Recent accident reports have highlighted that understanding what has gone wrong is fundamental to safely managing emergencies in multi-engine helicopters. Whilst type specific training is essential, there are some general principles which can be applied to all multi-engine helicopter engine emergencies.

In this article, we look at what can go wrong with helicopter engines and review some of the principles of how identify and deal with the malfunctions that can occur. We look at some incident reports to highlight how the principles can be applied and provide some scenarios that can be used by instructors to train and develop the skill of pilots in dealing with the unexpected.

It’s a long article, so grab a cup of your favourite beverage and settle in. As always, the manufacturer’s procedures have precedence. Nothing in this article should be controversial, but where the manufacturer says different, they win.

Contents

Principles of engine malfunction management

So we can stay focused on the goal, let’s list the principles for managing an engine malfunction first, then we will outline how they are derived.

  • Speed is life
    • When rotor speed is out of limits, contain that first before anything else. But the right airspeed is important too
  • No rush
    • When an engine has failed, there is normally no rush to shut it down
  • Dangerous indications
    • Make sure the engine(s) that are still running are healthy before looking at the bad one
  • Confirm, confirm, confirm
    • Always, always cross check critical switches before operating
  • Memory is faulty
    • Only use memory drills to stabilise the situation
  • Idle first
    • Never go straight to off, if there is an intermediate setting
  • High rotor, high engine
    • When the rotor speed is high, the high engine is usually at fault
  • Low rotor, low engine
    • When the rotor speed is low, the low engine is usually at fault
  • Oscillations are confusing
    • Do not rush to conclusions about which one is causing it
  • Know your aircraft
    • Know what causes certain cautions and what does not

What can go wrong

Helicopters are complex machines. The turbine engines that power multi-engine helicopters are masterpieces of engineering but just like any machine, they can malfunction. Without properly functioning engines, it is a one way ride to the surface.

In several accidents, this ride has been uncontrolled leading to a hard impact and loss of life and/or serious injury. In many of these accidents, with the benefit of hindsight, we can see how the outcome might have been different. We need to learn from these incidents and contain the next emergency so that we can walk away after landing.

Trying to provide emergency procedures that work for every multi-engine helicopter is inappropriate but there are general principles that can be applied as part of a fault identification and hazard management process that apply across the spectrum of aircraft. But first we need to know what types of failure we need to be ready for. Let’s examine some of the main groups of failures:

  • Engine failure – flameout
  • Engine failure – mechanical failure
  • Engine fire
  • Engine runaway – control malfunction
  • Engine runaway – fuel malfunction
  • Engine speed oscillation
  • Engine lubrication malfunction
  • Engine indication malfunction

Engine failure – flameout

A flameout is a rundown of an engine without a mechanical failure like a broken component. Crucially the engine may be intact and may be in state where it can be restarted. Of all the groups above this is is the only one where restart should be attempted unless a reversible cause is identified.

Causes

Why would an engine flameout?

Fuel starvation

Without fuel an engine cannot run. But there are many causes for that loss of fuel. Running out fuel is an obvious cause, but more fundamentally it is a lack of fuel in the right place in the aircraft. As occurred in the loss of EC135 G-SPAO on 29 November 2013, there was fuel on the helicopter, but not in the right fuel tanks leading to a double engine flameout. A similar but non-fatal incident occurred on BK117 B2 ZK-HJC on 5 May 2014.

The EC135 fuel tanks – on G-SPAO there was fuel left in the main tank but not the supply tanks leading to a double flameout – AAIB Report

Fuel starvation could also be caused by intentional or unintentional closing of fuel valves. Whilst not a complete flameout, a birdstrike on an S76C++ N748P on 4 January 2009, led to the power levers being retarded and the engine fire T-handle becoming unseated.

Wreckage of S76C++ following birdstrike – Aviation Safety Network
Fuel contamination

In another EC135 incident on JA135E on 28 March 2009 in Japan, the flameout of one engine was due to excess anti-fungal treatment agent in the fuel. This excess agent left deposits which in combination with atmospheric salt build up from flight near the ocean, blocked the fuel nozzles. Incidentally, nearly identical incidents have led to double flame outs on large airliners – see AAIB report on G-POWN on 26 February 2020

Fuel system contamination – Accident report
Ice / Water ingestion

If an engine ingested a lot of ice and/or water the combustion process can be stopped leading to a flameout. As covered by Pilots Who Ask Why, this occurred on an H145 LN-OOS operating in snow in Norway where ice which had built up on the Inlet Barrier Filters (IBF) was sucked into the engines causing a double flame out.

