On 31 July 2013 at about 1500 Eastern Standard Time, an instructor and pilot under review departed Bankstown, New South Wales, in a Bell 206B helicopter, registered VH‑EPQ (EPQ), to conduct a Helicopter Flight Review. The pilot under review flew the helicopter to just south of Bringelly to conduct aerial work.
The crew conducted practice autorotation’s with the plan to go-around at about treetop height. The instructor reported that because they intended to go-around, the flare was conducted higher than if they had planned to land on the ground.
At the commencement of the last autorotation, the instructor noticed that the pilot was heavy on the controls. At the flare point, the instructor attempted to increase the throttle, but he was unable to apply pressure in time. At that stage, the helicopter was too low to be able to apply power and go around, but too high for a normal landing flare.
The helicopter struck the ground heavily and one rotor blade touched the tail cone resulting in substantial damage, the crew were uninjured.
On 7 August 2013, the student pilot of a Robinson R22 helicopter registered VH-EGN (EGN) departed from the parking area near the flying school hangar to conduct a session of solo circuits at Camden Airport, New South Wales.
The student had been checked by his instructor earlier that morning and already conducted some solo circuit practice and returned to the parking area.
At the end of the solo circuits, the student taxied EGN back toward the hangar. Facing east, and hovering about 3ft above the ground, the student commenced a left pedal turn to position the helicopter in a westerly direction for landing. The helicopter commenced turning left. When in a downwind position, the student reported that the helicopter weather-cocked into wind and the rotational speed rapidly increased.
The student unsuccessfully attempted to regain control of the helicopter. He then lowered the collective to put EGN on the ground. The right skid struck the ground first, followed by the tail rotor. The student, who was not injured, exited the helicopter. EGN sustained substantial damage.
The United States Federal Aviation Administration (FAA) Helicopter Flying Handbook states that the nose of a helicopter will attempt to weather cock into the relative wind when a tailwind from 120° to 240° is experienced. If sufficient resisting pedal input is not made by the pilot, the helicopter will start a slow, uncommanded turn to either the left or right, depending on the wind direction. If the yaw rate is allowed to develop and the tail of the helicopter moves into this region, the yaw rate can accelerate rapidly. The FAA further stated that, when approaching the downwind portion of a turn, anticipate the helicopter’s tendency to weathercock by applying pedal pressure opposite to the direction of the turn.
On 31 July 2013, a Bell 206B helicopter, registered VH‑SMI, departed Horn Island, Queensland for an aerial filming flight about 5 NM to the north‑east, at the Tuesday Islets. The purpose of the flight was to film a 20 m vessel travelling back and forth along a channel in between the Islets.
After having completed four passes over the vessel, the pilot positioned the helicopter for the next pass. Maintaining 200 ft, the helicopter approached the vessel from behind and to the left. The vessel was travelling into wind. As the helicopter flew abeam the vessel, the pilot initiated a climb and then commenced a right turn to pass in front. At that time, the pilot was monitoring the view finder to ensure that the helicopter’s skids did not impede the film shot.
After having completed the film shot, when at about 450 ft, the helicopter entered an uncommanded yaw right by about 25-30° and started to experience a loss of tail rotor effectiveness (LTE). The helicopter rotation stopped momentarily, but shortly after, it began to yaw right again. Despite the pilot’s attempt to recover the situation, the helicopter continued to yaw right and descend. When below 100 ft, the pilot determined that he was unable to recover, and he prepared for a forced landing onto the water. The emergency flotation system was activated, and the helicopter landed on the water. The occupants received nil injuries.
As a result of this occurrence, the helicopter operator has advised the ATSB that all company pilots will be required to demonstrate their ability to recover from an LTE event during regular flight checks with the Chief Pilot.
Certain operations, such as low speed aerial filming/photography flights, lend themselves to being more at risk to LTE than others. If a helicopter was placed in conditions conducive to LTE, it is crucial that pilots not only recognise the onset of LTE, but respond immediately and appropriately before the situation develops.
On 29 July 2013, about 64 NM (119 km) from Sydney the captain of Bombardier DHC-8-315 (Dash 8) aircraft, registered VH‑SBG and operated by QantasLink on a scheduled flight from Sydney to Wagga Wagga, New South Wales noticed a blank area in the centre of the flight management system (FMS) screen. About 10 minutes later the screen went completely blank and thick, light-grey smoke was observed coming from the unit.
The flight crew commenced the quick reference handbook Fuselage Fire or Smoke checklist, donning oxygen masks and smoke goggles. The crew found communication difficult while wearing their masks and, as a result, removed the masks for the remainder of the flight. The aircraft was diverted to Canberra, Australian Capital Territory. The flight crew were taken to hospital for observation and later released without needing treatment. No injuries were reported by the cabin crew or passengers. The aircraft sustained no other damage.
What the ATSB found
Examination of the FMS unit found that two capacitors failed, resulting in the smoke and failure of the unit. The unit was manufactured in 1997 and, in 1998, the FMS manufacturer introduced a modification to replace those capacitors in all subsequently manufactured units. However, there was no recall or retrofit program for unmodified FMS units already in service.
The ATSB also found that, at the time of the occurrence, the approved QantasLink training did not provide sufficient familiarity to first officers in the use of oxygen masks and smoke goggles. The more-experienced captain’s familiarity with the equipment was enhanced by completion of additional mask and goggles training sessions.
What's been done as a result
In October 2013, as a result of this occurrence, the FMS manufacturer issued a service bulletin for the optional incorporation of different capacitors to unmodified in-service FMS units.
QantasLink undertook a number of safety actions in response to this occurrence. This included installing modified FMS units to all aircraft in its Dash 8 fleet. QantasLink has also implemented a number of improvements to crew training, including improved oxygen mask and smoke goggle training and identifying alternate stowage for the flight deck fire extinguisher.
Safety message
This occurrence highlights the importance of flight crew familiarising themselves with the operation of the onboard emergency equipment. It also reminds crews that inhalation of fumes can have an adverse effect on an individual’s ability to function. Flight crew need to fully consider the implications of removing their emergency breathing equipment when in an environment where smoke and fumes are, or have been, present.
Findings
From the evidence available, the following findings are made with respect to the failure of the flight management system unit and subsequent smoke on the flight deck occurrence involving Bombardier DHC-8-315 aircraft, registered VH-SBG, near Canberra Airport, Australian Capital Territory on 29 July 2013. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
Contributing factors
The flight management system unit failure and observed smoke were the result of a capacitor, which did not meet current design specifications, overheating.
Despite a design upgrade in 1998 for new flight management system units, unmodified units remained in service that had the original capacitors.
At the time of the occurrence, the approved QantasLink training did not provide first officers with sufficient familiarity on the use of the oxygen mask and smoke goggles. This likely contributed to the crew's communication difficulties, including with air traffic control. [Safety issue]
Other factors that increased risk
Despite removing their oxygen masks to improve communication, by doing so the crew increased the risk of impairment or incapacitation as there was still smoke in the cockpit.
The stress associated with the smoke in the cockpit resulted in a high workload for the crew and adversely affected their performance, leading to errors in aircraft management and checklist completion.
Safety analysis
Introduction
The failure of the flight management system (FMS) unit and subsequent smoke in the cockpit led to the flight crew diverting the aircraft to Canberra Airport, Australian Capital Territory. This analysis will examine the failure mode of the FMS unit, the actions of the flight crew, operational issues and organisational factors that had the potential to affect the flight.
Flight management system failure
The failure of the FMS unit was due to the dielectric breakdown and overheating of one of the unit’s capacitors. The FMS manufacturer had reviewed the suitability of the capacitors in the early model FMS units and implemented a design modification to upgrade the capacitors in 1998. This was done through an engineering change order, which was implemented about 12 months after the release to service of the FMS unit installed in VH-SBG.
Despite the availability of this modification, the FMS manufacturer did not have a retrospective fitment program for in‑service units. Such a program could be expected to reduce the likelihood of capacitors overheating and therefore in-flight FMS failures and subsequent fire/smoke occurrences. The manufacturer was unable to provide details of the number of unmodified units currently in service, which made evaluation of the risk of further in‑service failures as a result of this failure mode difficult to determine. However, in Australia, QantasLink commenced an upgrade of their FMS units in February 2014 to meet the new design specification under service bulletin SB10172.XX.()‑34‑3578 Installation of Mod 22 in the UNS-1C+ FMS. This upgrade was completed in June 2014.
Operational factors
Flight crew actions
As would be expected in any emergency situation, the appearance of smoke from the FMS created a level of stress for the flight crew. Their immediate response was to review the Quick Reference Handbook and action the Fuselage Fire or Smoke checklist. The first step was to put oxygen masks on, followed by fitting the smoke goggles before continuing the checklist.
During this time, the crew were interrupted numerous times due to the need to respond to air traffic control (ATC) and calls from QantasLink via radio as the first officer (FO) was reading out the checklist. After each interruption, the checklist was recommenced from the start. However, reports from the crew indicated that communication both between them and with ATC while wearing the oxygen masks was difficult. Consequently, the FO had to repeat the PAN call to ATC multiple times before being understood. This added to the crew’s stress and workload in trying to resolve this difficulty.
Research has shown that, under stressful conditions, the performance of tasks can be affected so that the outcomes are not as planned or in conformance with a procedure (Wickens and Hollands, 2000). The effects of stress on human performance have been characterised as:
Attentional narrowing, where an individual’s attention can concentrate on a single aspect of a task at hand to the detriment of other information cues or task requirements.
Perseveration[9], where an individual perseveres with a given action or plan they have used in the past, even if it is failing to provide a successful solution.
Confirmation bias, where a decision maker, once locked into a hypothesis on the reason behind an event, will be less likely to consider information cues that might support an alternative hypotheses.
The combined influence of those characteristics can contribute to a pattern of convergent thinking or ‘cognitive tunnelling’. This will initially narrow the set of cues processed by the individual to those they perceive as being the most important. As the cues have been viewed to support one hypothesis only, the individual will continue to consider that hypothesis only, and process a restricted range of cues consistent with that set.
The FO’s action to reduce altitude appears based on recognising this requirement from the training in simulated rapid depressurisation procedures. The captain did not recall discussing descending the aircraft with the FO at that time and was not aware that the FO had advised ATC they intended doing so. Consequently, the captain was surprised by the FO’s actions and immediately re-engaged the autopilot.
After the FO attempted to descend the aircraft without a direction to do so from the captain (who was the pilot flying) and, recognising that the FO was anxious, the captain ordered the removal of the oxygen masks. As the smoke goggles and oxygen masks were ‘tangled’ together, both crew members’ masks and goggles remained off for the remainder of the flight.
The captain reported that once the oxygen masks were removed, and better communications established as a result, the FO contacted ATC and determined that Canberra was the closest suitable airport. The crew requested radar vectors for Canberra from ATC as the FMS was no longer working. The captain stated that descent from FL 200 normally required about 60 NM (111 km). In this instance, the aircraft’s proximity to Canberra meant that the crew had to prepare for the descent and landing over a remaining distance of 30 NM (56 km). This resulted in a similar number of tasks being carried out in a reduced period of time.
Workload has been defined as ‘reflecting the interaction between a specific individual and the demands imposed by a particular task. Workload represents the cost incurred by the human operator in achieving a particular level of performance’ (Orlady and Orlady, 1999). A discussion of the effect of workload on the completion of a task requires an understanding of an individual’s strategies for managing tasks.
An individual has a finite set of mental resources they can assign to a set of tasks (for example, performing a take-off). These resources can change given the individual’s experience and training and the level of stress and fatigue being experienced at the time. An individual will seek to perform at an optimum workload by balancing the demands of their tasks. When workload is low, the individual will seek to take on tasks. When workload becomes excessive the individual must, as a result of their finite mental resources, shed tasks.
An individual can shed tasks in an efficient manner by eliminating performance on low priority tasks. Alternately, they can shed tasks in an inefficient fashion by abandoning tasks that should be performed. Tasks make demands on an individual’s resources through the mental and physical requirements of the task, temporal demands and the wish to achieve performance goals (Hart and Staveland, 1988 and Lee and Liu, 2003).
The inherent stress of the event, together with the associated high workload led to the crew making errors in both aircraft management and checklist completion. This included not completing the ‘transition drill’ when passing 10,000 ft on descent, which includes checking, and changing as required, the fuel system, exterior lights, pressurisation and ice protection. These drills were conducted at 8,000 ft prior to conducting the approach checklist.
