A sudden unexpected total engine power loss is a helicopter pilots worst nightmare but there is only one possible action. Get into autorotation NOW!
But what if the power loss or autorotation are imminent rather than right now? How should the pilot fly the aircraft to maximise their chances of survival?
In this article, we look at the causes of total power loss and how that relates to single and twin engine operations. We then look at how the imminent loss of all engine power should be planned for, managed and flown in the air. We review some relevant incidents and accidents that we can take lessons from and look to set a golden rule for such emergencies.
Let’s get stuck in.
Contents
Reasons to plan to autorotate
Before we discuss how we are going to handle an imminent autorotation, let’s consider some scenarios that might lead us to that point. We are not going to consider a catastrophic sudden double engine failure (twins) or sudden single engine failure (singles) but rather something that gives the crew a chance to act before total loss of engine power. What scenarios are there?
- Fuel starvation
- Fuel contamination
- Uncontained first engine failure damage to second engine
- Unrelated failure of second engine after losing first engine
- Icing
- Tail rotor failure
- Uncontained cabin fire
Fuel starvation
Helicopters are operated with minimum landing fuel. In normal conditions this is never used; it is a Mayday call if you end landing below it! It is exactly the same on aeroplanes and the recent incident on a Ryanair flight in 2025 (see here) is a demonstration of having to make that call when you are really low on fuel.
If a helicopter is flown to a lower fuel state than the required minimum, it is at risk of a flameout on the engines. Some helicopters are designed in such a way that the fuel available to each engine is slightly different so the engines will flameout with a slight delay between them.
Preventing simultaneous flame out
For example on EC135, the supply tanks with provide fuel to the fuel intake lines for the engines are of slightly different sizes at the bottom. This is done using a foam cutout in the right tank. The fuel cell that drops in there has a matching notch. The difference is actually only 4 kg of fuel though (just over 2 mins of fuel burn on one engine).

That theoretical time difference might be much shorter in reality. In the accident involving G-SPAO on 29 November 2013, the actual time between the failure of each engine due to fuel starvation was only 32 seconds. Tragically this was not enough for the crew to correct the fuel problem, but it’s a good design feature to have the delay.
But this delay does gives future crews a window to prepare for the second engine failure. What should they do? We are going to explore this later.

Missing in the certification?
Strangely, this delay is all a manufacturer choice. The design criteria in the Certification Specifications (CS-27 up to 3175 kg and CS-29 above 3175kg) do not explicitly require that the design must ensure that both engines do not run out of fuel at the same moment. They do however hint its not a good idea. The CS (29.953) states:
…the failure or malfunction of any engine, or the failure of any system that can affect any engine, will not…
…Prevent the continued safe operation of the remaining engines…
Arguably this means should one engine fail due to fuel starvation, the other one must continue to run. But that is a stretch. If you look at AW139, AW109, S76 and S92 each side of the fuel system is identical and could theoretically fail at the same time.
Fuel contamination
In most helicopter fuel systems, fuel is stored in connected systems such that a fuel contamination problem will affect both engines. There are several possible fuel contamination issues:
- Water
- Incorrect fuel
- Fuel treatment agents
Water
Should excess water get in the fuel there is a risk of it freezing up in the fuel system or encouraging growth of microorganisms. Water content in fuel is routinely monitored during fuel sump drainage and testing (Shell caps). Some fuel additives (FSII) are also designed to bond with the water to prevent it freezing. Engines also have to be certified (CS29.951(b)) to run with some water the fuel (0.02% by volume).
However, should that water get frozen up in the fuel lines, there might be a gap between one engine failing and the other engine fuel lines getting blocked, giving the pilot a window of opportunity.
Incorrect fuel
Should the aircraft receive the wrong fuel, unfortunately this would likely lead to a simultaneous failure of both engines so bad luck to the pilot for this article!
Fuel treatment agents
As mentioned above, fuel systems can get contaminated with a microbial growth which grows in fuel. Preventative maintenance using a dose of biocide can be used to kill the microbes and stop it causing engine issues.
However, if the dosage of this additive is not correct, this can in itself cause issues. There are 2 commonly used biocides in aviation fuel applications: Biobar and Kathon. In several incidents, the incorrect use of Kathon has led to engine flame out.
For example on 28 March 2009 an EC135 JA135E operated by a Japanese hospital experienced a flame out of one engine whilst transporting a patient between some islands. The crew made some errors in continuing past a suitable landing site and flew on across a large body of water. The remaining engine was on the verge of failing due to the same issue that caused the first flame out.
The investigation revealed the engine internals had a light contamination with sea salt which is unsurprising for Japan. During a recent maintenance event, the fuel had been dosed with Kathon as required by the maintenance programme. However, due to the instructions for the Kathon being only in English and the Japanese maintenance personnel being unfamiliar with the dosing in parts per million, the dosing was grossly excessive.

