The pilot reported that as he was preparing engine settings for descent, he noticed a very large bird ahead of the aircraft. Insufficient time remained to initiate avoidance, and the bird struck the left-wing leading edge. The flight continued without further incident and the aircraft made an uneventful landing at the planned destination. Post flight examination found the wing leading edge was deformed outboard of the left engine and a wing rib was damaged.
The take-off was being conducted in a northerly direction along a curving sea channel when the float-equipped aircraft struck a sandbar in the channel. It nosed-over and came to rest inverted. All five occupants received minor injuries: three sustained head and neck injuries.
From the information provided by the pilot and passengers it was determined that the aircraft was correctly loaded, and the centre of gravity was within limits.
The pilot reported that there was a light crosswind and the tide was low which created a narrower than usual channel for the take-off.However, he was familiar with the prevailing conditions having operated the aircraft along the same channel, in the same direction, with similar loadings, on several previous occasions. The planned take-off path followed the channel to the north west before changing to a north easterly direction. This meant that the first part of the take-off would have a quartering tailwind which would change to a quartering headwind after the aircraft rounded the first bend. From experience the pilot expected the aircraft to become airborne soon after rounding the bend.
The pilot reported that once the aircraft was on the step it continued to accelerate normally, and all power indications and flight controls were normal during the take-off. As the aircraft approached the first bend in the channel the pilot decided to abandon the take-off because the sandbar appeared to be larger and the bend tighter than usual. After closing the throttle, the pilot held back pressure on the control column, but was unable maintain enough rudder directional control to prevent the aircraft from floating onto the sandbar. The aircraft skidded along the sandbar until the floats entered a depression, causing the aircraft to nose over. The pilot assisted the passengers to vacate the aircraft through the left cockpit door.
Passengers reported that the pilot had given a pre-take-off safety briefing. A passenger who had occupied the rear cabin seat said that he had not fastened his seat belt because he could not find the end of the belt. He said that he did not inform the pilot about the seat belt because he had previously taken a similar flight which was uneventful, and he was confident that nothing would happen on this occasion.
Significant factors
The pilot misjudged the distance available to the sandbar during the take-off run.
The decision to reject the take-off was taken too late to avoid impact with the sandbar.
The aircraft departed from Parafield with three persons on board. The pilot estimated the aircraft weight was within tolerance, being just below the allowable maximum all up weight for the aircraft type.
The destination airstrip had a steep uphill gradient in the landing direction to the north. A 20 kt to 30 kt northerly wind was blowing at the time. The pilot assessed the situation, but because the wind was not generating a great deal of turbulence, he believed it to be lighter, but he still decided to make a shallow approach at a slightly faster speed. On final approach, as the aircraft descended through about 500 ft above ground level (AGL), the pilot believed it experienced windshear, with the airspeed decreasing from 70 kt to 60 kt, and an increase in the rate of descent.
On short final the pilot reduced power, then flared for the landing but too high. He felt the aircraft sink but did not increase power to arrest the descent, with the result the aircraft struck the ground heavily on its main wheels, bounced, then turned to the left impacting the ground again with the left main wheel, left wingtip, nose wheel, and propeller. The nose gear separated, and the left main gear fractured.
A witness on the ground reported that a stronger wind gust occurred just as the aircraft was on short final and commencing to flare at about 20 ft AGL. It then sank rapidly to the ground.
The pilot probably misjudged the flare height due to the steep incline of the airstrip, allowed the airspeed to decay, then failed to apply power to prevent the subsequent high sink rate. The heavy aircraft weight, and the wind roll over effect in the lee of the hill, would have contributed to the rapid rate of descent.
The pilot of VH-RQF reported "ready" for runway 03L and was instructed by the air traffic controller to line up. The pilot of VH-KGP, conducting crosswind landing practice on runway 08L, received a clearance for a touch-and-go landing.
The air traffic controller observed VH-KGP complete the landing and commence to take-off. He then noticed that VH-RQF was also taking off and attempted to instruct the pilot to stop but used the call sign of another aircraft operating in the circuit area, with the result that the instruction was ignored.
As both aircraft became airborne the air traffic controller gave a warning to the pilot of VH-KGP, who then saw VH-RQF and dived to pass beneath it. Both aircraft had climbed to about 100 ft above ground level and passed at the intersection of the two runways.
The pilot of VH-RQF stated that he had been involved in discussing the take-off technique with the student pilot, and thought he heard his take off clearance being given. When airborne he saw VH-KGP, and noticed that it had commenced to descend, so he climbed his aircraft as steep as possible to increase separation.
The aircraft was the third in a stream of five company aircraft departing the Tangalooma Resort airstrip at two-minute intervals on a clear moonlit evening.Following a routine departure at 2105 EST, the aircraft was climbed to 3,000 ft for the flight back to Coolangatta.Early in the cruise phase of the flight, the pilot found that the fourth aircraft was catching up to his and he elected to descend to 2,000 ft to ensure continued separation.
At 2127 EST, the pilot reported to Coolangatta Approach Control that the aircraft had severe problems, but did not inform the controller of the nature of his emergency. However, the controller activated the airport emergency procedures when he observed on his radar display that the aircraft was losing altitude. The pilot had his second VHF radio transceiver tuned to his company frequency and was answering transmissions received from other company pilots on this frequency while transmitting on the Coolangatta Approach frequency.
The pilot later said that after the aircraft passed the seaway at Southport, the right engine surged, which resulted in the aircraft yawing. After he switch the electric fuel pump to "on", the symptoms disappeared. About a minute later he switched the pump off, then on again.He said that when the engine began surging again, he shut the engine down, feathering the propeller. Left engine power was increased, and the aircraft maintained 1,500 ft in level flight. He switched the left engine's fuel supply to the right main tank, believing that this action would ensure supply from both main fuel tanks.
The pilot said that after the aircraft passed Burleigh Heads, many things appeared to go wrong at once. The left engine began to splutter and did not respond to the throttle. He recalled attempting to restart the right engine. This proved to be unsuccessful.As the descent continued, he planned to land on a beach.
The pilot selected a stretch of beach for a forced landing. During late final approach, aided by bright moonlight, he noticed that any overrun would take the aircraft into a crowded car park. He changed his aim point to the stretch of beach south of the Currumbin Lifesavers Clubhouse. Following the flare for landing, the right wing struck a low rocky outcrop, and the aircraft crashed into the surf.The entire wing assembly separated from the fuselage, which came to rest on its left side. Some of the nine passengers, and the pilot, escaped from the semi-submerged fuselage while bystanders rescued others.
Personnel information
The pilot was 45 years of age and had commenced flying training in October 1990. He was issued with a commercial pilot licence on 30 June 1993. He continued his training and, on 3 June 1994, gained a grade 3 instructor rating valid for single-engine aircraft. He was appropriately endorsed to fly the Britten-Norman Islander BN-2 series of aircraft. The pilot held a current command instrument rating valid for multi-engine aircraft. He satisfied the recency requirements for single-pilot flight under instrument flight rules, as contained in Civil Aviation Order 40.2.1. The pilot had a total flying experience of 881 hours, of which 606 were as pilot in command. He had recorded about 373 hours in multi-engine aircraft, of which 177 were on the Britten-Norman Islander aircraft. In the previous 30 days he had flown a total of 38 hours, all on the aircraft type.
The pilot had been employed by the company on a part-time basis until February 1996, when he became a full-time pilot. During his employment as a part-time pilot, he had worked in the maintenance hangar as a general hand assisting the licensed aircraft maintenance engineers who serviced the company's aircraft.
Medical information
The pilot's class 1 medical certificate was without restriction and was current until 7 May 1996. The pilot reported that he was not suffering from any illness and that he was fit to undertake the flight.
Aircraft information
The aircraft, a model BN-2A-21, Serial No. 415, was manufactured by Britten-Norman Limited in England in
1974.It was a high-wing, twin-engine, propeller-driven aircraft with a maximum allowable take-off weight of 2,994 kg. The aircraft was imported from Singapore in 1995 and placed on the Australian Aircraft Register on 25 October 1995 when Airworthiness Certificate AFD/10663 was issued. Maintenance Release Certificate No.
PA/51001, issued on 11 January 1996, was valid until 11 January 1997, or 6,020.8 hours total time in service (TTIS). The aircraft TTIS was 6,013.4 hours at the time of the accident.There were no identified outstanding maintenance requirements. The aircraft was fitted with forward facing seats and certified to carry 11 persons.
The aircraft was powered by two Avco Lycoming IO-540-K1B5 engines driving Hartzell fully feathering propellers. These components were within their mandatory service lives. The design of the propellers provides a feathering spring and dome air pressure to drive the blades into the feather position when the control is selected to feather. The blades may also go to feather when oil pressure has been lost if the blade pitch is on the coarse pitch side of the propeller stops. The propeller stops prevent the propeller from moving to feather during engine shutdown in normal operations.
The pilot flew the aircraft on the outbound flight earlier in the day. He did not report any defects.
Fuel system
The aircraft fuel system included four individual wing tanks: two integral main tanks located outboard of each engine, and two auxiliary tanks at the wingtips. The two main tanks have a total capacity of 518 L, and the two auxiliary tanks 223 L. Two main fuel tank selector valves provide for selection of OFF, PORT, and STARBOARD. When the selector is positioned to the opposite wing named on the selector, the engine uses fuel from that main tank only, in crossfeed.Two auxiliary fuel switches provide for selection of MAIN or TIP, which can also be crossfed in the same way by selecting the wing named on the selector and operating on TIP.
