior to use of the autopilot students must read the KAP140 / GFC700 supplement and be deemed competent by an instructor. During solo operations, use of the autopilot is limited to keeping current with autopilot operation and management of high workload situations.

Meteorological information

The Bureau of Meteorology reported that the majority of Victoria was affected by a slow moving high pressure system located in the Great Australian Bight near South Australia. This resulted in a high pressure ridge extending over Victoria, with associated cool, dry south-westerly winds and the presence of a large amount of stratocumulus cloud.

Recorded meteorological observations at Ballarat airport, located about 19 km WNW of the accident confirmed that the surface wind was from the SW at 10 to 15 kt.

After examining all meteorological observations and the surrounding topography, the Bureau of Meteorology advised that apart from the low cloud with a base of approximately 2,000 to 2,500 ft AMSL and the possibility of moderate turbulence between 5,000 ft to 9,000 ft AMSL near the accident site, there was no other significant weather in the area at the time of the accident.

The recorded cloud observations were consistent with witness reports of overcast cloud close to the accident site. A pilot operating near the Ballarat airfield also recalled overcast cloud conditions at about 3,000 ft AMSL around the time of the accident.

Although extensive cloud was apparent in the area of operation, there was no recorded or observed rain activity near the accident site. Reported visibility was greater than 10 km when clear of cloud.

Site and wreckage information

Site information

The aircraft impacted terrain on the south-eastern side of an extinct volcano known as Black Mount (Figure 7). The accident site was:

  • about 200 m to the right of the flight-planned track.
  • on a 20 degree upslope
  • at an elevation of about 2,160 ft AMSL
  • on a south-south-east track which was 15 degrees to the right of the flight planned track.

The area surrounding Black Mount was flat and clear farmland, which had a number of suitable off-field landing areas for the pilot to land in the event of an emergency.

Figure 7: Area of accident site on high ground with aircraft impact point highlighted

Figure 7: Area of accident site on high ground with aircraft impact point highlighted. Source: ATSB

Source: ATSB

Black Mount was a U shaped feature, which was covered in grass on the south-eastern side that matched the surrounding landscape. That created a visual illusion that the high terrain appeared to be a relatively flat area when viewed from the southwest.

Figure 8 is a picture of Black Mount taken in line with the aircraft’s direction of flight at about 1,000 ft AGL. The picture illustrates the ill-defined rising terrain.

Figure 8: Black Mount viewed at about 1,000 ft AGL in the direction of flight, showing the accident site

Figure 8: Black Mount viewed at about 1,000 ft AGL in the direction of flight, showing the accident site. Source: Victoria Police, modified by the ATSB

Source: Victoria Police, modified by the ATSB

Figure 9 is a profile representation of Black Mount, which shows the rising terrain and location of the accident site.

Figure 9: Black Mount in profile showing the rising terrain, direction of flight, accident site, and peak altitudes

Figure 9: Black Mount in profile showing the rising terrain, direction of flight, accident site, and peak altitudes. Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB

There were several identifiable impact marks in the initial part of the wreckage trail. They consisted of right and left wing impact marks, left, right and nose gear marks, propeller slash marks and nose impact point (Figure 10). Examination of the ground impact marks, wreckage splay, distribution, disruption and location indicated that the aircraft:

  • was travelling at a relatively high speed when it impacted with terrain
  • was slightly right wing low (in a turn to the right)
  • was about level on its pitch axis (in a level attitude)
  • travelled a distance of 70 m from the point of impact to the position that the aircraft came to rest.

Figure 10: Overview of accident site, location of aircraft impact marks and main wreckage in the background

Figure 10: Overview of accident site, location of aircraft impact marks and main wreckage in the background. Source: ATSB

Source: ATSB

Wreckage inspection

The ATSB conducted a detailed examination of the aircraft. That examination identified:

  • all aircraft parts were accounted for in the local area of the accident site
  • no observable pre-accident defects to the airframe or engine
  • propeller slash marks, bending and rotational damage indicated that the engine was driving the propeller at the time of impact
  • the flaps were retracted
  • the elevator trim was about midway between neutral and the full pitch down position.[4]
Aircraft safety features

The aircraft’s front seat belts were fitted with airbags, designed to inflate in front of the occupants to protect them from coming in contact with the instrument panel. The pilot’s airbag was outside of its casings which was consistent with it deploying during the accident sequence.

Emergency locator transmitter

A fixed 406 MHz emergency locator transmitter (ELT) was fitted to the aircraft. The transmitter was found securely located in its mounting, and appeared undamaged externally. It was set to the auto position and the activation light was illuminated. The ELT was also beeping intermittently, indicating that the internal inertial switch had activated and the ELT was transmitting.

Figure 11 shows the aircraft viewed from the rear, displaying the significant structural damage.

Figure 11: Main wreckage viewed from the rear showing significant disruption

Figure 11: Main wreckage viewed from the rear showing significant disruption. Source: ATSB

Source: ATSB

Avionics equipment

The G1000 integrated avionics system flight data log memory card had been dislodged during the accident sequence and was located about 20 m from the main wreckage. External examination of the card did not reveal any obvious damage. The memory card was retained for further examination and data download.

Recorded information

G1000 memory card download

The flight data log memory card was successfully downloaded by the ATSB. It provided data for the entire flight, including autopilot and engine parameters, recorded at one second intervals up to about 13-16 seconds prior to the impact. The premature termination of the recording was probably due to power supply disconnection as a result of impact forces, rather than normal system shut down. This likely prevented buffered data being written to the memory card.

The downloaded information did not show any anomalies with the flight and engine parameters that would indicate a mechanical or avionics issue with the aircraft. The ATSB provided the downloaded data from the accident flight to the aircraft and avionics manufacturers. They were asked if the data showed any indications of autopilot malfunction. The aircraft manufacturer stated that:

Based on the data provided, there does not appear to be an autopilot malfunction.

The avionics manufacturer also indicated that the data did not show a failure of the avionics or autopilot systems.

The data indicated a normal flight through all planned waypoints up until about 8 seconds before recording stopped, when the aircraft started climbed slightly before descending from 3,000ft AMSL at an increasingly rapid rate (Figure 12). The maximum vertical descent rate recorded was about 2,500 ft/min. The aircraft travelled a distance of about 900 m and descended a further 640 ft following the end of the recording. The time from the start of the descent until impact with terrain was estimated to be no more than about 20 seconds.

Figure 12: Recorded GPS flight track showing descent before recording ends, estimated track and impact point on Black Mount

Figure 12: Recorded GPS flight track showing descent before recording ends, estimated track and impact point on Black Mount. Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB
Recorded AFCS data

The recorded AFCS data during the accident flight showed that:

  • the pilot had conducted an autopilot function check as part of the pre-flight checks just prior to take-off.
  • the autopilot was utilised for about one third of the flight in total, with various heading and vertical modes selected
  • the autopilot had been switched on and off 14 times, not including the ground function test (Figure 13).

Figure 13: Flightpath plot showing the aircraft’s flight track with autopilot usage and modes utilised during the flight

Figure 13: Flightpath plot showing the aircraft’s flight track with autopilot usage and modes utilised during the flight. ource: ATSB

Source: ATSB

In normal AFCS operation with the autopilot engaged in a vertical mode, the pitch command and pitch attitude should follow each other closely. Towards the end of the recovered data, this was not the case. The data shows a slight pitch up attitude and then a significant pitch down attitude, which is different to the pitch command. This indicated a manual control input from the pilot while the autopilot was on and engaged in a vertical mode. Figure 14 is a graph of the last 50 seconds of flight showing the time of autopilot engagement in the various modes, the flight director pitch commands, and actual aircraft pitch attitude. The graph also shows an increase in engine RPM and fuel flow, which indicates that the pilot did not reduce power before descent.[5]

Figure 14: Data from the last 40 seconds of flight showing flight parameters, the autopilot selections, when the autopilot was disengaged, and the end of the recorded data

Figure 14: Data from the last 40 seconds of flight showing flight parameters, the autopilot selections, when the autopilot was disengaged, and the end of the recorded data. Source: ATSB

Source: ATSB

Table 1 is a timeline of the last recorded 30 seconds of data with the autopilot mode selections, and the aircraft reaction those selections.

Table 1: Autopilot usage during the last 30 seconds of recorded data

UTCDescription
05:17:44Autopilot selected ON in default Wings Level/Altitude mode (WL/ALT), to maintain a wings level attitude in roll attitude mode, and a reference altitude in altitude hold mode from the time of selection.
05:17:45Autopilot mode changed to Heading/Altitude mode (HDG/ALT), to hold a reference heading and altitude from the time of selection.
05:17:50Autopilot mode changed to Heading/Pitch (HDG/PIT) to hold a heading and pitch attitude from the time of selection.
05:17:52Autopilot mode changed to HDG/ALT.
05:17:55Autopilot mode changed to HDG/PIT. Pitch reference recorded at the time of selection was -1.9°. The pitch attitude was close to the pitch command value for the first 7 seconds.
05:17:58While still in HDG/PIT, the recording indicated the aircraft adopted a slight pitch up and then a pitch down attitude that was different to the pitch attitude reference set when HDG/PIT was selected.
05:18:04Autopilot mode changed to HDG/ALT, an altitude reference of 2,985 ft AMSL should automatically have been selected. Autopilot did not respond as expected, which was to hold the reference altitude. The aircraft nose down pitch angle continued to increase and the aircraft continued to descend.
05:18:08Pilot disengaged autopilot system manually by either switching the autopilot off at the controller, pressing disconnect on the control yoke or utilising the pitch trim switches on the control yoke. At that point the recorded vertical descent rate was about 1,000 ft/min, aircraft nose down pitch angle of -13.5° and an altitude of about 2,800 ft AMSL.
05:18:11Recording ends with an increasing vertical descent rate of 2,500 ft/min, nose down pitch angle of about -23°, and an altitude of about 2,615 ft AMSL.
05:18:25Approximate time of impact with terrain at an elevation of about 2,160 ft AMSL.

Manufacturer analysis of the autopilot data

The ATSB provided the accident flight data to the aircraft and avionics manufacturers for their interpretation of the data. The aircraft manufacturer stated that:

Below is a summation of our analysis of the data provided by the ATSB relating to this accident:

The pilot activated and deactivated the autopilot repeatedly throughout the flight. In addition, multiple pitch modes were selected throughout the flight, though ALT (altitude hold) mode was used the most.

For a majority of the flight, the pitch of the aircraft matches the pitch command recorded. However, there are three negative vertical speed increases. During those times the pitch of the aircraft does not match the pitch command recorded. This occurs while the autopilot was activated. During all three occurrences, a negative pitch command is recorded. At the “peak” of each negative vertical speed increase the autopilot is disconnected by the pilot and the aircraft’s descent rate is decreased. In each of the pitch down sequences the pitch of the aircraft exceeded the pitch command recorded (which would seem to indicate pilot input). It is also interesting to note that after each of those disconnects the autopilot is reengaged almost immediately and a positive pitch command is recorded. After this sequence, the autopilot is disconnected while the ALT mode is still engaged.

Based on the recorded data, the pitch and roll of the actual aircraft logged at the end of the recording was beyond what was being called for by the autopilot. This would seem to indicate pilot input.

The aircraft behavior vs. autopilot behavior would seem to indicate the pilot was experimenting with the aircraft/flight director/autopilot operation. If the pilot was experiencing some type of autopilot malfunction we would assume the pilot would follow the autopilot failure checklist and disable the autopilot.

The vertical mode is switched repeatedly between ALT and PIT (pitch hold) modes at the end of the recording. The data file also shows the autopilot was disconnected by the pilot before the recording stopped. This occurred when the aircraft was approximately 700 feet AGL and approximately 0.5 NM from the accident site.

The avionics manufacturer was unsure what caused the rapid pitch down, but indicated that the amount the aircraft pitched down was beyond the aircraft’s autopilot capability. They indicated that it was a possibility that the pilot had overpowered the autopilot.

ATSB comment

The ATSB analysis largely concurred with the aircraft manufacturer’s analysis of the data, with some variation about the conclusions detailed in points 2 and 4. The aircraft manufacturer indicated that there were three negative vertical speed increases where pitch and pitch command did not match while the autopilot was activated. Those sequences were on the sector between Swan Marsh and Ballarat.

The ATSB analysed the three sequences mentioned and established that the negative vertical speed increases and misalignment between pitch attitude and pitch command occurred just after the autopilot had been switched off (Figure 15). Further, there was no evidence in the data to show any separation between the aircraft pitch attitude and pitch command on any phase of the flight with the autopilot on in a vertical mode other than just prior to the accident.

The avionics and aircraft manufacturers contended that the pilot may have been experimenting with the autopilot during the three sequences identified. The ATSB considered that it was also possible that the pilot did not have a sound understanding of the difference between PIT and ALT modes. During the three highlighted climbs and descents, PIT was set with a positive attitude reference, meaning that the aircraft climbed at the set positive pitch attitude. The autopilot was then switched off and the aircraft manually descended. That indicated that the pilot may have been unaware that when PIT is selected it will hold an aircraft attitude rather than altitude. In summary, a lack of understanding and/or experimentation could have resulted in the altitude variation seen in the data.

Figure 15: Autopilot operation and altitude variations on the accident flight sector between Swan Marsh and Ballarat waypoints

Figure 15: Autopilot operation and altitude variations on the accident flight sector between Swan Marsh and Ballarat waypoints. Source: ATSB
Source: ATSB

Autopilot verification flights

The ATSB provided some recorded data information to the flight training organisation and discussed the interpretation of the data. This included possible factors that may have contributed to a rapid pitch down, which began with the autopilot engaged in a vertical mode. The flight training organisation advised that they were unsure why the autopilot reacted the way it did, but suspected it may have been due to manual manipulation of the flight controls.

Subsequent to that discussion, the flight training organisation conducted their own autopilot function verification flights with a Cessna 172S, fitted with the same avionics and autopilot systems. They advised the ATSB that during the verification flights:

  • back pressure was applied to the control yoke with the autopilot ON and engaged in HDG/PIT mode
  • the autopilot started to trim nose down to maintain reference attitude
  • the control forces increased significantly against pilot control input
  • the pilot released back pressure on the controls, which resulted in an immediate aircraft pitch down attitude
  • the aircraft descended rapidly at a rate of up to 4,500 ft/min with a corresponding increase in airspeed from 110 to 145 kt
  • with the exception of one test where the autopilot disconnected at about 20 degrees pitch down, the autopilot did not disconnect, re-trim or recapture the pitch reference attitude
  • the autopilot did not provide an aural or visual warning that the trim was running (apart from elevator trim wheel movement), that a mistrim existed, or that the autopilot reference attitude was not recaptured
  • in all but one case the autopilot was switched off manually and in all cases manual trim inputs were required to recover the out of trim situation.

The recorded data from the verification flight was obtained by the ATSB and compared to the accident flight data (Figure 16).

Figure 16: Data from one of the verification flights with application of override force with the autopilot ON in HDG/PIT mode

Figure 16: Data from one of the verification flights with application of override force with the autopilot ON in HDG/PIT mode. Source: ATSB

Source: ATSB

The verification flights did not completely match the accident flight profile. Some of the conditions varied, such as the autopilot vertical mode, which was constant during the verification flight but not for the accident flight. The initial increase in pitch was also greater in the verification flight and the power was reduced to decrease the airspeed in the descent. However, a comparison between the data of the two flights showed significant similarities which included:

  • slight pitch up before significant pitch down
  • a rapid pitch down (beyond 2,500 ft/min) and descent with the autopilot ON and engaged in a vertical hold mode
  • the autopilot not holding a set reference attitude/altitude
  • the autopilot remaining ON and engaged when reference attitude/altitude was not recaptured
  • a 600 ft reduction in altitude in about 15 seconds.