As part of the initial conduct of the checklist, the FO retrieved the fire extinguisher and handed it to the captain. However, as the FMS was still an intact, sealed unit, there was no way for the extinguisher to be used on the FMS. The captain’s decision to place the unused fire extinguisher on the floor adjacent to the seat may have been influenced by the impracticality of re-securing the fire extinguisher in the normal stowage location. Consequently, the fire extinguisher presented a potential projectile hazard within the flight deck.
The captain stated that passing about FL 120 the FO was requested to continue with the Fuselage Fire or Smoke checklist. The captain reported a number of interruptions at about this time to the extent that the FO was unable to recommence reading out the checklist actions until passing about 8,000 ft. These interruptions included the previously mentioned numerous ATC calls and from QantasLink ground personnel, enquiries from cabin crew and the need to make a public address announcement to the passengers.
When the Fuselage Fire or Smoke checklist was recommenced just prior to 8,000 ft, the captain misheard the cessation note as read out by the FO. This note was designed to highlight the need to prepare for and manage an immediate landing if the source of fire or smoke could not be identified and that to do so, the checklist could be terminated. It is likely that when this note was read out, the proximity to Canberra and the need to conduct the approach and landing checklist reinforced the captain’s decision to terminate the checklist at this point, despite it applying to an unknown source of fire.
In both the crew’s initial action to carry out the Fuselage Fire or Smoke checklist, and its review at 8,000 ft, circumstances prevented the completion of the Known Source of Fire or Smoke section. In both cases, the action to open the ‘forward outflow valve’ was missed. However, the associated note for this action specified its completion ‘if necessary to assist in removal of smoke’. Given the crew reported the smoke had dissipated by the time the approach was commenced into Canberra, even if this step was reached, it is unlikely it would have needed to be actioned.
Emergency equipment training
All QantasLink flight crew underwent a rapid depressurisation scenario simulator session as part of their Dash 8 endorsement training. Additional rapid depressurisation training was undertaken as part of command upgrade for captains. The crew were required to undertake emergency procedures training annually but this was primarily theory based.
QantasLink provided limited training in the use of smoke goggles and no training on using the goggles in combination with the oxygen mask. Both crew confirmed that the only training provided in the use of oxygen masks was during a rapid depressurisation scenario, which was reported not frequently practiced.
Resolution of emergency situations relies on effective decision making by crews given the information available. Emergency procedure training provides the opportunity for crews to familiarise themselves with those procedures for use in times of high stress and workload. In this instance, the lack of prior exposure to wearing smoke goggles in a training environment increased the risk of reduced flight crew performance in response to the occurrence.
Both crew reported being confident in the use of the oxygen mask. However, their infrequent practice using the mask microphone to communicate increased the risk of communication breakdown as experienced during this occurrence.
The communication difficulties experienced by the crew in this occurrence contributed to their decision to remove their oxygen masks. Despite addressing the problem of communication, it also resulted in their re-exposure to potentially harmful smoke/fumes. While the crew reported no adverse effects from this exposure, it did increase the risk of crew impairment/incapacitation.
At about 1130 Eastern Standard Time[1] on 29 July 2013, the crew of Bombardier DHC‑8‑315 (Dash 8) aircraft, registered VH-SBG and operated by QantasLink, departed Sydney on a scheduled flight to Wagga Wagga, New South Wales. On board were two flight crew, two cabin crew and 49 passengers. The captain was the pilot flying,[2] and the first officer (FO) was the pilot monitoring.
About 64 NM (119 km) from Sydney, the captain noticed a 30 mm diameter ‘blank’ area in the centre of the flight management system (FMS) screen. The crew were still within radio contact range with QantasLink ‘maintenance watch’ so technical advice was sought. While the captain was talking to maintenance watch, the blank area disappeared and normal FMS function resumed. On receiving that information, maintenance watch personnel advised the crew that it was safe for the flight to continue to Wagga Wagga.
About 10 minutes later, the crew observed the FMS screen go completely blank, with thick, light‑grey smoke coming from the unit. At that time, the aircraft was out of radio range with maintenance watch so further advice could not be obtained. The captain reported that when the FMS screen went blank, it emitted a solid stream of light‑grey smoke for about 5 minutes. The smoke reduced to puffs of about 30-second intervals, before finally stopping about 3 minutes before landing.
There were no warnings or alerts while the solid stream of smoke was visible. The captain reported that immediately preceding the loss of the FMS screen, the presentation of navigation information was degraded.
At the first sign of smoke, the FO removed the Quick Reference Handbook from its stowage and commenced reading out the checklist action items for the non‑normal/emergency procedure Fuselage Fire or Smoke (appendix A). This resulted in the crew donning their oxygen masks and smoke goggles. The FO also removed the portable fire extinguisher from its stowage at the rear of the centre console and passed it to the captain.
The captain could not see anywhere in the FMS unit into which to discharge the extinguishing agent, so the fire extinguisher was placed on the floor adjacent to the captain’s seat.
Both flight crew reported communication was difficult while using the oxygen masks. This was due to an initial incorrect intercom setting. It was further exacerbated by the need to switch the mask microphone OFF between talking. The FO also reported that the communication difficulties resulted in an increased level of anxiety.
The captain asked the FO to contact Melbourne Centre air traffic control (ATC) to report the situation. The FO, believing the captain wanted to descend from their current cruise altitude of flight level (FL) 200[3], declared a PAN[4] and requested a descent. The flight crew reported that ATC did not initially understand the call, so the FO repeated the broadcast a number of times until ATC acknowledged the PAN. Noting the aircraft was maintaining the cruise level, the FO disconnected the autopilot and initiated a descent.
The captain did not recall discussing the need to descend and did not intend doing so at that time. As a result, when the FO initiated the descent, the captain re-engaged the autopilot, pulled back on the control column and declared having control of the aircraft. Both crew reported the FO disconnected the autopilot a second time in similar circumstances, although data from the flight recorder did not show this. The captain again re-engaged the autopilot and repeated ‘my controls’ so the FO would know the captain had taken control of the aircraft. Due to the ongoing communication issues, the captain instructed the FO to remove their mask to improve communication between the crew. Both crew removed their masks and goggles to discuss the situation.
As the FMS was no longer functioning, the FO asked ATC for the nearest airport and was told Canberra was 30 NM (56 km) away. The crew advised ATC they would divert to Canberra and requested and received radar vectors for approach to Canberra Airport, Australian Capital Territory.
The captain briefed the cabin crew and made a public address to alert the passengers of the intention to divert to Canberra with a landing in about 10 minutes. At that time, the smoke in the flight deck had reduced to about 50 per cent of its original rate. As neither crew felt they were experiencing ill effects from the smoke, they did not refit their masks or goggles.
During the descent, the flight crew returned to the Quick Reference Handbook checklist items but misread a note that resulted in them ceasing the Fuselage Fire or Smoke checklist to allow commencement of the normal landing checks. The smoke had almost cleared from the flight deck by the time the aircraft commenced the approach. After touchdown, the aircraft was turned onto taxiway Golf where it was stopped and a precautionary disembarkation of the passengers and crew carried out.
The flight crew had flown without wearing their masks and smoke goggles for about 10‑15 minutes. As a result, they were taken by ambulance to a local hospital for monitoring, before being released some hours later.
No passengers or cabin crew reported injuries or ill effects from the smoke. There was no other damage to the aircraft.
The sources of information during the investigation included the:
flight crew of VH-SBG
QantasLink
Bombardier Inc
flight management system manufacturer
United States National Transportation Safety Board
United Kingdom Air Accidents Investigation Branch
Transportation Safety Board of Canada.
References
Hart, SG & Staveland, LE 1988, ‘Development of NASA-TLX (Task Load Index): Results of empirical and theoretical research’, In PA Hancock & N Meshkati (Eds.), Human Mental Workload. North Holland Press, Amsterdam.
Lee, YH & Liu, BS 2003, ‘Inflight workload assessment: Comparison of subjective and physiological measurements’, Aviation, Space, and Environmental Medicine, vol.74, pp. 1078‑1084.
Orlady, HW & Orlady, LM 1999, Human factors in multi-crew flight operations. Ashgate, Aldershot, p. 203.
Wickens, CD & Hollands, JG 2000, Engineering psychology and human performance. 3rd Edition. Prentice Hall, New Jersey.
Submissions
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the ATSB may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the crew of VH‑SBG, QantasLink, the Civil Aviation Safety Authority, Bombardier Inc, the flight management system manufacturer, United States National Transportation Safety Board and the Transportation Safety Board of Canada.
Submissions were received from the captain of VH-SBG, QantasLink and the Civil Aviation Safety Authority. The submissions were reviewed and where considered appropriate, the text of the draft report was amended accordingly.
Context
Personnel information
Captain
The captain commenced flying in 2002, held an Air Transport Pilot (Aeroplane) Licence and had a current Class 1 Medical Certificate. Their total aeronautical experience was about 3,525 hours, with about 2,000 hours on the Dash 8 aircraft type.
During the previous 7 days, the captain was on duty for 4 days, on stand-by (without call-out) for 1 day and then had 2 days off duty. The previous duty concluded at about 2255 on 25 July 2013. The captain reported being on duty for 3 hours at the time of the occurrence, having been awake for 6 hours. The captain did not report any fatigue‑related concerns or any illness leading up to the occurrence.
First officer
The first officer (FO) held a Commercial Pilot (Aeroplane) Licence and had a current Class 1 Medical Certificate. They had a total aeronautical experience of about 2,531 flying hours.
During the previous 7 days, the FO had 1 day on duty, 2 days off duty, and then 4 days on duty. The previous duty concluded at 1531 on 28 July 2013. The FO reported being awake for 4 hours and on duty for 2 hours at the time of the occurrence and did not report any fatigue‑related concerns or any illness at that time.
Emergency procedures training
Oxygen masks and goggles
As part of endorsement training, crew were required to conduct a rapid depressurisation simulator session. This session required the rapid donning and ongoing use of oxygen masks and:
included making a single radio transmission to air traffic control
included crew-to-crew communication
did not involve wearing the smoke goggles (as they were not required by the training scenario)
included the initiation of an emergency descent with the engines at the flight idle power setting
included the initiation of an emergency descent at the maximum operating airspeed.
Further rapid depressurisation sessions were conducted as part of command upgrade or other recurrent training. QantasLink also provided annual emergency procedures training. This training was theory‑based and covered the use of the emergency equipment including the oxygen masks, but not wearing, or communicating while wearing the mask. The emergency procedures training did not incorporate wearing the smoke goggles.
Training records indicated that since commencing employment with QantasLink in 2008, the captain had undertaken three rapid depressurisation simulator sessions. The most recent session was in 2011 on the DHC-8-402 aircraft that was fitted with a different type of oxygen mask. The captain had also undergone five emergency procedures training sessions. The captain reported not having previously worn the oxygen mask or smoke goggles during a flight.
The FO reported completing a rapid depressurisation simulator session about 18 months prior to the occurrence. That was the only occasion that the FO had worn the oxygen mask prior to the occurrence flight. Training records indicated that the FO completed three emergency procedures training sessions.
The FO advised that, during the initial simulator session, only one radio transmission was made while wearing the mask and that after the aircraft had descended to the safe altitude, the oxygen mask was able to be removed. The FO had not worn the smoke goggles prior to the occurrence flight.
Portable fire extinguisher
Neither crew member had used the portable fire extinguisher previously. As part of QantasLink’s investigation into the occurrence, a simulation was conducted where flight crew had to remove and then replace the portable fire extinguisher in its stowage. That simulation revealed that while seated, neither crew could refit the fire extinguisher in its stowage and secure it correctly. The aircraft manufacturer’s Fuselage Fire or Smoke checklist, which had been adopted by QantasLink, included a step to extinguish any fire with the portable extinguisher. No specific instruction was provided in the checklist regarding the stowage of an empty or unused extinguisher.
Aircraft information
Flight management system
General
The flight management system (FMS) was a fully integrated navigation management system designed to provide the crew with computer-based flight planning, fuel management and centralised control for the aircraft's navigation sensors. The aircraft incorporated a single FMS unit located on the left side of the centre console, adjacent to the captain’s seat (Figure 1).