The Kathon formed a gooey gel as it was heated in the combustion chamber and it stuck to the salt contamination inside the engine, interrupting the normal engine flow and flaming out the engine.
But again, the pilot had an opportunity to plan for the second engine failure – what should they do?
Uncontained first engine failure leading to damage on second engine
As we have seen above, helicopters certified to Category A (multi-engine) are required to be designed such that a failure of one engine will not lead to the failure of the other. Design features such as a titanium firewall and engine structure should ensure that damage stays inside the respective engine bay. However, a crew’s luck can sometimes run out and ejected components or a raging fire can jump into the neighbouring engine compartment.
As discussed in our article on engine malfunctions (Lessons in how to manage a helicopter engine malfunction) we looked at checking for dangerous indications.
However, this due to the stringent design criteria used for helicopters this type of failure is extremely rare.
Unrelated failure of second engine after losing first engine
The loss of the remaining engine or engines following the failure or malfunctioning of the first engine would seem like terrible luck but unfortunately fate sometimes intervenes. This is a scenario introduced by simulator instructors trying to induce an autorotation by adding a second malfunction. An engine fire on your only remaining engine is a brilliant conundrum for a crew to solve!
But tragically, it can be fate of the crew’s own making that leads to a failure of the remaining engine following the first engine failure. Errors or misunderstanding can lead to a wrong-engine shutdown. This is still relevant to our discussion as crews can fly defensively and prepare for the failure of the remaining power unit at any time. Let’s review a few examples:
- Incorrect engine manipulation – EC135 HA-ECE – The pilot shutdown the serviceable engine after a FADEC engine control failure on the other engine
- Death of Rhodri Leyshon – Merlin HC Mk4 ZJ135 – as we discussed in our article about engine malfunctions, https://rotarywinggeek.com/lessons-in-how-to-manage-a-helicopter-engine-malfunction, the left hand pilot shut down the two serviceable engines following an incorrect understanding of the original engine malfunction.
- Incorrect engine shutdown – EC145 N164DU – The pilot in this incident was confused by the indications of the first engine malfunction and again shut down the serviceable engine
- Incorrect engine manipulation – Bell 429 PK-WSX – The pilot had an engine control unit malfunction on the number 1 engine but moved the throttle of the number 2 engine. Subsequently there was insufficient overall power to maintain level flight

Icing
An accumulation of ice on a helicopter can lead to an autorotation for several reasons. For example, the escape route from icing might be a rapid descent. However, as we will see later when we look at cabin fires, an autorotation might not be the best option.
However, an engine failure induced by icing could be soon followed by other engine suffering the same fate – an excellent opportunity to apply the methods we are going to talk about later. There are some notable examples were ice has led to a failure of both engines:
- H145 LN-OOS – 20 November 2021 – Whilst waiting for a patient in snowy conditions, icing built up around the Inlet Barrier Filter (IBF) system. After the patient finally arrived the helicopter hover taxying over snow to carefully pass some over some wires. One engine failed, due to ingestion of ice that had formed on the underside of the IBF. The aircraft landed immediately and then the second engine failed
- SH-3H Sea King N612CK – 18 January 2006 – During low level flight at 200 ft above ground in poor weather conditions, both engines failed due to ice and snow ingestion. The aircraft did not have the optional snow/ice deflector fitted and the icing conditions were known to exist in the area.
Tail rotor failure
Should the tail rotor completely fail, one method of making an emergency landing is to land via an autorotation and land without the engines driving the rotors. This eliminates the anti-torque force requirement the tail rotor normally needs to provide. This is the appropriate procedure on many types (EC135, H145).
On another Japanese EC135 JA31NH on 9 December 2007, a fenestron pitch control failed due to maintenance error, leading to a complete loss of tail rotor thrust. The pilot attempted an approach to a helipad but lost yaw control and crashed. Subsequent investigation showed that a landing via an autorotation to a runway should have been survivable with the malfunction. A planned autorotation was the best way out of this problem.

Uncontained cabin fire
A cabin or cockpit fire is a helicopter pilots worst nightmare. This is particularly true if flying at altitude.
An autorotation is one way to descend quickly so it might seem like a good idea for getting down quickly with a fire. This might make this scenario worthy of inclusion in our discussion. But is the autorotation the best way to descend?
An autorotation involves careful management of collective position, airspeed and bank to safely descend. This is actually quite a high workload. How else could we descend rapidly?