The recorded movements of the aircraft were only possible in the verification flight if the pilot manually manipulated the flight controls with the autopilot on in a vertical hold mode, and followed by pilot inaction/slow reaction in rectifying an out of trim situation during the rapid pitch down event.

Ground testing

Ground testing was conducted by the ATSB in conjunction with the flight training organisation, utilising a Cessna 172S. With the autopilot engaged in a vertical mode, backpressure was applied to the control column with the following results:

  • the trim started to move in the opposite direction to the control column force about three seconds after initiation of back pressure
  • only a small amount of back pressure was required to initiate movement
  • the greater the back pressure applied, the faster the trim moved to a nose down position

Conversely, when forward pressure was applied to the control column the trim moved to a nose up position. The trim activation and rate of movement was similar to the nose down trim scenario.

With the seat pulled up to the flight position, the elevator trim wheel and therefore trim wheel movement was outside the pilot’s normal field of vision. This was exacerbated if the seat was moved further forward, as would be required by relatively short pilots (such as the pilot of ZEW).

Airservices recorded data

A review of surveillance data provided by Airservices Australia showed a symbol indicating an unidentified radar track with a secondary surveillance radar[6] (SSR) code 1200[7] that, based on time tracking details, was likely the occurrence aircraft. When compared to the aircraft’s downloaded GPS track, the SSR track was found to match in location and altitude.

The SSR track recording provided two more location and altitude data points about three and eight seconds after the data stopped recording in the aircraft. The final location points were not considered accurate enough to be useful to the investigation.

Flight operations

Pre-flight planning

The pilot created a full flight plan, which included:

  • The chosen route, with waypoints identified
  • The altitude on each sector
  • Estimated times and fuel usage
  • Analysis of the current weather in the area of operation
  • Aircraft weight and balance
  • Entering the waypoints for the flight into the G1000, so that they would be available for tracking.

The flight training organisations operations manual at section E-2-16 titled Cross-country operations, stipulated that:

Flight plans for the exercises must be checked thoroughly before departure by the student pilot's instructor and are to be handed in for record purposes at the completion of the exercise.

…Private and/or Commercial Pilots engaging in cross country flying are required to submit their flight plan for checking by the instructor authorising the flight.

The pilot’s flight instructor signed the training organisations solo authorisation sheet, after reviewing the pilot’s flight plan and weather information. The instructor left a note in the authorisation sheet that stipulated that the pilot must maintain a height of 1,000 ft above ground level (AGL).

The planned cruise level between Ballarat and Milton Reservoir waypoints was 2,500 ft AMSL. That gave the pilot a ground clearance of 270 ft AGL in the vicinity of the accident site at the flight planned altitude. The flight plan conflicted with the minimum altitude AGL as stipulated by the flight instructor. It was also below the minimum regulatory requirement of 500 ft over unpopulated areas. It should be noted that despite the flight plan, the flight data showed that the pilot was maintaining a height of about 3,000 ft AMSL (770 ft AGL) on the Ballarat Milton Reservoir sector before the rapid descent.

Previous flights on the same route

The route chosen by the pilot was a standard route utilised by the flight training school for navigation flights. When questioned about ground clearance in line with the Black Mount high terrain feature, the flight training organisation indicated that students usually flew to the right or left of track in order to improve ground clearance. Three flight data recordings of previous flights conducted by other students showed that the sector between Ballarat Airfield and Melton Reservoir was either flown at 3,500 ft AMSL, and/or flown either side of Black Mount in order to provide greater ground clearance (Figure 17).

The flight training organisation reported that their training included emphasis on flight adjustments for raised terrain to always comply with the mandated AGL of 500 ft. This included instruction on changes made as part of flight planning to include consideration of that requirements. The accident flight was flown at 3,000 ft AMSL and its flight path was directly over the top of Black Mount. That gave the aircraft a ground clearance of about 800 ft over the high terrain at the aircraft’s cruise altitude.

Figure 17: GPS flight track data from the accident flight and three other training flights in the area of Black Mount

Figure 17: GPS flight track data from the accident flight and three other training flights in the area of Black Mount. Source: Google Earth, modified by the ATSB

Source: Google Earth, modified by the ATSB

Autopilot training and knowledge

Regulatory auto flight system training requirements

Civil Aviation Safety Regulation 1998 Part 61 Manual of Standards (MOS) Schedule 3 listed the aeronautical knowledge standards required for all licence categories including for the Recreational Pilot Licence (RPL) and Private Pilot Licence (PPL).

The assessable knowledge areas included topics related to basic and general aeronautical knowledge. The RPL knowledge standards did not include topics related to aircraft systems and autopilot knowledge. However, those knowledge standards were included at the PPL level and are as follows:

2.2 Aircraft systems

2.2.1 Describe or state the function of the following typical components installed in aeroplanes, including the possibility of ‘overpowering the system and associated precautions a pilot should take:

(a) stall warning devices;

(b) auto-pilot components, including the following:

(i) roll attitude heading pitch controls;

(ii) trim indicator;

(iii) cut-out mechanisms.

Schedule 5 Section G of the MOS outlined the flight test requirements, knowledge requirements and practical flight standards required to demonstrate competency for the issue of a RPL and aeroplane category rating (RPL (A)). There was no requirement included in that section for pilots to have knowledge of, or have demonstrated use of the aircraft’s auto flight systems.

The CASA Flight Examiners Handbook included guidance for examiners about testing requirements of various licence categories. The handbook referenced knowledge standards and units of competencies included in the MOS. At the time of the accident, the flight examiners handbook did not include a requirement for examiners to test student pilot auto flight systems knowledge.

The July 2017 version of the flight examiners handbook introduced a requirement for examiners to assess a student pilot’s auto flight systems knowledge at the RPL level. The RPL (A) assessment scope and conditions section included:

Where the aircraft is fitted with an autopilot system, the applicant must demonstrate competency in the system.

Despite this inclusion, the MOS was not amended to reflect the additional requirements at an RPL (A) level. In December 2017 the ATSB asked CASA if the MOS should reflect the changes made in the flight examiners handbook. CASA stated that:

The flight test standards in Part 61 of the MOS are being amended currently. The standards will align between the MOS, the flight test forms, and the examiners handbook.

The ATSB also asked CASA how the elements of the MOS support the changes in the flight examiners handbook with respect to autopilot use. CASA stated that:

The new flight test standards in schedule 5 of the Part 61 MOS for the RPL (A) include ‘manage the aircraft systems required for the flight’. This standard is elaborated in the examiners handbook.

With regards to the elaboration mentioned in the examiners handbook the only item identified was the previously mentioned sentence for demonstrate competency in the system.

Additionally, the ATSB asked CASA what its expectations were with respect to the level of knowledge and use of autopilot systems during RPL training. CASA stated that:

The training standards for the grant of a recreational pilot licence focus on the knowledge and skills required to operate a basic light aircraft. The standards do not mandate knowledge and the use of autopilot systems. Competency using any system in an aircraft is finally regulated by regulation 61.385. CASA expects a flight training operator would ensure trainee pilots are competent using the systems in an aircraft he or she is assigned to fly.

CASR 61.385 Limitations on exercise of privileges of pilots licences- general competency requirement, states:

(1) The holder of a pilot licence is authorised to exercise the privileges of the licence in an aircraft only if the holder is competent in operating the aircraft to the standards mentioned in the Part 61 Manual of Standards for the class or type to which the aircraft belongs, including in all of the following areas:

(a) operating the aircraft‘s navigation and operating systems;

(b) conducting all normal, abnormal and emergency flight procedures for the aircraft;

(c) applying operating limitations;

(d) weight and balance requirements;

(e) applying aircraft performance data, including take-off and landing performance data, for the aircraft.

Part 61 of the MOS does not cross reference CASR 61.385 for further information.

Flight training organisation requirements

Pilots at the RPL level were required by the flight training organisation to demonstrate the use of basic autopilot modes for the purposes of turning the aircraft 180° after inadvertent flight into cloud. Additionally, it was reported by the flight training organisation that basic autopilot modes could be used at times of high workload. Observations of the pilot’s ability to use basic auto-flight modes such as heading, and altitude hold were conducted prior to pilots obtaining a RPL and the conduct of solo navigation flights.

In addition to the in-flight observations of autopilot use, pilots conducted at least one hour in-flight using the G1000 avionics system, which included the use of basic autopilot modes in simulated instrument meteorological conditions (cloud) and one hour using the ground based flight trainer. The accident pilot had successfully completed training using the aircraft’s autopilot system and flight trainer.

The flight training organisation reported that during the early stages, pilots were trained only to use basic autopilot functions, however instructors did not have a formal training syllabus that included an assessment of the students underpinning knowledge of the autopilot system as included in the MOS at the PPL level.

The pilot involved in the accident asked their instructor if the autopilot could be used during training flights. The instructor advised the pilot that it was only to be used during high workload situations.

Federal Aviation Administration autopilot guidance for certification requirements

FAA AC Part 23.1329

The autopilot system fitted to the Cessna 172S aircraft is subject to the rules of certification by the country of manufacture (US) for normal, utility, acrobatic and commuter category airplanes.[8]

The relevant guidelines for certification requirements of autopilots at Part 23.1329 stipulates that:

Automatic pilot system.…

(e) Each system must be designed and adjusted so that, within the range of adjustment available to the pilot, it cannot produce hazardous loads on the airplane or create hazardous deviations in the flight path, under any flight condition appropriate to its use, either during normal operation or in the event of a malfunction, assuming that corrective action begins within a reasonable period of time.

The term 'reasonable period of time' is described in FAA advisory circular AC23.1329 (b) 1)) as being:

(b) A reasonable period of time has been established for pilot recognition between the time a malfunction is induced into the autopilot system and the beginning of pilot corrective action following hands-off or unrestrained operation. The following time delays have been acceptable:

(1) A three-second delay following pilot recognition of an autopilot system malfunction, through a deviation of the airplane from the intended flight path, abnormal control movements, or by a reliable failure warning system in the climb, cruise, and descent flight regimes.

Tests and research

Previous events involving autopilot systems

The ATSB requested information from the aircraft and avionics manufacturers about any incidents or accidents that have occurred involving in-flight upsets with autopilots ON and engaged in a vertical hold mode. The manufacturers did not have information that was similar to the VH-ZEW event.

The ATSB conducted a search of its database for in-flight upsets involving autopilots in light aircraft, it did not reveal any other similar incidents or accidents. The ATSB also conducted a search of the National Transportation Safety Board (NTSB) database. One accident, two incidents and a recommendation highlighting several others accidents were identified.

Mooney M20TN accident 27 July 2012 in Adrian, Michigan

NTSB report CEN12FA487 refers to an incident involving a Mooney M20TN with a Garmin G1000 avionics system and a GFC700 autopilot fitted. The autopilot manufacturer advised that the aircraft flight manual contained a warning that manual pilot input was not be applied with the autopilot engaged. The report indicated that with the autopilot engaged the aircraft had a violent pitch-up which required extreme forward pressure on the control yoke to keep the aircraft from pitching up and stalling. The report stated that:

The Airplane Flight Manual contains emergency procedures for use in the event of an autopilot out‑of‑trim event; the third item on the checklist directs pilots to re-trim the pitch, if necessary, using the trim wheel. The pilot noted that he did not attempt to use the manual trim wheel to change the airplane’s pitch attitude because that would have required him to release hand pressure on the control yoke. He was uncertain when or how the autopilot was disengaged.

The report indicated that the probable cause could not be determined as the examination of the aircraft did not identify any anomalies. However, contributing to the accident was the pilot’s failure to use the manual trim wheel to reset pitch trim.

Cessna 172S registered N813SP and N24485

NTSB reports ANC01FA100 and ATL02LA013 refer to Cessna 172S aircraft incidents in 2001 involving uncommanded pitch trim leading to controllability issues. No problems were identified in the trim or autopilot systems, however, manual control inputs with the autopilot ON were considered to have been a likely cause of those incidents. Both aircraft had the KAP140 autopilot systems fitted and the pilot’s guide for that autopilot contained a warning that manual pilot input was not be applied with the autopilot engaged.

NTSB safety recommendation to Beech Aircraft Corporation

Following a number of accidents and incidents in the United States involving light aircraft autopilot systems, the NTSB issued safety recommendation A-94-163 to Beech Aircraft Corporation, which stated:

Since 1983, a number of Beech airplanes, including the single-engine Model A-36 and twin-engine Models 58P and 95-C55, have been involved in 17 accidents and incidents wherein an autopilot failure, malfunction, or systems-related event was determined to be the cause of or a significant factor contributing to the occurrence. Eight of the accidents resulted in a total of 14 fatalities. In addition, from January 1, 1986, to June 10, 1994, 175 service difficulty reports were submitted to the FAA concerning various autopilot systems installed in Beech airplanes.

If the autopilot malfunctions, or if the airplane is improperly operated with the autopilot engaged, significant deviations of the flightpath, mistrimming of the airplane, or excessive control forces may occur. These may result from a runaway electric trim, or pilot attempts to oppose or overpower the autopilot pitch axis. For example, if a pilot attempts to overpower the pitch axis for more than several seconds, the autopilot trim servo, in most cases, will move the elevator trim tab in a direction that will countermand the pilot’s input. If the pilot continues to restrain the control wheel, the trim tab will continue to operate and the wheel control forces may eventually become overwhelming.

A review of the accidents discloses that a significant number might have been prevented if the autopilot system had been used correctly, or if appropriate remedial measures or emergency procedures had been performed to correct an autopilot malfunction or problem.

The NTSB recommendation gave three examples of accidents that had occurred in the early 1990s which involved autopilot systems fitted to Beech aircraft. The NTSB recommended that Beech Aircraft Corporation issue a safety communique regarding the function, operation, and limitations of autopilot systems installed in Beech airplanes, and the need for strict adherence to the prescribed operating and procedural instructions contained in the respective airplane flight manual supplements and autopilot operating manuals. The recommendation also stated that the communique should:

…point out the potential hazards of mistrimming the airplane through pilot-induced or other abnormal operation of the autopilot-electric trim system; and emphasize the importance of thoroughly understanding the remedial measures or emergency procedures that may be necessary to resolve an autopilot malfunction or problem.

Beechcraft (Raytheon Aircraft) responded to the recommendation stating that they had sent a safety communique to all known operators for all Beech airplane models in June 1996. During the ATSB’s investigation two Beechcraft POHs (Beechcraft Baron and Bonanza) that were reviewed had limitations and warnings about manual manipulation of the controls with the autopilot on.

Research on Automation in General Aviation

A United States Federal Aviation Administration research paper DOT/FAA/AM-97/24 titled Automation in General Aviation: Two studies of pilot responses to autopilot functions stated that:

...

The NTSB notes that if an autopilot malfunctions or an airplane is improperly operated with the autopilot engaged, significant deviations from the flightpath, mistrimming of the aircraft or the need for excessive control forces may occur. These problems may result from a runaway electric trim or pilot attempts to oppose or overpower the autopilot pitch axis. In most situations when a pilot attempts to overpower the pitch axis for more than several seconds, the autopilot trim servo will move the elevator trim tab in a direction that will countermand the pilot's input. If the pilot continues to restrain the control yoke and the autopilot/electric trim doesn't automatically disconnect, the trim tab will continue to operate and yoke forces may become overwhelming.

