The Evolution of Aviation Safety: A Historical Overview

A quick tour of the history of aviation safety. In a couple of minutes.

As powered aircraft took to the skies it quickly became apparent that, of all the means of transport, aviation was less forgiving than others. Moving at speed in four dimensions, with the necessity to take-off and land safely, has inherent risks. By no means does this mean that flying is an dangerous activity. What it does necessitate is an exercise of sound engineering, preparation, and proficiency. When these are missing, and in cases of misfortune, accidents and serious incidents happen.

In the days between the world wars, aviation moved from the military and a circus-like amusement to a viable means of public transport. Progressively, more passengers had the opportunity to experience the wonders of flight.

Today, it’s not the early days of flight I want to focus on, but we do owe the engineers and aviators of that time a great debt. Much was learned as aeronautics matured. Since the end of the second world war the production, promotion and application of standards has embedded what had been learned. This has established the way that international civil aviation works.

One simple expression of the stages we’ve been through is Prof Patrick Hudson’s[1] model. This model describes five distinct levels of cultural maturity. The steps are pathological, reactive, calculative, proactive and generative.

This model sits alongside steps in the development of technology that have been a hallmark of aviation. Different categorisations exist. AIRBUS[2] has one that’s easily understood in terms of generations of civil aircraft.

First are the “classics” of the 1950s and 60s. Next, the second generation starts down the road of more electronics. More safety critical systems. Third generation starts flying in the early 1980s when automation becomes the norm (early fly-by-wire, glass cockpits, flight management systems). The fourth generation introduces safety systems, which address the major causes of fatal accidents, namely Controlled Flight Into Terrain (CFIT) and Loss Of Control In-Flight (LOC-I). That’s the early 1990s. When I made that move from industry (design and production) to an aviation safety regulator.

Now, I’d say we are well into fifth generation aircraft, with composite structures and integrated modular avionics. In fact, we are well into speculation about what the sixth generation may look like. Machine learning, single pilot operations, hybrid powerplants, aircraft as a node on a network.

Because aviation is a learning industry, and a conservative one, the expectation is of progressive improvement in maturity throughout the aviation system and innovative technology applied to enhance safety.

This is not to say that the potential for error, missteps and recklessness don’t exist. They do. I expect continuity in a way that takes full advantage of advanced methods without scarifying the legacy of an astonishing good global aviation safety achievement.

Later, to cover a lot of ground in a short time, I’m going to condense all the above into three distinct categories. But before that, I’ll talk about the present and a vision of the future.

POST: UK Farnborough Air Show on Thursday 23rd July 2026. Time: 13:00-13:15 BST. Location:  Hall 3 Stage. Session title Where Next for Aviation Safety?


[1] https://www.sciencedirect.com/science/article/abs/pii/S0925753507000227?via%3Dihub

[2] https://d10x.airbus.com/generation-of-jets/

Lessons from Operational Events

For an aviation industry that takes pride in learning lessons from experience and taking timely corrective action, a series of operational events is surprising to say the least.

Today’s large aircraft do look much the same. The tricycle undercarriage has become universal. A set of steerable wheels at the front and a heavy set of landing gear, each side, to the rear. When parked, a nose gear collapse or inadvertent retraction on a large aircraft is not catastrophic. The aircraft can be recovered, inspected, and repaired. This undesirable event can be dangerous for anyone in the vicinity. It has the potential to be fatal. Fortunately, so far, there has been no fatalities.

For an aircraft operator such an event at an airport gate is a massive expense. Putting an in-service aircraft out of action for a considerable time.

To date, several damaging nose gear collapse (and alike) events have occurred to large aircraft[1]. Detailed analysis of these events exists and corrective actions are proposed.

One conclusion is to say that this is about people not following procedures. That is the instruction is to put a pin in one place but instead it gets put in the wrong place. So, this dramatic unintended event is written up as a maintenance error. It’s an outcome that no one intended. That’s fine. There’s no doubt that an error was made. Accepting that an error occurred is not a reason to blame. That is if there are no signs of negligence.