Before departure from Coolangatta in the morning, the aircraft was refuelled to 240 L in the main tanks and 100 L in the auxiliary tanks. The flight to Tangalooma and return required approximately 120 L.
Engine handling during cruise
The operator of the aircraft required pilots to set the engine fuel mixture after the aircraft had levelled out in cruise. The normal technique was to lean the engine fuel mixture to peak exhaust gas temperature and then enrich the mixture to lower the exhaust gas temperature by 50 degrees (two divisions on the exhaust gas temperature gauge).
Weight and balance
The aircraft weight at the time of the accident was calculated at 2,749 kg, 245 kg below the maximum allowable take-off weight. The centre of gravity was within allowable limits.
Propeller controls
The manufacturer restricted the propeller controls for normal operations by offsetting the rear segment of the slots to prevent inadvertent feathering which would otherwise be possible when selecting coarse propeller pitch. To select feather, the pilot has to move the lever sideways slightly to bypass the 2-mm notched stop or detent.
Meteorological information
The Bureau of Meteorology prepared an analysis of wind conditions in the Coolangatta area. The low-level wind was a light northerly, less than 5 kts at the surface and increasing to about 10 kts at 2,000 ft. The Coolangatta Automatic Terminal Service reported a light north-westerly wind at 4 kts, a temperature of 21 degrees C, and a QNH of 1,018 hPa.
Witnesses reported that the night was clear, with a near-full moon about 20 degrees above the eastern horizon. Visibility was in excess of 10 km. The tide was about 1 hour short of high tide, which led to high cresting waves washing over the wreckage.
There was no evidence that weather conditions contributed to the accident.
Aids to navigation
The aircraft was equipped with very high frequency omni-directional radio range (VOR), automatic direction finding (ADF) and distance measuring equipment (DME) navigation aids. The flight was planned to operate under instrument flight rules; however, the weather was such that visual navigation was possible. The pilot did not report any navigation aid defects or difficulties.
Communications
The aircraft was fitted with two very high frequency (VHF) radio transceivers appropriate to the flight. Both radios were in use, monitoring air traffic control (ATC) and the company frequency at the same time. However, only one transmitter at a time could be used. The pilot had communicated without difficulty with Brisbane Flight Service, Brisbane Approach, and Coolangatta Approach before reporting problems.
The sound of an engine operating at high revolutions per minute was audible in the background of 17 subsequent transmissions. Engine noise was not apparent in the last transmission at 2137:37 but an aural warning tone could be heard. A stall-warning horn was the only aural warning device fitted to the aircraft.
Communications recorded on the ATC automatic voice recorder (AVR) tapes
All communications between the aircraft and air traffic services were recorded on automatic voice recorders in Brisbane and Coolangatta. The first indication of any significant problem was when the pilot transmitted at 2127:34 that he was experiencing severe problems with the aircraft. However, the pilot did not elaborate on the problems. A series of unnecessary transmissions were made by the pilot throughout the emergency sequence, some in answer to unrecorded questions received on his second radio which was monitoring the company frequency.
At 2131:05 the pilot reported that he seemed to have the aircraft under control again. At 2132:01 he transmitted "I'm having problems maintaining height with whatever this configuration is" and 50 seconds later, "OK guys, I'm just going to try a restart". This was the first indication to the Coolangatta approach controller that the aircraft was operating on one engine. The aircraft was then at approximately 600 ft. At 2133:05 another company pilot asked whether he had lost one (engine) or both. The pilot's answer indicated that the aircraft was operating on one engine which was not delivering the power he expected. The last transmission made by the pilot was at 2137:37 in which he said that he was going to land the aircraft on the beach.
Safety equipment
An emergency locater transmitter was not installed in the aircraft.
The restraint harnesses appeared to have effectively restrained all passengers and the pilot. The serious injuries received by both front-seat occupants were probably due to the cockpit structure collapsing, thereby reducing the occupiable space.
The Civil Aviation Orders required that the aircraft, which was authorised to carry more than nine passengers, be equipped with life jackets for each occupant where the take-off or approach paths extended over water. The aircraft was not equipped with life jackets on this flight.
Wreckage and impact information
The right wingtip separated when it struck a low rocky outcrop. The aircraft yawed right and landed in waist-deep water in the surf some 10-15 m further on. The force of impact of the fixed main gear with the sand and water caused the wing assembly to separate from the fuselage. The fuselage came to rest on its left side. Both engine/propeller combinations remained attached to the wings. Both propellers were bent. The wing flaps were fully retracted. Wave action exacerbated the impact damage and filled the structure with sand.
Aircraft maintenance documentation
The aircraft logbooks and maintenance work sheets were examined. In the period from November 1995 to late February 1996, the records showed that there were six reports of low engine power, mostly involving the right engine. The last report of low engine power was on 24 February 1996, when no fault was found. The aircraft had operated since then without any apparent engine defects requiring rectification. The recording of defects by maintenance personnel was incomplete due to omissions. Pilots had not recorded defects in the aircraft's maintenance release but had annotated a whiteboard in the chief pilot's office which was periodically checked by the chief licensed aircraft maintenance engineer. Defects which required urgent attention were also directly referred (verbally) to the engineer.
Aircraft systems examination
Approximately 100 L of fuel were recovered from the right main and left auxiliary (tip) tanks. The fuel, apart from salt water in the tip tank, was clean avgas. The main fuel-feed and vent lines were inspected and found to be free of any blockages. The left main tank was ruptured. The right auxiliary tank had separated, and the cap was off. Neither tank contained fuel. The fuel manifold of both the right and left engines contained fuel. The left fuel gascolator was found to be full of clean fuel.The right gascolator was loose, having sustained impact damage. It contained salt water and sand.The inlet filters in both left and right fuel control units were clean.
Due to the separation of the overhead panel from the fuselage, an examination of the main fuel selectors could not determine the settings. The two auxiliary fuel switches were set to MAIN. This selection was confirmed by the position of the electromechanically activated fuel valve in each wing.
The engines and propellers were dismantled and examined. The investigation gave considerable attention to the fuel injectors due to previously reported problems evident from the aircraft's maintenance history.No evidence of contamination or blockage was found with the injectors, other than some minor salt and sand deposits in two injectors from the left engine, consistent with immersion in the surf.
The condition of each engine was consistent with a low power setting at impact.Both propellers were bent, and each was found to be within its normal pitch range. The fuel control units from each engine were functionally bench tested and later dismantled. No fault was found with either unit. Both magnetos from each engine were examined and found to be functional, apart from saltwater damage.
The airframe, avionics and instrumentation were examined, but no pre-existing defects were found. Both left engine magneto switches were on but only the left magneto switch of the right engine was on. This is consistent with an incompleted air start attempt as the manufacturer recommends the use of only the left magneto during start. No other useful information was obtained from the engine controls located in the centre console due to the break-up of the wreckage.
Tests and research - aircraft performance
Test flights were arranged to determine certain aircraft performance parameters not available from the manufacturer's data. The pilot conducting the tests was a qualified experimental test pilot. The aircraft used was a Britten-Norman BN-2A-20 with similar performance to that of the accident aircraft and was ballasted to replicate its weight. The temperature was 19 degrees, within 2 degrees of the temperature at the time of the accident. The Owners Handbook specifies 65 kts as the best single-engine rate of climb speed (blue line on the airspeed indicator). The manufacturer indicated that this speed represents the speed at maximum allowable weight at which the margin of engine power in excess of that required for flight is greatest. The manufacturer indicated that the aircraft should be flown at this speed following an engine failure during the critical initial climb after take-off.
The following parameters were noted:
At 65 kts, to maintain level flight at 2,000 ft, flaps up and right propeller feathered; power (left engine) required was 19 inches manifold air pressure [MAP] (propeller in full fine pitch).
At 2,000 ft, to maintain level flight, flaps up, left engine at full power, right propeller feathered; stabilised speed was 102 kts.
At 2,000 ft, to maintain level flight, flaps up, left engine at full power, right propeller windmilling (fuel mixture closed); stabilised speed was 80 kts.
The test pilot found that at an air speed greater than 80 kts level flight was not possible with one propeller windmilling. The aircraft would descend at the approximate rate of 200 ft/min. for a 10-kt increase in air speed.
The test flights were conducted in daylight and in visual meteorological conditions with a distinct horizon as an aid to aircraft attitude control. These conditions were significantly better than those on the accident flight. The test pilot found that in order to obtain the best possible performance, fine attitude control was necessary. A significant rate of descent was easily set up by minor attitude deviations and the elevator required careful trimming until stabilised speeds were obtained.
Comparison of automatic voice recorder information
A further flight was conducted in the test aircraft to establish the engine power settings heard in the background of transmissions from the accident aircraft recorded on the Coolangatta AVR tape. A series of transmissions was broadcast from the test aircraft to Coolangatta Surface Movement Control. Each transmission was made with the left engine at a specific power setting and the right propeller windmilling. The power settings varied from cruise power to full rated power. The test transmissions were recorded on the Coolangatta AVR tape and were compared with those from the accident AVR tape. The result of this comparison indicated that the accident aircraft was operating on one engine, and that the engine was operating in excess of 2,590 RPM and at greater than 25 inches MAP from 2127:49 until just before impact at 2137:37.