Contributing Factors

A number of factors are likely to contribute to the chain of events ultimately leading to an autopilot related accident. These may include, but are not limited to: insufficient pilot training, pilot lack of an underlying model of autopilot behavior, misdiagnosis of malfunction, organizational policies, pragmatic considerations, human performance limitations, and system designs that do not capitalize on human factors principles.

Insufficient training. There is presently no regulation stating that a pilot must receive training in the use of an autopilot before flying with one in an aircraft. Although such training is the rule in Part 121 operations for flight management systems, General Aviation is yet another story. Theoretically, one could fly any aircraft that one was checked out in, and if a model of that aircraft happened to have an autopilot, the pilot would be free to use it without specific instruction. The same is true for GPS and other systems that one could conceivably add to the aircraft. The tempering factors, one would expect, would be that a prudent pilot generally would learn everything possible about the airplane to be flown, particularly if it were owned or regularly flown by that pilot. Additionally, if the aircraft were leased, it would be expected that all potential lessees would be thoroughly checked out in aircraft systems operations prior to being allowed to lease the aircraft, usually for insurance purposes. This is often not the case, however.

Lacking conceptual model. It is also possible that pilots lack an underlying conceptual model of how the various components of the autopilot/auto trim system work in concert or in opposition. It has been argued that the ability to diagnose novel malfunctions (those not specifically encountered before) of a system is directly related to the availability of such a mental model of the system. In the case of general aviation, it is likely that many pilots will not have experienced autopilot failures prior to their first need to respond to one as pilot in command. Thus, the need to have a working knowledge of system structure and functional relationships is important to prevent the first encounter from being the last.

Misdiagnosis. The lack of an adequate conceptual model of the autopilot/autonav systems may also, as pointed out in the Chapel Hill accident example, result in a misdiagnosis of the malfunction, leading the pilot to non-productive actions that may further aggravate the flight control problem.

Organizational policies /pragmatic concerns. The way in which the pilot responds to malfunctions may also be dictated by organizational policy, particularly if the organization is responsible for its own ab initio or continuing flight training. Some organizations prefer that pilots "work with" the autopilot rather than immediately disconnecting it in cases where a malfunction is apparently mild and does not pose an immediate and obvious threat to safe flight. There is also a pragmatic consideration when the pilot is also the aircraft owner. If a service technician is to be called upon to remedy an apparent autopilot malfunction following the termination of the flight, additional data on the aberrant behavior will be helpful in localizing the problem, potentially reducing the time required for diagnostics by the technician and, thus, cost.

Human performance limitations. Both perceptual and motor human performance limitations are likely to affect how a pilot responds to autopilot malfunctions. Detection of malfunctions is decidedly influenced by limitations in visual and aural perception, specifically where a stimulus to be detected is not in or near the line of sight or where the stimulus is not above threshold or is steady state. It has been noted that some auditory alarms go unnoticed by pilots who have high-frequency hearing loss due to a combination of aging and work-place exposure to high-amplitude narrow-band sounds.

Human factors and design issues. It is sometimes the case that installed systems simply do not conform to the standard human factors practices and principles. The instrument panel is a land of infinite space, and not everything can be between zero and fifteen degrees below line of sight and located on the centerline of normal vision. This often results in systems that may be added on or optional equipment being located at the bottom of the radio stack or in the most convenient panel location available. If the unit contains displays that require frequent monitoring for continued safe operation, placement may make this impossible. It is also possible that warnings, be they visual or aural, may not conform to standards. One usual departure is the use of steady-state visual and aural warnings rather than alternating on/off/on warnings, which are more likely to attract the attention of the pilot.

Research on distraction

Researchers (United Kingdom Civil Aviation Authority, 2013[9]) have found that distraction has been a major factor affecting flight crew allocation of attention, particularly when effective monitoring breaks down. Humans are capable of attending to more than one task through the use of selective attention techniques, however they have limited total cognitive capacity. If one of the tasks consumes all the attentional capacity of a pilot, then task shedding will occur and other, important information may be missed by the pilot. Distraction has been found to have been instrumental in the breakdown of monitoring of aircrafts’ instruments and position in many accident investigations.

In the case of this accident, the time between the final descent and impact with terrain was around 20 seconds. Based on the recorded data, the avionics manufacturer indicated that there was sufficient time to recover from the descent and the probable out‑of‑trim situation before impact with terrain. They contended that the pilot’s focus of attention was likely to have been on the autopilot, rather than flying by visual references outside the aircraft. As shown in the research above, distraction can lead to a diversion of attention away from the primary task of flying the aircraft by a secondary distracting stimulus such as the autopilot.

The ATSB was unable to confirm if distraction led to a delay in recovery of the aircraft to normal flight. However, it could not be ruled out as a possibility.

Federal Aviation Administration Advanced Avionics Handbook

Federal Aviation Administration educational material FAA-H-8083-6 titled Advanced Avionics Handbook states that:

The Advanced Avionics Handbook is a new publication designed to provide general aviation users with comprehensive information on advanced avionics equipment available in technically advanced aircraft. This handbook introduces the pilot to flight operations in aircraft with the latest integrated “glass cockpit” advanced avionics systems.

The chapter on Automated Flight Control included a section titled ‘How to use an Autopilot Function’ which stated the following text:

6. Allow the FD/autopilot to accomplish the modes selected and programmed without interference, or disengage the unit. Do not attempt to “help” the autopilot perform a task. In some instances, this has caused the autopilot to falsely sense adverse conditions and trim to the limit to accomplish its tasking. In more than a few events, this has resulted in a total loss of control and a crash.

New investigation techniques

Flight data recording

The Cessna 172S has on-board flight data recording capability incorporated into the avionics system. This is becoming more common in newer light aircraft types. Flight data log files can be used for flight training review, trend analysis and troubleshooting defects. In this case, the downloaded data, stored on a removable secure data (SD) card, provided important information that assisted with identifying the contributing factors to this accident.

A previous accident investigated by the ATSB involving a Cessna 172S had a flight data log SD card destroyed by impact forces. Therefore, valuable accident investigation information was lost. In the accident involving ZEW however, the SD card was liberated from its housing and found 20 m from the main aircraft wreckage in a state that permitted the data to be recovered.

Some light aircraft types are fitted with integrated avionics systems that record a duplicate flight data log file to a crash survivable module, similar to that of a flight data recorder in larger aircraft types. This has, and will, continue to protect a valuable source of information for accident investigations worldwide.

  1. The pilot’s Recreational Pilot Licence was approved by the Civil Aviation Safety Authority two days after the accident.
  2. AC 25.1329-1C – US Federal Aviation Administration Advisory Circular that provides an acceptable means of compliance with the regulatory requirements contained in Part 25 (larger aircraft types) of the US Federal Aviation Regulations for the certification of autopilot systems.
  3. The post impact position of the elevator trim was considered unreliable due to significant wreckage disruption.
  4. The increase in engine RPM and fuel flow was due to the fixed pitch propeller windmilling effect as the airspeed increased.
  5. Secondary radar returns are dependent on a transponder in the aircraft replying to an interrogation from the from a ground station. An aircraft with its transponder operating is more easily and reliably detected by radar and, depending on the mode selected by the pilot; the aircraft pressure altitude is also displayed to the air traffic controller.
  6. Code 1200 is the transponder code required when operating VFR in class E and G airspace.
  7. The Cessna 172S autopilot is included in this category.
  8. United Kingdom Civil Aviation Authority. (2013). Monitoring matters: Guidance on the development of pilot monitoring skills. Loss of control action group. CAA Paper 2013/02.

Safety analysis

Introduction

During the pilot’s first solo navigation training flight, and while in the cruise, the aircraft pitched down, descended rapidly, and impacted with rising terrain. The on-site examination of the wreckage and analysis of the recorded flight data indicated that the aircraft was likely in a serviceable condition prior to the accident.

The witnesses in the area of the accident site indicated that Black Mount (the high terrain feature) and the aircraft were not obscured by cloud in the final moments of flight. That information, along with the forecast and actual weather information indicated that a loss of visual reference was not a factor in the accident.

The recorded flight data showed that just prior to the accident, the autopilot was being used in a vertical mode when the aircraft pitched down with a resultant increase in vertical descent rate and airspeed. The witness interviews and aircraft attitude evidence at impact indicated that the pilot had stopped the aircraft’s descent, and was in the process of recovery when the aircraft impacted rising terrain.

The cruise altitude equated to about 800 ft above ground level (AGL) in the local area of the accident site. That was below the minimum stipulated training flight height of 1,000 ft AGL, and the minimum cruise height for flight training autopilot operation of 1,500 ft AGL. The lower than normal altitude limited the pilot’s time to diagnose, react, and recover from an abnormal and emergency situation.

Downloaded data from other Garmin G1000 (G1000) equipped aircraft included training flights that either, operated at an altitude that was 500 ft higher than the accident flight over the same area, or flew around the high terrain feature in order to maintain a minimum altitude of 1,000 ft AGL. The lower altitude used by the pilot on the accident flight was likely due to the extent and base of the cloud.

The following analysis will examine the pitch-down event with the autopilot ON, pilot experience, pilot training, and manufacturer advice, limitations, and warnings.

Autopilot data analysis

The flight data showed that in total, the autopilot was used for about one third of the flight in various heading and vertical modes. This was considered by the flight training organisation to be excessive and beyond the instruction to only use it for brief periods during high workload situations.

The data showed numerous occasions where multiple and rapid flight director mode changes were made, followed by manual altitude adjustments. This indicated that the pilot may not have had an accurate mental model of the flight director modes and was not effective at controlling the aircraft’s altitude utilising the autopilot. Alternatively, it may have been indicative of the pilot experimenting with the autopilot functions, or perhaps a combination of both. The last 24 seconds of recorded data showed that the vertical modes had been changed between pitch and altitude hold six times.

At the initiation of the pitch-down event, the autopilot was on and engaged in a vertical mode. The pitch attitude did not match the pitch command recorded. Additionally, the final descent rate and pitch attitude went beyond the autopilot maximum rate limitations before the autopilot was disconnected. This indicated it was likely that the pilot had manually manipulated the flight controls during autopilot operation.

The autopilot validation flights conducted by the flight training organisation showed that if a rearward control input was made on the control yoke with the autopilot engaged in a vertical mode, the autopilot would trim against this input in order to maintain the set pitch attitude or altitude reference. Control forces continued to increase over time as the backpressure was maintained. Once the backpressure was released, the aircraft descended rapidly in an out of trim condition. Recovery from the descent was the same as the emergency actions required for an autopilot malfunction, which was, apply backpressure on the control yoke, switch the autopilot off, and re-trim the aircraft. The validation flights and accident flight data was compared and showed numerous similarities, such as:

  • significant pitch down beyond the autopilot capability
  • high vertical descent rates beyond the autopilot capability
  • a mismatch between actual pitch and flight director pitch commands
  • the autopilot remaining on in a vertical hold mode.

The similarities in data indicated a likely scenario for the accident sequence. That is, the pilot probably, but unintentionally, induced a mistrim situation by applying backpressure to the control yoke with the autopilot switched ON and engaged in a vertical mode. The increased control column force may have led the pilot to release, and/or decrease the backpressure on the flight controls when a significant out of trim condition existed. Analysis of the data indicated that the pilot had no more than 20 seconds between the start of the descent until the aircraft impacted with terrain. Despite this, recovery had commenced and the aircraft descent had been stopped. However, given the terrain was rising in front of the aircraft, this action was insufficient to prevent the impact.

Immediately prior to the pitch‑down event, the aircraft was being operated with the autopilot engaged about 700 ft below the minimum height permitted by the flight training organisation (1,500 ft AGL). Although that relatively low operating height was probably due to the extent and base of the cloud, it was insufficient for the pilot to recover the aircraft from the autopilot‑related mistrim.

The level pitch attitude of the aircraft at impact indicated that, had the weather permitted visual flight at the operator’s minimum autopilot height, the pilot would probably have recovered from a similar mistrim event.

Pilot experience, training and assessment

At the time of the accident, there was no regulatory requirement in the Part 61 Manual of Standards (MOS) for pilots to demonstrate knowledge and competence of the autopilot, its limitations, and the effects of trim until they had reached the Private Pilot Licence (PPL) level. Despite this, some pilots were operating autopilots as part of their training at the Recreational Pilot Licence (RPL) stage. Although pilots may have obtained some level of autopilot systems knowledge during their RPL training, competence in the use of those systems was not required to be formally assessed and therefore could not be assured.

In July 2017, the Civil Aviation Safety Authority (CASA) introduced an element into the Flight Examiners Handbook that required pilots to demonstrate knowledge of the autopilot system if fitted to an aircraft being used for an RPL assessment. At the time of writing this report CASA was in the process of modifying the Manual of Standards (MOS) to reflect the additional training to support the assessment required by the handbook.

CASA indicated that pilots operating aircraft with special features such as an autopilot are required to learn about them in accordance with the general competency rules in regulation CASR 61.385. There was no cross reference to this in the MOS or the flight examiners handbook at the time of the accident or at the time of drafting this report.

Although not mentioned in the MOS or flight examiners handbook at the RPL level, the flight training organisation did take measures to ensure student pilots operating the more complex G1000 autopilot equipped Cessna aircraft were familiar with the operation of heading and altitude hold modes. However, the pilot’s underpinning knowledge of the autopilot system could not be ascertained due to the absence of formal assessment against a competency standard.

The flight training organisation’s position was that the autopilot should only be used in high workload situations, or in the case of inadvertent flight into cloud. Examination of the recorded flight data indicated that the pilot used the autopilot extensively during the accident flight. In addition, the pilot’s use of various flight modes demonstrated a limited understanding of, and/or experimentation with, the autopilot system, its operation, and limitations. As such, it was probable that the pilot’s use of the autopilot outside of the basic modes, along with a limited understanding of the autopilot system, led to unsafe operation of the aircraft.

Pilot decision making, reaction times and distraction

As discussed in the Federal Aviation Administration (FAA) research paper Automation in General Aviation, insufficient autopilot training and a lack of conceptual model (how it works) may have undesired effects that lead to autopilot mishandling, misdiagnosis of autopilot issues and slow reaction times.

In the context of the VH-ZEW (ZEW) accident, the lack of underpinning knowledge may have led to the inexperienced student pilot unintentionally mishandling the operation of the autopilot. As a result of this, it would have taken some time to recognise that the autopilot had placed the aircraft in an out‑of‑trim condition, with limited time available to correct the situation. A slower reaction time may have been exacerbated by the lack of an audible alert for mistrim situations.

Research into distraction also indicated that pilots’ attention may be drawn away from the primary task of flying the aircraft by use of visual outside cues, if another secondary task such as resolving a technical issue or misunderstanding becomes the primary focus. While the avionics manufacturer considered distraction to be the reason for the apparent delay in recovering the aircraft, there was insufficient evidence to determine if that occurred. Similarly, the degree to which insufficient knowledge of the autopilot system may have played a part in the accident could not be determined.

Autopilot operational guidance limitations and warnings

The FAA Advanced Avionics Handbook indicated that manual manipulation of the flight controls with the autopilot on should be avoided, as it has led to total loss of control and accidents on several occasions. That was supported by research, which identified numerous small aircraft accidents and incidents relating to the issue.

