5000-1 Safety Lesson: Communication
5000-1 Safety Lesson: Communication After their spectacular season, starting as 5000-1 underdogs but ultimately winning the English Football Premiership, a number of commentators have been discussing the success of Leicester City FC and their manager, Claudio Ranieri. In one article, the Guardian observes (emphasis added): They use technology that is more commonplace at the highest level…, regularly issue electronic questionnaires to gauge everything from energy levels to sleep patterns but, perhaps most importantly of all, strive to create an environment where everybody talks to each other. Isn’t odd that it is conventional safety ‘wisdom’ workers (‘workers’ in an us and them sense) are expected communicate their concerns by formal safety reports or by making database entries? ‘Culture’ is often mentioned, but mostly judged with a heavy emphasis on formal reporting, sometimes even against arbitrary ‘best practice’ quotas of reports per person. Some accident reports have even expressed dissatisfaction that issues were reported via the ‘wrong’ method. Some have argued that the bureaucratization of safety is a out-dated Taylorism, with an over emphasis on hierarchy, command and control, division of labour, rigid application of formalised rules and an unhealthy obsession with determining culpability. We think that interpretation is a little extreme! Reporting, investigating, analysing and acting on occurrence and hazard reports are still essential, as is clearly expressing behavioural expectations. However, if we want to build a championship safety team do we not need a trusting “environment where everybody talks to each other about the real safety issues” and works together to address them, rather than an environment of blind form filling and hoping ‘someone else’ will do ‘something’? In other words, more ‘connect and collaborate’ than ‘command and control’. As this article discusses: Safety Differently @ Laing O’Rourke: Are people placed at the centre of the solution or are they seen as the problem? Do you measure safety as the presence of positives or the absence of negatives? Has safety become a bureaucratic activity or an ethical responsibility? Elsewhere, Malcolm Brinded discusses leadership, communication and how good safety performance and good business performance go hand in hand: https://youtu.be/kTHtUvgmi78 UPDATE 11 May 2016: Who do we trust in times of change? UPDATE 1 August 2016: We also recommend this article: Leicester’s lesson in leadership, published in The Psychologist. UPDATE 3 August 2016: We further recommend this article on the importance of dialogue: People value dialogue and conversation. It takes much longer…but is infinitely more effective. It is through dialogue, as opposed to monologue, that leaders and managers can understand what people are thinking and feeling about change so that they are in a better position to gain their commitment to it and address their concerns. Three factors drive successful dialogue during organizational change: Firstly: an organization must encourage dialogue early, frequently and consistently. There must be an ongoing strategic approach to dialogue before, during and after any organizational transformation. Dialogue is, and must be, a constant. Secondly: the greater the value an organization has for its dialogue, the greater the likelihood for success. Thirdly: leaders and managers need to encourage dialogue with care. Dialogue with care means choosing the channels for dialogue strategically, tailoring the approach to the aims of the change initiative, authentically engaging in conversation and being sensitive to the pace and timing of dialogue. This means bringing together the right people to offer meaningful input and support. So successful dialogue allows more people to contribute, generating not only wisdom and a wealth of ideas but also commitment and engagement to change. UPDATE 19 September 2016: Disruptive HR discuss: Engagement –...