In-flight engine start procedure
The pilot reported that he attempted to start the right engine when he realised that it was unlikely that the aircraft would reach the aerodrome at its current performance. He was unable to restart the engine. Subsequent research found that the manufacturer's Owners Handbook was found to contain a procedure for air-starting an engine which was applicable to the Avco Lycoming O-540 carburetted engine and not the IO-540 fuel injected engine as fitted to this aircraft. The investigation did not reveal whether the pilot used this checklist on the night.
During a test flight the Owners Handbook emergency checklist was used in an attempt to start the right engine, propeller feathered. The test pilot was unable to start the engine using the procedure in the checklist. When the correct start procedure in the Avco Lycoming Operators Manual was used, the engine started immediately. The propeller did not unfeather until the engine started. The aircraft manufacturer confirmed that unfeathering was not possible without an engine start.
The aircraft manufacturer confirmed that the Avco Lycoming Operators Manual procedure was the correct procedure to use in an air start. The manufacturer also said that the Owners Handbook was not an approved document and was provided for advice only. The introduction in the first edition of the Owners Handbook, dated February 1971, states in part that more detailed information is contained in the flight and maintenance manuals.
Information from the pilot
The pilot was aware of incidents involving power losses, including one where a gascolator came loose and sprayed the wing with fuel. As pilot, he was involved in one incident where some fuel injectors to the right engine were blocked. He left the propeller windmilling on that occasion because the aircraft was only 3-4 minutes from landing. The engine stopped during the landing roll, but the pilot was able to restart the engine for the taxiing phase.
Observation of pilot's instrument rating renewal test
On 3 July 1996, a Civil Aviation Safety Authority flying operations inspector (FOI) observed an instrument rating renewal test on the pilot. During debriefing the significance of the best single-engine rate of climb speed was discussed. The FOI reported that the pilot did not understand the effects on aircraft performance if the speed deviated from the best single-engine rate of climb speed.
Information from witnesses
Some passengers reported that they saw the right propeller rotating before the final impact.
Witnesses near the beach said that the wind was almost calm. They heard engine noise as the aircraft approached and, when they looked towards the source of the sound, saw the aircraft with its landing lights on. About 10-15 seconds before impact, all engine sound ceased.
Recorded radar data
A secondary surveillance radar transponder with an altitude encoder was fitted to the aircraft.Consequently, aircraft pressure altitude, position and ground speed, as well as time, were recorded on the radar tape.The recorded radar data has been converted to altitude above mean sea level, local time and airspeed. However, the normal performance for this type of aircraft is 126-130 kts indicated airspeed in cruise, and all these aircraft were achieving approximately 130 kts groundspeed.Given this, the winds on the night of the accident flight were probably lighter than assessed by the Bureau of Meteorology.
The radar data showed that the accident aircraft was the slowest aircraft in the cruise phase, at 3,000 ft, compared to the other aircraft.Later, during and after descent to 2,000 ft, airspeed increased to about 130 kts and the other aircraft had airspeeds ranging between 126 kts to 135 kts. The first indication of a problem was at 2127:34 when the pilot transmitted that he had severe problems.Radar recorded that the aircraft descended from 2,000 ft at 2127:53, to approximately 200 ft at 2135:16.The airspeed during this period was approximately 90 kts and the rate of descent averaged 245 ft/min.
In the 1 minute 50 seconds before the aircraft disappeared from radar, the rate of descent reduced to an average of 55 ft/min and the aircraft airspeed progressively reduced from 87 kts to 70 kts.
ANALYSIS
Engine handling
From the pilot's evidence, the right engine surged a number of times. However, no defects were discovered which could explain the symptoms of the right engine surging. Such symptoms would be consistent with air or water in the fuel. Due to the damage to the aircraft, neither possibility could be established.
During level flight at 3,000 ft, the radar data showed that the aircraft was initially travelling at approximately 120 kts. The aircraft's speed increased to approximately 130 kts during and after descent to 2,000 ft. This higher speed continued in cruise and was probably due to the pilot setting a power setting greater than cruise power. Normal company procedure required pilots to lean the fuel mixture at cruise power once the aircraft was stabilised in level flight. If the pilot had not increased the fuel mixture to the engines to compensate for the increased power setting and lower altitude, the resulting over-lean mixture could have caused rough running. There is no evidence that the engine problem was of such severity that it should have been shut down. The pilot's intention to restart the engine later indicated that his earlier action in shutting the engine down was premature.
The pilot had been involved in a previous incident involving this aircraft when the right engine lost power due to the blockage of two fuel injectors. On that occasion he elected not to feather the propeller. This incident and the pilot's knowledge of the aircraft's maintenance history may have predisposed him to expect problems with the right engine and to conclude that the injectors were blocked again.
Propeller feathering
The pilot said that he had shut the right engine down by feathering the propeller, yet evidence indicated that the propeller was windmilling during the emergency sequence. The propeller was found to be in the normal operating range at impact and some passengers confirmed that the right propeller was rotating more slowly than the left propeller during the emergency. The pilot could not restart the engine when he attempted to do so. This information, together with the fact that the propeller cannot be unfeathered without an engine start, proved that the propeller was not feathered when the pilot thought he had done so. He probably brought the propeller lever back into the coarse pitch detent only, instead of fully back into the feather range.
Aircraft handling and performance
The series of test flights confirmed that level flight was possible with the right propeller windmilling or with it feathered, provided that the left engine produced sufficient power. These tests indicated that the flight could have been concluded safely had the pilot flown the aircraft near the recommended best single-engine rate of climb air speed. The radar data showed that the pilot did not fly the aircraft at or near the single-engine best rate of climb speed until just before impact.
The transmission made by the pilot at 2132:01 which included the comment "whatever this configuration is", indicated that the pilot did not understand the reason for the aircraft's apparent poor performance. Following a flight test, the pilot demonstrated that he was not aware that the best flight performance that could be obtained with one engine inoperative was at the best single-engine rate of climb speed.
The pilot's impression that the left engine was not delivering power was probably due to his rationalisation of the aircraft's apparent poor performance. His impression of low power was not supported by the performance profile of the aircraft as shown from recorded radar data, or by the analysis of engine sound during 17 transmissions over a 10-minute period which showed that the engine was operating close to rated power. The pilot would have been aware that the aircraft was capable of level flight at 90 kts with a feathered propeller, the speed maintained during the emergency sequence. However, the propeller was not feathered.
Engine restart
The attempt to restart the engine was made late and at a time when the pilot needed to concentrate on flying the aircraft to its best performance. The reason for the pilot's inability to restart the engine was not conclusively established. Had he used the electric fuel pump while the engine windmilled, it is likely that the engine would have been flooded.
Pilot knowledge and workload
The pilot was a qualified flying instructor. He was also the holder of a command instrument rating for twin-engine aircraft. However, the pilot appeared to demonstrate a lack of understanding of certain aspects of the aircraft's operation, including performance limitations of operating a twin-engine aircraft on one engine, and necessary details of the aircraft's fuel system. This lack of knowledge would have increased the pilot's difficulties in dealing with the apparent engine and performance problems.
During the emergency period, the pilot appeared to be experiencing a high workload. In addition to the difficulties in identifying the nature of the aircraft's performance problems, there were a large number of radio transmissions made to and from other company aircraft. This workload would have contributed to the pilot's difficulties in dealing with the apparent engine and performance problems.
SIGNIFICANT FACTORS
The pilot shut down an engine following surging but did not feather the propeller.
The aircraft was not flown at (or near) its best single-engine performance speed after the right engine was shutdown.
SAFETY ACTION
The Bureau of Air Safety Investigation is continuing its investigation into the incorrect air start procedure appearing in the Owners Handbook as supplied by the aircraft manufacturer.The results of any recommendation action that may subsequently arise will be published in the Quarterly Safety Deficiency Report.
The Saab 340 aircraft was inbound from Orange for a landing at Sydney and the crew had been instructed to track via the Sydenham locator for a left circuit to runway 16L. The Saab had been cleared to descend to 6,000 ft. At about the same time a Mooney aircraft, en route from Bankstown to Tobins Gap, was on climb to 5,000 ft while tracking north from overhead the Sydney Very High Frequency Omni-Directional Radio Range (VOR) navigation aid to Williamtown.
The approach controller was aware of the possibility of conflict between the aircraft due to the limited displacement (approximately 2.5 NM) between the Sydenham locator and the Sydney VOR. Consequently, he used a function of the radar display to highlight the symbol and label of the Mooney to assist in monitoring the aircraft's track. However, due to the close proximity of the terminal radar antenna and the VOR, the Mooney passed through the radar overhead cone of silence (an area immediately above the antenna where the radar is unable to detect aircraft) as it overflew the VOR. Consequently, the Mooney's symbol and label disappeared from the controller’s radar display.The radar display does not retain controller inputs for lost tracks and subsequently did not re-highlight the symbol and label when the aircraft emerged from the cone of silence. Consequently, the controller was not provided with the visual cue to assist in monitoring the aircraft's symbol after it passed over the VOR.
The controller intended to instruct the pilot of the Saab to turn downwind after passing overhead the Sydenham locator, an action that would ensure separation was maintained between the Saab and the Mooney.However, this instruction was not passed to the pilot as the controller commenced a handover/takeover to a new controller. As the Saab passed overhead the locator, the pilot maintained an easterly heading which was a converging course with the Mooney. The controller could not confirm whether or not the Saab's symbol and label were continuously displayed on the radar screen. The radar recording system showed a continuous plot for the aircraft; however, such a recording does not replay individual radar screen presentations and consequently, the actual radar display provided to the controller could not be confirmed.