Student pilots are instructed to read aircraft/avionics manufacturers operational guidance material in order to understand the various aircraft systems and operate the aircraft safely. The operational documentation for the superseded Cessna 172S Bendix/King KAP140 autopilot system contained limitations, cautions, and warnings about the manual manipulation of the flight controls during autopilot operation. Additionally, the system also incorporated an aural warning, to alert pilots if a mistrim or trim movement was occurring. In contrast, the newer integrated Garmin GFC700 (GFC700) autopilot system fitted to ZEW had no limitations, cautions, or warnings in the operational guidance documentation and no aural alert for mistrim or pitch trim movement. This had the potential to reduce pilot’s underpinning knowledge of the system and real time awareness of an issue.

The ATSB conducted a search of aircraft manuals for several other aircraft types that have the G1000/GFC700 fitted. About half of those aircraft types had relevant written limitations, cautions, and warnings.

The Cessna 172 is often used as a primary training aircraft, whose pilots inevitably have limited flight experience and a low knowledge base. Pilots at that level are reliant on operational guidance material and systems training to increase their knowledge on how to safely operate an aircraft. In the case of the ZEW accident, it was likely that the relatively inexperienced pilot was not aware of how the autopilot would react to manual control inputs, and that the autopilot had placed the aircraft in an out of trim situation. In the context that the occurrence pilot had not complied with the flight training organisation’s requirements regarding the use of the autopilot, it is difficult to conclude that additional guidance or alerting relating to its use would have altered the outcome of this accident. However, the inclusion of limitations, cautions, and warnings in the aircraft documentation, along with aural warnings would likely enhance pilot awareness of such situations and the associated hazards. Following on from those inclusions, it is of paramount importance that pilots are educated about the hazards involved in the manual manipulation of the flight controls with the autopilot on.

Findings

From the evidence available, the following findings are made with respect to the impact with terrain of a Cessna Aircraft Company 172S, registered VH-ZEW that occurred in Millbrook, Vic. on 08 September 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • During the pilot’s first solo navigation training flight, while cruising at about 800 ft above ground level, the aircraft pitched down, descended rapidly, and impacted with rising terrain. It is likely that the pilot manipulated the flight controls while the autopilot was engaged in a vertical mode. Consequently, the autopilot adjusted pitch trim to oppose manual control inputs, which led to a mistrim condition. For reasons that could not be established the pilot was unable to identify and/or correct the mistrim and recover the aircraft’s subsequent descent in the limited time available.
  • While probably influenced by the extent and base of the cloud, the autopilot was used below the minimum height required by the flight training organisation and too low to permit the pilot to recover the aircraft from the mistrim condition.

Other factors that increased risk

  • The lack of manufacturer written advice, limitations, cautions, or warnings (written or aural) about autopilot response to manual pilot control inputs meant that pilots may be unaware that their actions can lead to significant out of trim situations, and associated aircraft control issues [Safety Issue].
  • At the time of the accident the Civil Aviation Safety Authority’s Part 61 Manual of Standards schedule 3 for a Recreational Pilots Licence (RPL) did not specify that flight training organisations include a requirement for knowledge of all aircraft systems used by a pilot at an RPL level.
  • The flight training organisation incorporated some auto flight systems training at the Recreational Pilots Licence (RPL) level so that student pilots could utilise the system under limited circumstances. However, student pilots were not formally assessed against a competency standard to ensure they had an appropriate level of knowledge of auto flight systems, including limitations, cautions and warnings prior to use.

Safety issues and actions

The safety issue identified during this investigation is listed in the Findings and Safety issues and actions sections of this report. The ATSB expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Descriptions of each safety issue, and any associated safety recommendations, are detailed below. Click the link to read the full safety issue description, including the issue status and any safety action/s taken. Safety issues and actions are updated on this website when safety issue owners provide further information concerning the implementation of safety action.

Autopilot advice, limitations cautions and warnings (written and audible)

Safety issue numbers: AO-2015-105-SI-01 and AO-2015-105-SI-02

Safety issues description: The lack of manufacturer written advice, limitations, cautions, or warnings (written or aural) about autopilot response to manual pilot control inputs meant that pilots may be unaware that their actions can lead to significant out of trim situations, and associated aircraft control issues.

Proactive safety action

Flight training organisation

Following the accident, the flight training organisation conducted flight tests to determine autopilot reaction to pilot flight control inputs. The results of that testing was shared with the ATSB. Following that testing RMIT amended its standard operating procedures to include the following:

Warning: Pilots are to note that if a force is applied to control column whilst the autopilot is engaged, that the aircraft’s autopilot system will trim against the control column force that the pilot has applied. This can lead the aircraft to be in a significantly mistrimmed situation, and loss of control is possible. The GFC700 Autopilot will give no audible indication when this mistrim situation is developing.

A staff meeting was also held on the 17 August 2016 to discuss the outcome of the flight testing of the autopilot system. It was emphasised to the flight instructors that they must make their students aware of the risks of manipulating the controls with the autopilot on as a mistrim will occur as a consequence. Emphasis was also placed on the need to ensure the autopilot system before take-off checklist was conducted correctly to ensure the correct mode selection and ability to overpower the system.

A check of the safety management system was conducted in an effort to identify any other autopilot related issues. None were identified.

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • flight training organisation
  • pilot’s instructor
  • witnesses near the accident site
  • pilot operating in the area of the accident site
  • Victorian Police Department
  • Victorian Institute of Forensic Medicine
  • Bureau of Meteorology (BoM)
  • Airservices Australia
  • aircraft manufacturer
  • avionics manufacturer
  • Civil Aviation Safety Authority (CASA)
  • United States National Transportation Safety Board (NTSB) and Federal Aviation Administration (FAA).

References

US Department of Transportation, Federal Aviation Administration, FAA-H-8083-6, 2009, Advanced Avionics Handbook, Preface & Chapter 4-2.

U.S. Department of Transportation, Civil Aeromedical Institute, Federal Aviation Administration, Dennis B. Beringer & Howard C. Harris Jr. DOT/FAA/AM-97/24, 1997, Automation in General Aviation: Two Studies of Pilot Responses to Autopilot Malfunctions, pp. 2-3.

United Kingdom Civil Aviation Authority. (2013). Monitoring matters: Guidance on the development of pilot monitoring skills. Loss of control action group. CAA Paper 2013/02.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the pilot’s next of kin, the flight training organisation, the pilot’s instructor, the aircraft manufacturer, the avionics manufacturer, the NTSB, the BoM, the Victorian Coroner’s representative and CASA.

Submissions were received from the flight training organisation, the aircraft and avionics manufacturers and CASA. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through: 

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2018

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-105
Occurrence date 08/09/2015
Location near Millbrook
State Victoria
Report release date 18/04/2018
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Collision with terrain
Occurrence class Accident
Highest injury level Fatal

Aircraft details

Manufacturer Cessna Aircraft Company
Model 172S
Registration VH-ZEW
Serial number 172S11079
Sector Piston
Operation type Flying Training
Departure point Point Cook, Vic
Destination Point Cook, Vic
Damage Destroyed

Collision between track worker and passenger train, at Guildford, Western Australia, on 10 February 2015

Preliminary report

Preliminary report released 7 September 2015

On the morning of 10 February 2015, a track worker was struck by a Perth bound suburban passenger train at the Meadow Street level crossing at Guildford, WA.  The track worker sustained fatal injuries.

Context

Location

Meadow Street level crossing is located in Guildford, Western Australia, about 13 km from Perth Railway Station. The level crossing consists of dual-gauge double-track railway over a dual carriageway road with pedestrian walkways on both sides. The crossing is immediately adjacent to the road intersection between Meadow Street and James Street. The road intersection is controlled by traffic lights which work in conjunction with the level crossing equipment.

The level crossing and associated pedestrian gates were maintained by the PTA.

Track information

The track at Meadow Street was part of the dual-gauge line from Midland to East Perth; consisting of both narrow gauge (1067 mm) and standard gauge track (1435 mm) using a common rail.

The level crossing was equipped with boom gates, flashing warning lights and bells for road traffic. The pedestrian walkway included automatic gates and electronic alarms for pedestrian traffic, with a pedestrian escape route in the event that the gates closed while pedestrians were still crossing the track.

The Meadow Street level crossing used electronic approach and outer approach track circuits to detect the approach of trains from either direction on either line (Figure 2). When a train is detected on the approach, the control circuit causes the level crossing bells and lights to activate, and the boom gates to lower. In addition, the automatic pedestrian gates close and the pedestrian alarms sound. Due to the proximity to the James Street intersection, an indication is provided to the road traffic light control system to manage any traffic intending to turn into Meadow Street.

The purpose of the outer approach circuits is to prevent the level crossing boom gates from rising and descending in quick succession if a second train is approaching the crossing. If the level crossing equipment is already operating and a train detected on the outer approach, the boom gates remain lowered and the pedestrian gates remain closed until the second train has passed.

Figure 2: Diagram of Meadow Street level crossing, Guildford, WA

Figure 2: Diagram of Meadow Street level crossing, Guildford, WA

Source: PTA amended and annotated by ATSB

Train information

The PTA operate two types of electric multiple unit (EMU) railcars. The A-series EMUs (as involved in this incident) are comprised of two semi-permanently coupled railcars which are 48.42 m in length and have a gross weight of 114 t. The railcars’ maximum operating speed was 110 km/h.

Train services 9572 and 9573 were suburban services, stopping at all stations and operating between Perth and Midland.

Train crew information

Train 9572 was operated by a single driver. At the time of the incident the driver was appropriately qualified and trained to operate A-series railcars over the Perth - Midland route.

Following the incident the driver was tested for the presence of alcohol and other drugs and the results were negative.

Maintenance team information

The signals maintenance team working at Meadow Street consisted of:

  • PTA employee who was qualified in worksite protection and was working as the protection officer
  • contractor qualified and working as a signal technician
  • second contractor with qualifications of a signal technician but working as a maintainer.

All personnel had a safe working qualification allowing them to work within the rail reserve without supervision. The PTA employee (protection officer) had additional safe working qualifications allowing him to provide worksite protection associated with working on or about the railway reserve.

Environmental conditions

A weather report from Perth Airport (approximately 4km south of Meadow Street) showed the temperature at the time of the accident was about 27 degrees, with fine conditions and light winds.

As such, weather conditions were considered as unlikely to have contributed to the occurrence.

Maintenance Tasks

The track workers’ task was to undertake maintenance of the level crossing and pedestrian gates at Meadow St. The signal technician and maintainer carried out electrical checks, while the protection officer conducted maintenance on the boom gates and pedestrian gates.

Pedestrian Gates

To facilitate maintenance of the level crossing equipment, certain tasks require the crossing to be operating while work is being carried out. This work includes tasks such as circuit testing and checks of the boom and pedestrian gate operation. In some cases, these tasks required the signal technician or maintainer to work close to or inside the danger zone[4].

One such task was the inspection and, if required, adjustment of the pedestrian gate closing mechanism. The gate control box was located inside the pedestrian escape, with the control arm running from the box to the gate on the track side (Figure 3) - about 3 m from the railway line.

A level crossing test switch[5] was provided at Meadow Street that can facilitate operation of the crossing equipment when trains were not present. Despite the availability of a test switch, it was common practice for maintenance personnel to rely on scheduled train services to facilitate operation of the crossing equipment for testing and maintenance of the pedestrian gates. At interview, signalling personnel reported a reluctance to use the switch, in light of the view that it would (unnecessarily) close the crossing to road traffic. In addition, there was a slight difference in the operation of the pedestrian gates when initiated by the test switch (when gates would close under spring tension only) compared with normal operation when activated by a rail vehicle (when gates would close under a combination of spring tension and motor control).

Figure 3: General arrangement of south-western pedestrian gate

Figure 3: General arrangement of south-western pedestrian gate

Figure 3: General arrangement of south-western pedestrian gate

Source: ATSB

Maintenance personnel advised that to assess or adjust the control arm required track workers to stand inside the three metre danger zone. Some maintainers would carry out the task with the gate open, working in the escape area with the gate acting as a barrier to the track. However, it was evident that some other maintainers carried out the task when the gate was closed, in which case there was no barrier protecting them against inadvertently stepping onto the track.

It was apparent that the process for conducting maintenance on level crossing pedestrian gates varied between maintenance personnel. In this case, the workers adopted a process whereby the presence of a train was used to operate the level crossing equipment and maintenance and/or adjustment of the gate control arm was undertaken while the gate was in the closed position. This process meant that workers would be positioned within the danger zone, and focused on the maintenance task, at a time when trains were present and without a barrier between themselves and the track.

Worker safety and worksite protection

The safety of personnel working on and around operating rail services is achieved through a number of complementary safety measures. These can be grouped into two general areas:

Worksite protection

These are the measures put in place to mitigate the risk of injury from railway operational hazards. That is, ensuring separation between track workers and train operations.

Worker safety

These are the measures put in place to mitigate the risk of injury from site specific hazards and task specific hazards.

Worksite protection

Rail systems within Australia use various methods to ensure track workers carrying out maintenance tasks are kept separate from rail traffic. The higher levels of protection involve exclusion of rail traffic from a worksite and can include the complete closure of the railway (or part thereof). The lower levels of protection permit work to be undertaken between train services and can use other employees to warn track workers of approaching rail vehicles.

Access to maintain suburban railway networks is often more restrictive than for freight networks due to the volume and frequency of rail traffic. Works that require the railway to be closed, even for a short period of time, are generally only permitted at night when the frequency of rail vehicles has reduced. Works carried out during the day are usually associated with general maintenance or inspection tasks that can be achieved without closing the railway.

The rules for providing worksite protection are documented in the PTA Network Rules. Where track workers are working in the danger zone with hand tools only and have the ability to move to a place of safety prior to the arrival of any oncoming rail vehicle, Lookout Protection is routinely adopted for worksite protection. Rule 191 documents the requirements for lookout protection.

The purpose of lookout protection is to task a person or persons to maintain a watch for approaching trains - allowing track workers to be suitably warned to stop work, move to a place of safety and allow the train to pass before returning to work. A place of safety is defined in the PTA Network rules as either:

  • Where there is at least 3 m clearance between the person and the nearest running line (rail)
  • Properly constructed for use as a refuge
  • Where a structure or physical barrier has been erected to provide protection
  • Behind the safety line on a platform.

Under lookout protection, the lookout’s sole duty must be to maintain a constant watch for trains and no other work[6] may be undertaken. A lookout is only required when track workers are within, or likely to go within, the danger zone. Should the work be outside the danger zone, the lookout may perform other duties, however should track workers resume works within, or likely to go within the danger zone, the lookout must resume the exclusive lookout role.

In this occurrence, the ATSB found that prior to commencing work, the protection officer had not discussed the worksite protection method with the train controller or the contractors. It was evident that the role of a lookout had not been allocated, as all three track workers continued to be engaged in maintenance tasks. At the time of the collision, the protection officer was involved with maintenance tasks rather than the assigned role of protection officer.

Worker safety

The PTA had implemented two levels of hazard assessment to ensure worker safety.

Job Safety Analysis (JSA) forms
Job Safety Analysis (JSA) forms were used to document and assess the risks inherent to conducting the particular job at hand. The JSA for Maintenance of Automatic Pedestrian Crossing Equipment provided information such as the number of people required to carry out the job, equipment and training required, and a risk matrix containing a selection of high level generic risks that should be considered prior to commencing the job.

In the context of this incident, the JSA identified ‘Being hit by a train’ as a potential hazard, with the associated controls identified as ‘Adherence to safety procedures - assign competent lookout, obtain prior train information (booking on track)’.