Ice build up under the IBF on H145 – Pilots Who Ask Why

Engine failure – Mechanical

Instead of just flaming out, an engine can stop because something breaks inside. This could be in the reduction gearbox as on EC135 HB-ZUI on 20 January 2024. In that incident a manufacturing defect led to a gear in the reduction gearbox breaking up.

Extract from incident report

In another incident on S92 LN-OMI on 5 June 2023, an engine failed with a bang (remember that!) due bolts failing in the drive attachment. The bolts had possibly been over-torqued on installation.

Extract from incident report

Engine failures due to lubrication issues are covered later.

Engine Fire

An engine fire is a slight anomaly in this list. The engine has malfunctioned but otherwise be running relatively normally with normal indications. And of course an engine is always on fire on the inside. We have a problem when there is fire where is not supposed to be.

In most helicopters, a “fire” is actually detected as an abnormal increase in temperature in the engine bay. This can be detected by fire wire, fire temperature probes or other similar systems. Typically this will have it’s own indication to the crew.

A common cause of engine fires is a breakdown or failure of a bearing. This occurred on an EC145 N911MK on 26 January 2017 and on two S61, G-BBHM on 15 July 2002 and G-BEID on 13 July 1988.

Fire damage on N911MK – NTSB Docket

But an “engine” fire can be something else entirely. An incident on an EC135 N109BC that we covered in a recent article was actually a fire which was burning in the air conditioning unit structure, although it was likely caused by an engine malfunction.

Extract from the Airworthiness Group’s Factual Report – NTSB

Engine runaway – control malfunction

There are two elements to engine control – the brains behind that control which we will cover now and then the mechanical control of that fuel which is next.

Should the control system malfunction, a bad command will be sent to the fuel system leading to a runaway up, down or in oscillation. The typical actions are to use whatever reversionary control system that has been provided. On H145 this is the “Ultimate Backup Mode” and on EC135, AW109 and Bell 429 by manually controlled throttles/power levers (sometimes with remote control as on AW109).

But occasionally, the change to those reversionary controls can be done inadvertently leading to the failure of one or both engines. This happened twice to EC135 P1 in the USA – N44NY on 3 December 1998 and N312SA on 7 July 2018.

Extract from NTSB report – Aerossurance

Engine control – fuel malfunction

In contrast to a control malfunction, the actual system which delivers the right amount of fuel to the engine can go wrong. In this case, reverting to a manual control will not help as the bit you are controlling is actually broken. The engine speed will freeze, but this could also occur with a control failure.

This could be confusing to a crew but this possibility is covered in emergency procedures. For example on H145 and Bell 429 if the reversionary control mode does not work, the engine is shutdown as a failure of the Fuel Management Module (FMM) is suspected.

Extract from customised Bell 429 emergency checklist

Engine Speed Oscillation

A particularly confusing situation can occur if the control system or fuel system enter an oscillatory mode where engine power rises and falls cyclically. As the “good” engine(s) will try to compensate, actually trying to establish which engine is the problem child can be extremely difficult.

Of note, the oscillating behaviour can be a known response of the engine control system to an overspeed event. This is fairly typical on Pratt & Whitney 200 series engines.

Engine lubrication malfunction

With lots of moving parts, adequate lubrication is needed in turbine engines to prevent metal-on-metal contact. Should lubrication be interrupted to parts of the engine, a failure can result. The failure of engine bearings mentioned earlier were the result of oil not reaching those bearings, leading to an engine fire.

The same oil starvation and bearing failure, can lead to some very confusing indications. As we covered in our article about First Limit Indicators (FLI), loss of oil and bearing failure can lead to a rising engine temperature without causing a fire. Due to a failure which was nearly identical to N911MK, on 8 September 2017 N146DU was lost due to oil starvation of a bearing.

However, a loss of oil to the entire engine, perhaps due to seal degrading will be catastrophic to the engine – there is no-run dry capability for a turbine engine unlike some gearboxes.

