top of page

A Plume of Black Smoke in the Distance - Lessons from the Essendon Airport King Air Crash

On the morning of 21 Feb 17, I was climbing the external stairs at a large transport depot in the suburb of Melbourne Airport when I saw a heavy plume of black smoke rising to the south-east. With a long-standing interest in aviation, I knew it was in the general direction of Essendon Airport.



I had previously taken Air Force Cadets to Essendon for visits to the Victoria Police Air Wing, Air Ambulance Victoria, a commercial aviation operator and the control tower. I also had two mates working at the airport, so I sent them messages to find out whether they were safe and what had happened.


Information was confused during those first minutes. One colleague insisted that an Air Ambulance helicopter had crashed, while the early response from the airport was simply that the scene was chaotic. Confidence is not a verification method, and the incident was eventually confirmed as something quite different.


A Beechcraft B200 King Air had crashed into the Bulla Road retail precinct beside Essendon Airport shortly after take-off. The pilot and four passengers were killed.

One of our truck drivers witnessed the crash while travelling nearby, and the event was captured by the truck’s dash camera. The footage was terrible to watch, particularly once the scale of the devastation became known.


We activated support services for drivers who had been travelling along the Tullamarine Freeway at or around the time of the crash. Some may have witnessed the aircraft’s final moments, the impact, the fireball or the immediate aftermath, and that exposure had to be treated as a workplace health risk rather than dismissed because the crash did not involve one of our vehicles.


What happened at Essendon Airport

At about 0900h, VH-ZCR departed Essendon Airport on a charter flight to King Island, Tasmania. The aircraft carried one pilot and four passengers.


The Australian Transport Safety Bureau found that the take-off roll was longer than expected. After becoming airborne, the aircraft yawed and diverged to the left of the runway centreline, entered a shallow climb and developed a substantial left sideslip before descending.


The pilot transmitted a Mayday call, but there was no recovery. The aircraft struck a building within the retail precinct and was destroyed by the impact and post-impact fire, while two people on the ground sustained minor injuries.


The ATSB final investigation report found that the aircraft’s rudder trim was likely in the full nose-left position when the take-off commenced. That setting was not detected before departure and significantly affected the aircraft’s controllability and climb performance.


Both engines were likely producing high power at impact. This was not an engine failure, and it was certainly not the helicopter crash confidently described to me while black smoke was still rising over Melbourne’s north.


The ATSB also found that the aircraft was likely about 240 kg above its maximum take-off weight, although this was not considered to have influenced the accident. The aircraft’s cockpit voice recorder did not record the flight because an impact switch had tripped and had not been reset.


There was extensive public discussion about the location of the retail development beside the airport. The ATSB found that two buildings in the precinct exceeded relevant obstacle limitation surfaces, but the aircraft did not strike either of those buildings, and the obstacle limitation surface for the departure runway was not infringed.


The investigation also concluded that the building struck by VH-ZCR was unlikely to have increased the severity of the accident. Without the building, the uncontrolled flight path would probably have continued towards the busy Tullamarine Freeway, creating the potential for further casualties on the ground.



A checklist is only effective when it verifies the actual condition

The most direct safety lesson concerns the rudder trim setting and the role of the pre-flight checklist. The aircraft’s checklist provided opportunities to confirm that the rudder trim was correctly set, but the full nose-left position was not detected.


A checklist is not effective merely because it exists, has been approved or is available to the person performing the work. Its purpose is to produce and verify a required condition before the operation proceeds.


That distinction applies well beyond aviation. A pre-start inspection does not control risk if boxes are marked without confirming the condition of the plant, a load-restraint check does not control risk if nobody physically verifies the restraint, and a permit does not isolate energy unless the isolation has been applied and tested.


Critical checks should identify exactly what must be confirmed, how it will be checked and what result is acceptable. Where the consequence of error is catastrophic, positive verification should replace assumption, memory and visual familiarity.


Experience does not remove this requirement. The pilot held a commercial licence and had more than 7,600 hours of flying experience, but the ATSB’s safety message expressly noted that experienced pilots are not immune to checklist errors.

The same applies to experienced operators, drivers, maintainers and supervisors. Familiarity can improve competence, but it can also make an abnormal condition look routine when a task has been completed hundreds of times without consequence.


The procedure must match the equipment

The ATSB found that the operator did not have an appropriate flight-check system in place for the aircraft. The approval process had not identified that an incorrect checklist was nominated in the operator’s procedures manual, and it did not ensure that checks associated with the cockpit voice recorder were incorporated.


The ATSB did not identify this deficiency as contributing to the crash, but it increased the risk of incorrect checklists being used or applied. That remains an organisational control failure worth learning from.


Procedures must correspond with the actual plant, equipment, configuration and work being performed. A generic procedure, an outdated revision or a document copied from similar equipment can create the appearance of control while leaving the critical condition unmanaged.


Organisations need document control, but document control cannot stop at version numbers and approval signatures. The operational question is whether the procedure accurately reflects the equipment in front of the worker and whether following it will reliably establish the required safe state.