Examination of the failed flight management system unit
The FMS unit was sent to the manufacturer for examination. That examination found that there had been a dielectric breakdown[5] of a capacitor, which then acted as a low resistance load. This resulted in self-heating that led to the failure of that capacitor, of an adjacent capacitor and of a diode. Other signs of excessive heating were visible on a number of circuit boards, including the display circuit board and connector ribbons within the unit.
In November 1998, because of previous unit failures, the manufacturer released an engineering change order to replace the capacitors affected in this occurrence with components of a higher rating. That modification applied to newly-built units only, and was not retrospectively applied to existing units. As a result, a number of unmodified units remained in service globally.
The circuit board containing the failed capacitors and diode was in original condition and had not been modified. The capacitors were of a different rating, which did not meet the manufacturer’s post-1998 specifications.
Figure 1: DHC-8-315 instrument panel showing the location of the FMS on the captain’s side of the centre console (detailed view of the FMS at inset)
Source: QantasLink
FMS service history
The failed FMS unit, part number 10172-41-111, serial number 1590, was manufactured in 1997 and was acquired from the manufacturer as an overhauled unit by QantasLink in April 2010.
A review of the unit’s service history revealed that it entered service in November 2010 and was removed 438 hours later due to the screen going blank. In May 2011, the unit was returned to service and removed 2,808 hours later due to a backlight problem on the display panel. The unit was returned to service in March 2013 and was removed 671 hours later due to this occurrence. Following this occurrence, the unit was returned to service in August 2013 but was again removed 141 hours later due to the display being permanently set to full brightness.
Flight crew emergency oxygen system
The aircraft flight deck contained a fixed emergency oxygen system comprising of captain and FO half-face (oronasal) masks. The masks were suspended on quick-release hangers from the ceiling panel above and behind each crew seat. Each mask contained a microphone and a regulator that supplied normal or 100 per cent oxygen, either on demand or as continuous flow.
Communication using the mask microphone required the user to select the intercom switch on the communications panel at the rear of the centre console from BOOM (headset microphone) to MASK (mask microphone). The press-to-talk switches on the control columns were then required to be toggled ON when the individuals were speaking and OFF when finished. This was to prevent distraction for the other crew member from breathing noises associated with a live microphone.
During the first flight of the day, flight crew were required to check the serviceability of the emergency oxygen equipment. This included:
a visual inspection of the condition of the oxygen mask
checking the mask is connected to the oxygen supply
testing for continuous flow of oxygen
confirmation that the ‘100%/Dilute’ selector is in the 100 per cent position
checking the operation of the oxygen mask microphone.
The fitment of the smoke goggles was not routinely carried out as part of that check.
Operational factors
QantasLink DHC-8 Fuselage Fire or Smoke checklist
The aircraft manufacturer’s Quick Reference Handbook (QRH) was used by QantasLink. The QRH contains information derived from the Approved Airplane Flight Manual. It is used by flight crew to confirm that respective procedures have been performed correctly.
The QRH contains checklists for Normal and Non-normal/Emergency situations. The Non‑normal/Emergency checklists contain only those items and procedures that differ from those for normal aircraft operation.
The Fuselage Fire or Smoke checklist was divided into four sections (appendix A):
‘boxed’ action items (the recall/memory action items) and landing considerations
Known Source of Fire or Smoke action items
Unknown Source of Fire or Smoke action items
Source of Fire or Smoke cannot be identified action items.
The boxed action items that were applicable on the occurrence flight are shown in Figure 2.
Figure 2: Dash 8 Quick Reference Handbook extract showing the procedural action items in the case of a fire or smoke in the cockpit from a known source (from the FMS in this case)
Source: QantasLink
The Known Source of Fire or Smoke section of the checklist did not contain action items for removal of electrical power from affected systems, such as the FMS. The aircraft manufacturer advised the ATSB that the checklist relied on the flight crew isolating, as required, affected equipment from the aircraft’s electrical system through the operation of any integrated power switch. Reconfiguration of the aircraft’s electrical system in response to a fire or smoke situation of unknown origin was contained in other sections of the checklist (appendix A).
Flight crew actions
Quick reference handbook
On observing the smoke, the FO removed the QRH from its location at the rear of the centre console, located the Fuselage Fire or Smoke checklist, and commenced reading out the recall/memory action items. After donning their masks and goggles, the recirculation fans were selected to OFF. The FO went to select the emergency lights ON but was told to leave them off by the captain, who did not want to alarm the passengers or be distracted with cabin crew enquiries.
While actioning the checklist, the crew were interrupted multiple times with calls from air traffic control and QantasLink. Each time the crew were interrupted, they recommenced the checklist at the start to ensure all actions were conducted.
The crew briefly returned to the Fuselage Fire or Smoke checklist at about 8,000 ft. The FO read out the note that followed the recall actions. This allowed for the discontinuation of the procedures in response to an unknown source of smoke or fire prior to their completion. This was to facilitate preparations for an immediate landing. However, this was misheard by the captain as being applicable to their situation of a known source of fire or smoke – the FMS.
As a result, the checklist was terminated at that point. This meant that the forward outflow valve was never opened, which would have, if activated, assisted in the removal of the smoke from the flight deck.[6]
At the time the Fuselage Fire or Smoke checklist was inadvertently stopped, the normal approach and landing checklist became the priority, so the Fuselage Fire or Smoke checklist was not returned to, nor completed.
Oxygen masks
Both crew reported communication difficulty while wearing their oxygen masks. This difficulty related to both inter‑crew communication and communication between the FO and air traffic control. As a result of this difficulty, and the FO disengaging the autopilot, the captain directed the removal of oxygen masks. The oxygen masks were not worn for the remainder of the flight.
Neither crew reported suffering ill effects from the smoke and were subsequently medically cleared after landing.
Tests and research
Fume and smoke hazards
There has been extensive research into the effects of fumes and smoke in aircraft. The United States Federal Aviation Administration pilot safety brochure Smoke toxicity[7] highlights that smoke inhalation should be recognised as a very real danger. It also states that ‘smoke gas levels do not need to be lethal to seriously impair a pilot’s performance’.
Analysis of fumes and smoke events in Australian aviation from 2008 to 2012: A joint initiative of Australian aviation safety agencies,[8] found that over 1,000 fumes/smoke events were reported to the ATSB and the Civil Aviation Safety Authority in the period 2008–2012. From the data gathered, it was apparent that the most common source of fumes/smoke was the malfunction or failure of electrical systems and auxiliary power units.
The ATSB research report also identified a significant increase in reported fumes/smoke events from mid-2011, which was independent of the growth in flying activity. The report highlights that fumes relating to electrical failures may have the potential to pose a health risk through eye/skin irritation, difficulty in breathing, incapacitation or illness. This was especially the case if the fumes were associated with particulates (smoke) or fire. However, while the potential for a serious outcome is more likely from an occurrence involving smoke, the research also found that ‘very few led to a serious consequential event (such as a forced landing) or outcome such as fire or crew incapacitation’.
Other occurrences
Australia
QantasLink advised there had been a total of five FMS fire/smoke events within their fleet of Dash 8 aircraft during the period 2004–2013. One other Dash 8 operator in Australia had experienced an FMS smoke event, which occurred in 2011. The remaining Australian Dash 8 operators reported they had not experienced any FMS fire/smoke events within their fleets.
A review of the ATSB occurrence database confirmed that six Dash 8 FMS fire/smoke events were reported between 2007 and 2013 across all Australian Dash 8 operators. In one such event on 24 March 2007, while conducting a scheduled flight from Cairns to Horn Island, Queensland, the flight crew of Dash 8 aircraft, registered VH-SBV, reported the aircraft’s FMS unit ceased operating. About 60 seconds later, smoke was observed emanating from the FMS unit. As a precaution, the flight crew donned their oxygen masks and smoke goggles. After completing the action items in the Fuselage Fire or Smoke checklist, the captain ‘pulled’ (opened) the circuit breaker for the FMS to isolate electrical power. That action, while not in accordance with procedures or the checklist, resulted in the smoke ceasing. The opening of the forward outflow valve, in accordance with the checklist, resulted in the rapid removal of smoke from the flight deck.
Worldwide
The ATSB also reviewed a number of international safety databases. While that review found numerous reported smoke/fire events for the Dash 8 aircraft, it did not identify any additional FMS‑related occurrences.
The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The ATSB expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
The initial public version of these safety issues and actions are repeated separately on the ATSB website to facilitate monitoring by interested parties. Where relevant the safety issues and actions will be updated on the ATSB website as information comes to hand.
Emergency oxygen mask and smoke goggles training
At the time of the occurrence, the approved QantasLink training did not provide first officers with sufficient familiarity on the use of the oxygen mask and smoke goggles. This likely contributed to the crew's communication difficulties, including with air traffic control.
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence.
QantasLink
QantasLink has undertaken the following additional safety actions:
Amended the Aircrew Emergency Procedures Manual to include post‑precautionary evacuation procedures and post‑incident debriefings to all flight and cabin crew. This includes in crew emergency procedures training.
Completed a program in June 2014 to modify all QantasLink flight management system units to incorporate 22uF/25V capacitors in accordance with service bulletin SB10172.XX.()-34-3578 Installation of Mod 22 in the UNS‑1C+ FMS.
Amended their emergency procedures training to include alternative stowage of fire extinguishers in the flight deck.
Appendices
Appendix A – DHC-8-315 Quick reference handbook
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 25 July 2013, Pacific National locomotive 8122 was undertaking shunt operations in the Melbourne Freight Terminal (MFT) and onto areas of the main line controlled by signal DYN150. During one of the shunt movements, the locomotive stopped slightly forward of signal DYN150, in a position where indication on the signal was not visible to the driver. The signalling system should have detected the locomotive still occupied the track section forward of the signal, but in this instance, the system registered the train had cleared the section. The system then allowed points 143 ahead of signal DYN150 to change position for the passage of another train.
Unaware of the change in points 143, the driver continued with shunt operations by moving the locomotive forward. A Signal Passed at Danger (SPAD) alarm was generated and displayed to the Network Control Officer (NCO) who then contacted the MFT shunt planner. Meanwhile, the driver continued forward before stopping just after the lead bogie of locomotive 8122 had run through points 143, which were now set in the incorrect position for the move being undertaken.
Unaware that the points had been run through, the driver then reversed direction for the next shunt movement. This manoeuvre resulted in the lead bogie of the locomotive diverging onto a different track, causing all wheels of the locomotive and one bogie of the first wagon coupled to the locomotive to derail. At no point in time did a conversation occur between the NCO and the locomotive driver, and almost 30 minutes passed before the NCO and the shunt planner became aware of (and confirmed) the derailment at points 143.
What the ATSB found
The ATSB found that the location of the insulated rail joints adjacent signal DYN150 were incorrect. Consequently, the track section past the signal could be detected as unoccupied, even though the locomotive (and drivers cab) was positioned past the signal.
The ATSB also found that procedures specific to shunting in and about the MFT had not been implemented in this instance. It was evident that communication in response to the preceding SPAD alarm had been ineffective – allowing shunt operations to continue and locomotive 8122 to derail. Furthermore, significant time passed before the network control officer and the MFT shunt planner became fully aware of the derailment.
What's been done as a result
The Australian Rail Track Corporation initiated actions to verify (within Victoria) the position of insulated joints relative to the respective signals and develop a prioritised remediation plan for any non-conforming arrangements.
Pacific National and the Australian Rail Track Corporation have taken action to ensure all parties adhere to the documented process for shunting in and about the MFT. In addition, Pacific National has advised their drivers and shunt planners that communication regarding any issues related to the shunting movements must occur directly between the network controller and the locomotive driver.
Safety message
Rail transport operators must ensure that local communication practices are not substituted for, or do not influence required communication protocols in an emergency.
Context
Location
The Dynon area was a freight hub in Melbourne, Victoria with freight terminals servicing the Port of Melbourne, Appleton Dock, and Swanson Dock. The track from Footscray approached from the west; entering the Dynon area at Sims Street Junction, where a track branched to North Dynon Junction then on towards South Kensington. The main rail line continued east towards South Dynon Junction and the MFT.
The derailment occurred at points 143, situated at the 4.429 km mark[8] at the eastern end of Sims Street Junction. The distance from the points to signal DYN150 was about 177 metres. The connection between the ‘X track’ to South Kensington and the main line towards the MFT occurs at points 143 (Figure 3).
Figure 3: View of South Dynon Junction track layout including the main line, ‘X’ track and points 143
Source: Google Earth, annotated by ATSB.