read moreChernobyl: 30 Years On – Lessons in Safety Culture
Chernobyl: 30 Years On – Lessons in Safety Culture Late at night on 26 April 1986 in the then USSR, a team of nuclear workers prepared to conduct a test on Reactor 4 of the Chernobyl nuclear power plant as part of an otherwise routine shutdown. The exercise was to test a modified safety system and determine how long the reactor’s steam turbines would continue to power to the main coolant pumps following a loss of main electrical power supply. In order to achieve the test conditions automatic shutdown devices were inhibited and the emergency core cooling system shut-down. We the total clarity of hindsight we know this was particularly high risk because the particular RMBK-1000 reactor design is unstable at the low power levels (c7%) being tested. The test was also to be started by one shift and completed in the early morning by another, with potential shift handover and circadian low factors. A previous attempt had failed, potentially heightening the pressure to complete it on this shutdown. At 01:24 the reactor was shook by two massive explosions. Over the coming months many emergency workers were to die and many more members of the off site population exposed to harmful levels of radiation, with widespread environmental effects across many countries. Some reports suggest the operator’s actions were ‘violations‘, however as the World Nuclear Association notes: The 1991 report by the State Committee on the Supervision of Safety in Industry and Nuclear Power on the root cause of the accident looked past the operator actions. It said that while it was certainly true the operators placed their reactor in a dangerously unstable condition (in fact in a condition which virtually guaranteed an accident) it was also true that in doing so they had not in fact violated a number of vital operating policies and principles, since no such policies and principles had been articulated. Additionally, the operating organisation had not been made aware either of the specific vital safety significance of maintaining a minimum operating reactivity margin, or the general reactivity characteristics of the RBMK which made low power operation extremely hazardous. Safety Culture and Chernobyl The Chernobyl accident was analysed by the International Atomic Energy Agency‘s International Nuclear Safety Advisory Group (INSAG): INSAG concluded that the need to create and maintain a ‘safety culture’ is a precondition for ensuring nuclear power plant safety. The concept of ‘safety culture’ relates to a very general concept of dedication and personal responsibility of all those involved in any safety related activity at a nuclear power plant. Inculcation of a safety culture requires that, in training personnel for nuclear plants, particular emphasis be placed on the reasons for the establishment of safety practices and on the consequences in terms of safety of failures on the part of personnel to perform their duties properly. Special emphasis must be placed on the reasons for the establishment of safety limits and the consequences in terms of safety of violating them. Safety culture presupposes total psychological dedication to safety, which is primarily created by the attitude of the administrative staff of the organizations engaged in the development and operation of nuclear power plants. In INSAG publications, the concept of safety culture has been extended beyond the purely operational aspects to cover all types of activities at all stages in the lifetime of a nuclear power plant which...
read moreUK To Buy “Certifiable Predator B” Protector
UK To Buy “Certifiable Predator B” Protector The UK MOD has announced in a low key contracts notice that they intend to meet the PROTECTOR Unmanned Aerial System requirement to replace the RAF Reaper MQ-9A fleet, through a £415 million Government-Government Foreign Military Sales (FMS) contract with the US Department of Defence (US DoD). UPDATE 27 April 2016: This specific contract, that runs to 31 Oct 2023, appears to be £332 million. The contract announcement states the MOD has conducted a “thorough Assessment Phase (AP) which has concluded that the Certifiable Predator B (CPB) (also known as Guardian Eagle) is the only system capable of achieving UK [MAA] Military Type Certification (MTC) and delivering the PROTECTOR requirement within the required timescales”. This suggests, as expected, that that integration in non-segregated civil airspace is a key factor (the earlier Reapers are limited to ‘in theatre’ operations). Certification challenges saw the German cancellation of the RQ-4 Global Hawk based Euro Hawk in 2013 (including also lightning protection and icing capability). General Atomics Aeronautical Systems Inc (GA-ASI) says it is developing the CPB variant of the Predator B Remotely Piloted Aircraft (RPA) which will first “meet European airworthiness initial certification standards in 2017, and in cooperation with the FAA will subsequently meet domestic airworthiness certification standards”. In June 2015 GA-ASI said Certifiable Predator B: …has completed a successful internal Phase 1 Critical Design Review (CDR), along with reviews by two prospective European customers. Development of the system follows international airworthiness standards that include STANAG 4671, UK DEFSTAN 00-970, SAE ARP4754A, MIL HDBK-516C, DO-178, and DO-254, as well as others. GA-ASI is focused