The trouble is the simple question – how easy was it to make that error?

Then we get into that grey area of the gap between aircraft design and operations. In a design office it may be reasonably assumed that a procedure will be followed in an almost robotic manner. No need for the people in operations to think beyond taking the same action day-after-day. This would surely become widespread practice.

As we know the actual environment of aircraft operations can be more demanding than the original equipment manufactures might imagine. Pressure to turn around an aircraft can be high, working conditions can be poor and fatigue can play a part.

There are lines of communication between the aircraft design and operations organisations, and such difficulties are regularly discussed.

Faced with an event categorised as maintenance error then what next? Redesign the aircraft? Change a procedure or require more training? Those are three of the options, there are more.

This is where the possible discussion gets reactive. Now, it would be extremely costly to redesign an aircraft for the sake of an event that is rare or for which the consequences are minor. It is possible to put numbers on each of these. The rarity, the cost, and the impact.

Modifying or rewriting a procedure, on the other hand, can be less costly and it may be quite sufficient as a corrective action. That said, any procedure that can be written can be subject to error. In fact, the original procedure may have been straightforward and well thought out.

Then there is the fall-back position. Give the people in aircraft operations more training. The assumption being that more training means less errors. It is a crude assumption because this is not a linear relationship. So many other factors come into play.

Discussions surround the above possibilities can become protracted. There’s a call for more analysis and more data. There’s the proposal for a study to be conducted. Once in that loop a year can go by as if it was a month.

There’s always the argument that highlights dozens of aircraft operators haven’t had this event occur and therefore the finger is pointed at those who have. This argument gets an outing, but it is foolish. It’s like saying – I haven’t had an accident yet, and therefore I’m safe. Foolish.

There are a lot of detailed discussions and a million and one opinions. Taking the big picture, this is a problem that is solvable[2]. What is surprising is the reoccurrence of the problem.


[1] https://www.gov.uk/government/news/aaib-special-bulletin-g-zbjb-inadvertent-nose-landing-gear-retraction-during-pre-flight-maintenance

[2] https://www.federalregister.gov/documents/2019/12/12/2019-26734/airworthiness-directives-the-boeing-company-airplanes

Future Aircraft Systems

I read that there’s lesson to learn from the Maneuvering Characteristics Augmentation System (MCAS) experience that plagued Boeing. And led to fatalities. There’s a lot that has been written about the tragic saga. Much of great value.

It’s true. Aviation advances as the community learns lessons from incidents and accidents. Yes, there’s variability in the effectivity of this learning process. Occasions when oceans are written about one case and dozens of others are given an inappropriate light touch[1]. A trustworthy centralised repository of safety recommendations from published aviation accident reports is a useful tool. A point of reference. In the first months of the European Aviation Safety Agency (EASA) in Cologne, back in 2005, my team established such a database. It’s only possible to track the follow-up of key safety recommendation if there’s a well-maintained administrative system. Safety is often about the intelligent use of data.

Cockpit design, and the human factors issues involved, are without doubt one of the most critical parts of an aircraft. Society is not ready for fully autonomous passenger carrying aircraft. I believe it will happen, in decades to come but the horizon is way off. For certain types of vehicles, autonomy must be the solution given that flight control is beyond human capacities. Here’s I’m thinking mostly of hypersonic and space flight.

For a pilot to exercise responsibility for a flight there’s a need to have, at least, a basic understanding of what a machine is doing. In past times of strings and wires and clockwork instruments that understanding was ingrained knowledge gained from training and experience.

Future aircraft systems will not be easily described as functional blocks that perform well understood and dedicated functions. An autopilot, an autothrottle, autobraking, a flight management system, even an engine. Hybridisation is coming.

That does not mean a pilot must understand the inner working for a multicore microprocessor or complex software algorithm. Flight test pilots being the exception, in this case.

The design goal should always be to make safer systems. Engineering these aircraft systems is not a case of purely fitting together a set of Lego like components. The error made with the MCAS is one that ignored this fact. Interdependencies are manyfold.