Pre-start checklist
Pre-start checklists were used as a record that workers had considered all issues that ensure a task could be undertaken safely. The checklist is a generic form that can be used for any site or task and records information such as date, location, task and names of workers. The checklist records acknowledgment that workers have considered and understand the scope of work and the measures required to undertake the work safely, such as the information contained in the JSA.

The ATSB found that the site team, in this case, had not completed the pre-start checklist prior to commencing work at Meadow Street. While it is likely that the workers were aware of the JSA for pedestrian gate maintenance, there was no record that they had considered the risk controls contained therein to ensure worker safety.

__________

  1. Industry term generally considered everywhere within 3m horizontally from the nearest rail and any distance above or below this 3 m, unless a safe place exists or has been created.
  2. Also known as a flagman switch or manual switch. Used to manually activate the level crossing.
  3. Work is generally defined as any activity within the danger zone other than walking directly from one side of the rail reserve to the other.

Ongoing investigations

The investigation is continuing and will include an examination of the following:

  • Policies and procedures for safe working practices adopted by the PTA
  • The training programs for safe working practices and undertaking work on track
  • The human performance and behavioural factors that may have contributed to the incident.

Preliminary findings

From the evidence available, the following preliminary findings are made with respect to the fatality at Guildford, Western Australia on 10 February 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time..

Contributing factors

  • Worksite protection had not been adequately implemented to ensure workers were protected against inadvertently stepping into the path of a train while undertaking maintenance work.
  • It was common practice for maintenance personnel to adopt a process that was inherently less safe than an alternative when maintaining automatic pedestrian crossing equipment.
  • The Public Transport Authority of Western Australia did not have documented instructions to ensure a consistent and safe approach to maintaining automatic pedestrian crossing equipment. [Safety issue]

Safety analysis

The Western Australia Rail Safety Regulations 2011 prescribe the requirements that all railway operators in Western Australia must include in their safety management systems. Schedule 1, Clause 17 (4) requires a railway operator to have ‘systems, procedures and standards’ for monitoring and maintenance of rail infrastructure.

The Office of Rail Safety (Western Australia) makes reference to a publication titled National Rail Safety Guideline - Preparation of a Rail Safety Management System[7] for guidance on the development of these procedures and standards; specifically that railway operators should provide safe work procedures that include:

  • A description of the activity
  • Identification of the person or position that has a supervisory responsibility for the activity or process
  • A clear explanation in sequential order, of the steps or stages comprising the procedure or process
  • Identification of potential hazards in the process
  • Identification of safety controls to minimize potential risk from any identified hazards

The PTA Signalling Equipment Maintenance Manual provided a checklist which detailed all necessary tasks required to maintain automatic pedestrian crossings. The JSA identified the potential hazards and relevant safety controls, while the pre-start checklist recorded workers’ acknowledgment of these measures. While individually, these documents addressed the stated requirements of the regulations and guidelines, the incident on 10 February 2015 illustrated that the intent of the system was not met (that is, to ensure work is carried out to a consistent level of quality and safety). Explicitly, there were no instructions requiring that the work on the pedestrian crossing system be carried out in a manner that did not create an increased risk of being struck by operating train services and was consistent between all maintenance teams.

It was evident that the process for maintaining pedestrian gates varied between work groups. While not specified, the requirement in the JSA to assign a lookout implied that Rule 191 (lookout protection) should be adopted when maintaining pedestrian gates. Rule 191 requires workers to ‘…move from the track and stand clear in a position of safety at least 10 seconds before rail traffic arrives and remain clear until the rail traffic has passed by’. However, for some workers, it was common practice to carry out maintenance and adjustment of pedestrian gates (within the danger zone) while rail traffic was passing. It was evident that this process had been adopted by the maintenance team at Meadow Street level crossing on 10 February 2015.

An alternative practice adopted by some workers more closely aligned with the requirements documented in Rule 191. This involved maintaining the gates from within the pedestrian escape area while trains were not present. When a train was approaching, the workers would stop the maintenance task and only observe the gate operation. The workers would note any operational issues and, upon passing of the train, would make the necessary adjustments.

In any case, the absence of specific documented instructions meant that maintenance personnel adopted a variety of inspection, adjustment and maintenance practices – some of which may be inherently less safe than alternatives.

__________

  1. Published by the National Transport Commission (2008). The document was republished (2014) by the Office of the National Rail Safety Regulator and titled Preparation of a Safety Management System Guideline.

Safety issues and actions

The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.

Where relevant, safety issues and actions will be updated on the ATSB website as information comes to hand. The initial public version of these safety issues and actions are in PDF on the ATSB website.

Documented instructions

The Public Transport Authority of Western Australia did not have documented instructions to ensure a consistent and safe approach to maintaining automatic pedestrian crossing equipment.

Safety issue No. RO-2015-002-SI-01

Sources and submissions

Sources of information

The sources of information during the investigation included the:

  • Bureau of Meteorology.
  • Public Transport Authority of WA.
  • Brookfield Rail.
  • National Guideline Glossary of Railway Terminology Version 1.0, 3 December 2010 Railway Industry Safety and Standards. Board of Australia (RISSB).

References

  • Public Transport Authority Network Rules 2000.
  • Public Transport Authority Appendix to the Network Rules 2000.
  • Public Transport Authority, Signalling Equipment Maintenance Manual – Schedule of Maintenance Tasks 8100-600-046.
  • Western Australia Rail Safety Regulations 2011.

Submissions

Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.

A draft of this report was provided to the Public Transport Authority of Western Australia, WA Office of Rail Safety and individuals directly involved in the occurrence.

Submissions were received from Public Transport Authority of WA. The submissions were reviewed and where considered appropriate, the text of the report was amended accordingly.

 

 

The occurrence

The information contained in this Preliminary report is released in accordance with section 25 of the Transport Safety Investigation Act 2003 and is derived from the ongoing investigation of the occurrence. Readers are cautioned that new evidence will become available as the investigation progresses that will enhance the ATSB's understanding of the accident as outlined in this Preliminary report.

On the morning of 10 February 2015, Public Transport Authority of Western Australia (PTA) signal maintenance crews commenced duty at Claisebrook depot. The crews were arranged into teams according to their qualification and skill sets. One of these teams consisted of a PTA employee and two contractors. The PTA employee was a maintainer, but on this day he was undertaking the role of the protection officer[1] to provide safe working protection to the contractors. One of the contractors, who had more experience on the PTA network, was given the role of signal technician while the other was allocated maintenance duties.

At about 0830 the team departed Claisebrook depot and drove to the Meadow Street level crossing in Guildford, WA. On arrival, the protection officer contacted train control and booked on-track[2]. The team then commenced work, where the protection officer cleaned and maintained the pedestrian gates while the signal technician and maintainer carried out electrical testing.

At about 1019, down[3] suburban passenger service 9571 approached the Meadow Street level crossing from the west (Figure 1). When the level crossing protection equipment (gates, lights and bells) activated, the maintainer noticed the north-west pedestrian gate was not closing completely. He advised the signal technician who, as train 9571 passed through the crossing, called the protection officer over to help assess whether the pedestrian gate needed to be adjusted.

Figure 1: Location map – Meadow Street level crossing, Guildford

Figure 1: Location map – Meadow Street level crossing, Guildford

Source: Google earth annotated by ATSB

At about 1032, train 9573 approached the Meadow Street level crossing from the west. The team, after again observing the operation of the pedestrian gate, decided to compare the control arm settings with the south-west pedestrian gate control arm. After train 9573 had passed through the crossing, the protection officer and the maintainer crossed the railway to the south-west pedestrian gate while the signal technician returned to the electrical location case. The level crossing protection equipment continued to operate because another train (9572) was approaching the crossing from the east, although it could not be seen at the time. The maintainer mentioned to the protection officer that there was another train coming, which the protection officer acknowledged.

The protection officer and maintainer examined the south-west pedestrian gate control arm and agreed its adjustment was different to the north-west pedestrian gate. Meanwhile, up suburban passenger service 9572 continued to approach from the east. The driver of 9572 sounded the horn on approach to Meadow Street and noticed two people working on the trackside of the pedestrian gates.

Moments later, the protection officer turned to his right, facing away from train 9572, and started to walk towards the track. The maintainer who saw the train approaching the level crossing, called out a warning and attempted to stop the protection officer. The driver of 9572 saw the protection officer step towards the track and immediately made an emergency brake application.

At approximately 1035, train 9572 struck and fatally injured the protection officer as it passed through the crossing – coming to a stop a short distance further along the track. The signal technician (at the location case) heard the collision and called out to the maintainer, who replied the protection officer had been hit by the train.

Post-occurrence

The signal technician and maintainer immediately returned to their vehicle and contacted their supervisor. At the same time the driver of 9572 contacted train control and advised he had struck a person at Meadow Street level crossing.

All train services between Bassendean and Midland were suspended and the level crossing was closed to traffic. The PTA, emergency services, WA Office of Rail Safety (ORS) and Worksafe WA attended the site.

At about 1200 the signal technician and maintainer were taken back to Claisebrook depot. Drug and alcohol testing was conducted – returning negative results.

At about 1300, train 9572 was moved to the Claisebrook depot for examination.

__________

  1. Nationally recognised term to describe a person who provides worksite protection (RISSB Glossary of Railway Terminology 2010). This qualification is similar to a WPW15 accreditation on the PTA Network.
  2. Industry term used to describe contacting train control and advising them of the works to be undertaken at that location
  3. Trains on the Midland line travelling away from Perth are referred to as down trains, travelling towards Perth as up trains

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2015

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Final report

Safety summary

What happened

On 10 February 2015, a Public Transport Authority (PTA) maintenance crew commenced work at Meadow Street, Guildford, Western Australia. The crew’s assigned tasks included maintaining the pedestrian gates adjacent to the level crossing.

At about 1035 one of the track workers was struck by a Perth-bound suburban passenger train. The track worker sustained fatal injuries.

What the ATSB found

The ATSB investigation found that the PTA maintenance workers had not implemented any form of track worker protection at the work site. This was partially due to the PTA not having documented instructions specifying the level of protection required, preferring that track workers make their own assessment based on their knowledge of the Network Rules. The ATSB found that, under these arrangements, track workers could make an incorrect assessment, placing themselves at a greater risk of being struck by a train.

A review of the safeworking training provided to the track workers found that the training material did provide a suitable level of safe-working knowledge.

Following the occurrence, the toxicology report on the deceased track worker identified the presence of amphetamine and methamphetamine; methamphetamine being a prescribed drug under the Rail Safety Regulations 2011. The use of stimulants such as methamphetamine is associated with a range of neurocognitive effects in humans that may affect performance.

The ATSB found that in this instance, the presence of a prescribed drug within the worker’s system appeared to be a relatively isolated case. An examination of the company’s drug and alcohol policy / procedures found them to be generally effective in managing drugs and alcohol in the workplace.

What's been done as a result

The PTA issued a safety alert following the incident to highlight the importance of implementing the correct level of track worker protection. The subsequent introduction of new safeworking rules, track access accreditation levels and training further supported this.

Further, the PTA has created the role of Workplace trainer and assessor with the task of ensuring track workers comply with the network rules by way of competency-based assessments. Implementation of a new track access accreditation system, with improved training and job mentoring, has also commenced.

Safety message

This incident strongly emphasises the need for rail transport operators to provide clear and concise work instructions to employees working within the railway corridor. It also highlights the potential for recreational and other drug use to impair performance and affect workplace safety.

Meadow Street pedestrian gate

Meadow St pedestrian gate

Source: ATSB

Findings

From the evidence available, the following findings are made with respect to the fatality at Guildford, Western Australia on 10 February 2015. These findings should not be read as apportioning blame or liability to any particular organisation or individual.

Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.

Contributing factors

  • Worksite protection had not been adequately implemented to ensure workers were protected against inadvertently stepping into the path of a train while undertaking maintenance work.
  • When maintaining automatic pedestrian crossing equipment, it was common practice for maintenance personnel to adopt a process that was inherently less safe than an alternative.
  • The Public Transport Authority of Western Australia did not have documented instructions to ensure a consistent and safe approach to maintaining automatic pedestrian crossing equipment. [Safety issue]

Other Safety Factor

  • The Protection Officer tested positive to a substance that may impair performance, however it was not possible to determine whether this contributed to the incident.

Other findings

  • The Public Transport Authority’s Alcohol and Other Drug policy was found to be comprehensive and compliant with legislative requirements
  • The Public Transport Authority A-series rail cars do not have a dedicated system that records events such as the sounding of the horn.

The occurrence

On the morning of 10 February 2015, Public Transport Authority of Western Australia (PTA) signal maintenance crews commenced duty at Claisebrook depot. The crews were arranged into teams according to their qualification and skill sets. One of these teams consisted of a PTA employee and two contractors. The PTA employee was a maintainer, but on this day, he was undertaking the role of the protection officer[1] to provide safe working protection to the contractors. One of the contractors, who had more experience on the PTA network, was assigned the role of signal technician while the other was allocated maintenance duties.

At about 0830, the team departed Claisebrook depot and drove to the Meadow Street level crossing in Guildford, WA. On arrival, the protection officer contacted train control and booked on-track[2]. The team then commenced work, where the protection officer cleaned and maintained the pedestrian gates while the signal technician and maintainer carried out electrical testing.

At about 1019, down[3] suburban passenger service 9571 approached the Meadow Street level crossing from the west. When the level crossing protection equipment (gates, lights and bells) activated, the maintainer noticed the north-west pedestrian gate was not closing completely. He advised the signal technician who, as train 9571 passed through the crossing, called the protection officer over to help assess whether the pedestrian gate needed adjusting.

Figure 1: Location map – Meadow Street level crossing, Guildford

Figure 1: Location map – Meadow Street level crossing, Guildford

At about 1032, train 9573 approached the Meadow Street level crossing from the west (Figure 1). The team, after again observing the operation of the pedestrian gate, decided to compare the control arm settings with the south-west pedestrian gate control arm. After train 9573 had passed through the crossing, the protection officer and the maintainer crossed the railway to the south-west pedestrian gate while the signal technician returned to the electrical location case. The level crossing protection equipment continued to operate because another train (9572) was approaching the crossing from the east, although it could not yet be seen. The maintainer mentioned to the protection officer that there was another train coming, which the protection officer acknowledged.

The protection officer and maintainer examined the south-west pedestrian gate control arm and agreed its adjustment was different to the north-west pedestrian gate. Meanwhile, up suburban passenger service 9572 continued to approach from the east. The driver of 9572 sounded the horn on approach to Meadow Street and noticed two people working on the track side of the pedestrian gates.

Moments later, the protection officer turned to his right, facing away from train 9572, and started to walk towards the track. The maintainer, who saw the train approaching the level crossing, called out a warning and attempted to stop the protection officer. The driver of 9572 saw the protection officer step towards the track and immediately made an emergency brake application.

At approximately 1035, as it passed through the crossing, train 9572 struck and fatally injured the protection officer – coming to a stop a short distance further along the track. The signal technician (at the location case) heard the collision and called out to the maintainer, who replied that the protection officer had been hit by the train.

Post-occurrence

The signal technician and maintainer immediately returned to their vehicle and contacted their supervisor. At the same time, the driver of 9572 contacted train control and advised he had struck a person at the Meadow Street level crossing.

All train services between Bassendean and Midland were suspended and the level crossing closed to traffic. The PTA, emergency services, WA Office of Rail Safety (ORS) and Worksafe WA attended the site.

At about 1200, the signal technician and maintainer were taken back to Claisebrook depot. Drug and alcohol testing was conducted – returning negative results.

At about 1300, train 9572 was moved to the Claisebrook depot for examination.