Engine indication malfunction

The last group of engine malfunctions we are going to look at is an indication failure. A failure of a sensor or display could lead the crew to think something is wrong with the engine itself. Salt water ingress into delicate electrical control modules can also cause this issue. On 23 December 2008, AW139 G-CHCV expired a complete loss of number 2 engine indications along with other display and warning system faults. The issue was traced to unfiltered air from underneath the helicopter being directed to cool the avionics bay.

Corroded control board on AW139 – AAIB

Principles of managing engine malfunctions

So now we have looked at the breadth of what might go wrong, let’s expand on the principles established earlier.

Speed is life

Whilst helicopters can hover with no airspeed, the speed of the rotor and the airspeed are inextricably linked when it comes to managing engine malfunctions. Without appropriate rotor speed and airspeed, the safe continued flight of the helicopter is not assured.

The first action of a pilot following any engine malfunction is to reach a safe flight condition. Unless an immediate landing is possible, rotor speed must be maintained in the correct range to sustain flight. There are many accidents where this did not occur. As an example, in the incident mentioned earlier on N146DU, the crew had an engine malfunction, shutdown the wrong engine but then never got into a stable autorotation.

Wreckage on N146DU showing intact rotor blade showing it was not turning on impact – Aerossurance

But airspeed is important too. Following an engine malfunction, power may be limited, so achieving an airspeed where the power requirements match the power available from one engine is important. For example on Bell 429 the speed range following an engine malfunction is VY to VNEOEI.

No rush

When an engine has failed, there is generally no rush to shut it down – it is already stopped! Provided the other engine has taken up the load and any required flight manoeuvre has been completed, there is no rush to action a shutdown drill. Actioning such drills below a set height is often prohibited in commercial operations unless there is clear overriding reason to do otherwise.

Rushing to shutdown the engine and making errors while doing so has been the subject of alot of research. It even has an acronym – Propulsion System Malfunction Plus Incorrect Crew Response (PSM+ICR). There is an excellent article in Flight Safety Digest which covered the topic in 1999.

Similarly, if an engine malfunction leads to an engine operating at fixed power, there is also generally no need to rush. The fixed amount of power is better than it being the only power so take your time in getting the subsequent drills correct.

This rushed shutdown of the wrong engine occurred on EC135 HA-ECE on 31 July 2008 (report automatically translated to English from Hungarian). A FADEC engine control issue on right engine but the left one was shutdown. Again it is worthy of note that the pilot never successfully entered autorotation.

Wreckage of HA-ECE

Several more of the principles below focus on this area.

Dangerous Indications

A common mantra for helicopter crews following an engine malfunction is check for dangerous indications. As mentioned earlier, an abnormal NR is dangerous and needs to be remedied before any engine related actions. But the search for information in the cockpit needs to extend further. Is there a fire? Has the engine failure caused damage elsewhere? Is the remaining engine(s) working?

In the latter case, it may be the case that the remaining engine was intentionally not working. During a training exercise at Aberdeen airport on 10 October 1982, an SA330J G-BJWS was conducting engine failure training with the number 2 engine intentionally retarded to idle. When the number 1 engine caught fire and failed. There was insufficient time and height to either restore the number 1 engine or enter autorotation.

During the fuel contamination incident in Japan that was mentioned earlier on JA135E, the crew focused a lot of their attention on the failed engine. They spent a lot of the remaining time airborne trying to repeatedly restart the engine. Had they looked carefully at the remaining engine, they may have noted some abnormal indications. Although they did not know it was fuel contamination, this possibility should be foremost in the crew’s minds following the uncommand non-catastrophic wind down of an engine. They did manage to land before the other engine failed but there was ample opportunity to have landed at a much closer site!

Confirm, confirm, confirm

As has already been highlighted, wrong engine shutdowns have occurred and it is vital that a formal cross-check is conducted before an engine is irretrievably shutdown. This is captured in the concept of critical switches. No critical switch should be moved unless it has been confirmed by another member of the crew. For single pilot operations, this might be done by taking a moment to actually read the writing on the switch’s label.

Read the label out before moving a switch

Crews have to be careful though. If the non-flying crewmember points at a switch and says “Confirm number 2?” it is far too easy for the handling pilot to agree “Yes, it’s number 2” reactively. The pilot should be made to look and read the indication. So the response to “Confirm switch?” becomes “I confirm that’s number 2” after the pilot has looked at it.