Ideally, future aircraft systems, however capable and complex, should be describable, predicable, and ultimately trustworthy. These words sound so simple. One reason this is not simple is that very word – complex. The minute that there’s a massive number of possible combinations and permutations of conditions at may exit boundaries must be set. What’s a little more reassuring is that complexity if far from new in human experience[2].

Just to make the airspace of the future even more complex it’s no longer correct to think of an aircraft as alone and free to make any appropriate manoeuvre. Increasing connectivity, cybersecurity, and artificial intelligence (AI) all come into the mix.

To stay safe, pilots will have to appreciate how constraints and boundaries are managed. This information must be provided transparently and preferable with options.


[1] https://www.iata.org/en/pressroom/opinions/the-safety-paradox-fewer-accidents-greater-responsibility/

[2] https://en.wikipedia.org/wiki/Wheat_and_chessboard_problem

Understanding Conspicuity

It’s a weird word. That’s if you have not come across it before. How it’s used depends a lot on the context. Conspicuity isn’t everyday langauage.

One way to picture this word is to imagine a cyclist on a busy but poorly lit road. This is a case every driver has observed, I’m sure. Let’s consider two distinct cases. One where the cyclist is wearing dark cloths and riding without lights. The other case is where the cyclist is wearing a luminous jacket and is riding with lights. No prizes for guessing which one is the most conspicuous. Not only that, but the one who is less likely to be involved in an accident.

This is a simple two-dimensional space where two vehicles, or more, share a road. Both have a right to be there. However, one road user is much more vulnerable than the other. Being noticed, being seen, is key to a rider’s safety. Not a guarantee of safety. A necessary consideration, if not a mandatory one. Both driver and rider need to see each other for there to be safe operation.

In aviation the situation gets a whole lot more complex. For a start flying objects move in three-dimensional space and at speeds that can differ dramatically. From a static ballon to a fast military jet. Yet, just like driving on the roads the most basic way of avoiding collisions is to see and avoid. Naturally, there are a whole collection of rules of the air that wrap around that requirement. These rules set-up expectations that pilots will behave in predicable ways.

As technology has developed so the reliance on see and avoid has changed. Recently, I have found this is happening on the roads too. Sensors on my new car provide an autobraking function that kicks in when approaching a slower moving vehicle ahead. There’s a tracking function that nudges the steering wheel when drifting across a white line. Both forms of safety automation can be deselected. Do they result in fewer collisions? I don’t know.

There’s another aspect of flying that is an obvious difference from life on the roads. When collisions happen those involved are not going to stay put. Gravity will do its job. If an impact is sufficiently severe then it’s highly likely that one or more aircraft will not be flyable. An incident turns quickly into a catastrophe.

Thus, in aviation it’s vital that not only does each pilot need to know where they are but they need to know about everything around them. The condition of being conspicuous is not optional. It’s best if aircraft are easy to see. Surprisingly, this is far from always being the case. Unlike the lines on the roads, paths in the air crisscross and aircraft can be above and below one another. The geometry involved can get extremely complicated.

In the 1920s, innovations in Croydon[1] led to the world’s first air traffic control system. A growing amount of air traffic meant that a means had to be found to regulate their use of the air space. This was possible because an electronic means of aircraft communication had become viable.

The subject of Electronic Conspicuity[2] has come on in leaps and bound ever since. Finding ways of sharing awareness of everyone’s situation has made aviation safer. Radar and aircraft transponders are an integral part of commercial flying. This story doesn’t stop. I could go as far as to say that this whole subject is still in its infancy. With ever more airspace users demanding access then innovations continue to be absolutely vital.


[1] https://www.flightglobal.com/ops-safety/2020/02/colourised-images-mark-centenary-of-worlds-first-control-tower/

[2] https://www.caa.co.uk/General-aviation/Aircraft-ownership-and-maintenance/Electronic-Conspicuity-devices/

Navigating Change

It’s all too easy to say – it was different in my time. How things have gone downhill. There’s a boring refrain from me, and my baby boom generation, which laments a lost era. What we forget is that all of history is a lost era. Becoming history is a discomforting feeling.