on the development and testing of Detect and Avoid (DAA) capabilities for RPA, combining Traffic and Collision Avoidance System (TCAS) II with the company’s Due Regard Radar (DRR) to enable both automatic collision avoidance and the ability to remain well clear of other airspace users. The integrated DAA system will continue to fly aboard NASA‘s Ikhana (Predator B) in 2015 in support of a series of NASA flight tests. These tests will measure the performance of the entire system in a variety of situations to support the ongoing standards development within the RTCA Special Committee 228. The CPB has a 79 foot wingspan, 13 feet greater than Reaper, which gives a greater internal fuel capacity, increasing its endurance from 27 to more than 40 hours. The first flight of a test vehicle with the longer span wing occurred on 18 February 2016 at GA-ASI’s Grey Butte Flight Test Facility in Palmdale, CA. The Predator family has now achieved over 3.8 million flying hours. Protector followed on from the earlier MOD Scavenger programme. The Reaper has been operated by the RAF since 2007. The RAF are the only export operator of the type that carry weapons. Its first armed Reaper sortie was in Afghanistan in May 2008. Reaper is currently being employed as part of the UK contribution to activities against Islamic State / Daesh militants in Iraq and Syria. UPDATE 6 May 2016: Chris Pocock of AINonline suggestes that the other European customer is the Netherlands. He notes that France, Germany and Italy are teamed on the rival Euro-MALE UAS project. UPDATE 30 May 2016: At the Berlin Airshow GA-ASI and local subsidiary Spezialtechnik Dresden (STD) are positioning to offer CPB / Guardian Eagle to the German government. UPDATE 12 September 2016: Aircraft integration has been completed at the GA-ASI Poway, CA production facility and the prototype has...
read moreDim, Negative Transfer Double Flameout
Dim, Negative Transfer Double Flameout (Garden City BK117B2 ZK-HJC) A combination of inadvertently leaving cockpit lights dimed after an early morning take off, a compromise when modifying the helicopter for night vision goggles, a type without an aural low fuel warning and negligible recent experience on type all featured in a recent double engine flameout in New Zealand. While it occurred in different circumstances this incident is interesting to compare against two fatal police helicopter double flameouts (the 2013 Glasgow Clutha accident and the 2005 Shizuoka City accident). The New Zealand Transport Accident Investigation Commission (TAIC) have recently reported on a 5 May 2014 occurrence when Kawasaki BK117B2 helicopter ZK-HJC experienced a double engine power loss during a hospital patient transfer flight from Ashburton to Christchurch. The pilot made an emergency landing onto farmland near Springston. The 5 occupants were uninjured and the helicopter suffered only minor damage. The operator, Garden City Helicopters, operated several helicopters and fixed-wing types for a variety activities, including Helicopter Emergency Medical Services (HEMS). The Flight The helicopter departed Christchurch at ~0715. The pilot shut down the helicopter’s engines after landing in Ashburton. The patient was taken on board, after which the pilot carried out the before-start procedures and started both engines. At 0852 the helicopter departed Ashburton… About 20 minutes later a loud bang was heard by everyone on board and an aural warning sounded in the cockpit. The pilot noticed the right engine low-revolutions-per-minute light had illuminated and that the instrument readings for the right engine were decreasing. Shortly afterwards a similar banging noise was heard and the helicopter started to descend rapidly. The pilot realised that both engines had now lost power and he entered the helicopter into autorotation and…made a firm landing in a paddock near Springston. After the emergency landing the pilot checked the cockpit instruments and switches,.. He found that: The two fuel prime pump switches were ‘on’ (these would normally be off during flight) The two fuel transfer pump switches were ‘off’ (these would normally be on during flight) There was a total of 380 kilograms (kg) of fuel indicated on the fuel quantity gauges The cockpit lighting dimmer switches were ‘on’. The pilot stated these positions had not been changed during the flight. Fuel System The BK117 fuel tanks are located below the cabin floor. Each engine had an engine-driven fuel pump that would draw fuel from its respective supply tank. Both of these supply tanks were connected by transfer tubes to the front main tank. To ensure the supply tanks remained full, two transfer pumps were fitted inside the front main tank. It was therefore important that the transfer pumps were switched on during flight to ensure that an adequate supply of fuel… was maintained. In order to supply fuel to the engines during engine starts, a prime pump was installed in each supply tank to deliver fuel under pressure to the engine until the engine was running. These prime pumps were not needed during flight…. The normal before-start procedure was for the two prime pumps to be switched on for the engine start. Once the engines were up to operating speed, the two transfer pumps would be turned on and the prime pumps would then be turned off. In the case of early model BK117s, the fuel system had symmetric fuel supply tanks. meaning they could...