Some “switches” are obviously critical: engine condition switches, fuel switches. But there are some other controls that are also critical. On helicopters with manual throttles, they are just as critical and must be confirmed before operation. Perhaps Critical Controls would be better term than Critical Switches.

During the fatal incident on N146DU, the pilot moved the throttle of the wrong engine to idle which was not caught by the crew.

Memory if faulty

Some emergency procedures have to be committed to memory as they need to done immediately. But this only goes so far. Once a situation has been contained, time should be taken to get the emergency procedures out and check the memory actions were correct.

In particular, the process of shutting down a failed engine is not often something that has to done with extreme urgency. Taking a moment to pull out the checklist gives the opportunity for the crew to reflect. Having the list of symptoms read out might give the crew pause if something is missing. For example on Bell 429, if the ENG FAIL indicator is not lit, the engine has not failed and it may mean an alternative drill is appropriate (eg engine underspeed).

Despite having near identical power split on the Power Situation indicator, the left shows an underspeed and the right an engine failure

Idle First

Even when an engine control has been correctly identified, there is an another opportunity to catch an error. An engine engine control should never be moved directly to an OFF position if an idle position is available. This gives the crew a moment to check and confirm they have the right control before committing to a shutdown.

That being said, the person’s hand moving the control should not remove it from the control until the whole process is completed. This prevents the need to re-identify the control and also prevents leaving the engine in an intermediate state.

During the incident on EC135 T1 N109BC on 28 August 2023 which we have covered before, the pilot set a malfunctioning engine to idle but never followed through to switch it off. This error was part of the subsequent accident sequence that led to the fatal crash of the helicopter.

Wreckage of N109BC

High rotor, high engine

As we have already mentioned, containing the rotor speed is one of the first priorities for the pilot. This is normally done by raising the collective.

However, during those first critical moments, it is vital that the engine that is driving the rotor up is identified. Once the other engines take up the load, identifying the trouble engine needs to be done carefully by looking at indications and gently exercising the collective. Sometimes its really clearcut (see below) but making the correct assessment is very important for what comes next.

Rapid rise of number 2 engine is causing the rotor overspeed here

Low rotor, low engine

Should the rotor speed be drooped down below normal, the low engine is likely to be the problem. Imagine an engine has failed early during a helipad take off. To achieve the recovery to climbing flight, the collective is raised which might droop the rotor speed. The low engine is the problem.

Oscillations are confusing

Should an engine develop oscillatory power behaviour, its output will fluctuate up and down. This will in turn be compensated for by the good engine(s). This means it is very challenging to identify the problem engine.

Normal procedures are to watch carefully and apply the principles we have just looked at “High rotor, high engine”. The engine which drives rotor speed above normal is the bad engine. However, engine response is not instantaneous so the input and response can get out of phase. What can we do?

We need eliminate each engine from the situation. For example, if we made a guess and placed one engine into manual control and the oscillation continues we know the remaining engine is the problem. We just need to be ready to restore engines rapidly! Alternatively an engine could be placed at idle to see if the oscillation continues. This might not be a recommended practice on your type.

This delivers us nicely to our our final principle.

Know your aircraft

It is essential for pilots and crew to know their aircraft. There are various levels of knowledge needed:

  • Must to know – Actions and information that must be committed to memory to safely operate. For example, the immediate actions for an engine fire.
  • Need to know – Actions and information that is important but a task may be achievable without it. For example, knowing that the final action of a hydraulic failure is to land as soon as possible, a pilot could start a descent at the start of an emergency procedure.
  • Nice to know – Information that might be interesting but do not impact immediate performance of the task. For example how a hydraulic system operates in terms of fluid flow through various passages.

Whilst this hierarchy is generally sound, occasionally a need to know or nice to know nugget of knowledge can actually impede safe progress. For example, in the Kegworth Air Disaster the captains need to know knowledge about the source of cabin air from an earlier variant of the 737 led to incorrect application of procedures and the shutdown of the wrong engine.

Review – Death of Rhodri Leyshon

Now we have covered the principles lets apply them to a recent incident. On 4 September 2024, Merlin helicopter ZJ135 crashed following an uncontrolled ditching following loss of power from all three engines. Tragically, the handling pilot Lt Rhodri Leyshon lost his life during the incident. We can learn from what happened to try to ensure such a thing cannot happen again.