__________

  1. Protection Officer is a nationally recognised term to describe a person who provides worksite protection (RISSB Glossary of Railway Terminology 2010) and is used in that context throughout this report. At the time of this incident, a worker who held WPW15 accreditation was responsible for worksite protection, though the term Protection Officer was not used. As of 1 August 2015, the PTA introduced protection officer qualifications, which included additional safeworking training beyond that previously supplied under a WPW15 accreditation.
  2. Industry term used to describe contacting train control and advising them of the works to be undertaken at that location
  3. Trains on the Midland line travelling away from Perth are referred to as ‘down’ trains, travelling towards Perth as ‘up’ trains

Safety issues and actions

The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.

Depending on the level of risk of the safety issue, the extent of corrective action taken by the relevant organisation, or the desirability of directing a broad safety message to the rail industry, the ATSB may issue safety recommendations or safety advisory notices as part of the final report.

Documented Instructions

The Public Transport Authority of Western Australia did not have documented instructions to ensure a consistent and safe approach to maintaining automatic pedestrian crossing equipment.

Rail safety issue: RO-2015-002-SI-01

Context

Location

Meadow Street level crossing is located in Guildford, Western Australia, about 13 km from Perth Railway Station. The level crossing consists of dual-gauge double-track railway over a dual carriageway road with pedestrian walkways on both sides. The crossing is immediately adjacent to the road intersection between Meadow Street and James Street. The road intersection is controlled by traffic lights, which work in conjunction with the level crossing equipment.

The PTA maintained the level crossing and associated pedestrian gates.

Track information

The track at Meadow Street was part of the dual-gauge line from Midland to East Perth; consisting of both narrow gauge (1067 mm) and standard gauge track (1435 mm) using a common rail. The track in this area was part of the Australian Defined Interstate Rail Network (DIRN).

The level crossing was equipped with boom gates, flashing warning lights and bells for road traffic. The pedestrian walkway included automatic gates and electronic alarms for pedestrian traffic, with a pedestrian escape route in the event that the gates closed while pedestrians were still crossing the track.

The Meadow Street level crossing used electronic approach and outer approach track circuits to detect the approach of trains from either direction on either line (Figure 2). When a train is detected on the approach, the control circuit causes the level crossing bells and lights to activate, and the boom gates to lower. In addition, the automatic pedestrian gates close and the pedestrian alarms sound. Due to the proximity to the James Street intersection, an indication is provided to the road traffic light control system to manage any traffic intending to turn into Meadow Street.

The purpose of the outer approach circuits is to prevent the level crossing boom gates from rising and descending in quick succession if a second train is approaching the crossing. If the level crossing equipment is already operating and a train detected on the outer approach, the boom gates remain lowered and the pedestrian gates remain closed until the second train has passed.

Figure 2: Diagram of Meadow Street level crossing, Guildford, WA

Figure 2: Diagram of Meadow Street level crossing, Guildford, WA

The level crossing bells and lights operate when trains are detected on the approach track circuits (shown in green). If the crossing is already operating, it will continue to operate if another train is detected on either the approach track circuits or the outer approach track circuits (shown in blue). Source: PTA amended and annotated by ATSB

Train information

The PTA operates two types of electric multiple-unit (EMU) railcars. The A-series EMUs (as involved in this incident) are comprised of two semi-permanently coupled railcars, which are 48.42 m in length and have a gross weight of 114 t. The railcars’ maximum operating speed was 110 km/h.

Train services 9572 and 9573 were suburban services, stopping at all stations and operating between Perth and Midland.

Event recorders

The A-series railcars were fitted with an Automatic Train Protection (ATP) system to reduce the risk of train drivers passing a signal at danger / stop. The system also provided digital recordings of train performance such as braking, power applied, speed, etc. However, the A-series were not fitted with dedicated event recorders. In addition to the performance elements described above, an event recorder typically records operation of other mechanical and control systems such as the horn; providing important information to aid in the analysis of a safety occurrence.

Train crew information

Train 9572 was operated by a single driver. At the time of the incident the driver was appropriately qualified and trained to operate A-series railcars over the Perth - Midland route.

Following the incident the driver was tested for the presence of alcohol and other drugs and the results were negative.

Maintenance team information

The signals maintenance team working at Meadow Street consisted of:

  • a PTA employee who was qualified in worksite protection and was working as the protection officer
  • a contractor qualified and working as a signal technician
  • a second contractor with qualifications of a signal technician but working as a maintainer.

All personnel had a safe working qualification allowing them to work within the rail reserve without supervision. The PTA employee (protection officer) had additional safe-working qualifications allowing him to provide worksite protection associated with working on or about the railway reserve.

Drug and Alcohol testing

Following the incident, the signal technician and maintainer underwent preliminary screening for the presence of alcohol and prescribed drugs. Both tests returned a negative result.

As part of the coronial investigation into the accident, a toxicology examination was undertaken on the deceased worker. The examination was unable to confirm the presence of alcohol, but amphetamine and methamphetamine were present in the samples tested. Methamphetamine is classed as a prescribed drug under the Rail Safety Regulations 2011 - the legislation applicable to the PTA’s operations at the time of the incident.

Environmental conditions

A weather report from Perth Airport (approximately 4km south of Meadow Street) showed the temperature at the time of the accident was about 27 degrees, with fine conditions and light winds.

As such, weather conditions were considered unlikely to have contributed to the occurrence.

Maintenance Tasks

The track workers’ task was to undertake maintenance of the level crossing and pedestrian gates at Meadow St. The signal technician and maintainer carried out electrical checks, while the protection officer conducted maintenance on the boom gates and pedestrian gates.

Pedestrian Gates

To facilitate maintenance of the level crossing equipment, certain tasks required the crossing to be operating while the work is being carried out. This work included tasks such as circuit testing and checks of the boom and pedestrian gate operation. In some cases, these tasks required the signal technician or maintainer to work close to or inside the danger zone[4].

One such task was the inspection and, if required, adjustment of the pedestrian gate closing mechanism. The gate control box was located inside the pedestrian escape, with the control arm running from the box to the gate on the track side (Figure 3) - about 3 m from the railway line.

A level crossing test switch[5] was provided at Meadow Street that can facilitate operation of the crossing equipment when trains were not present. Despite the availability of a test switch, it was common practice for maintenance personnel to rely on scheduled train services to facilitate operation of the crossing equipment for testing and maintenance of the pedestrian gates. At interview, signalling personnel reported a reluctance to use the test switch, in light of the view that it would (unnecessarily) close the crossing to road traffic. In addition, there was a slight difference in the operation of the pedestrian gates when initiated by the test switch (when gates would close under spring tension only) compared with normal operation when activated by a rail vehicle (when gates would close under a combination of spring tension and motor control).

Figure 3: General arrangement of south-western pedestrian gate

Figure 3: General arrangement of south-western pedestrian gate

The protection officer and signal maintainer reviewed the operation of the south-western pedestrian gate from the track side of the closed gate (within the danger zone). This examination placed the track workers in a position that was less safe than being within the pedestrian escape area or on the outside of the closed gate. Source: ATSB

Maintenance personnel advised that to assess or adjust the control arm required track workers to stand inside the three-metre danger zone. Some maintainers would carry out the task with the gate open, working in the escape area with the gate acting as a barrier to the track. However, it was evident that some other maintainers carried out the task when the gate was closed, in which case there was no barrier protecting them against inadvertently stepping onto the track.

The ATSB’s investigation found that the process for conducting maintenance on level crossing pedestrian gates varied between personnel. In the subject case, the workers adopted a process whereby the presence of a train was used to operate the level crossing equipment and maintenance and/or adjustment of the gate control arm was undertaken while the gate was in the closed position. This process meant that workers would be positioned within the danger zone, and focused on the maintenance task, at a time when trains were present, and without a barrier between themselves and the track.

Worker safety and worksite protection

The safety of personnel working on and around operating rail services is achieved through a number of complementary measures. These fall into two general areas:

  • Worksite protection

These are the measures put in place to mitigate the risk of injury from railway operational hazards. That is, ensuring separation between track workers and train operations.

  • Worker safety

These are the measures put in place to mitigate the risk of injury from site-specific hazards and task specific hazards.

Worksite protection

To keep track workers separate from rail traffic, rail systems within Australia use various methods of safe working. The higher levels of protection involve exclusion of rail traffic from a worksite and can include the complete closure of the railway (or part thereof). The lower levels of protection permit work to be undertaken between train services and can use other employees to warn track workers of approaching rail vehicles.

Access to maintain suburban railway networks is often more restrictive than for freight networks due to the volume and frequency of rail traffic. Works that require the railway to be closed, even for a short period, are generally only undertaken at night when the frequency of rail vehicles has reduced. Works carried out during the day are usually associated with general maintenance or inspection tasks that do not require closing the railway.

The PTA Network Rules document the requirements for providing worksite protection. It is routine for track workers to use Lookout Protection when working in the danger zone with hand tools only and with the ability to move to a place of safety prior to the arrival of any oncoming rail vehicle. Rule 191 documents the requirements for lookout protection.

The purpose of lookout protection is to task a person or persons to maintain a watch for approaching trains - allowing track workers to be suitably warned to stop work, move to a place of safety and allow the train/s to pass before returning to work. The PTA network rules define a place of safety as either:

  • Where there is at least 3 m clearance between the person and the nearest running line (rail);
  • Properly constructed for use as a refuge;
  • Where a structure or physical barrier has been erected to provide protection; or
  • Behind the safety line on a platform.

Under lookout protection, the lookout’s sole duty must be to maintain a constant watch for trains and no other work[6] may be undertaken. A lookout is only required when track workers are within, or likely to go within, the danger zone. Should the work be outside the danger zone, the lookout may perform other duties, however should track workers resume works within, or likely to go within the danger zone, the lookout must resume the exclusive lookout role.

In this occurrence, the ATSB found that the protection officer had not discussed the worksite protection method with the train controller or the contractors prior to commencing work. It was evident that the role of a lookout had not been allocated, as all three track workers continued to be engaged in maintenance tasks. At the time of the collision, the protection officer was involved with maintenance tasks rather than the assigned role of protection officer.

Worker safety

The PTA had implemented two levels of hazard assessment to ensure worker safety.

  • Job Safety Analysis (JSA) forms

Job Safety Analysis (JSA) forms were used to document and assess the risks inherent to conducting the particular job at hand. The JSA for Maintenance of Automatic Pedestrian Crossing Equipment provided information such as the number of people required to carry out the job, equipment and training required, and a risk matrix containing a selection of high level generic risks that should be considered prior to commencing the job.

In the context of this incident, the JSA identified ‘Being hit by a train’ as a potential hazard, with the associated controls identified as ‘Adherence to safety procedures - assign competent lookout, obtain prior train information (booking on-track)’.

  • Pre-start checklist

Pre-start checklists were used as a record that workers had considered all issues that ensure a task could be undertaken safely. The checklist is a generic form that can be used for any site or task and records information such as date, location, task and names of workers. The checklist records acknowledgment that workers have considered and understand the scope of work and the measures required to undertake the work safely, such as the information contained in the JSA.

The ATSB found that the site team, in this case, had not completed the pre-start checklist prior to commencing work at Meadow Street. While it is likely that the workers were aware of the JSA for pedestrian gate maintenance, there was no record that they had considered the worker safety risk controls contained in it.

Training

To work within the rail corridor[7] on a railway within Australia, operators and infrastructure owners mandate that personnel are trained and deemed competent in a suitable level of safeworking. The level of training and associated competency assessments, depend on the tasks that the person is expected to carry out. Operators and infrastructure owners typically include training as part of their safety management system.

The PTA network rules stated that all persons require an appropriate Track Access Permit, before entering the PTA railway reserve to undertake work at, or closer than 3 metres from the nearest running line or overhead traction power equipment.

The PTA Appendix to the Network Rules detailed the typical accreditation level required for various position types. The appendix considers a WPW15 accreditation level for the positions of safe-working technician, electrical fitter / maintainer, as well as track supervisor and / or flag attendant as a minimum. The document Instructions to Staff Engaged on Maintenance of Signalling Apparatus also stated that a signal technician must be in possession of a PTA accreditation permit to the WPW15 level.

A simplified safe-working accreditation, designated WPW05, was also available for personnel such as managers, engineers, trades, and technical people working within the rail corridor. However, the PTA rules, instructions and training material all specified that any person undertaking work on the track or associated infrastructure must have, as a minimum, an accreditation level of WPW15. A person with WPW15 accreditation must supervise a person who only has a WPW05 accreditation when that person carries out work.

To obtain accreditation for the PTA network, workers must complete specified individual courses pertaining to the accreditation level. A WPW15 accreditation required a worker to complete courses in Working on or around the Railway Track, Safety Instructions for the electrified area and Work Site Protection. The course Awareness for unaccompanied access to worksite provides the majority of the training, which includes a section on how act as a flagman when using Lookout Protection.

In this case, the protection officer had been trained (August 2012) and deemed competent at accreditation level WPW15. The signal maintainer and signal technician both had a WPW05 accreditation at the time of the incident, although the maintainer had completed the necessary training for WPW15 accreditation during the previous week.

It is unclear whether the PTA classifies maintenance on signalling equipment as ‘work on track’ or ‘work on associated infrastructure’. Whilst the work being carried out at Meadow St was predominately undertaken more than 3 m from the track, it is reasonable to consider any work involving signalling equipment is, of its nature, work on associated infrastructure.

Since this incident, the PTA has introduced a new system of safe-working accreditation. This system has removed the WPW05 accreditation level; replacing it with a more rigid tier-based process. The theory-based training will also comprise coaching and on-the-job mentoring, which will form part of the assessment of an employee’s competency. Under the new accreditation system, track workers will gain a greater understanding of track protection implementation and operation. The PTA was also planning to internalise safe-working training for all those who work on track, rather than using an external provider. This will provide the ability to monitor and control the quality of training and assessment provided to all workers including contractors. 

__________

  1. Industry term generally considered everywhere within 3m horizontally from the nearest rail and any distance above or below this 3 m, unless a safe place exists or has been created.
  2. Also known as a flagman switch or manual switch. Used for manually activating the level crossing.
  3. Work is generally defined as any activity within the danger zone other than walking directly from one side of the rail reserve to the other.
  4. Also known as the rail reserve

Purpose of safety investigations & publishing information

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number RO-2015-002
Occurrence date 10/02/2015
Location Guildford
State Western Australia
Report release date 10/03/2016
Report status Final
Investigation level Systemic
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Rail
Rail occurrence category Collision
Occurrence class Accident
Highest injury level Fatal

Train details

Train operator Public Transport Authority of Western Australia
Train number AEA239/AEB339
Type of operation Metropolitan Public Transport
Destination Perth, WA
Train damage Minor

Near collision involving a Cessna 172, VH-EOT and a Jabiru J120, 24-5340, at Latrobe Valley Airport, Victoria, on 6 September 2015

Final report

What happened

On 6 September 2015, the pilot of a Jabiru 120 aircraft, registered 245340 (J5340), conducted a flight from Wangaratta to Latrobe Valley Airport, Victoria. Another Jabiru aircraft (J1) had departed Wangaratta about 2 minutes before J5340, and also travelled to Latrobe Valley. At about 1540 Eastern Standard Time (EST), the pilot of J5340 broadcast on the common traffic advisory frequency (CTAF) when 10 NM to the north of the aerodrome, stating the current position of the aircraft and advising that J5340 was on descent and inbound to Latrobe Valley. The pilot of J1 had broadcast about 2 minutes earlier inbound to the airfield at 10 NM, and reported hearing the broadcast from the pilot of J5340.