read moreNASA ASRS at 40 and the Continued Challenge of Timeliness for Safety Reporting
NASA Aviation Safety Reporting System at 40 and the Continued Challenge of Timeliness for Safety Reporting On 16 April 16 2016 the National Aeronautics and Space Administration (NASA) Aviation Safety Reporting System (ASRS) celebrated 40 years of operation. Its origins highlights one major challenge of safety reporting, learning and action: timeliness. The Purpose and Administration of ASRS The ASRS collects, analyses, and responds to voluntarily submitted aviation safety reports. ASRS data is used to: Identify deficiencies and discrepancies in the National Aviation System (NAS) so that these can be remedied by appropriate authorities. Support policy formulation and planning for, and improvements to, the NAS. Strengthen the foundation of aviation human factors safety research. This is particularly important since it is generally conceded that over two-thirds of all aviation accidents and incidents have their roots in human performance errors. ASRS was set up under a Memorandum of Agreement between the Federal Aviation Administration (FAA) and NASA in August 1975. The FAA fund the programme and provide for its immunity provisions. The NASA set programme policy and administer its operations. Similar programmes now exist elsewhere, such as CHIRP (the Confidential Human Factors Incident Report Programme) in the UK (which we have previously discussed). With the lack of a mandatory occurrence scheme in the US, such as that required by Regulation (EU) 376/2014 Reporting, Analysis and Follow-up of Occurrences in Civil Aviation (and the earlier UK Mandatory Occurrence Reporting [MOR] scheme, which also commenced in 1976), ASRS also fulfils some of that role in the US. The UK CAA had issued an Aeronautical Information Circular on 2 October 1972 proposing expanded reporting requirements. Its predecessor, the Air Registration Board (ARB), had introduced defect reporting requirements in 1964 and voluntary reporting of other occurrences had been encouraged in part through the UK Flight Safety Committee (UKFSC). The CAA proposed expanding this to include mandatory ‘incident’ (i.e. occurrence) reporting. The Origin of ASRS The origins of the scheme are particularly interesting. On 1 December 1974, TWA Flight 514, Boeing 727-231 N54328 was inbound through poor weather to Washington Dulles in Virginia. The flight was originally destined for Washington National Airport but was diverting to Dulles due to high crosswinds. As NASA relate: The flight crew misunderstood an ATC clearance and descended to 1,800 feet before reaching the approach segment to which that minimum altitude applied. The aircraft collided Mount Weather, near Berryville, Virginia (near a major US government bunker) killing all 92 aboard. The NTSB investigation determined the crew’s decision to descend was “a result of inadequacies and lack of clarity” in air traffic control procedures and a misunderstanding between pilots and controllers regarding each other’s responsibilities during terminal operations and in IMC conditions. The accident is discussed fin the FAA Lessons Learnt Database. NASA go on: A disturbing finding emerged from the ensuing NTSB accident investigation. Six weeks prior to the TWA accident, a United Airlines flight crew had experienced an identical clearance misunderstanding and narrowly missed hitting the same Virginia mountaintop. The United crew discovered their close call after landing and reported the incident to their company. A cautionary notice was issued to all United pilots. Tragically, there existed no method of sharing the United pilots’ knowledge with TWA and other airlines. Following the TWA accident, it was determined that safety information must be shared with the entire aviation community. Thus was born the...