The pilot of the Mooney had been instructed, by a controller on an adjacent control position, to turn north to track to Williamtown and climb to 8,000 ft. As separation between the aircraft reduced, the two controllers conducting the handover/takeover were alerted to the situation by a controller at an adjacent control position. The latter queried the track of the Saab as the aircraft was about to infringe his airspace. The new on-duty controller instructed the pilot of the Saab to turn left while the pilot of the Mooney was given traffic information and instructed to turn right for separation. Traffic was busy but not abnormal for the time of day and the weather was fine with unrestricted visibility.
The aircraft passed with approximately 1.5 NM horizontal separation and 100 ft vertical separation. The required standard was 3 NM horizontally or 1,000 ft vertically. There was a breakdown in separation.
ANALYSIS
Controllers were aware of the problem with the radar display not retaining controller inputs for lost tracks. This had become apparent with the advent of new procedures for parallel runway operations. The actual radar cone of silence is very narrow, and approach controllers sometimes transfer aircraft early to either of the Directors (East or West as appropriate) to ensure aircraft tracking via the Sydenham locator do not enter the cone. The directors operate on a larger scale display and consequently are better able to monitor aircraft clear of the cone and maintain aircraft symbols on the display.
In this incident the controller elected to retain the aircraft and then became distracted while conducting a handover/takeover. The provision of separation assurance techniques would have ensured separation between the two aircraft while they were in close proximity to the cone of silence. This was not done. Alternatively, the controller could have tracked the Mooney via a route which would have ensured that the aircraft did not enter the radar cone of silence and, consequently, the system would have maintained the track on the display.
The situation was compounded by the inability of the radar and display systems to continue plotting the track of the Mooney as it passed through the overhead cone of silence. Secondary surveillance radar data from the Sydney terminal area is available from two sources and the use of multi-radar tracking would eliminate the blind spot due to the cone of silence. However, this facility is currently not available at Sydney. Additionally, the system was unable to maintain controller display inputs to re-highlight the track. While not major factors in the incident, the lack of these functions reduced the defences available to the air traffic system.New equipment being provided by Airservices Australia will address this deficiency.
SIGNIFICANT FACTOR
Separation assurance techniques were not adequately utilised.
SAFETY ACTION
Safety deficiencies involving handover/takeover aspects are being addressed through Occurrence 9600800.
On final approach to land the helicopter in a clearing to refuel, the engine misfired and stopped. During the subsequent autorotation, the pilot managed to restart the engine. The engine faltered again on late final approach. The pilot attempted to stretch the glide to the clearing and managed to land the helicopter clear of the trees. The run-on landing was heavy. The pilot who was the only occupant, was able to exit the helicopter safely.
The skid gear and lower fuselage of the helicopter were damaged. The tail rotor drive was struck by the main rotor during the run-on landing.
The pilot confirmed that the helicopter had run out of fuel.
On 12 October 2014, at about 1517 Central Daylight-saving Time, the flight crew operating a Qantas Airways B737 aircraft, registered VH-XZI, were preparing for the approach and landing into Adelaide, South Australia. The aircraft had departed about one and a half hours earlier from Alice Springs, Northern Territory, with the captain as the pilot flying (PF) and the first officer as the pilot monitoring (PM).
During descent preparations, air traffic control (ATC) issued arrival instructions which the crew loaded into the flight management computer (FMC)[1] via the control display unit (CDU)[2] (Figure 1). In accordance with company procedures, the PM calculated the expected landing weight. After obtaining confirmation from the PF that his calculations were valid, he entered this figure into the aircraft gross weight (Gross WT) section of the approach reference page, (Figure 1). However, according to the post-flight data obtained from the quick access recorder (QAR), a figure of 52 tonne (T) had been inadvertently entered instead of the predicted landing weight of 62 T.
To complete the manual selections, the PM stated he verbalised, and then selected the flap 30 field on the CDU (Table 1).
Figure 1: An example of a CDU Approach Reference page
Source: Qantas Flight Crew Training Manual
Table 1: Approach reference page expanded information
No.
Item
Function / notes
Detail
1
Aircraft Gross WT
Normally displays the FMC calculated aircraft Gross WT.
Manual entry of Gross WT is allowed. Leaving and returning to this page replaces a manually entered weight with FMC computed Gross WT.
2
Vref
FLAPS – VREF
Displays landing Vref for three flap settings as computed by the FMC. Speeds are based on displayed gross weights. Vref once selected, will not be updated. To obtain an updated speed, the current speed must be deleted, or a different Vref selected or entered.
3
Flap/Speed (FLAP/SPD)
Displays selected approach reference flap and speed setting.
Manual input of desired flap and/or speed settings may be made.
4
Wind Correction
Displays current wind correction for approach.
Default is +5 kt
Source: Qantas
Following the inadvertent landing weight data entry error, the FMC calculated the flap speed schedule and the landing reference speed (Vref), based on this lower weight. With each stage of flap selection, the magenta bug[3] moved and pointed to the new command speed on the airspeed indicator. With the selection of flap 30, the command speed became Vref plus any wind correction factor entered by the crew[4] (Figure 2).
The captain briefed, then flew the arrival and approach onto runway 23 in clear conditions and mild, westerly winds. At about 1,500 ft above mean sea level, the aircraft was fully configured for landing with the gear down and flap 30. The captain disconnected the autopilot and hand flew the remainder of the approach and landing.
During the approach, the PM made a verbal reference about the airspeed being ‘wrong’. The PF reported he did not clearly hear what the PM had said, nor did he understand what message the PM was trying to convey. The captain assumed that the PM may have been making a comment in relation to a relatively new company procedure[5] used to calculate the approach speed. All the instrumentation presented to him looked normal, so he made the assumption that it was not something critical, and continued to focus on aircraft flight path management.
The PF continued to make adjustments to the thrust levers to allow for changes in wind. As was their normal procedure, the PF used the head-up guidance system (HGS) during the flight.[6] The PF reported that after the Flap 30 selection, he noted that the speed bug (‘magenta’ bug) moved a greater distance down the speed tape than normal, but he was not unduly concerned and continued to focus on flight path management.
At a height of about 200 ft, the PM reported he called “speed’ when he noticed the magenta speed bug on the primary flight display (PFD) airspeed indicator (ASI) reduce to within close proximity of the top of the amber band (Figure 2); however, the PF reported not hearing this call.
During touchdown, both crew noted that the aircraft’s pitch attitude was higher than usual. The aircraft had a nose-up pitch of 7.5°; whereas a normal nose-up pitch was 3.5-3.75°. The remainder of the landing was normal and there were no injuries and no damage to the aircraft.
The captain commented that with a non-VNAV approach, the crew set the approach speed into the mode control panel speed window (MCP). However, as in this case with a VNAV approach, the speed window is blank, the FMC selects the speed bug as the crew select the flap. This removed an opportunity for the crew to detect the speed mismatch.
The captain stated that in hindsight the aircraft nose attitude must have been higher than normal on the approach,[7] however he did not notice it during the occurrence.
First officer (PM) comments
When the PM noted that the magenta bug was closer than normal to the manoeuvring margin amber band on the PFD airspeed indicator, he thought the ‘moving’ amber band may have reached a higher airspeed due to the increased g loading in the gusty conditions, until he also noted the discrepancy on the CDU from the flaps 30 Vref calculated earlier during the preparation for descent phase.
The PM reported that when he made a reference about the airspeed being ‘wrong’, to the PF, he believed the call was clear and concise; he also added the instruction to fly a certain airspeed. He believed this was a safer option that going “head down” and reselecting the landing vref on the CDU.
As noted in Table 1 – note 1, once the crew left the approach reference page on the CDU and then returned to it, the page defaulted back to the FMC calculated (higher) GW and (higher) Vref for Flap 30. This realisation prompted the PM to say that the ‘speed’s wrong’ to the captain. When the PM saw the captain advance the thrust levers (for the gusty conditions) he thought this was a response to his comment.
Operator report
The operator conducted an investigation into the incident. Their report detailed the following:
The data entry error was made when entering the expected landing weight into the FMC Approach Reference page; this figure was not reconciled against the final load sheet
As the PM had only just started to comprehend the speed disparity, this led to the non-assertive comment. [note PM comment under First Officer comments regarding this aspect]
The Boeing Speed Calculation method may have contributed to a reduced level of recognition by the Captain of the significance of the position of the magenta bug and the amber band. This method varied from the previous Reference Ground Speed (RGS) method used to allow for changes in wind between when the aircraft was on approach and the wind experienced during touchdown
It is likely that the advancement of the thrust levels at the time the PM started to recognise a speed disparity led to a level of confirmation bias that the speed disparity was being addressed
The predicted landing weight was printed on the final load sheet given to the flight crew just prior to departure, however this figure did not allow for variations in fuel burn experienced in flight. The load sheet estimated landing weight was often used as a gross error check by flight crew, but it was not part of the company standard operating procedures. On this occasion, the crew did not conduct a gross error check using the load sheet figure, nor were they required to do so.
Non-technical skills training (NTS)
The operator reported that ‘flight crews undergo extensive non-technical skills training and recurrence during initial and cyclic training sessions. As part of this training, various levels of assertion are regularly highlighted in the event that a disparity in aircraft performance is recognised. Key indicators of uncertainty were observed in this occurrence around error recognition and confirmation. It is likely that this uncertainty resulted in a breakdown of the expected levels of assertion and a reduction in the preventative control’.