Network control
The Australian Rail Track Corporation (ARTC) managed the main line, ‘X track’ and associated signalling infrastructure involved in the derailment. The signalling infrastructure incorporated track circuits for rail vehicle detection and remotely controlling line-side signals and point machines.
The Phoenix control system, located at the Mile End control centre in South Australia, provided the remote control functionality. The system was a non-vital centralised traffic control system[9][10]monitored and operated by the NCO. The system also provided status indications for the signalling equipment supporting the monitoring and management of train movements in real time.
Train and train crew
Train information
The locomotive involved in the occurrence was an 81-class diesel electric with an overall length of about 21.2 m. The shunt movements involved the remarshalling of six (multiple-platform) wagons with a combined overall consist length of about 660 m. There was no evidence that any mechanical defects were affecting the locomotive’s operation.
The locomotive 8122 was fitted with a Hasler data logger; an electro-mechanical strip chart recorder. The logger recorded data such as time, speed, throttle position, vigilance control and brake pipe pressure, on a waxed paper tape.
Locomotive data loggers provide essential evidence in verifying the sequence of events during an investigation. In this case, the tape recovered from locomotive 8122 was damaged and in very poor condition when provided to the ATSB. The damage to the tape was near the data critical to the derailment sequence and prevented the accurate examination and analysis of events. Consequently, the data logger information could not verify the position of locomotive 8122 relative to signal DYN150 before it moved off and ran through points 143.
Train crew
The driver of locomotive 8122 had worked in the rail industry for about 8 years and had been qualified as a driver for 5 years. The driver’s route competency included a number of main line routes and local areas – including the MFT. The driver was familiar with the shunting operations at the MFT.
There was no evidence to suggest impairment of the driver’s performance from fatigue or other factors. Similarly, the driver’s health assessment records met the required National Standard for Health of Rail Safety Workers. Following the derailment, the driver underwent a routine drug and alcohol-screening test, which returned a negative result. There was no evidence to suggest that any medical or physiological factors affected the driver’s performance leading up to or during the derailment.
Freight terminal operations
There were four Pacific National facilities managed at this locality. These included the Melbourne Freight Terminal (MFT), the Melbourne Operations Terminal, the Locomotive Provisioning Centre and the Wagon Maintenance Centre. The facilities all had direct rail connections to the ARTC network.
The MFT contained multiple shunt roads used to load, unload and marshal wagons. The shunt roads within the terminal were not long enough to wholly accommodate the average train length, and as such, longer trains required shunting out of the MFT and onto the main line.
A shunt planner located in the terminal ‘tower’ coordinated shunt movements within the MFT. A shunter was also positioned on the ground (usually towards the rear of the train consist). The shunter operated the yard points and directed the locomotive driver on where to position the train for the coupling of wagons on the required shunt roads. Where a shunt movement was required to exit the terminal and move onto the main line, the shunt planner contacted the NCO to facilitate the clearing of the relevant main line signals.
Communication
The means of communication between the MFT shunt planner and the NCO was by way of landline telephone. The MFT shunt planner also had an Ultra High Frequency (UHF) base radio for communication with the terminal shunters and the locomotive drivers.
The locomotive 8122 was fitted with the AWARE[11] train radio system, providing the driver with direct voice communication to the relevant train control, the MFT shunt planner, and the shunter on the ground. Prior to obtaining access onto the ARTC track, the driver had logged access to the system using the prescribed code. The radio communication system was serviceable at the time of the derailment.
Operational rules
Section 12 of the ARTC Code of Practice for the Victorian Main Line Network (TA20)documents the rules for shunting of freight wagons on the ARTC main line, including the Dynon area. While generally under the instruction of a shunter, a train driver must also comply with the network’s fixed signals. That is, it is not permissible to shunt vehicles past a signal displaying a stop (red) indication, even if the shunter directs the movement.
If there is a requirement for a shunt movement to pass a signal, a route must be authorised by the NCO. A route is defined as ‘a section of track between one signal and the next, along which an authorised movement is to be made’[12].
Railway signalling systems usually facilitate single direction train movements from one signal to the next, so it is not normal practice for trains to change direction or divert from the original authorised route. Short shunting is a term commonly used to describe a diversion from an authorised route. The ARTC rules provide further clarification regarding the term short shunting:
`Short Shunting' is defined as a train movement whereby the train does not complete the full signalled route, in order to take an alternative route at a midway point.
Signalling in track circuited areas is generally designed directionally, so that when the rear of a train clears the fouling point, a cross movement can be performed behind that train, even though the rear of that train may not have cleared the opposing Fixed Signal.
A shunting movement must complete the full signalled movement prior to reversing the direction of the train in order to take an alternative route.
`Short Shunting' is not permitted.
A shunting movement may reverse direction within a set route, provided the integrity of the route is not compromised (i.e.: the route is not altered whilst the train is in between the controlling Signals).
In this instance, the authority of the controlling Signaller must first be obtained.
It is clear from the rule that diverting from the authorised route is short shunting and thus not permitted at any time. However, the rule also provides clarification regarding the permitted reversal of direction within an authorised route. That is, as there is no alteration to the route and only a reversal of direction, the movement is not classified as short shunting and is permitted so long as authority is provided.
In this case, the shunting operation undertaken by locomotive 8122 required a series of movements involving various shunt roads in the MFT and movement out onto the ARTC mainline via signal DYN150. The methodologies employed were accepted and commonly-practiced procedures for shunting at the MFT. At the time when locomotive 8122 needed to pass signal DYN150, the shunt planner requested authority from the NCO for shunt operations to move out past the signal. The NCO provided authority by setting a route between signal DYN150 and signal MGL57 (local line at Footscray).
When signal DYN150 cleared, shunt operations continued within the route set between signals DYN150 and MGL57. In conjunction with the instructions given by the shunter located on the ground in the MFT, the driver of locomotive 8122 followed the signalled route onto the main line. At no stage did the driver communicate directly with the NCO.
As noted previously, shunt movements were permitted to reverse direction so long as the route (between the two signals) could not be altered; that is, while the tracks between the signals remained occupied. If the entire train and locomotive had moved back behind the signal (clear of the track circuits), movements within the route would be considered complete and the driver would again need to abide by the relevant signal indication. Should the shunting operation need further forward movement and occupancy of the track ahead of the signal, authority from the NCO would once again be required.
These actions were all consistent with the ARTC rules. Authority was obtained to shunt within the route set between signals DYN150 and MGL57; including reversal of direction as was common practise at the MFT. There was no intention by the NCO to compromise (or alter) the route set between signal DYN150 and signal MGL57.
Operational procedures
ARTC Standing Train Notices provide notice of temporary or permanent alterations to the ARTC network. In October 2009, the ARTC issued notice (1983/2009), providing instructions related to shunting movements at the MFT. The notice stated:
As part of shunting operations at the Pacific National Melbourne Freight Terminal, a train or locomotive movement may need to shunt onto the ARTC main line outside either end of the terminal within specified limits.
PN must clearly outline the limits and moves required for the planned shunt to the ARTC Melbourne Metro Train Controller.
Before clearing the relevant signal for the shunt movement, the Train Controller must:
* Block relevant motor operated points that the movement is to traverse as required.
The Train Controller must maintain point blocking until the train or loco has completed the shunt and PN has advised that the movement is completely behind a controlled signal.
Point blocking is a facility used to prevent the operation of the points. The procedure defined in the notice provided an additional control measure to ensure the integrity of the authorised route and prevent short shunting. That is, all points that may provide an opportunity to alter the route are prevented from operating.
In this case, the PN shunt planner requested authority from the NCO for shunt operations to move out past signal DYN150. The NCO provided that authority by setting a route between signal DYN150 and signal MGL57 (local line at Footscray), but did not block points 143.
The investigation found that the driver of locomotive 8122 initially passed signal DYN150, which was displaying a proceed indication, with the intention of conducting a number of shunt movements. Shunting included reversing direction and pushing back towards the MFT. Recorded signal data indicated that during the shunt movement, the track section ahead of DYN150 registered being clear of any occupancy. This condition implied that locomotive 8122 had moved back behind DYN150. As the signal interlocking system now registered the route from DYN150 as complete, the system automatically operated points 143 to set the stored route for train 9794 from Footscray.
From the driver’s recollection, the locomotive had pushed back to a point where it was adjacent signal DYN150, but had not returned behind DYN150 at any time during shunting. As such, there was no trigger for the driver to notify the NCO before moving forward. When again requested by the shunter to move forward, the driver continued shunting as though the route from DYN150 was still available for shunt operations.
As the signalling system had previously registered the route from DYN150 had cleared, the subsequent occupation of the tracks beyond the (red) signal resulted in the NCO receiving a SPAD alarm.
From the evidence available, the following findings are made with respect to the derailment of locomotive 8122 at South Dynon Junction, West Melbourne, Victoria, on 25 July 2013. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Safety issues, or system problems, are highlighted in bold to emphasise their importance. A safety issue is an event or condition that increases safety risk and (a) can reasonably be regarded as having the potential to adversely affect the safety of future operations, and (b) is a characteristic of an organisation or a system, rather than a characteristic of a specific individual, or characteristic of an operating environment at a specific point in time.
Contributing factors
The driver, shunt planner and Network Control Officer did not implement the procedures documented in ARTC Standing Train Notice 1983/2009.
The placement of the insulated rail joints adjacent to signal DYN150 was not in accordance with the ARTC engineering procedure ESC-07-01. [Safety issue]
The Network Control Officer did not contact the driver of locomotive 8122 following receipt of the SPAD alarm.
The driver of locomotive 8122 was unaware that points 143 were set incorrectly for the passage of the locomotive.
The practice of using a third party (the shunt planner) to facilitate communication between Network Control Officers and train drivers at the Melbourne Freight Terminal preventedan effective response to the emergency. [Safety issue]
Other factors that increased risk
The driver of locomotive 8122 did not immediately report the derailment to the Network Control Officer.
Other findings
The data log tape from locomotive 8122 was damaged and in very poor condition when provided to the ATSB, so could not be used to verify the sequence of events.
Safety analysis
From the ATSB’s investigations and examination of recorded signalling data, it was evident that there had been a disparity between the driver’s observations and the indications displayed on the Phoenix signalling system, with respect to the relative position of locomotive 8122 and signal DYN150.
The following analysis examines the possibility that the integrity of the route set from DYN150 (for shunting) was compromised, resulting in the NCO receiving a SPAD alarm, the operation of points 143, and the subsequent derailment of locomotive 8122. The actions taken in response to the SPAD alarm and subsequent derailment are also examined.
Track infrastructure
The signalling system relied on track circuits to detect the location of rail vehicles. In simple terms, a track circuit uses the rails as electrical conductors to allow a power supply to energise a relay. Rail vehicle wheels and axles electrically short-circuit the two rails, which prevents energising of the relay, thereby detecting the presence of the rail vehicle. Insulated rail joints[13] (IRJs) provide electrical isolation between consecutive track circuits while maintaining the structural integrity of the rail for train movements.
To ensure the position of a rail vehicle is detected accurately with respect to the position of fixed line-side signals, it is essential that the IRJs are appropriately located – usually immediately adjacent the signal.
In this case, an examination of the track infrastructure for signal DYN150 found the IRJs were located about 4.8 m ahead of the signal’s physical position (Figure 4). This was non-compliant with the ARTC procedure[14], which specified the following requirement:
Ideally the insulated rail joints shall be located directly in line with signal to which they apply and no more than 2 m past the signal.
ARTC inspection records from January 2009 listed the position of the signal relative to the IRJ as being correct. There was no record of any significant changes to the infrastructure associated with signal DYN150 between the 2009 inspection and the derailment. The ARTC had no record of the reasons or considerations behind the installation of the IRJs 4.8 m past signal DYN150.
Figure 4: Schematic of rail vehicle axle, track circuit and signal displaying stop indication
Source: ATSB.
Track circuits
Track circuits do not detect a transition of occupancy until the lead wheelset of a rail vehicle has traversed the IRJs. If the IRJs are positioned ahead of a signal, the front of a rail vehicle may already be past the signal before its lead wheelset crosses the IRJs. Conversely, a movement in the opposite direction will be detected clear of the track circuit even though the rear of the train still occupies the track ahead of the signal.