read moreC-130J Control Restriction Accident, Jalalabad
C-130J Control Restriction Accident, Jalalabad The US Air Force (USAF) Air Mobility Command (AMC) has released its accident report into the fatal loss of control (LOC-I) accident involving of Lockheed Martin C-130J 08-3174 during a night-time take-off from Jalalabad Airfield, Afghanistan on 2 October 2015. The accident was caused by the failure to remove a loose article that had been deliberately placed behind the control column during a night-time engines-running turnaround to aid loading. The Accident All 11 persons on-board died (four crew, two fly-away security team members of the the 66th Security Forces Squadron and five civilian contractor passengers), as did three Afghan Special Reaction Force (ASRF) personnel as the aircraft struck a guard tower. There was also a post crash fire. This was the worst USAF C-130 accident in the last 25 years. The aircraft was from the 317th Airlift Group, Dyess Air Force Base, Texas, and operated by the 39th Airlift Squadron, while assigned to the 455th Air Expeditionary Wing at Bagram Airfield, Afghanistan. In an AMC press release they say: While conducting engine running on-load/offload operations at Jalalabad Airfield, the pilot raised the elevators mounted to the horizontal stabilizer by pulling back on the yoke. This provided additional clearance to assist with offloading tall cargo. After a period of time in which the pilot held the yoke by hand, he placed a hard-shell night vision goggle (NVG) case in front of the yoke [or control column] to hold the elevator in a raised position. However, because the pilots were operating in darkened night-time flying conditions and wearing NVGs, neither pilot recognized and removed the NVG case after loading operations were complete or during take-off. Once airborne, the aircraft increased in an excessive upward pitch during the take-off climb. The co-pilot misidentified the flight control problem as a trim malfunction, resulting in improper recovery techniques. The rapid increase in pitch angle resulted in a stall from which the pilots were unable to recover. The aircraft impacted approximately 28 seconds after lift-off, right of the runway, within the confines of Jalalabad Airfield. The investigators say, surprisingly, they could not determine if a flight controls check would have alerted the pilots to the obstruction. Conclusions The accident investigation board identified the following causes: Inadequate Real-Time Risk Assessment (Hard-Shell NVG Case Placement) Distraction Wrong Choice of Action During an Operation (Misidentification of Malfunction) They identified the following contributory factors: Environmental Conditions Affecting Vision (i.e. night-time operations, use of NVGs, and reliance on the Head Up Display [HUD] and Advisory, Caution, and Warning System [ACAWS]) Inaccurate Expectation (in relation to take-off technique applied) Fixation (on a trim failure) Accident Sequence Video and Other Resources A brief 5s animation of the flight: AIB Report – C-130J, TN 08-3174 (Report) AIB Report – C-130J, TN 08-3174 (Tabs A – U) AIB Report – C-130J, TN 08-3174 (Tabs V – EE) UPDATE 24 April 2016: The Air Force Times has now covered this accident. They quote sources who observe that such a workaround “was not uncommon”, “there’s no official way to do that other than holding it up by hand” and sometimes items would be used to “prop up yokes”: It wasn’t sanctioned, it was just something you did. Not always, just sometimes. It’s the end of a long day and you’re tired. Someone wants to stand up and walk around, you’d use something artificial to hold that up. During an engine running turnaround:...