Recovery controls
The operator also noted that recovery controls would have been effective had the speed reduced to a critical amount. The head up guidance system provides visual caution/warning to the captain in the event that a tail strike pitch angle or rate is approaching, or has been exceeded. The head-up guidance system also indicates the angle of attack and normal angle of bank as a visual cue to the captain.
Safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Flight operations
As a result of this occurrence, Qantas has advised the ATSB that they are taking the following safety actions:
Action taken by Qantas
As a result of this incident, the operator intends to revise the flight crew operations manual (FCOM) descent procedures. The procedures will include an item requiring the PM to compare the landing weight entered into the Approach Reference page during descent preparation, with the load sheet estimated landing weight.
Safety message
Data entry errors
Although having a primary focus on data input errors in preparation for take-off, the message is common. Errors can occur irrespective of pilot experience, operator, aircraft type, location and take-off [or landing] performance calculation method.
An ATSB research study titled Take-off performance calculated and entry errors: A global perspective is a research paper which focused on such incidents and accidents in the 20 years prior to 2009. A consistent aspect was the apparent inability of flight crew to perform ‘reasonableness checks’ to determine when parameters were inappropriate for the flight.
This research article is available at the ATSB website.
Also the ATSB have produced a short YouTube video on Safety concerns in regard to data input errors. This can be viewed at the ATSB website.
Crew communication
This incident highlights the importance of effective crew communication. The PM attempted to communicate his uncertainty to the PF, but the PF did not understand the specific nature of the PM’s concerns.
Non-technical skills (NTS) previously known as cockpit resource management (CRM) training has developed over many years to promote teamwork among pilots and to lead to a reduction in human error. Two studies conducted by Fischer, U., and Orasanu, J., published in 1999 looked at language and communication strategies between two groups of captains and first officers from three major US airlines. Of interest, the studies found that the strategies pilots indicated they would use to mitigate pilot errors, may not be the most effective ones. Also, there was a considerable difference between the captains’ and the first officers’ communication strategies.
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 21 October 2014, the pilot of a Eurocopter EC120B helicopter, registered VH-BGB, conducted a charter flight from a ship about 24 nautical miles north-north-west of Port Hedland to transfer two marine pilots to Port Hedland Airport, Western Australia. The flight was conducted under night visual flight rules.
At about 2240 Australian Western Standard Time, the helicopter lifted off and the pilot commenced the climb and transitioned to a forward airspeed of about 15 knots. As the helicopter passed over the bow of the ship, it encountered windshear. Approaching about 350 feet above sea level, the pilot observed the airspeed indicating about 5 knots. He reported that his focus had momentarily been on the radar altimeter, and he had not detected the airspeed decaying. He immediately applied forward cyclic to increase the airspeed, then continued the climb to 1,500 feet, and proceeded to Port Hedland without further incident.
The pilot reported that in a normal climb, by about 400 feet he would expect the airspeed to be approaching 40 knots. He believed that his delay in recognising the decreasing airspeed was due to feeling unwell. He had some symptoms of a cold prior to the flight, had been on duty for about 22 hours prior to the incident, and had slept for about 2 hours during that time.
The helicopter operator issued a Safety Notice to all company pilots reminding them of the importance of managing fatigue and fitness to fly in accordance with their Fatigue Management policy.
On 24 October 2014, the Melbourne to Sydney XPT service ST24 was approaching Culcairn station when there was a severe vibration. The driver stopped at the station and upon inspecting the train found that the axle had broken adjacent to the bearing box on the fourth passenger carriage. There were no injuries to passengers or crew. The passengers continued their journey to Sydney on chartered buses.
What the ATSB found
The ATSB found that the axle bearing had failed and completely seized, probably due to cage failure.
The probable cage failure caused the rollers to misalign and seize. This seizure of the rollers generated friction and excessive amounts of heat into the bearing journal. The heat applied to the bearing journal caused it to go ‘plastic’ and separate from the axle (commonly referred to as a screwed journal). In this case, much of the evidence was either lost or damaged beyond useful examination. Consequently, there was insufficient evidence available to determine why the bearing cage may have failed.
The ATSB also identified that ARTC train control, despite receiving reports of trackside fires, made contact with NSW Trains operations, rather than directly with the driver. It is unlikely that direct communication with the driver of ST24 would have resulted in a different outcome in this case because, by the time the potential cause of fires was known, ST24 was already on its way to Culcairn. However, in some scenarios, communicating directly with the train driver would likely ensure a more timely response to issues that may affect the safety of the network.
What's been done as a result
ARTC will ensure that all matters relating, or potentially relating to, the safety of a train operating on the network will be advised in the first instance to the driver of the involved train by the relevant Network Control Officer.
Safety message
Any issues with train services that can compromise the integrity and safety of the network must be communicated directly to the train driver. Communicating through a third party can compromise a timely response.
Source: Sydney Trains
Appendices
Appendix A – Condition monitoring systems
Hot-box detectors
Hotbox detectors are a reactive method of condition monitoring. They usually detect the infrared signature of bearing components and alarm if the temperature exceeds a predetermined setting. However, there are a number of variables that can affect their performance on a mixed freight/passenger rail corridor. These variables include but are not limited to:
train loading
train speed
weather conditions.
Consequently, hotbox detection is usually used as a ‘last line of defence’ to protect railway infrastructure assets critical to production processes such as coal and ore carrying railways.
Due to the potentially unreliable performance of hotbox detectors under mixed freight/passenger conditions, more effort has been directed towards predictive condition monitoring of railway rolling stock travelling on the interstate main lines.
Bearing Acoustic Monitoring
Bearing Acoustic Monitoring (BAM) is a predictive condition monitoring system that ‘listens’ to the acoustic signature of bearings and can detect faults as they develop. It is the primary method for detecting potential bearing faults on rolling-stock travelling on the interstate main line. Recorded data from each train is stored in a database allowing evaluation, trending, and maintenance scheduling of rolling-stock based on predicted bearing condition.
BAM uses sensitive acoustic arrays to record the sounds emanating from wheels and bearings passing through the monitoring site. The recordings are processed for the sound characteristics that are unique to specific types of bearing faults. BAM is best at detecting faults on rolling surfaces such as the inner and outer raceways, and rollers in rolling-stock bearings. BAM can also detect looseness or fretting faults and ‘noisy’ wheels (flanging and wheel flats).
BAM systems are usually installed and maintained by infrastructure managers. However, the data is made available to rolling stock operators through a web interface. The BAM database categorises potential bearing faults in the form of levels of severity (1, 2, and 3 with level 1 being the most critical). The database allows operators to analyse bearing fault history and trends in order to plan their preventative maintenance strategies.
As for any monitoring system, there are some limitations. For example, BAM is a system that ‘listens’ for bearing noises, and under some conditions, other noises (rubbing equipment, tread defects or flanging wheels) may affect the results. However, being a predictive condition monitoring system, multiple passes of potentially defective bearings allows true fault trends to be clearly identified and actioned before a defect reaches a critical level.
It is evident that predictive condition monitoring and a pro-active approach by train operators has become an integral tool for managing the risk of bearing defects on freight rolling stock, especially in relation to rolling surface defects. For example, the ARTC BAM site at Nectar Brook showed a reduction in the number of level 1 rolling surface faults from about 0.5% in 2002 to about 0.05% in 2010. However, Level 1 looseness or fretting (LF1) faults have not experienced the same improvement. In 2002, LF1 faults were about 1.2%, reducing down to about 0.6% in 2005 before rising back to 1.0% in 2009 and 2010.
On-board condition monitoring
In the past, condition monitoring of rolling-stock has been the realm of trackside equipment (Hotbox, RailBAM, etc.), usually fixed at a specific geographical location. While predictive systems may provide a broader level of protection, reactive systems are limited to protection of equipment and infrastructure in the immediate vicinity.
The next evolution of condition monitoring would be one that continuously monitored each wagon for developing faults (predictive) and immediately communicated any critical conditions to the train drivers (reactive). This type of system is referred to as an on-board condition monitoring system. While various limitations (functional and economic) have prevented these systems being widely used on railway freight operations in the past, recent technological developments have now made the concept more attractive. However, at the time of this incident, only limited developmental work had been started within Australia.
Findings
From the evidence available, the following findings are made with respect to the axle failure on XPT ST24 on 24 October 2014 at Culcairn NSW. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
Contributing factors
The XPT axle failed when the bearing seized, generating enough heat for the bearing journal to go ‘plastic’ and separate from the axle, a condition commonly referred to as a ‘screwed journal’
In the absence of any evidence to the contrary, the most probable cause of bearing seizure was failure of the bearing cage. This likely allowed the rollers to misalign and jam, resulting in slippage of the inner bearing ring on the journal.
Other findings
There was insufficient evidence available to determine why the bearing cage may have failed.
It is likely that a progressively failing bearing on ST24 caused the trackside fires reported to the ARTC train control.
On receipt of the initial advice of the fire at Winton ARTC promptly communicated with the NSW Trains Operations Manager. However, direct contact with the Driver of ST24 would have been more appropriate.
The grease used by the bearing manufacturer in the new supplied bearings was not an approved grease as documented in ESR 0400 Engineering Standard for bearing grease.
The Hasler data logger in lead power car XP2001 was defective in that it was not recording brake cylinder pressure or distance.