We need to reduce the force upwards whilst forcing our flight vector downwards. The key is bank. If we roll to a reasonable angle of bank, say 60 degrees, we reduce our effective lift in the vertical direction substantially. But we do not have to worry about rotor speed. We can also lower the collective and lower the nose and descend in relative stability with a very high rate of descent (multiple thousands of feet per minute). If we fly out of balance and open the window we can also generate a lateral flow of air to clear out the smoke.
So a spiral descent is the right answer here, so we are not going to include this scenario in our imminent autorotation discussion!
So let’s talk about what to do if an autorotation might be in our future
The plan
As we have seen above there are many reasons we might have forewarning that we need to autorotate. What can we do to plan for a successful landing?
A successful autorotation needs to conclude with a successful engine off landing, so let’s work backwards from the end.
The landing site
For a successful engine off landing we need:
- A reasonably flat surface that can support the weight of the aircraft
- An into wind component to minimise ground speed
- A nice long area to give us options for an undershoot or overshoot
- For skidded helicopter a very hard surface that will not flip us if we do not land quite straight
- Sufficient lighting if at night
The ideal is of course a runway but we might have to take second best. So the first element of the plan is to find somewhere suitable to land.
The imminent autorotation might happen at any point dependent on the malfunction, so we might need to choose a series of ever improving locations until we get to the gold-plated dead-cert airfield with an into runway.
Sometimes even a runway isn’t enough. For example, during an incident on a Bell 407 N512TP, an engine off landing practice to a runway at night went wrong when the pilot misjudged the height of the check, level, cushion.

The descent
Once established, an autorotative descent is relatively benign but manoeuvre is limited. In basic training we are taught advanced autorotations where we vary speed, angle of bank and rotor speed to adjust our aiming point and these may be needed. But a middle-of-the-road basic autorotation is best. We should plan our entry to achieve this type of autorotation.
A stable autorotation also gives us time to decide if its going to work. For some of our malfunctions (the tail rotor failure in particular) we are not committed to landing until we retard or shut down the engine. Should it not look like it is going to work we could go around before committing to engine shutdown.
But in order to have time to make this choice, we need altitude. The higher we are, the more chance we have of completing any necessary emergency actions or decisions. So start from as high as possible.
More importantly do not throw away height before the autorotation. You might not get it back.
This is particularly true at night, particularly if operating without night vision equipment. A low level total engine power loss is a very challenging failure at night. Having some time to establish in autorotation, action any drills (such as restoring power to the radar altimeter (Bell 429/EC135/H145!) and refining the landing point might make the difference.
In the EC135 accident on G-SPAO we have already looked at, the pilot started a descent after the first engine failed. The pilot had lost also 500 ft before the second engine failed. Those extra few hundreds of feet might have allowed the pilot time to successfully enter autorotation.

The entry
We want our nice stable autorotation to get us to the landing phase and to achieve that we need to make a smooth entry. If we have the option to choose our moment of entry into autorotation we can manipulate the flight parameters to make it straightforward.
Sadly in many accidents with progressive multiple engine failures, the aircraft never reached successful autorotation. Something went wrong with the entry phase. This could be due to a lack of altitude (it is really hard to lower the lever when the ground is rushing up at you) or a delay in lowering the lever due to startle. The loss of ZJ135, N164DU and PK-WSX are all examples of this.
For a smooth autorotation entry we want a speed above the normal autorotation speed so we have the option to use flare effect to maintain rotor speed if necessary. We also want straight flight so turning effects do not complicate the issue. Entering autorotation from a climb is not a good idea due to the collective position so level or descending flight should be the preferred option.
If we still have some engine power at the time, it makes the autorotation engine easier as we do not have to worry about low rotor speed as much. Do not pre-emptively shut down engines as the initiation of the autorotation. Only shut down the engines after getting into stable autorotation and being confident of reaching your intended landing point! It is amazing how many times some pilots do actually chop the throttles to initiate a pre-emptive emergency autorotation in the simulator!
Plan summary
Let’s look at our plan in summary and come up with a set of golden rules for dealing with imminent power loss:
- Plan – Plan for where you want to land and where you are going to land if you lose power on the way there
- Look for hard, flat, long, into-wind and lit
- Plan to use a straight forward basic autorotation
- Preserve – Preserve height where possible. Height is time
- Power – Do not electively shut down engines until you are sure of making your landing point
Fly safe
- Preparing for complete loss of engine power in helicopters

- Lessons in how to manage a helicopter engine malfunction

- Light twin helicopter AFCS – Have Airbus won the race?

- Maintenance by pilots – can the training be improved by sharing?

- Flight simulation revolution – A new method for matching training need to simulator capability

- Helicopter Single Engine IFR – New horizons

- Making the grade – understanding climb gradients in the go around

- Unfair Skies: Restrictive helicopter instructor rules and how to fix them

- How to create an instrument rating instructor (IRI) – A helicopter anomaly

- The evolution of Category A Helipad procedures – A strong foundation for VTOL to learn from?

- Strips vs dials – Which is better?

- Under the weather – are UK HEMS weather rules broken?

- Mastery of the GTN 750 – Ten things you should know

- Checking anomalies – The weird requirements of helicopter proficiency checks

- It’s all about the switch – How helicopter designers need to think about the human in the cockpit



Leave a Reply