Lt Rhodri Leyshon – FAA Memorial Church

Technical failure

The aircraft was operating at night to an aircraft carrier. The incident began with a technical failure in the number 2 engine fuel unit which led to an increase in fuel flow on that engine (Engine control – fuel malfunction from our list above). This led to the engine torque rising and driving the rotor speed higher.

The Merlin systems identified the engine was malfunctioning and posted an ENG FAIL warning. This was seen by the crew and called out. However, the engine had not actually failed and the aircraft warning system did not identify which engine it referred to.

Incorrect diagnosis

The crew aborted the approach they were conducting to the carrier to work the problem. During the diagnosis phase of the emergency handling, the crew latched onto the engine failure warning and assessed that a double engine failure had occurred.

Extract from Service Inquiry – MOD

Double engine shutdown

During the approach back again to the aircraft carrier, the non handling pilot shut down both the number 1 and number 3 engines directly to OFF. The Merlin engine control switches (called “Cooker knobs” colloquially by the crews) have a detent at the idle position.

The malfunctioning number 2 engine attempted to take up the load of the other engines but reached an overspeed condition due to the excessive fuel. The overspeed protection system automatically shut the engine down.

There was insufficient time and height for Rhodri to establish autorotation and the aircraft impacted the sea with a high rate of descent. Rhodri was incapacitated during the impact and did not escape the aircraft. The other crew exited through windows and were rescued.

Application of Principles

In the spirit of learning from tragedy and with the benefit of hindsight, lets review the principles and see how we might handle the situation differently.

Speed is life

During the initial phase of the emergency, the rotor speed rose to 107% which is above the normal datum. Had the principle of containing rotor speed been applied the crew might have realised that something was driving up the rotor speed and concluded that a double engine failure was not the likely cause. The low engines (1 and 3) were not at fault here.

No rush

The crew correctly made time for themselves by aborting the landing so they could deal with the problem. However, for reasons unknown, the non handling pilot rushed to shutdown 2 engines when it was not necessary at the time. Dead engines are dead engines. There was no rush to secure them.

Dangerous indications

The high rotor speed was a dangerous indication. That should have been addressed. As can be seen from the SMD, the ROTOR RPM warning was higher than the ENG FAIL warning. This is a common design philosophy in emergency warning systems. Deal with the top warning or caution first.

Extract from Service Inquiry – MOD

Confirm, confirm, confirm

Whilst the cockpit audio is redacted in the Service Inquiry, it is apparent that the non handling pilot did not confirm the operation of the engine condition switches before switching them off. It was a highly stressed environment at night at low level over the sea, but a short pause to confirm the action might have caught the error in time.

Memory is faulty

As has been discussed already, once the situation is contained, subsequent actions should be conducted using a checklist. Again, this might have prompted the crew to re-assess their diagnosis when the expected ENG FAIL cautions were not present on engine 1 and 2.

Idle First

The Merlin Engine Condition Switches have an idle detent. Had the switch been moved to the idle detent one at a time, the change in cockpit indications (eg the opposite engine spooling up to take the load) might have triggered a re-assessment.

Merlin Engine Condition Switches (Mk3)

High rotor, high engine vs low rotor, low engine

The rotor speed was higher than normal. Aside from an autorotation (not the case in steady level flight) the only cause is an engine driving it up. Had this been noted, the diagnosis may have been different.

Oscillations are confusing

Whilst the engines were not actively oscillating in this case, the assessment of which engine was driving the problem was still needed.

Know your aircraft

The fact that conditions other than an engine failure could generate an ENG FAIL warning were not generally known about my Merlin crew. However, the fact that ENG 1 FAIL and ENG 3 FAIL cautions were not present should have been known to the crew. The triggers for any caution should be captured in type rating training. They are a need-to-know item that has perhaps in the past been a nice-to-know.

Incident summary

In summary, a lot went wrong on the night of 4 September 2024. The reading in full of the Service Inquiry is time well spent. But learning from it is what matters.

Conclusion

They are a set of principles which can be applied to engine malfunctions on multi-engine helicopters. When the principles are not applied, things go wrong. Manufacturer procedures have priority but the principles will assist with containing the situation after an engine malfunction.

Fly safe.


Discover more from Rotary Wing Geek

Subscribe to get the latest posts sent to your email.


Leave a Reply

Your email address will not be published. Required fields are marked *