Following this incident, an exemplar locomotive was placed adjacent to signal DYN150, in a position where the lead wheels of the front bogie were immediately behind the IRJs (Figure 5) and not detected by the track circuit located ahead of the signal. The position was consistent with the driver’s recollection of locomotive 8122 before it moved towards points 143 and subsequently derailed. In this position, it was evident that a driver in the locomotive cab would not be able to observe the aspect of signal DYN150.
Figure 5: Exemplar locomotive near signal DYN150 and IRJ’s
Source: Pacific National with annotation by ATSB.
While there was insufficient evidence to discount the possibility that locomotive 8122 actually had pushed back behind signal DYN150, it was clear that the infrastructure configuration could permit a scenario whereby a locomotive driver may remain unaware that the expected route from signal DYN150 had not been maintained during shunt movements.
Existing risk controls
Regardless of the stopping point of the locomotive (either adjacent the signal or completely behind), the signalling system detected the track beyond signal DYN150 as clear. This released the route and allowed operation of points 143, which altered the route that had been set between signal DYN150 and signal MGL57 (for the shunting).
The ARTC had recognised the potential for this scenario and issued Standing Train Notice 1983/2009 to provide specific additional protection. That is, even if the route set between signal DYN150 and signal MGL57 became unoccupied, the integrity of the route could not be compromised (or altered) until the NCO had verified that the train or loco had returned completely behind signal DYN150.
All parties have responsibilities under Standing Train Notice 1983/2009, PN to communicate the planned shunt and the ARTC to apply blocking facilities to the relevant points. In this instance however, the driver, shunt planner and Network Control Officer had not implemented these procedures.
There is no clear reason why neither party initiated the requirements of the notice in this case, nor was there any evidence to suggest the lapse was a common occurrence. Both the ARTC and PN have initiated action to reinforce the requirement for relevant personnel to implement the instructions of Standing Train Notice 1983/2009 when shunting at the MFT (refer to Safety issues and actions section below).
Incident response and communication
To mitigate further risk following the development of this occurrence, two key events required an effective and timely response. The first was the SPAD alarm generated by the signalling system indicating a limit of authority overrun, and the second was the actual derailment of locomotive 8122 at points 143.
Signal passed at danger
The ARTC Code of Practice for the Defined Interstate Rail Network, Operations and Safeworking, Issue 2 (ARTC Annotated Version May 2002) documented the required action by the NCO when responding to a SPAD alarm. The code required the NCO to promptly react to emergencies or unusual circumstances and to protect the train that had overrun and any other train that may come into conflict. The code’s intent was for the NCO to promptly stop the train that had overrun its limit of authority and to stop any other movements that were at risk.
In this case, in response to the SPAD alarm, the NCO contacted the MFT shunt planner, rather than the driver of locomotive 8122, and a conversation began regarding the SPAD at DYN150. The driver was unaware of the SPAD alarm and did not recall receiving any instruction from either the NCO or the MFT shunt planner to stop the train.
Analysis of network voice recordings indicated that the shunt planner (during his conversation with the NCO) made a short call to the driver by UHF radio and used the phrase ‘red light’. This phrase was identical to the normal expression used by the shunter when directing a driver to stop, before making further directions to complete a particular shunt movement. The shunt planner’s ‘red light’ phrase did not alert the driver to the significance of the message and there was no follow up by the shunt planner to confirm that the driver had received and understood the communication.
The absence of direct communication between the driver and the NCO meant that the driver remained unaware of the SPAD alarm. The adopted process failed to ensure protection (in this case against derailment) for the train identified by the signalling system as having exceeding its authority.
Derailment of locomotive 8122
Without receiving clear instructions to the contrary and unbeknown to the NCO and MFT shunt planner, the driver of locomotive 8122 continued shunt operations that led to the derailment at points 143.
The ARTC Code of Practice for the Victorian Main Line Network documented the action required by a locomotive driver in response to an emergency scenario (such as a derailment). Drivers were required to advise the NCO by radio that a derailment had occurred and that the safe operation of the line was affected. Contrary to this however, the driver said that his first action in this case was to contact the MFT shunt planner, before relaying the information to other Pacific National representatives. The driver did not directly contact the NCO and there was no recorded evidence verifying discussions between the driver and the shunt planner. Examination of the train control voice logs indicated that almost 30 minutes passed before all parties became aware of (and confirmed) that locomotive 8122 and a wagon had derailed at points 143.
Communication
Typically, a driver would request an authority to enter the main line from a shunting yard or terminal directly from the NCO. This establishes a direct line of communication between the driver and the NCO.
The process for obtaining an authority in and about the MFT differed because of the type and frequency of train movements undertaken. For operational reasons, the shunt planner (rather than the driver) would contact the NCO to request an authority to enter the main line. This process inherently limited direct communication between the locomotive driver and the NCO – including on this occasion, the more urgent communications related to the SPAD alarm.
While communicating through a third party (the MFT shunt planner) may have been suitable for managing routine shunt operations at this location, it was evident that communication in response to the SPAD alarm was ineffective, as shunt operations continued and locomotive 8122 subsequently derailed. Furthermore, significant time passed before the NCO and the MFT shunt planner became fully aware of the derailment.
The investigation found that although communication systems and protocols were in place, the NCO and the train driver did not directly communicate following the SPAD alarm or the subsequent derailment. Had this communication occurred, it was possible that there would have been sufficient time to stop the train before the arrival at the points, or at least alert the driver and prevent the subsequent reverse manoeuvre that produced the derailment. Similarly, had the driver immediately reported the derailment directly to the NCO, actions could have been taken much earlier to ensure the protection of this and other train movements in the vicinity.
The safety issues identified during this investigation are listed in the Findings and Safety issues and actions sections of this report. The Australian Transport Safety Bureau (ATSB) expects that all safety issues identified by the investigation should be addressed by the relevant organisation(s). In addressing those issues, the ATSB prefers to encourage relevant organisation(s) to proactively initiate safety action, rather than to issue formal safety recommendations or safety advisory notices.
All of the directly involved parties were provided with a draft report and invited to provide submissions. As part of that process, each organisation was asked to communicate what safety actions, if any, they had carried out or were planning to carry out in relation to each safety issue relevant to their organisation.
Where relevant, safety issues and actions will be updated on the ATSB website as information comes to hand. The initial public version of these safety issues and actions are in PDF on the ATSB website.
The insulated rail joints were incorrectly placed
The placement of the insulated rail joints adjacent to signal DYN150 was not in accordance with the ARTC engineering procedure ESC-07-01.
Communication protocols at the Melbourne Freight Terminal
The practice of using a third party (the shunt planner) to facilitate communication between Network Control Officers and train drivers at the Melbourne Freight Terminal prevented an effective response to the emergency.
Whether or not the ATSB identifies safety issues in the course of an investigation, relevant organisations may proactively initiate safety action in order to reduce their safety risk. The ATSB has been advised of the following proactive safety action in response to this occurrence
Proactive safety action taken by the Australian Rail Track Corporation
The ARTC has issued a Network Control Centre Notice (Notice number 021, issued 16/9/2015), drawing attention to the requirements of Standing Train Notice 1983/2009 and that all Network Controllers are to adhere to the instructions regarding the blocking of points over which a shunt is to traverse at the MFT.
Sources and submissions
Sources of information
The sources of information during the investigation included:
Pacific National Pty Ltd
The Australian Rail Track Corporation
The driver of locomotive 8122
References
Rail Industry Safety and Standards Board (2010), Glossary of Rail Terminology – Guideline.
Code of Practice for the Defined Interstate Rail Network, Operations and Safeworking, Issue 2 – ARTC Annotated Version May 2002
ARTC Code of Practice for the Victorian Main Line Operations Issue 1, Revision 2, 07 August 2011
Submissions
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the Office of the National Rail Safety Regulator, Pacific National, the Australian Rail Track Corporation, and the driver of locomotive 8122.
Submissions were received from all parties. These were reviewed and where considered appropriate, the text of the report was amended accordingly.
The occurrence
On 25 July 2013, the shunt planner at the Melbourne Freight Terminal (MFT) requested the driver of Pacific National locomotive 8122 and a shunter[1], to marshal[2] wagons within the terminal. To achieve the desired order of wagons, the locomotive required access beyond the terminal limits and onto the main line.
At about 1715[3], at the request of the MFT shunt planner, the Australian Rail Track Corporation Network Control Officer (NCO) set a route onto the main line for locomotive 8122. About five minutes later, locomotive 8122 hauled a rake of six wagons from the MFT onto the main line and in the direction of Sims Street Junction (Figure 1). At about 1721, the locomotive passed signal DYN150 which was displaying a ‘medium speed warning’ aspect[4]. The locomotive continued beyond the signal for about 200 m before the shunter told the driver to stop.
Figure 1: Track layout Sims Street Junction showing path of locomotive 8122
Source: ARTC annotated by ATSB.
About the same time, though still some distance away, train 9794 was approaching from Footscray intending to travel towards North Dynon Junction via points 143. Although the NCO selected the required route for train 9794, the signal interlocking system[5] prevented the route from setting, due to locomotive 8122 occupying a track section that was also part of that route. The signal interlocking system stored the selected route until such time that all the required track sections were clear.
At about 1724, the driver of locomotive 8122 received a further direction from the shunter to propel[6] back toward the MFT. The locomotive pushed the attached wagons until they were in the required position and the shunter again told the driver to stop. This placed the locomotive adjacent to signal DYN150.
The driver recalled that part of the locomotive (including the driver’s cab) was forward of the signal. A rail vehicle placed in this position should register in the signalling system as occupying the track section ahead of the signal. In this instance however, the system registered the track section as clear and the original route set for locomotive 8122 from signal DYN150 completed.
As the route from DYN150 was no longer active, the system then commenced to set the stored route for train 9794 from Footscray. This included the operation of points 143 from the normal position (main line through South Dynon Junction), to the reverse position (‘X’ track through North Dynon Junction).
At about 1729, unaware of the change in the setting at points 143, the driver of locomotive 8122 continued the marshalling movements under the direction of the shunter. As the locomotive moved forward in another hauling move, the track circuitry detected occupancy of the section ahead of signal DYN150. This indicated on the Phoenix control system (Figure 2, Left), which provided the NCO with real time monitoring and control of field equipment. The Phoenix system recorded the track occupancy as an unauthorised movement past signal DYN150 and generated a Signal Passed at Danger (SPAD) alarm for attention by the NCO.
Meanwhile, the locomotive was moving toward points 143, which were now incorrectly set for this movement. At about 1730, the locomotive ran through[7] the points. Shortly after trailing the points, the shunter again told the driver to stop the shunt movement.
At about the same time, the NCO responding to the SPAD alarm phoned the MFT shunt planner. A conversation commenced about what the driver of the shunt movement was doing in passing signal DYN150 without authorisation.
As locomotive 8122 ran through the points, the signalling system lost detection of the point orientation. This, in conjunction with the new track occupancy, caused the cancellation of the route from Footscray. The Phoenix system reflected this change (Figure 2, Right), but it went unnoticed by the NCO.
Figure 2: Screen captures from Phoenix control panel
The left-hand image shows the Phoenix control panel screen immediately after the signalling system detected locomotive 8122 occupying the track section ahead of Signal DYN150. The right-hand image shows the Phoenix control panel screen immediately after the signalling system loses detection of the points 143 orientation. Source: ARTC annotation by ATSB
The locomotive stopped while straddling the points 143, with the lead bogie on the facing side of points 143 and the rear bogie on the trailing side. The shunter again told the driver to change direction and propel back towards the MFT. This manoeuvre caused the lead bogie of the locomotive to diverge onto the ‘X’ track (towards North Dynon Junction), while the locomotive’s rear bogie and wagons continued along the main line towards the MFT. The driver realised what was happening and applied the brake, but could not stop the train before derailing the locomotive and the lead bogie of the first coupled wagon.
At about the same time, the MFT shunt planner interrupted his phone conversation with the NCO and issued an instruction to the driver by UHF radio to stop the train. The MFT shunt planner did not wait for a response from the driver, but confirmed with the NCO that he had told the driver to stop. Neither the shunt planner nor the NCO was aware that the locomotive had derailed.
The NCO, the shunt planner and other representatives of the operator continued with a series of phone conversations about the SPAD and their intention to authorise the locomotive to push back behind signal DYN150. None considered the possibility of a derailment. Almost 30 minutes passed before the NCO and the shunt planner became aware of (and confirmed) that locomotive 8122 and a wagon had derailed at points 143.
The NCO then arranged for protection of the track and an inspection of the damage to the infrastructure. At 1515 on 26 July, the locomotive and the lead wagon were recovered and the track restored for traffic.