The occurrence
At about 0700[1] on October 24 2014, TrainLink[2] Sydney to Melbourne passenger service ST21, operated by NSW Trains,[3] arrived at Broadmeadows[4] Victoria (Figure 1). At Broadmeadows, there was to be a crew change and passengers disembarking the service.
As ST21 arrived at Broadmeadows, the relief driver, who was waiting on the platform, noticed what the driver described as a strong smell of brakes. During the handover briefing, the two drivers discussed the smell coming from the train. Although a smell coming from the brakes was common on long trips, the relieving driver, now in charge of the train, decided that he would undertake further inspection at McIntyre. McIntyre is located between Broadmeadows and Southern Cross station and was where refuelling of the return service to Sydney occurred.
At McIntyre, the train was re-fuelled and cleaned in readiness for the return journey to Sydney, with a new train identification number of ST24. While re-fuelling, the driver also examined the area of the train thought to be the source of the smell, paying particular attention to the brakes. While he again noticed the brake smell, he did not consider it unusual for a train having just completed a trip from Sydney. He then readied the train, departed McIntyre and arrived at Broadmeadows at about 0835 to pick up passengers. At about 0855, train ST24 departed Broadmeadows for Sydney with 125 passengers and crew on-board.
Figure 1: Location of Broadmeadows, Benalla, Winton, and Culcairn.
Source: Geoscience Australia annotated by the ATSB
At about 1041, ST24 arrived at Benalla station, stopping briefly to set down and pick up passengers. At about 1106, ST24 undertook another passenger stop at Wangaratta before continuing on to its next scheduled stop at Albury.
At about 1123, the Emergency Service Telecommunications Authority (ESTA known as ‘000’) received a phone call from a member of the public, advising of a fire between the Hume Hwy and the railway line about 5 km north of Benalla. After confirming the location, the operator dispatched the Country Fire Authority (CFA) to attend the scene. For the next 20 minutes, passing motorists and members of the public in the Benalla Winton area, reported more spot fires to 000.
At about 1143, the Australian Rail Track Corporation (ARTC) Train Transit Manager (TTM) at Junee Train Control Centre, NSW received a call from the CFA. The CFA reported that a fire in the Winton area was adjacent to the railway line.
Soon after, ST24 arrived at Albury station to set down and pick up passengers, then departed Albury for Culcairn at about 1153.
At about the same time, the ARTC TTM received another call from the CFA reporting that crews were attending the trackside fires. The CFA suggested that the last train through the area (about 30-45 minutes prior) had started the fires. The TTM advised that, at about 1100, a northbound passenger train (ST24) had passed through that area. The CFA re-affirmed their belief that this train had started the fire, as no other fires had been reported anywhere other than the Winton area. The TTM advised that he would contact TrainLink operations in Sydney and get them to make enquiries with the driver of ST24 about its possible connection with the Winton fires.
The TTM contacted the NSW Trains Daily Operations Continuity Centre (DOCC) Operations Manager and informed him of the fire in the Winton area. The TTM explained that the only train through that area in the last 50 minutes was the XPT Melbourne to Sydney service ST24 and that this train may have caused the fire. The Operations Manager informed the TTM that he would contact the driver of ST24 and make further enquiries regarding any problems with the train.
At around 1200, the NSW Trains Operations Manager contacted the driver of ST24 to inform him of a fire in the Winton area. He told the driver that the TTM in Junee had contacted him after they had received a report from the CFA regarding a fire adjacent to the track in the Winton-Benalla area. He told the driver that they believed his train had started it and asked if he had any issues with his train. The driver reported that everything seemed to be okay, but would inspect his train at his next scheduled stop.
The DOCC Operations Manager then contacted the TTM and informed him that he had spoken directly to the driver of ST24 and the driver reported nothing wrong with his train. He also advised that the driver would check it at the next scheduled stop.
At about 1213, the driver of ST24 experienced what felt like a run-in,[5] which he considered unusual for the approach into Culcairn. At about the same time, the driver heard (over the radio) the Passenger Attendant (PA) report to the Passenger Services Supervisor (PSS) of a severe vibration in the first class passenger car. Shortly thereafter, the PSS contacted the driver and advised that something was wrong with the first class passenger car. The PSS described it as a severe vibration, as if the passenger car was running over something.
At this stage, ST24 was approaching Culcairn. The driver determined that the train was still coupled and on the rails, so he decided to continue on the short distance to Culcairn.
At about 1216, the driver stopped the train at the station and notified Train Control (TC) that he was in clear[6] at Culcairn. He also advised that he was going to inspect the train, as the PSS had reported vibration in a passenger car. He asked for the departure signal to be placed at stop and asked for permission to access the track to inspect the train.
After inspecting the train, the driver notified TC that the trailing axle on car B (XL2235) had sheared off (Figure 2). He informed TC that the train was unable to continue its journey and alternative arrangements would be required for passengers to continue their journey. During the conversation, TC informed the driver of other reported fires in the Albury and Gerogery areas.
Figure 2: Failed axle and swing arm hanging down.
The image shows the failed axle journal, commonly referred to as a ‘screwed journal’. As the bearing housing no longer supports the axle, the swing arm has dropped. Source: NSW Trains, annotated by the ATSB
Events post-derailment
Passengers continued their journey on buses. The Australian Rail Track Corporation (ARTC) and NSW Trains examined options for moving the train to a siding at Culcairn. Once a suitable solution was identified, the damaged car was moved to the siding where it remained until arrangements could be made to replace the defective bogie. The remainder of the train then continued to Sydney.
It is likely that a progressively failing bearing on ST24 caused a number of fires beside the track. The fire services attended the fires, while the police attended the scene at Culcairn.
The ARTC arranged for an inspection to ensure the track had not been damaged by the dragging swing-arm. There was no damage to the track infrastructure.
Sydney Trains XPT Inspection Schedule & TMP Inspection Timetable
ASM Handbook, Volume11, Failure Analysis and Prevention
State Rail Authority Engineering Instruction EIDSS 5152 22 November 2004 issue 2
Submissions
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to Transport for NSW, Sydney Trains, the driver of train ST24, NSW Trains, Bearing Engineering Services, the Australian Rail Track Corporation, and The Office of National Rail Safety Regulator (ONRSR).
Safety actions
Additional safety action
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
Additional safety action taken by ARTC
ARTC will ensure that all matters relating, or potentially relating to, the safety of a train operating on the network will be advised in the first instance to the driver of the involved train by the relevant Network Control Officer.
Context
Location
The failed axle occurred near Culcairn (NSW), about 357 km [7] from Melbourne (Figure 1). The line, referred to by Train Control Junee as Main Line South, forms a main arterial link between Sydney and Melbourne.
The first reported fire occurred near Winton in Victoria (Figure 1) located at about the 207 km point.
Train information
The Express Passenger Train (XPT) is a ‘push-pull’ configured train with a power car at each end of the consist. The XPT was introduced in 1982 and is based on the InterCity 125/Class 43 design used in Britain.
Figure 3: XPT TrainLink power car XP2001.
The image shows an XPT power car and passenger car. ST24 consisted of five passenger cars, identified by the letters A-E, with a power car both leading and trailing. Source: ATSB
Sydney Trains owns the XPT fleet. NSW Trains is the operating agency providing passenger services through country NSW and to Brisbane, Canberra, and Melbourne.
The XPT train (ST24) consisted of a 5-car set with power car XP2001 leading and XP2016 trailing.
Train crew information
At the time of the incident, there were seven train crew on board, including the train driver. The driver of ST24 had over 13 years driving experience with 7 years driving XPT trains. The driver was tested for drugs and alcohol, and returned zero readings.
Train handling
The XPT power cars are fitted with Hasler tape data logging devices. Hasler data loggers record:
time, speed, distance
throttle position (power/idle)
vigilance acknowledgement
brake cylinder pressure.
Of the two devices, the data logger in XP2016 (trailing car) was fully functioning. The recording for the leading power car, XP2001 was incomplete in that it did not record distance or brake cylinder pressure correctly.
The data logged from XP2016 was validated against train control graphs for distance travelled. The brake cylinder pressure could not be validated against XP2001 data logger. However, the recorded brake cylinder pressures changes indicate a consistent deceleration pattern with similar changes seen in the recorded BCP during all braking sequences on XP2016.From the evidence available, it was determined that the train handling was generally consistent with common train handling practices.
Refuelling
The XPT trains require mid-journey refuelling for the service from Sydney to Melbourne and return. During the re-fuelling at McIntyre, the driver of ST24 also looked for any issues that may have caused the brake smell observed at Broadmeadows.
Due to the train’s position, it was not safe to check its left hand side (in the direction of travel to Sydney) because of the adjacent live track. However, the driver did check the right hand side of the train, checking cars A, B, and C (Melbourne end - last three carriages). During these checks, the driver did not see any signs of the journals or bearing boxes being abnormal but noted that there was a smell and the brakes were warm. However, the driver did not think it was out of the ordinary, as the train had just completed a journey of over 1000 km.
Track information
The Main Line South track is a standard gauge track[8] consisting of continuously welded rail on concrete sleepers, fastened by resilient clips.
The ARTC lease and manage the track. Control for the Main Line South signalling is from the ARTC Train Control Centre at Junee.
Track speed approaching Culcairn station is 160 km/h for XPT services. The service only stops at Culcairn when passengers are scheduled to disembark or board the service.