read moreCrew Bag FOD Shatters Hawk Canopy
Crew Bag FOD Shatters Hawk Canopy On 28 Jan 2016 Royal Canadian Air Force (RCAF) CT-155 BAE Systems Hawk Mk 115 trainer CT155219, based at CFB Cold Lake, Alberta, was performing a Cuban 8 manoeuvre. In an interim report from safety investigators: During the inverted 45 degree portion following the first loop the pilot’s unrestrained publications bag drifted upwards (relative to the cockpit) and aft. The pilot then rolled upright and pulled 5g to complete the Cuban 8. During the 5g pull, the bag dropped down towards the aft portion of the right console and struck the Miniature Detonation Cord (MDC) firing unit (red circle in the photos) with enough force to activate it, fragmenting the canopy. The pilot ceased manoeuvring, slowed the aircraft and [Returned to Base] RTB without further incident. The pilot received minor injuries from the MDC combustion products and canopy fragments and there was significant damage to cockpit equipment and external airframe structures. The engine ingested some of the canopy fragments but only received minor damage. The investigation so far has not identified any technical issues with the airworthiness of the aircraft or the fleet. The investigation is focusing on operational and human factors, primarily the procedures and requirement to carry and store a publications bag in the cockpit. The investigation is also looking at possible ways to protect the MDC firing unit from being inadvertently activated. While aerobatic aircraft are particularly sensitive to loose articles in the cockpit, non-aerobatic aircraft are also susceptible to this threat. We reported in June 2014 on a Royal Air Force (RAF) A330 Voyager ZZ333, that was involved in a loss of control (LOC-I) incident during a flight from Afghanistan in February 2014. The aircraft suddenly pitched nose down while in the cruise at 33,000ft. In 27 seconds, the aircraft lost 4,400ft, with a maximum rate-of-descent of approximately 15,000ft per minute, before recovering. The resulting negative g forces were sufficient for almost all of the unrestrained passengers and crew to be thrown towards the ceiling, resulting in a number of minor injuries. The aircraft diverted to Incirlik in Turkey. The UK Military Aviation Authority (MAA) issued a preliminary report on 17 March 2014 that said investigators: …found evidence to link the movement of the seat to the movement of the side-stick, in the form of a Digital SLR camera obstruction which was in-front of the Captain’s left arm rest and behind the base of the Captain’s side-stick at the time of the event. Analysis of the camera has confirmed that it was being used in the three minutes leading up to the event. Furthermore, forensic analysis of damage to the body of the camera indicates that it experienced a significant compression against the base of the side-stick, consistent with having been jammed between the arm rest and the side-stick unit. The full Service Inquiry report has since been published. UPDATE 17 April 2016: We also report on a US Air Force (USAF) Air Mobility Command (AMC) Lockheed Martin C-130J, 08-3174 that crashed at Jalalabad, Afghanistan after a loss of control (LOC-I) on 2 Oct 2015. That accident was caused by the failure to remove a loose article. a Night Vision Goggle (NVG)box, that had been deliberately placed behind the control column during a night-time engines-running turnaround to aid loading by holding the elevator displaced. UPDATE 12 February 2017: Flying Control FOD: Screwdriver Found...
read moreA319 Double Cowling Loss and Fire – AAIB Safety Recommendation Update
A319 Double Cowling Loss and Fire – AAIB Safety Recommendation Update The UK Air Accidents Investigation Branch (AAIB) has issued an update on responses to their safety recommendations from their investigation into British Airways Airbus A319 G-EUOE. G-EUOE, powered by IAE V2500s, lost both engine fan cowlings and suffered an associated fire on take-off from London Heathrow on 24 May 2013 after cowlings were left unlatched after an ‘aircraft swap error’ during maintenance. We have discussed that accident report and the causal factors in depth: A319 Double Cowling Loss and Fire – AAIB Report The AAIB had raised 6 recommendations: Safety Recommendation 2013-011 It is recommended that Airbus formally notifies operators of A320-family aircraft of the fan cowl door loss event on A319 G-EUOE on 24 May 2013, and reiterates the importance of verifying that the fan cowl doors are latched prior to flight by visually checking the position of the latches. This resulted in in communication by Airbus to all operators. AAIB Assessment – Adequate – Closed Safety Recommendation 2015-001 It is recommended that the European Aviation Safety Agency publishes amended Acceptable Means of Compliance and Guidance Material in Part 145.A.47(b) of European Commission Regulation (EC) No 2042/2003, containing requirements for the implementation of an effective fatigue risk management system within approved maintenance organisations. EASA has responded: The Agency is working on Rulemaking Task RMT.0251 (MDM.055) which is intended to introduce Safety Management (SMS) requirements for Part-145 organisations with one of the most important elements being the identification and mitigation of risks one of which is fatigue. The envisaged timeline for this task is to issue an NPA in 2017, with a final Opinion for 2018. AAIB Assessment – Partially Adequate – Open Aerossurance has previously