I remember walking around the transport museum at Brooklands in Surrey. Look to one side and there was an aircraft cockpit display that was the latest tech in my days as a young design engineer. It was slightly worse than that in that the retired equipment, covered in dust, was one I worked on in the late 1980s. Sophisticated at the time. Now an item of curiosity.

This weekend, I stood under the last flying Concorde at Aerospace Bristol. Looking up the supersonic aircraft, it remains stunning, impressive, and futuristic. It’s a real testament to the British and French engineers who were so adventurous, creative, and foresighted in its design.

That said, in the end that era came down to money and politics. Just goes to show what the implications are of having made a robust international commitment and finding it impossible to backout. As a purely business adventure, a project like Concorde is difficult to justify. As a cultural icon and industrial marker laid down for all of history to appreciate, it’s momentous. It’s reasonable to say that the success modern-day AIRBUS has roots in this tremendous European collaboration.

Anyway, back to war and more day-to-day concerns. There’s no doubt that having some form of industrial strategy is better than not having one. The trouble is that UK Governments come and go and are incredibly fickle. So, a nice policy document with sound ideas can either spur change or slowly gather dust with equal measure.

Reflecting over the last 40-years and more, the UK has taken a large peace dividend. Defence spending has declined steadily under every political flag. This has led to a focus on fewer engineering projects. A concentration on fewer prestige assets whether in the air, at sea or on land. A gradual cutting of cloth to fit a lesser role in the world.

How do I write is without the predicable lament? It’s a matter of highlighting the downsides of the current position without lapsing into an archaic wish for a return to a bygone era.

One observation I would make here. If I pick up a British aviation magazine of the 1960/70s it’s clear that there’s a huge diversity of small and medium sized enterprises (SMEs) making products that are as diverse as they are spread across the country. Yes, the large aerospace companies have consolidated so that there remains a handful of prominent names. A lot of the iconic British names have disappeared. Consigned to museums. Inward investment has meant that the titans of the past have been swallowed up by international businesses.

There’s a pattern here that is not uniquely British. I’d make the point that one of the most concerning weaknesses is the decline of the large ecosystem of SMEs. Or the precarious situation that is often their fate. These businesses are the smaller fish that swim around the bigger players. They have the capacity to be dynamic and innovative. Even if they are often under regarded and more vulnerable to economic shocks.

Central government can’t always solve problems. That said, they can, at least, take an interest and create an environment where such entrepreneurs can flourish. Reflecting over the last 40-years and more, governments have been immensely ineffective in this respect. Policy documents are great. Where the failing persists is going from words to effective actions.

Aviation Insights

One shilling and seven pence, that’s what a copy of Flight magazine cost in 1960. Today, roughly that’s equivalent to £6. Which is not so far off the weekly cost of a typical printed magazine taken off-the-shelf in a newsagent. Now, Flight is a digital subscription[1] at £22 a month. We consume our News in a different way, but the overall price is not so different.

Spending money in charity shops always contributes to some good cause or another. Certainly, our British High Streets in 2026 are markedly transformed from that of 66 years ago. Fine, if I get hung up on that elegant number. It’s not a bingo call. It’s the number of times I’ve circled the Sun. Circled, that is, while safely attached to this rocky planet.

The young woman behind the counter was chatting to what must have been a regular when she looked up. I pointed an unregarded dusty box on the floor in the corner of the shop. “How much to you want for that box of old aviation magazines”. She looked slightly fazed. Nobody had even thought about pricing them let alone selling them. They had probably been donated as someone emptied the attic of their grandparents. Probably on the verge of going to the recycling bin.

Eventually, we settled on a modest price. She looked me up and down. I’m sure she thought that I was completely mad. That said, charity shop workers, volunteers, must face that colourful situation more than a couple of times a week. Even a day.

What struck me was the first inside page. The weekly editorial could have been written yesterday. It’s titled “Facing it” and reads thus:

“More than one great newspaper has given warning that our nation is living beyond its means – that our export prospects are poor, and that we are taking a commercial thrashing”.