Bearings
The bearings used on the XPT fleet are Timken SP120 package tapered roller bearing. Package bearings consist of two tapered bearing assemblies (commonly referred to as cones, and includes the inner rings, rollers and cage). Between the two bearing assemblies is a spacer ring of specific width, correctly positioning the two cones when the bearing is assembled. Outside each bearing assembly is a seal wear ring, over which the grease seal is positioned. When installed in the wheel-set, a backing ring is mounted on the inboard side of the axle journal and an end-cap is bolted onto the outer end of the bearing journal (Figure 4).
Figure 4: Package bearing components
Source: ATSB
The Engineering Instruction for TrainLink wheelsets requires the bearings to be put into service within two years of manufacture or requalified date. If the date is more than two years, the bearings are required to have the grease replaced.[9]
Package bearings are installed as fully greased sealed units and are press fitted onto the journal at Unipart UGL in Auburn. The bearings do not require in-service regreasing, which reduces the risk of inadequate, excessive, or contaminated lubricant during operation.
Bearing history
Timken bearings supply new SP120 bearings to Bearing Engineering Services[10] (BES), which then supply UGL Unipart bearings for the XPT fleet. BES also service and requalify bearings for reinstallation.
Combinations of new and requalified bearings were installed on passenger car XL2235. The new bearings were manufactured in South Africa in 2012. These bearings were supplied to UGL with Renolit MP3 grease, as installed by the manufacturer. The requalified bearings were overhauled in 2013 (by BES) and supplied to UGL with Timken premium railroad grease.
The bearing installed into position 3 (Figure 5) on bogie NHA-8B in June 2014 was a new bearing. The serial number of the bearing was 302379 with a manufacture date of July 2012.
At the time of its failure, the bearing was well within its service life of 375,000 km.[11]
Figure 5: Bearing position on bogie NHA-8B
Source: ATSB
Bearing and axle examination
The bogie was taken to the UGL Unipart in Auburn for examination. Preliminary examination of the failed bearing components by the ATSB indicated that the bearing had seized. The remains of the bearing and the accompanying swing arm were taken back to ATSB laboratory for further analysis. The remains of the axle journal were not recovered.
It was evident that the bearing had seized while the axle was still turning. The heat generated by the failed bearing was sufficient to heat the journal, to make it ‘plastic’ (Figure 6) and cause it to separate from the axle (commonly referred to as a screwed journal).
Figure 6: Swing-arm bearing housing
The XPT bogie swing-arm bearing housing, viewed from the inboard side. The heat damage is evident and the remaining bearing components can be seen inside the housing. Source: ATSB
The ATSB failure analysis specialists conducted an examination of the failed bearing. Witness marks at the interface between the bearing and the swing-arm bearing housing could not be examined due to the extensive damage to the bearing.
There were a number of flat rollers on the inboard (Figure 7-1) and the outboard (Figure 7-3) bearings. Markings on the flattened rollers indicate that the rollers seized and misaligned in the bearing cage while the axle was rotating.
The inboard raceway showed evidence of full-width spalling[12] fatigue (Figure 7-2). The spalling fatigue began from the 6 o’clock position and continued in the direction of rotation to the 9 o’clock position. There was also some fracturing of the shoulders on the unworn surfaces of the track.
The outboard raceway showed a full-width area of galling[13] and deposited metal (Figure 7-4). Galling is usually associated with a lack of lubrication, resulting in the two metal surfaces welding together for brief periods.
The investigation also examined the partner bearing from the opposite end of the axle.
The partner bearing was removed from the journal and the end cap bolt torque measured. The torque values were consistent with the maintenance requirement. Initial observations indicated that the partner bearing was generally in good condition.
Partner bearing examination by BES
BES conducted an examination of the partner bearing, with the ATSB present.
The bearing was weighed and grease samples from the inner, outer and spacer (centre) of the bearing was taken and sent for analysis. The BES examination found that the bearing showed uneven adaptor fretting[14] marks on the cup exterior (Figure 8-1). There was also wear and damage to the inboard raceway (Figure 8-2) and outside edges of the inboard cone rolling elements (Figure 8-3). Conversely, the raceway and rolling elements of the outboard cone (Figure 8-4) were in good condition.
Based on the amount of fretting on the bearing cup BES concluded that the bearing was probably misaligned (unevenly loaded) from when the bogie was put into service.
Figure 8: Partner bearing
Image 1: Uneven fretting marks on the exterior of bearing cup indicating uneven contact pressure between the bearing cup and the swing-arm bearing housing.
Image 2: Indentation damage to the inboard raceway.
Image 3: Peeling damage to the rolling elements of the inboard cone, predominately on the outside edges due to uneven loading.
Image 4: Undamaged rolling elements from the outboard cone. Source: BES
During the BES examination, ATSB investigators took grease samples from the partner bearing for analysis. After the BES examination was completed, ATSB investigators retained the partner bearing for further analysis.
Partner bearing examination by the ATSB
An ATSB failure analysis specialist examined the partner bearing components using an illuminated magnifier and with a stereomicroscope.
Outer cone
The outer cone had limited wear with fine brinelling,[15] scoring and polishing. This wear was also evident in the analysis of the grease samples. The samples contained iron but not chromium from alloy steel (the rollers, cup, and cone). The wear had mostly come from the soft, plain-carbon steel cage.
Inboard cone
The results of the inboard cone analysis contrasted with that of the outboard cone, with significantly higher presence of chromium from the alloy steel cup, cones and rollers.
The examination found evidence of metal loss to the bearing spacer and inner rear enclosure. The wear on the spacer would likely have resulted in some loss of preload on the bearings resulting in excessive end float. Increased end float would have placed uneven loading on the bearing, in particular the back-face end of the inner cone/double cup. It is possible that this point on the partner bearing acted as a fulcrum when the axle journal failed and the opposite end of the axle became unsupported.
The rollers of the inboard cone showed evidence of adhesive wear, but only at the back-face end. This corresponded with the inboard raceway, which exhibited a worn shoulder with several bright areas of spalling.
Swing-arm Bearing Housing
The swing-arm bearing housing showed heavy fretting wear that corresponded with asymmetric fretting wear on the bearing cup (Figure 9). Also observed, was the crack in the upper half of the bearing housing (Figure 10).
Figure 9: Partner bearing (position 4) serial number 302111
The corresponding fretting marks found on the partner-bearing cup was also evident on the partner swing arm. Source: ATSB
Figure 10: Swing arm assembly with exploded view of the bearing housing bore below
Figure 10 is of the partner swing arm (from the same axle). The exploded view shows the fretting wear on the swing arm shoulder evident by the shiny marks as annotated. As illustrated, there is also a crack in the valley of the housing. Source: ATSB
These wear patterns provided further evidence of uneven loading, possibly due to the axle misaligning when the axle journal failed and the opposite end of the axle became unsupported.
When matching the bearing cup witness marks to those in the swing-arm bearing housing, the marks ranged from a 9-3 o’clock position and were asymmetric in nature. This indicated that there might have also been some misalignment in the horizontal plane (Figure 11).
Figure 11: Bearing position on bogie NHA-8B
Figure 11 is for illustrative purposes and not a direct representation of an XPT bogie. The black dotted line on the trailing axle represents the centreline of the axle when running true. The red line illustrates a misalignment of the trailing axle, in the horizontal plane. Source: ATSB
The ATSB concluded that there was evidence of uneven loading. However, there was insufficient evidence to determine if the misalignment was predominantly in the horizontal or vertical planes.
When considering the physical evidence and examinations by both BES and ATSB specialists, the most likely conclusion is there was a misalignment in the axle. However, there was insufficient evidence to determine if this was a pre-existing condition or if it occurred because of the bearing failure.
There were no conditions associated with the partner bearing (position 4) that would suggest a possible cause for the failure of the bearing in position 3.
Grease analysis
The type of grease used by Timken in the new bearings is Renolit MP3 grease. The operator’s Engineering Standard for grease used in journal bearings for seal and package units requires that the grease be approved by the Association of American Railroads (AAR). Renolit MP3 grease is not approved by the AAR in this application. However, the grease has almost identical properties to that of an AAR approved grease type such as Timken premium railroad grease. There is no evidence that the use of Renolit MP3 grease contributed to the failure.
Partner bearing grease analysis
The partner bearing grease samples were sent to the ALS Laboratory Group for analysis. The results showed a mid-range content of silicon (contaminant) and higher levels of iron from the centre (spacer ring) grease sample, mid-range chromium and silicon with higher levels of iron from the inboard sample and low levels of chromium with mid-range levels of silicon and higher levels of iron from the out-board sample.
The chromium levels from the inner and outer grease samples indicate that it was liberated most likely from the inner and outer cup and because of the peeling damage from the inboard cone roller faces. Indentation marks on the inner and outer race was evident from the BES report and ATSB analysis.
The iron found in all three samples is likely to be from the roller cage as a result of the axle failure placing more stress on the partner bearing.
Although the grease analysis showed high levels of contaminants and iron it is likely this is due to the failed axle.
Examination of the partner bearing grease found no condition or anomaly that could be directly related to a potential issue with the corresponding failed bearing.
Bearing failure types
The recovered bearing components were examined in relation to the common failure modes for railway bearings.
A loss of interference fit between the bearing and axle journal often occurs later in the failure sequence. That is, other faults may combine to cause progressive loss of interference fit. Initial slippage may be small, but as the journal wears, the amount of slippage increases.
However, if a bearing seizes, slippage of the inner ring on the journal can suddenly occur.