written: Maintenance Personnel Fatigue Safety Recommendation 2015-002 It is recommended that the European Aviation Safety Agency requires Airbus to modify A320-family aircraft to incorporate a reliable means of warning when the fan cowl doors are unlatched. EASA responded last October: Airbus has developed a warning flag, as a design solution for retrofit, that will be more obvious to maintenance crews and pilots to indicate when the fan cowl doors are not properly closed. This flag solution will be available for retrofit for the majority of single aisle fleet in service. An EASA airworthiness directive is planned before the end of 2015 to mandate the implementation of this design change. AAIB Assessment – Partially Adequate – Open Safety Recommendation 2015-002 It is recommended that the European Aviation Safety Agency amends Certification Specification 25.901(c), Acceptable Means of Compliance (AMC) 25.901(c) and AMC 25.1193, to include fan cowl doors in the System Safety Assessment for the engine installation and requires compliance with these amended requirements during the certification of modifications to existing products and the initial certification of new designs. EASA responded: Based on the lessons learnt from in-service events, the Agency introduced, in 2013, a new Certification Review Item (CRI) providing Special Conditions (SC) for the retention of engine cowls. The SC requires a cowling design that minimizes any inflight opening or loss of cowling. It also provides some requirements for the retention system of each openable or removable cowling: Keep the cowling closed and secured under the operational loads and after improper fastening of any single latching, locking, or other retention device, or the failure of...
read moreC-130 Fireball Due to Modification Error
C-130 Fireball Due to Modification Error A botched modification program unnecessarily changed the original design for a hydraulic system modification when a drawing was misread. A longer hydraulic hose was necessary after that change but an inappropriate design process short-cut meant the shorter hose remained listed as an alternative. The shorter hose was fitted to the modified fleet and resulted in chaffed electrical wiring and a fire that damaged an aircraft beyond economic repair over ten years later. Introduction and the Accident Flight During a touch and go at NAS Key West, on 21 Feb 2012, a fireball erupted in the back of Royal Canadian Air Force (RCAF) Lockheed Martin CC-130 / C-130H(T) Hercules Air to Air Refuelling tanker CC130342, just in front of the 25,000 lbs, 3,600 US gallon cabin mounted AAR tank. According to the recently issued investigation report: Concurrent with the fire alert, the aircraft became airborne and reached 10 feet in altitude above the runway. With sufficient runway remaining, the Flying Pilot landed straight ahead and aggressively stopped the aircraft…all nine crewmembers quickly egressed and moved upwind of the aircraft. Crash Fire and Rescue services responded and expeditiously extinguished the fire. The aircraft was extensively damaged [beyond economic repair] and one crewmember received a minor injury. The aircraft had a hydraulic system modification (CF-378) to install ground test connections to the auxiliary hydraulic system, just below an electrically driven pump. This safety investigation identified routing and clamping deficiencies in the modification that resulted in chafing between the hydraulic pump electrical wiring and a hydraulic flexible hose. Electrical arcing resulted in a pin-hole breach of the hose, release of high pressure hydraulic fluid and ignition of the fire. A re-design followed, along with more education on the hazards associated with chafing. Other observations focused on the dual layer clothing principle for aircrew fire protection and improving communication between airworthiness authorities when imposing and lifting operational restrictions. The Modification and the Fireball Modification CF-378 was originally designed in 1976 for the first five Canadian C-130Hs. CC130342 was one of the third batch of RCAF C-130sHs, ordered in 1990 as tanker aircraft. The RCAF Weapon System Manager (WSM) subsequently requested that CF-378 be embodied on this batch and two further C-130H-30s during contracted base maintenance. However, the contractor noted that they could not embody modification CF-378….as the auxiliary hydraulic system on the CC130 H(T) and H-30 aircraft were different than depicted in the modification instruction… To facilitate the work, the third line contractor produced a Maintenance Production Permit (MPP) in which a “standard repair” was developed to change the CF-378 modification to accommodate the aircraft configuration. The WSM approved the MPP and the first aircraft to embody the MPP version of CF-378 was CC130341 in 2001. The modification was embodied on CC130342 on 1 February 2002. During the investigation the CF-378 modification’s flexible 28.25 inch steel braided hydraulic hose was found to be in contact with the hydraulic pump motor power cable. Lab examination: …revealed there was a 2 mm diameter hole in the stainless steel braiding, at the site where it was found in contact with the hydraulic pump motor power cable… Examination of the hose braid indicated deposits of copper and tin consistent with the material in the auxiliary hydraulic motor power cable. Examination of the hydraulic pump power motor cable revealed broken wire strands…consistent with...