Following the broadcast by the pilot of J5340, the pilot of a Cessna 172 aircraft, registered VHEOT (EOT), broadcast on the CTAF, that EOT was 10 NM from the aerodrome and inbound from the west. The pilot of EOT reported that he heard the broadcast from the pilot of J5340, who estimated his arrival time at the circuit at 1544. The pilot of EOT broadcast an estimated arrival time of 1543. The pilot of EOT reported that he then called the pilot of J5340 asking where he was, to which the pilot replied ‘north’. The pilot of EOT did not see a Jabiru aircraft at that time.

The pilot of J5340 reported that he broadcast again, when 5 NM from the airfield, advising his intention to join the circuit on a long downwind for runway 03. Then, when approaching abeam the northern threshold of the runway and on the downwind leg of the circuit, the pilot of J5340 broadcast joining downwind at circuit height for runway 03.

The pilot of J1 reported also having broadcast at 5 NM and when joining downwind, and was on late downwind when J5340 joined the circuit.

The pilot of EOT reported hearing a Jabiru aircraft broadcast joining final for runway 21, and then amending that to turn right to join on downwind for runway 03. However, both Jabiru pilots reported that at no stage did they broadcast or intend to join on final or to use runway 21.

About 15 to 20 seconds after the pilot of J5340 broadcast joining downwind, the pilot of EOT broadcast joining on a midfield crosswind leg for runway 03 (Figure 1). The pilot of J1, then on late downwind, sighted EOT and reportedly called the pilot of EOT, asking whether he had J1 in sight, and received the response ‘yes’. The pilot of J5340 then sighted EOT approaching from his left at the same height, about 300 m away, and reportedly also called asking whether the pilot of EOT had J5340 in sight. He reported that the pilot of EOT again responded ‘yes’, but the pilot of EOT later reported that he had not seen either Jabiru at that time.

The pilot of J5340 assessed that a collision with EOT was imminent, and immediately applied full power, conducted a steep climb and sharp right turn. As he levelled the aircraft off, after climbing about 200-300 ft, EOT passed directly underneath and then turned left onto downwind. The pilot of J5340 then broadcast a call to the pilot of EOT advising that he was above him and to his right and asked whether he had J5340 in sight. The pilot of EOT then sighted the Jabiru (J5340) above him to his right, and responded ‘yes’.

The pilot of EOT asked what the Jabiru (J5430) pilot’s intentions were. The pilot of J5340 responded that he would follow EOT, and extended the downwind leg to ensure adequate separation existed between the two aircraft. J1 had landed by that time, and both EOT and J5340 subsequently landed safely.

Pilot experience and comments

Pilot of VH-EOT

The pilot of EOT had recently passed his private pilot licence exam but had not yet received the associated paperwork. The pilot was conducting a navigation exercise towards the commercial pilot licence and had about 110 hours experience.

The pilot of EOT did not see J5340 until it had passed overhead. He did not see the other Jabiru (J1), or hear any broadcasts from the pilot of J1, at any time either in the air or after landing.

Pilot of Jabiru 24-5340

The pilot of Jabiru 24-5340 held a Recreational Aviation Australia licence and had approximately 700 hours experience as pilot in command.

The pilot of J5340 prefaced each broadcast with ‘Jabiru 53-40’ and the pilot of J1 also prefaced each broadcast with Jabiru and the aircraft registration number. The pilot of J1 reported that he read out each digit of the registration to make a clearer distinction between the two Jabiru aircraft.

Figure 1: Latrobe Valley Airport showing approximate aircraft tracks

Figure 1: Latrobe Valley Airport showing approximate aircraft tracks

Source: Google earth – annotated by the ATSB

ATSB comment

The CTAF at Latrobe Valley was not recorded, and the ATSB was unable to verify any of the reported transmissions. The pilots of both Jabiru aircraft reported hearing each other’s broadcasts as stated. The ATSB obtained radar data, however none of the aircraft operating in the area at the time were visible. The operator of EOT provided recorded flight data of the aircraft track.

Safety message

Pilots operating under the visual flight rules are required to maintain vigilance so as to see and avoid other aircraft. Civil Aviation Advisory Publication (CAAP) 166-2(1), stated:

Lookout is the principal method for implementing see-and-avoid. Effective lookout means seeing what is ‘out there’ and assessing the information that is received before making an appropriate decision.

Broadcasting on the CTAF is known as radio-alerted see-and-avoid, and assists by supporting a pilot’s visual lookout for traffic. An alerted search is more likely to be successful as knowing where to look greatly increases the chances of sighting traffic.

Following a broadcast, it is important for other pilots in the vicinity to ensure they have the aircraft sighted. Issues associated with unalerted see-and-avoid have been detailed in the ATSB research report Limitations of the See-and-Avoid Principle.

As detailed in the booklet A pilot’s guide to staying safe in the vicinity of non-towered aerodromes, ATSB research found that, between 2003 and 2008, there were 709 airspace-related events at, or in the vicinity of non-towered aerodromes. This included 60 serious incidents and six accidents (mid-air and ground collisions). Most of the 60 serious incidents were near mid-air collisions.

The ATSB investigated a mid-air collision at Latrobe Valley Airport on 1 December 2007, AO-2007-065, in which a Cessna 172 collided with an Avid aircraft on final approach to runway 09.

rId24 Picture 6_159x85.jpg

Aviation Short Investigations Bulletin - Issue 45

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2015

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

Occurrence summary

Investigation number AO-2015-104
Occurrence date 06/09/2015
Location Latrobe Valley Airport
State Victoria
Report release date 22/12/2015
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Near collision
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model 172S
Registration VH-EOT
Serial number 172S10317
Sector Piston
Operation type Flying Training
Destination Latrobe Valley, Vic.
Damage Nil

Aircraft details

Manufacturer Jabiru Aircraft Pty Ltd
Model J120-C
Registration 24-5340
Serial number 004
Sector Piston
Operation type Private
Destination Latrobe Valley Vic.
Damage Nil

Landing accident involving a Cessna 180, VH-FDH, at Karumba Airport, Queensland, on 1 September 2015

Final report

What happened 

On 1 September 2015, a Cessna 180C aircraft, registered VH-FDH (FDH), departed Normanton for Karumba Airport, Queensland at about 1435 Eastern Standard Time (EST). The pilot and two passengers were on board for the private flight. The aircraft had a tail wheel landing gear and the landing technique planned to be used was a wheel landing (see Landing techniques below).

At Normanton, the aircraft was refuelled and departed at almost maximum take-off weight. The aircraft climbed to about 1,000 feet for the short distance to Karumba (about 20 NM). On approaching Karumba, the pilot used the aircraft radio to contact another pilot who had just landed at Karumba to ascertain the weather conditions and to determine the most suitable runway for a landing. The pilot of the aircraft that just landed indicated to the pilot that the wind was directly across the runway from the north-west and either runway direction would be suitable for a landing. They decided to land on runway 21 (Figure 1) and joined the circuit on the downwind leg. On downwind, the windsock was observed and confirmed that the wind direction was directly across the runway from the north-west and the pilot estimated the wind speed to be about 10 knots.

Accident site of Cessna 180C, VH-FDH

rid21-picture-4.png

Source: Carpentaria Shire Council

Figure 1: Map of Karumba Airport

rid22-picture-7.png

Source: Google earth, modified by the ATSB

The aircraft was established in a stable final approach and the pilot determined that there was no crosswind correction required. The main wheels touched down firmly on the runway and the aircraft bounced about 3 to 4 feet. The pilot moved the control column forward slightly to stop the tail from touching the runway. The main wheels touched again at about the same time as the pilot noted that the nose started to move to the right (turning into wind). The pilot moved the aircraft controls to straighten the aircraft in line with the runway, but the aircraft did not respond to the correction. The tail continued to move quickly around (ground loop) [1] before the pilot could take any other action. The pilot was pushed up against the cockpit door. A very loud bang was heard as the left main landing gear failed, the left wing folded up and the fuselage tilted onto its side where the aircraft skidded a short distance to a stop. The aircraft stopped, almost pointing back in the opposite direction to the landing, partly on the grass beside the runway (Figure 2). The pilot turned off the engine magnetos, aircraft fuel, and electrical master switch. The two passengers exited the cockpit right door with the help of bystanders and then the pilot exited the same way. The pilot received minor injuries and the two passengers were uninjured. The aircraft was substantially damaged.

Figure 2: Cessna C180 FDH accident site

rid23-picture-6.png

Source: Carpentaria Shire Council

Landing techniques

There are two landing techniques that can be used in tail wheel aircraft. A wheel landing is where the tail of the aircraft is held off the runway and the main wheels touch down first and then the tail wheel. The other landing technique used in a tail wheel aircraft is the three-point landing where the two main wheels and tail wheel touch the runway together.

Pilot training and tail wheel experience

The pilot had about 1,200 total flight hours with about 84 hours in tail wheel aircraft. The majority of landings in those tail wheel aircraft were three-point landings. The pilot commenced training in 2006 for a tail wheel endorsement, initially training in an Avions Mudry CAP 10, where only three-point landings were practiced. The pilot gained further training in an American Champion Super Decathlon, focussing on the wheel landing technique. During an aerobatics and formation endorsement in the Super Decathlon, the pilot revised both wheel and three-point landings. The pilot was also checked-out to fly an Aviat Aircraft Husky and a de Havilland Chipmunk, although reported only having a few hours in each. The pilot conducted a biannual flight review in March 2015 in a Cessna 172 (tricycle landing gear aircraft). The pilot had flown one other Cessna 180 and in that aircraft, had conducted three-point landings.

Of the pilots 84 hours in tail wheel aircraft, 30 were in a Cessna 180, and in the preceding 30 days, about 23 hours were in FDH.

Pilot comment

The flight was part of an air race and prior to the accident they had conducted about 20 hours of flying, departing Jandakot, and landing at Esperance, Forrest, Ayers Rock, Alice Springs, Davenport Downs, Winton, and Normanton. Of those landings, the pilot reported not being happy with any of the landings. The pilot indicated that this was the first landing in the aircraft that was conducted at almost the maximum landing weight and with a significant crosswind. All the other landings were with little to no crosswind component.

The pilot reported that the owner of FDH, who was also a pilot (medical not current), was extremely proficient at conducting wheel landings and wanted the pilot to conduct wheel landings in FDH. The pilot had conducted circuits with the owner about 2.5 weeks prior to the air race and recalled mentioning to the owner that they felt more comfortable conducting three-point landings.

The pilot reported that during the landing, they were very focused on keeping the aircraft straight with the runway and recovering from the bounce. On another landing in FDH where the aircraft had bounced about 3 to 4 feet, the pilot reported resolving the landing without going around.

Safety message

The US Federal Aviation Administration (FAA) discusses in their publication Airplane Flying Handbook Chapter 13 Transition to Tailwheel Airplanes the importance to land with the aircraft in the longitudinal axis exactly parallel to the direction the aircraft is moving along the runway. If the aircraft lands while in a crab or while drifting, it imposes severe side loads on the landing gear and imparts ground looping (swerving) tendencies. The handbook is available from the FAA website.

Aviation Short Investigations Bulletin - Issue 48

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2016

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. A ground loop is an uncontrolled turn during ground operation.

Occurrence summary

Investigation number AO-2015-103
Occurrence date 01/09/2015
Location Karumba Airport
State Queensland
Report release date 27/05/2016
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Loss of control
Occurrence class Accident
Highest injury level None

Aircraft details

Manufacturer Cessna Aircraft Company
Model 180C
Registration VH-FDH
Serial number 50680
Sector Piston
Operation type Private
Departure point Normanton, Qld
Destination Karumba, Qld
Damage Substantial

Near collision involving a Schweizer 269, VH-JXO and a military Lockheed AP-3C, at Edinburgh Airport, South Australia, on 31 August 2015

Final report

What happened

On 31 August 2015, the pilot, and sole occupant, of a Schweizer 269C helicopter, registered VHJXO (JXO), was conducting aerial spraying in the Edinburgh area, South Australia, and operating under the visual flight rules (VFR). The helicopter departed from Calvin Grove aeroplane landing area (ALA) at about midday Central Standard Time (CST), and the pilot obtained a clearance from Edinburgh Airport air traffic control (ATC) to track to Virginia (Figure 1). The pilot conducted spraying operations in that area, and then requested and obtained a clearance to track to an area south of Gawler. The operations included regular take-offs and landings to refuel and reload with chemical. The pilot continued spraying operations about 3.5 NM southeast of Gawler aeroplane landing area (ALA), which was outside the Edinburgh control zone, below the 1,500 ft lower limit of restricted airspace, and therefore in Class G airspace.

Figure 1: Locations relevant to VH-JXO

Figure 1: Locations relevant to VH-JXO

Source: Google earth – annotated by the ATSB

At about 1503 CST, a Military Lockheed AP-3C aircraft (Orion) was about 15 NM northeast of Edinburgh, at 6,500 ft, tracking for the runway 18 instrument landing system (ILS) –Y approach to Edinburgh Airport. The Orion, with 5 crewmembers and 14 passengers on board, had departed about 10 hours earlier on an international flight bound for Edinburgh, and was operating under the instrument flight rules (IFR).[1] The weather conditions at Edinburgh at the time, included no cloud below 5,000 ft and visibility greater than 10 km.

At about 1504, the pilot of JXO called Edinburgh Tower air traffic control, and requested a clearance to track to ‘Clare’ (Clare Valley), South Australia. In order to track direct to Clare Valley, which was about 45 NM to the north-northwest, the pilot needed a clearance through a corner of the Edinburgh control zone (Figure 2).

Figure 2: Operating area of JXO, Edinburgh Control Zone and relative tracks

Figure 2: Operating area of JXO, Edinburgh Control Zone and relative tracks

Source: Airservices Australia – annotated by the ATSB

The tower (TWR) controller 1, mistook the pilot’s request to ‘Clare’ for ‘Calvin Grove’, and cleared the pilot of JXO to track direct to Edinburgh Tower, not above 1,000 ft in order to be able to visually separate the helicopter with the arriving Orion and another aircraft conducting circuit operations at the airfield. The pilot complied with the instruction, even though this was not the direction requested, nor the clearance expected. However, being new to the area and concerned about the direction of the clearance, the pilot attempted, unsuccessfully, to contact their company via UHF radio to ask for advice.

At about 1506, the TWR controller 1 completed their shift and conducted a handover to tower (TWR) controller 2. The TWR controller 1 advised TWR controller 2 of JXO, tracking to the tower then for Calvin Grove, and stating that they planned to track JXO ‘over the top’ (of the airfield) to separate with the Orion and could hold JXO if necessary, depending on the requirements of the aircraft conducting circuits. About 2 minutes later, the crew of the Orion reported established on the ILS.

At about 1509, when about 5 NM from the tower, the pilot of JXO reported the helicopter’s position to the tower controller, hoping to prompt the controller for a clearance towards Clare Valley, but the TWR controller 2 directed the pilot to continue tracking direct to the control tower. The pilot then again attempted to contact their company via UHF radio to seek guidance on Edinburgh operations.

About 1 minute later, the TWR controller 2 advised the aircraft conducting circuit operations at Edinburgh of both the Orion, then at 12 miles on the ILS, and JXO, as traffic, stating that JXO was for Calvin Grove. During that transmission, the pilot of JXO was trying to communicate on UHF radio and did not assimilate the information about the Orion. Soon after that transmission, the flight crew of the Orion, which was then at 9 NM, advised they were on the ILS-Y passing 3,200 ft[2] on descent.