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.
On 23 July 2013, the pilot of a Bell 47G2A helicopter, registered VH‑KHJ (KHJ), departed Lake Manchester, Queensland, on a local aerial photography flight.
The pilot had taken off with carburettor heat on, as it was required for the climb and had then adjusted the amount of carburettor heat required as indicated by the carburettor gauge. He referred to the gauge about every 30 seconds during the flight.
During the third photography shoot, the pilot was climbing through about 1,300 ft above mean sea level (AMSL) when the engine stopped suddenly.
The pilot established the helicopter in an autorotation. Within 40 seconds of the engine failure, the helicopter landed heavily and was substantially damaged. Neither the pilot nor the photographer was injured.
Almost no carburettor heat was on, with the lever at about 1/8th of the available travel at the time of the incident. According to the Carburettor Icing Probability chart, the conditions indicated a serious probability of carburettor icing at any power.
All pilots of aircraft fitted with a carburettor are advised to check the forecast conditions and know the risk of carburettor icing prior to each flight.
On 14 January 2012 at approximately 0930 (local time), a ‘GT Kruza’ gyroplane (registration G-762) with a pilot and student passenger on-board, departed Mangalore Aerodrome, Victoria, for a one hour training flight. At around 1130 later that morning, a member of the public identified the wreckage of the gyroplane, which had impacted terrain a short distance from the aerodrome. Both occupants had sustained fatal injuries. There were no witnesses to the accident.
The Victorian Police Service was responsible for investigating this accident; assisted by investigators from the Australian Sports Rotorcraft Association (ASRA). From an assessment of the accident site, ASRA investigators determined that the gyroplane had impacted terrain at high speed with a near-vertical nose-down attitude. The rotor system had detached from the airframe during the impact sequence and lay several metres from the majority of the wreckage. There was no evidence of fire.
A preliminary inspection of the gyroplane’s flight controls found that the rotor head torque tube had fractured through the central section where it adjoined the rotor head torque bar. Upon closer examination, ASRA investigators identified evidence of possible pre-existing cracking within the torque bar at the point of failure, and in consideration of the critical nature of this component in the flight control system, ASRA staff sought assistance from the Australian Transport Safety Bureau (ATSB) in the formal technical examination and analysis of the torque bar failure. Assistance was also sought in the examination and possible data recovery from a GPS unit and personal mobile telephone being carried on board the gyroplane.
The following conclusions were drawn from the examinations performed:
Fracture of the rotor head torque tube was directly associated with the development of fatigue cracking that had initiated from stress concentration effects around a clamping bolt hole that passed, by design, through the centre of the tube.
The level of surface fretting and evidence of movement between the tube and torque bar suggested a level of inadequate clamping force between the components.
There was no evidence of loosening of the clamping bolt locking nut.
There was some evidence to suggest that the tightness/security of the clamping bolt nut had been checked at some time before the accident.
No data was able to be recovered from either the Blackberry mobile phone or the Garmin GPSmap 295 device.
Further information:
The investigation into the circumstances of this accident was conducted by the Victorian Police Service, supported by the Australian Sports Rotorcraft Association. The involvement of the Australian Transport Safety Bureau was limited to the technical examinations summarised within the associated report.
Requests for further information regarding the occurrence should be directed to the Victorian Police Service or ASRA.
On 3 July 2013, a company representative was boarding the bulk carrier Atlantic Princess via the ship’s pilot ladder when he fell and landed on the deck of the pilot launch below. At the time, the ship was at anchor off Whyalla, South Australia, loading iron ore from an offshore transhipment barge.
The injured man was provided with immediate first aid and transported to the local hospital. However, he died later that day as a result of his injuries.
What the ATSB found
The ATSB found that while Atlantic Princess’s pilot ladder had been rigged in accordance with the relevant international requirements, no further risk assessment was carried out for the personnel transfer. The investigation also found that the company’s safety management system provided no guidance relating to actions that should be taken when less experienced personnel were to use a pilot ladder to board or disembark the ship.
In addition, there were no facilities on board the transhipment barge that could be used to provide a safe means of access between the barge and the ship for personnel transfers with the barge operator’s procedures prohibiting such transfers.
The investigation also identified safety issues relating to the content and implementation of the pilot launch operator’s safety management system.
What's been done as a result
The ship’s managers have issued a fleet safety circular noting that helicopters should be used for transfers of persons other than pilots wherever possible. When this is not possible, they are required to use a safety harness while climbing a pilot ladder. These requirements are to be advised to the ship’s agent in advance.
The pilot launch operator’s safety management system has been audited and the company is working to improve the system and its implementation. The company’s personnel transfer procedures have also been updated.
Safety message
This accident highlights the fact that while pilots may be competent in the use of pilot ladders, it should not be assumed that other personnel are proficient in climbing or descending a pilot ladder or fit to do so.
On 4 July 2013, a coastal pilot was disembarking from the chemical tanker Golden Concord in the Torres Strait when the pilot ladder manrope he was holding appeared to give way. He was unable to establish a firm grip on the rope, lost his balance and fell to the deck of the pilot launch below.
The pilot did not sustain any serious injuries, as his fall was arrested by the deckhand on board the launch.
What the ATSB found
The ATSB identified that a number of risk controls designed to limit the likelihood of an error resulting in an accident had been compromised. These included: the use of a deck party on board the ship to assure the safety of the ladder and manropes, clear and standardised communication protocols between the pilot and the pilot launch crew and the provision of information to pilot launch crews to assist in recognising the correct pilot ladder arrangements for each pilot.
What's been done as a result
The ship’s management company has revised its pilot transfer procedures to ensure that all transfers are conducted with a deck party consisting of a supervising officer and at least one deck rating. The company has also revised its procedures to ensure that the rigging and securing of pilot ladders and manropes are in accordance with the most recent international requirements.
The pilotage company has revised its procedures to incorporate the provision of information about the use of manropes to pilot launch crews on their approach to the ship. The procedures now specify that pilots and launch deckhands shall conduct a visual and manual check of pilot ladders and manropes prior to disembarking. Additionally, the company will reinforce the importance of adhering to the standard communication protocols specified in their safety management system.
Safety message
Pilot transfers by way of pilot ladders are routine, yet inherently risky operations. In order to minimise the risk to pilots, ship operators and pilotage companies need to ensure that clear and standardised procedures and communication protocols are implemented and followed.
On the morning of 13 July 2013, a Kavanagh E-260 balloon, registered VH-FSR, was being prepared for a charter tourist flight near Alice Springs, Northern Territory. Due to the wind conditions at the time, the passengers were pre-loaded into the balloon basket as it lay on its side. As one of the passengers prepared to enter the basket, their scarf became entangled in a fan that was being used to inflate the balloon envelope. Consequently, the passenger was rapidly drawn into contact with the fan’s steel guard and the scarf was pulled tightly around their neck. Despite being provided with first aid, and subsequent medical treatment, the passenger died as a result of their injuries several days later.
What the ATSB found
The ATSB found that pre-loading of the passengers during the inflation process, although appropriate in the wind conditions, resulted in them coming into close proximity to the operating inflation fan. Additionally, the mesh and steel tubing guard positioned around the inflation fan was ineffective in preventing loose items of clothing from becoming entangled in the wooden fan blades and driveshaft. As a result, when the passenger approached the balloon basket in preparation for loading, their scarf was drawn into the fan blades, leading to fatal injuries.
The pilot conducted two safety briefings prior to the proposed flight that advised the passengers to remain clear of the fan as it was noisy and dangerous. A warning sign fitted to the fan was also pointed out. However, none of the passengers recalled that the specific danger of fan entanglement had been mentioned.
What's been done as a result
Shortly after this accident, the ATSB forwarded a Safety Advisory Notice (SAN) to balloon operators highlighting the circumstances of this occurrence and advising that they review their risk controls in relation to the safety of inflation fans. With the assistance of the Professional Balloon Association of Australia and the Australian Ballooning Federation (ABF) the SAN was also provided to their members. The ABF and Northern Territory (NT) WorkSafe also issued safety alerts highlighting the danger of fan entanglement.
The balloon operator made a number of changes to prevent a similar accident, including:
modification of all fan guards to reduce the likelihood of entanglement
establishment of a passenger exclusion zone in the vicinity of the fan
assignment of a crew member whose sole duty was to operate and supervise the fan
inclusion of detail on the danger of entanglement in the passenger briefing card.
Safety message
This accident highlights how quickly entanglement in industrial equipment, such as the inflation fan, can cause fatal injury. While highlighting the danger to those unfamiliar can reduce the risk, isolating the hazard through effective fan safeguarding and passenger control is the most effective method of preventing such tragic accidents.
The occurrence
On 13 July 2013 at about 0530 Central Standard Time[1] a bus containing 10 passengers, a balloon pilot and a driver/ground crew member departed from Alice Springs, Northern Territory for a location on the outskirts of the city. The bus was ferrying the passengers and crew to the launch site of a charter flight in a Kavanagh E-260 balloon, registered VH-FSR. A large trailer, containing the balloon and required launch equipment was towed behind the bus.
As the bus travelled toward the planned departure site, the balloon pilot provided the passengers with a safety briefing that highlighted some of the hazards involved with the flight. That briefing included the requirement for the passengers to remain clear of the fan used to inflate the balloon (see the section titled Cold-air inflation fan).
On arrival at the planned launch site the balloon crew assessed that the location was unsuitable as the prevailing wind would have carried the balloon towards power lines during departure. Consequently, the crew decided to move to another location about 2 km away.
Once at the alternative launch site, the wind speed for the departure was found to be greater than ideal. The pilot reported that, as the wind often dropped at around sunrise, it was decided to wait until that time to launch the balloon. On that day sunrise occurred at about 0717.
During the wait the pilot conducted a further passenger briefing that reiterated how the flight was to progress as well as the hazards. Specifically, the passengers were told:
to remain clear of the cold-air inflation fan
that they were not permitted between the balloon basket and the bus during inflation.
The requirement to remain clear of the area between the basket and the bus was to minimise the risk of injury should the balloon basket move during inflation. Additionally, as the basket was tethered to the front of the bus during the inflation process, there was also a trip hazard associated with the tether.
The passengers were also informed that, due to the wind, they would be pre-loaded into the basket while it was positioned on its side and before the balloon was fully inflated (see the section titled Passenger loading procedure). The passengers were divided into two groups of five and allocated their positions in the basket. Due to the basket configuration, with the pilot and gas bottles occupying the centre area, passenger loading was only possible from either end of the basket (Figure 1).
Figure 1: Balloon basket passenger and pilot compartments
Source: ATSB
Following assessment that the wind speed was within the allowable limits, the balloon inflation process commenced at about 0700 using the cold-air inflation fan. Two of the passengers assisted with the inflation, under the supervision of the crew, by supporting the balloon’s mouth (Figure 2).
Figure 2: Passengers assisting with the initial balloon inflation
Source: C and J Siviour
As the balloon inflated the ground crew member repositioned to take control of a long rope (crown line) that was attached to the top of the balloon envelope (Figure 3). The crown line ensured that the balloon envelope remained stable as it inflated and did not contact the basket, burner or inflation fan. Operation of the crown line resulted in the ground crew member being over 50 m away from the basket and out of sight of the pilot and passengers. The pilot remained at the basket to conduct preflight checks on the balloon and supervise the loading of the passengers.
Figure 3: Example of a ground crew member controlling the balloon crown line
Source: ATSB
Once the balloon was inflated sufficiently for the balloon mouth to support itself, the assisting passengers moved to their allocated end of the basket ready for loading. Once they were clear of the mouth, the pilot accelerated the inflation process by using the burners positioned on the frame mounted above the basket to heat and expand the air within the envelope (Figure 4).
Figure 4: Balloon inflation was assisted by the application of burner heat once the assisting passengers had moved clear of the balloon mouth
Source: C and J Siviour
As the balloon envelope inflated it gradually rotated to the left and aligned itself with the wind. As a result of that movement, the basket connected to the balloon was pulled around closer to the inflation fan (Figures 5 and 6). In response, the pilot repositioned the fan away from the basket a number of times to ensure continued efficient inflation of the balloon.