Lubrication failure
The function of a lubricant is to separate the rolling contact surfaces at the point of high-pressure contact. The lubricant film between the surfaces acts to reduce wear, friction and corrosion such that the bearing should achieve its predicted fatigue life; assuming that no other factors exist that may cause premature failure. Lubrication failure can occur due to an inappropriate grade of lubricant, insufficient lubricant or contamination of the lubricant.
Cage failure
The bearing cage is designed to retain the rollers within the bearing in a consistently spaced and correctly aligned position. The cage has no role in the transmission of forces. The cages in bearings used in the railway industry are usually pressed out of metal plate.
The purpose of roller bearings is to avoid sliding friction. However, sliding at the cage surfaces cannot be avoided. Consequently, the softer material of the cage (when compared to other components) is likely to be the first area to wear when lubrication becomes inadequate or foreign material causes abrasion. Once wear occurs, the cage loses the ability to align the rollers correctly and leads to a rapidly deteriorating cage resulting in a complete failure of the cage. Once the cage fails, material jams the rollers, generating heat and the bearing inevitably fails.
Bogie NHA-8B maintenance
UGL Unipart, located in Auburn NSW, is the contracted maintenance provider for XPT bogie refurbishments. XPT carriage bogies are overhauled every 750,000 km with the wheelsets overhauled every 375,000 km. New or requalified[16] bearings are fitted with the changed out wheelsets.
The ATSB examined the maintenance records of bogie NHA-8B. The records show that during the assembly and overhaul of the bogie, all components and relevant measurements meet the requirements of the XPT carriage NHA Bogie Overhaul Specification RX01_0200_123MP.
In June 2014, passenger car XL2235 had the overhauled bogie NHA-8B fitted to the B end of the passenger car. The failed axle of the bogie set (the trailing axle in this case) had new bearings installed. The lead axle assembly had requalified bearings.
In-service inspection and maintenance
XPT carriages undergo trip inspections either at 2-day intervals or at 3000km, and maintenance every 90 days.[17] Both inspection intervals include the testing of axle box temperatures (by feel) as the train is being fuelled and decanted.
Axle boxes are also inspected for:
loss of lubricant at rear axles seals
discolouration indicating overheating.
During the operation of carriage XL2235 on 15 August 2014, a defect was noted on bogie NHA-8B on the power car logbook[18]. The defect was reported as a ‘whirring’ noise from beneath the car and the axle boxes were warm to touch. The defect was inspected on the next scheduled service on 16 August 2014 and no issue was found. The carriage was returned to service without any further noted defect regarding whirring noises or warm axle boxes.
The last documented trip inspection was on 23 October 2014 with no issue recorded. Analysis of the maintenance documentation including the defect history and inspection records indicated that there were no pre-existing maintenance issues identified with bogie NHA-8B.
Condition monitoring systems
Condition monitoring systems can be split into two generic types, reactive and predictive. These are akin to reactive and preventative maintenance. A reactive approach requires an immediate action after a serious condition develops or equipment failure occurs, whereas a predictive/preventative approach identifies the requirement for future action before a serious condition develops.
Reactive condition monitoring, such as hotbox detectors, are usually used as a ‘last line of defence’ to protect significant or critical railway infrastructure assets. They are usually used on track associated with production processes such as coal and ore carrying railways, but less common on mixed freight/passenger tracks such as the interstate main lines (refer to appendix A).
In this case, there were no reactive condition monitoring systems in place that could have detected the imminent failure of the bearing on XPT service ST24.
Infrastructure managers and rolling stock operators have directed more effort towards predictive condition monitoring of railway rolling-stock travelling on the interstate main lines. With regards to bearing condition monitoring, the predictive systems adopted are Bearing Acoustic Monitoring (BAM) systems (refer to appendix A).
Being a predictive condition monitoring system, multiple passes of potentially defective bearings are required for trends to be clearly identified and actioned before a defect reaches a critical level. Consequently, the systems are positioned throughout the interstate network based on major rail corridors. For the Sydney-Melbourne corridor, the BAM system was located on the Main South up line at Exeter, NSW (about 155 km from Sydney).
Examination of the BAM data for XPT passenger car XL2235 found no evidence of acoustic signatures to suggest the onset of a bearing failure.
In this case, much of the evidence that may have indicated the cause of its failure was either lost or damaged beyond useful examination. However, the absence of BAM data indicating a developing bearing fault would suggest that the bearing on XL2235 experienced a relatively quickly developing fault resulting in catastrophic failure. Consequently, failure modes such as metal fatigue, rolling surface defects and loose bearing components are less likely to have been failure initiators.
Examination of the partner bearing provided no clear indication of a failure mode that may have resulted in the failure of the bearing on XL2235. However, some iron particles where found in the grease indicating wear on the bearing cage. There was also evidence of uneven loading due to misalignment of the axle. However, there was insufficient evidence to determine if this was a pre-existing condition or if it occurred because of the bearing failure.
As most failure modes were considered less likely, the most probable cause of the bearing failure was a cage failure. The cage failure caused the bearing rollers to become misaligned and subsequently seize in the bearing housing. The seizure then caused friction resulting in excessive heat to build up in the bearing housing within the swing arm and journal. This generated enough heat into the bearing journal to cause it to go ‘plastic' and separate from the bearing journal.
Bearing cages may fail due to lack of lubrication, bearing misalignment (uneven loading), shock loading (wheel impacts), or a combination of these conditions. In this case, there was insufficient evidence available to determine why the bearing cage may have failed.
Reports of trackside fires
While in Melbourne, the driver of XPT train ST24 noticed a strong smell typical of hot brakes. The driver inspected the train before departure, but found nothing of concern. The investigation found no other precursor events or conditions that might suggest imminent failure of a bearing on XPT car XL2235 prior to its departure from Melbourne. However, there were events reported during the journey that may have suggested a potential problem with XPT train ST24.
After the passage of ST24, several fires were reported to the fire authorities, which required fire crews to attend.
The first report to the ARTC train control centre was of a fire in the Benalla-Winton area. Soon after, train ST24 arrived at Albury, set down and picked up passengers, then departed Albury for Culcairn. At about the same time, the Country Fire Authority made a second call to the ARTC.
The reported fires were all in close proximity to the track, suggesting that a train had started them. The timing and sequence of the reports suggested that train ST24 had started the fires, as it was the last train to have travelled through that area. It is likely that the failing bearing liberating hot components that consequently started the fires.
Following the second call from the Country Fire Authority, the ARTC TTM contacted the NSW Trains operations manager to advise that there may be a problem with their TrainLink service ST24, and requested them to check their train.
County Link operations contacted the driver of ST24 as he was travelling through the Table Top area advising him of the fire in the Benalla-Winton area. About 15 minutes had passed between the first report to train control and the request for the driver to check the condition of train ST24.
The North Albury and Gerogery fires were reported to train control when ST24 was already at Culcairn. There were no other fires reported on the Main Line South between Winton/Benalla and Sydney for that period.
It is likely that heat generated by a progressively failing bearing on ST24 had started a number of trackside fires. While the fires were reported to train control, there was no direct communication with the driver of ST24.
Communications between train control and ST24
TrainLink XPT trains have mobile phones fitted to every power car that use the Telstra mobile network.
An examination of phone records show that the calls made to the lead power car of ST24 were from the NSW Trains Daily Operations Continuity Centre (DOCC) in Sydney. Phone records obtained from ARTC and Sydney Trains confirm that at no stage prior to the axle failure did ARTC train control contact the driver of ST24.
ARTC Emergency Management
ARTC has an emergency management procedure (TA44) which outlines the management of emergencies within the ARTC rail network. The procedure addresses trackside fires and the management of the network and trains that may be affected by that fire. In short, the Train Transit Manager (TTM) or nominated representative takes the role of the Incident Response Coordinator, responsible for advising the relative parties such as emergency services and train operators of the incident.
In this case, the TTM assumed the incident response coordinator’s role when advised of the fire in the Benalla-Winton area. The TTM then liaised with the CFA control centre to ascertain the position of the fire and if CFA officers were on or near the track.
With respect to a fire in or near the rail corridor, it was evident that the procedures documented in procedure TA44 were intended to manage potential damage to infrastructure, and to manage the risks associated with fire crews working near the rail track. The procedure did not include consideration of the potential cause of a fire.
Requirements under Network Rule ANTR 402
Network rule ANTR 0402 ‘Inspecting trains’ covers inspecting of trains during travel in NSW. The Inspection during travel rule states that:
If unsafe conditions or defects are reported to Network Control, a Network Control Officer must:
Tell the affected Train Crew about unsafe conditions and defects, and
Follow the requirements of Rule ANGE 206 Reporting and responding to a Condition Affecting the Network
An equivalent requirement is not specifically documented in the rules applicable to Victoria.
In this case, the ARTC received advice from the CFA that they believed a train that had started the fires at Winton. By this time, ST24 had just departed Albury and was travelling towards Culcairn. The ARTC contacted a third party (DOCC) requesting a check of train ST24, rather than directly contacting the train crew.
It is unlikely that direct communication with the driver of ST24 would have resulted in a different outcome in this case because, by the time the potential cause of fires was known, ST24 was already on its way to Culcairn. However, in some scenarios, communicating directly with the train driver would likely ensure a more timely response to issues that may affect the safety of the network.
The ATSB identified a similar issue during another investigation.[19] In that incident, it was apparent that the use of a third party was common for facilitating communication between Network Control Officers and train drivers.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.