The circuit aircraft then turned onto base leg for runway 18, was cleared for a touch-and-go, and advised they had the (Orion) aircraft in sight.

At about 1512, the Orion was passing 2,400 ft, on a 6.5 NM final and travelling at 170 kt. JXO was at 600 ft and travelling at 60 kt (Figure 3). Based on the expected tracking of the three aircraft, the TWR controller 2 assessed that JXO would safely cross the runway centreline in front of the Orion, and behind the aircraft conducting circuits (then on a short final). Consequently, the TWR controller 2 cleared JXO to track to Calvin Grove. The pilot heard the call and responded, but the radio was still selected to transmit on UHF not VHF, so the controller did not receive a response. The pilot was flustered and expecting an onwards clearance to Clare Valley, consequently had turned right to track northwards to Clare Valley.

Figure 3: Aircraft positions when JXO was cleared to Calvin Grove (time 1512)

Figure 3: Aircraft positions when JXO was cleared to Calvin Grove (time 1512)

Source: Department of Defence – annotated by the ATSB

Having not received a response, the TWR controller 2 repeated the call to JXO, and again did not receive a response. The TWR controller 2 then made two more attempts to communicate with the pilot of JXO, including requesting a ‘radio check’, without receiving a response. The pilot of JXO could hear the calls and eventually realised they had the incorrect radio selected to transmit.

Separation Standards

According to the Manual of Air Traffic Services (MATS), separation is the concept of ensuring aircraft maintain a prescribed minimum from another aircraft (or object), while meeting the associated conditions, and requirements of the standard. A separation standard is a prescribed means to ensure separation between aircraft using longitudinal, lateral, vertical and visual standards.

Use of the Situation Data Display

Edinburgh Tower controllers did not hold approach endorsements and therefore were not able to use the radar situation data display (SDD) to vector aircraft to achieve separation. The controllers were required to achieve separation through the issue of tracking instructions, level assignment or through visual observation. The radar SDD could be used to monitor separation and achieve situational awareness.

While attempting to establish communications with JXO, the TWR controller 2 monitored JXO’s tracking using binoculars. About the time of the radio check, JXO appeared to turn right, then fluctuate between north-westerly and westerly headings. Due to the small size of JXO and its distance from the tower, its exact tracking was difficult to determine visually. Furthermore, the tower radar situation data display (SDD) did not provide a true representation of the helicopter’s tracking, due to its slow speed. The SDD did indicate that JXO had tracked further north than cleared, which increased the closure rate between the helicopter and the Orion.

At about 1513, the pilot of the Orion reported at the outer marker on the ILS (4.2 NM from the runway threshold), and the TWR controller 2 cleared the Orion to land (Figure 4). JXO was then tracking north-northwest, about 3 NM from the Orion, and converging. The TWR controller 2 was then apprehensive about JXO’s tracking. Although the crew of the Orion had heard the controller’s attempts to contact JXO, as the controller had not provided them with directed traffic information, they were unaware of JXO’s position, and assumed it was not a consideration for their tracking.

Figure 4: Orion at the outer marker (time 1513)

Figure 4: Orion at the outer marker (time 1513)

Source: Department of Defence – annotated by the ATSB

The TWR controller 2 then conducted another radio check with the pilot of JXO in an attempt to re-establish communications. The Orion and JXO were about 1.5 NM apart, and their flight paths were merging. On the radar SDD, JXO was indicating about 700 ft and the Orion was passing 1,100 ft on descent. The TWR controller 2 then conducted another radio check using an alternative handset, to ascertain whether the communications issue may be due to ATC equipment.

The pilot of JXO responded, apologised, advised they had the radio selected to an incorrect frequency, and that they had requested a clearance to track to Clare Valley, not Calvin Grove. During that transmission, the distance between JXO and the Orion reduced to about 1 NM laterally, and 200 ft vertically.

Immediately following the pilot of JXO’s response, the TWR controller 2 asked whether the pilot had the ‘P3’ (Orion) in sight, advising that it was then in the pilot’s 1 o’clock[3] position at about 2 miles. The pilot queried the aircraft type, and the TWR controller 2 advised that the ‘P3 Orion’ was now at about 1 mile in the pilot’s 2 o’clock position. The pilot was initially unable to sight the Orion, as it was below, to the right, and behind the helicopter, and therefore not in the pilot’s 1 or 2 o’clock position (Figure 5). The pilot then saw the Orion’s shadow on the ground and sighted the Orion. The pilot of JXO responded having the aircraft in sight, and the TWR controller 2 directed the pilot to pass behind that aircraft.

Figure 5: Relative positions when ATC advised JXO of the Orion (time 1514)

Figure 5: Relative positions when ATC advised JXO of the Orion (time 1514)

Source: Department of Defence – annotated by the ATSB

By the time the controller completed that transmission, JXO had passed overhead the Orion. On sighting the Orion, the pilot of JXO had immediately initiated a climb to avoid a collision, and estimated the Orion passed about 100 ft below. On hearing the controller pass the Orion as traffic to the pilot of JXO, the Orion crew immediately became concerned about the helicopter’s proximity, and looked for it. The co-pilot (non-flying pilot) of the Orion sighted JXO, assessed there was a risk of collision, and called ‘go low, go low, go low’. The captain (flying pilot), also sighted JXO, and increased the rate of descent to pass beneath the helicopter. The Orion crew estimated that JXO passed about 50 ft directly above the Orion, and were concerned it may collide with the Orion’s vertical tail fin. On the radar SDD, at 1514:25, both aircraft appear in the same position at 600 ft (Figure 6).

Figure 6: Aircraft collocated on radar SDD

Figure 6: Aircraft collocated on radar SDD

Source: Department of Defence – annotated by the ATSB

The Orion landed without further incident on runway 18. The pilot of JXO was subsequently cleared to depart the Edinburgh control zone tracking to Clare Valley.

Pilot comments

The pilot of JXO provided the following comments:

  • The pilot could have tracked around the restricted airspace towards Clare Valley, by going via Roseworthy. The pilot was new to the area, unsure of the local landmarks, and therefore requested a clearance to track direct.
  • The pilot was nervous about operating in military controlled airspace and therefore did not question the clearance to track towards the Tower, even though it was not where they wanted to go. The pilot reported feeling ‘a bit rattled’.
  • The pilot had selected Clare Valley on the GPS, and was unsure exactly where Calvin Grove was from their current position. If JXO had tracked to Calvin Grove, it would have remained clear of the aircraft approaching runway 18.

Department of Defence investigation

The Department of Defence conducted an investigation and made a number of findings. Some of those findings are detailed here.

Initial airways clearance issued to JXO

The TWR controller 1 interpreted JXO’s destination as Calvin Grove. Two hours prior to the incident, the TWR controller 1 had processed JXO from Calvin Grove, thereby associating JXO with Calvin Grove. Additionally, JXO could have tracked from their location near Gawler to Clare, with only a small deviation east of Roseworthy to remain clear of the restricted airspace (see Figure 1). Therefore, the controller would not have expected a request of an airways clearance to Clare from JXO.

Communications issue

The TWR controller 2 made six attempts to re-establish two-way communications with the pilot of JXO over a period of 92 seconds. The loss of two-way communications was due to the pilot transmitting on an alternative frequency.

The loss of two-way communications with JXO meant that the TWR controller 2 was unable to pass instructions to the pilot to sight, and maintain separation with, the Orion. The attempts of the pilot of JXO to communicate with their company on UHF radio also diminished the pilot’s ability to maintain situational awareness of other traffic within the control zone from the radio calls of the circuit aircraft, the Orion crew, and the controller.

The combination of communication difficulties and clearance towards an incorrect destination, led to the pilot of JXO becoming flustered. The pilot therefore turned towards Clare instead of the cleared destination of Calvin Grove. Shortly before returning to Tower frequency, the pilot realised the last clearance issued was to Calvin Grove, and turned onto a westerly heading, thereby converging with the Orion.

Visual separation

Visual separation (MATS)Separation may be reduced in the vicinity of aerodromes when adequate separation can be provided using visual observation and each aircraft is continuously visible to the aerodrome controller.

Visual separation (MATS)
Separation may be reduced in the vicinity of aerodromes when adequate separation can be provided using visual observation and each aircraft is continuously visible to the aerodrome controller.

The TWR controller 2 assessed that sufficient time and distance existed for JXO (tracking for Calvin Grove) to cross final ahead of the Orion while maintaining the visual separation standard. However, the disparate sizes and speeds of the Orion and JXO, combined with their relative positions and distance from the control tower, made it difficult to maintain separation by visual observation.

After the Orion crew reported at the outer marker, it became apparent to the controller that visual separation would be lost. However, due to the proximity and relative tracks of the helicopter and the Orion, it was then impossible to introduce an alternative separation standard such as vertical displacement[4] or assigning separation responsibility to the pilot.

Compromised separation recovery

In accordance with the Manual of Air Traffic Services (MATS), the Orion had a higher priority because it was operating under IFR flight rules. This influenced the TWR controller 2’s decision to allow the Orion to continue the ILS-Y approach, while attempting to communicate with JXO. However, MATS also required controllers not to compromise safety in order to meet the priorities.

The TWR controller 2 did not pass traffic information on JXO to the crew of the Orion, as the controller did not intend to assign responsibility for separation to them. The controller intended for the pilot of JXO to sight the Orion and accept responsibility for separation. Passing traffic information to the smaller aircraft on the larger aircraft conformed to the compromised separation recovery techniques taught to the controller.

The combination of incorrect application of visual separation, ATC priorities, and the decision not to amend the Orion’s tracking, led to a loss of separation between the Orion and JXO, including a loss of wake turbulence separation.

The TWR controller 2 assessed that instructing the Orion to go around from the approach would not solve the confliction, as the aircraft may not achieve sufficient climb performance to overfly JXO. The controller also assessed that the Orion crew may not safely have been able to conduct a hard right turn as the aircraft was in the landing configuration and at a critical stage of flight. The Orion flight crew later advised that a right turn manoeuvre to avoid the confliction would have been within the capabilities of the aircraft.

The TWR controller 2 did not issue a safety alert. The controller reported that they were about to issue a safety alert to the Orion crew, when the pilot of JXO returned to the Tower frequency, and made a transmission that lasted 10 seconds. At that time, the aircraft were 1.2 NM apart laterally, and 400 ft vertically. A safety alert issued at that time may have allowed the Orion crew to increase the vertical separation between the aircraft. If the controller had issued a safety alert earlier, it would have increased both lateral and vertical distances between them.

The clock positions provided to the pilot of JXO were incorrect and delayed the pilot’s ability to sight the Orion. The preferred compromised separation recovery technique is to provide a bearing and distance of the other aircraft to the pilot, which was available from the radar SDD.

Traffic collision avoidance system

The Orion is fitted with a traffic collision avoidance system (TCAS). In accordance with standard operating procedures, the crew of the Orion had selected low sensitivity mode on the TCAS when established on the ILS, and prior to contacting Edinburgh Tower. This mode provides no audible alert to the aircrew of potentially conflicting traffic. The captain and the co-pilot both observed the circuit aircraft on the TCAS display indicating that the system was functioning normally, but JXO did not appear. While JXO had a functioning transponder, the reason that it was not being displayed on the Orion’s TCAS could not be determined.

Safety action

Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.

Department of Defence

As a result of this occurrence, the Department of Defence advised the ATSB that they are taking a number of safety actions. These include the following:

Compromised separation recovery training

The Department of Defence has released a Standing Instruction that mandates annual compromised separation recovery training for all air traffic controllers.

Controller briefing

All controllers will be briefed on the events and findings of the incident as an element of compromised separation recovery training.

Tower simulation capability

Tower simulation capability is being introduced to enhance compromised separation recovery training.

Additionally, simulation will be used to:

  • compensate for low traffic levels and to facilitate controller attainment and retention of skills associated with processing complex traffic scenarios
  • compensate for low traffic levels and to facilitate controller attainment and retention of skills associated with application of ATC priorities
  • assess controller proficiency when live traffic levels are below that required to judge controllers’ abilities to process complex traffic scenarios
  • provide controllers with regular exposure to compromised separation recovery scenarios, to improve decision making and ensure the associated actions become instinctive.
Airspace procedure briefings

The Edinburgh controllers will provide airspace procedure briefings to pilots who conduct airwork within and around Edinburgh airspace. The Airservices Australia Aeronautical Information Publication (AIP) En Route Supplement Australia (ERSA) entry for Edinburgh will be amended to include a section detailing the requirements for pilots of civil aircraft intending to conduct airwork within, or near, the Edinburgh control zone, to have airspace briefing.

Safety message

This incident highlights the importance of communication, and demonstrates the potential consequences of a loss of communication. Whether pilots are communicating with each other, or with air traffic control, it is essential to understand what is being said and how that potentially affects them. In particular, if an instruction from air traffic control is not as expected, pilots should request clarification.

For controllers, having tactical separation assurance in place reduces the likelihood of a loss of separation, particularly in the event of communications failure.

Compromised separation recovery is a critical skill for air traffic controllers, which needs to be practiced often and in sufficiently complex scenarios to be applicable and implemented when necessary.

The Australian Transport Safety Bureau (ATSB) research report AR-2012-034 titled Loss of separation between aircraft in Australian airspace January 2008 to June 2012 found that aircraft separation is a complex operation with many levels of defences to avoid errors and safely manage the results of errors made by air traffic controllers and pilots.

Aviation Short Investigations Bulletin - Issue 45

Purpose of safety investigations

The objective of a safety investigation is to enhance transport safety. This is done through:

  • identifying safety issues and facilitating safety action to address those issues
  • providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.

It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.

Terminology

An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.

Publishing information 

Released in accordance with section 25 of the Transport Safety Investigation Act 2003

Published by: Australian Transport Safety Bureau

© Commonwealth of Australia 2015

image_5.png

Ownership of intellectual property rights in this publication

Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.

Creative Commons licence

With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.

Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.

The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau

Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.

__________

  1. In accordance with the Manual of Air Traffic Services (MATS) para. 2.4.2.2, air traffic control is responsible for providing separation between IFR and VFR aircraft.
  2. All altitudes in the report are in feet above mean sea level (AMSL). Edinburgh Airport elevation is 67 ft AMSL. The radar display shows altitude to the nearest 100 ft.
  3. The clock code is used to denote the direction of an aircraft or surface feature relative to the current heading of the observer’s aircraft, expressed in terms of position on an analogue clock face. Twelve o’clock is ahead while an aircraft observed abeam to the left would be said to be at 9 o’clock.
  4. The minimum vertical separation required at that time, would have been 1,000 ft.

 

Occurrence summary

Investigation number AO-2015-101
Occurrence date 31/08/2015
Location at Edinburgh Airport
State South Australia
Report release date 22/12/2015
Report status Final
Investigation level Short
Investigation type Occurrence Investigation
Investigation status Completed
Mode of transport Aviation
Aviation occurrence category Near collision
Occurrence class Serious Incident
Highest injury level None

Aircraft details

Manufacturer Lockheed Aircraft Corp
Model AP-3C Orion
Aircraft operator Royal Australian Airforce
Sector Turboprop
Operation type Military
Destination Edinburgh, SA
Damage Nil

Aircraft details

Model Schweizer Aircraft Corp
Registration VH-JXO
Serial number 0352
Sector Piston
Operation type Aerial Work
Departure point Gawler, SA
Destination Clare Valley, SA
Damage Nil