“Bleak prospects for a people who have never had it so good, and one that promotes us to consider how the aircraft industry is facing up to cold reality.”

It went on to highlight that there had been few new aircraft at the Farnborough airshow of that year. It was an October publication[2]. There was a lot of talk about industry and Government cooperation but that this was not delivering.

“And now that the industry is needed, as it has never been needed before, it will not be found unready or unwilling.”

But the lament was about the failings of the Government of the time, and there being no room for complacency. This was 4-years after the Suez Crisis.

Today, we have an increased security threat, much as arose in the Cold War days. Industry and Government cooperation needs to be a lot more than fervent aspirations. We seem to be in the same phase of formulating strategies rather than implementing actions.

Don’t let me paint a picture of gloom and doom. What this Flight magazine had is great stories of British technical innovation. Electronics and control systems were advancing rapidly. Automatic landing systems were being pioneered. Technology applied improved aircraft performance and aviation safety significantly. In fact, in numerous areas Britain was not only leading, but guiding the world.


[1] https://www.flightglobal.com/subscribe

[2] Flight Number 2691 Volume 78.

Regulatory Insights

I can’t remember if my teacher was talking about maths or physics. His scholarly advice has stuck with me. When things get complex, they can seem overwhelming. Problems seem insolvable. So, it’s good to take a deep breath, step back and see if it’s possible to reduce the problem to its most basic elements. Do what could be called helicopter behaviour. Try to look at the problem top-down, in its simplest form. Break it into parts to see if each part is more easily comprehended.

Today’s international aviation regulatory structure, for design and production, follows the arrow of time. From birth to death. Every commercial aircraft that there ever was started as a set of ideas, progressed to a prototype and, if successful, entered service to have a life in the air.

This elementary aircraft life cycle is embedded in standards as well as aviation rules. Documents like, ARP4754(), Aerospace Recommended Practice (ARP) Guidelines for Development of Civil Aircraft and Systems are constructed in this manner. There are as many graphs and curves that represent the aircraft life cycle as there are views on the subject, but they all have common themes.

That said, the end-of-life scenarios for aircraft of all kinds is often haphazard. Those like the Douglas DC-3 go on almost without end. Fascinatingly, this week, I read of an Airbus A321neo being scrapped after only 6-years of operations. Parts being more valuable than the aircraft.

Generally, flight-time lives in operational service are getting shorter. The pace of technology is such that advances offer commercial and environmental advantages that cannot be resisted. Operating conditions change, business models change and innovation speeds forward.

My earlier proposition was that our traditional aviation regulatory structure is out of date. Well, the detail is ever evolving – it’s true. Some of the fundamentals remain. The arrow of time, however fast the wheels spin, mixing my metaphors, remains an immobile reality.

In airworthiness terms an aircraft life cycle is divided into two halves. Initial airworthiness and continuing airworthiness. This provides for a gate keeper. A design does not advance into operational service, along the aircraft life cycle, until specified standards have been demonstrated as met. An authority has deemed that acceptable standards are met.

I’m arguing, this part of the aviation regulatory structure is far from out of date. However much there’s talk of so called “self-regulation” by industry it has not come into being for commercial aviation. I think there’s good reason for retaining the role that a capable independent authority plays in the system. A gate keeper is there to ensure that the public interest is served. That means safety, security and environmental considerations are given appropriate priority.

To fulfil these basic objectives there’s a need for oversight. That is the transparency needed to ensure confidence is maintained not just for a day but for the whole aircraft life cycle. And so, the case for both design and production approvals remain solid. The devil being in the detail.

Aviation Regulations Outdated?

Machines, like aircraft started life in craft workshops. Fabric and wood put together by skilful artisans. Experimentation being a key part of early aviation. It’s easy to see that development by touring a museum that I’d recommend a visit. At Patchway in Bristol there’s a corner of what was once a huge factory. In fact, somewhere where I worked in the early 1980s. Aerospace Bristol[1] is a story of heritage. A testament to the thousands who have worked there over decades.