Abnormal cues need predetermined stop criteria

The aircraft’s take-off roll was longer than expected. The ATSB identified the challenges associated with decision-making during a critical stage such as take-off, particularly when the available time to recognise a problem and act is extremely limited.


It is easy to examine an accident afterwards and identify the point at which an operation should have stopped. It is much harder for a person inside the event to recognise an emerging deviation, interpret incomplete information and abandon a task they are already committed to completing.


That is why stop criteria should be determined before the critical operation begins. A driver should know which restraint defect prevents departure, a crane operator should know which ground condition stops a lift, and a production worker should know which guard or interlock condition requires the machine to remain isolated.


“Stop if it does not feel right” is not a reliable control. Defined thresholds reduce the need for rapid subjective judgement when workload, time pressure and task momentum are already working against the person making the decision.


Workers must also know that stopping will be supported. A stop-work rule is worthless if the first person who uses it is questioned about delay, productivity or customer inconvenience.


Findings do not need to be causal before they matter

The aircraft’s likely weight exceedance did not influence the crash, and the cockpit voice recorder failure did not cause it. Neither finding should therefore be presented as an explanation for the loss of control.


They still mattered. One showed that an operating limitation had probably been exceeded, while the other deprived investigators of evidence that may have improved their understanding of the final flight.


Incident investigations should distinguish between causes, contributing factors, risk-increasing factors and unrelated deficiencies. They should not, however, discard a control failure simply because it did not cause that particular event.


If an investigation identifies an expired inspection, inaccurate load information, failed recording system or unsuitable procedure, the organisation should address it on its own risk merits. Waiting until a deficiency appears in the causal chain of a fatality is a fairly expensive method of validating whether it matters.


The impact extends beyond the crash site

A catastrophic event does not affect only the people physically injured. Workers may witness the event directly, encounter its aftermath, receive confronting footage, support affected people or repeatedly review distressing material during an investigation.


Our drivers were working when the Essendon crash occurred. Those travelling on the Tullamarine Freeway could have witnessed an aircraft descending towards them, the impact beside the roadway or the fire that followed.


The fact that they continued driving did not establish that they were unaffected. A person may initially remain task-focused and only begin processing what they have seen after the immediate operational demands have passed.


Current Safe Work Australia guidance recognises witnessing, investigating or otherwise being exposed to a fatality or serious incident as a psychosocial hazard. Exposure can be direct, indirect or cumulative, and the appropriate response must address the actual nature and severity of that exposure.


In Victoria, health under the Occupational Health and Safety Act 2004 includes psychological health. WorkSafe Victoria’s guidance on violent or traumatic events identifies serious transport accidents, workplace deaths and indirect exposure to distressing information as potential sources of harm.


Following a serious event, an organisation should promptly identify who may have been exposed and privately check on their immediate condition. A driver who is distressed, distracted or experiencing an acute stress response may not be fit to continue driving, regardless of whether the vehicle was involved in the incident.


The response should include accurate information, practical assistance, access to professional support and later follow-up. It should also control further exposure by preserving relevant recordings as evidence, restricting access and preventing confronting footage from being circulated for curiosity or workplace entertainment.


Providing an employee assistance program telephone number is useful, but it is not a complete critical-incident system. Managers need to know how to recognise possible effects, how to respond without pressuring workers to discuss the event publicly, and when duties, driving or exposure to further material should be modified.


Control rumours as well as hazards

The early claim that an Air Ambulance helicopter had crashed illustrates another recurring feature of emergencies. Initial information is often incomplete, and speculation can rapidly be repeated as fact.


Emergency communication should distinguish clearly between what is confirmed, what is unconfirmed and what workers need to do immediately. Incorrect information can cause unnecessary distress, interfere with response decisions and undermine trust when the facts emerge.


Organisations should nominate an authoritative source, provide short factual updates and correct misinformation promptly. Silence creates a vacuum, and workplace folklore is always willing to volunteer as incident controller.


The lasting lesson

Five people boarded VH-ZCR expecting to fly from Essendon to King Island on 21 Feb 17. None survived the first minute of that flight, while workers, motorists, emergency responders, families and others were left to deal with the consequences.


The technical lesson concerns a critical aircraft setting that was not detected before take-off. The broader organisational lesson is that procedures must verify real conditions, abnormal cues must trigger defined decisions, non-causal deficiencies must still be corrected, and the people exposed to a catastrophe must remain within the organisation’s field of care.


That morning, our transport operation could not alter what had happened at Essendon Airport. It could, however, recognise that our drivers may have been exposed to something no worker should simply be expected to absorb and then continue with the day as though nothing had happened.


That was the control available to us, so we used it.

Comments


Subscribe to The Toolbox Talk

Fortnightly newsletter with practical WHS analysis, podcast updates and new Safety Jon articles.

© Zero Harm Safety Pty Ltd t/as Safety Jon. 2026 and beyond.

bottom of page