read moreFatigued Flight Test Crew Superjet 100 Crosswind Accident
Fatigued Flight Test Crew Crosswind Accident The Icelandic Transportation Safety Board (ITSB), the RNSA, recently issued their report into a wheels up runway excursion accident that occurred on 21 July 2013 to Sukhoi RRJ-95B ‘Superjet 100’ 97005 during flight tests by Sukhoi at Keflavik airport. The Flight Test Objective and the Accident Flight The purpose of the flight test campaign was to expand the aircraft’s automatic approach capability from CAT II to CAT IIIA. Seven approaches and go-arounds with possible landing gear touchdown, had been conducted to RWY 20, followed by two to RWY 11. The RNSA explain that on the 9th approach: …the flight crew intended to execute a go-around at 2-3 feet radio altitude over RWY 11, under crosswind conditions [>19.5 knots], near the airplane‘s maximum landing weight, with one engine inoperative. Keflavik is a popular location for crosswind testing because of its exposed location and runways at 90ºs give a high probability of useful crosswind conditions. When the aircraft was at radio altitude of 17 ft the Automatic Flight Control System (AFCS) at 05:23:25, in accordance with its programmed logic, commanded both throttles to IDLE. One second later, as per plan, at about 10 ft the test pilot sitting in the jump seat shut down the right engine using the ENG MASTER SWITCH. This disconnected the AFCS autothrottle on that engine, while the left engine continued to reduce thrust to IDLE. A further second later, at about 4 ft, the pilot flying disconnected the AFCS autopilot. This resulted in the left autothottle returning to SPEED mode and advancing the left throttle. The pilot flying pressed the TOGA button on the right TQL [throttle lever] to initiate a go-around and, according to the cockpit voice recorder, called out “go-around”. Almost simultaneously, at 05:23:28.70, the main landing gear touched the RW and as a result of left main LG [landing gear] shock strut compression a/c avionics complex received WOW signal (weight on wheels) [for 0.4s]. However, in accordance with the Certification Specification for All Weather Operation (CS-AWO), after the WOW signal the left autothrottle disengaged (to prevent inadvertent selection of TOGA after landing), as did the AFCS flight director. The pilot flying spotted this and started to perform a go-around in manual mode, but erroneously set the right (i.e. the inoperative) engine throttle lever to TOGA, pitched-up the aircraft and ordered landing gear retraction. Consequently the aircraft started to loose speed, and having reached 27 ft stopped climbing and started to descend. The speed decreased further, below 120 knots and the pilot flying, reduced the pitch to prevent stalling. The “LANDING GEAR NOT DOWN” aural warning then triggered. The pilot flying realized after about 15 s that he had been controlling the inoperative engine, just moments before the aircraft (still wheels up) hit the runway at 05:23:47. The aircraft skidded 1600 m down the runway, overran the runway and came to a stop at 05:24:25. The RNSA comment: Video recording from the cockpit provided the investigators with visual evidence showing the inoperative engine throttle lever being advanced during the go-around procedure, as well as showing the work load and the task division between the individual flight crew members. During the evacuation the forward left door was opened, but as it had not been armed the emergency escape slide did not deploy. The forward right hand door was opened, and while the slide deployed, it was blown under the aircraft by the...
read more
Recent Comments