Fabric and wood played part in the early days. The factory at Filton in Bristol started life making trams. An integral part of turn of the century city life. Carriage work brought together skilled workers in wood, metal and fabrics. It was soon recognised that these were just the skills needed for the new and emerging aircraft industry. The Bristol Aeroplane Company (BAC) was born.

It’s war that industrialised aviation. Demonstration of the value of air power led to ever more technical developments. Lots of the lessons of Henry Ford were applied to aircraft production. Factories grew in importance, employing a large workforce.

My time at the Filton site was in a building next to a hanger where the Bristol Bulldog[2] was originally produced. This was a single engine fighter, designed in the 1920s, in-service with the Royal Air Force (RAF).

Right from the start orderly processes and regulatory oversight formed part of aircraft design and production. The management of production quality started as a highly prescriptive process. As aviation grew into a global industry, the risks associated with poor design or faulty production became all too apparent.

In the civil industry, regulatory systems developed to address the control of design and production as two different worlds. Airworthiness, or fitness to fly, depended on having a good design that was produced in a consistent and reliable manner. So, now we have a regulatory framework with two pivotal concepts: DOA (Design Organisation Approval) and POA (Production Organisation Approval). It took about a century to get here. Now, these concepts are codified within EASA Part 21, FAA regulations, and other national aviation authorities’ frameworks.

Here’s my more controversial point. Is this internationally accepted regulatory model, that has evolved, conditioned by circumstances, the right one for the future? Are the airworthiness concepts of DOA and POA out of date?

This is a question that nobody wants to hear. Evolution has proved to be a successful strategy. At least, to date. What I’m wondering is, now the world of traditional factories and large administrative workforces is passing, how will regulation adjust to meet future needs?

Maybe I’ll explore that subject next.


[1] https://aerospacebristol.org/

[2] https://en.wikipedia.org/wiki/Bristol_Bulldog

Understanding Boeing 787 Avionics

In what I’ve written so far, I’ve taken the humancentric view much as most commentators. The focus of interest being on what the two Air India crew members were doing during the critical moments of this tragic flight. Let’s shift perspective. It’s time to take an aircraft level view.

On the Boeing 787-8 “Dreamliner”, the flight deck has two crew seats and two observer seats. One observer seat is directly behind and between the two crew seats. Since these observer seats are not mentioned in the preliminary report, it’s responsible to assume that they were unoccupied.

In my days working on civil aircraft certification, it was often as a part of a multidisciplinary team. I suppose one of the privileges of working on aircraft avionic systems is that they touch every part of a modern civil aircraft. That meant working with highly experienced specialist in every technical field, including flight test pilots and engineers.

When it came to reviewing aircraft system safety assessments, we’d often put it like this, you look at the aircraft from the inside out and well look at the aircraft from the outside in. Meaning that the flight test team looked at how the aircraft flew and performed. Systems engineering specialists focused on how the aircraft functioned. What was the detailed design, the means and mechanisms. It was by putting these differing perspectives together that a comprehensive review of an aircraft could be established.

Here’s where I need to be careful. Although, I worked on the technical standards1 for complex aircraft systems, I did not work on the Boeing 787 at initial certification.

If I go back 25-years, a major change that was happening with respect to aircraft systems. It was the move to apply Integrated Modular Avionics (IMA). This was a move away from federated systems, where just about every aircraft function had its own box (autopilot, autothrottles, instruments, etc.) There was a fundamental architectural difference between federated and IMA systems.

The Boeing 787 has what is called a Common Core System (CCS). As an analogy let’s think of a time before the smart phone became universal. I had a Nokia mobile phone, a Canon camera, a HP calculator, a Dell lap-top, lots of connectors and pen and paper. Now, the only one that has survived the passage of time is the pen and paper.

So, it is with modern civil aircraft. An Integrated Modular Avionics (IMA) hosts the applications that are necessary for safe flight and landing. The IMA hosts functions that provide, Environmental Control, Electrical, Mechanical, Hydraulic, Auxiliary Power Unit (APU), Cabin Services, Flight Controls, Health Management, Fuel, Payloads, and Propulsion systems.