Figure 5: Balloon basket originally positioned parallel to the front of the bus
Source: C and J Siviour
Figure 6: The basket orientation altered as the balloon increased in size and became affected by the wind
Source: R Bernoth
At around 0715, the pilot instructed the passengers allocated basket positions furthest from the inflation fan to commence pre-loading (Figure 7). After several of the passengers had entered the basket, the pilot directed the passengers assigned locations closest to the fan to begin preloading. The pilot reported that he monitored the passengers as they entered both ends of the basket. During the loading process he remained on the fan-side of the basket near to the balloon’s burner frame, about 1.5 m to 2 m away from the fan. The passenger’s recollection of the distance between the basket and the fan varied between 1 and 2.5 m.
Figure 7: Passengers pre-loading into the side of the basket furthest from the inflation fan (Note: the pilot on the left side adjusting the fan’s position)
Source: N Poulsen
The first passenger who entered the basket on the fan-side stated that they gained access by moving through a gap between the fan and the basket as they did not wish to be subjected to the force of the air that would have resulted from passing in front of the fan. Several passengers situated close to the fan recalled that a second passenger then similarly moved between the fan and the basket to begin preloading. In contrast, the pilot recalled that both passengers approached the fan side of the basket by walking around in front of the operating fan.
As the second passenger approached the fan, the scarf they were wearing was drawn into the operating fan and rapidly become entangled around the fan blades and driveshaft. As a result, the passenger was drawn into contact with the fan’s steel guard and the scarf was pulled tightly around their neck. The pilot reported that, in response, he immediately shutdown the fan and called out to the ground crew member. He advised that he did not recall that the passenger had been wearing a scarf.
None of those present witnessed the initiation of the entanglement, nor what specific part of the fan guard the scarf was drawn into. The pilot reported having positioned the passenger at the basket prior to the scarf contacting the fan guard. However, other witnesses recalled that the accident occurred as the passenger moved between the fan and the basket.
Most passengers indicated that prior to the actual day of the flight they had been advised to wear warm clothes. Some passengers mentioned that items such as beanies, scarves and gloves had been suggested.
The passenger who became entangled in the fan wore a scarf that was wrapped twice around their neck and loosely knotted such that it could not be quickly removed if caught. The scarf had long, lightweight tassels on each end, some of which extended just beyond the bottom of the passenger’s coat.
The ground crew member advised that, as a result of hearing the fan stop, he returned to the basket. On reaching the injured passenger he cut the scarf free and, with the assistance of the pilot, called for an ambulance.
Despite the provision of first aid and subsequent medical treatment, the passenger succumbed to their nonsurvivable injuries several days later.
The balloon pilot held a Commercial Pilot (Balloon) Licence and a medical certificate issued by the Civil Aviation Safety Authority (CASA). The pilot had significant ballooning experience, having flown VH-FSR and other similar balloons in the Alice Springs area many times over a number of years. The pilot was also a qualified balloon instructor and held a number of overseas commercial balloon pilot licences.
The pilot complied with the operations manual recency requirement and had undergone a biennial balloon flight review with the operator on 13 November 2011. They had also completed a number of other flight reviews and checks as recently as 6 weeks prior to the accident.
Meteorological information
The pilot reported that a weather forecast for the intended flight was obtained from the Bureau of Meteorology. The weather was predicted to be fine with a northerly wind of 7 kt. Observations from Alice Springs Airport, about 6 km from the launch site, recorded a north-north-easterly wind from 4 to 7 kt at about the time of the accident.
The pilot assessed the actual wind direction at the launch site by releasing a number of small weather balloons. Their movement indicated an easterly wind at the surface that transitioned to the forecast northerly with height. The pilot estimated that the wind strength was between 6 and 8 kt. The passengers reported that the weather on the day was fine and ‘breezy’ or ‘a bit of a surface breeze’. The operations manual had a requirements that flights were not to proceed when the surface wind exceeded 8 kt.
Cold-air inflation fan
Initial inflation of a hot air balloon envelope requires the use of a cold-air inflation fan. Efficient inflation relies on correct fan positioning relative to the mouth of the envelope. As a result, if the balloon envelope position changes due to the effects of the wind, the fan may need to be repositioned.
Once there is sufficient air inside the envelope to support the mouth, heat from the gas burners is applied. The application of heat expands the air and, as a result, the envelope. Expansion of envelope results in more air being drawn in via the mouth. The continued use of the cold-air inflation fan during the expansion stage assists the speed of the overall inflation process.
The occurrence fan
The occurrence fan consisted of a large two-bladed wooden propeller attached to the output shaft of a petrol-powered engine (Figure 8). The fan blades were enclosed within a welded steel mesh cage with square holes about 47 mm in width. The operator stated that the fan cages were made locally to their own specifications as they had found that previously used production fans were not sufficiently robust. The fan also had two wheels at the bottom to facilitate positioning.
The fan assembly had a sign attached to one side that advised ‘DANGER HIGH SPEED FAN KEEP AWAY’ (Figure 9). The fan engine had a key switch located on a panel at the rear of the engine that could immediately stop the engine/fan.
Examination of the fan identified remnants of the woollen scarf caught around the blades and driveshaft. Both wooden blades had tip damage that also contained small strands of wool. The upper front part of the guard had minor damage that increased the size of the mesh opening (Figure 8). That damage appeared to pre-date the accident.
Figure 8: The cold-air inflation fan with remnants of the scarf (pre-existing minor cage damage highlighted)
Source: ATSB
Figure 9: Installed fan warning sign
Source: ATSB
Fan testing
The ATSB tested the airflow around one of the operator’s similar fans while it was operating at normal inflation RPM (Figure 10).
It was identified that air was drawn from the rear of the fan at a distance of 40 cm behind the guard, with significantly more suction within 15 cm of the guard. The fan also drew air in from the circular section of the guard from about 20 cm and from a region in front of the guard.
Figure 10: Cold-air inflation fan airflow (blue arrows show air being drawn in, yellow arrows show outflow)
Source: ATSB
Fan design and safety information
CASA is the regulatory body responsible for ballooning operations in Australia. CASA provides guidance for the commercial operation of balloons with regard to maintenance, passenger control and other safety related issues. While CASA had not regulated or specified the design or use of devices such as cold-air inflation fans at the time of the accident, CASA subsequently advised that:
…as the new balloon regulation is developed Civil Aviation Safety Regulation 1998 Part 131 will include that balloon operators whether private, or commercial Air Operator Certificate (AOC) operators, must have adequate safety procedures for inflation fan use. AOC holders will need to describe their Standard Operating Procedures in their operations manual.
At the time of writing the making of Part 131 was estimated to occur in mid2016, with commencement expected by the first quarter of 2017.
As part of this investigation, the ATSB identified the following information relating to the safeguarding of fans.
International Standard ISO 12499:1999 Industrial fans – Mechanical safety of fans – Guarding
Although not related specifically to balloon cold-air inflation fans, the International Organisation for Standardisation published a standard that provided ‘information on the safety aspects of fixed guards for use with industrial fans’. The document identified that mechanical hazards from fans could result in severe or fatal injuries. Consequently, the standard advised that ‘safeguarding measures shall be undertaken to minimize risk’.
The standard identified a number of means of safeguarding the fan, including:
identification of the hazard(s) via warning labels
elimination or avoidance of the hazard(s) through the use of safety distances
the use of physical safeguards such as protective fixed guards.
In relation to the use of fixed guards, the standard stated that:
The guard shall, by its design, prevent access to the dangerous parts of the fan and associated equipment. It shall be of robust construction, sufficient to withstand the stresses generated by the operation of the fan and the environmental conditions…
…
Perforated material used for the manufacture of guards shall be perforated metal, woven mesh, welded wire, metal lattice or similar. The mesh size and distance of the guard from the danger point or zone shall be sufficient to prevent contact….
United States Department of Labor Occupational Safety and Health Standard 1910.212 Machinery and Machine Guarding
The United States Department of Labor Occupational Safety and Health Standard 1910.212 detailed the requirements for machinery and machine guarding in industrial applications.
Standard number 1910.212(a)(5) stated that when a fan is less than 7 ft (2.1 m) above the working floor, the blades shall be guarded and that the opening in the guard shall be less than half an inch (12.5 mm). An accompanying document clarified that the use of concentric rings (Figure 11) with spacing between them not exceeding half an inch was considered to be acceptable providing that sufficient radial spokes and firm mountings were used to make the guard rigid.
Figure 11: Concentric ringstyle fan guard
Source: Ventry Solutions Inc.
United States Federal Aviation Administration Balloon Flying Handbook
In relation to the hazards associated with cold-air inflation fans, the United States Federal Aviation Administration (FAA) Balloon Flying Handbook (www.faa.gov) stated:
The inflation fan is one of the most dangerous pieces of equipment in ballooning…Fan blades have been known to shatter or break, throw rocks at high velocity, and inadequate cages or guards fail to protect fingers and hands…The fan should have a cowling of fibreglass or metal because a cage or grill alone is not sufficient to stop rocks or pieces of blade from being thrown.
…
Crewmembers, as well as the pilot, should be clothed for safety and comfort. Cover or restrain long hair. Scarves, hanging jewellery, or loose eyeglasses can interfere with smooth setup, and can potentially be very dangerous, particularly near the inflation fan.
The balloon operator advised that one of their inflation fans had a metal cowl around the periphery of the cage as recommended in the FAA handbook (Figure 12). The operator reported that the presence of the cowl significantly reduced the inflation airflow.
Figure 12: Shrouded fan design
Source: ATSB
That view was supported by an inflation fan manufacturer (www.ventry.com). A video demonstration conducted by that manufacturer compared the operation of a fan with a cowl around the periphery to one having only a mesh surround. The footage showed that operation of the fan with a cowl in place significantly decreased the fan’s output while also increasing the amount of noise generated by the fan. The manufacturer’s description on the airflow pattern around a mesh enclosed fan were consistent with the findings of the ATSB testing.
Flight preparation
Passenger briefing
The company operations manual listed the various responsibilities and procedures to be followed during ballooning operations. The manual contained a requirement that a flight briefing was to be provided to all passengers detailing the:
procedure to be followed by passengers during landing in order to minimise the risk of injury
correct method to enter and exit the balloon basket
requirement not to interfere with the flight controls in the pilot’s compartment
dangers of the inflation fan and smoking in proximity to the balloon.
In the event that the passengers had limited understanding of English, the briefing was required to include a physical demonstration and use a pictorial briefing card.
The operations manual also detailed the briefing to be provided to passengers assisting with the inflation of the balloon. That briefing was required to detail:
‘…where to stand, what to do and what to expect as the inflation progresses.’
the process for holding the balloon envelope mouth open during cold and hot air inflation
the method of handling the envelope to ensure that it was not damaged.
That section of the operations manual also stated that:
If a person is allocated the task of supervising the inflation fan they will not be wearing clothing that can be entangled in the fan. The importance of standing behind the line of rotation of the fan blade will also be emphasised.
Although detailed in the manual, the operator stated that passengers had not supervised the operation of the inflation fan for at least 15 years. Only company pilots and crew that had been trained in inflation fan management were permitted to operate the fan.
The passengers reported that they received two briefings prior to the start of the balloon inflation process. Those briefings identified the hazards of the fan indicating that it was noisy and could be dangerous. The danger sign on the side of the fan was also pointed out.
When interviewed by the ATSB shortly after the accident, the pilot reported that the passengers had been instructed not to stand too close to the fan. The pilot later advised that the danger posed by long hair or loose clothing had also been emphasised. None of the passengers reported that any mention was made of the hazards of long hair or of wearing clothing that could become entangled in the fan.
In addition to the hazard posed by the fan, the passengers recalled that the briefings also emphasised a number of other aspects, including the:
requirement to remain clear of the gap between the bus and balloon basket once the inflation commenced
potential for unrestrained cameras to cause injury during landing
requirement not to smoke.
A number of the passengers did not speak English as their primary language. As a result, several of them advised that they had difficulty understanding parts of the briefings. However, those passengers further stated that there was sufficient understanding within the group for the message to be successfully explained. It was reported that the passenger who became entangled in the fan had a high level of English language proficiency.
Passenger loading procedure
Under conditions of little or no wind passengers would normally enter the basket once it and the balloon envelope were upright (Figure 13). Due to the wind conditions that existed on the morning of the accident however, the pilot decided to pre-load the passengers into the basket while it was on its side.