Information is digitised (sensors, switches and alike), processed and then acted upon. General Processing Modules (GPM) inside the aircraft CCS perform the functions needed. There’s an array of these GPMs and redundancy to provide a high integrity aircraft system.

An aircraft’s Fuel Shutoff Valve Actuator depend on the above working as intended in all foreseeable circumstances. No doubt the accident investigators are undertaking an analysis of the Boeing 787 avionics architecture to gain assurance that it worked as intended.

  1. Standards: EUROCAE started a working group (Number 60) in September 2001, which was tasked to define guidance. Later, in November 2002, there was a merge with an RTCA steering committee (Number 200). ↩︎

Fuel Control Switches

I’ll not go any further than the investigation report that’s in the public domain. The Air India AI171 Boeing 787-800 Preliminary Report is published for all to read. The aircraft’s Enhanced Airborne Flight Recorder (EAFR) has been replayed. Sadly, this report raised questions as much as it closes down erroneous theories.

It warrants saying again, and again. My thoughts are with the friends and families of those affected. They deserve to know exactly what happened and as far as is possible, why. Not only that but the global travelling public need to be confident that any necessary corrective action is being taken to prevent a recurrence of such a rare fatal accident.

What requires a one or two words is one of the commonest ways we interact with electrical and electronic systems. The humble switch. In fact, they are far from humble and come in lots of shapes and sizes. The general idea is that a mechanical device, that can be manipulated with a purpose in mind, is used to control the flow of electrical current. There are non-mechanical switches, but I’ll not go there for the moment.

I remember conversations with my aircraft electrical engineering colleagues. It goes like this – you deal with the small currents (avionic systems), and we will deal with the big ones (power systems). Also, a mantra was that all electrical systems are, in part, mechanical systems. Switches, cables, generators, control valves, relays, bonding, you name it, they are in part, mechanical systems. In the past traditional electrical engineers got a but jittery when faced with “solid state” controls (semiconductors).

Switches. I’ve seen the words “cognitive engagement” used. In simpler terms, by design, pilots interact with switches with a purpose in mind. Equally, as in the world of human factors, unprotected switches can be operated in error, unintentionally or by physical force.

So, what are the chances of two protected Fuel Control Switches moving, within seconds of each other, at the most critical phase of an aircraft’s flight?

[There is a discussion to be had in respect of timing. Remember the record from the flight recorders is a sampling of events. The sampling rate maybe as low as one per second. Note: EASA AMC2 CAT.IDE.A.190.]

These cockpit switches are designed and certificated to perform as intended under specified operating and environmental conditions. That’s a wide range of vibration and temperature (shake and bake).

Switch operation is indicated by their physical position[1]. In addition, operation of these switches will be evident by cockpit indications. The concept being that a flight crew can confirm that the Fuel Control Switches have moved by their effect on the engines. If a crew need to take corrective action it is in relation to the information presented to them by the engine instrument system.

The report makes it clear that both mechanical switches transitioned from ‘RUN’ to ‘CUT-OFF’ almost immediately as the aircraft became airborne. That is a worst-case scenario. The time available to recognise and understand the situation, for training to kick-in, and then to take appropriate corrective action was insufficient.

This leads me to think that there may be a case for disabling the Fuel Control Switch function up until at least an altitude where aircraft recovery is possible. Now, these switches need to be available up until the V1 speed is achieved (Example: aborting a take-off with an engine fire). After that an aircraft is committed to becoming airborne.

I suspect the reason there is no inhibit function is the possibility of adding another potential failure condition. Inadvertent and unrecoverable disabling of ‘CUT-OFF’ are scenarios that would need to be considered. No doubt a reasonableness argument was used. No crew would shut-down both engines down immediately an aircraft became airborne, would they?

POST: I hope I haven’t given the impression that this is a case of simple switches and wires. The Boeing 787 is a digital aircraft.  Mechanical fuel technology plays its part but control functions are digital.


[1] Designs that offer switch illumination are not used in this case.