Figure 13: Passenger loading in calm conditions
Source: ATSB
Preloading is a widely used method of passenger loading that stabilises the balloon envelope against the effect of wind as it rises vertically. That method also ensured that the passengers did not have to enter a moving basket. The pilot reported having conducted preloading operations many times previously. Although a number of passengers recalled that the method of preloading was discussed during the briefing provided by the pilot, no procedural guidance on that method of loading was provided in either the flight or operations manuals.
Civil Aviation Order (CAO) 20.16.3 Air service operations - Carriage of persons, contained requirements relating to the loading of passengers in hot air balloons. Specifically, subsection 6A of the order stated:
A manned balloon or hot airship engaged in charter operations need not carry a cabin attendant if:
(d) during passenger loading and launching operations, and as far as possible during landing and passenger unloading operations, at least the following are available [ATSB emphasis] to help the pilot with loading or unloading passengers:
(i) if not more than 16 passengers are carried – 1 ground crew member trained in accordance with the manual (a trained ground crew member)
The ATSB sought clarification from CASA in relation to the meaning of ‘available’ in the context of the ground crew member operating the crown line during passenger loading. The following advice was received:
The CAO required the ground crew to be available to help the pilot load the passengers at all times during the loading process. The ordinary dictionary meaning of the word ‘available’ required the ground crew to be at hand, of use or service. If the ground crew was engaged in a task that he or she could not readily stop performing, then that person was not available to help the pilot load the passengers.
The pilot stated that the CAO requirements were complied with as the ground crew member was at all times able to release the crown line and assist the pilot without jeopardising the safety of the balloon.
Related occurrences
In order to identify other accidents and incidents involving cold-air inflation fans, the ATSB conducted an extensive review of Australian and overseas occurrence databases. That review identified one similar accident to this occurrence in which a crew member was seriously injured when a rope they were handling became entangled in an inflation fan (www.ntsb.gov - National Transportation Safety Board reference FTW96LA140).
Findings
From the evidence available, the following findings are made with respect to the flight preparation event involving Kavanagh E260 balloon, registered VHFSR, which occurred near Alice Springs, Northern Territory on 13 July 2013. These findings should not be read as apportioning blame or liability to any particular organisation or individual.
Contributing factors
Pre-loading of the passengers during the inflation process, although appropriate in the wind conditions, resulted in them coming into close proximity to the operating cold-air inflation fan.
The mesh and steel tubing guard positioned around the cold-air inflation fan was ineffective in preventing loose items of clothing from becoming entangled in the wooden fan blades and driveshaft.
In preparation for loading, the passenger moved sufficiently close to the operating cold-air inflation fan for their scarf to be drawn into the fan blades, leading to their fatal injuries.
Safety actions
No safety issues were identified during this investigation. However, the following proactive safety action was taken by a number of organisations in response to this occurrence.
ATSB safety advisory notice to balloon operators
On 18 July 2013 the ATSB wrote to Australian balloon operators to advise the circumstances of this accident. Due to concern that other balloon operators may be similarly exposed to the hazard associated with coldair inflation fans, that correspondence included the following safety advisory notice (SAN) AO-2013-116-SAN-003:
The Australian Transport Safety Bureau advises balloon operators to review their risk controls in relation to the safety of cold-air inflation fans, especially in relation to passenger proximity to operating fans, and the security of loose items, such as passenger clothing.
The SAN was forwarded to the Professional Balloon Association of Australia and the Australian Ballooning Federation (ABF) for dissemination to members of those organisations. In response, the ABF produced Pilot Safety Alert No 02 in July 2013 (appendix A).
The SAN was also distributed to all operators of balloons listed on the Civil Aviation Safety Authority’s register.
Other safety action
Northern Territory (NT) WorkSafe
On 20 August 2013 Northern Territory (NT) WorkSafe issued a safety alert titled, Preventing contact or entanglement with machinery or plant with moving parts. That alert highlighted the ineffectiveness of the fan guard in this accident. NT WorkSafe recommended that barriers should be erected around the fan to prevent access. They also advised that the fan operation should be supervised in public thoroughfares or areas of high traffic (appendix B). This safety alert was reproduced by other safety related organisations in Australia and internationally.
Civil Aviation Safety Authority
In February 2014 the Civil Aviation Safety Authority (CASA) included an article titled Spiralling Danger in issue 96 of the Flight Safety Australia magazine. That article highlighted the hazards associated with cold-air inflation fans (www.casa.gov.au).
The balloon operator
Fan guard modification
The mesh size on the operator’s cold-air inflation fan guards have been reduced in size to impede the ingress of items such as scarves and other items of loose clothing (Figure 14). Changes to the mesh size can be identified by comparison with the occurrence fan (Figure 8).
Figure 14: Modified fan guard with reduced mesh size
Source: Balloon operator
Operational changes
The operator introduced a number of operations manual requirements to reduce the risk posed by inflation fans. Specifically, a passenger exclusion zone was established around operating fans and detail on the danger of entanglement was included in the passenger briefing. On arrival at the launch site passengers are now required to leave any scarves on the bus.
The following procedure was also established regarding the operation of the fan:
The fans may only be operated by a ‘fan’ crew person trained to manage the fan. The fan crew person must remain within the exclusion zone and within 1 metre of the fan at all times the fan is running.
The fan person must wear a high visibility vest, ear plugs and carry a knife suitable for cutting any rope like material that may be entangled in fan.
The operator has produced new passenger briefing cards that highlight the hazards of the inflation fan and a ‘keep clear’ distance of 2 m. A new passenger exclusion zone between the front of the bus and the balloon is also illustrated (appendix C).
Finally, and although not required for balloon operations, the operator has introduced a safety management system to provide:
… an integrated set of work practices, beliefs and procedures for monitoring and improving the safety and health of all aspects of our operation. It recognizes the potential for errors and establishes robust defences to ensure that errors do not result in incidents and accidents.
Safety analysis
Introduction
The results of a worldwide database search identified that this accident appeared to be a rare occurrence, with only one other fan related accident identified.
This analysis will examine the factors that contributed to the accident, including the management of risks associated with moving around hot air balloons that are being prepared for flight.
Development of the accident
The passengers had been advised to wear warm clothing for the early morning balloon flight and all had worn attire consistent with that request. The passenger who became entangled in the fan had worn a long scarf, loosely knotted, on the outside of their clothing. Due to the way the scarf was worn, there was no opportunity for it to pull free as it was drawn in to the fan.
Pre-loading of the passengers during the inflation process, although appropriate in the wind conditions, resulted in the passengers entering the fan-side of the basket coming into close proximity to the operating inflation fan. The effectiveness of the following measures that were in place on the day to prevent fan entanglement will be examined:
fan safeguarding
passenger briefings
passenger supervision.
Fan safeguarding
Although there was no specific standard identified relating to inflation fans, the occurrence fan did have two of the safeguards recommended for industrial fans: a warning sign and a fixed guard. The warning sign had been identified during the passenger briefing. However, as the sign was only on one side of the fan assembly, and accounts varied as to the path taken by the passenger to the basket, it may not have been visible to them. In that regard, and despite the warning sign having been identified by the pilot during the passenger briefing, the salience of the warning to the passenger as they approached the fan could not be determined.
The mesh and steel tubing guard positioned around the fan did not prevent the scarf tassels being drawn in to the fan blades as the passenger walked towards the basket. A review of the safeguarding of similar fans identified that the occurrence fan had a relatively large mesh size and no peripheral cowl. The mesh size on the occurrence fan was also larger than that recommended in the United States (US) Department of Labor Occupational Safety and Health Standard. Given the lightweight nature of the scarf tassels, it could not be concluded that a smaller mesh would have prevented the scarf from reaching the fan blades on this occasion. More generally however, safeguarding forms an important part of managing the risk associated with hazardous equipment such as fans. Therefore, the ATSB recommends that balloon operators review the adequacy of fan guards, including the mesh size, in the context of the international and US standards for industrial fans.
None of the witnesses recalled whether the scarf was drawn in to the periphery of the fan guard. As ATSB testing identified that air was also drawn in from other areas of the guard, the fitment of a cowl may not have altered the outcome. Additionally, while the inclusion of a peripheral cowl provides additional safeguarding, it also appears to significantly reduce the fan output. That could result in a situation where an additional fan was required for efficient inflation, likely increasing the overall risk.
Given the limitations of the above safety measures, and the typical distances from which items can be drawn in to a fan, the most effective method of preventing entanglement would be through isolation of the inflation fan. Recognising the reduction of overall inflation efficiency, that could best be achieved by shutting the fan down during passenger loading. The use of barriers or minimum approach distances may also be effective.
Passenger briefing
Prior to commencing the balloon launch preparation, the pilot briefed all of the passengers on a number of the hazards associated with the planned flight. While the passengers did not share the pilot’s recollection that the danger of fan entanglement had been specifically identified, they did have a common belief that the cold-air inflation fan had been identified as noisy and dangerous. The passengers also recalled that the danger sign attached to the fan had been highlighted.
The passenger who became entangled in the fan was reported to have had a high degree of proficiency in English. As such, it was considered unlikely that they would have had difficulty understanding the briefing.
Given the adventurous nature of hot air ballooning, it is likely that the majority of passengers would be focussed on the impending flight rather than the launch site hazards. In that context, the danger posed by equipment such as inflation fans would be best managed by actively blocking access. Therefore, limited reliance should be placed on the effectiveness of hazard information conveyed via briefings.
Passenger supervision
The management of the crown line by the ground crew member resulted in the pilot alone supervising the passenger loading while also inflating the balloon. In the context of the Civil Aviation Order 20.16.3 requirement, the pilot stated that the ground crew member was at all times able to release the crown line and assist the pilot without jeopardising the safety of the balloon. That viewpoint is supported by the crew member’s action in releasing the line and returning to the basket on hearing the fan stop.
The pilot reported that they did not recall that the passenger who became entangled had been wearing a scarf. That indicated that the pilot either did not specifically notice the scarf, recognise the potential for the scarf to be drawn in to the fan, or their attention was focussed on other activities at the time. While the presence of the ground crew member at the basket during loading would have provided additional supervision of the passengers, there was insufficient evidence to conclude that it would have prevented the accident.
Sources and submissions
Sources of information
The sources of information during the investigation included the:
Under Part 4, Division 2 (Investigation Reports), Section 26 of the Transport Safety Investigation Act 2003 (the Act), the Australian Transport Safety Bureau (ATSB) may provide a draft report, on a confidential basis, to any person whom the ATSB considers appropriate. Section 26 (1) (a) of the Act allows a person receiving a draft report to make submissions to the ATSB about the draft report.
A draft of this report was provided to the balloon operator and crew and the Civil Aviation Safety Authority.
Any submissions from those parties will be reviewed and where considered appropriate, the text of the draft report will be amended accordingly.
Appendices
Appendix A – Australian Ballooning Federation alert
Appendix B – Northern Territory (NT) WorkSafe alert
Appendix C – Passenger briefing card
Purpose of safety investigations & publishing information
Purpose of safety investigations
The objective of a safety investigation is to enhance transport safety. This is done through:
identifying safety issues and facilitating safety action to address those issues
providing information about occurrences and their associated safety factors to facilitate learning within the transport industry.
It is not a function of the ATSB to apportion blame or provide a means for determining liability. At the same time, an investigation report must include factual material of sufficient weight to support the analysis and findings. At all times the ATSB endeavours to balance the use of material that could imply adverse comment with the need to properly explain what happened, and why, in a fair and unbiased manner. The ATSB does not investigate for the purpose of taking administrative, regulatory or criminal action.
Terminology
An explanation of terminology used in ATSB investigation reports is available here. This includes terms such as occurrence, contributing factor, other factor that increased risk, and safety issue.
Publishing information
Released in accordance with section 25 of the Transport Safety Investigation Act 2003
Ownership of intellectual property rights in this publication
Unless otherwise noted, copyright (and any other intellectual property rights, if any) in this report publication is owned by the Commonwealth of Australia.
Creative Commons licence
With the exception of the Coat of Arms, ATSB logo, and photos and graphics in which a third party holds copyright, this publication is licensed under a Creative Commons Attribution 3.0 Australia licence.
Creative Commons Attribution 3.0 Australia Licence is a standard form licence agreement that allows you to copy, distribute, transmit and adapt this publication provided that you attribute the work.
The ATSB’s preference is that you attribute this publication (and any material sourced from it) using the following wording: Source: Australian Transport Safety Bureau
Copyright in material obtained from other agencies, private individuals or organisations, belongs to those agencies, individuals or organisations. Where you wish to use their material, you will need to contact them directly.